Article 15: accuracy, robustness and cybersecurity
Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.
The official source remains authoritative. This general interpretation is not legal advice.
- Status
- Upcoming
- Application date
- 2 December 2027
- Version
- 1.0.0
- Last reviewed
- 8 August 2026
Who this is relevant to
When this applies
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1The provider places a high-risk AI system on the market or puts it into service.
What the official source establishes
Article 15 requires high-risk systems to achieve and maintain appropriate levels of accuracy, robustness and cybersecurity throughout the lifecycle, including resilience against errors and AI-specific attacks such as data poisoning and adversarial examples.
For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.
Our interpretation
Accuracy here is not a marketing number but a declared, testable value stated in the instructions for use and held against you in production.
What you can do now
Ask suppliers now for declared accuracy levels and test reports, and set up production monitoring against those levels.
- 01
Set and test performance and security levels
Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.
What to retain
Performance and security file
Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.
Control and reassessment
Performance monitoring in use
Monitor whether the system stays within declared levels in production and escalate on deviation.
Public tools
Full text of Article 15
The full legal text in the public AI Act Explorer.
Conditions and exceptions
- Systems that continue learning after deployment carry additional requirements to control feedback loops and drift.
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 15(1)-(5)
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Amended Article 113 application dates
Version history
v1.0.0
27 July 2026
Article 15: accuracy, robustness and cybersecurity
Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.
Execution
From obligation to arranged and demonstrable
Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.
See the Embed AI approachFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.