AI Act, Article 15 (accuracy, robustness and cybersecurity)
Regulation (EU) 2024/1689, Article 15
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force in 437 days, effective 2 December 2027.
An AI risk obligations rule binding public and private bodies.
As of 21 September 2026.
What it requires
- This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
- If you are the provider of a high-risk AI system, design and develop it to achieve an appropriate level of accuracy, robustness and cybersecurity, held consistently throughout its lifecycle.
- Declare the levels of accuracy and the relevant accuracy metrics of your high-risk AI system in its accompanying instructions of use.
- Build your high-risk AI system to be as resilient as possible to errors, faults or inconsistencies, including those arising from its interaction with people or other systems, through technical and organisational measures.
- If your high-risk AI system continues to learn after it is placed on the market or put into service, develop it to eliminate or reduce as far as possible the risk of biased outputs feeding back into future operations, and put mitigation measures in place for any feedback loop that remains.
- Make your high-risk AI system resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting vulnerabilities, with technical solutions appropriate to the circumstances and the risk.
- Where appropriate to the risk, include measures to prevent, detect, respond to, resolve and control for data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and other model flaws.
If you get it wrong
Private right of actionNo
What it reaches
Obligation class
Security, Governance
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Providers of a high-risk AI system must design and develop it to achieve an appropriate level of accuracy, robustness and cybersecurity, performing consistently in those respects throughout its lifecycle. The system's accuracy levels and metrics must be declared in its accompanying instructions of use.
The system must be as resilient as possible to errors, faults or inconsistencies, including those arising from its interaction with people or other systems, through technical and organisational measures, and a system that continues to learn after deployment must be developed to eliminate or reduce as far as possible the risk of biased outputs feeding back into future operations, with mitigation measures for any feedback loop that remains.
The system must be resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting vulnerabilities, with technical solutions appropriate to the circumstances and the risk, including, where appropriate, measures against data poisoning, model poisoning, adversarial examples or model evasion, and confidentiality attacks.
A high-risk AI system that meets the essential cybersecurity requirements of the Cyber Resilience Act (Regulation (EU) 2024/2847) and whose declaration of conformity under that Regulation demonstrates the level of cybersecurity Article 15 requires is deemed to comply with Article 15's cybersecurity requirement, though no such presumption covers accuracy or robustness.
Article 15 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.
When LexLint raises it
high_risk_decisions
Read the law
official consolidated Official Journal text, EUR-Lex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.