What matters in AI.

Subscribe

Learn / AI governance

Definition · AI governance

EU AI Act Article 15

Article 15 of the EU AI Act requires high-risk AI systems to achieve an appropriate level of accuracy, robustness and cybersecurity, and to perform consistently throughout their lifecycle. Its paragraph 5 requires resilience against unauthorised attempts to alter a system's use, outputs or performance, and names attacks to address where appropriate, including data poisoning and adversarial examples.

Last reviewed

Key points

  • Article 15 requires high-risk AI systems to achieve an appropriate level of accuracy, robustness and cybersecurity throughout their lifecycle.
  • Paragraph 5 names five things to defend against "where appropriate": data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.
  • It binds only systems Article 6 classes as high-risk, through certain EU product laws in Annex I or the uses listed in Annex III.
  • The Act describes the two poisoning attacks by what the attacker manipulates, and does not define confidentiality attacks or model flaws.
  • NIST calls its guidance on these attacks voluntary. Article 15 is binding law, applying from 2 December 2027 at the earliest.

Article 15 of the EU AI Act sets the accuracy, robustness and cybersecurity requirements for high-risk AI systems, and names attacks specific to AI. For the systems it covers, once it applies, it makes defending against some AI security attacks a legal duty. The US National Institute of Standards and Technology (NIST) says its own guidance on these attacks “remains voluntary”.

What Article 15 requires

  • Paragraph 1: “an appropriate level of accuracy, robustness, and cybersecurity”, kept up “throughout their lifecycle”.
  • Paragraph 2: the Commission encourages ways to measure accuracy and robustness.
  • Paragraph 3: accuracy levels go in the instructions of use.
  • Paragraph 4: “as resilient as possible” to errors and faults, for example through fail-safe plans. A system that keeps learning after release must reduce, as far as possible, the risk of its biased outputs feeding back into its inputs, and must mitigate such feedback loops.
  • Paragraph 5: cybersecurity, in three sentences.

The first sentence of paragraph 5 requires resilience against attempts by “unauthorised third parties” to alter a system’s use, outputs or performance by exploiting its vulnerabilities. The second requires cybersecurity solutions “appropriate to the relevant circumstances and the risks”. Only the third, which lists what to defend against, says “where appropriate”.

What paragraph 5 names

The Act describes the two poisoning attacks by what the attacker manipulates, and adversarial examples by what the input is designed to do. It does not define the last two items. Recital 76, one of the numbered explanations that come before the articles, gives membership inference as an example of an attack on trained models, without saying which item it falls under.

Which systems it covers

Article 15 binds only AI systems that Article 6 classifies as high-risk. There are two routes in.

  • Products, Article 6(1). The AI system is a product, or a safety component of a product, covered by the EU product laws listed in Annex I. That product must also pass a third-party conformity assessment, meaning an outside body checks it before it goes on the market.
  • Listed uses, Article 6(2). The AI system appears in Annex III, which lists specific high-risk uses in eight areas: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and justice and democratic processes. Not every system in those areas is listed.

The product route has limits. Article 15 applies only to products under the laws in Section A of Annex I, such as toys, lifts and medical devices. For those in Section B, such as vehicles, aviation and rail, the Act instead amends each sector’s own law so that its rulemaking takes these requirements into account. The Digital Omnibus on AI, a 2026 regulation amending the Act, narrowed the route further:

  • it moved machinery from Section A to Section B
  • AI used solely for non-safety tasks such as user assistance or convenience is not a safety component, unless its failure would endanger health and safety
  • a product that needs the outside check only for risks other than health and safety, such as radio spectrum use, does not count
  • the Commission may limit Article 15 for Section A products whose own law gives equal or higher protection, if overall protection is not reduced

Article 6(3) makes an exception for Annex III systems that do “not pose a significant risk of harm to the health, safety or fundamental rights of natural persons”. It applies only if the system is meant to do one of four things: “perform a narrow procedural task”; “improve the result of a previously completed human activity”; spot decision-making patterns while “not meant to replace or influence the previously completed human assessment, without proper human review”; or perform a preparatory task for an assessment in an Annex III use. An Annex III system that profiles people is always high-risk.

The Cyber Resilience Act route

The Digital Omnibus added Article 42(3). A high-risk system that falls under the Cyber Resilience Act, Regulation (EU) 2024/2847, and meets the conditions of its Article 12(1) is “deemed to comply with the cybersecurity requirements set out in Article 15”.

When it applies

The Digital Omnibus set the start: 2 December 2027 for Annex III systems, and 2 August 2028 for Annex I products under Article 6(1). The original dates were 2 August 2026 and 2 August 2027.

Where definitions disagree

NIST AI 100-2e2025 classifies attacks along five dimensions, including the AI system type, the attacker’s objective and the attacker’s capabilities. For predictive AI, its taxonomy groups attacks by objective: availability breakdown (stopping the system working), integrity violation (making it misperform) and privacy compromise (leaking information). For generative AI, it adds misuse enablement. Article 15(5) has no objective layer. It lists five items, and describes three of them by what they target.

The two model poisoning definitions draw their lines in different places. The Act’s turns on the target: “pre-trained components used in training”. NIST’s turns on access: “the adversary controls the model and its parameters”. NIST says that happens most in federated learning, where many parties train one model together, and in supply-chain attacks by model suppliers. On data poisoning the two agree in substance.

The confidentiality label differs too. NIST notes that “confidentiality” is the more common term in traditional cybersecurity, while the adversarial machine learning field “has tended to use” “privacy” for attacks on a model’s confidentiality and on its training data. NIST files model extraction as a model privacy attack. The Act says “confidentiality attacks” and does not say what they include.

Questions and answers

What does Article 15(5) of the EU AI Act require?

Article 15(5) says high-risk AI systems "shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities". Their cybersecurity solutions must be "appropriate to the relevant circumstances and the risks". The solutions for AI-specific vulnerabilities must include, where appropriate, measures to "prevent, detect, respond to, resolve and control for" five named items: data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.

Which AI systems does Article 15 apply to?

Only AI systems that Article 6 of the EU AI Act classifies as high-risk, and not all of those. One route is AI that is a product, or a safety component of a product, covered by EU product laws listed in Annex I, where the product must pass an assessment by an outside body. Article 15 applies only to products under the laws in Section A of Annex I, such as toys, lifts and medical devices. The other route is Annex III, which lists specific high-risk uses in areas such as biometrics, employment, essential services and law enforcement. An Annex III system can escape the high-risk label if it poses no significant risk of harm to health, safety or fundamental rights and meets one of four narrow conditions, but never if it profiles people.

What does 'where appropriate' mean in Article 15(5)?

Paragraph 5 has three sentences, and "where appropriate" appears only in the third, which lists measures against the named attacks and model flaws. The first, a duty to be resilient against unauthorised attempts to alter the system, does not use the phrase. The second applies to all the cybersecurity solutions: they must be appropriate to the circumstances and the risks.

How does Article 15(5) differ from NIST guidance on AI security?

The main difference is legal force. NIST AI 100-2e2025 states its guidance "remains voluntary". Article 15 of the EU AI Act is binding regulation, though it does not apply until December 2027 at the earliest. The two are also built differently. NIST sorts attacks along several dimensions, such as the attacker's objective and capabilities. Article 15(5) gives a list of five items.

When does Article 15 start to apply?

Not yet. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the dates. Article 15 applies from 2 December 2027 to high-risk systems listed in Annex III, where the original date was 2 August 2026. It applies from 2 August 2028 to high-risk systems under Article 6(1): AI that is, or is a safety component of, an Annex I Section A product that needs third-party conformity assessment. There the original date was 2 August 2027. A high-risk system already on the market before its date is covered only if its design later changes significantly. Systems meant for public authorities must comply by 2 August 2030 regardless, and parts of the EU's large-scale IT systems listed in Annex X have their own deadline of 31 December 2030.

Is Article 15 the same as the entire EU AI Act?

No. Article 15 is the last article of Chapter III, Section 2 (Articles 8 to 15), the Act's requirements for high-risk AI systems. The other requirements there cover risk management, data governance, technical documentation, record-keeping, transparency and human oversight. This page covers only Article 15's accuracy, robustness and cybersecurity obligations.

Sources

  1. Regulation (EU) 2024/1689 (EU AI Act), Article 15: Accuracy, Robustness and CybersecurityEuropean Union, 12 Jul 2024
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), recital 40 and Article 1 points 39 and 40 amending Articles 111 and 113European Union, 24 Jul 2026
  3. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025)NIST, 24 Mar 2025