Achieve appropriate accuracy, robustness and cybersecurity
Under EU AI Act, Article 15
What does it require?
High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.
Practical action
Include AI-specific threat modelling and adversarial testing in your security programme.
Who does it apply to?
Providers of high-risk AI systems.
- Actors
- Provider / developer
- Sectors
- Cross-sector / all sectors
Applies from:
Evidence examples
- Accuracy metrics and test evidence (report)
- AI security assessment (report)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Annex A controls on AI system verification and validation | Original editorial mapping. | medium |
| ISO/IEC 27001:2022 | Clause 8 and Annex A security controls | Original editorial mapping for cybersecurity aspects. | medium |
| NIST AI RMF 1.0 | MEASURE 2.5, 2.6, 2.7 | Validity, safety, security and resilience measurement. | high |
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.