Legal requirement Accuracy, robustness and cybersecurity European Union Partially applicable

Achieve appropriate accuracy, robustness and cybersecurity

Under EU AI Act, Article 15

Source-linked Open official source

What does it require?

High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.

Practical action

Include AI-specific threat modelling and adversarial testing in your security programme.

Who does it apply to?

Providers of high-risk AI systems.

Applies from:

Evidence examples

  • Accuracy metrics and test evidence (report)
  • AI security assessment (report)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Annex A controls on AI system verification and validationOriginal editorial mapping.medium
ISO/IEC 27001:2022Clause 8 and Annex A security controlsOriginal editorial mapping for cybersecurity aspects.medium
NIST AI RMF 1.0MEASURE 2.5, 2.6, 2.7Validity, safety, security and resilience measurement.high

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.