Article 15: Accuracy, robustness and cybersecurity
Praxikon tracks Article 15 (Accuracy, robustness and cybersecurity) under the EU AI Act, citing the source for every statement.
Application dates
- : Requirements for high-risk systems listed in Annex III
- : Requirements for high-risk systems linked to Annex I
Article 15 requires high-risk AI systems to achieve an appropriate level of accuracy, robustness and cybersecurity, and perform consistently throughout their lifecycle.
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF) →Official guidance on this article
3- Commission Implementing Decision C(2025) 3871 of 23.6.2025 on a standardisation request to CEN and CENELEC as regards high-risk AI systems in support of Regulation (EU) 2024/1689 and repealing Implementing Decision C(2023) 3215Requests separate standards for accuracy, robustness and cybersecurity, the three requirements that Article 15 imposes without a concrete yardstickPublishedImplementing actEuropean Commission23 Jun 2025
- prEN 18281:2026 Evaluation methods for computer vision systems (draft European standard, public enquiry)Provides the measurement methods by which a provider can substantiate the accuracy of an image recognition system as required by Article 15 and explain it in the instructions for use.DraftStandardCEN-CENELEC JTC 21, national consultation through NEN7 Apr 2026
- prEN 18282 Cybersecurity specifications for AI systems (draft European standard, public enquiry)Works out the cybersecurity requirement of Article 15 into concrete measures against AI-specific attacks such as data poisoning and model manipulation, which the legal text itself only names without elaboration.DraftStandardCEN-CENELEC JTC 21, national consultation through NEN19 May 2026
Compliance checklist
- Accuracy, robustness and cybersecurity ensured
- System resilient to errors and inconsistencies
- Protected against unauthorised access
- Redundancy solutions available
- Performance consistent under expected conditions
Want to save your progress? Create an account
Related Recitals
Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Related blog posts
Cross-references
Frequently asked questions
What does Article 15 AI Act require regarding accuracy?+
Does Article 15 set cybersecurity requirements for AI?+
What documentation does Article 15 of the AI Act require?+
What Article 15 requires in practice
Connections
What connects to Article 15 AI Act
Themes where this returns
The counterpart in the other law
GDPR interpretation that also applies here
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland · via Security and robustness
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB) · via Security and robustness
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB) · via Security and robustness