Skip to main content
Praxikon
All obligations
Upcomingv1.0.0

Article 15: accuracy, robustness and cybersecurity

Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.

Article 15 requires high-risk systems to achieve and maintain appropriate levels of accuracy, robustness and cybersecurity throughout the lifecycle, including resilience against errors and AI-specific attacks such as data poisoning and adversarial examples.

Praxikon tracks Article 15: accuracy, robustness and cybersecurity under the EU AI Act, checked against the official source on 8 August 2026, citing the source for every statement.

Status
Upcoming
Application date
2 December 2027
Version
1.0.0
Last reviewed
8 August 2026

Review status: placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Upcoming · 2 December 2027

For whom

Provider of an AI system

What you do

Set and test performance and security levels

What you record

Performance and security file

Official source

Article 15(1)-(5)

Who this is relevant to

When this applies

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1The provider places a high-risk AI system on the market or puts it into service.

What the official source establishes

For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

Accuracy here is not a marketing number but a declared, testable value stated in the instructions for use and held against you in production.

What you can do now

Ask suppliers now for declared accuracy levels and test reports, and set up production monitoring against those levels.

  1. 01

    Set and test performance and security levels

    Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.

What to retain

Performance and security file

Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.

Control and reassessment

  • Performance monitoring in use

    Monitor whether the system stays within declared levels in production and escalate on deviation.

Public tools

Conditions and exceptions

  • Systems that continue learning after deployment carry additional requirements to control feedback loops and drift.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 15(1)-(5)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended Article 113 application dates

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 15: accuracy, robustness and cybersecurity",
praxikon:eu:ai-act:obligation:article-15-accuracy-robustness@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 96fcf15ac99ca507169f462e66eaebb72ab06b66e3754b0cf69a69347ed4dc6d,
https://www.praxikon.com/en/verplichtingen/article-15-accuracy-robustness
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-15-accuracy-robustness&effective_at=2026-07-27&known_at=2026-08-08&lang=en, accessed 2026-09-07)

Short form

praxikon:eu:ai-act:obligation:article-15-accuracy-robustness@1.0.0 (sha256 96fcf15a)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-15-accuracy-robustness-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 15: accuracy, robustness and cybersecurity},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-15-accuracy-robustness},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 96fcf15ac99ca507169f462e66eaebb72ab06b66e3754b0cf69a69347ed4dc6d},
  url          = {https://www.praxikon.com/en/verplichtingen/article-15-accuracy-robustness},
  urldate      = {2026-09-07},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-15-accuracy-robustness@1.0.0",
    "type": "dataset",
    "title": "Article 15: accuracy, robustness and cybersecurity",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-15-accuracy-robustness",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-15-accuracy-robustness",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          7
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 96fcf15ac99ca507169f462e66eaebb72ab06b66e3754b0cf69a69347ed4dc6d; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-15-accuracy-robustness&effective_at=2026-07-27&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v1.0.0

    27 July 2026

    Article 15: accuracy, robustness and cybersecurity

    Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, lawyer and AI governance specialist

Expert behind this page

Zahed Ashkara

Lawyer and AI governance specialist

Execution

From obligation to arranged and demonstrable

Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.