What the Article requires
Article 15 sets three substantive performance requirements. Accuracy: declared metrics and measurement methodology. Robustness: resilience against errors, faults, inconsistencies, and the technical state of the art. Cybersecurity: resilience against attempts to alter use, behaviour or performance, including data-poisoning, model-poisoning, adversarial examples, and confidentiality attacks. The Article also addresses 'feedback loops' (where outputs are reused as future training inputs) — these must be mitigated.
In engineering terms
Accuracy is the easy part for teams with mature ML/AI engineering — declare the eval metric, run the harness on every release, publish the result. Robustness implies a structured evaluation harness with adversarial scenarios. Cybersecurity for AI is the newest discipline: prompt-injection threat modelling, model-poisoning detection on continuous-learning systems, and the feedback-loop mitigation discipline for any system whose outputs train downstream models.
Compliance checklist
- ✓Accuracy metrics declared and tracked across releases
- ✓Robustness eval harness including adversarial scenarios
- ✓Prompt-injection threat model documented
- ✓Cybersecurity controls per ENISA AI guidelines
- ✓Feedback-loop mitigation discipline
Terms used here
All Articles in the reference · The EU AI Act compliance architecture
Need audit-survivable evidence for Article 15?
MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.