Home · EU AI Act · Articles · Article 15
EU AI Act · Engineering reference

Article 15 — Accuracy, Robustness and Cybersecurity

High-risk AI systems must achieve appropriate levels of accuracy, robustness and cybersecurity, including resilience against adversarial input and feedback loops.

Audit-survivable
33%
of 50 EU-exposed enterprises in MindMap's 2026 readiness benchmark

What the Article requires

Article 15 sets three substantive performance requirements. Accuracy: declared metrics and measurement methodology. Robustness: resilience against errors, faults, inconsistencies, and the technical state of the art. Cybersecurity: resilience against attempts to alter use, behaviour or performance, including data-poisoning, model-poisoning, adversarial examples, and confidentiality attacks. The Article also addresses 'feedback loops' (where outputs are reused as future training inputs) — these must be mitigated.

In engineering terms

Accuracy is the easy part for teams with mature ML/AI engineering — declare the eval metric, run the harness on every release, publish the result. Robustness implies a structured evaluation harness with adversarial scenarios. Cybersecurity for AI is the newest discipline: prompt-injection threat modelling, model-poisoning detection on continuous-learning systems, and the feedback-loop mitigation discipline for any system whose outputs train downstream models.

Compliance checklist

  • ✓Accuracy metrics declared and tracked across releases
  • ✓Robustness eval harness including adversarial scenarios
  • ✓Prompt-injection threat model documented
  • ✓Cybersecurity controls per ENISA AI guidelines
  • ✓Feedback-loop mitigation discipline

Terms used here

EU AI ActAnnex III high-risk AI

All Articles in the reference · The EU AI Act compliance architecture

Need audit-survivable evidence for Article 15?

MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.

Download the whitepaper →Check your tier →Book a scoping call →