Article 15 — Accuracy, Robustness and Cybersecurity
Article No.
15
Legal Provision
Accuracy, robustness and cybersecurity: Lays out that high-risk AI systems must be built to stay accurate, robust, secure, and reliably protected against errors, bias, and misuse.
Scope
Applies to entities who are providers and deployers of high-risk AI systems.
Requirement type
Duty: when providing or deploying a high-risk system, the entity must exercise measures towards accuracy, robustness, security and reliability.
Actions to demonstrate compliance
A. Binary (yes/no)
- The system has documented its accuracy, error rates and limits.
- Robustness test reports that test the system under difficult or imperfect conditions for safety and predictability, have been completed and recorded.
- Cybersecurity test evidence (such as pen tests, vulnerability scans).
- Alert system in place to detect unusual behaviour and alert humans when performance drops.
B. Non-binary (require a contextual assessment)
- The accuracy thresholds are suitable for the system's intended use.
- Robustness testing is thorough and covers all relevant scenarios.
- The system's cybersecurity protections are strong and appropriate.
- The system performs reliably in real-world conditions.
- Documentation is transparent, clear, and aligned with actual performance.
- Measures are proportionate to the system's overall risk profile.
Monitoring requirement
- Measure and document accuracy metrics & test results.
- Conduct and document stress tests and other cybersecurity tests, and update when necessary.
- Implement effective alert system in place.
- Protect the system against tampering, unauthorised access, and adversarial inputs.
Consequences of non-compliance
- Fines up to €15 million or 3% of worldwide annual turnover, whichever is higher.
- Other enforcement measures including warnings, suspensions or recalls that are put in place by Member States.