EU AI Act Art. 15: accuracy, robustness and cybersecurity

Accuracy, robustness and cybersecurity

From clause to evidenceThe chain from EU AI Act Art. 15 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI ActArt. 15Duty holderProviderApplies from2027-12-02DeferredArtefactEval gateLayersLayer 03Layer 04Evidence recordEval result+4 moreSame topic in 20 frameworks (52 clauses): ISO 42001, NIST AI RMF, TC260 Framework 3.0, China GenAI Measures, China DeepSynthesis, CSA AICM, OWASP LLM and 13 moreAs of 2026-09-24 · illustrative, not a claim of conformity From clause to evidenceThe chain from EU AI Act Art. 15 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI Act · Art. 15Duty holderProviderApplies from2027-12-02 · DeferredArtefactEval gateLayersLayer 03Layer 04Evidence recordEval result · +4 moreSame topic in 20 frameworks (52 clauses):ISO 42001, NIST AI RMF, TC260 Framework 3.0,China GenAI Measures, China Deep Synthesis…As of 2026-09-24illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-EUAIA-ART15. Drawn from chapter 08.
Text alternative
  • Clause: EU AI Act, Art. 15.
  • Duty holder: Provider.
  • Applies from: 2027-12-02, Deferred.
  • Artefact: Eval gate.
  • Layers: Layer 03, Layer 04.
  • Evidence record: Eval result, +4 more.
  • Record schemas: Eval result , Control observation , Test plan , Test report , Design record .
  • The same topic in 20 other frameworks; the crosswalk section below links each clause.
Id
AIGE-OBL-EUAIA-ART15
Instrument
EU AI Act (post-Omnibus) law
Compared side by side
ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
Clause
Art. 15
Duty holder
Provider
Authority
National MSA
Applies from
Deferred · Annex III
Later dates
  • Applies to Annex I embedded (product safety-component) systems
  • Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))
System class
High-risk (Annex III) · High-risk (Annex I)

The artefact that evidences it

Eval gate; adversarial red-team suite; robustness and security controls; regression evals.

Patterns that build it

The same topic in other frameworks

From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.

Runtime guardrails

Robustness, security and evaluations

Open controls that evidence it

Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.

Source

Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). EU AI Act Art. 15: accuracy, robustness and cybersecurity (AIGE-OBL-EUAIA-ART15). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{EU AI Act Art. 15: accuracy, robustness and cybersecurity (AIGE-OBL-EUAIA-ART15)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15},
  note         = {Version 0.5.0}
}