The framework
- Article 15 sits in the high-risk requirements of the EU AI Act (Regulation (EU) 2024/1689).
- It demands that high-risk AI systems perform consistently across their lifecycle on accuracy, robustness and cybersecurity, with the relevant metrics declared in the accompanying documentation.
- It explicitly calls for resilience against adversarial manipulation — data poisoning, model poisoning, adversarial examples, and attempts to exploit the system to alter its behaviour.
- No harmonised robustness standard exists yet (CEN-CENELEC JTC 21 targets Q4 2026); Provael’s Art. 15 example uses ISO/IEC TR 24029 as its empirical-robustness methodology anchor.
Where a red-team result fits
Robustness
High-risk AI must be resilient to errors, faults and inconsistencies, and to malicious third-party attempts to alter use or performance by exploiting vulnerabilities.
Declared metrics
Accuracy and the relevant accuracy metrics must be declared. A calibrated attack-success rate with a confidence interval is exactly the kind of declared, defensible metric this anticipates.
Beyond the lead clause
- Article 9
- Risk-management system — the calibrated ASR and its trace feed the identification and evaluation of reasonably foreseeable misuse.
- Article 72
- Post-market monitoring — the CI red-team gate is a monitoring signal that re-tests robustness on every checkpoint after release.
- Article 11 / Annex IV
- Technical documentation — carried by the CycloneDX ML-BOM Provael emits for the policy under test.
Evidence produced
- A calibrated attack-success rate with a 95% Wilson confidence interval and a benign false-positive control — a declared robustness metric, not a marketing number.
- A reproducible attack trace per finding, so the robustness evidence is auditable.
- A SARIF report and CI red-team gate that demonstrate ongoing robustness testing across the lifecycle.
- Beyond Art. 15 robustness, the same evidence pack maps to Art. 9 (risk-management system), Art. 72 (post-market monitoring) and Art. 11 / Annex IV (technical documentation — carried by the CycloneDX ML-BOM Provael emits).
Dates (verified 6 Jul 2026)
- High-risk (Annex I) obligations apply
- 2 August 2027Statutory date under Regulation (EU) 2024/1689.
- Proposed extension
- 2 August 2028Digital Omnibus proposal — provisional agreement May 2026, NOT yet adopted. State both; do not treat 2028 as settled.
Not legal advice; verify the live EUR-Lex/ISO text at launch before relying on these dates.
Primary references
What it is — and isn’t
- adversarial-only — Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.
- evidence-not-certification — The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
- behavioural-not-worst-case — Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.
Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Clause references are indicative; a wrong clause citation is worse than a missing one.
Turn this into filed evidence.
Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.