# EU AI Act · Article 15

> Article 15 requires high-risk AI systems to achieve appropriate levels of accuracy, robustness and cybersecurity, and to be resilient against attempts to alter their use or behaviour by exploiting vulnerabilities. It is the clearest legal hook for adversarial red-teaming of a robot policy — and the one Provael leads with.

Regulation/standard: Regulation (EU) 2024/1689
Timing: Annex I high-risk obligations apply 2 August 2027 (statutory).

## What it is

- Article 15 sits in the high-risk requirements of the EU AI Act (Regulation (EU) 2024/1689).
- It demands that high-risk AI systems perform consistently across their lifecycle on accuracy, robustness and cybersecurity, with the relevant metrics declared in the accompanying documentation.
- It explicitly calls for resilience against adversarial manipulation — data poisoning, model poisoning, adversarial examples, and attempts to exploit the system to alter its behaviour.
- No harmonised robustness standard exists yet (CEN-CENELEC JTC 21 targets Q4 2026); Provael’s Art. 15 example uses ISO/IEC TR 24029 as its empirical-robustness methodology anchor.

## Where a red-team result fits

- **Robustness** — High-risk AI must be resilient to errors, faults and inconsistencies, and to malicious third-party attempts to alter use or performance by exploiting vulnerabilities.
- **Declared metrics** — Accuracy and the relevant accuracy metrics must be declared. A calibrated attack-success rate with a confidence interval is exactly the kind of declared, defensible metric this anticipates.

## What Provael maps to it

- A calibrated attack-success rate with a 95% Wilson confidence interval and a benign false-positive control — a declared robustness metric, not a marketing number.
- A reproducible attack trace per finding, so the robustness evidence is auditable.
- A SARIF report and CI red-team gate that demonstrate ongoing robustness testing across the lifecycle.
- Beyond Art. 15 robustness, the same evidence pack maps to Art. 9 (risk-management system), Art. 72 (post-market monitoring) and Art. 11 / Annex IV (technical documentation — carried by the CycloneDX ML-BOM Provael emits).

## Dates (verified 6 Jul 2026)

- High-risk (Annex I) obligations apply: 2 August 2027 (Statutory date under Regulation (EU) 2024/1689.)
- Proposed extension: 2 August 2028 (Digital Omnibus proposal — provisional agreement May 2026, NOT yet adopted. State both; do not treat 2028 as settled.)

## Sources

- EU AI Act Article 15 (artificialintelligenceact.eu): https://artificialintelligenceact.eu/article/15/
- Regulation (EU) 2024/1689 (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Canonical: https://www.provael.com/compliance/eu-ai-act-article-15

---
Provael · Prove it. Prevail. · Apache-2.0 · https://github.com/provael/provael
Not legal advice; verify regulatory dates against the primary source.
