The framework
- Article 15 sits in the high-risk requirements of the EU AI Act (Regulation (EU) 2024/1689).
- It demands that high-risk AI systems perform consistently across their lifecycle on accuracy, robustness and cybersecurity, with the relevant metrics declared in the accompanying documentation.
- It explicitly calls for resilience against adversarial manipulation - data poisoning, model poisoning, adversarial examples, and attempts to exploit the system to alter its behaviour.
- No harmonised robustness standard exists yet (CEN-CENELEC JTC 21 targets Q4 2026); Provael’s Art. 15 example uses ISO/IEC TR 24029 as its empirical-robustness methodology anchor.
Where a red-team result fits
Robustness
High-risk AI must be resilient to errors, faults and inconsistencies, and to malicious third-party attempts to alter use or performance by exploiting vulnerabilities.
Declared metrics
Accuracy and the relevant accuracy metrics must be declared. An attack-success rate with a confidence interval and a benign control is exactly the kind of declared, defensible metric this anticipates.
Beyond the lead clause
- Article 9
- Risk-management system - the measured ASR and its trace feed the identification and evaluation of reasonably foreseeable misuse.
- Article 72
- Post-market monitoring - the CI red-team gate is a monitoring signal that re-tests robustness on every checkpoint after release.
- Article 11 / Annex IV
- Technical documentation - carried by the CycloneDX ML-BOM Provael emits for the policy under test.
Evidence produced
- An attack-success rate with a 95% Wilson confidence interval and a benign false-positive control - a declared robustness metric, not a marketing number. Candidate evidence toward Art. 15 documentation, not a conformity conclusion.
- A reproducible attack trace per finding, so the robustness evidence is auditable.
- A SARIF report and CI red-team gate that demonstrate ongoing robustness testing across the lifecycle.
- Beyond Art. 15 robustness, the same evidence pack maps to Art. 9 (risk-management system), Art. 72 (post-market monitoring) and Art. 11 / Annex IV (technical documentation - carried by the CycloneDX ML-BOM Provael emits).
Dates (verified 26 Jul 2026)
- Statutory application date (product-embedded high-risk, Annex I)
- 2 August 2027Original date under Regulation (EU) 2024/1689 - now superseded by the adopted AI Digital Omnibus.
- Application date under the adopted AI Digital Omnibus
- 2 August 2028Regulation (EU) 2026/1744 (Digital Omnibus on AI): Parliament 16 June 2026, Council 29 June 2026, published OJ 24 July 2026, in force 27 July 2026. Re-verified 26 July 2026; verify the primary source before relying on it.
Not legal advice; verify the live EUR-Lex/ISO text at launch before relying on these dates.
Primary references
What it is - and isn’t
- adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
- evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
- behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Clause references are indicative; a wrong clause citation is worse than a missing one.
Turn this into filed evidence.
Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.