! High compliance impact for SMEs
WHAT THE ARTICLE IS ABOUT
Technical performance as a legal obligation
Article 15 closes the Section 2 requirements for high-risk AI by addressing the technical quality of the system itself. It establishes that high-risk AI systems must achieve appropriate levels of accuracy, be robust against errors and inconsistencies, and be protected against cybersecurity threats — particularly those that could manipulate the AI’s behaviour.
WHAT IT SAYS
Accuracy declared, robustness maintained, security protected
- High-risk AI systems must achieve an appropriate level of accuracy, robustness, and cybersecurity — and perform consistently in these respects throughout their lifecycle
- The accuracy levels, and the metrics used to measure them, must be declared in the instructions for use provided under Article 13
- Systems must be resilient against errors, faults, and inconsistencies — whether arising from within the system, from the environment, or from deliberate manipulation
- Technical redundancy solutions, including backup or fail-safe plans, must be implemented where technically feasible
- Providers must implement appropriate cybersecurity measures to protect against attacks that could exploit AI-specific vulnerabilities — including data poisoning, model poisoning, adversarial examples, and model theft
- Where the system continues to learn after deployment, safeguards must be in place to ensure post-deployment learning does not compromise accuracy or create bias
WHO IS AFFECTED
Primarily providers — but deployers share responsibility for security
- Providers of high-risk AI systems — must design and test systems to meet accuracy and robustness requirements before market placement
- Technical and security teams responsible for AI system architecture
- Deployers operating AI systems in sensitive or high-stakes environments — must maintain cybersecurity standards in their own infrastructure
- Organisations procuring AI systems — accuracy and robustness requirements give you a basis to demand performance benchmarks from vendors
WHAT IT MEANS FOR SMES
Accuracy claims must be honest — and security cannot be an afterthought
- If you are a provider: the accuracy level you declare in your instructions for use is a legal commitment — overstating accuracy to win customers creates compliance and liability risk
- Build robustness testing into your development cycle, not just pre-launch — the obligation applies throughout the lifecycle
- If you are a deployer: the cybersecurity of your infrastructure matters here — a system that is technically compliant can still be compromised through your own IT environment
- AI-specific attacks like data poisoning and adversarial inputs are different from traditional cybersecurity threats — ensure whoever manages your IT security understands these AI-specific risks
- For systems that learn after deployment: put governance in place to monitor for accuracy drift or bias creep — this is both a technical and a compliance obligation
Related Articles
- Article 9 — Risk management (accuracy and security risks must be addressed here)
- Article 13 — Transparency (accuracy metrics must be disclosed to deployers)
- Article 72 — Post-market monitoring (ongoing accuracy monitoring is required)
- Article 10 — Data governance (data quality directly affects accuracy)
