Chapter III · High-risk AI systems
Article 15 — Accuracy, robustness and cybersecurity
Official text
Each paragraph records where its wording comes from. Only text reproduced unchanged from the Official Journal is authentic; consolidated text is editorial and has no legal value. Paragraphs, subparagraphs and points each have their own link.
High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.
Authentic — as published in the Official Journal
To address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies.
Authentic — as published in the Official Journal
The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.
Authentic — as published in the Official Journal
High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard.
The robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans.
High-risk AI systems that continue to learn after being placed on the market or put into service shall be developed in such a way as to eliminate or reduce as far as possible the risk of possibly biased outputs influencing input for future operations (feedback loops), and as to ensure that any such feedback loops are duly addressed with appropriate mitigation measures.
Authentic — as published in the Official Journal
High-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities.
The technical solutions aiming to ensure the cybersecurity of high-risk AI systems shall be appropriate to the relevant circumstances and the risks.
The technical solutions to address AI specific vulnerabilities shall include, where appropriate, measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the training data set (data poisoning), or pre-trained components used in training (model poisoning), inputs designed to cause the AI model to make a mistake (adversarial examples or model evasion), confidentiality attacks or model flaws.
Authentic — as published in the Official Journal
The formal analysis of Article 15
Article 6 is formalised first. The remaining articles follow.
Article 15 is formalised node by node: each rule as a deontic position with its operator, each exception with its rank, each predicate resolved against the definitions in Article 3.
What members get, per article
- the rule logic: every norm as a formal position, with the defeater chain that decides which exception wins
- the competency questions and their answers, every unanswered one marked as a gap and named
- the ontology: predicates bound to AISV (AI Standardisation Vocabulary) and to the definitions they depend on, exportable as JSON-LD and OWL
- the documentation: the Article 6(4) assessment record generated from a fact set, with its derivation and the version of the law it was decided against
Built for providers claiming the 6(3) derogation, for the counsel who has to defend that claim, and for the auditor who reads it afterwards.
Access is invite-only and opening in stages. Article 6 is formalised first; the remaining articles follow.
No mail client? Write to hello@signatu.com
Already a member? Sign in
Commentary in preparation
The official text above is complete. The editorial layer for this article — duties, the roles bound by them, the AISV concepts that model them, and the European standards written to support them — is in preparation, in the same form as the articles already published.
See the published articles