Insights

EU AI Act Article 15: Technical Evidence Planning

Establish legal scope before selecting technical evidence.

EndigitalX editorialReviewed

What to review

Article 15 addresses accuracy, robustness and cybersecurity of high-risk AI systems. First identify the actual system and role with legal and compliance owners. An agent’s ability to take actions does not by itself settle its legal classification.

Official AI Act text.

What to test or document

For an applicable review, discuss versions, threat scenarios, control configuration, observed test results, known limitations and operating responsibilities. These artefacts may contribute evidence; they do not establish full legal compliance or replace the wider required documentation.

Prepare the next step

Use Security Review Readiness Checklist to record gaps and owners before a scoped assessment.

Build an evidence index with clear boundaries

  1. Record the legal applicability decision made by the responsible team, including the system and role in scope.
  2. Link the agreed technical requirement to a control owner and implementation record.
  3. Attach versioned tests, observed results, exclusions and unresolved findings.
  4. Identify the reviewer who accepts the evidence and the changes that trigger another review.

An agent action-policy test can show that a specific export was denied under a specific configuration. It cannot establish overall AI Act compliance. Keep that distinction visible when evidence is reused across buyer, engineering and regulatory discussions.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.