Insights
EU AI Act Article 15: Technical Evidence Planning
Establish legal scope before selecting technical evidence.
What to review
Article 15 addresses accuracy, robustness and cybersecurity of high-risk AI systems. First identify the actual system and role with legal and compliance owners. An agent’s ability to take actions does not by itself settle its legal classification.
What to test or document
For an applicable review, discuss versions, threat scenarios, control configuration, observed test results, known limitations and operating responsibilities. These artefacts may contribute evidence; they do not establish full legal compliance or replace the wider required documentation.
Prepare the next step
Use Security Review Readiness Checklist to record gaps and owners before a scoped assessment.
Build an evidence index with clear boundaries
- Record the legal applicability decision made by the responsible team, including the system and role in scope.
- Link the agreed technical requirement to a control owner and implementation record.
- Attach versioned tests, observed results, exclusions and unresolved findings.
- Identify the reviewer who accepts the evidence and the changes that trigger another review.
An agent action-policy test can show that a specific export was denied under a specific configuration. It cannot establish overall AI Act compliance. Keep that distinction visible when evidence is reused across buyer, engineering and regulatory discussions.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.