Standards and guidance
EU AI Act Article 15: AI Cybersecurity Context
The AI Act establishes requirements according to the role, system classification and use case. Article 15 concerns accuracy, robustness and cybersecurity of high-risk AI systems.
How to use this reference
Establish applicability before selecting evidence requirements. An agent control review can contribute technical evidence but does not determine the legal classification or establish full compliance. Consult the applicable current text and your legal advisers.
Evidence to discuss
Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.
Source and status
Regulation (EU) 2024/1689, official text
Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.
Article 15 evidence discussion
These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.
- Has the responsible team established the role and system classification?
- Which accuracy, robustness and cybersecurity requirements are being reviewed?
- Which versioned tests support each requirement, and which claims remain untested?
Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.