Standards and guidance

EU AI Act Article 15: AI Cybersecurity Context

The AI Act establishes requirements according to the role, system classification and use case. Article 15 concerns accuracy, robustness and cybersecurity of high-risk AI systems.

How to use this reference

Establish applicability before selecting evidence requirements. An agent control review can contribute technical evidence but does not determine the legal classification or establish full compliance. Consult the applicable current text and your legal advisers.

Evidence to discuss

Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.

Source and status

Regulation (EU) 2024/1689, official text

Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.

Article 15 evidence discussion

These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.

  • Has the responsible team established the role and system classification?
  • Which accuracy, robustness and cybersecurity requirements are being reviewed?
  • Which versioned tests support each requirement, and which claims remain untested?

Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.