Article 15: Accuracy, Robustness, Cybersecurity
Article 15 requires high-risk systems to achieve an appropriate level of accuracy, robustness, and cybersecurity, and to perform consistently in these respects throughout their lifecycle. Systems that continue to learn after deployment must have measures to address risks of biased or corrupted feedback loops, including protection against data poisoning and adversarial attacks.
- 02 Dec 2027 Applies to Annex III high-risk systems
- 02 Aug 2028 Applies to Annex I embedded high-risk systems
- Declare accuracy metrics and levels appropriate to the system's intended purpose in the instructions for use.
- Ensure resilience against errors, faults, and inconsistencies in the system's environment.
- Implement technical measures against data poisoning, adversarial examples, and other cybersecurity attack vectors relevant to the system.
- For systems that continue to learn after deployment, address risks of feedback loops that could bias future outputs.
- Monitor accuracy and robustness over time rather than testing only before launch.
- Test protocols and accuracy/robustness metrics in the technical documentation
Accuracy and robustness testing is often treated as a pre-launch checkbox, but Article 15 requires consistent performance across the system's whole lifecycle, including monitoring for drift after deployment.
What regulators published on Art. 15
- Loading from the public feed…
- Regulation (EU) 2024/1689 on EUR-Lex
- Look for Article 15
- Deadline changes and the acts behind them
Get told when Art. 15 moves.
Deadlines under this regulation have already shifted once in 2026. A signed webhook, a REST API and an MCP server carry the same record this page is built from, so your systems learn about the next change without anyone re-reading the text. Free during the beta.
Get free accessInformational content only. Not legal advice and not a substitute for qualified counsel. Dates reflect Regulation (EU) 2026/1744 as of 04 Aug 2026.