Security & Resilience
AI Accuracy, Robustness and Cybersecurity Assurance
What this control does
Define and test accuracy, robustness and cybersecurity measures for high-risk AI, including AI-specific attack resilience.
How to implement
For a high-risk AI provider, define and document appropriate performance, resilience and security criteria for the intended use. Assess likely errors, failures and attacks, including AI-specific threats where relevant. Test suitable safeguards and recovery measures, and document the limits of the evaluation. Keep instructions aligned with validated performance and revisit weaknesses after changes or incidents. Where a presumption of conformity is relied on, verify its exact scope and conditions; it does not establish compliance with unrelated obligations.
Suggested timing and triggers
Before release; throughout the lifecycle as appropriate; after relevant model, infrastructure or threat changes.
Evidence examples
Performance metrics and validation reports Fault, resilience and security test plans and results Threat assessments and safeguard decisions Remediation and retest records Published performance information and any relied-on conformity evidence
How to check this control
Trace a significant performance or security risk to a safeguard and test result. Check that failures were investigated and that the deployer-facing information matches the validated system. Include one changed component in the sample.
Related EU AI Act obligations
Article 15
Ensure High-Risk AI Accuracy, Robustness and Cybersecurity
Article 15(1)-(3)
Define, Validate and Declare Appropriate Accuracy Levels and Metrics
Sub-obligation of Article 15: Ensure High-Risk AI Accuracy, Robustness and Cybersecurity
Article 15(4)
Design High-Risk AI for Resilience to Errors, Faults and Inconsistencies
Sub-obligation of Article 15: Ensure High-Risk AI Accuracy, Robustness and Cybersecurity
Article 15(5); Article 42(3)
Protect High-Risk AI Against Cybersecurity and AI-Specific Attacks
Sub-obligation of Article 15: Ensure High-Risk AI Accuracy, Robustness and Cybersecurity