Logo Teldat

• Cybersecurity Glossary

EU AI Act and Cybersecurity: What Article 15 requires of AI systems?

Article 15 of the EU AI Act, Regulation (EU) 2024/1689, is the provision that ties AI reliability to Cybersecurity. It requires High risk AI systems to be designed for an appropriate level of accuracy, robustness and cybersecurity, and to perform consistently throughout their lifecycle. That means declaring accuracy metrics, staying Resilient against errors and harmful feedback loops, and resisting attempts by unauthorised third parties to alter a system’s use, outputs or performance by exploiting vulnerabilities, including AI specific threats like data poisoning and adversarial examples. This page explains what Article 15 requires, which systems it covers, the threats it targets, and how resilient infrastructure supports it.

What Article 15 is?

Article 15 of the EU AI Act, Regulation (EU) 2024/1689, is titled Accuracy, robustness and cybersecurity, and it is the provision where the AI Act meets cybersecurity most directly. It sets out how well a high risk AI system must perform and how strongly it must be protected, across its entire lifecycle rather than just at launch.

The core rule, in Article 15 (1), is that high risk AI systems must be designed and developed to achieve an appropriate level of accuracy, robustness and cybersecurity, and to perform consistently in those respects throughout their lifecycle. The word appropriate matters: the Act does not set a single numeric bar, but expects the level to match the system’s purpose and risk.

What makes Article 15 stand out for security teams is that it treats cybersecurity not as an optional add on but as a defining property of a compliant high risk AI system. If a system can be manipulated by an attacker, it is not just insecure, it is potentially non compliant. That is why understanding this article matters to anyone building, deploying or securing AI in the EU.

The x4 core requirements

Article 15 rests on four intertwined properties, accuracy, robustness and cybersecurity, each with its own meaning. The feature list below breaks down what each one requires in practice.

1
Accuracy, declared and consistent
Systems must reach an appropriate level of accuracy and keep it across their lifecycle. Under Article 15 (3), the accuracy levels and the relevant metrics must be declared in the instructions for use, so deployers know how the system is expected to perform and can spot when it drifts.
2
Robustness against faults and drift
Under Article 15 (4), systems must be as resilient as possible to errors, faults and inconsistencies, which may be achieved through technical redundancy such as backups and fail-safe plans. Systems that keep learning after deployment must also control feedback loops so biased outputs do not corrupt future behaviour.
3
Cybersecurity against manipulation
Under Article 15 (5), systems must resist attempts by unauthorised third parties to alter their use, outputs or performance by exploiting vulnerabilities. The technical solutions must be appropriate to the circumstances and risks, and must address AI specific attacks, not just conventional IT security.
4
Consistency across the Lifecycle
All four properties must hold consistently throughout the system’s lifecycle, not just at the moment it is placed on the market. This makes ongoing monitoring and maintenance essential, since a system that was accurate and secure at launch can degrade or become vulnerable over time.

AI specific threats it targets

Article 15 (5) is explicit that the cybersecurity of AI is not the same as ordinary IT security. It calls for measures that address threats unique to how AI systems learn and operate. The table summarizes the main AI specific attacks the article has in mind.

Threat What it means?
Data poisoning Manipulating training data to corrupt how the model learns
Model poisoning Tampering with the model itself to change its behaviour
Adversarial examples Crafted inputs, also called evasion, that fool the system
Confidentiality attacks Extracting the model or its underlying training data

Why this matters: traditional security controls do not fully cover these attacks, because they target the model and its data rather than the surrounding network alone. Article 15 expects providers to combine AI specific defences with strong conventional security, and to keep detecting and responding to threats across the system’s whole life, not just secure it once.

Which systems it applies to?

Article 15 does not apply to all AI. It is part of the high risk regime, so knowing whether a system is high risk is the first step in knowing whether the article applies.

1
Standalone Annex III systems
High risk systems listed in Annex III, such as AI for recruitment, credit scoring, education, law enforcement and border control, must meet Article 15. After the Digital Omnibus, these obligations apply from 2 December 2027.
2
Embedded Annex I systems
AI acting as a safety component in products regulated under Annex I, such as medical devices, machinery and vehicles, is also high risk and must meet Article 15. After the Digital Omnibus, these obligations apply from 2 August 2028.
3
General purpose AI in high risk use
General purpose AI models are not caught by Article 15 in themselves, but when they are integrated into a high risk use case they fall within the high risk requirements. The classification follows the use, not just the underlying technology.
4
Not for minimal or limited risk
Minimal and limited risk systems do not have to meet Article 15, though good security practice still applies. The point of the risk based approach is to focus these strict technical duties where potential harm to safety and rights is greatest.

How it fits the wider framework?

Article 15 does not stand alone. It is the performance and security capstone of a set of high risk requirements that work together, and it is easiest to meet when the others are already in place.

1
Risk management, Article 9
A continuous risk management system underpins everything, identifying and mitigating risks across the lifecycle. The cybersecurity risks Article 15 targets should be identified and managed through this Article 9 process.
2
Data governance, Article 10
Good data governance reduces the risk of both bias and data poisoning. Clean, well managed training data is a precondition for the accuracy and robustness Article 15 demands, linking data quality directly to security.
3
Human oversight, Article 14
Human oversight is a safeguard for when technical measures fall short. If an attack or fault slips past Article 15 defences, people must be able to intervene, making oversight and robustness complementary lines of defence.
4
Monitoring after deployment
Because Article 15 requires consistency across the lifecycle, it connects to post market monitoring duties. Accuracy drift or a new vulnerability must be detected, reported and corrected, which makes continuous monitoring part of staying compliant.

The through line is continuity: accuracy, robustness and cybersecurity are not one time checks but properties that must hold for as long as the system is in use. That is why detection, monitoring and resilient infrastructure sit at the heart of meeting Article 15, tying AI governance to everyday security operations.

Article 15 and Teldat

Article 15 turns cybersecurity and resilience into legal requirements for high risk AI, and those are exactly the properties that network and security infrastructure underpins. Teldat is a European manufacturer whose portfolio supports that foundation.

1
Detection with be.Safe XDR
Article 15 (5) requires resilience against attempts to tamper with a system. Teldat be.Safe XDR provides monitoring and extended detection and response that help identify and contain such attempts across the network, supporting the continuous protection the article expects.
2
Redundancy with SD-WAN
Article 15 (4) points to technical redundancy as a way to achieve robustness. Teldat SD-WAN delivers self healing, redundant connectivity that keeps critical services available, aligning with the fail-safe thinking the article describes.
3
Continuous monitoring for consistency
Since Article 15 demands consistency across the lifecycle, the monitoring and visibility Teldat builds into its portfolio support the ongoing detection of drift or intrusion that keeping a high risk system compliant requires.
4
European jurisdiction and sovereignty
The AI Act is part of the EU’s push for trustworthy, sovereign technology. As a European manufacturer under European jurisdiction, Teldat fits that context, giving organizations infrastructure aligned with the European regulatory direction.

Infrastructure behind compliant AI: Article 15 makes resilience and cybersecurity a legal duty, and secure, well monitored infrastructure is part of delivering it. Teldat combines be.Safe XDR detection and SD-WAN redundancy under European jurisdiction to support that foundation. Teldat does not certify AI Act compliance, and responsibility for meeting Article 15 rests with the provider of the AI system, but the infrastructure beneath a high risk system is part of what keeps it accurate, robust and secure.

Frequently asked questions about Article 15

❯ What does Article 15 of the EU AI Act require?

Article 15 of the EU AI Act sets the requirements for accuracy, robustness and cybersecurity of high risk AI systems. It requires that such systems be designed and developed to achieve an appropriate level of accuracy, robustness and cybersecurity, and to perform consistently in those respects throughout their lifecycle. It also requires that accuracy levels and metrics be declared in the instructions for use, that systems be resilient against errors, faults, inconsistencies and problematic feedback loops, and that they resist attempts by unauthorised third parties to alter their use, outputs or performance by exploiting vulnerabilities. In short, it is the article that ties AI reliability directly to cybersecurity.

❯ Which AI systems does Article 15 apply to?

Article 15 applies to high risk AI systems, the category the AI Act subjects to its strictest obligations. These include standalone systems listed in Annex III, such as AI used in recruitment, credit scoring, education, law enforcement and border control, and AI embedded as a safety component in products regulated under Annex I, such as medical devices, machinery and vehicles. It does not apply to minimal or limited risk systems. General purpose AI models are only caught by Article 15 when they are deployed within a high risk use. After the Digital Omnibus, the high risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.

❯ What cybersecurity threats does Article 15 address?

Article 15(5) requires high risk AI systems to be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities, and it specifically points to AI specific threats. These include data poisoning, where training data is manipulated; model poisoning, where the model itself is tampered with; adversarial examples, also called evasion attacks, where inputs are crafted to fool the system; and confidentiality attacks that try to extract the model or its data. The article says the technical solutions must be appropriate to the circumstances and the risks, so the depth of protection should scale with how sensitive and exposed the system is.

❯ How can robustness be achieved under Article 15?

Article 15(4) says robustness may be achieved through technical redundancy solutions, which can include backup or fail-safe plans, so that a system can keep operating safely despite errors, faults or inconsistencies. It also requires that systems which continue to learn after being placed on the market are developed to reduce the risk of biased outputs feeding back into future operations, known as feedback loops, and that any such loops are addressed with mitigation measures. Robustness in Article 15 is therefore both about resisting failure and about not degrading or drifting in harmful ways over time.

❯ How does Teldat relate to Article 15 cybersecurity requirements?

Article 15 makes cybersecurity and resilience a legal requirement for high risk AI, and those are exactly the properties that network and security infrastructure underpins. Teldat be.Safe XDR provides monitoring and extended detection and response that help identify and contain attempts to tamper with systems, while Teldat SD-WAN delivers the resilient, redundant connectivity that supports the kind of technical redundancy Article 15 describes. As a European manufacturer operating under European jurisdiction, Teldat fits the European sovereignty context of the AI Act. Teldat does not certify AI Act compliance, and responsibility for meeting Article 15 rests with the provider of the AI system, but resilient, well monitored infrastructure is part of the foundation those requirements rely on.

Support Article 15 resilience with Teldat

Article 15 makes accuracy, robustness and cybersecurity legal duties for high risk AI. Teldat combines be.Safe XDR detection and SD-WAN redundancy under European jurisdiction to support the resilient, well monitored foundation those requirements rely on.