Applies 2 Dec 2027

EU AI Act Article 15: Accuracy, robustness, and cybersecurity

Article 15 of the EU AI Act requires high-risk AI systems to achieve appropriate accuracy, robustness, and cybersecurity, and to perform consistently in those respects throughout the lifecycle. Accuracy metrics must be declared in the instructions for use; robustness must extend to errors, faults, and inconsistencies including adversarial inputs.

Who
Providers of high-risk AI systems; accuracy metrics must be declared in the instructions for use.
From when
2 Dec 2027 (Annex III), 2 Aug 2028 (Annex I)
Art. 113(c)(i), as amended
Maximum fine
€15M or 3%
Art. 99(4), point (a), through the provider obligations in Art. 16

Quoted from EUR-Lex

What Article 15 says

15(1)

1. High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.

15(3)

3. The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.

15(4), first subparagraph

4. High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard.

15(4), second subparagraph

The robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans.

Selected paragraphs, quoted exactly. Read the whole article in Regulation (EU) 2024/1689 on EUR-Lex. Checked 4 Oct 2026.

Regulation (EU) 2026/1744 · in force 27 Jul 2026

What changed

Change in lawArticle 113, third paragraph, point (c)
It shall apply from 2 August 2026.
Removed: (c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.Added: (c) Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from:Added: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; andAdded: (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;

The context line is the second paragraph of Article 113, which set the date for Annex III systems before the change. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.

Source: Regulation (EU) 2026/1744, Article 1, point (40), verified 4 Oct 2026

In plain words

What you must produce

Declared accuracy levels and metrics, and evidence of robustness and cybersecurity.

  • 15(3)The levels of accuracy and the accuracy metrics, declared in the instructions for use
  • 15(4)Technical and organisational measures for resilience to errors, faults or inconsistencies
  • 15(5)Measures against attempts by unauthorised third parties to alter use, outputs or performance

A summary to help you plan. The quoted text above is the law.

Coverage: Covered

RAG Benchmarking

RAG Benchmarking is a framework-agnostic evaluation harness for RAG and agentic AI systems. It covers Article 15's accuracy and robustness requirements through reproducible benchmarks (faithfulness, answer relevancy, retrieval precision, four agentic metrics) with versioned eval sets and lifecycle drift monitoring. Article 15 also requires cybersecurity: prompt injection resistance, jailbreak defence, model integrity. Pair it with a runtime AI security control to cover the cybersecurity leg as well.

Install

bashpip install rag-benchmarking

Writes: Retrieval accuracy report (JSON / Markdown)

From the fact register

Questions about Article 15

When does Article 15 apply?
It applies from 2 Dec 2027 for high-risk systems listed in Annex III (Art. 113(c)(i), as amended), and from 2 Aug 2028 for high-risk systems covered by Annex I (Art. 113(c)(ii), as amended). Before Regulation (EU) 2026/1744, the dates were 2 Aug 2026 and 2 Aug 2027.
What is the maximum fine for breaching Article 15?
Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher (Art. 99(4), point (a), through the provider obligations in Art. 16). For SMEs, including start-ups, the fine is capped at whichever of the two is lower (Art. 99(6)). Since 27 Jul 2026, the same lower cap applies to small mid-cap enterprises (Art. 99(6a)).
Did the Digital Omnibus change Article 15?
Its text is unchanged. Regulation (EU) 2026/1744 moved the date it applies from, through Article 113. The section "What changed" quotes the old and new text.
Is there an AiExponent tool for Article 15?
Yes. RAG Benchmarking is released and open source. It writes a Retrieval accuracy report (JSON / Markdown).

Content verified 4 Oct 2026 · Not legal advice.