# EU AI Act Article 15: Accuracy, robustness, and cybersecurity

Source: https://aiexponent.com/eu-ai-act/article-15 · Content verified 2026-10-04

Article 15 of the EU AI Act requires high-risk AI systems to achieve appropriate accuracy, robustness, and cybersecurity, and to perform consistently in those respects throughout the lifecycle. Accuracy metrics must be declared in the instructions for use; robustness must extend to errors, faults, and inconsistencies including adversarial inputs.

- Status: Applies 2 Dec 2027
- Who: Providers of high-risk AI systems; accuracy metrics must be declared in the instructions for use.
- From when: 2 Dec 2027 (Annex III), 2 Aug 2028 (Annex I) (Art. 113(c)(i), as amended)
- Maximum fine: €15M or 3% (Art. 99(4), point (a), through the provider obligations in Art. 16)

## What Article 15 says

> **15(1)** 1. High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.

> **15(3)** 3. The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.

> **15(4), first subparagraph** 4. High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard.

> **15(4), second subparagraph** The robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans.

Selected paragraphs, quoted exactly from Regulation (EU) 2024/1689: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (checked 4 Oct 2026).

## What changed

Regulation (EU) 2026/1744, in force since 27 Jul 2026. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.

### Article 113, third paragraph, point (c)

```diff
  It shall apply from 2 August 2026.
- (c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.
+ (c) Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from:
+ (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and
+ (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;
```

The context line is the second paragraph of Article 113, which set the date for Annex III systems before the change.

Source: Regulation (EU) 2026/1744, Article 1, point (40), https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 4 Oct 2026).

## What you must produce

Declared accuracy levels and metrics, and evidence of robustness and cybersecurity.

- 15(3): The levels of accuracy and the accuracy metrics, declared in the instructions for use
- 15(4): Technical and organisational measures for resilience to errors, faults or inconsistencies
- 15(5): Measures against attempts by unauthorised third parties to alter use, outputs or performance

A summary to help you plan. The quoted text above is the law.

## The tool: RAG Benchmarking

Coverage: Covered.

RAG Benchmarking is a framework-agnostic evaluation harness for RAG and agentic AI systems. It covers Article 15's accuracy and robustness requirements through reproducible benchmarks (faithfulness, answer relevancy, retrieval precision, four agentic metrics) with versioned eval sets and lifecycle drift monitoring. Article 15 also requires cybersecurity: prompt injection resistance, jailbreak defence, model integrity. Pair it with a runtime AI security control to cover the cybersecurity leg as well.

```bash
pip install rag-benchmarking
```

Writes: Retrieval accuracy report (JSON / Markdown).

Tool docs and tool FAQ: https://aiexponent.com/docs/rag-benchmarking.md

For coding agents:

Install rag-benchmarking from PyPI into a virtual environment (Python 3.11 or newer). Retrieval metrics need no API key: import `EvalSample` and `RunConfig` from `rag_benchmarking.harness.schemas` and `EvaluationRunner` from `rag_benchmarking.harness.runner`, build samples with `retrieved_doc_ids` and `relevant_doc_ids`, then call `EvaluationRunner(RunConfig(metric_group="retrieval")).evaluate(samples)`. The LLM-judge metrics need GEMINI_API_KEY; on a fresh install of 1.0.2 they fail to import (github.com/aiexponent/rag-benchmarking/issues/35). Docs: https://aiexponent.com/docs/rag-benchmarking.md

## Questions about Article 15

### When does Article 15 apply?

It applies from 2 Dec 2027 for high-risk systems listed in Annex III (Art. 113(c)(i), as amended), and from 2 Aug 2028 for high-risk systems covered by Annex I (Art. 113(c)(ii), as amended). Before Regulation (EU) 2026/1744, the dates were 2 Aug 2026 and 2 Aug 2027.

### What is the maximum fine for breaching Article 15?

Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher (Art. 99(4), point (a), through the provider obligations in Art. 16). For SMEs, including start-ups, the fine is capped at whichever of the two is lower (Art. 99(6)). Since 27 Jul 2026, the same lower cap applies to small mid-cap enterprises (Art. 99(6a)).

### Did the Digital Omnibus change Article 15?

Its text is unchanged. Regulation (EU) 2026/1744 moved the date it applies from, through Article 113. The section "What changed" quotes the old and new text.

### Is there an AiExponent tool for Article 15?

Yes. RAG Benchmarking is released and open source. It writes a Retrieval accuracy report (JSON / Markdown).

---

Not legal advice. Not a notified body. The tools produce evidence, not conformity assessment.
All docs as Markdown: https://aiexponent.com/llms.txt · Guide for coding agents: https://aiexponent.com/agents.md
