Skip to main content
Category: Adversarial Security

Cybersecurity (Article 15)

Simply put

Cybersecurity, in a general sense, refers to the practices and measures used to protect systems and information against threats, and is commonly framed around preserving the confidentiality, integrity, and availability of data. The reference to 'Article 15' suggests a specific provision within a broader regulatory instrument, but the evidence provided does not contain the text or content of any such article. As a result, the specific requirements attributed to 'Article 15' cannot be described from the available evidence.

Formal definition

As commonly defined, cybersecurity is a legal and operational framework intended to promote the confidentiality, integrity, and availability of public and private information systems and data (Kosseff). Related activities include implementing preventative measures and managing cyber risks (CISA), as well as guarding against procedures that could enable or facilitate the defeat of a security control (Cybersecurity Information Sharing Act of 2015). Important limitation: the evidence packet does not include the text, jurisdiction, or issuing body associated with a specific 'Article 15,' so no authoritative statement can be made here about the scope, binding status, or precise obligations of that provision. Where 'Article 15' refers to a cybersecurity clause within a specific AI or data-protection instrument, its exact requirements should be verified against the primary regulatory source rather than inferred from the general concept of cybersecurity.

Why it matters

Cybersecurity is a foundational concern for any organization deploying AI systems, because the confidentiality, integrity, and availability of data and systems directly affect whether an AI system behaves as intended and whether the information it processes remains protected. Compromised training data, tampered model artifacts, or manipulated inputs can undermine both the reliability of a system and the trust placed in it, which is why cybersecurity is commonly framed as a legal and operational framework rather than a purely technical exercise (Kosseff).

Who it's relevant to

Compliance and legal professionals
Those responsible for mapping regulatory obligations to organizational controls will need to identify the specific instrument and jurisdiction in which any 'Article 15' cybersecurity provision sits, since the available evidence does not establish its scope or binding status. Verification against the primary regulatory source is necessary before treating any obligation as settled.
Model risk managers and information security teams
Practitioners managing risks arising from AI and model use rely on cybersecurity measures to help preserve the confidentiality, integrity, and availability of data and systems. These measures reduce and manage risk but do not eliminate it, and they should be coordinated with broader risk identification and monitoring activities.
Auditors and second-line oversight functions
Those assessing whether cybersecurity controls are designed and operating effectively should distinguish general cybersecurity practices—such as the preventative measures and cyber risk management described by CISA—from any specific provision. Given the evidence limitation, audit conclusions about 'Article 15' compliance should be grounded in the actual text of the governing instrument.

Inside Cybersecurity (Article 15)

Accuracy, robustness, and cybersecurity linkage
As commonly discussed, Article 15 of the EU AI Act addresses accuracy, robustness, and cybersecurity together for high-risk AI systems, treating cybersecurity as one of several technical requirements rather than a standalone obligation. The provision is framed as a legal requirement under EU law for systems falling within its scope, not as voluntary guidance.
Resilience against manipulation and exploitation
The cybersecurity dimension typically concerns the system's ability to resist attempts by unauthorized parties to alter its use, behavior, or performance by exploiting vulnerabilities. This is often described in terms of resilience appropriate to the risks and circumstances of the specific high-risk system.
AI-specific threat considerations
Discussions of this provision commonly reference threats particular to AI systems, such as attacks on training data or model inputs, alongside more conventional information-security concerns. The precise categories emphasized may vary, and the exact statutory wording should be consulted directly rather than paraphrased as definitive.
Proportionality to risk
Cybersecurity measures under this framing are generally expected to be appropriate to the level of risk and the intended purpose of the system, rather than a fixed, uniform standard applied identically to all systems.

Common questions

Answers to the questions practitioners most commonly ask about Cybersecurity (Article 15).

Does Article 15 apply to all AI systems placed on the market in the EU?
No. Article 15 of the EU AI Act sets accuracy, robustness, and cybersecurity requirements specifically for high-risk AI systems as defined under the Act. It should not be read as a blanket obligation applying to every AI system. Whether a given system falls in scope depends on its classification under the Act's risk categories, and other provisions govern systems outside the high-risk category. Confirm the classification of your specific system before assuming Article 15 obligations attach.
Does complying with Article 15's cybersecurity requirement eliminate the security risk to a high-risk AI system?
No. As commonly understood, the cybersecurity measures contemplated under Article 15 are intended to reduce and manage risk to a level appropriate to the system, not to eliminate it. The provision addresses resilience against attempts to alter use, behavior, or performance, and against exploitation of AI-specific vulnerabilities, but no control set removes residual risk entirely. Treat compliance as risk mitigation supported by ongoing monitoring rather than a one-time guarantee of security.
How does the Article 15 cybersecurity obligation relate to an organization's broader information security program?
Article 15's cybersecurity expectations concern the AI system itself and, in particular, resilience against AI-specific threats. In many organizations these obligations are operationalized through the existing enterprise information security program rather than a wholly separate function. Consider mapping the AI-specific measures to existing security controls, identifying gaps that arise from AI-particular vulnerabilities, and clarifying accountability so that AI governance and information security responsibilities are coordinated without being conflated. The precise integration approach is organization-specific and not prescribed in a single settled form.
What kinds of AI-specific vulnerabilities is the cybersecurity requirement typically expected to address?
The provision is commonly associated with vulnerabilities that arise from the nature of AI systems, such as attempts to manipulate a system's inputs, training data, or behavior. Depending on the system, teams may consider threats to the integrity of data and models and the resilience of the system against attempts to alter its intended use or performance. Because the technical threat landscape evolves and the Act does not enumerate an exhaustive fixed list, treat any specific threat catalog you adopt as informed by current practice rather than as a closed statutory list. Consult authoritative and current guidance for the applicable technical detail.
Who within an organization is typically responsible for meeting Article 15 cybersecurity obligations?
Responsibility often spans several functions rather than sitting with a single role. AI development and model teams, information security, and governance or compliance functions each commonly contribute, and organizations frequently align these responsibilities across their lines of defense. The Act places obligations on defined roles such as providers and, in certain respects, deployers, so the allocation of responsibility should track the organization's role in relation to the system. The exact internal assignment is a governance design choice and is not dictated by a single required structure.
How can cybersecurity resilience for a high-risk AI system be evidenced and maintained over time?
Because cybersecurity resilience is not a static property, organizations typically treat it as something to be demonstrated and sustained through ongoing measures rather than a single point-in-time check. Common approaches include documentation of the measures adopted, monitoring for emerging threats and for changes in system behavior, and processes to reassess and update controls as the system and threat environment change. The specific evidence expected can vary with the system and with how obligations are interpreted in practice, so align documentation with the applicable regulatory expectations and current guidance rather than assuming one fixed evidentiary standard.

Common misconceptions

Article 15 is a general cybersecurity law that governs all AI systems and organizations using AI.
As commonly understood, Article 15 sits within the EU AI Act and is scoped to high-risk AI systems within that instrument. It does not purport to replace or universally cover all cybersecurity obligations, and it is a requirement of EU law rather than a globally applicable or interchangeable standard. Practitioners should confirm the exact scope and applicable system categories against the current legal text.
Meeting the Article 15 cybersecurity requirement eliminates the risk of attacks or compromise.
The provision is best described as requiring measures that reduce and manage cybersecurity risk to a level appropriate to the system, not as a guarantee against all attacks. No control set eliminates risk entirely, and residual risk typically remains even where requirements are satisfied.
Article 15 cybersecurity and AI governance are the same thing.
Cybersecurity under Article 15 is a technical requirement for particular systems. AI governance refers more broadly to the organizational structures, policies, accountability, and oversight surrounding AI use. They overlap—governance may drive how cybersecurity controls are assigned and monitored—but they are distinct concepts and should not be collapsed.

Best practices

Consult the current official text of the EU AI Act directly for the exact wording, scope, and any implementing or referenced technical standards, rather than relying on paraphrased summaries of the cybersecurity requirement.
Confirm whether the specific AI system falls within the high-risk category addressed by the provision before designing controls, since obligations are scoped rather than universal.
Calibrate cybersecurity measures to the assessed risk and intended purpose of the system, documenting the rationale for the proportionality of the chosen controls.
Address AI-specific threat vectors—such as those targeting training data or model inputs—in addition to conventional information-security controls, and document how each is considered.
Treat cybersecurity controls as risk-reducing measures and track residual risk explicitly, avoiding any representation that the requirement guarantees protection against compromise.
Coordinate cybersecurity implementation with the organization's broader AI governance structures so that accountability and monitoring are assigned, while keeping the technical requirement and governance oversight distinct in documentation.