Evidence AI-specific cybersecurity
Protect the system against AI-specific attacks (data poisoning, model poisoning, adversarial examples, confidentiality attacks) throughout its lifecycle; produce dated cybersecurity evidence including an AI threat model.
- Applies to
- Provider
- Applies from
- 2027-12-02 — Stand-alone high-risk (Annex III) obligations apply
- Derives from
- Article 15
- Primary source
- Art. 15 AIA
Evidence an auditor expects
- AI cybersecurity threat model & evidence — Dated AI-specific threat model (data poisoning, model poisoning, adversarial examples, confidentiality attacks) with mitigations and validation.
- Annex IV technical file — The full technical documentation package; primary evidence at conformity assessment; must be a living, versioned document.
Audit red flags
Fails an audit
- Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
FAQ
What evidence do I need for Article 15?
AI cybersecurity threat model & evidence, Annex IV technical file. Each should be contemporaneous, versioned, and traceable to the system version.
When does “Evidence AI-specific cybersecurity” apply?
From 2027-12-02 — Stand-alone high-risk (Annex III) obligations apply. It applies to: Provider.
What fails an audit here?
Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
Legal source
Explained in the newsletter
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.