Skip to content
EU AI Regulation DecodedKnowledge Platform

Evidence AI-specific cybersecurity

Protect the system against AI-specific attacks (data poisoning, model poisoning, adversarial examples, confidentiality attacks) throughout its lifecycle; produce dated cybersecurity evidence including an AI threat model.

Last reviewed 2026-07-30Version 1Primary sources 1Status Verified against primary source
Applies to
Provider
Scope
High-risk (Annex III use case), High-risk (Annex I regulated product)
Applies from
2027-12-02 — Stand-alone high-risk (Annex III) obligations apply
Derives from
Article 15
Primary source
Art. 15 AIA

Evidence an auditor expects

Audit red flags

Fails an audit

FAQ

What evidence do I need for Article 15?
AI cybersecurity threat model & evidence, Annex IV technical file. Each should be contemporaneous, versioned, and traceable to the system version.

When does “Evidence AI-specific cybersecurity” apply?
From 2027-12-02 — Stand-alone high-risk (Annex III) obligations apply. It applies to: Provider.

What fails an audit here?
Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.

Legal source

Art. 15 AIA

Explained in the newsletter

Stay audit-ready as the Act changes

EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.

Subscribe — free, weekly

Not legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.