Regulation Tracker / EU AI Act / Chapter III · Section 2
Article 15
Accuracy, robustness and cybersecurity
Chapter III — Classification rules for high-risk AI systems, Section 2 — Compliance with the requirements. 5 distinct duties, powers or definitions are coded from this article, applying from 2027-12-02. 4 reach legal practice directly.
Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 165 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex. 5 of the duties below now apply later than Article 113 originally provided; each shows both dates.
official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub
The text
1. High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.
2. To address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies.
3. The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.
4. High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard.
5. High-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities.
What it requires, coded
SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.
Art. 15(1)RequirementHigh-risklegal practice
High-risk AI systems must be designed and developed to achieve appropriate accuracy, robustness and cybersecurity and perform consistently in those respects throughout their lifecycle.
"High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle."
- Who
- Provider
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — Legal-AI vendors must meet accuracy, robustness and cybersecurity expectations for high-risk systems used in legal or public-authority contexts.
- See
- Annex III point 8
Art. 15(2)Support measureHigh-risk
The Commission must encourage development of benchmarks and measurement methodologies for appropriate accuracy, robustness and other relevant performance metrics, in cooperation with stakeholders and organisations.
"To address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies."
- Who
- Commission
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Legal practice
- Reaches legal-AI vendors or public bodies — Benchmarks may influence how high-risk legal-AI performance is measured and explained.
- See
- Annex III point 8
Art. 15(3)TransparencyHigh-risklegal practice
The levels of accuracy and relevant accuracy metrics for high-risk AI systems must be declared in the accompanying instructions for use.
"The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use."
- Who
- Provider
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — Law firms, courts and legal departments need declared accuracy metrics before relying on high-risk legal-AI outputs.
- See
- Annex III point 8
Art. 15(4)RequirementHigh-risklegal practice
High-risk AI systems must be as resilient as possible against errors, faults or inconsistencies in the system or operating environment, and technical and organisational measures must be taken.
"High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard."
- Who
- Provider
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — High-risk legal-AI systems must be resilient to errors or environmental inconsistencies that could affect legal outcomes or rights.
- See
- Annex III point 8
Art. 15(5)RequirementHigh-risklegal practice
High-risk AI systems must be resilient against unauthorised third-party attempts to alter their use, outputs or performance by exploiting system vulnerabilities.
"High-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities."
- Who
- Provider
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — Cybersecurity is critical for legal-AI systems processing privileged, confidential or court-related information.
- See
- Annex III point 8
Cite
Regulation (EU) 2024/1689, Article 15 (Accuracy, robustness and cybersecurity), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_15 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-15, accessed 2026-09-08, CC BY 4.0.