TwinEthosRequest access

Control

High-risk AI without accuracy, robustness, and AI-specific security measures

A high-risk AI system must achieve appropriate accuracy, robustness, and cybersecurity across its lifecycle, including resilience to errors/faults, feedback-loop control for continuously-learning systems, and defences against AI-specific attacks (data/model poisoning, adversarial examples, model evasion, confidentiality attacks).

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Control id cond.high-risk-ai-no-robustness-security-measures

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in European Union (EU); next date 2027-12-02.

The guard to add

Declare accuracy metrics per model version, add a fail-safe fallback, gate retraining on verified labels, and defend against poisoning, adversarial input and tampering.

Four pieces for the high-risk system. An evaluation report per model version with the declared accuracy metrics and thresholds, and a CI step that blocks promotion when they regress. A fallback in the serving path (rules-based decision or human review) when the model errors, times out or returns low confidence. For systems that keep learning, a retraining pipeline that accepts only human-verified labels, never the model's own predictions or LLM outputs, and promotes a new model only after holdout, drift and bias checks; plus AI-specific security controls such as hash-verified training data and model artifacts, safe serialization formats, adversarial and out-of-distribution input checks, and rate limits against extraction.

Where it goes: 11 CI/CD pipeline, 1 application source code, 12 repository artifacts, 13 tests and evals.

What reviewers look for: an eval report with declared metrics tied to the deployed model version and a CI gate on it; a fallback branch in the inference handler; no partial_fit on predictions or training_examples.append of model outputs, with retraining limited to label_source == 'human' and gated by holdout, drift and bias checks; integrity checks (checksums or signatures) before loading training data and weights.

Example (scikit-learn online learning), before:

y_pred = model.predict(X_batch)
model.partial_fit(X_batch, y_pred)        # learns from its own outputs

After:

rows = feedback.fetch(batch_ids, label_source='human')    # verified labels only
if rows:
    candidate = copy.deepcopy(model)
    candidate.partial_fit(rows.X, rows.y)
    if passes_holdout_drift_bias(candidate, holdout):       # gate before promotion
        model = candidate

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — not yet in force or stayed (1)