Control
High-risk AI without accuracy, robustness, and AI-specific security measures
A high-risk AI system must achieve appropriate accuracy, robustness, and cybersecurity across its lifecycle, including resilience to errors/faults, feedback-loop control for continuously-learning systems, and defences against AI-specific attacks (data/model poisoning, adversarial examples, model evasion, confidentiality attacks).
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
enacted, not yet applying in European Union (EU); next date 2027-12-02.
The guard to add
Declare accuracy metrics per model version, add a fail-safe fallback, gate retraining on verified labels, and defend against poisoning, adversarial input and tampering.
Four pieces for the high-risk system. An evaluation report per model version with the declared accuracy metrics and thresholds, and a CI step that blocks promotion when they regress. A fallback in the serving path (rules-based decision or human review) when the model errors, times out or returns low confidence. For systems that keep learning, a retraining pipeline that accepts only human-verified labels, never the model's own predictions or LLM outputs, and promotes a new model only after holdout, drift and bias checks; plus AI-specific security controls such as hash-verified training data and model artifacts, safe serialization formats, adversarial and out-of-distribution input checks, and rate limits against extraction.
Where it goes: 11 CI/CD pipeline, 1 application source code, 12 repository artifacts, 13 tests and evals.
What reviewers look for: an eval report with declared metrics tied to the deployed model version and a CI gate on it; a fallback branch in the inference handler; no partial_fit on predictions or training_examples.append of model outputs, with retraining limited to label_source == 'human' and gated by holdout, drift and bias checks; integrity checks (checksums or signatures) before loading training data and weights.
Example (scikit-learn online learning), before:
y_pred = model.predict(X_batch)
model.partial_fit(X_batch, y_pred) # learns from its own outputsAfter:
rows = feedback.fetch(batch_ids, label_source='human') # verified labels only
if rows:
candidate = copy.deepcopy(model)
candidate.partial_fit(rows.X, rows.y)
if passes_holdout_drift_bias(candidate, holdout): # gate before promotion
model = candidateEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : High-risk AI systems must be accurate, robust, and secure against AI-specific attacks (EU AI Act Art. 15) (European Union (EU); first application)
- : High-risk AI systems must be accurate, robust, and secure against AI-specific attacks (EU AI Act Art. 15) (European Union (EU); later phase)
Every rule this guard addresses
Binding law — not yet in force or stayed (1)
- European Union (EU)
- High-risk AI systems must be accurate, robust, and secure against AI-specific attacks (EU AI Act Art. 15) Article 15 · applies from 2027-12-02