AI_ACTArt. 15voice-validated

AI_ACT Art15: Art. 15

AI_ACT

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in those respects throughout their lifecycle. High-risk AI systems must be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities. Technical solutions must address AI-specific vulnerabilities including data poisoning, model poisoning, adversarial examples, model evasion, and confidentiality attacks.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T11901. Exploiting public-facing applications directly enables unauthorized third parties to alter AI system outputs or performance. Art. 15 mandates resilience against such exploitation of system vulnerabilities.
90%
T15661. Phishing attacks provide initial access to systems managing AI, facilitating data or model poisoning. Art. 15 requires resilience against unauthorized alteration by third parties.
80%
T10781. Compromised valid accounts allow unauthorized alteration of AI system configurations, data, or models. Art. 15 demands resilience against such unauthorized actions.
90%
T15471. Establishing persistence on AI-hosting systems enables continuous malicious data injection or model modification. Art. 15 requires consistent performance throughout the AI system's lifecycle.
70%
T10681. Exploiting vulnerabilities for privilege escalation grants elevated access to critical AI components or data. Art. 15 explicitly addresses exploiting system vulnerabilities to alter AI.
90%
T10271. Obfuscating malicious inputs or model alterations evades detection, undermining AI system robustness and cybersecurity. Art. 15 mandates both robustness and cybersecurity.
80%
T10701. Removing indicators of compromise after an attack on an AI system hinders incident response. Art. 15 requires robust cybersecurity measures for AI systems.
70%
T10031. OS credential dumping provides access to AI system hosts, enabling further data or model manipulation. Art. 15 requires resilience against unauthorized third parties.
80%
T10871. Account discovery helps attackers map access to AI development or deployment environments. Art. 15 demands resilience against unauthorized alteration.
70%
T10831. File and directory discovery identifies sensitive AI model files or training data for modification. Art. 15 addresses exploiting system vulnerabilities to alter AI.
80%
T10051. Collecting data from local systems can facilitate crafting adversarial examples or executing confidentiality attacks. Art. 15 explicitly lists confidentiality attacks as an AI-specific vulnerability.
90%
T10741. Staging data is crucial for 'data poisoning' and crafting 'adversarial examples'. Art. 15 specifically identifies these as AI-specific vulnerabilities requiring technical solutions.
90%
T10711. Using application layer protocols for command and control can inject adversarial inputs or exfiltrate model information. Art. 15 requires robust cybersecurity for AI systems.
80%
T10411. Exfiltration over C2 channels allows theft of proprietary AI models or sensitive data. Art. 15 mandates protection against 'confidentiality attacks'.
90%
T14851. Data destruction or corruption of training data directly degrades AI system accuracy and robustness. Art. 15 requires AI systems to achieve and maintain appropriate levels of accuracy and robustness.
90%

Defending mitigations · 7

MitigationWhat it doesConfidence
M10351. Limiting access to resources directly prevents unauthorized third parties from altering AI systems, data, or performance. Art. 15 mandates resilience against such unauthorized actions.
100%
M10381. Implementing side-channel defenses directly addresses 'confidentiality attacks' mentioned in Art. 15. This protects against information leakage from AI systems.
90%
M10401. Network segmentation enhances cybersecurity and resilience by isolating high-risk AI systems. This limits the impact of breaches, as required by Art. 15.
80%
M10471. Auditing enables detection of unauthorized alterations, data poisoning, and model evasion attempts. This ensures consistent performance and robustness, as mandated by Art. 15.
100%
M10491. Patch management addresses 'exploiting system vulnerabilities' by ensuring underlying infrastructure and AI frameworks are up-to-date. Art. 15 requires this resilience.
90%
M10501. Privilege auditing ensures only authorized entities interact with high-risk AI systems. This prevents unauthorized alterations, as per Art. 15's resilience requirement.
90%
M10511. Secure software configuration prevents exploitation of vulnerabilities and maintains AI system accuracy, robustness, and cybersecurity. Art. 15 explicitly requires these attributes throughout the lifecycle.
100%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-201. Improper input validation directly enables 'data poisoning' and 'adversarial examples'. Art. 15 requires technical solutions for these AI-specific vulnerabilities.
100%
CWE-3271. Use of broken cryptographic algorithms contributes to 'confidentiality attacks'. Art. 15 mandates cybersecurity for AI systems, including protection against such attacks.
90%
CWE-2871. Improper authentication allows 'unauthorised third parties to alter' AI systems. Art. 15 demands resilience against such unauthorized actions.
100%
CWE-2691. Improper privilege management enables attackers to gain elevated access within AI systems. This facilitates 'model poisoning' and other unauthorized alterations, as addressed by Art. 15.
90%
CWE-7981. Hard-coded credentials provide an easy target for 'unauthorised third parties' to access AI systems. This undermines the cybersecurity and resilience required by Art. 15.
80%
CWE-5021. Deserialization of untrusted data can lead to 'model poisoning' or code execution. This directly impacts AI system robustness and consistency, as per Art. 15.
90%
CWE-7321. Incorrect permission assignment allows unauthorized modification of AI models or data. This directly enables alterations by 'unauthorised third parties', as prohibited by Art. 15.
100%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0184 compute · voice-rubric self-validated