AI_ACTArt. 15voice-validated
AI_ACT Art15: Art. 15
AI_ACT
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in those respects throughout their lifecycle. High-risk AI systems must be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities. Technical solutions must address AI-specific vulnerabilities including data poisoning, model poisoning, adversarial examples, model evasion, and confidentiality attacks.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1190 | 1. Exploiting public-facing applications directly enables unauthorized third parties to alter AI system outputs or performance. Art. 15 mandates resilience against such exploitation of system vulnerabilities. | 90% |
| T1566 | 1. Phishing attacks provide initial access to systems managing AI, facilitating data or model poisoning. Art. 15 requires resilience against unauthorized alteration by third parties. | 80% |
| T1078 | 1. Compromised valid accounts allow unauthorized alteration of AI system configurations, data, or models. Art. 15 demands resilience against such unauthorized actions. | 90% |
| T1547 | 1. Establishing persistence on AI-hosting systems enables continuous malicious data injection or model modification. Art. 15 requires consistent performance throughout the AI system's lifecycle. | 70% |
| T1068 | 1. Exploiting vulnerabilities for privilege escalation grants elevated access to critical AI components or data. Art. 15 explicitly addresses exploiting system vulnerabilities to alter AI. | 90% |
| T1027 | 1. Obfuscating malicious inputs or model alterations evades detection, undermining AI system robustness and cybersecurity. Art. 15 mandates both robustness and cybersecurity. | 80% |
| T1070 | 1. Removing indicators of compromise after an attack on an AI system hinders incident response. Art. 15 requires robust cybersecurity measures for AI systems. | 70% |
| T1003 | 1. OS credential dumping provides access to AI system hosts, enabling further data or model manipulation. Art. 15 requires resilience against unauthorized third parties. | 80% |
| T1087 | 1. Account discovery helps attackers map access to AI development or deployment environments. Art. 15 demands resilience against unauthorized alteration. | 70% |
| T1083 | 1. File and directory discovery identifies sensitive AI model files or training data for modification. Art. 15 addresses exploiting system vulnerabilities to alter AI. | 80% |
| T1005 | 1. Collecting data from local systems can facilitate crafting adversarial examples or executing confidentiality attacks. Art. 15 explicitly lists confidentiality attacks as an AI-specific vulnerability. | 90% |
| T1074 | 1. Staging data is crucial for 'data poisoning' and crafting 'adversarial examples'. Art. 15 specifically identifies these as AI-specific vulnerabilities requiring technical solutions. | 90% |
| T1071 | 1. Using application layer protocols for command and control can inject adversarial inputs or exfiltrate model information. Art. 15 requires robust cybersecurity for AI systems. | 80% |
| T1041 | 1. Exfiltration over C2 channels allows theft of proprietary AI models or sensitive data. Art. 15 mandates protection against 'confidentiality attacks'. | 90% |
| T1485 | 1. Data destruction or corruption of training data directly degrades AI system accuracy and robustness. Art. 15 requires AI systems to achieve and maintain appropriate levels of accuracy and robustness. | 90% |
Defending mitigations · 7
| Mitigation | What it does | Confidence |
|---|---|---|
| M1035 | 1. Limiting access to resources directly prevents unauthorized third parties from altering AI systems, data, or performance. Art. 15 mandates resilience against such unauthorized actions. | 100% |
| M1038 | 1. Implementing side-channel defenses directly addresses 'confidentiality attacks' mentioned in Art. 15. This protects against information leakage from AI systems. | 90% |
| M1040 | 1. Network segmentation enhances cybersecurity and resilience by isolating high-risk AI systems. This limits the impact of breaches, as required by Art. 15. | 80% |
| M1047 | 1. Auditing enables detection of unauthorized alterations, data poisoning, and model evasion attempts. This ensures consistent performance and robustness, as mandated by Art. 15. | 100% |
| M1049 | 1. Patch management addresses 'exploiting system vulnerabilities' by ensuring underlying infrastructure and AI frameworks are up-to-date. Art. 15 requires this resilience. | 90% |
| M1050 | 1. Privilege auditing ensures only authorized entities interact with high-risk AI systems. This prevents unauthorized alterations, as per Art. 15's resilience requirement. | 90% |
| M1051 | 1. Secure software configuration prevents exploitation of vulnerabilities and maintains AI system accuracy, robustness, and cybersecurity. Art. 15 explicitly requires these attributes throughout the lifecycle. | 100% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-20 | 1. Improper input validation directly enables 'data poisoning' and 'adversarial examples'. Art. 15 requires technical solutions for these AI-specific vulnerabilities. | 100% |
| CWE-327 | 1. Use of broken cryptographic algorithms contributes to 'confidentiality attacks'. Art. 15 mandates cybersecurity for AI systems, including protection against such attacks. | 90% |
| CWE-287 | 1. Improper authentication allows 'unauthorised third parties to alter' AI systems. Art. 15 demands resilience against such unauthorized actions. | 100% |
| CWE-269 | 1. Improper privilege management enables attackers to gain elevated access within AI systems. This facilitates 'model poisoning' and other unauthorized alterations, as addressed by Art. 15. | 90% |
| CWE-798 | 1. Hard-coded credentials provide an easy target for 'unauthorised third parties' to access AI systems. This undermines the cybersecurity and resilience required by Art. 15. | 80% |
| CWE-502 | 1. Deserialization of untrusted data can lead to 'model poisoning' or code execution. This directly impacts AI system robustness and consistency, as per Art. 15. | 90% |
| CWE-732 | 1. Incorrect permission assignment allows unauthorized modification of AI models or data. This directly enables alterations by 'unauthorised third parties', as prohibited by Art. 15. | 100% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0184 compute · voice-rubric self-validated