HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Editorial explainer · official sourcesmedium

AI Act: securing AI becomes an obligation on 2 August

On 2 August 2026 a little-reported piece of the European AI Act kicks in: the obligations for high-risk AI systems listed in Annex III. Among them is Article 15, which places accuracy, robustness and cybersecurity on the same footing. It is not a statement of principle: it requires a high-risk AI system to withstand attempts to alter its use, outputs and performance. An explainer on what the rule actually says, with the dates that matter and without mistaking it for the attack of the day.

A deadline drawing near

The AI Act — Regulation (EU) 2024/1689 — did not enter into force all at once. It has a staggered calendar, and the next step is close: from 2 August 2026 the obligations apply for the high-risk AI systems listed in Annex III, those used in areas such as recruitment, credit, education and essential services. For high-risk systems covered by the harmonisation legislation in Annex I the date moves to 2 August 2027. It is a technical distinction, but it changes who must be ready and when.

  1. 1 August 2024
    Entry into force

    The regulation becomes Union law.

  2. 2 August 2026
    High-risk (Annex III)

    Obligations begin, Article 15 included.

  3. 2 August 2027
    High-risk (Annex I)

    Obligations for systems in already-regulated products.

What Article 15 requires

Article 15 brings together three words that rarely sit in the same sentence of law: accuracy, robustness and cybersecurity. The point is that a high-risk AI system must work reliably throughout its life cycle, and must withstand not only errors but also attacks. The rule explicitly requires the system to be resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting its vulnerabilities.

This is where AI security stops being a conference topic and becomes a requirement. The text and interpretive materials point to technical measures matched to the threats specific to models: defences against poisoning of training data and of the model, against adversarial examples built to fool predictions, against attempts to extract confidential information from the model. In practice: input validation, robust training, controls on data integrity. These are countermeasures, not slogans.

What it is not, to avoid confusion

Two clarifications help read the rule correctly. First: Article 15 concerns high-risk systems, not general-purpose AI models — so-called GPAI, such as large language models as such — which have their own regime in Articles 51 to 56. Confusing the two levels leads to wrong conclusions about who must do what. Second: the AI Act does not replace other cybersecurity rules. An organisation that also falls within the NIS2 perimeter, or that processes personal data under the GDPR, still has to comply with those; the AI Act adds a layer specific to AI, it does not zero out the others.

The honest uncertainty to state is that many implementation details — harmonised standards, guidelines, compliance practices — are still consolidating, and some will arrive after the date of application. But the pivot is already written and has a date: from 2 August, for a high-risk AI system, withstanding those who try to tamper with it is not an optional good practice. It is a legal obligation. The sources to verify all of this are the text on EUR-Lex and the technical framework ENISA is building around AI security.

More dossiers