ao link
Menu
Business Reporter
Business Reporter

Decoding Article 15 of the EU AI Act: defining and maintaining agentic resilience   

Aner Gelman at Salt Security explores what ‘cyber-resilience’ means in terms of the EU AI Act and how organisations can prepare for Article 15 compliance  

Linked InXFacebook

On 2 August 2026, a significant new phase of the EU AI Act’s implementation began, but whilst some provisions did take effect - including important transparency obligations - the detailed requirements governing high-risk AI systems did not come into effect as originally planned.   

 

Instead, the application of the high-risk requirements has been staggered. They will apply from 2nd December 2027 for high-risk AI systems under Article 6(2) and Annex III, such as certain systems used in recruitment, education, critical infrastructure, law enforcement, migration and access to essential services. High-risk AI systems under Article 6(1) and Annex I, which are used as safety components of, or are themselves, regulated products, will follow on 2nd August 2028.  

 

Although the deadline has moved, the eventual scope of the requirements remains substantial. Whilst the total number of organisations that will fall into the scope of the EU AI Act is relatively undefined, it is thought that hundreds of thousands of organisations across Europe will be affected. In fact, the scope could fall beyond Europe, as any organisation that trades within the EU will need to comply. Luckily, the delay gives organisations more time to contend with compliance with the regulations.  

 

The delay could be seen as a lifeline for organisations struggling with compliance, as non-compliance can be costly: €15 million or 3% of an organisation’s total worldwide annual turnover (whichever is higher). But it’s not just about fines, as the AI Office also has broad investigative powers, including the ability to demand technical documentation and evidence, test AI models, require corrective action, and, where necessary, access models to assess compliance.   

Despite the extended deadline, organisations shouldn’t wait to comply. The extension should not be treated as a reason to pause, but an opportunity to get ahead before the regulations kick in, especially as preparation for compliance can have a lengthy lead time. This is particularly important for Article 15, focusing on cyber-resilience, an area where compliance was alarmingly lagging behind the August 2nd deadline.   

 

So, what does Article 15 require organisations to do? And how can security teams achieve and remain compliant before the extended deadline?  

 

 

Defining Article 15  

Like most of the requirements for high-risk systems, Article 15 has been delayed, rather than removed. Article 15 is all about cyber-security resilience; plainly, “accuracy, robustness and cyber-security”. Specifically, Article 15 says that high-risk AI systems must be:  

 

Accurate  

High-risk AI systems must perform at an appropriate level for their intended purpose, and providers must disclose the accuracy metrics in the system’s documentation.   

 

Robust  

The legislation says that high-risk AI systems should continue to operate reliably even when errors, unexpected situations or faults occur. This may include adding fail-safe mechanisms, redundancy and controls to prevent feedback loops in AI systems that continue learning after deployment.  

 

Cyber-secure  

High-risk AI systems must be designed to resist attacks that could alter their behaviour, outputs or performance, including specific AI threats.  

 

What’s more, the legislation states that organisations must maintain an appropriate level of accuracy, robustness and cyber-security “throughout their lifecycle.” Critically, this means that Article 15 cannot be viewed as a tick-box exercise; rather, resiliency must be built into systems, and risk must also be continuously evaluated and monitored.

 

Article 15 is also about protection against adversarial attacks, data poisoning, adversarial examples and model evasion at the API and MCP layer.   

 

 

Reframing AI security for enterprise  

It’s not always straightforward when managing AI platforms, tools and agents. Recent research reveals that CISOs face several challenges when deploying agent-based systems, including maintaining reliability for mission-critical automation (50%), monitoring machine-to-machine traffic (49%) and detecting malicious bots impersonating legitimate agents (48%). Additionally, most leaders don’t quite understand the sheer number of agents working within their organisations or the scale at which they can act on behalf of others.   

 

Even more worryingly, most leaders don’t fully understand what’s happening at the agentic action layer - the APIs that allow the AI agents to interact with enterprise systems. The real enterprise risk is not just in what an agent can say. It is in what an agent can do through MCP servers and APIs. These systems connect agents to data, workflows and enterprise services and are what leaders are referring to as the ‘Agentic Security Graph’.  

 

Preparing for Article 15, like most cyber-security disciplines, starts with visibility. Organisations should inventory where AI agents are deployed, map the systems, APIs and tools they can access and apply least-privilege principles so agents only receive the permissions they genuinely need.  

 

Continuous monitoring is equally important. Static security reviews conducted before deployment are unlikely to identify misuse, unexpected behaviours or compromised integrations once agents are operating in production. Runtime monitoring, audit trails and policy enforcement help organisations detect when agents exceed their intended scope and provide the evidence needed to demonstrate compliance.  

 

This is where the conversation is moving towards agentic security: securing not just the model, but the entire chain of decisions and actions an AI agent performs. ‘Agentic security’ is not the same as AI security. Agentic security encompasses all aspects of securing the autonomous ‘digital employee’: LLM security (traditionally thought of as AI security), MCP security and API security. You have to secure all three to be protected, especially as organisations transition away from using AI that talks to AI that takes action.  

 

Emerging approaches to agentic security focus on providing visibility across AI agents, their connected tools and the APIs they interact with, enabling organisations to identify risky behaviour before it becomes a security incident.   

 

 

A core component of AI governance  

To go beyond compliance and aim for resilience, organisations must treat agentic security as a core component of AI governance. As AI systems become more autonomous and connected, security needs to extend beyond the model itself to encompass the actions agents take, the APIs they access and the decisions they make. Embedding these controls from the outset (and throughout the entire product lifecycle) will help organisations reduce risk while giving them the visibility and assurance needed to support safe AI adoption.   

 

Article 15 requires accuracy, robustness and adequate cyber-security. By understanding agentic risk and acting on it accordingly, organisations can go beyond compliance and build real cyber-resilience.  

 


 

Aner Gelman is VP of Product at Salt Security

 

Main image courtesy of iStockPhoto.com and Rafmaster

Linked InXFacebook
Business Reporter

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Business Reporter

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@business-reporter.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543