NXT

Frameworks

EU AI Act: what Article 15 asks for, and when

High-risk AI systems must be resilient against third parties exploiting their vulnerabilities, with technical measures that address adversarial examples, confidentiality attacks, and poisoning. The Act became generally applicable on 2 August 2026. The high-risk rules now apply from 2 December 2027. Here is the text and what an assessment produces against it.

NXT AI research team · Updated October 7, 2026

01

The timeline, as amended

Dates are from the European Commission's AI Act page, updated 3 August 2026. Many summaries published before the amendment still show the high-risk rules starting in August 2026. They do not.

2 February 2025

Prohibited practices and AI literacy obligations apply.

2 August 2025

Governance rules and obligations for general-purpose AI models apply.

27 July 2026

The AI Omnibus amendment enters into force, extending the high-risk deadlines below.

2 August 2026

The Act becomes generally applicable, with exceptions. Transparency obligations apply.

2 December 2027

Obligations for stand-alone high-risk systems in Annex III apply, including credit scoring and life and health insurance pricing.

2 August 2028

Obligations for high-risk AI embedded in regulated products in Annex I apply.

02

The text, and what an assessment produces against it

Quotations are from Regulation (EU) 2024/1689. The right-hand column is what an NXT assessment of an AI agent delivers for each.

Article 15(1)

High-risk AI systems “shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity.”

An assessment report that documents the robustness and cybersecurity of the agent as deployed, with evidence rather than assertion.

Article 15(5)

Systems shall be “resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities.”

Adversarial testing of every channel an outsider can reach: prompts, documents, email, forms, and tool results, with a record of what altered the agent’s behavior.

Article 15(5), AI-specific vulnerabilities

Technical solutions shall address “data poisoning,” “model poisoning,” “adversarial examples or model evasion,” “confidentiality attacks,” and “model flaws.”

Findings classified against those named categories, so the register speaks the regulation’s language.

Article 9, risk management

A risk management system that runs across the lifecycle, with testing to identify the most appropriate risk management measures.

Re-test after remediation and quarterly re-tests, with an attestation each time, so the testing is a process rather than an event.

Article 15(4)

Systems shall be “as resilient as possible regarding errors, faults or inconsistencies.”

Multi-step workflow testing, where one bad interaction is followed through to see whether it cascades.

03

Who it reaches in finance and health

Annex III names the high-risk uses. For our clients the relevant lines are credit scoring and creditworthiness assessment of natural persons, with fraud detection excluded, and risk assessment and pricing in life and health insurance. An AI agent that produces or materially informs one of those decisions is in scope for Article 15 from December 2027.

Agents outside those lines are not exempt from everything. Transparency obligations already apply, the Act's general cybersecurity expectations inform how European buyers write their vendor requirements today, and a European customer's procurement review is usually the first place a US vendor meets the Act, well before any regulator does.

04

Questions we get

Does the EU AI Act require red teaming?

Not in those words. Article 15 requires resilience against third parties exploiting vulnerabilities and names the AI-specific attack classes that technical measures must address. For the largest general-purpose models, Article 55 separately requires adversarial testing. For a deployed high-risk system, the obligation is the outcome, and independent adversarial testing is how you show you met it.

We are a US company. Does it apply to us?

If your AI system is placed on the EU market or its output is used in the EU, yes, regardless of where you are based. Many US vendors meet it first through a European customer’s procurement review rather than a regulator.

Is a customer service agent high-risk?

Usually not by itself. Annex III lists specific uses: credit scoring, life and health insurance pricing, employment decisions, education, essential services, and others. An agent that feeds one of those decisions can be in scope. Most agents fall under the general transparency obligations, which already apply, and under whatever their buyer’s own risk policy demands.

Didn’t the high-risk rules start in August 2026?

They were scheduled to. The AI Omnibus amendment, in force since 27 July 2026, moved the Annex III deadline to 2 December 2027 and the Annex I deadline to 2 August 2028. The Act itself became generally applicable on 2 August 2026. Several published summaries still show the old dates.

Resilient against third parties. Shown, not stated.

An assessment of your agent, mapped to Article 15 and Annex III, with the NIST AI RMF and OWASP mappings alongside.

Written by the NXT AI research team. This page describes the regulation; it is not legal advice. Quotations are from the sources below. NXT is not affiliated with any EU institution. Last updated October 7, 2026.

Sources