Compliance mechanisms for EU AI Act Article 15(5) attack-prevention requirement
Determine concrete technical and organizational measures by which providers and deployers of machine-learning, neural-network, and large language model systems can comply with Article 15(5) of Regulation (EU) 2024/1689, which requires prevention of unique attacks against such AI systems, specifying how these measures can be implemented in practice to meet the "where appropriate" standard.
References
Article 15(5), part 3, is worth focussing on because it mandates that all types of unique attacks on machine-learning, neural-network or LLM based AI should be prevented where appropriate. How this is complied with going forward is unknown, as several of these are hard problems to solve in a technical context.
— Large Language Models as a (Bad) Security Norm in the Context of Regulation and Compliance
(2512.16419 - Ludvigsen, 18 Dec 2025) in Section 4.1 (Statutory Law)