AR-005AltoFornitorePreventivo
Misure di cibersicurezza per i sistemi di IA
L'articolo 15, paragrafo 5, richiede che i sistemi di IA ad alto rischio siano resilienti contro tentativi non autorizzati di terzi di alterarne i risultati, e i fornitori devono attuare misure di cibersicurezza adeguate durante l'intero ciclo di vita del sistema.
Articoli:Article 15(5)
Esempi di prove
- Cybersecurity architecture review
- Penetration test report
- Model access control specification
Norme
ISO 42001:2023 §8.4ISO/IEC 27001:2022ENISA AI Threat Landscape
Controlli correlati
- AR-001Accuracy Level Definition and CommitmentArticle 15(1) requires that high-risk AI systems are designed and developed to achieve an appropriate level of accuracy, robustness, and cybersecurity,…
- AR-002Accuracy Measurement and VerificationProviders must measure and verify the accuracy of the AI system against defined metrics using representative test sets, documenting the methodology,…
- AR-003Robustness Testing Against Input VariationsProviders must test the AI system's robustness against input variations that may arise in real-world deployment, including incomplete data, noisy inputs,…
- AR-004Adversarial Robustness TestingWhere relevant to the AI system's use case, providers must test robustness against adversarial inputs designed to cause misclassification, data poisoning…
- AR-006Fallback Procedures for System FailuresProviders must design and implement fallback procedures that activate when the AI system cannot operate within its designed parameters, ensuring safe…
- AR-007Input Validation and Data Quality ChecksProviders must implement input validation mechanisms that verify the quality, format, and plausibility of data before it is processed by the AI system,…
Termini correlati del Regolamento IA
- AccuracyThe requirement that high-risk AI systems achieve an appropriate level of accuracy in relation to their intended purpose, as specified in the technical documentation. Providers must declare the level of accuracy in the instructions for use.
- RobustnessThe ability of a high-risk AI system to maintain its level of performance under adverse conditions — including technical limitations, adversarial inputs, errors, or unexpected situations — or within foreseeable operating conditions outside the intended purpose.
- CybersecurityThe requirement that high-risk AI systems are resilient against attempts by third parties to alter their use, behaviour, or performance in ways that could result in risks to health, safety, or fundamental rights, including protection against data poisoning, adversarial examples, and model evasion attacks.
Passa alla versione completa quando la conformità deve essere
Il questionario gratuito fornisce segnali preliminari. La Valutazione Completa trasforma i dati reali di sistema in un fascicolo decisionale governato: estrazione, separazione componenti, prove, sovrapposizioni nazionali e dossier pronto per audit.
Avvia anteprima gratuita del rischio