Robustness and Cybersecurity in the EU Artificial Intelligence Act
arXiv:2502.16184 · doi:10.1145/3715275.3732020
Abstract
The EU Artificial Intelligence Act (AIA) establishes different legal principles for different types of AI systems. While prior work has sought to clarify some of these principles, little attention has been paid to robustness and cybersecurity. This paper aims to fill this gap. We identify legal challenges and shortcomings in provisions related to robustness and cybersecurity for high-risk AI systems(Art. 15 AIA) and general-purpose AI models (Art. 55 AIA). We show that robustness and cybersecurity demand resilience against performance disruptions. Furthermore, we assess potential challenges in implementing these provisions in light of recent advancements in the machine learning (ML) literature. Our analysis informs efforts to develop harmonized standards, guidelines by the European Commission, as well as benchmarks and measurement methodologies under Art. 15(2) AIA. With this, we seek to bridge the gap between legal terminology and ML research, fostering a better alignment between research and implementation efforts.
A previous version contained an incorrect publication year for the AI Act on page 1. This has been corrected
References in corpus (8)
- A Survey on Large Language Model (LLM) Security and Privacy: The Good, the Bad, and the Ugly
- A Survey on ChatGPT: AI-Generated Contents, Challenges, and Solutions
- Post-Hoc Explanations Fail to Achieve their Purpose in Adversarial Contexts
- Unlocking the Black Box: Analysing the EU Artificial Intelligence Act's Framework for Explainability in AI
- A Classification of Feedback Loops and Their Relation to Biases in Automated Decision-Making Systems
- One Model Many Scores: Using Multiverse Analysis to Prevent Fairness Hacking and Evaluate the Influence of Model Design Decisions
- Fairness Hacking: The Malicious Practice of Shrouding Unfairness in Algorithms
- Don't Throw it Away! The Utility of Unlabeled Data in Fair Decision Making