Skip to content
Selva Ops

Compliance

EU AI Act and Security Testing

Published

Selva Ops S.R.L.

Regulation (EU) 2024/1689 (the EU AI Act) is product and risk legislation for AI systems — not a SOC-style attestation. Obligations scale with risk category and role (provider, deployer, and others).

Security-relevant obligations (high level)

For high-risk AI systems, the Act expects a risk management system and requirements spanning data governance, documentation, logging, transparency, human oversight, and accuracy, robustness, and cybersecurity (see especially the obligations clustered in Articles 9–15 of the Regulation). Exact applicability depends on Annex classification and role.

What “security testing” means in this context

Traditional application penetration testing remains relevant for the software that serves models. AI-specific assessment — prompt injection, tool-calling abuse, retrieval poisoning, insecure plugin bridges — often sits alongside it. See LLM / AI penetration testing.

Harmonised standards vs management standards

Pair this page with the ISO/IEC 42001 stub when your program uses an AI management system as supporting governance evidence.

Related services

FAQ

Does the EU AI Act require a traditional penetration test?
The Act sets cybersecurity and robustness obligations for relevant AI systems, especially high-risk systems, but it is not a penetration-testing standard. Technical testing is one way providers may demonstrate that security and resilience requirements are met.
Is ISO/IEC 42001 the same as AI Act conformity?
No. ISO/IEC 42001 is a voluntary AI management system standard. It can support governance evidence but does not, by itself, create a legal presumption of conformity under the AI Act.

See what the deliverable looks like

Review a sanitized sample report before you talk to anyone — findings structure, severity model, and remediation detail.

Get the sample report