Questionnaire answers · AI topics · Article 15(4)
How to answer AI model security questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Answer with the attacks the Act names and what you do against each, for the systems they reach. For a high-risk system Article 15(5) asks for resilience against attempts to alter its use, outputs or performance. It names data poisoning, model poisoning, adversarial examples, confidentiality attacks and model flaws. Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“How do you protect your AI against attacks?”
- Q2“How do you handle prompt injection?”
- Q3“How robust is the system to errors and unexpected input?”
- Q4“Who can change the model or its data?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: How do you handle prompt injection?
- Direct answerYes, partly or no first
- We limit what the model can do with any input, so an injected instruction cannot reach data or actions outside the request.
- ControlWhat you actually do
- The model has no tools that write data, and every output is shown to a user before it is used.
- ScopeWhich AI systems
- Reply drafting and ticket summaries.
- EvidenceWhat you can show
- The architecture note of 20 September 2026 and the test cases for injected instructions in the release test set.
- ExceptionsBe honest
- We do not claim injection cannot happen; we claim it cannot act without a person.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCThe architecture note: what the model can reach, and what it cannot.
- DOCTest cases for the attacks you name, with results and dates.
- DOCAccess control on models, prompts and training data, with the audit log.
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
Article 15(4)a high-risk system is as resilient as possible to errors, faults or inconsistencies, including through technical redundancy. A system that continues to learn reduces the risk of biased feedback loops.
Read Article 15 on EUR-Lex ↗ - Article 15(5): resilience against attempts by unauthorised third parties to alter use, outputs or performance by exploiting vulnerabilities; the measures, where appropriate, address data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.
- The Act does not use the term prompt injection.
What Complipath does
- ✓Two-factor sign-in A code from your phone after the email link, which the owner can require for everyone
- ✓Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
- ✓Evidence management A file linked to the requirements it proves, with the passage and its page
- ✓Article mapping Each reason behind a verdict names the provision it rests on, so a reader can check it herself
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
- ✗Domain-specific guidance Not supported Guidance written for one sector.
Questions
Does the AI Act mention prompt injection?
Not by that name. Article 15(5) names adversarial examples or model evasion, inputs designed to make the model make a mistake, beside data poisoning, model poisoning, confidentiality attacks and model flaws. Answer the buyer's question in their words and cite the Act's categories, for a high-risk system.
Does Complipath secure our models?
No. Complipath does not do your security work. It keeps the evidence and answers with a source: the evidence of your security work, linked to the requirement it proves, with the article behind each requirement. Its own account security includes two-factor sign-in and an audit log nobody can edit.
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.