Performance, Robustness & Cybersecurity — Lifecycle Operations
EU AI Act Compliance Regulatory Knowledge EU/UK aligned
+ On this page
Key takeaways
- Agree acceptance per cohort/context, not just global averages. Declare trade-offs and residual risks.
- Robustness mixes testing (adversarial/red-team) with design (guardrails, filters, isolation, rate-limits).
- Security is supply-chain + runtime + operations; keep attestations and SBOMs in the evidence pack.
Targets & acceptance
- Define accuracy/utility targets, fairness thresholds, safety limits and latency/availability SLOs.
- Acceptance gates with owner sign-off; publish tolerances and monitoring strategy.
Cohorts & contexts
- Slice performance by protected attributes (where lawful), environment, channel and language.
- Stress contexts: noisy inputs, domain shift, long-tail prompts, time-pressure, partial failures.
Robustness & adversarial testing
- Adversarial examples; perturbations; conflicting instructions; model inversion/extraction tests.
- Safety decks: disallowed content, self-harm, medical/legal claims, financial advice.
LLM/Jailbreak protection
- Prompt hygiene; system/policy prompts; refusal rules; tool-use restrictions; content classification pre/post-generation.
- Guardrails for personally identifiable/sensitive content; grounding and citation checks for RAG.
Hardening patterns
- Input validation; safelist/denylist; output sanitisation; deterministic fallbacks for critical flows.
- Network isolation; egress control; key management; policy-gated CI/CD; canary releases.
Observability & SLOs
- Golden signals: latency, errors, saturation, cost, queue depth, and model-quality signals.
- Pager duty with SLO burn-rate alerts; automated triage and playbooks.
Supply-chain & attestations
- SBOM; model provenance; license checks; vendor attestations (evaluation scope, safety, security).
- Third-party risk assessments; contract clauses for incident support and notifications.
Privacy & secure MLOps
- Secrets rotation; short-lived tokens; data minimisation in traces; access logging and approvals.
- PII scanning in prompts/outputs; redaction; consent flows; per-tenant isolation where applicable.
Resilience & rollback
- Downgrade modes (heuristics/manual review) for safety-critical flows; circuit-breakers.
- Backups, disaster recovery RTO/RPO; cross-region failover; rollback buttons with validation.
Governance & waivers
- Risk acceptance/waiver process with expiry; senior accountability; regular review cadence.
Evidence & change control
- Keep evaluation suites, red-team results, jailbreak logs, security tests and sign-offs in the evidence pack.
- All changes via tickets with diffs, approvers and rollback criteria linked to PMM.
Implementation checklist
- Targets set per cohort/context; adversarial/robustness tests defined; guardrails live.
- Observability and SLOs active; supply-chain attestations stored; rollback rehearsed.
© Zen AI Governance UK Ltd • Regulatory Knowledge • v1 05 Nov 2025 • This page is general guidance, not legal advice.
Related Articles
Accuracy, Robustness & Cybersecurity Controls (EU / UK Aligned)
Zen AI Governance — Knowledge Base • EU AI Act Compliance • Updated 17 Nov 2025 www.zenaigovernance.com ↗ Accuracy, Robustness & Cybersecurity Controls (EU / UK Aligned) EU AI Act Compliance Accuracy • Robustness • Cybersecurity + On this page On ...
Accuracy, Robustness & Cybersecurity — Risk Management
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ Accuracy, Robustness & Cybersecurity — EU/UK aligned EU AI Act Compliance Risk Management EU/UK aligned + On this page On this page Accuracy & ...
Post-Market Monitoring (PMM) — Lifecycle Operations
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ Post-Market Monitoring (PMM) — EU/UK aligned EU AI Act Compliance Lifecycle Operations EU/UK aligned + On this page On this page Objectives & KPIs ...
Serious Incident Reporting (EU/UK) — Lifecycle Operations
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ Serious Incident Reporting (EU/UK) — workflow & evidence EU AI Act Compliance Lifecycle Operations EU/UK aligned + On this page On this page ...
Evaluation Suite — Safety & Robustness — Evaluation & Documentation
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ Evaluation Suite — Safety & Robustness EU AI Act Compliance Evaluation & Documentation EU/UK aligned + On this page On this page Scope & risk mapping ...