Recital 77
(77)
Without prejudice to the requirements related to robustness and accuracy set out in this Regulation, high-risk AI systems which fall within the scope of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, in accordance with that regulation may demonstrate compliance with the cybersecurity requirements of this Regulation by fulfilling the essential cybersecurity requirements set out in that regulation. When high-risk AI systems fulfil the essential requirements of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, they should be deemed compliant with the cybersecurity requirements set out in this Regulation in so far as the achievement of those requirements is demonstrated in the EU declaration of conformity or parts thereof issued under that regulation. To that end, the assessment of the cybersecurity risks, associated to a product with digital elements classified as high-risk AI systemAI systemmeans a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environmentsArticle 3(1) according to this Regulation, carried out under a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, should consider risks to the cyber resilience of an AI systemAI systemmeans a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environmentsArticle 3(1) as regards attempts by unauthorised third parties to alter its use, behaviour or performance, including AI specific vulnerabilities such as data poisoning or adversarial attacks, as well as, as relevant, risks to fundamental rightsfundamental rightsIncludes human dignity, right to life, prohibition of torture, protection of personal datapersonal dataAny information relating to an identified or identifiable natural person ('data subjectsubjectfor the purpose of real-world testing, means a natural person who participates in testing in real-world conditionsArticle 3(58)data subjectsubjectfor the purpose of real-world testing, means a natural person who participates in testing in real-world conditionsArticle 3(58)An identified or identifiable natural person to whom personal data relateGDPR Art. 4(1)'). Includes name, ID number, location data, online identifiers, or factors specific to physical, physiological, genetic, mental, economic, cultural or social identityGDPR Art. 4(1), freedom of expression, non-discrimination, equality between women and men, rights of the child, right to an effective remedy and fair trialCharter of Fundamental Rights Art. 1–54 as required by this Regulation.