The EU AI Act, Regulation (EU) 2024/1689, entered into force on August 1, 2024, and its obligations phase in between February 2025 and August 2027. For security teams, the parts that matter most are the risk tiers, which decide whether a system is banned, heavily regulated or largely left alone, and Article 15, which sets accuracy, robustness and cybersecurity requirements for high-risk AI systems, including protection against AI-specific attacks such as data poisoning and adversarial examples. The Act also sets logging and incident reporting duties, and fines of up to €35 million or 7% of worldwide turnover. Knowing where AI runs in your organization is the practical first step.

When does the EU AI Act apply?

The Act was published in the Official Journal on July 12, 2024 and entered into force on August 1, 2024. Its obligations apply in stages under Article 113:

Date What starts to apply
February 2, 2025 General provisions, including AI literacy (Article 4), and the prohibited practices (Article 5)
August 2, 2025 Obligations for general-purpose AI models, governance, penalties, and rules on notified bodies
August 2, 2026 Most remaining provisions, including obligations for high-risk systems listed in Annex III
August 2, 2027 High-risk classification for AI in products covered by the EU product laws listed in Annex I, and the obligations that go with it

The Act applies directly in every member state, and the first deadline is less than five months away.

Who does the AI Act apply to?

Obligations follow your role. The two most common are:

  • Provider: the organization that develops an AI system or model, or has one developed, and places it on the market or puts it into service under its own name.
  • Deployer: any organization that uses an AI system under its authority in a professional context.

The Act reaches beyond the EU. It covers providers placing AI systems on the EU market wherever they're established, and providers and deployers outside the EU where the system's output is used in the EU. Military, defense and national security uses are excluded, as is AI developed solely for scientific research.

Roles can shift. Under Article 25, a deployer that puts its own name on a high-risk system, substantially modifies it, or changes its intended purpose so that it becomes high-risk is treated as a provider.

How does the AI Act classify risk?

The Act sorts AI into tiers, and the tier decides the obligations.

Prohibited practices

Article 5 bans a short list of practices from February 2, 2025, including:

  • Manipulative or deceptive techniques that materially distort behavior and cause significant harm
  • Exploiting vulnerabilities related to age, disability or social or economic situation
  • Social scoring leading to unjustified or disproportionate detrimental treatment
  • Predicting criminal offending based solely on profiling or personality traits
  • Untargeted scraping of facial images to build facial recognition databases
  • Emotion recognition in the workplace or in education, except for medical or safety reasons
  • Biometric categorization to infer sensitive characteristics such as race or political opinions
  • Real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions

The workplace emotion recognition ban deserves a check. Some monitoring and analytics tools infer emotional states from voice, video or behavior, and using them on employees is prohibited outside the medical and safety exceptions.

High-risk AI systems

High-risk systems carry the heaviest obligations, and there are two routes in:

  • Annex I: AI that is a product, or a safety component of a product, covered by listed EU product safety laws, such as those for machinery or medical devices, where that product needs third-party conformity assessment.
  • Annex III: AI used in eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services; law enforcement; migration, asylum and border control; and administration of justice and democratic processes.

Under Article 6(3), an Annex III system isn't high-risk if it poses no significant risk of harm, for example because it only performs a narrow procedural task. That exception never applies to systems that profile people. The Commission must publish guidelines with practical examples by February 2, 2026.

One detail matters for security teams. Annex III covers AI used as safety components in the management and operation of critical digital infrastructure. Recital 55 clarifies that "components intended to be used solely for cybersecurity purposes should not qualify as safety components." A detection model in your security stack usually won't be high-risk on that basis alone. An AI system that monitors and evaluates employee behavior to inform work-related decisions may fall into the employment category, though.

Transparency risk

Some systems carry lighter transparency duties, such as telling people they're interacting with an AI system unless it's obvious.

Minimal risk

Everything else, such as spam filters or AI-enabled video games, faces no new obligations under the Act.

General-purpose AI models

General-purpose AI (GPAI) models, such as large language models, have their own track from August 2, 2025. All GPAI providers owe technical documentation and information to downstream providers, among other duties. Models with systemic risk, presumed when training compute exceeds 10^25 floating-point operations, face more. Under Article 55, their providers must run model evaluations that include adversarial testing, assess and mitigate systemic risks, report serious incidents, and "ensure an adequate level of cybersecurity protection" for the model and its physical infrastructure.

What does Article 15 require for cybersecurity?

High-risk AI systems must "achieve an appropriate level of accuracy, robustness, and cybersecurity" and perform consistently in those respects throughout their lifecycle.

That breaks into three expectations:

  • Accuracy. Providers must declare accuracy levels and the relevant metrics in the instructions for use, so deployers know what to expect.
  • Robustness. Systems must be as resilient as possible to errors, faults and inconsistencies, for example through technical redundancy, backup or fail-safe plans. Systems that keep learning after deployment must reduce the risk of biased outputs feeding back into future inputs.
  • Cybersecurity. Systems must be resilient against attempts by unauthorized third parties to alter their use, outputs or performance by exploiting vulnerabilities.

Article 15(5) goes further than most laws by naming AI-specific attacks. Where appropriate, technical solutions must prevent, detect, respond to, resolve and control for:

Attack named in Article 15(5) What it targets
Data poisoning Manipulation of the training data set
Model poisoning Manipulation of pre-trained components used in training
Adversarial examples or model evasion Inputs crafted to make the model err
Confidentiality attacks Attempts to extract data or information from the model
Model flaws Weaknesses in the model itself

For a security team, that means familiar work applied to a new asset class:

  • Provenance, integrity and access controls for training data
  • Verification of pre-trained models and other third-party components before use
  • Adversarial testing before release and at intervals afterward
  • Monitoring of inputs and outputs for anomalies and drift
  • Access control and rate limiting on model endpoints to reduce extraction risk
  • Hardening of the pipelines, infrastructure and model registries behind the system

Article 42(2) offers a shortcut: systems certified under a scheme adopted under the EU Cybersecurity Act are presumed to meet Article 15's cybersecurity requirements, to the extent the certificate covers them. Harmonized standards are also in development.

What are the logging and record-keeping requirements?

Article 12 requires high-risk AI systems to "technically allow for the automatic recording of events (logs) over the lifetime of the system." Logging has to support three things: identifying situations that could present a risk or lead to a substantial modification, post-market monitoring, and monitoring of the system's operation by deployers. Remote biometric identification systems have extra minimum fields, such as the period of each use and the reference database checked.

Providers and deployers must each keep the logs under their control for at least six months (Articles 19 and 26(6)), unless other EU or national law says otherwise.

Serious incidents trigger reporting under Article 73. Providers must report to the market surveillance authority no later than 15 days after becoming aware. The deadline shortens to two days for widespread infringements or a serious and irreversible disruption of critical infrastructure, and to 10 days where a person has died. Deployers who identify a serious incident must inform the provider immediately.

Treat AI logs like any other audit trail, and build the Article 73 clock into your incident response process.

Why do you need an AI inventory?

The Act doesn't explicitly require every organization to keep an AI inventory. It's still the only practical way to comply, because you can't classify, secure or log systems you don't know about.

By February 2, 2025, you'll want to be sure nothing in use crosses into a prohibited practice. That date also brings the Article 4 duty for providers and deployers to ensure a sufficient level of AI literacy among staff who operate or use AI systems.

A useful inventory records, for each system:

  • Name, owner, purpose and vendor
  • Your role (provider, deployer or both)
  • Risk tier and the reasoning behind it
  • Data sources and connected systems
  • Security controls, testing history and logging

Include AI features embedded in licensed software. Many arrived as product updates, not procurement decisions.

What are the penalties under the AI Act?

Article 99 sets three tiers of administrative fines:

  • Prohibited practices: up to €35 million or 7% of total worldwide annual turnover, whichever is higher
  • Most other obligations, including high-risk, deployer and transparency duties: up to €15 million or 3%, whichever is higher
  • Supplying incorrect, incomplete or misleading information to notified bodies or authorities: up to €7.5 million or 1%, whichever is higher

For SMEs and start-ups, each cap is whichever amount is lower. Fines for GPAI model providers are handled separately by the Commission.

Frequently asked questions

We only use AI from vendors. Do we have obligations?

Yes, as a deployer of any high-risk system. You must use it according to the instructions, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents to the provider.

Do high-risk AI systems have to be registered?

Yes. Under Article 49, providers must register Annex III high-risk systems in an EU database before placing them on the market, though critical infrastructure systems are registered nationally. Deployers that are public authorities must register their use too.

Does the AI Act replace GDPR or NIS2?

No. It applies alongside them. AI that processes personal data still has to comply with GDPR, and NIS2 entities still have to secure all their network and information systems, including those that run AI.

Next steps

  1. Start the AI inventory now, including embedded AI features, and record your role for each system.
  2. Screen for prohibited practices and plan AI literacy measures before February 2, 2025.
  3. Classify each system, flagging likely high-risk systems and the deadline that applies.
  4. Extend your security program to AI. Add the Article 15(5) attacks to threat models and testing plans.
  5. Set up AI logging, with at least six months' retention and integrity protection.
  6. Update vendor due diligence. Ask AI suppliers about classification, Article 15 and logging support.

The AI Act is new and guidance is still to come, so treat this as an explainer rather than legal advice and confirm specifics with counsel.