Showing posts with label EU AI Act. Show all posts
Showing posts with label EU AI Act. Show all posts

Thursday, August 06, 2026

EU AI Act's GPAI Rules Are Now Enforceable: What Changed on August 2, 2026 (And What Your Team Missed)


For twelve months, Brussels asked nicely. As of August 2, 2026, it doesn't have to anymore.

If your compliance team spent the summer congratulating itself on a "quiet" AI Act rollout, it's time for an uncomfortable conversation. The obligations for general-purpose AI (GPAI) providers didn't just appear this month — they've technically applied since August 2, 2025. What changed on August 2, 2026 is that the European Commission's AI Office can finally do something about non-compliance: audit models, demand corrective action, restrict market access, and issue fines of up to €15 million or 3% of global annual turnover, whichever is higher.

That distinction — obligation versus enforcement — is exactly what most European boardrooms missed while they were busy tracking the wrong deadline.

The Grace Period Is Over

When the EU AI Act entered into force in August 2024, it built in a deliberate one-year runway for GPAI providers. Chapter V obligations — training-data summaries, copyright compliance, technical documentation, and systemic-risk management for the most powerful models — became legally binding on August 2, 2025. But the AI Office needed time to build its own supervisory machinery before it could act on any of it.

That runway has now ended. From August 2, 2026, the Commission can request technical documentation, run model evaluations, order risk-mitigation measures, and pull non-compliant GPAI models from the EU market. Models placed on the market before August 2, 2025 get a slightly longer runway — they must be fully compliant by August 2, 2027 — but every model launched after that date has already been operating on borrowed time.

Signing the voluntary GPAI Code of Practice helps, but it isn't a shield. Regulators have indicated that Code signatories will have their good-faith commitments weighed when calculating penalties, yet enforcement applies "signatures or not." A partial signature — committing to some chapters of the Code while skipping others — is a detail worth scrutinising in any vendor's compliance claims, not taking at face value.

Article 50 Is the Deadline Everyone Underestimated

While GPAI enforcement grabbed the headlines, Article 50 transparency obligations quietly went live the same day — and this one reaches far beyond model providers. Any organisation deploying a chatbot or conversational AI system must now disclose, clearly and at the start of the interaction, that the user is talking to an AI. AI-generated or manipulated content, including deepfakes, requires machine-readable labelling. The same €15 million / 3% turnover penalty ceiling applies here too.

This is the requirement that catches European businesses off guard, because it isn't aimed at Silicon Valley labs — it's aimed at every customer service bot, marketing assistant, and generative content workflow running inside ordinary companies across Germany, France, Ireland, and the Netherlands. If your team's AI inventory doesn't already flag which systems talk directly to customers, that's the gap to close first.

Don't Confuse This With the Digital Omnibus Delay

Here's where a lot of internal risk registers went wrong this year. The Digital Omnibus, finalised by the European Parliament on June 16, 2026 and given final Council sign-off on June 29, 2026, pushed high-risk AI system obligations under Annex III from August 2026 out to December 2, 2027. That's a genuine, significant delay — but it applies to a completely different track of the Act.

It does nothing to soften GPAI enforcement powers or Article 50 disclosure duties. If your compliance roadmap assumed the Omnibus bought extra breathing room on chatbot transparency, it was working from an outdated script. Two separate clocks, two separate consequences — and conflating them is precisely how well-resourced teams end up caught flat-footed on the deadline that actually mattered.

What Your Team Likely Missed

  1. Treating "GPAI obligations" and "GPAI enforcement" as the same milestone. They weren't. The rules existed for a year with no teeth; now they have teeth.
  2. Assuming the Omnibus delay covered everything. It covered high-risk systems only — not GPAI supervision, not Article 50.
  3. Ignoring deployer-side exposure. Being a "deployer" rather than a "provider" doesn't create a safe harbour under Article 50. Disclosure duties reach anyone whose customers interact with AI.
  4. No live AI inventory. Regulators, national market surveillance authorities, and even downstream providers can now trigger scrutiny. Without a current inventory of AI systems, owners, and purposes, an inquiry response starts from zero.
  5. Reading "Code of Practice signatory" as full compliance. It's a mitigating factor in penalty calculation, not an exemption.

What To Do Before the Next Inquiry Lands

European organisations — not just AI labs — now sit inside an active enforcement regime. Practical next steps look less like a policy rewrite and more like an operational audit: build (or refresh) a complete AI systems inventory, classify which tools are GPAI-adjacent versus deployer-only, confirm chatbot disclosure is actually implemented at the interaction level, and stress-test whether your documentation would survive a Commission request this quarter.

VISTA InfoSec's own EU AI Act compliance checklist is a useful starting point for scoping classification and Annex IV documentation gaps, and their breakdown of 10 controls every organisation should implement in 2026 maps well against exactly the gaps regulators are now empowered to act on. For organisations that haven't yet run a structured gap assessment, VISTA InfoSec's practitioner-led AI governance assessments are built around operational audit experience rather than template-driven paperwork — a meaningful difference now that "we have a policy" is no longer enough to satisfy an AI Office inquiry.

The Bottom Line

August 2, 2026 didn't introduce new rules. It introduced consequences. For European businesses running customer-facing AI, procuring GPAI models, or quietly letting departments adopt generative tools without central oversight, the honest question isn't "are we compliant on paper" — it's "could we produce evidence of compliance inside a week if the AI Office asked." If the answer is uncertain, the runway to find out just got a great deal shorter.

Thursday, July 30, 2026

ISO 42001 Is Becoming the New SOC 2: Why European AI Vendors Can't Ignore It in 2026

Three years ago, a SOC 2 report was the single piece of paper that opened enterprise doors. No SOC 2, no procurement shortlist, no matter how good your product was. In 2026, European AI vendors are watching a new document take that seat at the table: ISO/IEC 42001, the world's first certifiable standard for an Artificial Intelligence Management System (AIMS).

If you sell AI-powered software to European enterprises, banks, or public bodies, this isn't a distant compliance trend. It's already showing up in RFPs, vendor security questionnaires, and boardroom risk registers. Here's why ISO 42001 is following SOC 2's exact playbook, and what you need to do about it this year.

Why SOC 2 Stopped Being Enough

SOC 2 was built to answer one question: can this vendor be trusted with our data? It says nothing about whether an algorithm is biased, whether a model's decisions can be explained, or whether an organisation has a documented process for retraining, monitoring, and decommissioning AI systems. As generative AI and automated decision-making moved into lending, hiring, healthcare, and customer service, European buyers started asking questions SOC 2 was never designed to answer.

Enter ISO 42001: The AIMS Standard

Published by ISO and IEC in December 2023, ISO/IEC 42001 gives organisations a Plan-Do-Check-Act framework, modelled on the same structure as ISO 27001, but built specifically for how AI is developed, procured, deployed, and monitored. It covers AI risk assessment, data governance, human oversight, transparency, supplier AI risk, and lifecycle monitoring precisely the gaps SOC 2 leaves open.

Certification is voluntary, but "voluntary" is doing less work than it used to. Enterprise procurement teams across Europe are folding ISO 42001 into vendor due diligence the same way they folded in SOC 2 a decade ago not because a regulator demands it, but because it's the fastest way to prove AI governance is real rather than a slide deck.

The EU AI Act Is the Real Accelerant

The EU AI Act's obligations for high-risk AI systems became enforceable on 2 August 2026, covering risk management, data governance, technical documentation, human oversight, and accuracy and robustness requirements under Articles 9–15. ISO 42001 doesn't automatically satisfy the Act as of 2026 it is not yet a harmonised standard published in the Official Journal of the EU, and CEN-CENELEC is still finalising a dedicated European deliverable (prEN 18286) aligned with it. But regulators and auditors consistently point to ISO 42001 as the strongest available evidence of structured AI governance while that harmonisation work continues, which is exactly why European vendors are moving now rather than waiting.

For a practical breakdown of what auditors expect before enforcement dates land, VistaInfosec's EU AI Act compliance checklist is worth a read it lays out exactly which evidence buyers and regulators will ask for first.

What This Means for European AI Vendors, Specifically

  • Sales cycles are shifting left. Security questionnaires now include ISO 42001 status alongside SOC 2 and ISO 27001, often before a demo is even scheduled.
  • ISO 27001 holders have a head start. Because both standards share the same management-system backbone, organisations with an existing ISMS typically cut ISO 42001 implementation effort by roughly a third to a half.
  • Timelines are compressing. Certification generally runs four to twelve months from gap assessment to certificate, but firms with ISO 27001 already in place can often get there in three to four months.
  • Cost is real but manageable. First-year costs for a mid-size organisation typically fall in the €80,000–€140,000 range, covering gap assessment, documentation, internal audit, and the external certification audit.

ISO 42001 vs SOC 2: How They Actually Compare

DimensionSOC 2ISO 42001
Core question answeredIs customer data handled securely?Is AI governed responsibly across its lifecycle?
ScopeSecurity, availability, confidentiality controlsAI risk management, bias, transparency, oversight
OriginAICPA (US)ISO/IEC (international)
Typical buyer ask"Send your SOC 2 report""Are you ISO 42001 certified?"
Relevance to EU AI ActMinimalStrong supporting evidence, not yet a presumption of conformity

Building an AIMS Doesn't Mean Starting from Zero

The organisations moving fastest aren't building AI governance from scratch they're extending what they already have. If you're certified against ISO 27001, your risk register, internal audit programme, and management review process already exist; ISO 42001 adds an AI-specific layer on top rather than replacing anything. VistaInfosec's guide on ISO 42001 certification timeline and cost breaks down exactly how much faster this path is, stage by stage.

"ISO 42001 is becoming the new SOC 2 the certificate buyers ask for before they sign."

Getting Started: A Practical Sequence

  • Run a gap assessment against ISO/IEC 42001:2023, reusing your ISO 27001 scope and risk process wherever possible.
  • Build (or extend) your AI risk register and complete impact assessments for each AI system in production.
  • Formalise human oversight, data governance, and supplier AI assurance controls.
  • Run an internal audit and management review before inviting an accredited certification body for Stage 1.
  • Automate evidence collection so documentation doesn't lag behind what your engineering team ships.

Vendors that treat this as a checkbox exercise tend to stall at Stage 1. Vendors that treat it as an extension of existing security maturity the same instinct that made SOC 2 straightforward for mature SaaS companies move through certification in a fraction of the time.

The Bottom Line

ISO 42001 is not a legal mandate, and it won't single-handedly make you EU AI Act compliant. But it is rapidly becoming the commercial signal European enterprises use to separate serious AI vendors from the rest exactly the role SOC 2 played for cloud software a decade ago. Vendors who certify early won't just tick a compliance box; they'll shorten sales cycles, win procurement conversations before competitors even reach the table, and walk into EU AI Act enforcement with governance already in place.

Considering your ISO 42001 roadmap? VistaInfosec's ISO 42001 certification and AI governance consulting service helps organisations move from gap assessment to certification in as little as 4–6 months often by extending an existing ISO 27001 or SOC 2 programme rather than starting over.

Wednesday, July 22, 2026

The EU AI Act Is Now Enforceable: What Your Dev Team Must Change Before the Next Compliance Milestone


If your engineering team has been treating the EU AI Act as "next year's problem," it's time for a hard reset. The Act (Regulation 2024/1689) is not a future proposal anymore it is live law, and its most demanding milestone yet arrives on 2 August 2026, when obligations for high-risk AI systems and Article 50 transparency duties become fully enforceable across the EU. For CTOs, engineering leads, and compliance-adjacent developers from Berlin to Bucharest, this is the deadline that turns "we should probably look into this" into "our system is non-compliant and the fine is up to €35 million or 7% of global turnover."

This isn't a legal briefing. It's a practical, developer-facing look at what actually needs to change in your codebase, your pipelines, and your documentation before the milestone hits.

Quick fact: Maximum penalty under the EU AI Act is €35 million or 7% of global annual turnover higher than GDPR's own maximum fine.

Where things actually stand right now

A quick reality check, because there's a lot of noise online: prohibited AI practices and AI literacy obligations have been in force since February 2025. GPAI (general-purpose AI) obligations and the designation of national authorities followed in August 2025. The big one full compliance for high-risk AI systems under Annex III (biometrics, critical infrastructure, education, employment, law enforcement, migration, justice, and democratic processes) activates on 2 August 2026.

Yes, the European Commission's November 2025 Digital Omnibus package proposed easing some administrative burdens, and parts of it were provisionally agreed in mid-2026. But unless final technical standards are approved in time, the backstop compliance date for high-risk systems remains 2 December 2027 at the latest, and the August 2026 date for GPAI penalty powers and transparency rules stays firmly on the calendar. In other words: don't build your roadmap on the hope of a delay. Build it on the assumption that enforcement is real, and soon.

What your dev team must actually change

1. Stop treating "the model" as the whole system

Auditors and regulators evaluate the AI system data pipeline, model, interface, monitoring, and human oversight controls together. If your risk classification only covers the model weights, you're already behind. Map every AI-touching component your team owns and classify each one against the Act's four risk tiers.

2. Build (and keep) a technical documentation trail

Annex IV technical documentation isn't a one-off PDF. It needs to be a living artifact: training data provenance, evaluation metrics, known limitations, and change logs updated every time a model is retrained or fine-tuned. If your CI/CD pipeline doesn't already generate this documentation automatically, this is the milestone to fix that.

3. Wire in logging and human oversight, not just uptime monitoring

High-risk systems require automatic event logging sufficient to trace decisions after the fact, plus a genuine human-in-the-loop override not a rubber-stamp approval button. Engineering teams should treat this the same way they'd treat audit logging for financial transactions: immutable, timestamped, and queryable.

4. Implement Article 50 transparency by design

From 2 August 2026, chatbots must disclose they're AI, emotion-recognition systems must notify users, and synthetic or manipulated content (including deepfakes) needs machine-readable watermarking. If your frontend team hasn't already added disclosure UI and your generation pipeline hasn't added content provenance metadata, this is now a blocking ticket, not a backlog item.

5. Treat GDPR and the AI Act as one compliance surface, not two

Every high-risk AI system that processes personal data needs both an AI-specific risk assessment and, in most cases, a Data Protection Impact Assessment. Running these as separate workstreams doubles the effort and doubles the chance of gaps. Teams that have already mapped their GDPR compliance obligations for AI data processing are finding it far easier to extend that same governance model to AI Act requirements, rather than starting from scratch.

6. Register before you deploy

High-risk AI systems must be registered in the EU database before being placed on the market or put into service. This is a deployment gate, not a paperwork afterthought build it into your release checklist alongside security sign-off.

A practical control checklist

For teams that want a structured starting point rather than reverse-engineering the regulation article by article, VISTA InfoSec has published a detailed EU AI Act readiness guide covering the 10 controls every organisation should implement in 2026, mapped against the specific deadlines each control gates. It's a useful cross-check against your own implementation plan, especially where high-risk and transparency obligations now sit on different compliance clocks.

Why "later" is no longer a strategy

The Brussels Effect means this isn't just a European problem companies outside the EU that touch EU users or EU markets are restructuring their AI governance to match, because Japan, Canada, Brazil, and South Korea are already modelling their own AI laws on this framework. If your product ships anywhere near the EU, your dev team's AI governance decisions this quarter will likely define your architecture for years.

The organisations that are ahead right now didn't wait for a final legal interpretation of every clause. They ran a gap assessment, fixed what a tested control revealed rather than what a checklist implied, and moved. If your team needs an outside, evidence-based view of where your AI estate actually stands rather than another internal checklist nobody has time to finish it's worth getting a second set of eyes before the August milestone, not after. VISTA InfoSec's compliance and AI governance advisory services run exactly this kind of practitioner-led gap assessment.

The bottom line

2 August 2026 doesn't mark the end of the EU AI Act's rollout Annex X systems in justice and migration have until December 2030, and legacy public-sector systems get grandfathering until the same year. But for most product and engineering teams building or deploying AI in or for the European market, this is the milestone that turns "AI governance" from a slide in a board deck into code, logs, and documentation that a regulator can actually inspect. Start there.

Thursday, June 11, 2026

The EU AI Act Is Now Enforced: Here Is What Your Business Must Do for Cyber-security Compliance in 2026


For years, organisations deploying artificial intelligence operated in a comfortable grey zone innovating freely while regulators struggled to keep pace. That era is definitively over. The EU Artificial Intelligence Act (EU AI Act) is now in active enforcement, and August 2026 marks a critical deadline for businesses using high-risk AI systems to demonstrate full compliance. If your organisation has not yet assessed its AI exposure, the clock is no longer ticking it has already run out for some obligations.


This article cuts through the regulatory noise and gives you a clear, practical picture of what the EU AI Act demands from a cybersecurity and compliance standpoint, and what steps to take right now.


What Is the EU AI Act and Why Does It Matter for Cybersecurity?

The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. It applies to any organisation that develops, deploys, imports, or uses AI systems within the European Union regardless of where the organisation is headquartered. This means a company based in Singapore, the US, or India that serves EU customers or uses EU personal data must still comply.


The regulation adopts a risk-based approach, categorising AI systems into four tiers: unacceptable risk (banned outright), high risk (tightly regulated), limited risk (transparency obligations), and minimal risk (largely unregulated). The most critical category for most businesses is high-risk AI which includes systems used in HR and recruitment, credit scoring, biometric identification, access to critical services, law enforcement, and more.


From a cybersecurity lens, the EU AI Act is not just an ethics or transparency law. It mandates rigorous technical and organisational security controls for high-risk systems making it directly relevant to your information security posture, data protection programme, and compliance frameworks like ISO 27001, SOC 2, and GDPR.


Key Cybersecurity Requirements Under the EU AI Act

If your organisation develops or deploys high-risk AI systems, the Act mandates specific technical and governance controls. Here is what compliance looks like in practice:


1. Robustness, Accuracy, and Cybersecurity (Article 15)

High-risk AI systems must be resilient against attempts by unauthorised third parties to alter their outputs. They must maintain consistent performance and include protections against adversarial attacks, model poisoning, and data integrity manipulation. This is not a vague aspiration it requires documented, tested controls.


2. Data Governance and Quality (Article 10)

Training, validation, and testing datasets must be managed with rigorous data governance practices. Organisations must demonstrate data quality, relevance, and freedom from harmful biases. This aligns closely with existing data protection obligations under GDPR, creating a dual compliance requirement that many organisations have yet to map.


3. Technical Documentation (Article 11)

Providers of high-risk AI must maintain comprehensive technical documentation covering system architecture, training methodology, performance metrics, and risk management processes. This documentation must be available to regulators on request and kept up to date throughout the system's lifecycle.


4. Logging and Traceability (Article 12)

High-risk AI systems must have automatic logging capabilities that allow regulators and auditors to trace system decisions. This is a significant operational requirement for any organisation currently relying on black-box AI models without audit trails.


5. Human Oversight (Article 14)

Organisations must implement measures enabling meaningful human oversight of AI-driven decisions, particularly where those decisions have significant impacts on individuals. This has direct implications for how AI tools are embedded in business workflows and what controls are placed around automated decision-making.


The August 2026 Deadline: What Changes Now?

Phase two of the EU AI Act enforcement applies from August 2, 2026. This phase brings the full weight of compliance obligations for high-risk AI systems into force. Organisations in scope face:

  • Fines of up to €30 million or 6% of global annual turnover for violations involving prohibited AI practices.
  • Fines of up to €20 million or 4% of global annual turnover for non-compliance with high-risk AI requirements.
  • Reputational damage, loss of EU market access, and potential suspension of AI system operations.
  • Mandatory registration of high-risk AI systems in the EU's public database.

 

Cyber insurance carriers are already factoring AI governance into their underwriting criteria, requiring documented adversarial testing, model-level risk assessments, and alignment with recognised AI risk management frameworks. Organisations without demonstrable AI security controls may face higher premiums or coverage exclusions.


How the EU AI Act Overlaps With GDPR, ISO 27001, and SOC2

One of the most important and often overlooked aspects of EU AI Act compliance is how heavily it overlaps with existing cybersecurity and data protection frameworks. This is both a challenge and an opportunity.


If your organisation is already compliant with GDPR, ISO 27001, or SOC 2, you are not starting from zero. Many of the controls these frameworks require access management, data minimisation, incident response, audit logging, vendor oversight directly support EU AI Act compliance. A well-structured compliance programme can address all three frameworks without duplicating effort.


For example, ISO 27001's Annex A controls around information classification, system security, and supplier relationships map directly to the EU AI Act's requirements for data governance and third-party AI provider oversight. Similarly, SOC 2's availability and confidentiality criteria support the Act's requirements for AI system robustness and access controls.


However, gaps remain. Most organisations' existing frameworks do not yet cover AI-specific risks such as model drift, adversarial inputs, or bias monitoring. These gaps must be identified and addressed before audit exposure increases.


Your EU AI Act Compliance Checklist for 2026

  • Conduct an AI inventory audit: Identify all AI systems in use, classify them by risk tier, and flag any high-risk systems that require immediate attention.
  • Map EU AI Act requirements to your existing compliance frameworks (ISO 27001, SOC 2, GDPR) to identify gaps and avoid duplicating effort.
  • Implement technical documentation for all high-risk AI systems, covering architecture, training data, performance baselines, and risk management.
  • Enable logging and audit trail capabilities across all high-risk AI deployments.
  • Conduct adversarial testing and red-team exercises to validate AI system robustness against manipulation and attacks.
  • Review your data governance processes for training and validation datasets to ensure GDPR and AI Act dual compliance.
  • Establish human oversight workflows for AI-driven decision-making in HR, finance, access control, or any high-stakes domain.
  • Update vendor contracts and supplier risk assessments for any third-party AI providers.
  • Register applicable high-risk AI systems in the EU AI Act public database before the August 2026 deadline.

How Vista Infosec Can Help

Navigating the EU AI Act alongside your existing compliance obligations is genuinely complex but it does not need to be overwhelming. Vista Infosec is a CREST-accredited global cybersecurity and compliance consulting firm with over 20 years of experience helping organisations across the US, UK, Singapore, India, and the Middle East achieve and maintain compliance with the world's most demanding frameworks.


Our team of certified experts can help you:

  • Perform an AI risk assessment and map your current controls to EU AI Act requirements.
  • Design and implement technical documentation, logging, and human oversight frameworks.
  • Integrate EU AI Act compliance into your existing ISO 27001, SOC 2, or GDPR programme to minimise cost and duplication.
  • Prepare for regulatory audits and maintain ongoing compliance as the regulatory landscape evolves.

 

Do not wait for an enforcement action to drive your compliance programme. Get ahead of the curve now.

 

Book a free 30-minuteconsultation with Vista Infosec today.

Monday, May 18, 2026

The EU AI Act Is Now in Force — Is Your Business Ready or Already Non-Compliant?


You adopted AI to move faster. To cut costs. To stay competitive.

But here's the question nobody in your boardroom is asking loudly enough:

Did you adopt it legally?


The EU AI Act the world's first comprehensive legal framework governing artificial intelligence — is no longer a distant regulation on the horizon. It's here. It's enforceable. And for businesses using AI in anything from hiring and lending to medical diagnosis and customer profiling, the compliance clock isn't just ticking.


For some provisions, it has already run out.


What Exactly Is the EU AI Act?

The EU AI Act (Regulation EU 2024/1689) is a landmark piece of legislation passed by the European Union that creates a unified legal framework for how AI systems are developed, deployed, and used across Europe and beyond.


Think of it as the GDPR moment for artificial intelligence.


Much like GDPR didn't just affect European companies but any company processing EU citizens' data, the EU AI Act doesn't just apply to businesses headquartered in Europe. If your AI system is used by people in the EU whether you're based in Mumbai, New York, or London you are in scope.


The regulation takes a risk-based approach, categorizing AI systems into four tiers based on the potential harm they can cause:


  • Unacceptable Risk — Banned outright. Think social scoring systems, real-time biometric surveillance in public spaces, or AI that manipulates human behavior subconsciously.
  • High Risk — Heavily regulated. These AI systems must meet strict requirements before deployment.
  • Limited Risk — Subject to transparency obligations. Users must know when they're interacting with AI.
  • Minimal Risk — Largely unregulated. Most AI tools like spam filters and AI-enabled video games fall here.

The most immediate and business-critical category? High-risk AI and the list of what qualifies may surprise you.


Is Your AI System "High-Risk"? You Might Be Shocked

Most business leaders assume the EU AI Act is about robots and facial recognition things that happen in sci-fi movies, not in their company's day-to-day operations.


They're wrong.


Under the EU AI Act, high-risk AI systems include AI used in:


  • Recruitment and HR — CV screening tools, automated interview scoring, employee performance monitoring
  • Credit and financial services — AI-driven credit scoring, loan eligibility assessments
  • Education — Automated grading, student performance evaluation, admissions filtering
  • Law enforcement — Risk assessment tools, predictive policing
  • Critical infrastructure — AI managing energy grids, water systems, transportation networks
  • Healthcare — Medical devices with AI components, clinical decision support tools
  • Border control and migration — Automated visa processing, risk profiling


If your business is using an AI-powered applicant tracking system to filter CVs, deploying a chatbot that makes or influences credit decisions, or using any AI tool embedded in a product that touches EU citizens you may already be operating a high-risk AI system under EU law.


And if you haven't started your compliance journey, you're already behind.


The Timeline: What's Already Live, What's Coming

The EU AI Act rolled out in phases, and unlike some regulations that give businesses years of grace, this one moves fast:


August 2024 — The Act entered into force.


February 2025 — Prohibitions on unacceptable-risk AI became enforceable. If you're running any system that falls into the "banned" category, you've been in violation for over a year.


August 2025 — Rules for General-Purpose AI (GPAI) models and governance obligations became applicable. If you're building or deploying large language models or foundation models in the EU, this is already your reality.


August 2026 — High-risk AI system requirements become fully enforceable. This is the big one. The deadline that most businesses are racing toward some without even knowing it.


2027 — Additional obligations for certain high-risk AI systems already on the market before 2024.


The window to prepare is narrowing. For high-risk AI, businesses have until August 2026 to comply which sounds like runway, until you realize how much needs to be built, documented, and validated between now and then.


What Does Compliance Actually Look Like?

For operators and deployers of high-risk AI systems, the EU AI Act requires:


1. Risk Management System
A continuous, documented process for identifying and mitigating risks throughout the AI system's entire lifecycle. Not a one-time assessment an ongoing program.


2. Data Governance
Training, validation, and testing data must meet quality criteria. Bias must be identified and mitigated. Data lineage must be documented. This is not optional.


3. Technical Documentation
Comprehensive documentation of how the AI system was designed, trained, what data it uses, how it performs, and how it was tested before it touches a single user.


4. Transparency and User Information
Users must be informed they are interacting with an AI system. High-risk systems must come with instructions for use. No black boxes without labels.


5. Human Oversight
High-risk AI cannot simply run autonomously without human oversight mechanisms. Businesses must design and implement meaningful controls allowing humans to monitor, intervene, or shut down the system.


6. Accuracy, Robustness, and Cybersecurity
AI systems must be designed to be resilient against attempts to alter their behavior including adversarial manipulation, data poisoning, and model theft. Yes, your AI has its own attack surface.


7. Conformity Assessment
Before deployment, certain high-risk systems must undergo formal conformity assessment either self-assessment or third-party audit and be registered in the EU database.


8. CE Marking
Compliant high-risk AI systems must bear CE marking before entering the EU market. This is not unlike CE marking for physical products.


The Penalties: Bigger Than You Think

Still thinking this might not apply to you, or that enforcement will be lax?


Consider the numbers:


  • €35 million or 7% of global annual turnover — whichever is higher for violations involving prohibited AI practices
  • €15 million or 3% of global annual turnover — for non-compliance with other obligations including high-risk AI requirements
  • €7.5 million or 1.5% of global annual turnover — for providing incorrect or misleading information to authorities


For context, GDPR's maximum fine is 4% of global turnover. The EU AI Act's top penalty is 7%.


Regulators across Europe have already stood up National Competent Authorities to enforce the Act. The EU AI Office, established within the European Commission, oversees general-purpose AI models and has broad investigative powers. This is not regulatory theater it is enforcement infrastructure.


The Intersection With Cybersecurity: Why Your CISO Needs to Own This Too

Here's something most AI Act guides won't tell you: EU AI Act compliance is not just a legal problem. It's a cybersecurity problem.


Article 15 of the Act explicitly requires that high-risk AI systems be resilient against cybersecurity threats including adversarial attacks designed to manipulate outputs, poisoning of training data, and exploitation of model vulnerabilities.


This means your security team needs to be involved in:


  • AI-specific threat modeling — What are the attack vectors against your AI system?
  • Model robustness testing — Can your AI be manipulated into making wrong decisions?
  • Data pipeline security — Is your training data protected from tampering?
  • Access controls and audit trails — Who can interact with your AI system, and is it logged?


The EU AI Act doesn't just ask "does your AI work?" It asks "can your AI be broken, fooled, or weaponized and what have you done to prevent that?"


If your current cybersecurity program doesn't include AI-specific controls, it's time to close that gap.


5 Immediate Steps Every Business Should Take Right Now

Whether you're just beginning to map your AI landscape or already mid-compliance journey, these five steps will move you in the right direction:


Step 1: Inventory your AI systems.
List every AI tool your business uses or deploys including third-party tools embedded in your products or operations. You cannot manage what you haven't mapped.


Step 2: Classify each system by risk tier.
Use the EU AI Act's criteria to determine whether each system is high-risk, limited-risk, or minimal-risk. When in doubt, treat it as high-risk until proven otherwise.


Step 3: Identify your role.
Are you a provider (you built the AI), a deployer (you use someone else's AI in your product or service), or both? Your obligations differ significantly depending on your role.


Step 4: Start documentation immediately.
Even if you're not compliant yet, starting your technical documentation and risk management records now demonstrates good faith and gives you a foundation to build on.


Step 5: Engage a compliance partner.
The EU AI Act intersects with GDPR, cybersecurity obligations, sector-specific regulations, and product liability law. Getting it right requires expertise that bridges legal, technical, and security domains.


The Bottom Line: AI Without Compliance Is a Liability, Not an Asset

AI is not going away. The competitive advantages it offers are real. But in 2026, deploying AI without governance is no longer just an ethical grey area it's a legal and financial risk that regulators are actively prepared to enforce.


The businesses that will lead in the AI era aren't just the ones that adopted AI fastest. They're the ones that built the governance, documentation, security controls, and oversight mechanisms to use it responsibly and prove it to regulators when asked.


The question isn't whether the EU AI Act applies to you.


The question is: how prepared are you to show that you're compliant?


How Vista Infosec Can Help You Navigate EU AI Act Compliance

At Vista Infosec, we sit at the intersection of cybersecurity and regulatory compliance which makes us uniquely positioned to help businesses tackle the EU AI Act head-on.


Our experts help organizations:


  • Conduct AI risk assessments to classify systems and identify compliance gaps
  • Build robust AI governance frameworks aligned with EU AI Act requirements
  • Align AI compliance with existing GDPR and ISO 27001 programs
  • Implement cybersecurity controls specifically designed for AI systems
  • Prepare technical documentation and conformity assessment readiness


You've invested in AI to grow your business. Let us make sure that investment doesn't become a regulatory liability.


Book afree consultation with Vista Infosec today and find out exactly where your AI compliance stands before the August 2026 deadline arrives.

EU AI Act's GPAI Rules Are Now Enforceable: What Changed on August 2, 2026 (And What Your Team Missed)

For twelve months, Brussels asked nicely. As of August 2, 2026 , it doesn't have to anymore. If your compliance team spent the summer c...