Sharpen CISO Logo

The EU AI Act, Explained: What Businesses Actually Need to Know

The EU AI Act is no longer a future regulation to prepare for. As of August 2026, most of it is already in force. It also applies far beyond companies headquartered in Europe. If your AI system’s output reaches someone in the EU, the regulation likely reaches you too.

That surprises a lot of teams. Many still treat the EU AI Act as a distant compliance project, something to revisit “closer to the deadline.” In practice, though, the deadlines have already started passing. More are coming through 2027.

This post breaks down what the regulation actually says. It covers how the EU AI Act classifies risk, what it bans outright, what it demands from high-risk systems, and what your team should be doing right now.

What Is the EU AI Act, Exactly?

Formally, it’s Regulation (EU) 2024/1689. It defines an AI system broadly. A machine-based system that operates with some autonomy, may adapt after deployment, and infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions all counts.

That definition matters because it’s intentionally wide. It covers everything from a resume-screening tool to a large generative model. It isn’t limited to headline-grabbing systems like facial recognition or autonomous vehicles.

Just as importantly, the EU AI Act reaches outside the EU’s borders. Say you place an AI system on the EU market, or its output gets used within the EU. Either way, you fall under scope. Location alone doesn’t exempt anyone, and neither does routing your AI infrastructure through a non-EU subsidiary.

The EU AI Act’s Risk-Based Approach

Rather than regulating every AI system the same way, the EU AI Act sorts systems into risk tiers. Each tier carries a different level of obligation.

At the top sits unacceptable risk: practices banned outright, with no compliance path available. Below that comes high-risk, meaning systems that stay on the market but only under strict obligations around risk management, documentation, and oversight. Below that sits limited risk, which mainly triggers transparency duties, such as disclosing that content was AI-generated. Everything else falls into minimal risk, where the regulation imposes no binding requirements at all.

This structure explains why compliance work looks so different from one AI use case to the next. A chatbot on a retail website faces a light touch. A tool used to screen job applicants faces a heavy one, even though both are technically “just AI.”

What’s Banned Outright Under the EU AI Act

Article 5 lists AI practices the EU AI Act prohibits entirely, regardless of sector or safeguards. These prohibitions have applied since February 2025, well ahead of the rest of the regulation.

Banned practices include AI systems that use subliminal or manipulative techniques to distort someone’s behavior in ways that cause harm. They also include systems that exploit vulnerabilities tied to a person’s age, disability, or economic situation. Social scoring by public or private actors is banned too. So is untargeted scraping of facial images from the internet or CCTV footage to build recognition databases.

A few other practices sit in this banned category with narrow carve-outs. Emotion recognition in workplaces and schools is prohibited, except for medical or safety purposes. Real-time remote biometric identification in public spaces for law enforcement is banned by default as well. A narrow exception exists for cases like searching for abduction victims or preventing an imminent terrorist threat. Even then, courts and strict safeguards apply before any deployment.

High-Risk AI Systems Carry the Heaviest Obligations

Annex III of the EU AI Act lists the areas where AI systems are automatically classified as high-risk. They include biometric identification and critical infrastructure. They also cover education and vocational training, employment and worker management, and access to essential public and private services. Law enforcement and migration and border control round out the list.

Falling into one of these categories doesn’t ban the system outright. Instead, it triggers a substantial compliance package. Providers must run a risk management process across the system’s lifecycle. They must maintain detailed technical documentation, ensure meaningful human oversight, and build in logging and traceability. Registration in an EU database is required too, before the system ever reaches deployment.

There’s a narrow exception worth knowing. A system that performs only a narrow procedural task, or one that merely improves on already-completed human work without replacing human judgment, may fall outside the high-risk category. But that exception has limits. Any system that profiles natural persons is automatically treated as high-risk, no matter how narrow its stated task looks.

General-Purpose AI Models Get Their Own Rules

Large generative models don’t fit neatly into the high-risk framework built around specific use cases. So the EU AI Act creates a separate track for general-purpose AI (GPAI) models instead.

All GPAI providers must maintain technical documentation. They also need to give downstream developers the information required to use the model responsibly. On top of that, providers must put a policy in place to comply with EU copyright law, including a summary of the content used to train the model.

Models presumed to carry systemic risk face additional duties. These include model evaluation, adversarial testing, incident reporting, and cybersecurity protections for the model itself. Open-source models get some relief from the transparency rules above. That relief disappears, however, the moment a model is considered to present systemic risk.

Transparency Obligations: Chatbots and Deepfakes

Article 50 covers systems that don’t reach high-risk status but still need to be honest with users about what they’re looking at.

Providers must ensure people know when they’re interacting with an AI system rather than a human. The exception is when that fact is already obvious from context. Separately, deployers of systems that generate deepfakes must disclose it too. A deepfake here means AI-manipulated image, audio, or video content that resembles a real person, place, or event.

These aren’t heavy obligations compared to the high-risk tier. Still, they’re easy to miss. That’s especially true for marketing or content teams experimenting with generative tools without security or legal in the loop.

The EU AI Act Timeline: What Applies When

The EU AI Act didn’t arrive all at once. It phases in across several dates, and by August 2026, most of those dates have already passed.

Prohibited practices under Article 5 became enforceable on 2 February 2025. That date also brought the general provisions and AI literacy obligations in Chapters I and II. Governance structures, GPAI obligations, and the penalty framework followed on 2 August 2025. Then, on 2 August 2026, the bulk of the regulation became applicable, including most high-risk system obligations under Annex III.

One piece still remains on the horizon. High-risk AI systems that serve as safety components of products already regulated under other EU harmonization law, think machinery or medical devices, get extra time. Article 6(1) and its corresponding obligations won’t apply to them until 2 August 2027.

Penalties: How Much Non-Compliance Actually Costs

The EU AI Act backs its obligations with real financial exposure. The amounts scale with the type of violation, not a flat penalty across the board.

Violating the Article 5 prohibitions carries the steepest penalty: fines up to €35 million, or 7% of global annual turnover, whichever is higher. Non-compliance with high-risk system obligations, transparency duties, or requirements for importers and distributors caps lower, at €15 million or 3% of turnover. Supplying incorrect or misleading information to regulators tops out at €7.5 million or 1% of turnover.

For SMEs and startups, each of those caps applies at whichever figure is lower, not higher. That softens the blow somewhat. Even so, regulators weigh factors like intent, cooperation, and harm caused when setting the actual fine. In other words, the ceiling isn’t the only number that matters.

How to Start Preparing

Given how much of the EU AI Act is already active, the practical question isn’t whether to prepare. It’s where to start.

Begin with an inventory. Map every AI system your organization builds, buys, or deploys. Don’t forget tools embedded in third-party software that teams may not even think of as “AI.” From there, classify each system against the risk tiers above, since that classification determines everything else about your obligations, from documentation depth to whether you can deploy the system at all.

If you already run an ISO 27001 or NIS2 compliance program, resist the urge to treat AI governance as a separate track. The EU AI Act’s risk management, documentation, and audit requirements overlap heavily with controls you likely already have in place. Extending an existing information security management system to cover AI systems and their data pipelines is far more efficient than building a parallel compliance silo from scratch. It also keeps a lean compliance team from drowning under yet another standalone framework.

For related reading, see your Secure by Design and Default guide, your Cyber Resilience Act compliance guide, and your ISO 27001 documentation checklist.

The Takeaway

The EU AI Act is no longer a regulation on the horizon; it’s current, active law for most AI systems on the EU market. Its prohibitions have been enforceable since early 2025. Its core obligations took effect in August 2026. Only one narrow category, embedded high-risk systems inside already-regulated products, still has runway left, until August 2027.

The fastest path forward is classification. Once you know which risk tier each of your AI systems falls into, the rest of the compliance work follows a clear, documented path from there.


Sources: Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex

 

 

AI Governance in Cybersecurity: The Gap Between Perceived Risk and Reality

One number sets the scene. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 87% of cybersecurity professionals now see AI-related risk as growing fast. That’s more than phishing. More than ransomware. More than classic software flaws. And it’s exposing a widening AI governance gap inside most organizations.

Yet another number tells a different story. Only 64% of organizations assess the security of an AI tool before deploying it. That share is improving. It stood at just 37% in 2025. But it still leaves more than a third of companies exposed to tools they’ve never truly vetted.

This gap isn’t a statistical footnote. It’s the new terrain CISOs must navigate in 2026, and it’s why AI governance is becoming a board-level topic.

The nature of the risk has shifted

A year ago, the dominant fear centered on AI’s offensive capabilities. Deepfakes, auto-generated malware, hyper-personalized phishing: it was the attacker who worried people most. In 2025, 47% of leaders named these adversarial capabilities as their top generative AI concern.

In 2026, that trend has flipped. The figure has dropped to 29%. Data leaks tied to generative AI now lead instead, cited by 34% of respondents, up from 22% the year before.

In other words, the fear no longer comes only from outside. It also comes from within. An employee pasting sensitive data into a public chatbot. An AI agent connected to a critical system, unsupervised. An internal model poorly segmented. The WEF confirms it: the “AI arms race” between attackers and defenders keeps intensifying. But attention is now shifting toward the unintended exposure of data.

A booming market, an AI governance lag

Gartner’s Hype Cycle for Cyber-Risk Management 2026 adds a complementary lens, this time from the market side. The AI-security tooling sector is expected to grow from $1.5 billion in 2025 to $16.5 billion by 2030. A staggering pace, and a clear sign of shared urgency.

But Gartner also flags a blind spot: shadow AI. Generative and agentic assistants are rolling out faster than the governance frameworks meant to contain them. The result is an attack surface expanding quietly, often off the CISO’s radar.

Another telling signal: data security governance is going through what Gartner calls a “trough of disillusionment.” Organizations struggle to deploy it. The culprits are fragmented data silos and underestimated operational complexity. Technology is outpacing the processes meant to keep it in check.

This shift shows up in the budgets too. By 2030, AI-enhanced security solutions are expected to account for more than half of the entire cybersecurity market, itself projected at $353 billion. Investment is following the threat. The question is whether governance can keep the same pace.

France adds its own layer of urgency: sovereignty

This global picture takes on a distinct tone in France. The CESIN cybersecurity barometer (wave 11, January 2026) is unambiguous on this point. 63% of French companies now say they’re concerned about digital sovereignty and trusted cloud. That’s up 11 points in a single year.

This shift matters. Securing AI isn’t just about picking the right tool. It also means knowing where data is hosted, under which jurisdiction, and with what real level of control. For French and European companies, sovereignty and AI governance are becoming inseparable — and a growing number are folding sovereignty checks directly into their ISO 27001 risk assessment process.

The same barometer points to confidence that remains fragile. 67% of respondents say they’re worried about their company’s ability to face cyber risk going forward, up from 63% in the previous wave. Vigilance is rising faster than reassurance.

Geopolitics is adding to the pressure

AI isn’t the only factor complicating the picture. The WEF finds that geopolitics remains, in 2026, the top factor shaping cyber risk strategies. 64% of organizations now factor in geopolitically motivated attacks: disruption of critical infrastructure, espionage.

This climate is also eroding executive confidence. Fewer than 45% of private-sector CEOs trust their country’s ability to respond to a major cyberattack. That uncertainty feeds, once again, the growing interest in digital sovereignty.

For French companies, geopolitics and cloud sovereignty are no longer separate topics. They reinforce each other. And together they fuel the same demand: regaining control over data, and over who handles it.

Why checklists aren’t enough for AI governance

Faced with this acceleration, the instinct is to respond with more controls. More policies, more committees, more manual sign-offs. The WEF warns against exactly this trap. Too many controls create friction. Teams end up working around the rules instead of following them.

The challenge, then, isn’t stacking up constraints. Effective AI governance keeps pace with the business instead of slowing it down. That calls for three things:

  • guardrails built in by design (security-by-design), rather than bolted on afterward;
  • continuous human oversight, especially for high-impact decisions;
  • near real-time monitoring, rather than periodic, backward-looking audits.

This is exactly the philosophy behind the “AI proposes, the CISO decides” approach. Artificial intelligence speeds up detection. It prioritizes risk. It automates repetitive compliance work. But the final call stays in human hands, especially when it touches a business risk or a regulatory obligation.

The link to the EU AI Act

This governance shift isn’t happening in a regulatory vacuum. The EU AI Act already imposes obligations on AI systems classified as high-risk: technical documentation, risk management, human oversight, decision traceability.

For a CISO, there’s good news here too. The AI Act’s requirements largely overlap with ISO 27001 and NIS2. They demand the same discipline: identify risks, document controls, prove compliance over time. Treating AI as an isolated compliance track means duplicating work already under way elsewhere.

The more effective approach is folding the AI Act into the same control mapping as other frameworks. One control plan, several regulations covered. That’s also what keeps a compliance team lean, even as regulatory requirements keep piling up.

AI governance that builds on what already exists

Good news for CISOs already running an ISO 27001 or NIS2 program: there’s no need to start from scratch. AI governance fits naturally into existing GRC processes.

An information security management system (ISMS) already covers most of the groundwork. Asset mapping, risk management, access control, vendor management: these building blocks already exist. It’s simply a matter of extending them to AI tools and their data pipelines, rather than building a parallel silo.

This continuity has a direct payoff. It avoids compliance fatigue. Teams work from a single map, where ISO 27001, NIS2, DORA, and the AI Act overlap and reinforce each other.

Where to start, concretely

A few priorities stand out from the 2026 data, for any CISO looking to structure a response now:

  • Map real AI usage, including tools not officially declared by business teams (shadow AI).
  • Extend vendor risk assessments to AI solution providers, with close attention to data location.
  • Document a pre-deployment validation process, even a lightweight one. The goal: close the gap between perceived risk (87%) and actual coverage (64%).
  • Prioritize human oversight on use cases with high business or regulatory impact.
  • Reassess the cloud supply chain in light of sovereignty concerns, now a priority for two-thirds of French companies.

None of these steps require an organizational big bang. They build on GRC fundamentals most companies already apply elsewhere — the same ones covered in our GRC practices checklist.

In summary: closing the AI governance gap

AI risk is no longer just a sophisticated external threat. It also lives in the everyday, often invisible uses of generative AI at work. The 2026 data leaves little doubt: perceived risk is rising faster than the AI governance meant to contain it.

Closing that gap doesn’t mean slowing AI adoption. It means applying the same rigor already used for information security. Mapping, risk assessment, continuous oversight. And a human decision that keeps the final word.

Want to assess how mature your organization’s AI governance really is? Talk to us about your specific context.


Sources cited: World Economic Forum; Gartner ; CESIN.