444 days left
AI Act
The AI Act reaches anyone who places an AI system on the EU market or puts one into service — including an organisation that buys one and uses it. For police, border and critical-infrastructure work it is the regime that decides what may be deployed at all.
Which tier you are in
The Act sorts systems by risk rather than by technology. A handful of practices are prohibited outright. A much larger group is high-risk, and that is where the real obligations sit: risk management, data governance, logging, human oversight, accuracy and robustness, technical documentation and a conformity assessment before the system goes into use. Everything else carries only transparency duties. Most organisations discover they are a deployer of a high-risk system rather than a provider of one, which is a lighter set of duties but not an empty one.
High-risk uses that matter in this market
- Biometric identification and categorisation of people
- Safety components of critical infrastructure — water, energy, transport
- Law enforcement: risk assessment, evidence evaluation, profiling
- Migration, asylum and border control
- Employment: recruitment, task allocation, monitoring
- Access to essential public and private services
Where it meets the rest of this page
- Accuracy, robustness and cybersecurity are an explicit high-risk requirement — the same evidence NIS2 asks for
- An AI system inside a product also falls under the CRA
- Training data pulls GDPR and ZVOP-2 in with it
- A supplier's AI component becomes your supply-chain risk
THE DATES
Where this stands today
-
AI Act enters into force
-
Prohibited practices and AI-literacy duties apply
-
General-purpose AI model obligations apply
-
Transparency obligations apply
-
High-risk obligations apply — moved by the Digital Omnibus
-
Remaining high-risk obligations apply
What it actually requires
- An inventory: which AI systems you provide, and which you merely use
- A tier decision per system, written down, with the reasoning
- Human oversight that a person can actually exercise, not a checkbox
- Logging sufficient to reconstruct a decision months later
- AI literacy for the staff operating the system — already applicable
- Cybersecurity and robustness testing of the model, not only of the network around it
What it costs to get wrong
Up to €35 million or 7% of worldwide annual turnover for a prohibited practice — the highest ceiling in EU digital law, above even the GDPR. High-risk breaches reach €15 million or 3%, and supplying incorrect information to an authority €7.5 million or 1%. For a public body procuring a system, the sharper risk is not the fine but the deployment being stopped.
WHAT WE DO ABOUT IT
The services that close this gap
Not the whole catalogue — these are the ones that map onto the obligations above. If something here is already covered internally, say so and we will scope around it.
Chief Information Security Officer
A security executive on subscription: policy, risk register, board reporting and the evidence an auditor asks for — without a six-figure hire.
Read more PenTestPenetration testing
A real attack, run by people who have done it for a living, ending in a report your engineers can act on and your auditor will accept.
Read more TPRMaaSThird-party risk management
Your suppliers are your attack surface, and under NIS2 they are also your legal responsibility. We inventory them, rate them and keep watching.
Read moreNot sure whether AI Act applies to you?
Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.