Back to briefings
    Briefing

    EU AI Act for security governance

    The AI Act as consolidated on 27 July 2026: the scope test, obligations by article, the split high-risk timetable, and what security owns.

    Compliance5 Sept 20269 min read

    ISO/IEC 42001:2023NIST AI 100-1Regulation (EU) 2024/1689
    On this page

    What it is

    The AI Act is Regulation (EU) 2024/1689, laying down harmonised rules on artificial intelligence, published in the Official Journal of 12 July 2024. Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended it; every citation below is to the consolidated text of 27 July 2026 1.

    It is drafted like product-safety law. It reaches providers placing systems or models on the Union market, and deployers established in the Union. It also reaches third-country operators whose output is used there, plus importers, distributors, product manufacturers and representatives 2.

    Obligations scale with the tier: prohibited practices, Chapter III for high-risk systems, transparency duties, and a chapter for general-purpose AI models.

    Who is in scope (decision test)

    Six questions in order. The written answer is the record.

    1. AI system, or general-purpose AI model? A system infers from input how to generate predictions, content, recommendations or decisions; a model shows generality across tasks 3.
    2. Which role? Provider, deployer, importer, distributor and authorised representative are defined at Article 3; product manufacturers enter through Article 2(1); one system can carry two roles 4.
    3. Is the practice prohibited? The Omnibus added two points to Article 5(1): (ba), realistic intimate or sexually explicit material of an identifiable person made without explicit consent; (bb), material under Article 2, points (c) and (e), of Directive 2011/93/EU. Placing on the market is caught where that generation is the intended purpose, or foreseeable without safeguards. Use is caught only where the deployer uses the system for that purpose 5.
    4. Is it high-risk? Article 6(1) catches a system that is, or is a safety component of, an Annex I product needing third-party conformity assessment. Article 6(2) catches eight Annex III areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Article 6(3) carves out a system posing no significant risk, though profiling stays high-risk and the carve-out is documented 6.
    5. Does a transparency duty apply? Article 50 covers direct interaction, synthetic content marking, emotion recognition, biometric categorisation and deep fakes 7.
    6. Does a model carry systemic risk? High-impact capabilities are presumed above 10^25 floating point operations of training compute; the provider notifies the Commission 8.
    OutcomeWhat it meansNext step
    Out of scopeNo system, model, or an exclusionRecord the reason
    Light dutiesArticle 4, plus Article 50 if applicableAssign disclosure owners
    High-risk or systemic-risk modelChapter III, or Article 55Start now

    Obligations by article

    Security-relevant paragraphs only.

    ArticleObligationIn practiceEvidence
    Art. 4AI literacy for staff and others using systems on their behalf 9Sufficient level, none definedTraining record
    Art. 9A risk management system, iterative across the lifecycle 10Fed by post-market dataDated records
    Art. 10, 11Data governance on data sets, and documentation to Annex IV 11Provenance is a controlVersioned records
    Art. 12, 13Event recording, and instructions stating accuracy and cybersecurity 12Deployers depend on bothLogging design
    Art. 14Oversight designed in and effective in use 13Automation bias is namedOversight design
    Art. 15Accuracy, robustness and cybersecurity; resilience against unauthorised alteration 14Named threats: "data poisoning", "model poisoning", "adversarial examples or model evasion", "confidentiality attacks", "model flaws"Threat model
    Art. 16, 17Twelve lettered provider duties, and a quality management system 15One owner per letterRegister; manual
    Art. 25Re-branding or modification makes that party provider 16Substantial modification triggers itRole decision
    Art. 26Instructions followed; competent overseers; input-data control; monitoring; six-month logs; worker notice 17Suspend on Article 79(1) riskOverseers; retention
    Art. 27Impact assessment by public bodies, public-service providers, Annex III 5(b), 5(c) deployers 18Annex III point 2 exceptedAssessment
    Art. 50Disclose interaction; mark synthetic content and deep fakes 19Due at first exposureMarking build
    Art. 53, 55Model documentation and copyright policy; for systemic risk, adversarial testing, incident tracking and adequate cybersecurity protection 20Red-teaming, by another nameEvaluations
    Art. 72, 73Post-market monitoring on an Annex IV plan; incident reporting 21Three clocks, belowTimestamped filings

    The outer limit is 15 days after the provider or deployer becomes aware. A widespread infringement, or a serious incident under Article 3, point (49)(b), is reported within two days; where a person has died, within 10 days 22.

    Dates (verified)

    DateWhat happensSource
    2024-08-01Entry into force, the twentieth day after publication23
    2025-02-02Chapter I and Chapter II, less the new Article 5 points24
    2025-08-02Chapter III Section 4, Chapters V, VII, XII, Article 78; not Article 10125
    2026-07-27Articles 102 to 110; the Omnibus enters into force three days after publication26; 27
    2026-08-02General application28
    2026-12-02Article 5(1) points (ba), (bb), and 5(1a), 5(1b); Article 50(2) for earlier generative systems29
    2027-12-02Chapter III Sections 1 to 3 for Article 6(2) systems, less Article 6(5)30
    2028-08-02The same for Article 6(1) systems31

    The two tracks on one estate

    The deferral split one timetable in two. One estate can carry an Article 6(2) deadline of 2 December 2027 for credit scoring, and an Article 6(1) deadline of 2 August 2028 for a safety component in a regulated product. Two dates, one inventory.

    Little of the security work waits. The prohibitions already apply, and the two added points arrive on 2 December 2026, ahead of every high-risk date. Relief for systems already on the market is narrow: one is caught once its design changes significantly, and public-authority systems must comply by 2 August 2030 32.

    The work to start has no deadline of its own: what is in use, who owns it, and what proves it. Six readiness items make that concrete. The inventory is done when every use case has an ID and a named owner. The role is done when provider or deployer is written down with its reason. The screen is done when every generative use has been checked against points (ba) and (bb). The threat baseline is done when the five Article 15(5) threats map to controls. Logging is done when six-month retention is set and tested. The incident route is done when one exercise has timed all three clocks.

    Mapping to NIST AI RMF and ISO/IEC 42001

    Names as published 33 and logged 34.

    AI ActNIST AI RMF 1.0ISO/IEC 42001:2023Gap
    Art. 4GOVERN 2 accountability structures5.2 AI policyNot per system
    Art. 6MAP 2 categorization performed4.4 AI management systemNo legal tier or dates
    Art. 9MEASURE 1 methods and metrics; MANAGE 1 risks prioritized8.2 AI risk assessment, 8.3 AI risk treatmentNo lifecycle iteration
    Art. 10 to 12MAP 3 capabilities; MAP 4 components7.5 Documented informationAnnex IV list; no retention floor
    Art. 14, 26MAP 3.5 oversight processes; GOVERN 3.2 human-AI configurations5.3 Roles, responsibilities and authoritiesCompetence as a test
    Art. 15(5)MEASURE 2.7 security and resilience evaluated8.2 AI risk assessmentThe five named threats
    Art. 27MAP 5 impacts characterized8.4 AI system impact assessmentWho must do it
    Art. 72, 73MEASURE 3 risk tracking; MANAGE 4 response plans9.1 Monitoring, measurement, analysis and evaluationThe statutory clocks

    Next 90 days

    WeekActionOwnerOutput
    1-2Inventory use cases, then decide provider or deployer per rowAI governance ownerTriage sheet; role decisions
    2Screen generative uses against Article 5 (ba), (bb)Security officerPass or stop, dated
    3-4Classify against Article 6(1), 6(2), the carve-outAI governance ownerClass per row, cited
    4-6Build the Article 15(5) threat baselineSecurity architect roleThreat-to-control map
    5-7Set logging and retention per Article 12 and 26(6)Platform engineeringRetention evidenced
    6-8Rehearse the Article 73 route on all clocksIncident managerExercise report, timed
    8-12Confirm Article 50 marking, then plan both tracksAI governance ownerTwo-track plan

    References

    1. European Parliament and Council. Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026. CELEX 02024R1689-20260727. OJ L, 2024/1689, 12.7.2024. Read at the Cellar, 2026-09-05. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727
    2. European Parliament and Council. Regulation (EU) 2026/1744 (Digital Omnibus on AI). OJ L, 2026/1744, 24.7.2026. Read at the Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
    3. NIST. AI Risk Management Framework (AI RMF 1.0). NIST AI 100-1. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
    4. ISO/IEC 42001:2023. https://www.iso.org/standard/42001

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1EU Publications Office CELEX 02024R1689-20260727 header · verified 2026-09-05
    2. 2EU Publications Office CELEX 02024R1689-20260727 Art. 2(1) · verified 2026-09-05
    3. 3EU Publications Office CELEX 02024R1689-20260727 Art. 3(1) and 3(63) · verified 2026-09-05
    4. 4EU Publications Office CELEX 02024R1689-20260727 Art. 3(3) to 3(7) and Art. 2(1) · verified 2026-09-05
    5. 5EU Publications Office CELEX 02024R1689-20260727 Art. 5(1) and 5(1a) · verified 2026-09-05
    6. 6EU Publications Office CELEX 02024R1689-20260727 Art. 6(1) to 6(4) and Annex III · verified 2026-09-05
    7. 7EU Publications Office CELEX 02024R1689-20260727 Art. 50(1) to 50(4) · verified 2026-09-05
    8. 8EU Publications Office CELEX 02024R1689-20260727 Art. 51(1), 51(2) and 52(1) · verified 2026-09-05
    9. 9EU Publications Office CELEX 02024R1689-20260727 Art. 4(1) · verified 2026-09-05
    10. 10EU Publications Office CELEX 02024R1689-20260727 Art. 9(1) to 9(2) · verified 2026-09-05
    11. 11EU Publications Office CELEX 02024R1689-20260727 Art. 10(2), Art. 11(1) and Annex IV · verified 2026-09-05
    12. 12EU Publications Office CELEX 02024R1689-20260727 Art. 12(1) to 12(2) and Art. 13(2) to 13(3) · verified 2026-09-05
    13. 13EU Publications Office CELEX 02024R1689-20260727 Art. 14(1) to 14(4) · verified 2026-09-05
    14. 14EU Publications Office CELEX 02024R1689-20260727 Art. 15(1) and 15(5) · verified 2026-09-05
    15. 15EU Publications Office CELEX 02024R1689-20260727 Art. 16 and Art. 17(1) · verified 2026-09-05
    16. 16EU Publications Office CELEX 02024R1689-20260727 Art. 25(1) · verified 2026-09-05
    17. 17EU Publications Office CELEX 02024R1689-20260727 Art. 26(1) to 26(7) · verified 2026-09-05
    18. 18EU Publications Office CELEX 02024R1689-20260727 Art. 27(1) · verified 2026-09-05
    19. 19EU Publications Office CELEX 02024R1689-20260727 Art. 50(1) to 50(5) · verified 2026-09-05
    20. 20EU Publications Office CELEX 02024R1689-20260727 Art. 53(1) and Art. 55(1) · verified 2026-09-05
    21. 21EU Publications Office CELEX 02024R1689-20260727 Art. 72(1) to 72(3) and Art. 73(1) to 73(2) · verified 2026-09-05
    22. 22EU Publications Office CELEX 02024R1689-20260727 Art. 73(2) to 73(4) · verified 2026-09-05
    23. 23EU Publications Office CELEX 02024R1689-20260727 Art. 113 first paragraph · verified 2026-09-05
    24. 24EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (a) · verified 2026-09-05
    25. 25EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (b) · verified 2026-09-05
    26. 26EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (d) · verified 2026-09-05
    27. 27EU Publications Office CELEX 32026R1744 Art. 4 · verified 2026-09-05
    28. 28EU Publications Office CELEX 02024R1689-20260727 Art. 113 second paragraph · verified 2026-09-05
    29. 29EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (a) and Art. 111(4) · verified 2026-09-05
    30. 30EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(i) · verified 2026-09-05
    31. 31EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(ii) · verified 2026-09-05
    32. 32EU Publications Office CELEX 02024R1689-20260727 Art. 111(2) · verified 2026-09-05
    33. 33NIST AI 100-1 §5.1 to §5.4, nvlpubs.nist.gov · verified 2026-09-05
    34. 34ISO OBP, ISO/IEC 42001:2023 clause titles 4 to 10 · verified 2026-09-03