EU AI Act for security governance
The AI Act as consolidated on 27 July 2026: the scope test, obligations by article, the split high-risk timetable, and what security owns.
Compliance5 Sept 20269 min read
On this page
What it is
The AI Act is Regulation (EU) 2024/1689, laying down harmonised rules on artificial intelligence, published in the Official Journal of 12 July 2024. Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended it; every citation below is to the consolidated text of 27 July 2026 1.
It is drafted like product-safety law. It reaches providers placing systems or models on the Union market, and deployers established in the Union. It also reaches third-country operators whose output is used there, plus importers, distributors, product manufacturers and representatives 2.
Obligations scale with the tier: prohibited practices, Chapter III for high-risk systems, transparency duties, and a chapter for general-purpose AI models.
Who is in scope (decision test)
Six questions in order. The written answer is the record.
- AI system, or general-purpose AI model? A system infers from input how to generate predictions, content, recommendations or decisions; a model shows generality across tasks 3.
- Which role? Provider, deployer, importer, distributor and authorised representative are defined at Article 3; product manufacturers enter through Article 2(1); one system can carry two roles 4.
- Is the practice prohibited? The Omnibus added two points to Article 5(1): (ba), realistic intimate or sexually explicit material of an identifiable person made without explicit consent; (bb), material under Article 2, points (c) and (e), of Directive 2011/93/EU. Placing on the market is caught where that generation is the intended purpose, or foreseeable without safeguards. Use is caught only where the deployer uses the system for that purpose 5.
- Is it high-risk? Article 6(1) catches a system that is, or is a safety component of, an Annex I product needing third-party conformity assessment. Article 6(2) catches eight Annex III areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Article 6(3) carves out a system posing no significant risk, though profiling stays high-risk and the carve-out is documented 6.
- Does a transparency duty apply? Article 50 covers direct interaction, synthetic content marking, emotion recognition, biometric categorisation and deep fakes 7.
- Does a model carry systemic risk? High-impact capabilities are presumed above 10^25 floating point operations of training compute; the provider notifies the Commission 8.
| Outcome | What it means | Next step |
|---|---|---|
| Out of scope | No system, model, or an exclusion | Record the reason |
| Light duties | Article 4, plus Article 50 if applicable | Assign disclosure owners |
| High-risk or systemic-risk model | Chapter III, or Article 55 | Start now |
Obligations by article
Security-relevant paragraphs only.
| Article | Obligation | In practice | Evidence |
|---|---|---|---|
| Art. 4 | AI literacy for staff and others using systems on their behalf 9 | Sufficient level, none defined | Training record |
| Art. 9 | A risk management system, iterative across the lifecycle 10 | Fed by post-market data | Dated records |
| Art. 10, 11 | Data governance on data sets, and documentation to Annex IV 11 | Provenance is a control | Versioned records |
| Art. 12, 13 | Event recording, and instructions stating accuracy and cybersecurity 12 | Deployers depend on both | Logging design |
| Art. 14 | Oversight designed in and effective in use 13 | Automation bias is named | Oversight design |
| Art. 15 | Accuracy, robustness and cybersecurity; resilience against unauthorised alteration 14 | Named threats: "data poisoning", "model poisoning", "adversarial examples or model evasion", "confidentiality attacks", "model flaws" | Threat model |
| Art. 16, 17 | Twelve lettered provider duties, and a quality management system 15 | One owner per letter | Register; manual |
| Art. 25 | Re-branding or modification makes that party provider 16 | Substantial modification triggers it | Role decision |
| Art. 26 | Instructions followed; competent overseers; input-data control; monitoring; six-month logs; worker notice 17 | Suspend on Article 79(1) risk | Overseers; retention |
| Art. 27 | Impact assessment by public bodies, public-service providers, Annex III 5(b), 5(c) deployers 18 | Annex III point 2 excepted | Assessment |
| Art. 50 | Disclose interaction; mark synthetic content and deep fakes 19 | Due at first exposure | Marking build |
| Art. 53, 55 | Model documentation and copyright policy; for systemic risk, adversarial testing, incident tracking and adequate cybersecurity protection 20 | Red-teaming, by another name | Evaluations |
| Art. 72, 73 | Post-market monitoring on an Annex IV plan; incident reporting 21 | Three clocks, below | Timestamped filings |
The outer limit is 15 days after the provider or deployer becomes aware. A widespread infringement, or a serious incident under Article 3, point (49)(b), is reported within two days; where a person has died, within 10 days 22.
Dates (verified)
| Date | What happens | Source |
|---|---|---|
| 2024-08-01 | Entry into force, the twentieth day after publication | 23 |
| 2025-02-02 | Chapter I and Chapter II, less the new Article 5 points | 24 |
| 2025-08-02 | Chapter III Section 4, Chapters V, VII, XII, Article 78; not Article 101 | 25 |
| 2026-07-27 | Articles 102 to 110; the Omnibus enters into force three days after publication | 26; 27 |
| 2026-08-02 | General application | 28 |
| 2026-12-02 | Article 5(1) points (ba), (bb), and 5(1a), 5(1b); Article 50(2) for earlier generative systems | 29 |
| 2027-12-02 | Chapter III Sections 1 to 3 for Article 6(2) systems, less Article 6(5) | 30 |
| 2028-08-02 | The same for Article 6(1) systems | 31 |
The two tracks on one estate
The deferral split one timetable in two. One estate can carry an Article 6(2) deadline of 2 December 2027 for credit scoring, and an Article 6(1) deadline of 2 August 2028 for a safety component in a regulated product. Two dates, one inventory.
Little of the security work waits. The prohibitions already apply, and the two added points arrive on 2 December 2026, ahead of every high-risk date. Relief for systems already on the market is narrow: one is caught once its design changes significantly, and public-authority systems must comply by 2 August 2030 32.
The work to start has no deadline of its own: what is in use, who owns it, and what proves it. Six readiness items make that concrete. The inventory is done when every use case has an ID and a named owner. The role is done when provider or deployer is written down with its reason. The screen is done when every generative use has been checked against points (ba) and (bb). The threat baseline is done when the five Article 15(5) threats map to controls. Logging is done when six-month retention is set and tested. The incident route is done when one exercise has timed all three clocks.
Mapping to NIST AI RMF and ISO/IEC 42001
Names as published 33 and logged 34.
| AI Act | NIST AI RMF 1.0 | ISO/IEC 42001:2023 | Gap |
|---|---|---|---|
| Art. 4 | GOVERN 2 accountability structures | 5.2 AI policy | Not per system |
| Art. 6 | MAP 2 categorization performed | 4.4 AI management system | No legal tier or dates |
| Art. 9 | MEASURE 1 methods and metrics; MANAGE 1 risks prioritized | 8.2 AI risk assessment, 8.3 AI risk treatment | No lifecycle iteration |
| Art. 10 to 12 | MAP 3 capabilities; MAP 4 components | 7.5 Documented information | Annex IV list; no retention floor |
| Art. 14, 26 | MAP 3.5 oversight processes; GOVERN 3.2 human-AI configurations | 5.3 Roles, responsibilities and authorities | Competence as a test |
| Art. 15(5) | MEASURE 2.7 security and resilience evaluated | 8.2 AI risk assessment | The five named threats |
| Art. 27 | MAP 5 impacts characterized | 8.4 AI system impact assessment | Who must do it |
| Art. 72, 73 | MEASURE 3 risk tracking; MANAGE 4 response plans | 9.1 Monitoring, measurement, analysis and evaluation | The statutory clocks |
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1-2 | Inventory use cases, then decide provider or deployer per row | AI governance owner | Triage sheet; role decisions |
| 2 | Screen generative uses against Article 5 (ba), (bb) | Security officer | Pass or stop, dated |
| 3-4 | Classify against Article 6(1), 6(2), the carve-out | AI governance owner | Class per row, cited |
| 4-6 | Build the Article 15(5) threat baseline | Security architect role | Threat-to-control map |
| 5-7 | Set logging and retention per Article 12 and 26(6) | Platform engineering | Retention evidenced |
| 6-8 | Rehearse the Article 73 route on all clocks | Incident manager | Exercise report, timed |
| 8-12 | Confirm Article 50 marking, then plan both tracks | AI governance owner | Two-track plan |
References
- European Parliament and Council. Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026. CELEX 02024R1689-20260727. OJ L, 2024/1689, 12.7.2024. Read at the Cellar, 2026-09-05. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727
- European Parliament and Council. Regulation (EU) 2026/1744 (Digital Omnibus on AI). OJ L, 2026/1744, 24.7.2026. Read at the Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- NIST. AI Risk Management Framework (AI RMF 1.0). NIST AI 100-1. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- ISO/IEC 42001:2023. https://www.iso.org/standard/42001
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1EU Publications Office CELEX 02024R1689-20260727 header · verified 2026-09-05
- 2EU Publications Office CELEX 02024R1689-20260727 Art. 2(1) · verified 2026-09-05
- 3EU Publications Office CELEX 02024R1689-20260727 Art. 3(1) and 3(63) · verified 2026-09-05
- 4EU Publications Office CELEX 02024R1689-20260727 Art. 3(3) to 3(7) and Art. 2(1) · verified 2026-09-05
- 5EU Publications Office CELEX 02024R1689-20260727 Art. 5(1) and 5(1a) · verified 2026-09-05
- 6EU Publications Office CELEX 02024R1689-20260727 Art. 6(1) to 6(4) and Annex III · verified 2026-09-05
- 7EU Publications Office CELEX 02024R1689-20260727 Art. 50(1) to 50(4) · verified 2026-09-05
- 8EU Publications Office CELEX 02024R1689-20260727 Art. 51(1), 51(2) and 52(1) · verified 2026-09-05
- 9EU Publications Office CELEX 02024R1689-20260727 Art. 4(1) · verified 2026-09-05
- 10EU Publications Office CELEX 02024R1689-20260727 Art. 9(1) to 9(2) · verified 2026-09-05
- 11EU Publications Office CELEX 02024R1689-20260727 Art. 10(2), Art. 11(1) and Annex IV · verified 2026-09-05
- 12EU Publications Office CELEX 02024R1689-20260727 Art. 12(1) to 12(2) and Art. 13(2) to 13(3) · verified 2026-09-05
- 13EU Publications Office CELEX 02024R1689-20260727 Art. 14(1) to 14(4) · verified 2026-09-05
- 14EU Publications Office CELEX 02024R1689-20260727 Art. 15(1) and 15(5) · verified 2026-09-05
- 15EU Publications Office CELEX 02024R1689-20260727 Art. 16 and Art. 17(1) · verified 2026-09-05
- 16EU Publications Office CELEX 02024R1689-20260727 Art. 25(1) · verified 2026-09-05
- 17EU Publications Office CELEX 02024R1689-20260727 Art. 26(1) to 26(7) · verified 2026-09-05
- 18EU Publications Office CELEX 02024R1689-20260727 Art. 27(1) · verified 2026-09-05
- 19EU Publications Office CELEX 02024R1689-20260727 Art. 50(1) to 50(5) · verified 2026-09-05
- 20EU Publications Office CELEX 02024R1689-20260727 Art. 53(1) and Art. 55(1) · verified 2026-09-05
- 21EU Publications Office CELEX 02024R1689-20260727 Art. 72(1) to 72(3) and Art. 73(1) to 73(2) · verified 2026-09-05
- 22EU Publications Office CELEX 02024R1689-20260727 Art. 73(2) to 73(4) · verified 2026-09-05
- 23EU Publications Office CELEX 02024R1689-20260727 Art. 113 first paragraph · verified 2026-09-05
- 24EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (a) · verified 2026-09-05
- 25EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (b) · verified 2026-09-05
- 26EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (d) · verified 2026-09-05
- 27EU Publications Office CELEX 32026R1744 Art. 4 · verified 2026-09-05
- 28EU Publications Office CELEX 02024R1689-20260727 Art. 113 second paragraph · verified 2026-09-05
- 29EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (a) and Art. 111(4) · verified 2026-09-05
- 30EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(i) · verified 2026-09-05
- 31EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(ii) · verified 2026-09-05
- 32EU Publications Office CELEX 02024R1689-20260727 Art. 111(2) · verified 2026-09-05
- 33NIST AI 100-1 §5.1 to §5.4, nvlpubs.nist.gov · verified 2026-09-05
- 34ISO OBP, ISO/IEC 42001:2023 clause titles 4 to 10 · verified 2026-09-03
Related
- AI use-case triage form
Template
- Findings-to-closure tracker template
Template
- Running the external audit
Playbook