Key takeaways
- As of August 2026, the EU AI Act's transparency requirements officially became enforceable. But certain high-risk AI categories have extended deadlines.
- Organizations deploying, providing, or importing AI systems to the EU market are responsible for complying.
- Non-compliance can lead to significant fines.
The use of artificial intelligence has accelerated since Chat-GPT was released to the public in late 2022. Since then, organizations have moved quickly to integrate AI tools and features into an array of business processes.
In an effort to better govern the emerging technology and its access to data, the European Parliament and Council passed the European Union Artificial Intelligence Act (EU AI Act) in 2024. It marked the world’s first comprehensive AI regulation.
In August 2026, the EU AI Act became enforceable, meaning that businesses based in Europe or which do business in Europe are expected to follow certain obligations when bringing AI to market. Learn more about what the EU AI Act entails, who it affects, and why it's important.
What is the EU AI Act?
The EU AI Act creates a unified framework governing how AI systems are developed, deployed, and used across the EU. According to Chapter 1, Article 3, the Act defines "AI systems" as a machine that takes in information, figures out on its own how to respond, and produces results — like predictions, content, or decisions — that can shape what happens in both physical and virtual environments.
It prohibits certain harmful practices while imposing specific obligations on high-risk systems and general-purpose AI models. It also establishes transparency requirements, market surveillance and enforcement structures, and support measures to help organizations, especially start-ups, innovate within these new rules.
What is the goal of the EU AI Act?
The Act has two simultaneous goals: encourage organizations to innovate and develop trustworthy AI, while also protecting people's health, safety, and right to privacy. It also positions the EU as a leader in AI governance by mandating transparency requirements for all AI applications.
What went into effect in August 2026?
While much of the EU AI Act was set to go into effect in August 2026, the Council and European Parliament reached an agreement in May 2026 to push back deadlines for certain high-risk AI system categories.
What is now enforceable has to do with Article 50, which outlines transparency requirements and covers four areas:
- Chatbots and AI agents: Providers must disclose that users are engaging with AI, unless this is already obviouss
- Generative AI content: Providers must mark outputs (text, images, audio, video) in a machine-readable format so they're detectable as AI-generated or manipulated.
- Emotion recognition and biometric categorization: Deployers must inform people when they're exposed to these systems.
- Deepfakes and AI-generated public-interest content: Must be disclosed as artificially generated, unless it's gone through human editorial review with someone taking editorial responsibility.
What are the requirements of the EU AI Act?
The EU AI Act prohibits certain AI practices and outlines rules and responsibilities for deploying high-risk AI systems.
Prohibited AI practices
Prohibited AI practices became banned six months after the EU AI Act's entry in August 2024; however, there was a further delay regarding when organizations could be fined for violations. These went into effect in August 2025.
High-risk AI systems
The other major category has to do with high-risk AI systems, which went into effect in August 2026. High-risk AI systems are those that negatively affect safety or fundamental rights, and citizens will have the right to file complaints about these systems.
They are divided into two categories:
- AI systems used in products falling under the EU’s product safety legislation, including toys, aviation, cars, medical devices, and lifts
- AI systems falling into specific areas that will have to be registered in an EU database, including management and operation of critical infrastructure, education and vocational training, and migration, asylum, and border control management
Obligations overview
Articles 8 through 15 lay out the substantive compliance requirements that high-risk AI systems must meet before entering the EU market. These include:
- Compliance: Meet requirements per intended purpose; can integrate with existing certifications.
- Risk management: Continuous lifecycle risk identification and mitigation.
- Data governance: Quality, representative, bias-checked training data.
- Technical documentation: Pre-market compliance records (simplified for SMEs).
- Record-keeping: Automatic event logging for traceability.
- Transparency: Clear instructions so deployers understand outputs.
- Human oversight: Humans can monitor, override, or stop the system.
- Accuracy and security: Robust, accurate, cyberattack-resistant performance.
High-risk AI deadlines extended to 2027 and 2028
Providers of high-risk AI systems will need to be compliant by the following dates:
December 2, 2027: Annex III, which covers standalone, use-based systems like employment, credit scoring, law enforcement, and education.
August 2, 2028: Annex I, which covers AI embedded in already-regulated products like medical devices, machinery, and vehicles.
Obligations for gen AI systems
Generative AI tools like Microsoft 365 Copilot and ChatGPT are not classified as high risk, but they do require compliance with transparency requirements and EU copyright laws, which took effect in August 2026. This includes:
- Clearly disclosing when content is generated by AI so end users are aware
- Designing the model to prevent it from generating illegal content
- Publishing summaries of copyrighted data used for training
High-impact general-purpose AI models must pass thorough evaluations, and serious incidents must be reported to the European Commission.
Who does the EU AI Act impact?
The EU AI Act primarily affects three categories of business. The first are providers of high-risk AI systems in the EU, which means any organization that is developing AI. The second are deployers of high-risk AI systems in the EU, which means both people and organizations using AI for professional purposes. And the third is importers and distributors of high-risk AI systems, which means organizations that make an AI system available on the EU market. In all instances, the Act applies to any organization based or doing business in the EU.
There are two notable caveats. The Act excuses organizations from these regulations as they testing and refining an AI system. In other words, before it has gone to market and is accessible by other companies or people. And it also does not apply to AI systems and models designed and being used for scientific research and development.
Articles 16 through 27 outline the obligations that each category faces. Let's break it down in more detail.
Provider obligations
Providers are responsible for ensuring compliance, obtaining a CE mark before deploying an AI system, ensuring the system is a quality one, and providing technical documentation. They must also adhere to the following:
- Quality management system: Documented compliance, testing, and accountability processes
- Documentation keeping: Retain compliance records for 10 years.
- Automatically generated logs: Retain system logs for at least six months.
- Corrective actions: Fix, withdraw, or recall non-compliant systems.
- Cooperation with authorities: Respond to regulator requests and investigations.
- Authorized representatives: Non-EU providers must appoint an EU rep.
Deployer obligations
Deployers of high-risk systems have a responsibility to use the technology responsibly and must adhere to the following:
- Follow instructions: Use the system per the provider's instructions for use.
- Assign oversight: Designate qualified, trained personnel with authority to supervise the system.
- Control input data: Ensure input data is relevant and representative.
- Monitor operation: Track system performance, and suspend use and notify the provider and authorities if a risk emerges.
- Report serious incidents: Immediately notify the provider and then the authorities.
- Keep logs: Retain system-generated logs for at least six months.
- Inform workers: Notify employees and worker representatives before deploying AI in the workplace.
- Register (public bodies): Public authorities must register the system in the EU database before use.
- Support data protection assessments: Use provider-supplied information to fulfill GDPR/DPIA obligations.
- Special rules for biometric ID: Obtain prior judicial authorization for post-remote biometric identification in law enforcement. Document and report annually.
- Inform affected individuals: Tell people when a high-risk system is used in decisions affecting them.
- Cooperate with authorities: Assist regulators in enforcement actions related to the system.
What are the fines for non-compliance?
There are three tiers of fines for non-compliance.
1. Prohibited AI practices: Fines of up to €35,000,000 or seven percent of total worldwide annual turnover for the preceding financial year, whichever is higher.
2. Providers, deployers, importers, and distributors: Fines of up to €15,000,000 or up to three percent of annual worldwide turnover for companies.
3. Supplying incorrect, incomplete, or misleading information to the authorities: Fines of up to €7,500,000 or one percent of total worldwide turnover.
How Varonis can help with EU AI Act compliance
Complying with complex regulatory structures is challenging. With the introduction of the EU AI Act, the necessity for transparency and data security becomes even greater.
Varonis simplifies compliance management and provides real-time visibility and control over the critical data used by AI to help you comply with the EU AI Act in four critical ways:
- Securing the private and sensitive data ingested and produced by generative AI
- Providing complete visibility into AI prompts and responses, including indicating when sensitive data is accessed
- Alerting on threats and anomalies, including activity and behaviors that indicate misuse
- Automatically securing data, including revoking excessive access, correcting labels, and fixing misconfigurations, to reduce exposure and risk
We’ve also enabled thousands of enterprises to comply with regulations, including HIPAA, GDPR, CCPA, NIST, and ITAR.
Honestly, I don’t know how other agencies achieve compliance without a solution like Varonis. I think we’re doing a lot better than other organizations in the space, and Varonis supports that.
Security Admin, Healthcare Organization
Accelerating AI adoption for security teams
Our Data Security Platform’s wide range of security capabilities can accelerate your organization's AI adoption and deployment with complete visibility and control over tool permissions and workloads.
Ready to secure everything you build and run with AI?