惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
S
SegmentFault 最新的问题
N
Netflix TechBlog - Medium
B
Blog
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 聂微东
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
V2EX
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
大猫的无限游戏
大猫的无限游戏
U
Unit 42
J
Java Code Geeks
IT之家
IT之家
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
T
The Blog of Author Tim Ferriss
博客园 - 【当耐特】
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
腾讯CDC

Information Age

Rethinking what scale means in an era of scarcity - Information Age Stop fixating on cyber tactics and start disrupting attacker behaviour - Information Age When security teams step away, attackers step in - Information Age 5 ways AI is rewriting the rules of enterprise storage security - Information Age Is the SaaSpocalypse already over? - Information Age Stopping bad data from becoming bad business - Information Age Google I/O 2026 shows why enterprise AI governance needs an operating model Moving off the cloud – how to get repatriation right The AI inventory is the EU AI Act artefact most teams underestimate From speed to safety – how regulation is reshaping DevOps Why every organisation needs a minimum viable company strategy Quantum is coming. Here’s what CTOs can be doing today Small Language Models (SLMs) as the gold standard for trust in AI Your employees are waiting for your change programme to blow over How technical debt turns your IT infrastructure into a game you can’t win The business mobility trends driving workforce performance in 2026 Four actions CIOs must take to turn innovation into impact Eliminating blind spots – nailing the IPv6 transition Goodbye Software as a Service, Hello AI as a Service Smart auto-tiering vs. data reduction – logical efficiency vs. architectural efficiency The value of reducing middle office emissions for ESG How to match tech investment with real-world output
What the EU AI Act means for your organisation - Informat...
Anna Jordan · 2026-08-04 · via Information Age

As of August 2, 2026, the EU AI Act has fully come into law. The new legislation outlines what organisations can and can’t do when it comes to AI systems.

What is an AI system?

An AI system is a machine-based system that is designed to operate with varying levels of autonomy and from the input it receives. It can generate outputs such as predictions, content recommendations or decisions that have the potential to influence physical or virtual environments.

You’ll see mentions of ‘downstream providers’ in the Act. These are the providers of an AI system – including a general-purpose AI (GPAI) system – which integrates an AI model, whether it was provided by themselves or a third-party.

Who does it apply to?

It applies to public and private companies inside and outside of the EU. Confirm whether you should be following the rules by filling out the EU AI Act Compliance Checker.  

What rules do I need to know?

The following types of AI system are prohibited:

  • Deploying subliminal, manipulative or deceptive techniques to distort behaviour and impair decision-making, ‘causing significant harm’
  • Exploiting vulnerabilities based on age, disability or socioeconomic circumstances to distort behaviour, again, causing significant harm
  • Biometric categorisation systems inferring sensitive attributes (race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation), except filtering or labelling of lawfully acquired biometric datasets or when law enforcement categorises biometric data
  • Social scoring, in other words, evaluating or classifying individuals based on social behaviour or personality traits, causing detrimental or unfavourable treatment of these people
  • Assessing the risk of someone committing criminal offences solely based on profile or personality traits, except when used to augment human assessments based on objective, verifiable facts directly linked to criminal activity
  • Compiling facial recognition databases by untargeted scraping of facial images from the internet or CCTV
  • Inferring emotions in workplaces or educational institutions except for medical and safety reasons
  • Real-time biometric identification in publicly accessible spaces for law enforcement

High risk providers need to:

  • Establish a risk management system throughout the high-risk AI system’s lifecycle
  • Conduct data governance
  • Draw up technical documentation to approve compliance and provide authorities with the means to approve that compliance
  • Design their high-risk system for automatic record-keeping
  • Provide instructions for use for ‘downstream deployers’
  • Design high-risk systems to allow human oversight, while achieving robustness, accuracy and cybersecurity
  • Establish quality management systems to ensure compliance

General Purpose AI is more likely to apply to a broader range of organisations. It covers AI models, including those trained on large datasets and are autonomous at scale. Note that it doesn’t cover AI models that are used before release on the market for research, development and prototyping activities.

A GPAI system refers to an AI system which is based on a general purpose AI model that can serve a variety of purposes for direct use and for integrations with other AI systems.

All providers of GPAI models must:

  • Create technical documentation, including training and testing process and evaluation results
  • Compile information and documents to give to downstream providers that want to integrate the GPAI model into their own AI system so that they understand what can and can’t do as well as being able to comply
  • Establish a policy to respect the Copyright Directive
  • Publish a detailed summary about the content used for training the GPAI model

What about Article 50?

The key target here is imagery and text that looks authentic but isn’t:

  • Artificially generated images, audio and text designed to look authentic must be labelled
  • Customers must know that they are interacting with chatbots or viewing images or text manipulated by AI.
  • Media must have a machine-readable watermark to show origins of content (due to an omnibus, existing AI systems have until December 2, 2026 to meet this requirement)
  • Texts on matters of public interest must be labelled as AI if there hasn’t been any human editorial oversight
  • Should be labelling existing content as AI, but this is not compulsory

Fines of up to €15 million (£12.8 million) or 3% of the company’s global turnover will be imposed for breaches, whichever is greater.

How will the AI Act be implemented?

To enforce the Act, the European AI Office will be monitoring the implementation and compliance of GPAI model providers.

Downstream providers can file a complaint about infringement by upstream providers to the European AI Office.

The Office may do inspections of a GPAI model to:

  • Judge whether compliance is being met where the information gathered under its powers to request information isn’t enough
  • Investigate systemic risks, particularly following a qualified report from the scientific panel of independent experts

What can I do about this?

Industry experts weigh in on what your organisation should be doing as a matter of urgency.

Tech firms

Peter Van Dyck, partner at A&O Shearman, has commented on the impact these rules will have on Big Tech and how they will be enforced in practice:

“Big Tech firms will need to adapt how they operate if they want to continue to do business in Europe. Due to the EU AI Act’s substantial extraterritorial reach, any lab with European customers now needs to be aware that if its model’s outputs reach EU users, it’s considered in scope. The most immediate obligation requirement is that all AI-generated content – synthetic text, images, audio, and video – is labelled as such.”

Get your governance in line now

Ivana Bartoletti, global chief privacy & AI governance officer at Wipro, said:

“As the EU AI Act’s core transparency obligations take effect this week, organisations should stop treating this as paperwork and start treating it as design. Map the AI systems and content workflows you provide or use, build clear disclosures for deepfakes, machine-readable marking where required, and review processes with real accountability behind them.

“Governance by design is what makes innovation scalable, defensible and sustainable.”

Establish how much the rules apply to you

Mark Molyneux, field CTO of Northern Europe at Commvault, said: 

“Following Sunday’s ruling, companies with their own AI projects or those using external AI services should now assess to what extent the AI rules apply to them from a governance perspective and how they should rethink their existing concepts. For IT leaders and CISOs, the task is clear: they need to evolve their security model as quickly as AI adoption advances in their environment. 

“A few immutable truths apply. Every AI agent should be treated as a privileged digital identity. Companies should continuously review what an AI agent can access instead of relying on assumptions. Anyone preparing for AI governance needs trusted data and a resilient AI infrastructure. Trust in AI must be continuously verified. Resilience is just as important in enabling rapid recovery, even when the best security controls are bypassed.”

Read more

The AI inventory is the EU AI Act artefact most teams underestimate – As part of the EU AI Act, organisations will need to implement an AI inventory. This is what you need to identify