









As of August 2, 2026, the EU AI Act has fully come into law. The new legislation outlines what organisations can and can’t do when it comes to AI systems.
An AI system is a machine-based system that is designed to operate with varying levels of autonomy and from the input it receives. It can generate outputs such as predictions, content recommendations or decisions that have the potential to influence physical or virtual environments.
You’ll see mentions of ‘downstream providers’ in the Act. These are the providers of an AI system – including a general-purpose AI (GPAI) system – which integrates an AI model, whether it was provided by themselves or a third-party.
It applies to public and private companies inside and outside of the EU. Confirm whether you should be following the rules by filling out the EU AI Act Compliance Checker.
The following types of AI system are prohibited:
High risk providers need to:
General Purpose AI is more likely to apply to a broader range of organisations. It covers AI models, including those trained on large datasets and are autonomous at scale. Note that it doesn’t cover AI models that are used before release on the market for research, development and prototyping activities.
A GPAI system refers to an AI system which is based on a general purpose AI model that can serve a variety of purposes for direct use and for integrations with other AI systems.
All providers of GPAI models must:
The key target here is imagery and text that looks authentic but isn’t:
Fines of up to €15 million (£12.8 million) or 3% of the company’s global turnover will be imposed for breaches, whichever is greater.
To enforce the Act, the European AI Office will be monitoring the implementation and compliance of GPAI model providers.
Downstream providers can file a complaint about infringement by upstream providers to the European AI Office.
The Office may do inspections of a GPAI model to:
Industry experts weigh in on what your organisation should be doing as a matter of urgency.
Peter Van Dyck, partner at A&O Shearman, has commented on the impact these rules will have on Big Tech and how they will be enforced in practice:
“Big Tech firms will need to adapt how they operate if they want to continue to do business in Europe. Due to the EU AI Act’s substantial extraterritorial reach, any lab with European customers now needs to be aware that if its model’s outputs reach EU users, it’s considered in scope. The most immediate obligation requirement is that all AI-generated content – synthetic text, images, audio, and video – is labelled as such.”
Ivana Bartoletti, global chief privacy & AI governance officer at Wipro, said:
“As the EU AI Act’s core transparency obligations take effect this week, organisations should stop treating this as paperwork and start treating it as design. Map the AI systems and content workflows you provide or use, build clear disclosures for deepfakes, machine-readable marking where required, and review processes with real accountability behind them.
“Governance by design is what makes innovation scalable, defensible and sustainable.”
Mark Molyneux, field CTO of Northern Europe at Commvault, said:
“Following Sunday’s ruling, companies with their own AI projects or those using external AI services should now assess to what extent the AI rules apply to them from a governance perspective and how they should rethink their existing concepts. For IT leaders and CISOs, the task is clear: they need to evolve their security model as quickly as AI adoption advances in their environment.
“A few immutable truths apply. Every AI agent should be treated as a privileged digital identity. Companies should continuously review what an AI agent can access instead of relying on assumptions. Anyone preparing for AI governance needs trusted data and a resilient AI infrastructure. Trust in AI must be continuously verified. Resilience is just as important in enabling rapid recovery, even when the best security controls are bypassed.”
The AI inventory is the EU AI Act artefact most teams underestimate – As part of the EU AI Act, organisations will need to implement an AI inventory. This is what you need to identify
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。