Although some provisions of the AI Act have been in force since 2025 – including prohibitions on unacceptable practices and regulations on general AI models (GPAI) – the key moment for many organizations falls on August 2, 2026. From this date, all entities operating in the European Union that offer or use high-risk artificial intelligence systems must meet the detailed requirements arising from the AI Act.
These responsibilities are not limited to legal departments – they include CISO, IT, security, compliance and board teams. Negligence may lead to severe sanctions: up to EUR 35 million or 7% of global turnover for the use of prohibited practices (e.g. behavioral manipulation, social scoring) and up to EUR 15 million or 3% for other non-compliance.
In this article, we show you how toachieve compliance with the AI Act – with an emphasis onkey actions in 2026.
What is the AI Act and who does it apply to?
What is the AI Act?
AI Act is a regulation adopted by the European Union in order tocreate uniform rules for the design, implementation and supervision of artificial intelligence systems. It is directly applicable in all member states – like the GDPR – and covers both companies operating inside and outside the EU if their AI systems impact users in the EU.
The AI Act is not limited to classic AI models. It also includes modern generative systems, autonomous agents, and even tools used only internally (e.g. for HR, finance or IT). In practice, if your organization uses any AI solution – even experimentally – the regulations apply.
What are the main goals of the AI Act?
The AI Act has one overarching goal – to increase trust in artificial intelligence. It does this through specific requirements regarding the security of systems, the transparency of their operation and the protection of users’ fundamental rights. In practice, this means, among others:
- Establish a single legal framework for AI systems across the EU – to prevent regulatory fragmentation and ensure a consistent approach across the EU.
- Promoting trust and human-centric AI – i.e. artificial intelligence that is understandable, transparent and consistent with EU values.
- Protection against the harmful effects of AI systems – including: by prohibiting the use of manipulative, subliminal techniques or social scoring systems.
- Supporting innovation – including: by creating regulatory sandboxes, i.e. test environments in which new systems can be developed under the supervision of authorities.
What do the provisions of the AI Act cover and who do they apply to?
The AI Act Regulation covers awide range of entities involved in the lifecycle of artificial intelligence systems, regardless of whether they operate in the European Union or offer their services to users in the EU. Obligations arising from the AI Act concern in particular:
- AI system suppliers – i.e. entities that create, develop or integrate AI models.
- AI system users – organizations using AI to achieve business goals (e.g. process automation, recruitment, data analysis).
- Distributors and importers – who introduce AI systems to the EU market.
- Entities in the supply chain – that modify, adapt or implement AI models, even if they are not their creators.
The scope of responsibilities depends on the level of risk assigned to a given system – the higher the risk, the more stringent the supervision, documentation and compliance requirements. You can read in detail about high-risk systems in the next part of the article.
AI Act checklist for CISOs:
High-risk AI systems
Schedule for implementation of AI Act provisions
The AI Act formally entered into force on August 1, 2024, but the provisions will be implemented in stages – giving organizations time to prepare for compliance and implement necessary changes to AI systems, documentation and operational processes.
AI Act key dates
- August 2, 2024 – AI Act enters into force. A transitional period begins, but no specific requirements apply yet.
- February 2, 2025 – the so-called bans come into force. unacceptable uses of AI (e.g. social scoring systems, behavioral manipulation, emotion recognition). Obligation to implement AI Literacy training.
- August 2, 2025 – first wave of obligations for suppliers of general-purpose models, including generative models:
- technical documentation,
- compliance policy,
- information obligations,
- publication of summaries of teaching content,
- copyright compliance.
- February 2, 2026 – The European Commission will publish guidelines on monitoring AI systems after they are placed on the market.
- August 2, 2026– requirements for high-risk systems specified in Annex III of the AI Act come into force (including AI in recruitment, lending, health care, education, critical infrastructure, law enforcement). Requirements include conformity assessment, classification, documentation, registration and supervision of AI systems. On this date, the obligations to mark the AI system with the CE mark, prepare the EU declaration of conformity and register it in the EU database also become active.
What next?
- August 2, 2027 – the regulations will also cover high-risk systems not listed in Annex III. In practice, this means that also proprietary and non-standard solutions – e.g. AI models used in predictive analyzes, HR process automation, or risk management – may fall under the obligations of the AI Act if they meet the risk criteria.
- August 2, 2028 – first assessment of the effectiveness of the AI Act by the European Commission.
- August 2, 2029 – review of the application of the regulation, which may lead to its amendment.
- August 2, 2030 – obligation of full compliance of high-risk AI systems used by public administration bodies.
- August 2, 2031 – The European Commission will present a report on the general assessment of the implementation of the AI Act.
Why are the years 2026-2027 crucial for CISOs in the context of the AI Act?
It is during these two years that themost operational obligations come into force for organizations using AI – both for high-risk Annex III models and non-standard solutions. Companies must be ready not only to comply with the AI Act in terms of new implementations, but also to audit and adapt all existing systems that will be classified as high-risk systems under Art. 6 section 1 or are included in Annex III.
When does an AI system become high-risk?
AI risk classification system
The AI Act classifies artificial intelligence systems into four levels of risk, based on the impact their use may have on the health, safety and fundamental rights of EU citizens. This classification determines the scope of responsibilities of organizations implementing or using a given system.
Four levels of AI risk according to the AI Act
- Prohibited uses of AI (Unacceptable risk)
AI systems that, by definition, pose a serious threat to human rights and freedoms are prohibited – e.g. behavioral manipulation, assessment of citizens (social scoring), mass recognition of emotions in the workplace or schools. - High risk
These are systems that – due to their impact on the lives of individuals – are subject to the most stringent regulations. They include, among others: AI in recruitment, education, health care, critical infrastructure, law enforcement and lending. - Limited risk
AI systems that do not directly affect the security or rights of users, but require transparency of operation. Example: chatbots – the user must be informed that he is talking to AI, not a human. - Minimal risk or no risk
AI used in purely functional or entertainment tools – e.g. photo filters, product recommendations. There are no specific regulatory obligations, but the implementation of good practices is recommended.
Free series of meetings for CISOs
AI vs Cybersecurity
What AI systems are considered high risk?
Artificial intelligence systems classified as high-risk (AI systems) are those that canactually impact the safety, fundamental rights or lives of users. The AI Act details which applications are subject to such classification – based on the risk approach known from sector regulations, such as NIS2.
According to Annex III of the AI Act, systems are considered high risk if they are used in the following areas:
- Biometrics – e.g. remote biometric identification in public spaces, emotion recognition systems, categorization based on sensitive features.
- Critical infrastructure – management and operation of systems in energy, transport, telecommunications, water, gas, heat and electricity supplies.
- Vocational education and training – e.g. systems deciding on admission to universities, assessing learning results, assigning education levels or monitoring the course of exams.
- Employment and employee management – e.g. recruitment, application analysis, task assignment, assessment of employee efficiency and behavior.
- Access to public and private services – e.g. qualification for health services, creditworthiness assessment, risk assessment in health and life insurance, triage in emergency services.
- Justice, law enforcement and democratic processes – e.g. crime risk analysis, evidence assessment, profiling tools, support for judges in analyzing the law, systems that may influence the outcome of elections or referenda.
- Migration, asylum and border control – e.g. systems supporting migration risk analysis, processing visa applications or identifying people at borders.
From August 2, 2026, obligations related to these systems will apply to organizations that introduce them to the market or use them in their operational activities. FromAugust 2, 2027 – also for systems that are not explicitly listed in the Annex, but meet the general high-risk criteria specified in Art. 6 section 1 AI Act.
What are the obligations of organizations implementing high-risk systems?
Organizations that create or implement AI systems classified as high risk must meet a number of technical, organizational and documentation requirements set out in Chapter III of the AI Act. The purpose of these obligations is to ensure security, transparency and compliance with the fundamental rights of end-users.
Key responsibilities include:
- Pre-implementation Compliance Assessment – Each organization must conduct a formal assessment of an AI system’s compliance with the AI Act requirements before it is put into service or on the market. Depending on the type of system, this may require the involvement of a notified body.
- Technical documentation and registration – it is mandatory to prepare complete technical documentation and register the system in the EU database. The documentation must include, among others: information about training data, model architecture, tests and constraints.
- Risk management – the organization must implement a continuous risk management process throughout the entire life cycle of the AI system, including the identification, analysis and minimization of threats related to its operation, also in real conditions.
- Quality management system (QMS) – it is necessary to implement a QMS system that takes into account the specifics of design, data, testing, monitoring and AI compliance. This is the foundation that ensures that all duties are carried out systematically.
- Data quality – data used to train and test AI must be adequate, representative, reliable and free from bias. In the case of sensitive data, their processing is allowed only with strict security measures.
- Transparency and user information – end users must be clearly informed that they are dealing with AI and know its functions, limitations and how it works. The ability to interpret the model results is required.
- Human supervision and the “STOP button” – the system must be under real human supervision. The organization is obliged to ensure the possibility of intervention and stopping the operation of AI (the so-called “STOP button”) to prevent uncontrolled decisions or harmful effects.
- Post-implementation monitoring and incident management – AI must be monitored in real-world conditions, and the organization should have procedures in place to respond to serious incidents, including the obligation to report them.
- Cybersecurity and personal data protection – the organization must ensure compliance of the system with cybersecurity requirements (including resistance to manipulation, adversarial attacks) as well as GDPR and other data protection regulations.
All of the above activities must be documented, regularly reviewed and available for review by regulatory authorities. From August 2026, failure to meet any of these obligations may result in financial sanctions and a ban on using the AI system.
How to prepare your organization for the AI Act? Key tips for CISOs for 2026
- Identify high-risk systems – carry out an internal classification based on the criteria of the level of impact on the rights and safety of users and compliance with the list of uses indicated in Annex III
- Build a compliance management system (QMS) – adapt it to the specifics of AI. Include design, testing, monitoring, updates and response procedures.
- Secure data and models – ensure the quality and representativeness of data and the resistance of the AI system to manipulation, errors and attacks.
- Implement the principles of human oversight – ensure human supervision over AI decisions and the ability to immediately stop the model operation (“STOP button”).
- Prepare technical documentation – make sure that the documentation contains not only technical parameters and logs, but also descriptions of the security measures used, possible threat scenarios and supervision mechanisms.
- Design procedures for monitoring and reporting incidents – define clear criteria for what constitutes an incident, establish reporting channels and response procedures.
Summary
AI Act, the EU regulation on artificial intelligence, introduces coherent regulations for artificial intelligence systems used in the European Union. From August 2026, organizations implementing high-risk artificial intelligence systems must demonstrate full compliance with the new regulations.
The provisions of the AI Act include, among others: compliance assessment, implementation of a quality management system, human supervision over AI operation, model transparency and mandatory documentation and registration. The regulation on artificial intelligence also provides for significant sanctions for violations – therefore, every organization using AI technologies should now prepare to meet the obligations that the Artificial Intelligence Act is intended to introduce.

