The EU AI Act, for security and risk teams
A risk-tiered law that lands on anyone building or deploying AI. What it classifies, what it demands, and where it overlaps with the security programme you already run.
The risk tiers
The Act is structured by risk. Prohibited uses (such as certain manipulative or social-scoring systems) are banned outright. High-risk uses — safety components, and applications in areas like employment, critical infrastructure and law enforcement — carry the full weight of obligations. Limited-risk systems mainly owe transparency, such as telling people they are interacting with a bot. Most systems are minimal-risk with few duties. The obligations phase in over staggered dates.
What high-risk actually demands
For high-risk systems, providers must run a lifecycle risk-management system, govern their training data, keep technical documentation and logs, be transparent to deployers, ensure human oversight, and meet accuracy, robustness and cybersecurity bars. Deployers carry their own duties around how the system is used, monitored and overseen.
None of that is unfamiliar to a security team — it is governance, logging, access control and monitoring, applied to a new class of asset.
Where it meets your security programme
The efficient path is to treat AI systems as assets inside your existing risk and governance process rather than standing up a parallel programme. The same ISMS disciplines — asset inventory, logging, monitoring, incident handling, supplier governance — carry most of the load.
Governing the AI you adopt is what turns the Act from a compliance headache into an extension of controls you already run.
Questions, answered
Does it apply to us if we are outside the EU?
Is general-purpose AI covered?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.