The EU AI Act for Security Teams
On 29 August 2026, Henna Virkkunen, the European Commission’s Executive Vice-President for Tech Sovereignty, Security and Democracy, confirmed that the AI Office had sent formal requests for information to providers of general-purpose AI (GPAI) models. The requests asked three things: how the providers secure their models against attack, whether independent external evaluators have assessed them, and how the models are monitored after release. The Commission confirmed on 1 September that it had written to more than thirty AI companies across two strands, one on safety and security and one on copyright and transparency. The first exercise of enforcement power under the EU AI Act was a demand for security evidence.
Forward that sentence to your CISO. Most organisations treated this regulation as a legal review and produced a register of AI systems and a policy document. The first enforcement instrument the Commission used, a request for information under Article 91, asks for adversarial testing results, third-party evaluation evidence, and post-market monitoring records. Those are security artefacts. An organisation that cannot produce them has done compliance work that does not touch the provisions now being enforced.
The high-risk regime that occupied two years of preparation did not apply on 2 August 2026. A regulation adopted this summer deferred it to December 2027 and August 2028. The transparency obligations that most organisations treated as secondary did apply on schedule and are enforceable today. Anyone working from a 2025 compliance calendar has made two errors at once: preparing for the Annex III regime, which is fifteen months away, and missing Article 50, which applied on 2 August 2026.
What follows covers the state of the law on 5 September 2026 and what each security-relevant provision requires as engineering work. Four companion pieces go deeper on Articles 15, 50, 55 and 73, and a fifth sets out the architectural gap around agents. All five are linked below.
What the Digital Omnibus changed
Regulation (EU) 2026/1744, the Digital Omnibus on AI, appeared in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The European Parliament voted on 16 June, the Council adopted its decision on 29 June, and the instrument is dated 8 July. It amends Regulation (EU) 2024/1689, the AI Act itself.
The central change was a deferral. Obligations for standalone high-risk systems under Annex III moved from 2 August 2026 to 2 December 2027. Obligations for high-risk AI embedded in regulated products under Annex I had been due on 2 August 2027. The Omnibus moved them by a year, to 2 August 2028. Both dates are fixed. The Commission’s original proposal tied the deferral to the availability of harmonised standards, and the co-legislators removed that condition.
The deadline for Member States to establish regulatory sandboxes moved to 2 August 2027. The obligation on the Commission to adopt a mandatory template for post-market monitoring plans was deleted outright and replaced by a duty to publish non-binding guidance with a voluntary template by 2 September 2027. The mandatory template had been due on 2 February 2026 and was never adopted.
Two amendments went the other way. The Omnibus inserted points (ba) and (bb) into Article 5(1), prohibiting AI systems that generate or manipulate realistic intimate imagery of an identifiable person without that person’s consent, and AI systems that generate child sexual abuse material. The amended Article 113 sets both to apply from 2 December 2026, so neither was part of the 2 August set. It also softened Article 4 on AI literacy from a duty to ensure a sufficient level of literacy to a duty to take measures supporting its development.
Whether the deferral counts as simplification or deregulation is disputed. The Commission described it as targeted simplification addressing a compliance burden heavier than expected. A joint open letter signed by more than a hundred civil society organisations, trade unions and public-interest groups described it as an attempt to dismantle protections under cover of technical tidying. Neither description changes the dates.
The calendar on 5 September 2026
| Obligation | Article | Applies from | Enforceable now |
|---|---|---|---|
| Prohibited practices | Art. 5 | 2 February 2025 | Yes |
| AI literacy | Art. 4 | 2 February 2025 | Yes, as amended |
| GPAI model obligations | Arts. 53–56 | 2 August 2025 | Yes |
| Penalties regime | Ch. XII | 2 August 2025, except Art. 101 | Yes |
| GPAI provider fines | Art. 101 | 2 August 2026 | Yes |
| AI Office enforcement powers | Arts. 88 et seq. | 2 August 2026 | Yes, and in use |
| Transparency: providers Art. 50(1), deployers Art. 50(3) and (4) | Art. 50 | 2 August 2026 | Yes |
| Machine-readable marking of synthetic content | Art. 50(2) | 2 August 2026 for new systems | Grace to 2 December 2026 for existing systems |
| NCII and CSAM prohibitions | Art. 5, as amended | 2 December 2026 | No |
| High-risk systems, Annex III | Ch. III | 2 December 2027 | No |
| High-risk AI in regulated products, Annex I | Ch. III | 2 August 2028 | No |
| Regulatory sandboxes | Art. 57 | 2 August 2027 | No |
Three consequences follow for a security function.
Enforcement powers became exercisable on 2 August 2026 and the Commission used them within four weeks. For the preceding year, GPAI obligations existed with no mechanism to enforce them.
The high-risk requirements that define most of the engineering work, Articles 9 to 15 and Article 17, do not apply for another fifteen months. That interval is time to build. Conformity assessment for an Annex III system will not compress into a final quarter.
The obligations in force today concentrate in two places. Article 50 splits across roles: paragraphs 1 and 2 are provider duties covering interactive-system design and machine-readable marking, while paragraphs 3 and 4 are deployer duties covering emotion-recognition notification and deepfake disclosure. The GPAI obligations apply to model providers. Most organisations are deployers, and most of their live exposure is Article 50(4).
Article 15 and the standards that do not exist
Article 15 sets the accuracy, robustness and cybersecurity requirements for high-risk systems. Article 15(5) requires resilience against attempts by unauthorised third parties to alter a system’s use, outputs or performance by exploiting its vulnerabilities. It then names the attack classes that technical solutions must prevent, detect, respond to, resolve and control for: manipulation of the training data set, which it calls data poisoning; manipulation of pre-trained components, which it calls model poisoning; inputs designed to cause a mistake, which it calls adversarial examples or model evasion; confidentiality attacks; and model flaws.
That list summarises the adversarial machine learning literature accurately. securing.ai/ has covered each item at length: data poisoning, adversarial attacks and evasion, backdoors and neural trojans, model extraction, and model inversion as a confidentiality attack.
Two qualifying sentences follow the one everyone quotes. Article 15(5) requires technical solutions appropriate to the relevant circumstances and the risks. It then provides that those solutions must include, where appropriate, measures addressing the attack classes it lists. That is a proportionality standard with an illustrative list, and the Act sets no threshold for appropriate.
Article 15(2) contemplates the Commission encouraging benchmarks and measurement methodologies in cooperation with stakeholders and with metrology and benchmarking bodies. None have been published. Harmonised standards would give a presumption of conformity under Article 40, and no standard supplies a robustness metric either. CEN-CENELEC Joint Technical Committee 21, created in 2021, has drafted the standards under the 2023 standardisation request M/593, Decision C(2023)3215, replaced in 2025 by M/613. EN 18286:2026, covering quality management for Article 17, was published in July 2026 as the first European Standard supporting the AI Act. Publication is not citation: no JTC 21 deliverable has been cited in the Official Journal, so none confers a presumption of conformity. CEN and CENELEC adopted acceleration measures in October 2025 targeting the priority deliverables by the fourth quarter of 2026, and M/613 expires on 28 February 2027. Standards give a presumption of conformity and are not a precondition for it; the Act provides assessment routes where none exists.
Fifteen years of published work has produced defences that hold under a stated threat model and fail when it changes. Nobody has found a robustness property that survives that change, so a standard has nothing stable to measure. A standard can require a documented process. It cannot supply a threshold that survives an adaptive attacker.
I set out what that means for anyone building an Annex III system in Article 15 requires robustness nobody can measure.
What Article 55 requires of frontier model providers
Chapter V applies to providers of general-purpose AI models. Article 51(2) presumes systemic risk when cumulative training compute exceeds 10^25 floating point operations. The Commission may amend that threshold by delegated act and has not done so.
Providers of systemic-risk models owe four obligations under Article 55. They must evaluate the model using state-of-the-art protocols including documented adversarial testing. They must assess and mitigate systemic risks at Union level. They must track serious incidents and report them to the AI Office. They must ensure an adequate level of cybersecurity for the model and for its physical infrastructure.
That fourth obligation is a weight security mandate written into regulation. The General-Purpose AI Code of Practice, published on 10 July 2025, translates it into specific controls covering weight encryption, access control, supply chain security for compute providers, and vulnerability disclosure. The Commission’s signatory list, last updated on 31 July 2026, names twenty-one full signatories including Amazon, Anthropic, Cohere, Google, IBM, Microsoft, Mistral AI and OpenAI. xAI signed the Safety and Security chapter only. Meta is absent. The list is updated as signatures are confirmed, so any count needs its date.
The 29 August requests for information asked about this material specifically. Anyone procuring frontier models should read the GPAI security chapter as a weight security mandate next.
Article 73 and three other reporting deadlines
Article 73 requires providers of high-risk systems to report serious incidents to the market surveillance authority of the Member State where the incident occurred. The deadline is fifteen days from becoming aware, ten days where a death may have been caused, and two days for a widespread infringement or a serious and irreversible disruption of critical infrastructure.
The two-day tier is the one to plan for. No other European reporting obligation is shorter except the twenty-four hour early warnings, which require a warning and not a full report.
Article 73 does not operate alone. Cyber Resilience Act reporting applies from 11 September 2026, six days after this article’s check date, requiring an early warning within twenty-four hours and a notification within seventy-two through the ENISA Single Reporting Platform. NIS2 requires a twenty-four hour early warning and a seventy-two hour notification to a different authority. The GDPR requires notification of a personal data breach within seventy-two hours to a third authority.
The Act anticipated part of this. Article 73(9) limits notification for Annex III systems whose providers face equivalent Union reporting obligations to Article 3(49)(c) fundamental-rights incidents. Article 73(10) applies the same limit to high-risk systems that are themselves medical devices under Regulations 2017/745 and 2017/746, or are safety components of them. The carve-outs are in the Regulation itself. Which regimes actually stack for a given incident depends on which limb of Article 3(49) it engages, and that determination has to be made in the first hours. I work through it in one AI incident, four reporting regimes.
Article 50 and the watermarks it presumes
Article 50 applies now. Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format detectable as artificially generated. Deployers of chatbots must inform users they are interacting with an AI system. Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Deployers who generate or manipulate deepfakes must disclose that the content is artificial.
The marking obligation under Article 50(2) applied on 2 August 2026 to systems placed on the market from that date. Systems already on the market received a transitional period ending 2 December 2026.
The AI Office published a Code of Practice on Transparency of AI-Generated Content on 10 June 2026. It endorses a layered approach combining signed and timestamped provenance metadata with imperceptible watermarking, and requires providers to offer a detection interoperability solution by 2 February 2027. Around 190 organisations had signed by the end of July 2026.
Article 50 prescribes no technique. It requires marking that is effective, interoperable, robust and reliable as far as technically feasible, and the Code of Practice is what selects the method. Published attacks defeat the ones it selects. Diffusion-based regeneration removes invisible image watermarks, and separate work demonstrates forgery, which is the more serious result: an attacker who forges a mark attributes synthetic content to a provider that did not generate it. I develop that argument in the transparency Code relies on watermarks that break, which connects to this site’s existing coverage of AI disinformation and democratic process.
Where the Act reaches agents, and where it does not
The Commission’s AI Act Service Desk states that AI agents are not a separate category under the Act and that the definitions of an AI system in Article 3(1) and of a GPAI model in Article 3(63) are sufficient to cover them. It routes agentic risk through systemic-risk designation, naming autonomy and tool use as factors under Article 51(1)(b) and Annex XIII point (e), and through the GPAI Code’s risk management measures. It also says the Commission’s regulatory considerations on agents are only preliminary at this stage.
Every route the Service Desk names operates at the GPAI model layer. Chapter III, which contains the security requirements for high-risk systems, is unaffected by it. Article 15’s enumerated vulnerabilities target fixed points in a pipeline, and an agent’s exposure is indirect prompt injection through retrieved content, corruption of persistent memory across sessions, and misuse of legitimately delegated tool authority. The list does not name them, and the where appropriate qualifier leaves a provider to work them out unaided. I have written that up in the AI Act now recognises agents, and its security rules still miss them.
Penalties and the authorities that impose them
Article 99 sets three tiers. Breach of the Article 5 prohibitions costs up to 35 million euro or 7 per cent of total worldwide annual turnover, whichever is higher. Breach of most other obligations, including the Article 50 transparency duties, costs up to 15 million euro or 3 per cent. Supplying incorrect, incomplete or misleading information to authorities costs up to 7.5 million euro or 1 per cent. For SMEs and start-ups each cap is the lower of the two figures.
Article 101 sets a separate regime for providers of general-purpose AI models at up to 15 million euro or 3 per cent, and it covers incorrect, incomplete or misleading information supplied in response to a request. A GPAI provider answering the AI Office carelessly faces that 3 per cent exposure. The lower Article 99 information tier does not apply to it. Article 91(4) requires the AI Office to state that exposure on the face of every request it sends.
Enforcement divides three ways. The AI Office enforces the obligations on general-purpose AI models. National market surveillance authorities enforce the obligations on AI systems placed on their territory. The European Data Protection Supervisor supervises the EU institutions.
The Omnibus rewrote Article 75 and moved a class of systems out of the second group and into the first. The AI Office now holds exclusive competence over AI systems built on a general-purpose AI model where the model and the system come from the same provider, or from providers forming part of the same undertaking, and over systems that constitute or are integrated into a very large online platform or search engine designated under the Digital Services Act. Systems under Annex I, Annex III point 2 and Annex III point 8 are excluded, as are systems provided by law enforcement, border management and financial institutions falling under Article 74(6). Article 75 sits in Chapter IX, which applies from 2 August 2026, so the rewritten powers became exercisable a week after the amendment entered the text. If you build a product on a model your own group trained, your supervisor is in Brussels rather than in your capital.
Member States were required to designate authorities by 2 August 2025. A European Parliament research briefing recorded eight of twenty-seven Member States having notified a single point of contact as of March 2026. The Future of Life Institute’s national implementation tracker recorded nine of twenty-seven having designated both a market surveillance authority and a notifying authority as of 17 June 2026, twelve with a partial designation, and six with neither. That is the most recent published count I could find on 5 September 2026. Ireland designated fifteen existing regulators by statutory instrument in September 2025 and is standing up a coordinating AI Office of Ireland under its Regulation of Artificial Intelligence Bill 2026. Spain established a dedicated agency. Germany named the Bundesnetzagentur as market surveillance authority and single point of contact, and the Deutsche Akkreditierungsstelle as notifying authority, in the draft KI-MIG that the federal cabinet adopted on 11 February 2026 and that had not cleared the Bundestag and Bundesrat by mid-2026.
One further caution on enforcement. Several widely circulated articles report that the AI Office issued 47 million euro in fines in August 2026 against a hiring platform, a credit scoring provider and a retail chain. Those reports describe fines for Annex III conformity assessment failures, an obligation that does not apply until December 2027, imposed by a body with no jurisdiction over deployers. I found no primary source for any of it. Treat the story as false unless the Commission publishes a decision.
What to do before December 2026
Four items are time-bound between now and the end of the year.
Inventory every user-facing system that generates content or holds a conversation, and confirm it discloses. Article 50(1) and 50(4) are in force and apply to deployers, not only to model providers. Most organisations are exposed here today, and the fix is a disclosure line.
Establish whether any system you placed on the market before 2 August 2026 generates synthetic content, and confirm machine-readable marking before 2 December 2026, when the transitional period ends.
If you provide a general-purpose AI model, assume a request for information is possible and check that you can produce adversarial testing records, external evaluation reports and post-market monitoring evidence on demand. Article 101 exposure attaches to the quality of the answer.
If you are building anything that falls under Annex III in December 2027, start the Article 15 work now and document the threat model you tested against. No standard will define sufficient before you have to decide what it means.
The Commission published an Action Plan on Cybersecurity and Artificial Intelligence on 7 July 2026, establishing a dedicated EU capacity to evaluate advanced models before they reach the market, targeted to be operational during 2027. The Commission is adding technical model-evaluation capacity alongside documentary supervision. An organisation that prepared only a documentation exercise has prepared for half the audit.
Checked against the Official Journal and Commission publications on 5 September 2026. This calendar has moved twice and will move again. I review this article when a harmonised standard is cited in the Official Journal, when the Article 6 classification guidelines are finalised, and at each date in the table above.
In the early 2000s, running emerging-technology risk labs at CyberAgency, a defence client asked my team to break the AI systems they planned to put into weapons. We did. That is where my work on AI security started, two decades before the current wave of attention. I kept at it through risk labs at IBM, Accenture, PwC and KPMG. In 2016 I co-wrote a book on AI and leadership. My commercial work today is quantum, at Applied Quantum, which is why this site sells nothing.