Cybersecurity blog

EU AI Act: What It Means for Your Business

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorized
CEMEA · Asia Pacific · USA

Our Offerings -PCI-DSS Audit,RBI/SEBI/IRDAI/Aadhar/NBFC & Housing Cybersecurity Audit,SOC1/2/3,GDPR,ISMS,ISO,Our Offerings -PCI-DSS Audit,RBI/SEBI/IRDAI/Aadhar/NBFC & Housing Cybersecurity Audit,SOC1/2/3,GDPR,ISMS,ISO,

EU AI Act Explained: What It Means for Your Business

The EU Artificial Intelligence Act is the world's first comprehensive AI law — and like the GDPR before it, its reach extends well beyond Europe. If your organisation builds, sells or uses AI systems that touch the EU market, the AI Act likely applies to you, even if you are based in India, the UK, the US, the Gulf or anywhere else. This guide explains what the Act does, who it affects, the timeline, and how to prepare.

What is the EU AI Act?

The EU AI Act is a risk-based regulation that sets obligations for AI systems based on how much risk they pose to health, safety and fundamental rights. It entered into force on 1 August 2024 and applies in phases. Rather than regulating the technology itself, it regulates how AI is used — the higher the risk of a use case, the stricter the requirements.

Does it Apply to Non-EU Companies?

Yes — the AI Act is extraterritorial. It applies to providers that place AI systems on the EU market regardless of where they are established, and to providers and deployers outside the EU whose AI system output is used in the EU. In practice, if EU users or EU-based customers rely on your AI, you should assume the Act is in scope and assess accordingly.

The Four Risk Tiers

1. Unacceptable Risk (Prohibited)

Certain AI practices are banned outright — for example, social scoring by public authorities, manipulative or exploitative systems, and most real-time remote biometric identification in public spaces. These prohibitions began applying in early 2025.

2. High Risk

AI used in sensitive areas — such as critical infrastructure, employment and HR, education, essential services, law enforcement and certain medical or safety components — is classed as high risk. These systems face the strictest obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity.

3. Limited Risk (Transparency)

Systems like chatbots and generative AI must meet transparency obligations — users should be told they are interacting with AI, and AI-generated content (including deepfakes) should be labelled.

4. Minimal Risk

The majority of AI systems — spam filters, recommendation engines, AI in games — fall here and face no new mandatory obligations, though voluntary codes of conduct are encouraged.

General-Purpose AI (GPAI) Models

The Act also sets obligations for general-purpose AI models (the foundation models behind many products), including technical documentation, transparency about training data, and copyright compliance — with additional requirements for the most capable models that pose systemic risk. If you build on top of GPAI models, your obligations depend on how you use and modify them.

Key Obligations for High-Risk AI

  • Establish a risk management system across the AI lifecycle.
  • Apply data governance — quality, relevance and bias controls for training data.
  • Maintain technical documentation and automatic logging/traceability.
  • Ensure meaningful human oversight of the system.
  • Achieve appropriate accuracy, robustness and cybersecurity.
  • Register the system and complete conformity assessment where required.

Timeline at a Glance

WhenWhat applies
Aug 2024AI Act enters into force
Feb 2025Prohibited (unacceptable-risk) practices banned; AI literacy duties begin
Aug 2025Obligations for general-purpose AI (GPAI) models apply
Aug 2026Most high-risk and transparency obligations apply
Aug 2027Remaining high-risk obligations (AI in regulated products) apply

Penalties

Non-compliance carries GDPR-scale fines: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for other violations. The combination of large fines and extraterritorial reach makes the AI Act a board-level issue.

How to Prepare

  • Inventory your AI systems and classify each by EU AI Act risk tier.
  • For high-risk systems, perform a gap assessment against the Act's obligations.
  • Stand up AI governance using ISO/IEC 42001 and the NIST AI RMF — they map closely to the Act's requirements.
  • Implement risk management, data governance, logging and human-oversight controls.
  • Security-test and red-team AI systems (robustness and cybersecurity are explicit obligations).
  • Document everything — technical files, model cards and conformity evidence.

How CyberSigma Helps

Meeting the AI Act is part governance, part security. CyberSigma classifies your AI systems by risk tier, runs gap assessments against the Act, implements ISO/IEC 42001 and NIST AI RMF governance, and red-teams your AI to satisfy the robustness and cybersecurity obligations — giving you defensible, audit-ready evidence whether you are in the EU or serving EU users from elsewhere.

Conclusion

The EU AI Act makes responsible, secure AI a legal requirement — with real penalties and global reach. The organisations that act now to inventory, classify, govern and security-test their AI will adopt AI with confidence; those that wait risk fines and lost market access. Start with an AI inventory and a risk classification, and build governance and security from there.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled, PCI QSA authorized cybersecurity firm helping organisations secure and govern AI with red-teaming, penetration testing and AI governance aligned to the EU AI Act, NIST AI RMF and ISO/IEC 42001.

Leave A Comment

CyberSigma office locations across India, UAE, Egypt and Australia

Our Office

Locations we operate from

HQ, Noida, India

405, 4th Floor, Majestic Signia, Sector 62, Noida, Uttar Pradesh 201309

Pune, India

InCube Centre, Tejaswini Society, Lane 2, Aundh, PUNE, India, 411007

Mumbai, India

A802, Crescenzo, C /38-39, G-Block, Bandra Kurla Complex, Mumbai-400051, Maharashtra, India

Bengaluru, India

Maharaj, 152/4, 8th Cross, Chamrajpet, Bengaluru, Karnataka, India, 560018

UAE

Business Point Building - Office No. 702 - Dubai - United Arab Emirates

UAE

L.L.C Muna AlJaziri Building, Office No 303 Al Mararr Dubai, UAE

Egypt

19 Dr. Omar Dessouky Street, Cairo- Egypt 4271020

Australia

Level 4, 80 Market Street, South Melbourne 3205