Live Webinar | 26 June 2025 9AM PT
From Black Box to Boardroom: Operationalizing Trust in AI Governance
September 17, 2024

The European Union Artificial Intelligence (AI) Act: Managing security and compliance risk at the technological frontier

A growing wave of AI-related legislation and regulation is building, with the most significant example being the European Union's (EU) Artificial Intelligence (AI) Act. In March 2024, European leaders passed this sweeping legislation into law.

It will clearly have huge impacts on the way business is done, both in the EU and globally. In this post we'll go look at the implications for organizations deploying AI to drive business value.

We'll also explore how Scrut's Responsible AI framework can help organizations address the coming regulatory requirements.

Background

With initial drafts starting in 2018, the AI Act was formally proposed by the European Commission in early 2021. But it has continued to evolve over the subsequent 2.5 years. The explosion in the use of AI tools following the launch of ChatGPT in late 2022 provided special urgency to EU rulemakers.

Following a graduated approach, the AI Act lays out four different categories:

  • Unacceptable risk
  •  
  • High risk
  •  
  • Non-high risk
  •  
  • Specific transparency risk

While each of the EU member states will need to develop its own regulatory infrastructure, the AI Act also creates a European AI Office within the European Commission. This office will help coordinate between the various national governments as well as supervise and regulate “general purpose” AI models, such as Large Language Models (LLMs) trained on a diverse array of information.

Although it's not clear from official communications, a leaked draft of the Act suggested it would not apply to open-source models. The open-source community has aggressively criticized many EU regulatory efforts, such as the AI Act but also the proposed Cyber Resilience Act (CRA).

Enforcement of the Act will begin within six months of passage when unacceptably risky AI systems will be legally banned. After 12 months, rules for general purpose AI will come into force. And at 24 months, the entire AI Act will be in force.

The forecasted fines for non-compliance are steep:

  • 35 million or 7% (whichever is greater) of global annual revenue for prohibited AI application use.
  •  
  • 7.5 million or 1.5% of revenue for supplying incorrect information.
  •  
  • 15 million or 3% of revenue for violations of other obligations.

The first category of potential fines is meant to strongly deter organizations from deploying certain types of AI applications, which we'll dive into next.

Banned applications of AI

The EU Commission drew a clear line in the sand by completely outlawing certain types of AI applications and development. Banned systems include those:

  • That manipulate human behavior to circumvent free will. While the EU press release gives the example of toys that use voice assistance to encourage dangerous behavior in minors, it isn't clear how this rule will apply to more ambiguous situations. Basically, every type of advertising attempts to redirect human behavior, and it's hard to see how advertising will not use AI in the future. So, this is definitely something that will need clarification.
  • That allow social scoring' by governments or companies. This provision is a clear allusion to fears that China is planning to build a system that integrates financial, social media, and criminal record monitoring to evaluate its entire population. The implementation details will be important here because many companies use things like net promoter or customer sentiment scores to track reputation and other business risks.
  • Use emotion recognition systems in the workplace. This is another area that will need substantial elaboration. While it is understandable that the EU might want to prohibit certain types of oppressive monitoring of employees, where it will draw the line is important. There is already a range of AI-powered communications tools that use emotions to predict things like churn risk, for example.
  • Include certain applications of predictive policing. While this is not a blanket ban as some had hoped, it seems certain crime-prediction methods will be outlawed.
  • Allow real-time remote biometric identification for law enforcement purposes in public (with some exceptions for national security). This provision appears to ban police from deploying facial recognition or other sensor systems in a general way to identify criminals. The narrowness of the exceptions will be key to determining how big an issue this provision is.

High-risk systems and their required controls

Aside from banned systems, there is another category of permitted but high-risk use cases. These include:

  • Critical infrastructure applications, e.g., water, gas, and electricity
  •  
  • Educational institution admission
  •  
  • Biometric identification
  •  
  • Justice administration
  •  
  • Sentiment analysis
  •  
  • Medical devices
  •  
  • Border control

The AI Act will require that such systems comply with a range of requirements to mitigate the risk, including those related to:

  • High-quality data sets
  •  
  • Logging and auditing
  •  
  • Human oversight
  •  
  • High accuracy
  •  
  • Cybersecurity

How Responsible AI sets organizations up for success

As a wave of AI-related innovation swept the globe, we understood that organizations would need a firm set of guidelines in place to navigate it safely, effectively, and ethically. That is why we launched our Responsible AI framework.

No matter how the AI Act eventually turns out, it is clear that companies will need to deal with an array of first- and second-order challenges (in the form of regulatory action). These include:

  • Dependence on unreliable or biased data sources
  •  
  • Exposure of sensitive intellectual property
  •  
  • Legal complexity and uncertainty
  •  
  • Potential privacy infringement

The clear signs of how important these things would be led us to develop an actionable framework to help address them. That is why Responsible AI provides a roadmap for:

  • Cost savings through early risk identification
  •  
  • Responsible data and systems usage
  •  
  • Avoidance of fines and penalties
  •  
  • Risk identification and mitigation
  •  
  • Ethical and legal compliance
  •  
  • Building customer trust
  •  
  • Out-of-the-box controls

Conclusion

As we have seen from previous EU regulatory efforts, especially the General Data Protection Regulation (GDPR), the impacts of the AI Act are likely to be felt far and wide. While it may take some time for regulators to catch up with the pace of technology, they inevitably do so.

Even five years after it came into effect, the GDPR is just building up momentum in terms of enforcement action, resulting in some shocking fines from major companies.

This type of “regulation through enforcement” is unfortunate but likely unavoidable as companies test the limits of new rules and governments react aggressively. The best approach, then, is to follow a balanced course of action that allows for taking advantage of AI's many benefits while avoiding or mitigating its greatest risks.

Interested in seeing how Scrut's Responsible AI framework can help you navigate rules like the EU AI Act? Book a demo!

Liked the post? Share on:
Table of contents
Join our community
Join our community and be the first to know about updates!
Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Join our community and be the first to know about updates!

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Related Posts

HIPAA
Compliance Essentials
Understanding HIPAA violations: Types, prevention, and best practices
HIPAA
PHI vs PII: Essential comparisons, compliance differences, and a focused checklist
GDPR
Risk Management
Best GDPR Compliance Automation Software in 2025: Features, Pricing, Pros & Cons

Ready to see what security-first GRC really looks like?

Ready to see what security-first GRC really looks like?

Ready to see what security-first GRC really looks like?

See what a real security- first GRC platform looks like

Ready to see what security-first GRC really looks like?

Focus on the traveler experience. We’ll handle the regulations.

Get Scrut. Achieve and maintain compliance without the busywork.

Choose risk-first compliance that’s always on, built for you, and never in your way.

Ready to see what security-first GRC
One platform, every framework. No more duplicate work.
You can’t manage user access if you’re always playing catch-up.
Explore the future of enterprise GRC
Tired of chasing vendors for risk assessments?

Join the thousands of companies automating their compliance with Scrut.

The right partner makes all the difference. Let’s grow together.

Make your business easy to trust, put security transparency front and center.

Risk-first security starts with risk-first visibility.
Secure your team from the inside out.
Don't settle for slow, expensive compliance. Get Scrut instead.
Risk-first compliance for forward-thinking teams.
Audits without the back-and-forth. Just seamless collaboration.
Scale fast. Stay compliant. Automate the rest.
Compliance? Done and dusted, in half the time.
Get ahead of GDPR compliance before it becomes a problem.
Outgrowing table-stakes compliance? Create custom frameworks with ease.
Navigate SOC 2 compliance, minus the stress.
PCI DSS compliance, minus the panic.
Take the wheel of your HIPAA certification journey today.
We’ve got what you need to fast-track your ISO 27001 certification.
Make your NIST AI RMF journey as smooth as possible.

Your GRC team, multiplied and AI-backed.

Modern compliance for the evolving education landscape.

Ready to simplify healthcare compliance?

Don’t let compliance turn into a bottleneck in your SaaS growth.

Find the right compliance frameworks for your business in minutes

Ready to see what security-first GRC really looks like?

Real-time visibility into every asset

Ready to simplify fintech compliance?

The Scrut Platform helps you move fast, stay compliant, and build securely from the start.

Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.

Scrut helps you streamline audits, close deals faster, and stay ahead of risk without slowing down your team. Because trust shouldn’t take months to earn.

Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.

Tag, classify, and monitor assets in real time—without the manual overhead.

Whether you're entering new markets or launching new products, Scrut helps you stay compliant without slowing down.

Scrut pulls compliance data straight from the tools you already use—so you don’t have to dig for evidence, chase approvals, or manually track controls.

Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.

With Scrut, you’re not just adding a tool to your offering—you’re adding a competitive edge. Join our Partner Network and help your clients streamline their GRC program.

Gaining trust is your first step to growing and cracking better deals. The Scrut Platform comes pre-built with all the tools you need to showcase a firm security posture and build confidence.

Don’t settle for rigid systems—Scrut ensures your risk management strategy is as flexible as your business needs.

Start building a security-first culture. Save your operations from improper training and a lack of compliance awareness.

Scrut fast-tracks compliance so you can focus on scaling, not scrambling. Automate compliance tasks and accelerate enterprise deals—without the grind.

Automate assessments, track compliance, and get full visibility into third-party risk—all in one place.

Scrut automates compliance tasks, supports proactive risk management, and saves you time, so you can focus on growing your business. Start building trust with customers and scaling confidently.

Leave legacy GRC behind. Meet the AI-powered platform built for teams managing risk and compliance in real time.

Give auditors direct access, keep track of every request, and manage audits effortlessly—all in one place.

Scrut ensures access permissions are correct, up-to-date, and fully compliant.

Whether you need fast results or a fully tailored program mapped to your risks and needs, Scrut delivers exactly what you need, when you need it. Ready to start?

Scrut unifies compliance across all your frameworks, so you can stop juggling systems and start scaling securely.

Manually managing your compliance processes and audits can get inefficient and overwhelming. Scrut automates these outdated, manual processes and eliminates your last-minute worries.

Access automated compliance, real-time risk tracking, and expert-backed support—all in one platform. Get started with Scrut!

Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.

The Scrut Platform helps you move fast, stay compliant, and build securely from the start.

Earn trust and back it up with solid evidence. Scrut takes you through the SOC 2 compliance journey step-by-step, navigating every complexity you face.

Manage your PCI DSS compliance with real-time monitoring and effortless automation. Get started with Scrut today!

Securing your PHI shouldn’t be a constant hassle. Scrut automates your workflows—from risk assessments to monitoring—so you can put your compliance worries on the back burner.

Automate security controls, simplify audits, and keep your ISMS aligned with the latest standards. Get started with Scrut!

Tackle potential AI risks with NIST AI RMF-compliant controls and get expert support every step of the way.

Offload the grunt compliance work to us. Execute manual, draining GRC tasks with the reliable AI-powered Scrut Teammates without switching contexts or bottlenecks.

Whether you're managing student data, partnering with educational institute, or expanding to new geographies—Scrut gives you the tools to stay compliant, manage risk, and build trust at every step.

Scaling healthcare doesn’t have to come at the cost of security. Scrut keeps your organization compliant, audit-ready, and protected—no matter how fast you grow.

Scrut automates the hard parts of compliance and security so you can move fast and stay ahead of risks from day one.

The Scrut Platform helps you move fast, stay compliant, and build securely from the start.

Growth in fintech comes with heavy scrutiny. Scrut helps you stay compliant, audit-ready, and secure—without slowing down your momentum.

Book a Demo
Book a Demo
Join the Scrut Partner Network
Join the Scrut Partner Network