Don’t do SECURITY. Do business SECURELY.

EU AI Act: first obligations now apply

Prohibited AI practices are now banned in the EU, and AI literacy obligations apply.

The first obligations under the EU AI Act apply from today.

Prohibited AI practices are now banned, including:

  • Social scoring.
  • AI that manipulates behaviour or exploits vulnerabilities to cause significant harm.
  • Untargeted scraping of facial images to build facial recognition databases.
  • Emotion recognition in the workplace and education (with limited exceptions).
  • Certain uses of real-time remote biometric identification in public spaces for law enforcement.

Providers and deployers must also take measures to ensure a sufficient level of AI literacy among staff dealing with AI systems.

Now is a good time to build an inventory of AI systems in use across your organisation, including AI features embedded in third-party tools, and to classify them against the Act’s risk categories.

Source: Regulation (EU) 2024/1689, AI Act (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights