Thank you
The EU AI Act is already in force.
Now is the time to act on EU AI governance — if you wait, you are already late. Some of the key dates are outlined below:
Aug 2, 2024
Aug 2, 2026
Dec 2, 2027
What you'll find in the EU AI Act Implementation Guide.
-
Any organization using AI in the EU, or an outside company doing business there, needs to comply with the Act.
-
Non-compliance can bring fines up to €35 million or 7% of global revenue.
-
The 2026 Digital Omnibus delayed high-risk deadlines, but transparency rules stay on schedule.
- Baseline AI literacy rules and banned practices have been in effect since early 2025.
- Transparency requirements, like deep-fake labeling and biometric disclosures, still take effect mid-2026, alongside new bans on non-consensual imagery and social scoring.
- High-risk system obligations were pushed to late 2027 and mid-2028, giving more time to prepare.
- The recitals aren't legally binding but explain the law's intent, giving courts and stakeholders context for interpreting it.
- The 113 articles and 13 annexes carry equal legal force. Articles set the binding rules, and annexes hold the technical detail they refer back to.
- Codes of practice, regulator guidance, and harmonised standards fill in the compliance detail, though most are still being finalized.
- Deployers, meaning most organizations using AI, have baseline duties around data protection, transparency for things like deep-fakes and biometric systems, and respecting copyright in AI outputs.
- High-risk AI use comes with stricter obligations, now locked to firm deadlines of December 2027 for standalone systems and August 2028 for embedded ones.
- Those obligations span ten areas, including human oversight, input data quality, incident monitoring, log retention, and transparency to affected individuals.
- Compliance starts with knowing what AI systems are running, who's using them, and what data they touch, since you can't govern what you can't see.
- AI compliance is closely tied to data security, since nearly all AI systems process data and GDPR still applies alongside the Act's own requirements.
- Varonis pairs a Data Security Platform with the Atlas AI Security Platform to cover inventory, least privilege, posture management, monitoring, red teaming, and third-party AI risk.
ON-DEMAND WEBINAR
Built, Deployed, Compliant: How to Map Your AI and Avoid Regulatory Fines
Ready to see the #1 Data Security Platform in action?
Ready to see the #1 Data Security Platform in action?
“I was amazed by how quickly Varonis was able to classify data and uncover potential data exposures during the free assessment. It was truly eye-opening.”
Michael Smith, CISO
"What I like about Varonis is that they come from a data-centric place. Other products protect the infrastructure, but they do nothing to protect your most precious commodity — your data."
Deborah Haworth, Director of Information Security
“Varonis’ support is unprecedented, and their team continues to evolve and improve their products to align with the rapid pace of industry evolution.”
Al Faella, CTO
