01Introduction
The EU AI Act is the first broad law regulating AI. Any company that places AI systems on the EU market or uses them there, wherever it is based, needs to know which category its systems fall into.
02What is EU AI Act?
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. It classifies AI by risk: prohibited practices, high-risk systems, systems with transparency duties, and minimal risk, with separate rules for general-purpose AI models.
Article 15 requires high-risk AI systems to achieve appropriate accuracy, robustness and cybersecurity, including resilience against data poisoning, adversarial inputs and model flaws. Prohibitions applied from February 2025 and general-purpose AI duties from August 2025. Most high-risk obligations follow in stages, and some dates have been subject to proposed delays, so check current timelines. Fines reach €35 million or 7% of global turnover.
03How EU AI Act works
Obligations depend on your role (provider, deployer, importer) and the system's category.
- 1.
Classify systems
Inventory AI systems and determine their risk category and your role.
- 2.
Risk management
For high-risk systems, run a lifecycle risk process and data governance, supported by ISO 42001.
- 3.
Test robustness and security
Evaluate systems against adversarial attacks and LLM-specific threats.
- 4.
Document and monitor
Keep technical documentation, logs and post-market monitoring, and report serious incidents.
04Threats and risks
Article 15 names the attack classes regulators expect you to address.
Data poisoning
Manipulated training data that changes model behavior.
Adversarial inputs
Crafted prompts or inputs that cause harmful or incorrect output.
Model confidentiality
Extraction of model weights or sensitive training data.
Penalties
Large fines and market withdrawal for noncompliant systems.
05How Parameter helps
Parameter tests AI features as an attacker would, producing evidence for robustness and cybersecurity duties.
Adversarial testing
The pentesting agents test AI features for prompt injection, jailbreaks and data exfiltration.
Application context
Tests cover the APIs, auth and data flows around the model, where most real exploits land.
Posture
Cloud Security supports AI-SPM by mapping AI resources and access.

