Parameter

What is EU AI Act?

EU Artificial Intelligence Act

What the EU AI Act requires, its risk categories, the cybersecurity duties for high-risk AI, key dates and fines.

01Introduction

The EU AI Act is the first broad law regulating AI. Any company that places AI systems on the EU market or uses them there, wherever it is based, needs to know which category its systems fall into.

02What is EU AI Act?

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. It classifies AI by risk: prohibited practices, high-risk systems, systems with transparency duties, and minimal risk, with separate rules for general-purpose AI models.

Article 15 requires high-risk AI systems to achieve appropriate accuracy, robustness and cybersecurity, including resilience against data poisoning, adversarial inputs and model flaws. Prohibitions applied from February 2025 and general-purpose AI duties from August 2025. Most high-risk obligations follow in stages, and some dates have been subject to proposed delays, so check current timelines. Fines reach €35 million or 7% of global turnover.

03How EU AI Act works

Obligations depend on your role (provider, deployer, importer) and the system's category.

  1. 1.

    Classify systems

    Inventory AI systems and determine their risk category and your role.

  2. 2.

    Risk management

    For high-risk systems, run a lifecycle risk process and data governance, supported by ISO 42001.

  3. 3.

    Test robustness and security

    Evaluate systems against adversarial attacks and LLM-specific threats.

  4. 4.

    Document and monitor

    Keep technical documentation, logs and post-market monitoring, and report serious incidents.

04Threats and risks

Article 15 names the attack classes regulators expect you to address.

  • Data poisoning

    Manipulated training data that changes model behavior.

  • Adversarial inputs

    Crafted prompts or inputs that cause harmful or incorrect output.

  • Model confidentiality

    Extraction of model weights or sensitive training data.

  • Penalties

    Large fines and market withdrawal for noncompliant systems.

05How Parameter helps

Parameter tests AI features as an attacker would, producing evidence for robustness and cybersecurity duties.

  • Adversarial testing

    The pentesting agents test AI features for prompt injection, jailbreaks and data exfiltration.

  • Application context

    Tests cover the APIs, auth and data flows around the model, where most real exploits land.

  • Posture

    Cloud Security supports AI-SPM by mapping AI resources and access.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your EU AI Act program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.