AI Act (cybersecurity)

← All instruments
applies partiallyadjacent
Type
regulation
Layer
adjacent
Status
applies partially
In force
2024-08-01
Key date
2026-08-02 high-risk obligations
Last verified
2026-07-16

AI Act — the cybersecurity of AI systems

Regulation (EU) 2024/1689 is the EU’s horizontal AI law. It is not a cybersecurity law, but it imposes real cybersecurity obligations on AI providers, and it interacts with the CRA when an AI system is also a product with digital elements.

The cybersecurity-relevant provisions

Article 15 — accuracy, robustness and cybersecurity (high-risk AI)

Providers of high-risk AI systems must design and develop them to achieve appropriate cybersecurity and resilience against attempts to alter use, behaviour or performance by exploiting vulnerabilities. This explicitly covers AI-specific attacks:

  • data poisoning (manipulating training data),
  • model poisoning (manipulating pre-trained components),
  • adversarial examples / evasion (inputs crafted to cause misclassification),
  • model evasion and confidentiality attacks (e.g. model extraction). Measures must be proportionate and state-of-the-art.

Article 55 — obligations for GPAI models with systemic risk

Providers of general-purpose AI models with systemic risk must ensure an adequate level of cybersecurity for the model and its physical infrastructure (protecting weights, preventing theft/leakage), alongside adversarial testing and incident tracking.

Phased application (why status is “partial”)

  • 2 Feb 2025 — prohibited-practice bans and AI-literacy duties apply.
  • 2 Aug 2025 — GPAI-model obligations (incl. Art. 55) apply.
  • 2 Aug 2026 — most high-risk-system obligations (incl. Art. 15) apply.
  • 2 Aug 2027 — rules for high-risk AI embedded in regulated products. ⚠️ The Digital Omnibus proposed adjustments/delays to some AI Act deadlines — VERIFY.

Interplay with cyber law

  • CRA: an AI system that is a product with digital elements can satisfy Art. 15’s cybersecurity requirement by meeting the CRA’s essential requirements — a presumption of conformity intended to avoid double assessment.
  • NIS2: AI providers may separately be NIS2 entities (e.g. as manufacturers or digital providers); AI is increasingly used within NIS2 entities’ security stacks.
  • The Commission’s AI-in-cybersecurity action plan addresses both AI as a threat and AI as a defensive tool.

Sources