Startup Bets

EU AI law takes first steps

 ·  By Sophronia Wentworth
EU AI law takes first steps - ai law
EU AI law takes first steps

The first year of EU AI Act transparency enforcement is expected to prioritize operational corrections over heavy financial penalties. Edwin Weijdema, a Field CTO at Veeam, suggests that while the legislation allows for fines up to 15 million euro or three percent of global turnover, regulators will likely focus on compliance assistance initially. The immediate risk for companies is less about paying a fine and more about being forced to shut down systems.

Corrective Orders Over Fines

Regulators often use the first year of new rules as a transition phase. Weijdema notes that corrective orders will likely outnumber major financial penalties, especially for organizations trying to comply. Authorities typically examine proportionality, the scale of impact, and whether basic governance controls were in place.

However, companies should not expect a free pass. One or two high-profile fines may appear eventually to demonstrate resolve, though probably not in the initial twelve months. The bigger practical exposure in year one will likely be operational. An organization ordered to suspend, relabel, or withdraw an AI-enabled process at speed could face far more disruption than paying a fine.

For IT departments, this means the architecture of automated workflows must change before they are deployed. Companies can no longer simply plug an agent into a mailbox and hope for the best; they must build technical gates that prevent the AI from acting autonomously unless specific conditions are met. This shift moves the burden of compliance from policy documents to actual infrastructure.

Defining Direct Interaction

The legislation does not care if the interaction happens in a chatbot window or a ticket queue. It cares if a human is effectively dealing with the machine. A ticketing queue or shared inbox does not automatically mean direct interaction, but it can if the AI is communicating without a human intermediary exercising meaningful control.

Related: Cisco flaw lets hackers gain full server control

If an AI drafts a response and a human reviews and sends it, the risk profile is lower. But an autonomous agent replying to a customer or supplier starts to look like direct interaction. Companies need to separate internal agents from customer-facing ones with appropriate barriers. Access controls must exist across the organization, not just for the agents themselves.

As of mid-June, only nine of the twenty-seven member states had designated both a market surveillance authority and a notifying authority. Twelve had partial designations, and six had neither. This administrative lag means enforcement structures are still being built across the continent.

Security Testing and Deepfakes

Security teams often run simulated phishing or vishing exercises using cloned executive voices. These are not automatically exempt from transparency rules. Understandably, teams resist labeling these tests because it ruins the realism, but a security purpose does not justify an undisclosed deepfake.

Cloning an executive’s voice is particularly sensitive. If AI is used to make a real person appear to say something they did not say, that can quickly become a legal issue. Weijdema advises involving legal and compliance teams early. Best practices include using synthetic voices that do not imitate real employees or providing immediate post-exercise disclosure.

Related: 7AI rolls out partner-driven SOC program

Documentation should be thorough. It needs to show the purpose of the exercise, the scope, what AI tools were used, and whether any real person was imitated. “A security objective does not magically turn an undisclosed deepfake into a compliant one,” Weijdema said.

Accountability Challenges

The first formal enforcement action will likely come from a market surveillance authority, though the trigger may be a complaint from a consumer group or competitor. Defamation claims are possible but less likely to be the primary route for initial Article 50 cases.

Clients are struggling with a specific question: How do we prove what an AI agent did, why it did it, and who was accountable? Evidence matters in cybersecurity, but agentic AI can reason and take actions across multiple systems. Governance has to move into technical controls.

Weijdema advises treating AI agents like privileged digital identities. They need owners, defined roles, least-privilege access, and a kill switch. Without logs, approvals, and audit trails, proving governance to regulators or a board remains a difficult task.

Leave a Comment

Your email address will not be published.