What is AI Act?
The AI Act is the European Union’s regulatory framework for the development, placing on the market, and use of artificial intelligence. Its objective is to establish harmonized rules for AI across the EU and support the safe and trustworthy use of the technology while protecting areas including health, safety, and fundamental rights.
The AI Act largely follows a risk-based approach. Requirements vary depending on the risks associated with an AI system and the role an organization has under the regulation. Certain AI practices are prohibited, while AI systems classified as high-risk are subject to extensive requirements. The regulation also contains provisions covering areas such as transparency and general-purpose AI (GPAI).
For organizations, this means it is important to understand which AI systems are being developed or used, what role the organization has under the regulation, and which requirements apply to each system.
A useful analogy is the safety regulation of different types of vehicles. A bicycle, passenger car, and truck present different levels of risk and are therefore subject to different requirements. Similarly, the AI Act applies different requirements depending on an AI system’s characteristics, intended use, and potential impact.
Sicra and AI Act
The AI Act makes governance and risk management increasingly important for organizations developing or using artificial intelligence. Compliance is not limited to the technology itself but also involves areas such as accountability, documentation, risk assessments, security, and controls throughout the AI system lifecycle.
For organizations, an important first step can be identifying which AI systems are already in use, who is responsible for them, what data they process, and which risk classifications and obligations may apply. This can also help uncover AI use that the organization previously had insufficient visibility into.
Sicra helps organizations with security strategy, maturity assessments, risk assessments, and regulatory requirements. This can support the establishment of governance and security processes for responsible AI adoption and compliance with the AI Act.
Services
Security strategy
Security maturity assessment
ISO27001 and NIS2
CISO-for-hire
Related terms: Artificial intelligence (AI), Agentic AI, LLM (Large Language Model), Governance, Compliance, NIS2 (Network and Information Systems Directive 2), GDPR compliance, IT-GRC (IT Governance, Risk and Compliance)