Compliance Guide
EU AI Act Compliance: A Practical Guide for Enterprise Security Teams
The EU AI Act entered into force on August 1, 2024, and applies in phases — the ban on prohibited practices and the AI literacy obligation since February 2, 2025, the bulk of the obligations from August 2, 2026. Fines run up to 35M EUR or 7% of global annual turnover for prohibited practices, and up to 15M EUR or 3% for most other breaches. This guide explains what matters for enterprises using AI tools — not building them.
What is the EU AI Act?
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Adopted by the European Parliament on March 13, 2024, it establishes harmonized rules for the development, deployment, and use of AI systems within the European Union.
Unlike sector-specific regulations such as the GDPR (data protection) or NIS2 (cybersecurity), the EU AI Act addresses AI across all industries. It categorizes AI systems by risk level: unacceptable, high-risk, limited risk, and minimal risk. Most enterprise AI usage — ChatGPT, Claude, Gemini, Copilot — falls into the limited or minimal risk categories, but specific obligations still apply.
Key Timeline
Which Articles Matter for AI Users (Not Builders)?
Most compliance guides focus on AI developers. But 90% of European enterprises are AI deployers or users — they use third-party AI tools, not build them. Here are the articles that apply to you:
Article 4 — AI Literacy
Organizations must ensure their staff have sufficient AI literacy to understand capabilities and risks of deployed AI systems. This includes training programmes, usage guidelines, and documented competency frameworks.
How Noxys helps: Shadow AI discovery identifies exactly which AI tools employees are using, enabling targeted literacy programmes for the tools actually in use — not theoretical ones.
Article 9 — Risk Management
Organizations deploying AI systems must implement risk management processes including identification, analysis, and mitigation of risks throughout the AI system lifecycle.
How Noxys helps: Real-time monitoring and policy engine provides continuous risk management. Policy enforcement blocks high-risk use cases automatically.
Article 13 — Transparency
High-risk AI systems must be designed to be transparent. Deployers must provide users with clear information about the AI system's capabilities, limitations, and the nature of AI involvement in decisions.
How Noxys helps: Audit trail provides complete transparency into which AI systems are used for which purposes, by whom, and when. Export-ready for regulatory disclosure.
Article 14 — Human Oversight
AI systems must be designed to allow effective human oversight. Organizations must implement controls that enable humans to review, intervene, and override AI decisions.
How Noxys helps: Policy engine enforces human-in-the-loop controls. Admins can block, coach, or log AI interactions in real time based on configurable rules per department.
The Shadow AI Problem
Gartner surveyed 302 cybersecurity leaders between March and May 2025: 69% of organisations suspect, or have evidence, that employees are using prohibited public GenAI tools. Employees use ChatGPT, Claude, Gemini, DeepSeek and dozens of other AI tools daily — often pasting sensitive data including customer records, financial data, credentials and internal documents into prompts.
This creates a dual compliance problem: data protection violations under GDPR (unauthorized transfer of personal data to third-party processors) and AI governance gaps under the EU AI Act (no visibility, no risk management, no audit trail).
Key statistic: According to a 2024 Cyberhaven study, 11% of data pasted into ChatGPT by employees is confidential. The average enterprise has 23 unsanctioned AI tools in active use.
Penalties for Non-Compliance
Fines under the EU AI Act are structured by severity:
Getting Started: 5-Step Compliance Checklist
- Inventory — Discover all AI tools in use across your organization (sanctioned and shadow).
- Classify — Map each AI tool to the EU AI Act risk categories.
- Policy — Define acceptable use policies per department, per tool, per risk level.
- Monitor — Implement real-time monitoring with Risk Signal detection (PII, secrets, code, IP) and audit logging.
- Report — Maintain compliance documentation and audit trails for regulators.
Noxys covers steps 1, 3, 4, and 5 out of the box. Browser-based discovery is operational in under 10 minutes with no infrastructure changes required.
Start Your EU AI Act Compliance Journey
Deploy Noxys in under 10 minutes. Start on the free discovery tier. No credit card required.