REGULATORY: EU AI ACT 2024/1689  ·  ENFORCEMENT ACTIVE

EU AI Act High-Risk
Enforcement:
A CISO Breakdown

AI-Sec Global Summit 2026 CISOs / GRC Directors Europe & UK Focus 15 min read

Annex III obligations are active. Article 50 transparency rules are being enforced. The €35M fine threshold is not theoretical — it applies to any AI system touching EU persons. Here's what you actually need to audit before your NCA inspection.

The EU AI Act is no longer a future compliance problem. Regulation (EU) 2024/1689 entered full enforcement in 2026, and National Competent Authorities across member states are actively conducting market surveillance. For CISOs in multinational organizations, the question is no longer "when do we need to comply" — it is "what do our auditors need to see when they arrive."

This breakdown focuses on the three areas generating the most friction in enterprise AI programs right now: Annex III high-risk classification, Article 50 transparency obligations, and the documentation requirements that will determine whether a fine reaches the €15M threshold or the €35M ceiling.

// The Penalty Structure: What €35M Actually Means

€35M
or 7% global annual turnover
Violations of prohibited AI practices under Article 5 — including real-time biometric surveillance in public spaces and social scoring systems
€15M
or 3% global annual turnover
Non-compliance with obligations for high-risk AI systems under Annex III — the category most enterprise AI systems fall into
€7.5M
or 1.5% global annual turnover
Provision of incorrect or misleading information to NCA auditors or notified bodies during a conformity assessment
⚠ CISO ALERT: "GLOBAL ANNUAL TURNOVER" APPLIES

The percentage-based cap applies to the global annual turnover of the entire undertaking — not the EU revenue. A US-headquartered company with €2B global revenue deploying a high-risk AI system in its EU HR platform faces a potential €60M fine (3% of €2B), not 3% of EU-only revenue.

// Annex III: What Counts as High-Risk

Most enterprise AI compliance teams underestimate how many of their systems qualify as high-risk under Annex III. The eight categories are broad and functionally defined — what matters is what the system does, not what it is marketed as.

annex_iii_classifier.txt // does this apply to your systems?
ANNEX III HIGH-RISK CATEGORIES

1. BIOMETRIC IDENTIFICATION & CATEGORIZATION
   → Any AI that identifies or categorizes natural persons by biometric data
   Likely: emotion recognition tools, identity verification, face analysis

2. CRITICAL INFRASTRUCTURE MANAGEMENT
   → AI in water, gas, electricity, transport, or digital infrastructure control
   Likely: predictive maintenance systems, anomaly detection in SCADA

3. EDUCATION & VOCATIONAL TRAINING
   → AI determining access to educational institutions or evaluating students
   Likely: automated admissions screening, exam proctoring AI

4. EMPLOYMENT & WORKER MANAGEMENT
   → AI for recruitment, CV screening, performance evaluation, termination
   Likely: ATS tools with AI ranking, productivity monitoring, scheduling AI

5. ACCESS TO PRIVATE ESSENTIAL SERVICES
   → AI for credit scoring, insurance risk, emergency services dispatch
   Likely: loan decisioning models, insurance underwriting AI

6. LAW ENFORCEMENT
   → Polygraph alternatives, risk assessment for criminal recidivism
   Highly restricted — contact legal before deploying

7. MIGRATION & ASYLUM
   → Visa application risk scoring, border control assistance
   Highly restricted — notified body conformity assessment required

8. ADMINISTRATION OF JUSTICE
   → AI assisting courts in interpreting facts or applying law
   Requires independent fundamental rights impact assessment

// Article 50: Transparency Obligations You May Be Missing

Article 50 applies to a much broader set of AI systems than Annex III — including general-purpose AI systems interacting with humans. The core obligations that are generating enforcement attention in 2026:

MANDATORY

AI Interaction Disclosure

Any AI system designed to interact with natural persons must disclose its non-human nature "in a clear and distinguishable manner" at the moment of interaction. This applies to customer service chatbots, AI-generated support emails, and autonomous agents sending communications on behalf of your organization to EU persons.

TRANSPARENCY

Synthetic Media Labeling

AI-generated or manipulated image, audio, and video content must carry machine-readable metadata indicating its synthetic origin. "Deepfake" content in commercial communications, marketing, and public information is explicitly covered. Compliance requires both technical watermarking and visible disclosure.

AUDIT TRAIL

Emotion Recognition Disclosure

Any system using emotion recognition technology must inform individuals that it is being used, even where the emotion data is not the primary output. This catches a surprising number of enterprise HR tech and security screening tools that use "engagement scoring" as a euphemism for emotion analysis.

// AI-SEC GLOBAL SUMMIT 2026 · NOV 18

Executive & CISO Governance Roundtable

Closed-door session with EU regulatory counsel, DPA representatives, and CISOs from regulated industries — covering live enforcement cases, NCA audit playbooks, and the documentation stack that determines fine severity.

REQUEST ROUNDTABLE ACCESS →

// The Documentation Stack NCAs Are Auditing

When an NCA conducts a market surveillance audit of a high-risk AI system, they are specifically looking for the documentation package mandated under Articles 11, 13, and 17. The absence of any component in this package is itself a violation — separate from the underlying compliance status of the system.

required_documentation.txt // art. 11, 13, 17 compliance package
TECHNICAL DOCUMENTATION (Art. 11)
  ├── General description of AI system and its intended purpose
  ├── Description of system architecture and component interactions
  ├── Training data sources, data governance, and preprocessing steps
  ├── Validation and testing methodology with performance metrics
  ├── Known limitations and foreseeable risks with mitigation measures
  └── Post-market monitoring plan

INSTRUCTIONS FOR USE (Art. 13)
  ├── Provider identity and contact details
  ├── AI system capabilities and performance limits
  ├── Hardware/software infrastructure requirements
  ├── Human oversight measures the deployer must implement
  └── Expected lifetime and maintenance/update requirements

QUALITY MANAGEMENT SYSTEM (Art. 17)
  ├── Risk management process documentation (Art. 9)
  ├── Data governance policy with access control records
  ├── Post-market monitoring procedures
  ├── Incident reporting and corrective action processes
  ├── Fundamental Rights Impact Assessment (FRIA)
  └── Conformity assessment records (notified body certificate if required)

RETENTION: All documentation must be maintained for 10 years post-deployment
MISSING FRIA: Most common compliance gap identified in 2026 audits

// Priority Compliance Checklist for CISOs

// The Strategic CISO Position

The organizations that will emerge from EU AI Act enforcement with their compliance posture intact are not the ones that built elaborate technical controls at the last minute. They are the ones that integrated AI risk governance into their existing information security management framework — treating the FRIA like a security impact assessment, treating the quality management system like an ISO 27001 control domain, and treating the NCA audit like a scheduled penetration test.

The enforcement cases that will define EU AI Act jurisprudence in 2026 and 2027 will be decided not on technical sophistication but on documentation completeness, human oversight implementation, and the speed of incident disclosure to competent authorities.

→ RELATED: UK AI REGULATORY DIVERGENCE

Post-Brexit, the UK has adopted a sector-led, principle-based approach rather than a single horizontal AI Act. UK-based organizations operating in both markets face a genuine dual-compliance challenge. The AI-Sec Summit CISO Roundtable includes a dedicated session on UK/EU regulatory arbitrage strategies.

EU AI Act Annex III GRC AI Governance CISO Strategy Regulatory Compliance