In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ticket queue counts as interacting with a person, and how security teams should handle simulated phishing that uses cloned

The initial year of enforcement for the EU AI Act's Article 50 is expected to prioritize corrective orders over substantial financial penalties, according to an analysis by Edwin Weijdema, Field CTO at Veeam. While breaches of Article 50 carry potential exposure of up to 15 million euros or three percent of worldwide turnover, regulators are likely to adopt a "bedding-in" approach, particularly for organizations demonstrating genuine compliance efforts. Factors such as proportionality, impact scale, intent, cooperation speed, and existing governance controls will influence enforcement decisions.
However, the operational disruption of being ordered to suspend, relabel, modify, or withdraw an AI-enabled process could pose a greater immediate risk than monetary fines. While headline-making fines are anticipated eventually, they are not expected to materialize in the first year.
The Act's transparency obligations apply when a person interacts with an AI system and needs to be informed they are dealing with AI, unless the circumstances make it obvious. The channel of interaction, such as a ticketing queue, shared inbox, or procurement portal, is not the decisive factor. The key is whether the AI system itself is communicating with a natural person, or if a human intermediary is exercising meaningful review and control. For instance, an AI agent autonomously replying to a customer, supplier, or employee, even through a ticketing system, could be considered direct interaction, triggering transparency requirements. Companies must establish clear distinctions and appropriate barriers between internal and customer-facing AI agents, ensuring robust access and privacy controls.
Simulated phishing and vishing exercises that utilize AI-generated elements, such as cloned voices, are not automatically exempt from the AI Act's transparency requirements. While labeling these elements can undermine the exercise's effectiveness, using AI to make a real person appear to say something they did not say can quickly escalate into a deepfake scenario. A security purpose alone does not create an exemption, and the argument that "the exercise works better without disclosure" is not a sufficient compliance justification.
Organizations opting not to label AI-generated elements in these exercises must be able to demonstrate a careful assessment of the legal basis and risks involved. Best practices include involving legal and compliance departments early to document reasoning, and ideally including input from privacy, HR, and employee representatives, particularly if a real person's voice, image, or likeness is used. Alternative approaches such as fictional personas, synthetic voices that do not imitate real employees, prior general notice of synthetic media use, and immediate post-exercise disclosure are advisable. Documentation should detail the exercise's purpose and scope, AI tools used, whether a real person was imitated, disclosure provided and when, personal data processed, necessity and proportionality of the approach, safeguards in place, and employee debriefing.
As of mid-June, only nine of the twenty-seven EU member states had fully designated both a market surveillance authority and a notifying authority, with twelve having partial designations and six having neither. While a market surveillance authority is the most likely formal originator of an Article 50 action, the practical trigger could come from other sources. Defamation claims are less likely to be the initial clean Article 50 enforcement case, though possible where synthetic media damages reputation. Consumer groups could initiate early challenges for AI systems impacting large numbers of people. However, regulator-led action is considered the most probable starting point for the first Article 50 case, even with some markets still establishing their enforcement structures.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.