LIVE · cybersecurity feed
Live wire
phishing

What the first year of EU AI Act transparency enforcement could look like

In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ticket queue counts as interacting with a person, and how security teams should handle simulated phishing that uses cloned

zeroday.news ·

The initial year of enforcement for the EU AI Act's Article 50 is expected to prioritize corrective orders over substantial financial penalties, according to an analysis by Edwin Weijdema, Field CTO at Veeam. While breaches of Article 50 carry potential exposure of up to 15 million euros or three percent of worldwide turnover, regulators are likely to adopt a "bedding-in" approach, particularly for organizations demonstrating genuine compliance efforts. Factors such as proportionality, impact scale, intent, cooperation speed, and existing governance controls will influence enforcement decisions.

However, the operational disruption of being ordered to suspend, relabel, modify, or withdraw an AI-enabled process could pose a greater immediate risk than monetary fines. While headline-making fines are anticipated eventually, they are not expected to materialize in the first year.

The Act's transparency obligations apply when a person interacts with an AI system and needs to be informed they are dealing with AI, unless the circumstances make it obvious. The channel of interaction, such as a ticketing queue, shared inbox, or procurement portal, is not the decisive factor. The key is whether the AI system itself is communicating with a natural person, or if a human intermediary is exercising meaningful review and control. For instance, an AI agent autonomously replying to a customer, supplier, or employee, even through a ticketing system, could be considered direct interaction, triggering transparency requirements. Companies must establish clear distinctions and appropriate barriers between internal and customer-facing AI agents, ensuring robust access and privacy controls.

Simulated phishing and vishing exercises that utilize AI-generated elements, such as cloned voices, are not automatically exempt from the AI Act's transparency requirements. While labeling these elements can undermine the exercise's effectiveness, using AI to make a real person appear to say something they did not say can quickly escalate into a deepfake scenario. A security purpose alone does not create an exemption, and the argument that "the exercise works better without disclosure" is not a sufficient compliance justification.

Organizations opting not to label AI-generated elements in these exercises must be able to demonstrate a careful assessment of the legal basis and risks involved. Best practices include involving legal and compliance departments early to document reasoning, and ideally including input from privacy, HR, and employee representatives, particularly if a real person's voice, image, or likeness is used. Alternative approaches such as fictional personas, synthetic voices that do not imitate real employees, prior general notice of synthetic media use, and immediate post-exercise disclosure are advisable. Documentation should detail the exercise's purpose and scope, AI tools used, whether a real person was imitated, disclosure provided and when, personal data processed, necessity and proportionality of the approach, safeguards in place, and employee debriefing.

As of mid-June, only nine of the twenty-seven EU member states had fully designated both a market surveillance authority and a notifying authority, with twelve having partial designations and six having neither. While a market surveillance authority is the most likely formal originator of an Article 50 action, the practical trigger could come from other sources. Defamation claims are less likely to be the initial clean Article 50 enforcement case, though possible where synthetic media damages reputation. Consumer groups could initiate early challenges for AI systems impacting large numbers of people. However, regulator-led action is considered the most probable starting point for the first Article 50 case, even with some markets still establishing their enforcement structures.

phishingai
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

US fuel gauge exposure fell by more than half in three months

Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months sit below the previous year’s floor, and the decline holds up against checks for address churn and port hopping. Exposure figures rarely move this way, and almost never t

ai

ShieldFont Fights AI Scraping With Deceptive Text

A new web font called ShieldFont has been developed to combat AI-driven web scraping. It displays one version of text to human users while serving a different, altered text to automated crawlers that inspect the page's source code. This technique aims to confuse AI models trained on scraped data by providing them with inaccurate information.

ai

How the famed USENIX Security conf is managing a flood of papers in the AI era

AI usage is evident but isn't yet a serious problem

ai

OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it

OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]

malware

ClickFix attack pushes macOS infostealer for crypto theft attacks

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]

security

ChainDrop: Inside a Self-Propagating npm Worm

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.