The EU AI Act: Compliance for Companies Serving the EU Market

The EU AI Act is a global business issue. Just like GDPR before it, it reaches beyond EU borders. If your organization does business in the EU, you are in scope. Full enforcement begins August 2, 2026, with fines of up to 35 million euros or 7% of global turnover for non-compliance.

GDPR gave North American security and legal teams a preview of how the EU enforces rules that cross borders. The EU AI Act raises the stakes for any organization running high-risk AI systems. If your AI agents are touching APIs or external platforms, your attack surface is the compliance surface, and it is almost certainly larger than you think.

What We Cover in this video:

  • Who the EU AI Act applies to and why organizations outside of Europe may still be subject to its requirements.
  • How the Act classifies AI systems by risk and what those risk categories mean for security, engineering, and compliance teams.
  • The security requirements for high-risk AI systems, including expectations for cybersecurity, resilience, accuracy, and robustness.
  • Why AI security extends beyond the model to the APIs, integrations, and MCP servers your AI agents rely on, and how that impacts compliance.
  • What Article 15 actually requires: cybersecurity resilience, accuracy, and robustness for high-risk AI systems.

August 2, 2026 is a fixed deadline. Every month without a continuous monitoring record is a month of compliance evidence you cannot recover.

Have questions about AI compliance? Check out the site for more information: https://salt.security/eu-ai-act-compliance