The European Union's Artificial Intelligence Act is moving from rulebook to reality, and the first year of enforcement under Article 50 will be closely watched by every organization deploying AI systems. The provision addresses transparency obligations for AI systems that interact with natural persons or generate synthetic content, and it carries financial exposure of up to 15 million euros or three percent of worldwide annual turnover. But according to Edwin Weijdema, Field CTO at Veeam, the practical impact in the first year will likely be less about fines and more about corrective orders, operational disruption, and unresolved accountability questions.
Enforcement will vary by member state
Weijdema points out that, as with GDPR and NIS2, enforcement of the EU AI Act will be handled by individual member states rather than a single European regulator. That means procedures, priorities, and penalties will vary depending on the country. In the first year, regulators may treat enforcement as a bedding-in period, especially for organizations that can demonstrate a genuine effort to comply. Corrective orders, he argues, will significantly outnumber major financial penalties. Regulators will likely weigh proportionality, the scale of impact, intentionality or negligence, cooperation speed, and whether basic governance controls were already in place.
That does not mean fines are impossible. Weijdema notes that regulators sometimes issue one or two headline-making penalties to signal seriousness, but he would not expect that to happen in year one. Instead, the bigger practical exposure will be operational. An organization ordered to suspend, relabel, change, or withdraw an AI-enabled process at short notice could face far more disruption than a financial penalty. In year one, the biggest risk is being told to stop using a system until compliance is proven.
Agentic systems and direct interaction with people
A critical area of uncertainty is how the AI Act applies to agentic systems that interact with people indirectly through ticketing queues, shared inboxes, or procurement portals. Weijdema explains that the channel is not decisive. A ticketing queue or shared inbox does not automatically mean direct interaction with a natural person, but it can. The key question is whether the AI system itself is communicating with a person, or whether a human intermediary exercises meaningful review and control.
If an AI drafts a response and a human reviews and sends it, the risk profile is very different from an AI agent autonomously replying to a customer, supplier, or employee. The latter can begin to look like direct interaction, even if it happens through a backend system rather than a chatbot window. Organizations need to make deliberate choices to separate internal-facing and customer-facing agents, and to implement access and privacy controls across the entire organization, not just across individual agents. As Weijdema puts it, telling an agent not to enter a room is not enough; the door needs a lock.
The AI Act does not care whether the interaction occurs in a chatbot window or a ticket queue. It cares whether the human is effectively dealing with the machine.
Security testing and cloned voices
Security teams that run simulated phishing and vishing exercises sometimes clone an executive's voice to test employee awareness. Weijdema warns that these exercises are not automatically exempt from the AI Act's transparency requirements. There is understandable reluctance to label AI-generated phishing emails or cloned voices because the exercise loses its value if it is obvious. But cloning a real person's voice is particularly sensitive. If AI makes a person appear to say something they did not say, it can quickly become a deepfake scenario. A security purpose does not create an automatic exemption, and the argument that the exercise works better without disclosure is not a compliance justification.
Organizations that decide not to label AI-generated elements in these exercises should be able to demonstrate that the legal basis and risks were carefully assessed. Weijdema advises security teams to involve legal and compliance departments early, and to document reasoning. He also recommends including privacy, HR, and employee representatives, especially when using a real person's voice, image, or likeness. In most cases, he suggests alternatives such as fictional personas, synthetic voices that do not imitate real employees, prior general notice that simulations may use synthetic media, and immediate post-exercise disclosure. The goal is to preserve realism without normalizing undisclosed executive impersonation inside the company.
The internal documentation should cover the purpose and scope of the exercise, the AI tools used, whether any real person was imitated, what disclosure was provided and when, what personal data was processed, why the approach was necessary and proportionate, what safeguards were in place, and how employees were debriefed afterwards. Weijdema's direct advice to security teams: a security objective does not magically turn an undisclosed deepfake into a compliant one. If you have to clone the CEO's voice to make the test work, legal should be in the room before anyone presses send.
Where the first Article 50 action will come from
By mid-June, only nine of the twenty-seven member states had designated both a market surveillance authority and a notifying authority. Twelve had partial designations, and six had neither. This patchwork of readiness raises questions about where the first Article 50 action will originate. Weijdema believes it is most likely to come from a market surveillance authority because that is where enforcement responsibility sits at national level. But the practical trigger could come from elsewhere.
Defamation is probably the least likely as a first clean enforcement case, though it is possible when synthetic audio or video damages someone's reputation. Consumer groups could be likely candidates for an early challenge, especially for AI systems that affect large numbers of people. The most probable scenario is a regulator-led action on paper, but a complaint-led one in reality, triggered by a consumer group, competitor, employee, journalist, civil society organization, or affected individual.
The accountability question no one can answer
The most common question Weijdema hears from clients is a simple but profound one: How do we prove what an AI agent did, why it did it, and who was accountable? There is still no good answer. In cybersecurity and governance, evidence matters. Logs, approvals, identities, access controls, retention, and audit trails are essential. But agentic AI can reason, retrieve data, generate content, and take actions across multiple systems. Governance must move from policy documents into technical controls.
Weijdema advises clients to treat AI agents like privileged digital identities, with an owner, a defined role, least-privilege access, monitoring, approval gates, and a kill switch. Organizations that get this right will be more compliant and more resilient. Another recurring question is where transparency ends and security testing begins. Security teams need realistic simulations, but the AI Act pushes toward disclosure when people interact with AI or are exposed to deepfakes. Designing exercises that remain realistic without crossing legal, ethical, or employee trust boundaries is difficult. Security teams want realism, regulators want transparency, and the challenge is satisfying both.
Beyond those, clients are also asking who is ultimately accountable when an AI system causes harm, whether vendor, deployer, business owner, or executive team. They ask how to prove to regulators, customers, and the board that AI governance is working in practice, not just documented in policy. And they ask how much business value they are willing to lose to remain compliant, transparent, and auditable when using AI at scale. These questions remain open, and the first year of enforcement will likely force many organizations to confront them without clear answers.
Source: Help Net Security News