Browse
AI Directory Open Source AI News 🏆 AI Challenge AI Statistics
Browse by profession
Accounting, Bookkeeping & TaxCompliance, Audit & GRCConstructionCustomer SupportData ScienceMedical All 38 professions →
Company
About Advertise Submit a tool Get the free AI guide
Home AI Directory Career Paths AI News
Home AI News Cybersecurity
🔐 Cybersecurity

EU AI Act Cybersecurity Compliance Checklist (2026)

A practical checklist for the EU AI Act's cybersecurity rules, effective August 2026. Covers Article 15, high-risk systems, and tools to manage compliance.

August 31, 2026· 14 min read

The short answer

The EU AI Act became generally applicable on August 2, 2026, and its governance and transparency rules are already in force. However, following the 2026 “AI Omnibus” simplification package, the compliance deadline for most high-risk AI systems (the Annex III use cases like critical infrastructure and employment) has been extended to December 2, 2027. Providers and deployers of high-risk AI must still ensure their systems meet strict requirements for accuracy, robustness, and resilience against cyber threats as detailed in Article 15 of the regulation.

Verified against live pricing pages·30 Aug 2026·How we test

The EU’s Artificial Intelligence Act is the world’s first comprehensive law for AI. As of September 2026, its general provisions and transparency rules are already in force, and the 2026 “AI Omnibus” simplification package has pushed the compliance deadline for most high-risk systems out to December 2, 2027. For any organization developing, deploying, or whose AI outputs are used in the EU, that extended runway is a reason to prepare now, not a reason to wait. The Act imposes binding obligations, with penalties for non-compliance reaching up to €35 million or 7% of global annual turnover.

This isn’t just another compliance hurdle; it’s a fundamental shift in how we build and secure intelligent systems. For working AI & cybersecurity professionals, understanding these new rules is not optional. This guide provides a practical, actionable checklist for navigating the cybersecurity requirements of the EU AI Act, focusing on what matters most as of September 2026.

How We Evaluated These Requirements

ZEKAI reviews all compliance frameworks and tools independently. Our recommendations are based on the official text of Regulation (EU) 2024/1689, associated guidance from the European Commission, and our analysis of tools that can help meet these obligations. We do not accept payment for editorial placement. Our goal is to provide a clear, actionable path to compliance based on verifiable facts.

What Is the EU AI Act? A Cybersecurity-Focused Overview

The AI Act takes a risk-based approach, sorting AI systems into four categories. Understanding which category your system falls into is the first and most critical step.

7% of Global

Revenue Source: foley.com

The maximum fine for violating the EU AI Act’s rules on prohibited AI practices can be up to €35 million or 7% of a company’s total worldwide annual turnover, whichever is higher.

Core Cybersecurity Requirements for High-Risk AI (Article 15)

For cybersecurity professionals, Article 15 of the AI Act is the most important section. It mandates that high-risk AI systems must be designed and developed to achieve an appropriate level of “accuracy, robustness, and cybersecurity” throughout their lifecycle. This isn’t a vague suggestion; it’s a set of concrete technical and organizational obligations.

Here are the key pillars of Article 15:

These requirements apply to the AI system as a whole, not just the underlying model. This means the entire infrastructure, data pipelines, and APIs connected to the system are in scope.

A Practical Cybersecurity Compliance Checklist

Compliance is not a one-time task but a continuous process. Here is a step-by-step checklist to guide your efforts.

  1. Classify Your AI System: First, determine if any AI system you provide or deploy falls into the “high-risk” category based on the criteria in Article 6 and Annexes I and III. The European Commission has published guidelines with practical examples to help with this classification.
  2. Establish a Risk Management System (Article 9): Implement and document a risk management system that runs throughout the AI system’s entire lifecycle. This process must identify, estimate, and evaluate foreseeable risks to health, safety, and fundamental rights, and then adopt measures to manage them.
  3. Ensure Data Governance (Article 10): For any data used to train, validate, and test the high-risk system, you must ensure it is relevant, representative, and as free of errors and complete as possible. This includes examining and mitigating possible biases in the datasets.
  4. Implement Robustness & Cybersecurity (Article 15):
  5. Conduct a security risk assessment for the entire AI system.
  6. Implement technical measures to ensure resilience against adversarial attacks, data poisoning, and other AI-specific vulnerabilities.
  7. Develop fail-safe plans and technical redundancies to handle errors and faults.
  8. For learning systems, implement measures to address and mitigate feedback loops.
  9. Enable Human Oversight (Article 14): Design the system to allow for effective human oversight. This includes providing clear interfaces that allow the human overseer to understand the system’s capabilities and limitations and to decide when to intervene or discard the system’s output.
  10. Maintain Technical Documentation & Logs (Articles 11, 12, 19): Before placing the system on the market, create detailed technical documentation demonstrating compliance. The system must also be capable of automatically recording events (“logs”) while it is operating to ensure a level of traceability of the system’s functioning.
  11. Conduct a Conformity Assessment & Register: For most high-risk systems, providers must conduct a self-assessment to certify compliance. Once conformity is declared, you must register the system in the public EU database managed by the Commission.

Tools to Help Automate & Manage Compliance

No single tool can guarantee compliance, but modern security platforms can provide critical capabilities for meeting the technical requirements of the AI Act. The key is to leverage tools that provide visibility, monitoring, and protection across the entire AI system and its environment.

ToolPrimary FunctionHow It Helps with AI Act Compliance (as of September 2026)
Palo Alto Networks Cortex XDRExtended Detection & ResponseHelps meet Article 15 (Cybersecurity & Robustness) by integrating endpoint, network, and cloud data to detect and respond to sophisticated attacks. Its behavioral analytics can help identify anomalous activity that might indicate an adversarial attack or system misuse.
GitHubSource Code Management & DevSecOpsAddresses Article 15 (Cybersecurity) and Article 11 (Technical Documentation). GitHub’s Code Security and Secret Protection add-ons (formerly bundled as “Advanced Security”) provide code and secret scanning to secure the development lifecycle. The repository itself serves as a core part of the technical documentation and version control.

Swipe the table sideways →

8.0/10

Palo Alto Networks Cortex XDR

Excellent for Article 15’s robustness and monitoring needs, but only if you’re an enterprise-scale…

Excellent for Article 15’s robustness and monitoring needs, but only if you’re an enterprise-scale organization already in or moving to the Palo Alto ecosystem.

Price from
Quote-based; analyst estimates suggest approx. $81/endpoint/year for Pro
Free tier
No free tier available, enterprise sales motion only.
PA Tool review Palo Alto Networks Cortex XDR — read our full review Pricing, free tier and where it falls short
9.0/10

GitHub

Essential for secure development and documentation.

Essential for secure development and documentation. Meeting Article 15’s cybersecurity requirements for private repos now only requires the Team plan’s add-ons, not a full Enterprise upgrade.

Price from
Team: $4/user/month; Enterprise: from $21/user/month. Code Security and Secret Protection are paid add-ons available on both.
Free tier
Generous free tier with unlimited public/private repos and 2,000 Actions minutes/month. Code Security and Secret Protection are free for public repositories only.
GI Tool review GitHub — read our full review Pricing, free tier and where it falls short

Beyond the AI Act: NIST AI RMF & OWASP LLM Top 10

Compliance with the AI Act does not happen in a vacuum. Two other frameworks are critical for any cybersecurity professional working with AI:

Integrating these frameworks into your compliance strategy provides a comprehensive, defense-in-depth approach that satisfies legal requirements and builds genuinely trustworthy AI systems. As you prepare for the new era of AI regulation, remember that the goal is not just to check a box, but to build a sustainable culture of AI security and governance. For more resources, visit our hub for AI & cybersecurity professionals.

Does the EU AI Act apply to US companies?

Yes. The EU AI Act has extraterritorial scope. It applies to any company, regardless of its location, if its AI system is placed on the EU market or if the output produced by its system is used in the EU.

When does the EU AI Act become fully enforceable?

Enforcement is phased. Rules for prohibited AI systems became effective in early 2025, and the Act’s governance rules, GPAI obligations, and transparency requirements became applicable between August 2025 and August 2026. Following the 2026 “AI Omnibus” simplification package, the compliance deadline for high-risk AI systems in sensitive-use areas (Annex III) was extended to December 2, 2027, and for high-risk systems embedded in regulated products (Annex I) to August 2, 2028.

What are the penalties for not complying with the EU AI Act?

Penalties are severe and tiered. Violating the ban on unacceptable-risk AI can result in fines up to €35 million or 7% of global annual turnover. Non-compliance with other key requirements, including those for high-risk systems, can lead to fines up to €15 million or 3% of turnover.

Are all AI tools considered high-risk?

No. The majority of AI systems are expected to fall into the minimal or no-risk categories. An AI system is only “high-risk” if it is used as a safety component in specific regulated products or is used in one of the sensitive areas listed in Annex III of the Act, such as critical infrastructure, employment, or law enforcement.

What is the difference between a “provider” and a “deployer” in the AI Act?

A “provider” is the entity that develops an AI system and places it on the market or puts it into service under its own name. A “deployer” is an entity that uses a high-risk AI system under its own authority. Both have distinct obligations, but the provider bears the primary responsibility for initial compliance.

How does the AI Act relate to other cybersecurity laws like NIS2?

They are designed to work together. If an AI system is used in a sector covered by the NIS2 Directive (e.g., critical infrastructure), it must comply with both the cybersecurity requirements of NIS2 and the specific AI safety and transparency rules of the AI Act.

Do I need a third-party audit for my high-risk AI system?

It depends. For most high-risk AI systems listed in Annex III, the provider can perform a self-assessment of conformity. However, for AI systems that are components of products requiring a third-party conformity assessment under other EU laws (Annex I), that third-party assessment will also cover the AI Act requirements.

Sources (45)
  1. Official Text and Interpretation of EU AI Act Article 15, via vertexaisearch.cloud.google.com, June 2026
  2. OWASP Top 10 for LLM Applications 2025, via vertexaisearch.cloud.google.com, November 2024
  3. OWASP Top 10 for LLM Applications Project Overview, via owasp.org, August 2023
  4. “U.S. Companies Face EU AI Act’s Possible August 2026 Compliance Deadline”, via Hunton Andrews Kurth LLP, April 2026
  5. Mapping to OWASP Top 10 for LLM applications, via AWS Prescriptive Guidance
  6. “A guide to high-risk AI systems under the EU AI Act”, via Pinsent Masons, February 2024
  7. “Palo Alto Networks Pricing 2026: Ultimate Guide for Security Products”, via UnderDefense, January 2026
  8. “Declaring Accuracy and Robustness Metrics Under Article 15”, via Zen AI Governance, August 2026
  9. “High-risk AI in the European Union”, via DLA Piper Intelligence, February 2026
  10. “What are the OWASP Top 10 risks for LLMs?”, via Trend Micro, February 2026
  11. EU AI Act Service Desk – Article 15, via preoccupations.org
  12. “EU AI Act Compliance 2026: What High-risk AI Systems Must Do Now”, via Salt Security, 2026
  13. “NIST AI Risk Management Framework (AI RMF) Explained”, via Orca Security, May 2026
  14. “How to Achieve Cybersecurity Compliance with the EU AI Act”, via Ankura, September 2025
  15. “The enforcement framework of the AI Act”, via European Commission, August 2026
  16. “How the OWASP LLM Top 10 Applies to Code Generation”, via Sonar, 2026
  17. “EU AI Act: Transparency Obligations Take Effect 2 August 2026”, via Cooley, August 2026
  18. “NIST AI Risk Management Framework (AI RMF) Explained: What Enterprises Need to Know”, via Private AI, April 2026
  19. “NIST AI Risk Management Framework (AI RMF)”, via Palo Alto Networks
  20. “What is the NIST AI Risk Management Framework?”, via SentinelOne, October 2025
  21. “NIST AI Risk Management Framework: A simple guide to smarter AI governance”, via Diligent, July 2025
  22. “Compliance and Enforcement in Global AI Regulation”, via Foley & Lardner LLP, July 2026
  23. “Long awaited EU AI Act becomes law”, via White & Case, July 2024
  24. “EU AI Act: Risk-Classifications of the AI Regulation”, via trail AI, August 2026
  25. “What Are High-Risk AI Systems Within the Meaning of the EU’s AI Act”, via WilmerHale, July 2024
  26. “Draft Commission guidelines on the classification of high-risk AI systems”, via European Commission, May 2026
  27. “Palo Alto CORTEX XDR PRO Price”, via firewalls.com, 2022
  28. “EU AI Act | Updates, Compliance, Training”, via PECB
  29. “The EU AI Act and its interactions with Cybersecurity Legislation”, via BSI, April 2025
  30. “The EU AI Act: A Primer”, via CSET, September 2023 (updated January 2024)
  31. “High-level summary of the AI Act”, via EU Artificial Intelligence Act Portal
  32. “EU AI Act Compliance Guide for U.S. Businesses”, via STACK Cybersecurity, January 2026
  33. “How to Achieve EU AI Act Compliance and Build Trustworthy AI”, via Secureframe, September 2025
  34. “EU AI Act: What it means for AI regulation and compliance”, via Thales Group, April 2026
  35. “CrowdStrike vs Palo Alto Cortex XDR 2026: Pricing Model & SOC Fit”, via ZEKAI, August 2026
  36. “Cybersecurity of Artificial Intelligence in the AI Act”, via JRC Publications Repository, September 2023
  37. Cortex XDR license plan, via Palo Alto Networks Documentation Portal, August 2026
  38. “Cortex XDR Pro – license – 1 TB capacity”, via CDW.com
  39. “GitHub pricing 2026: All enterprise plans compared”, via eesel AI, June 2026
  40. “GitHub Pricing 2026: Plans, Hidden Costs & Real-World Examples”, via ZEKAI, March 2026
  41. “GitHub Pricing: Free, Pro, Team and Enterprise Costs (2026)”, via GetPricePulse, August 2026
  42. “Overview of the Code of Practice”, via EU Artificial Intelligence Act Portal, July 2025
  43. “Artificial Intelligence Act (full text)”, via activeMind.legal
  44. “Snyk vs GitHub Advanced Security 2026: Which AppSec Wins?”, via ZEKAI, April 2026
  45. “GitLab vs GitHub 2026: Which DevOps Platform Should You Choose?”, via Strapi, September 2025

See Zekai first in Google

This article is provided for general information only and does not constitute professional advice. Facts, product details, and figures were accurate to the best of our knowledge at the time of publication and may have changed since. Zekai is an independent publisher and is not affiliated with the companies mentioned. Spotted an error? See our Corrections & Removal Policy.

The weekly AI briefing for your profession

One weekly email: the AI changes that actually affect your profession — tools, deals, and what to do about them.

Free · 1 email/week · profession-segmented · unsubscribe anytime

More Cybersecurity stories

See Zekai first in Google