The European Union's AI Act is moving from rulebook to reality, and Article 50's transparency obligations are now a pressing concern for organizations deploying AI systems. With penalties reaching up to 15 million euros or three percent of worldwide turnover, the stakes are clear. But what does the first year of enforcement actually look like in practice?
Key facts
- Article 50 breaches can trigger fines up to 15 million euros or 3% of global annual turnover.
- First-year enforcement is expected to favor corrective orders over major financial penalties.
- AI agents interacting with people through ticketing queues or procurement portals can count as direct interaction under the AI Act.
- Simulated phishing or vishing exercises using cloned voices are not automatically exempt from transparency rules.
- The first Article 50 action is likely to be regulator-led on paper but complaint-led in reality.
- Organizations still lack clear answers on proving AI agent actions and assigning accountability.
What first-year enforcement will look like
Edwin Weijdema, Field CTO at Veeam, says the first year of enforcement will probably be a settling-in period. Drawing on lessons from GDPR and NIS2, he notes that individual member states will enforce the AI Act with their own procedures and priorities. That makes precise predictions difficult, but some patterns are emerging.
Corrective orders are likely to be far more common than headline fines. Regulators will look at proportionality, the scale of impact, whether a breach was intentional or negligent, how quickly an organization cooperated, and whether basic governance controls were already in place. Companies that make a genuine effort to comply may receive guidance rather than punishment.
Still, one or two major fines could appear to signal that regulators mean business. Weijdema says such fines may not land in the first year, but the operational risk is already real. Being ordered to suspend, relabel, change, or withdraw an AI-enabled process at speed can be far more disruptive than paying a fine. In year one, the bigger risk may be being told to stop using a system until the organization can prove it is compliant.
Agentic systems and the meaning of direct interaction
One of the most complex areas is agentic AI, where systems interact with people through indirect channels like ticketing queues, shared inboxes, or supplier procurement portals. Under the EU AI Act, the channel itself does not determine whether transparency obligations apply. The key question is whether the AI system is communicating directly with a natural person or whether a human intermediary exercises meaningful review and control.
If an AI drafts a response and a human reviews and sends it, that is very different from an AI agent autonomously replying to a customer, supplier, or employee. The latter can look like direct interaction even if it happens through a ticketing system rather than a chatbot window. Weijdema emphasizes that companies must make deliberate choices to separate internal agents from customer-facing ones. Access controls and privacy safeguards should apply across the organization, not only across the agents. As he puts it, telling an agent not to enter a room is not enough; the door also needs a lock.
Security testing with cloned voices
Security teams often run simulated phishing and vishing exercises, sometimes cloning an executive's voice to make the test realistic. These exercises fail if the material carries a label saying it is AI-generated. But Weijdema warns that these exercises are not automatically exempt from the AI Act's transparency requirements.
Cloning an executive's voice is especially sensitive. If AI makes a real person appear to say something they did not say, it can quickly become a deepfake scenario. A security purpose does not automatically create an exemption, and the argument that the exercise works better without disclosure is not a compliance justification by itself.
Organizations that decide not to label AI-generated elements of security exercises should be able to demonstrate that the legal basis and risks were carefully assessed. Weijdema recommends involving legal and compliance departments early, and documenting the reasoning behind the decision. Privacy, HR, and employee representatives should also be consulted, especially when a real person's voice, image, or likeness is used.
In most cases, he advises alternatives such as fictional personas, synthetic voices that do not imitate real employees, prior general notice that simulations may use synthetic media, and immediate post-exercise disclosure. The goal is to preserve realism without normalizing undisclosed executive impersonation. Documentation should cover the purpose of the exercise, its scope, the AI tools used, whether any real person was imitated, what disclosure was provided and when, what personal data was processed, why the approach was necessary and proportionate, what safeguards were in place, and how employees were debriefed afterward.
His message to security teams is direct: a security objective does not turn an undisclosed deepfake into a compliant one, and if a test requires cloning the CEO's voice, legal should be involved before anyone presses send.
Where the first action will come from
As of mid-June, only nine of the twenty-seven member states had designated both a market surveillance authority and a notifying authority. Twelve had partial designations, and six had neither. This uneven readiness raises the question of where the first Article 50 action will originate.
Weijdema expects the first formal action to come from a market surveillance authority, since enforcement responsibility sits at national level. But the practical trigger may be a complaint from a consumer group, competitor, employee, journalist, civil society organization, or affected individual. A defamation claim is possible, especially where synthetic audio or video damages someone's reputation, but that is more likely to be a parallel legal route than the first clean Article 50 enforcement case. Regulator-led action is the most likely scenario on paper, but complaint-led enforcement is the likely reality.
The unanswered accountability question
The question clients keep asking, according to Weijdema, is how to prove what an AI agent did, why it did it, and who was accountable. This remains a hard question with no clear answer. In cybersecurity and governance, evidence matters: logs, approvals, identities, access controls, retention, and audit trails. But agentic AI can reason, retrieve data, generate content, and take actions across multiple systems, so governance must move from policy documents into technical controls.
His advice is to treat AI agents like privileged digital identities. Give each agent an owner, a defined role, least-privilege access, monitoring, approval gates, and a kill switch. Organizations that do this will not only be more compliant; they will be more resilient.
Another recurring question concerns the boundary between transparency and security testing. Security teams need realistic simulations, but the AI Act pushes organizations toward disclosure when people interact with AI or are exposed to deepfakes. Designing exercises that remain realistic without crossing legal, ethical, or employee trust boundaries is difficult. Security teams want realism, regulators want transparency, and the challenge is designing exercises that satisfy both.
Other unresolved questions include who is ultimately accountable when an AI system causes harm, whether it is the vendor, the deployer, the business owner, or the executive team. Organizations also struggle with how to prove to regulators, customers, and the board that AI governance is working in practice and not just documented in policy. And there is the fundamental question of how much business value an organization is willing to lose to stay compliant, transparent, and auditable when using AI at scale.
Source: Help Net Security News