AI Governance Frameworks

EU AI Act

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

The world's first comprehensive AI law, with risk-based obligations, phased deadlines, and fines up to EUR 35 million or 7% of worldwide turnover. Explained here for organizations inside and outside the EU whose people and products touch AI.

European Union, with extraterritorial reachIn force since August 1, 2024; obligations applying in phases through 2027Verified 2026-08-31

What it means for AI and data privacy

The EU AI Act is binding law, not a framework: it bans some AI practices outright, imposes strict obligations on high-risk AI systems, and reaches organizations far beyond Europe, since it applies to providers and deployers outside the EU whenever the AI system's output is used in the EU. Its two workhorse provisions for anyone operating high-risk AI are Article 9, which requires a documented, continuous risk management system across the AI lifecycle, and Article 14, which requires effective human oversight of the system in use. The obligations arrive in phases: prohibitions took effect in February 2025, general-purpose AI obligations in August 2025, and most high-risk requirements in August 2026, with some product-embedded systems extending to 2027. Penalties top out at EUR 35 million or 7% of worldwide annual turnover. For Canadian and US organizations, the practical exposure is twofold: serving EU users or customers directly, and demonstrating to EU business partners that AI use, including employee use of AI tools on personal data, is under documented control.

Who it applies to

  • Providers placing AI systems or general-purpose AI models on the EU market, wherever the provider is established
  • Deployers of AI systems located in the EU, including employers whose staff use AI in regulated contexts
  • Providers and deployers outside the EU when the output of the AI system is used in the EU
  • Importers, distributors, and product manufacturers embedding AI in regulated products
  • Canadian and US vendors whose EU customers pass Act obligations down through contracts and diligence

Enforcement and penalties

Penalties are tiered by violation under Article 99. Engaging in prohibited AI practices (Article 5) draws fines up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Most other violations, including breaches of the high-risk obligations such as Articles 9 and 14, draw up to EUR 15 million or 3% of worldwide turnover. Supplying incorrect, incomplete, or misleading information to authorities draws up to EUR 7.5 million or 1%. National market surveillance authorities and the European AI Office enforce the Act, and caps are adjusted downward for SMEs and startups.

Key provisions for AI and data privacy

Article 9

Risk management system for high-risk AI

Article 9 requires providers of high-risk AI systems to establish, implement, document, and maintain a risk management system that runs as a continuous, iterative process across the entire lifecycle: identify foreseeable risks to health, safety, and fundamental rights, estimate and evaluate them including under reasonably foreseeable misuse, and adopt targeted risk management measures, with testing to confirm the residual risk is acceptable.

Fundamental rights include data protection, so the flow of personal data into and through an AI system is squarely inside the Article 9 analysis. Reasonably foreseeable misuse is the clause that catches everyday behaviour: employees feeding personal or confidential data into AI tools in ways the provider or deployer never intended is foreseeable, well documented, and therefore something the risk management system must anticipate and mitigate. IBM's 2025 breach study found 97% of organizations that suffered an AI-related breach lacked proper AI access controls, which is precisely the gap a functioning Article 9 process is supposed to close before an incident, not after.

Article 14

Human oversight

Article 14 requires high-risk AI systems to be designed so natural persons can effectively oversee them while in use: understand the system's capacities and limits, monitor its operation, remain aware of automation bias, correctly interpret output, and be able to intervene, override, or stop the system. Oversight measures can be built into the system or organized by the deployer.

Oversight is only effective if a person can actually see and act on what the AI is doing, including what data goes in. An organization where AI use happens invisibly in browser tabs cannot claim effective oversight: LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage, and 71% of GenAI connections go through personal, non-corporate accounts. Making AI interactions visible to accountable humans, and putting a control at the point where data enters, is the operational substance behind Article 14's design requirement.

Article 2

Scope and extraterritorial reach

Article 2 sets the Act's reach: it applies to providers placing AI systems or GPAI models on the EU market regardless of where they are established, to deployers located in the EU, and to providers and deployers located outside the EU where the output produced by the AI system is used in the EU.

This is the provision that makes the Act relevant in Toronto and Texas. A Canadian firm whose AI-assisted analysis, screening decisions, or generated content is used by clients in the EU can be within scope without any EU office. Even organizations that never trigger scope directly encounter the Act through contracts: EU customers and partners increasingly require evidence of AI governance, including controls on what data employees expose to AI tools, as a condition of doing business.

Articles 5 and 113 (timeline)

Prohibited practices and phased application

The Act entered into force on August 1, 2024, and applies in phases: prohibitions on unacceptable-risk practices (such as social scoring and certain biometric uses) and AI literacy duties from February 2, 2025; general-purpose AI model obligations from August 2, 2025; most remaining obligations, including the bulk of the high-risk regime, from August 2, 2026; and high-risk systems embedded in regulated products under Annex I from August 2, 2027.

The phase-in is a compliance calendar, not a grace period: the governance work behind Articles 9 and 14 (inventories, risk assessments, oversight design, data controls) takes quarters to build, and evidence of a functioning system cannot be backdated. Organizations that map their AI usage and put data controls in place now will meet the 2026 and 2027 deadlines with documentation already in hand; those that wait will be reconstructing what their employees did with AI after the fact.

Practical compliance steps

  1. 1Determine scope: inventory AI systems you provide or deploy, and check whether any output is used in the EU
  2. 2Classify each system against the Act's risk tiers, flagging anything near the Annex III high-risk categories
  3. 3Stand up an Article 9 risk management process that covers data flows, including reasonably foreseeable employee misuse of AI tools
  4. 4Design Article 14 oversight so accountable people can see AI use, interpret outputs, and intervene, rather than discovering usage after the fact
  5. 5Put a technical control at the point of entry so personal and confidential data is caught before it reaches AI tools
  6. 6Train staff on permitted AI use to satisfy the AI literacy duty that has applied since February 2025
  7. 7Track the phased deadlines (August 2026 and August 2027) and keep documentation ready for market surveillance authorities and EU business partners

How Sanitized AI maps to this

Article 9 (risk management system)

Redacting sensitive data in prompts before submission is a concrete risk management measure against the foreseeable misuse the Article requires providers and deployers to anticipate: employees exposing personal data to AI tools.

Article 14 (human oversight)

Administrator dashboards make employee AI usage and intercepted data categories visible, giving the humans responsible for oversight the awareness of actual system use that effective oversight presupposes.

Article 2 (extraterritorial scope) for non-EU organizations

Usage and interception reporting gives Canadian and US organizations the documented AI data controls that EU customers and partners request in diligence, whether or not the organization is directly in scope.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. Under Article 2 it applies to providers placing AI systems on the EU market wherever they are established, and to providers and deployers located outside the EU when the output of the AI system is used in the EU. A Canadian or US organization can be in scope with no EU presence at all, and many more feel the Act indirectly through EU customers' contracts and vendor diligence.

When do the EU AI Act obligations actually apply?

In phases. The Act entered into force on August 1, 2024. Prohibitions and AI literacy duties applied from February 2, 2025; general-purpose AI model obligations from August 2, 2025; most other obligations, including the bulk of the high-risk regime, from August 2, 2026; and high-risk AI embedded in regulated products under Annex I from August 2, 2027.

What are the penalties under the EU AI Act?

Up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited AI practices; up to EUR 15 million or 3% for most other violations, including breaches of the high-risk obligations; and up to EUR 7.5 million or 1% for supplying incorrect or misleading information to authorities. Caps are moderated for SMEs and startups.

What does Article 9 of the EU AI Act require?

A documented risk management system for high-risk AI that runs continuously across the lifecycle: identify reasonably foreseeable risks to health, safety, and fundamental rights, evaluate them including under foreseeable misuse, adopt measures that bring residual risk to an acceptable level, and test that the measures work. Data protection is a fundamental right, so personal data flowing into AI systems is part of the analysis.

What counts as human oversight under Article 14?

Oversight that actually works: the people responsible must be able to understand the system's capabilities and limits, monitor its operation, guard against automation bias, interpret its output correctly, and intervene or stop it. Oversight measures can be built into the system or implemented organizationally by the deployer. Invisible, unmonitored AI use is the opposite of what the Article describes.

Does the EU AI Act cover employees pasting data into chatbots?

Not as a standalone prohibition, but it reaches the behaviour through several doors: reasonably foreseeable misuse in the Article 9 risk analysis, the deployer's Article 14 oversight duties, the AI literacy obligation in force since February 2025, and the GDPR, which continues to apply in parallel to any personal data in those prompts. An organization with no control over what employees feed AI tools will struggle to evidence any of the four.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards