Bottom line: Companies deploying AI in the EU must comply with the EU AI Act's requirements, including data protection and human oversight, to mitigate risks to individuals and society.
What's happening: The EU AI Act, signed into law on July 19, 2023, targets AI developers, providers, and deployers, including multinational companies like Google, Microsoft, and Amazon, with requirements to ensure the safe and transparent use of AI, as outlined in the Act's Annex I.
What to do: Security leaders should ensure their companies' AI systems meet the EU AI Act's data protection requirements, including implementing robust access controls, data minimization, and human oversight, to minimize the risk of AI-related data breaches and other security incidents.