Compliance/EU AI Act/Cybersecurity

EU AI Act compliance for Cybersecurity

Cybersecurity AI typically isn't itself high-risk under Annex III, but value-chain responsibilities (Art. 25) + GPAI obligations (Art. 53 when using foundation models) apply. Sales into regulated customers cascades evidence demands.

Updated 15 May 2026·Adjacent application·Primary source ↗

What applies

Articles + provisions of Regulation (EU) 2024/1689 — Artificial Intelligence Act most directly engaged by Cybersecurity deployments:

  • Art. 25
  • Art. 53

What this looks like in Cybersecurity

Cybersecurity AI typically isn't itself high-risk under Annex III, but value-chain responsibilities (Art. 25) + GPAI obligations (Art. 53 when using foundation models) apply. Sales into regulated customers cascades evidence demands.

Flagship exampleCybersecurity vendor selling into NIS2 essential entities: customers ask for AI-decisioning evidence as part of their supply-chain assessment.

Where Promethean's evidence layer fits

The substrate emits specific evidence kinds that map to EU AI Act obligations. Most directly relevant for Cybersecurity:

For the full sector view including LLM-feature catalogue, tier recommendation, and reviewer-gate examples, see the Cybersecurity sector page.

Adjacent cells

Other regulations for Cybersecurity