Skip to content
AI SecurityLLMllm-securityPrompt Injection

EU AI Act enforcement started three weeks ago. Your AI tools are 76% unprotected.

3 min read
Share

EU AI Act enforcement started three weeks ago. Your AI tools are 76% unprotected.

On August 2, 2026, the EU AI Act's most consequential obligations entered active enforcement. Article 50 transparency requirements. Annex III high-risk AI system rules. Conformity assessments. Fines up to 35 million euros or 7% of global annual turnover. The week the enforcement machine switched on, NDSS 2026 published a study showing that 89.45% of production LLM-integrated applications carry at least one capability abuse vector, and that multi-turn jailbreaks now succeed 97% of the time against frontier models. Only 24% of enterprise GenAI projects include meaningful safeguards. That combination is the problem.

What the EU AI Act actually requires from you now

If your product uses a chatbot that EU users interact with, Article 50 requires clear disclosure that they are interacting with an AI system. If your AI-powered product falls into Annex III categories (HR screening, credit scoring, biometric identification, critical infrastructure management), you now need post-market monitoring, incident reporting to national authorities, and audit logging. This applies globally if your system outputs are used within the EU. Enforcement sits with national market surveillance authorities, not the central EU AI Office, which means 27 different enforcement regimes are now active simultaneously.

The jailbreak data is not academic

The NDSS 2026 study scanned 807,207 real applications integrating language models and found capability abuse vectors in nearly nine out of ten of them. Multi-turn jailbreaks, where an attacker gradually shifts the model's context across a conversation, succeed at a 97% rate against frontier models in controlled evaluations. Jailbreak-as-a-service kits are available on dark web forums for $50 to $200 per month. The 24% safeguard adoption rate means three out of four enterprise GenAI deployments have no meaningful protection against these techniques.

The enforcement and the exploit data point at the same gap

The EU AI Act exists precisely because legislators observed that AI deployments were outrunning safety practices. The NDSS data confirms this is still happening at scale, three years into the GenAI deployment wave. The regulatory response and the security research arrived in the same week, describing the same problem from two directions: most organizations deploying AI are doing so without the safeguards needed to meet regulatory requirements or resist attack techniques already in use against them.

Where to start if your GenAI project has no safeguards

Start with a capability audit: what can your AI system do, and what should it not be able to do? Add input filtering and output validation. Implement logging so you can detect anomalous interaction patterns. Classify whether your use case falls into Annex III categories and identify your Article 50 obligations. If you are in the 76% without safeguards, the question is not whether you will face a jailbreak attempt or a regulatory inquiry, it is which comes first.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are assessing your EU AI Act compliance posture or need to add safeguards to an existing GenAI deployment.

Related articles