---
title: "The AI Act and the protection of digital rights: new compliance challenges"
description: Explore the compliance challenges posed by the AI Act and discover how organizations can balance innovation with the protection of digital rights.
image: https://blog.cyberoo.com/hubfs/Cyberoo%20Blog%20-%20Grafiche%20di%20copertina%20(3).gif
---

<https://blog.cyberoo.com/en/the-ai-act-and-the-protection-of-digital-rights-new-compliance-challenges#menu>

- Solutions
  
  Cyber Security Suite
  
    - [What is the Cyber Security Suite?](https://cyberoo.com/en/cyber-security-suite/)
    - [Cypeer – Internal Security](https://cyberoo.com/en/cypeer-managed-detection-and-response/)
    - [CSI – Cyber Threat Intelligence](https://cyberoo.com/en/cyber-threat-intelligence/)
  
  
  Cybersecurity Advisory
  
    - [Incident response](https://cyberoo.com/en/incident-response/)
    - [Risk Assessment](https://cyberoo.com/en/risk-assessment/)
    - [VA/PT](https://cyberoo.com/en/vulnerability-assessment-penetration-test/)
    - [Cyber Security Advisory & VCISO](https://cyberoo.com/en/cyber-security-advisory-vciso/)
  
  
  Titaan Suite
  
    - [Titaan Neemesi – GDPR compliance](https://cyberoo.com/en/titaan-neemesi-gdpr-compliance/)
  
  
  Security Awareness 
  
    - [KEATRIX – Human Risk & Security Training Platform for Business](https://cyberoo.com/en/keatrix-security-awareness-platform-business/)
- Corporate
  
  Cyberoo
  
    - [Company](https://cyberoo.com/en/cybersecurity-company/)
    - [Certifications](https://cyberoo.com/en/certifications/)
    - [People](https://cyberoo.com/en/people-in-cybersecurity/)
    - [Above The Rest](https://cyberoo.com/en/above-the-rest/)
    - [Jobs](https://cyberoo.com/en/jobs/)
  
  
  Investors
  
    - [Investors relations](https://cyberoo.com/en/investors-relations/)
    - [Sustainability](https://cyberoo.com/en/sustainability/)
- Resources
  
    - [Cyber Blog](https://blog.cyberoo.com/en)
    - [Tech Blog](https://cert.cyberoo.com/en/)
    - [Press News](https://cyberoo.com/en/news-press/)
    - [Media Kit](https://cyberoo.com/en/media-kit/)

[![Cyberoo](https://blog.cyberoo.com/hubfs/raw_assets/public/Cyberoo_May2023/images/CYBEROO-logo.svg)](https://cyberoo.com/en/)

- [Contacts](https://cyberoo.com/contacts/)
- [English](https://blog.cyberoo.com/en) 
    - [Italiano](https://blog.cyberoo.com/)
    - [Français](https://cyberoo.com/fr/)
    - [Deutsch](https://cyberoo.com/de/)
    - [Polski](https://blog.cyberoo.com/pl)
    - [Español](https://cyberoo.com/es/)

<https://blog.cyberoo.com/en/the-ai-act-and-the-protection-of-digital-rights-new-compliance-challenges#sidewidgetarea>

- Solutions 
    - Cyber Security Suite 
          - [What is the Cyber Security Suite?](https://cyberoo.com/en/cyber-security-suite/)
          - [Cypeer – Internal Security](https://cyberoo.com/en/cypeer-managed-detection-and-response/)
          - [CSI – Cyber Threat Intelligence](https://cyberoo.com/en/cyber-threat-intelligence/)
    - Cybersecurity Advisory 
          - [Incident response](https://cyberoo.com/en/incident-response/)
          - [Risk Assessment](https://cyberoo.com/en/risk-assessment/)
          - [VA/PT](https://cyberoo.com/en/vulnerability-assessment-penetration-test/)
          - [Cyber Security Advisory & VCISO](https://cyberoo.com/en/cyber-security-advisory-vciso/)
    - Titaan Suite 
          - [Titaan Neemesi – GDPR compliance](https://cyberoo.com/en/titaan-neemesi-gdpr-compliance/)
    - Security Awareness 
          - [KEATRIX – Human Risk & Security Training Platform for Business](https://cyberoo.com/en/keatrix-security-awareness-platform-business/)
- Corporate 
    - Cyberoo 
          - [Company](https://cyberoo.com/en/cybersecurity-company/)
          - [Certifications](https://cyberoo.com/en/certifications/)
          - [People](https://cyberoo.com/en/people-in-cybersecurity/)
          - [Above The Rest](https://cyberoo.com/en/above-the-rest/)
          - [Jobs](https://cyberoo.com/en/jobs/)
    - Investors 
          - [Investors relations](https://cyberoo.com/en/investors-relations/)
          - [Sustainability](https://cyberoo.com/en/sustainability/)
- Resources 
    - [Cyber Blog](https://blog.cyberoo.com/en)
    - [Tech Blog](https://cert.cyberoo.com/en/)
    - [Press News](https://cyberoo.com/en/news-press/)
    - [Media Kit](https://cyberoo.com/en/media-kit/)
- [Contacts](https://cyberoo.com/contacts/)
- [English](https://blog.cyberoo.com/en) 
    - [Italiano](https://blog.cyberoo.com/)
    - [Français](https://cyberoo.com/fr/)
    - [Deutsch](https://cyberoo.com/de/)
    - [Polski](https://blog.cyberoo.com/pl)
    - [Español](https://cyberoo.com/es/)

- <https://twitter.com/CYBEROO_ITALIA>
- <https://www.linkedin.com/company/cyberoo/>
- <https://www.youtube.com/channel/UC7AwVDG9Ngdwohk_zPd25xQ>
- <https://www.instagram.com/cyberoo_official/>
- <https://t.me/cyberoo_tech_blog>

![](https://blog.cyberoo.com/hubfs/Cyberoo%20Blog%20-%20Grafiche%20di%20copertina%20(3).gif)

# The AI Act and the protection of digital rights: new compliance challenges

 Published by [Barbara Sabellico](https://blog.cyberoo.com/en/author/barbara-sabellico) on  9 July 2026

Within European regulation of **artificial intelligence**, the **AI Act** represents one of the fundamental pillars for the protection of **digital rights**. Its aim is to strike a balance between **technological innovation** and the protection of citizens’ **privacy**, **non-discrimination** and **security**. From my perspective as a lawyer specialising in digital rights, with a focus on the **GDPR**, the **AI Act** and **cybersecurity**, it is now essential to guide companies towards a **proactive compliance** approach, capable of mitigating not only legal risks but also, and above all, the reputational risks to which they may be exposed.

## 3 Key Takeaways

- **The AI Act requires companies to adopt a proactive approach to compliance**  
  Organisations must prepare immediately for the obligations introduced by the regulation, particularly for high-risk AI systems, by incorporating requirements for transparency, robustness, human oversight and the protection of digital rights.
- **AI compliance cannot be managed in isolation**  
  The AI Act is intertwined with the GDPR, NIS2 and DORA, necessitating an integrated risk governance model capable of harmonising cybersecurity, data protection, management accountability and incident management.
- **Responsible AI management can become a competitive advantage**  
  Training, periodic audits, DPIA, incident response and voluntary certifications are not merely obligations or defensive tools: if managed with a strategic vision, they can strengthen stakeholder trust and consolidate ethical leadership in the field of digital rights.

 

## The AI Act and digital rights: a new balance between innovation and protection

The phased entry into force of the AI Act, particularly regarding the strict obligations for high-risk systems, requires organizations to take immediate action. This urgency is reinforced by enforcement mechanisms, with penalties for non-compliance reaching up to 6 percent of global turnover. Methodologically, the regulation adopts a risk-proportionate approach, strictly prohibiting practices deemed unacceptable—such as real-time biometric recognition in public spaces or subliminal manipulation—that directly threaten privacy and human autonomy (Articles 5–6). 

Particular attention is paid to systems classified as **high-risk**, a category which also includes various **artificial intelligence** applications in the field of **cybersecurity**, for example in surveillance systems, the management of critical infrastructure or credit scoring.

In these cases, the **AI Act** imposes stringent requirements regarding **transparency**, **robustness** and **human oversight**. In practical terms, this means designing secure systems right from the development stage, capable of withstanding adversarial attacks, **data poisoning** and **model inversion** techniques. All of this takes place within the framework of the rights guaranteed by the former Charter of Fundamental Rights of the European Union (Articles 8 and 21) and in constant coordination with the **GDPR**, particularly to reduce the risk of **discriminatory bias** and high-impact data processing.

 

## AI Act, NIS2 and DORA: compliance as an integrated responsibility

The **AI Act**, however, cannot be interpreted in isolation. Its regulatory framework is necessarily intertwined with the **NIS2** Directive, which covers essential sectors such as energy, healthcare and finance, and with the **DORA** Regulation for the financial sector. These instruments introduce obligations regarding **ICT risk management** and **incident reporting**, with different timeframes: 24 hours in the case of NIS2 and up to 15 days for the AI Act. This means that organisations must harmonise their **compliance** processes, avoiding overlaps or, worse still, gaps in accountability.

In the case of **artificial intelligence** systems applied to **cybersecurity**, the responsibility of **senior management** – already set out in Article 5 of **NIS2** – is also of particular importance. This responsibility now extends to accountability for any breaches of **digital rights**. A faulty or inadequately supervised AI model, for example in **threat detection** systems, can generate false positives with tangible impacts on the rights of defence or the privacy of data subjects.

In this sense, **robust compliance** also helps to strengthen the organisation’s **legal resilience**, reducing exposure to class actions under the Directive on Representative Actions and to investigations by supervisory authorities, such as the Data Protection Authority.

[![Cyberoo Observatory Report 2026](https://no-cache.hubspot.com/cta/default/6892231/55cf4778-1b18-4010-a961-113c0879e685.png)](https://cta-redirect.hubspot.com/cta/redirect/6892231/55cf4778-1b18-4010-a961-113c0879e685)

 

## From system robustness to corporate governance

From an operational perspective, the **AI Act** introduces very specific requirements. System robustness must include the ability to withstand evasion attacks, in line with the requirements of Article 32 of the **GDPR**. Transparency, on the other hand, entails the need to maintain **auditable logs** and traceability throughout the entire lifecycle of the systems, whilst also guaranteeing the right to an explanation of **automated decisions**. Added to this is the obligation to report **serious incidents** within 15 days and the option to adhere to sector-specific codes of conduct, which provide a presumption of compliance. Taken together, these elements outline a structured and clear framework, which is particularly relevant for senior management.

In such a context, it is important to consider what concrete actions can be taken. For **CEOs** and **COOs**, a first step is to establish a **Data Protection Board** with oversight responsibilities for artificial intelligence systems, alongside the definition of ethical policies consistent with the guidelines of the **EDPB** (European Data Protection Board). It is also essential to carefully assess risk profiles, including those of a criminal nature, particularly when dealing with health or financial data.

From a technical perspective, **CTOs** and **IT managers** are required to correctly classify the AI systems used internally, identifying those posing a high risk, particularly when artificial intelligence is integrated into security tools. The adoption of techniques such as **federated learning** or **differential privacy** can contribute significantly to reducing data exposure and improving the overall level of compliance.

The role of the **CISO** also becomes central. They are required to act proactively, carrying out AI-specific **DPIAs**, testing for vulnerabilities in accordance with the frameworks defined by **ENISA**, and drawing up **incident response** plans suited to attack scenarios amplified by artificial intelligence.

 

## Training, audits and ethical leadership in AI management

To complete this picture, it is essential to provide **mandatory training** on **digital rights** for all those involved in the use of intelligent systems, accompanied by periodic **audits** and **gap analyses**. Simulations of AI cyber scenarios and voluntary certifications can also become a tangible competitive advantage.

The**AI Act** should not be viewed merely as yet another regulatory requirement. If approached methodically and with a strategic vision, it can become a genuine opportunity to establish **ethical leadership** in the field of **digital rights** and to strengthen the trust of customers, partners and stakeholders.

**By Barbara Sabellico – Lawyer & DPO, Legal Tech expert**

[Back to Blog](https://blog.cyberoo.com/en)

- [Tweet](https://twitter.com/share)

## Related Articles

<https://blog.cyberoo.com/en/cybersecurity-2026-le-8-priorità-per-aziende-davvero-resilienti>

## [Cybersecurity 2026: the 8 priorities for truly resilient companies](https://blog.cyberoo.com/en/cybersecurity-2026-le-8-priorità-per-aziende-davvero-resilienti)

[Read More](https://blog.cyberoo.com/en/cybersecurity-2026-le-8-priorità-per-aziende-davvero-resilienti)

<https://blog.cyberoo.com/en/cybersecurity-2026-ai-threats-identity-risks-and-regulatory-changes>

## [Cybersecurity 2026: AI Threats, Identity Risks, and Regulatory Changes](https://blog.cyberoo.com/en/cybersecurity-2026-ai-threats-identity-risks-and-regulatory-changes)

 2026 marks a turning point in cybersecurity: threats are not only increasing in number, but also in...

[Read More](https://blog.cyberoo.com/en/cybersecurity-2026-ai-threats-identity-risks-and-regulatory-changes)

<https://blog.cyberoo.com/en/understanding-cybersecurity-essential-for-business-protection-in-2026>

## [Understanding Cybersecurity: essential for Business Protection in 2026](https://blog.cyberoo.com/en/understanding-cybersecurity-essential-for-business-protection-in-2026)

 Cybersecurity is the practice of implementing people, policies, processes, and technologies to...

[Read More](https://blog.cyberoo.com/en/understanding-cybersecurity-essential-for-business-protection-in-2026)

[![Cyberoo](https://blog.cyberoo.com/hubfs/raw_assets/public/Cyberoo_May2023/images/CYBEROO-logo.svg "Cyberoo")](https://blog.cyberoo.com/)

**TRUSTED BY USERS**

[![Capterra](https://blog.cyberoo.com/hubfs/raw_assets/public/Cyberoo_May2023/images/a0e3aa33abf348490d739e99e692012d.svg "Capterra")](https://www.capterra.com/reviews/206253/Cyber-Security-Suite?utm_source=vendor&utm_medium=badge&utm_campaign=capterra_reviews_badge)

![Gartner Peer](https://blog.cyberoo.com/hubfs/raw_assets/public/Cyberoo_May2023/images/GartnerPeerInsightsLogo-white.svg "Gartner Peer")

- SERVICES 
    - [CYPEER](https://cyberoo.com/en/managed-detection-and-response/)
    - [CSI](https://cyberoo.com/en/threat-intelligence/)
    - [INCIDENT RESPONSE](https://cyberoo.com/en/incident-response/)
    - [TITAAN NEEMESI](https://cyberoo.com/en/titaan-neemesi/)
    - [KEATRIX](https://cyberoo.com/en/keatrix-security-awareness-training/)

- USEFUL LINKS 
    - [WE ARE CYBEROO](https://cyberoo.com/en/company/)
    - [BLOG](https://blog.cyberoo.com/en)
    - [CONTACTS](https://cyberoo.com/en/contacts/)

© 2026 Cyberoo.  
Registered Office: Via Brigata Reggio, 37 - 42124 Reggio Emilia (RE) - PEC amministrazione@pec.cyberoo.com  
Fully paid-up share capital € 1.035.432,35 Tax Code and VAT No. 04318950286 - R.E.A. RE 288453  
[Privacy Policy](https://cyberoo.com/privacy-policy/) - [Privacy Policy - National Register of State Aids](https://www.rna.gov.it/RegistroNazionaleTrasparenza/faces/pages/TrasparenzaAiuto.jspx)- ISO27001

- <https://twitter.com/CYBEROO_ITALIA>
- <https://www.linkedin.com/company/cyberoo/>
- <https://www.youtube.com/channel/UC7AwVDG9Ngdwohk_zPd25xQ>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Barbara Sabellico",
    "url" : "https://blog.cyberoo.com/en/author/barbara-sabellico"
  },
  "dateModified" : "2026-07-10T07:12:31.576Z",
  "datePublished" : "2026-07-09T05:00:00.000Z",
  "headline" : "The AI Act and the protection of digital rights: new compliance challenges",
  "image" : [ "https://blog.cyberoo.com/hubfs/Cyberoo%20Blog%20-%20Grafiche%20di%20copertina%20(3).gif" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.cyberoo.com/en/the-ai-act-and-the-protection-of-digital-rights-new-compliance-challenges",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/vast.png"
    },
    "name" : "Cyberoo"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Article",
  "articleBody" : "Within European regulation of artificial intelligence, the AI Act represents one of the fundamental pillars for the protection of digital rights. Its aim is to strike a balance between technological innovation and the protection of citizens’ privacy, non-discrimination and security. From my perspective as a lawyer specialising in digital rights, with a focus on the GDPR, the AI Act and cybersecurity, it is now essential to guide companies towards a proactive compliance approach, capable of mitigating not only legal risks but also, and above all, the reputational risks to which they may be exposed. 3 Key Takeaways The AI Act requires companies to adopt a proactive approach to compliance Organisations must prepare immediately for the obligations introduced by the regulation, particularly for high-risk AI systems, by incorporating requirements for transparency, robustness, human oversight and the protection of digital rights. AI compliance cannot be managed in isolation The AI Act is intertwined with the GDPR, NIS2 and DORA, necessitating an integrated risk governance model capable of harmonising cybersecurity, data protection, management accountability and incident management. Responsible AI management can become a competitive advantage Training, periodic audits, DPIA, incident response and voluntary certifications are not merely obligations or defensive tools: if managed with a strategic vision, they can strengthen stakeholder trust and consolidate ethical leadership in the field of digital rights. The AI Act and digital rights: a new balance between innovation and protection The phased entry into force of the AI Act, particularly regarding the strict obligations for high-risk systems, requires organizations to take immediate action. This urgency is reinforced by enforcement mechanisms, with penalties for non-compliance reaching up to 6 percent of global turnover. Methodologically, the regulation adopts a risk-proportionate approach, strictly prohibiting practices deemed unacceptable—such as real-time biometric recognition in public spaces or subliminal manipulation—that directly threaten privacy and human autonomy (Articles 5–6). Particular attention is paid to systems classified as high-risk, a category which also includes various artificial intelligence applications in the field of cybersecurity, for example in surveillance systems, the management of critical infrastructure or credit scoring. In these cases, the AI Act imposes stringent requirements regarding transparency, robustness and human oversight. In practical terms, this means designing secure systems right from the development stage, capable of withstanding adversarial attacks, data poisoning and model inversion techniques. All of this takes place within the framework of the rights guaranteed by the former Charter of Fundamental Rights of the European Union (Articles 8 and 21) and in constant coordination with the GDPR, particularly to reduce the risk of discriminatory bias and high-impact data processing. AI Act, NIS2 and DORA: compliance as an integrated responsibility The AI Act, however, cannot be interpreted in isolation. Its regulatory framework is necessarily intertwined with the NIS2 Directive, which covers essential sectors such as energy, healthcare and finance, and with the DORA Regulation for the financial sector. These instruments introduce obligations regarding ICT risk management and incident reporting, with different timeframes: 24 hours in the case of NIS2 and up to 15 days for the AI Act. This means that organisations must harmonise their compliance processes, avoiding overlaps or, worse still, gaps in accountability. In the case of artificial intelligence systems applied to cybersecurity, the responsibility of senior management – already set out in Article 5 of NIS2 – is also of particular importance. This responsibility now extends to accountability for any breaches of digital rights. A faulty or inadequately supervised AI model, for example in threat detection systems, can generate false positives with tangible impacts on the rights of defence or the privacy of data subjects. In this sense, robust compliance also helps to strengthen the organisation’s legal resilience, reducing exposure to class actions under the Directive on Representative Actions and to investigations by supervisory authorities, such as the Data Protection Authority. From system robustness to corporate governance From an operational perspective, the AI Act introduces very specific requirements. System robustness must include the ability to withstand evasion attacks, in line with the requirements of Article 32 of the GDPR. Transparency, on the other hand, entails the need to maintain auditable logs and traceability throughout the entire lifecycle of the systems, whilst also guaranteeing the right to an explanation of automated decisions. Added to this is the obligation to report serious incidents within 15 days and the option to adhere to sector-specific codes of conduct, which provide a presumption of compliance. Taken together, these elements outline a structured and clear framework, which is particularly relevant for senior management. In such a context, it is important to consider what concrete actions can be taken. For CEOs and COOs, a first step is to establish a Data Protection Board with oversight responsibilities for artificial intelligence systems, alongside the definition of ethical policies consistent with the guidelines of the EDPB (European Data Protection Board). It is also essential to carefully assess risk profiles, including those of a criminal nature, particularly when dealing with health or financial data. From a technical perspective, CTOs and IT managers are required to correctly classify the AI systems used internally, identifying those posing a high risk, particularly when artificial intelligence is integrated into security tools. The adoption of techniques such as federated learning or differential privacy can contribute significantly to reducing data exposure and improving the overall level of compliance. The role of the CISO also becomes central. They are required to act proactively, carrying out AI-specific DPIAs, testing for vulnerabilities in accordance with the frameworks defined by ENISA, and drawing up incident response plans suited to attack scenarios amplified by artificial intelligence. Training, audits and ethical leadership in AI management To complete this picture, it is essential to provide mandatory training on digital rights for all those involved in the use of intelligent systems, accompanied by periodic audits and gap analyses. Simulations of AI cyber scenarios and voluntary certifications can also become a tangible competitive advantage. TheAI Act should not be viewed merely as yet another regulatory requirement. If approached methodically and with a strategic vision, it can become a genuine opportunity to establish ethical leadership in the field of digital rights and to strengthen the trust of customers, partners and stakeholders. By Barbara Sabellico – Lawyer &amp; DPO, Legal Tech expert",
  "author" : {
    "@type" : "Person",
    "name" : "Barbara Sabellico",
    "sameAs" : [ "https://www.linkedin.com/in/barbara-sabellico/" ],
    "url" : "https://blog.cyberoo.com/en/author/barbara-sabellico"
  },
  "dateModified" : "1784108924124",
  "datePublished" : "2026-07-09 05:00:00",
  "description" : "Explore the compliance challenges posed by the AI Act and discover how organizations can balance innovation with the protection of digital rights.",
  "editor" : {
    "@type" : "Person",
    "name" : "Barbara Sabellico"
  },
  "headline" : "The AI Act and the protection of digital rights: new compliance challenges",
  "image" : {
    "@type" : "ImageObject",
    "height" : 675,
    "url" : "https://content.cyberoo.com/hubfs/Cyberoo%20Blog%20-%20Grafiche%20di%20copertina%20%283%29.gif",
    "width" : 1200
  },
  "inLanguage" : "it-IT",
  "isAccessibleForFree" : true,
  "mainEntityOfPage" : {
    "@id" : "https://blog.cyberoo.com/en/the-ai-act-and-the-protection-of-digital-rights-new-compliance-challenges",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : ""
    },
    "name" : "Blog",
    "sameAs" : [ "https://www.linkedin.com/company/cyberoo-italia" ]
  },
  "url" : "https://blog.cyberoo.com/en/the-ai-act-and-the-protection-of-digital-rights-new-compliance-challenges",
  "wordCount" : 1043
}
```