March 27, 2026

That is why companies should still start preparing now

Even though the implementation of the AI Act is being delayed, this does not change the fact that requirements for the responsible use of AI are on the way. Companies should therefore take action now to reduce…

Even though the implementation of the AI Act is being delayed, this does not change the fact that requirements for the responsible use of AI are on the way. Companies should therefore take action now to mitigate risk and ensure compliance. The AI Act is not something you can put off—it is something you must prepare for.

Why the AI Act Remains Relevant, Even With Delays

Many companies may be tempted to put AI initiatives and compliance efforts on hold when regulations are postponed. That is a mistake.

The AI Act is designed to regulate the use of artificial intelligence in the EU, with a focus on risk management, transparency, and responsible use. The delay does not change the requirements—it only changes the timeline.

For Danish companies, this means:

  • AI solutions will still be classified by risk level
  • There will still be requirements regarding documentation and governance
  • Employees' use of AI will continue to pose a security risk

The key question, therefore, is not when the AI Act will take effect, but whether the company is ready.

The AI Act and Cybersecurity: An Overlooked Risk

AI is already widely used in organizations—often without clear guidelines. This creates new vulnerabilities.

Examples of specific risks

  • Employees enter sensitive data into AI tools
  • AI is used to generate high-quality phishing emails
  • Automated decisions are made without oversight or an audit trail
  • Lack of awareness regarding AI policies

The AI Act specifically addresses these issues, but until the regulation is fully implemented, it is up to the companies themselves to take responsibility.

Here’s how companies should start working with the AI Act right now

If your organization wants to be well-prepared when the AI Act takes effect, you should start working systematically on the following right now:

1. Assess your use of AI

Identify where and how AI is used in the organization:

  • Internal tools (e.g., Copilot, ChatGPT)
  • Customer-focused solutions
  • Automated processes

Without a clear overview, compliance is impossible.

2. Establish clear policies for the use of AI

Employees should know:

  • What they can and cannot use AI for
  • How data must be handled
  • Which tools are approved

Awareness is crucial here.

3. Integrate AI into your existing security setup

AI should not be a separate track.

This needs to be taken into account:

  • Information Security
  • Risk assessments
  • Compliance work (e.g., NIS2 and CIS18)

Get ready for the demands of the future with NIS2 compliance
Get a handle on your security level with CIS18 compliance

4. Train employees on new threat scenarios

AI is changing the way cyberattacks are carried out.

Phishing is becoming more targeted, more convincing, and harder to detect.

Test your organization with realistic attacks via phishing simulation

The AI Act is not just about compliance, but about competitiveness

Companies that take a proactive approach to AI governance and security achieve:

  • Greater trust from customers and business partners
  • Better control over data and processes
  • Lower risk of security breaches
  • Faster adaptation to new requirements

The AI Act should therefore not be viewed as a burden, but as an opportunity to professionalize the use of AI.

The AI Act Demands Attention Now

Even though the AI Act has been delayed, the message is clear: companies should take action now.

Regulations are coming, and the requirements will be extensive.

Organizations that get an early start on:

  • governance
  • awareness
  • safe use of AI

will be significantly stronger both in terms of security and business.

The AI Act isn’t something you can prepare for at the last minute. It’s a strategic discipline that should be prioritized today.

Dion Grydell

Introductory Meeting – SecureFirst

Questions?

Should you have any questions, please do not hesitate to contact us by phone or email.

What is ransomware, and why do companies choose to pay millions to cybercriminals?

What is ransomware, and why do companies choose to pay millions to cybercriminals?

Ransomware has become one of the most serious cyber threats facing modern businesses. These attacks are no longer just about locking files; they increasingly involve extortion, data theft, and threats to a company’s operations and reputation. When the consequences become severe enough, even well-protected organizations may find themselves in a situation where paying a ransom becomes a real consideration.

But why does this happen, and what can companies do to reduce the risk?

How phishing training works

How phishing training works

Phishing remains one of the most common ways for cybercriminals to gain access to businesses. Even though spam filters, firewalls, and security systems are getting better, fake...