Even though the implementation of the AI Act is being delayed, this does not change the fact that requirements for the responsible use of AI are on the way. Companies should therefore take action now to mitigate risk and ensure compliance. The AI Act is not something you can put off—it is something you must prepare for.
Why the AI Act Remains Relevant, Even With Delays
Many companies may be tempted to put AI initiatives and compliance efforts on hold when regulations are postponed. That is a mistake.
The AI Act is designed to regulate the use of artificial intelligence in the EU, with a focus on risk management, transparency, and responsible use. The delay does not change the requirements—it only changes the timeline.
For Danish companies, this means:
- AI solutions will still be classified by risk level
- There will still be requirements regarding documentation and governance
- Employees' use of AI will continue to pose a security risk
The key question, therefore, is not when the AI Act will take effect, but whether the company is ready.
The AI Act and Cybersecurity: An Overlooked Risk
AI is already widely used in organizations—often without clear guidelines. This creates new vulnerabilities.
Examples of specific risks
- Employees enter sensitive data into AI tools
- AI is used to generate high-quality phishing emails
- Automated decisions are made without oversight or an audit trail
- Lack of awareness regarding AI policies
The AI Act specifically addresses these issues, but until the regulation is fully implemented, it is up to the companies themselves to take responsibility.
Here’s how companies should start working with the AI Act right now
If your organization wants to be well-prepared when the AI Act takes effect, you should start working systematically on the following right now:
1. Assess your use of AI
Identify where and how AI is used in the organization:
- Internal tools (e.g., Copilot, ChatGPT)
- Customer-focused solutions
- Automated processes
Without a clear overview, compliance is impossible.
2. Establish clear policies for the use of AI
Employees should know:
- What they can and cannot use AI for
- How data must be handled
- Which tools are approved
Awareness is crucial here.
3. Integrate AI into your existing security setup
AI should not be a separate track.
This needs to be taken into account:
- Information Security
- Risk assessments
- Compliance work (e.g., NIS2 and CIS18)
Get ready for the demands of the future with NIS2 compliance
Get a handle on your security level with CIS18 compliance
4. Train employees on new threat scenarios
AI is changing the way cyberattacks are carried out.
Phishing is becoming more targeted, more convincing, and harder to detect.
Test your organization with realistic attacks via phishing simulation
The AI Act is not just about compliance, but about competitiveness
Companies that take a proactive approach to AI governance and security achieve:
- Greater trust from customers and business partners
- Better control over data and processes
- Lower risk of security breaches
- Faster adaptation to new requirements
The AI Act should therefore not be viewed as a burden, but as an opportunity to professionalize the use of AI.
The AI Act Demands Attention Now
Even though the AI Act has been delayed, the message is clear: companies should take action now.
Regulations are coming, and the requirements will be extensive.
Organizations that get an early start on:
- governance
- awareness
- safe use of AI
will be significantly stronger both in terms of security and business.
The AI Act isn’t something you can prepare for at the last minute. It’s a strategic discipline that should be prioritized today.





