The EU AI Act in Cyprus: What Businesses Actually Need to Do Now
- 9 minutes ago
- 5 min read
The EU Artificial Intelligence Act — Regulation (EU) 2024/1689 — is the first horizontal EU regulatory framework for artificial intelligence. It entered into force on 1 August 2024 and applies directly in Cyprus, without the need for transposing legislation. It does not sit in isolation. Any business using AI to process personal data is also operating under the General Data Protection Regulation (Regulation (EU) 2016/679) and the Cyprus Law on the Protection of Natural Persons with Regard to the Processing of Personal Data (Law 125(I)/2018). The two regimes are enforced by different Cyprus authorities and businesses need to satisfy both.
The Act's obligations have not all landed on the same date, and the timeline has moved once already. Businesses that assumed the original schedule still holds are working from the wrong compliance calendar.
The risk-based structure
The Act classifies AI systems by risk rather than regulating AI as a single category.
Unacceptable risk — practices prohibited outright under Article 5. This includes social scoring by public authorities, manipulative AI that exploits vulnerabilities, most forms of real-time remote biometric identification in public spaces by law enforcement, and — added by amendment in 2026 — AI systems designed to generate non-consensual intimate imagery or child sexual abuse material. These prohibitions have applied since 2 February 2025, with the new imagery-related prohibitions applying from 2 December 2026.
High-risk — systems listed in Annex III (including AI used in employment decisions, access to essential services, credit scoring, education, and law enforcement) and AI embedded in products already regulated under EU product-safety law (Annex I — medical devices, machinery, and similar). These carry the heaviest obligations: risk management systems, data governance requirements, technical documentation, human oversight, and conformity assessment before the system can be placed on the market.
Limited risk — systems subject to transparency obligations under Article 50: chatbots must disclose that a user is interacting with AI, and providers of systems generating synthetic audio, image, video or text must label the output as artificially generated, including deepfakes.
Minimal risk — the majority of AI systems in ordinary commercial use, which fall outside specific obligations under the Act, though general-purpose AI (GPAI) model rules apply separately to model providers regardless of the use case.
The timeline has changed — and this matters
The Act's high-risk obligations were originally due to apply from 2 August 2026. That date no longer holds for standalone high-risk systems.
On 19 November 2025, the European Commission proposed the Digital Omnibus on AI to address delays in the underlying technical standards the high-risk regime depends on. After a contested negotiation, the Council of the EU gave final approval on 29 June 2026 and the European Parliament had already endorsed the package on 16 June 2026. The amending regulation — Regulation (EU) 2026/1744 — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original deadline.
The practical effect:
Standalone high-risk systems under Annex III (employment, credit, education, law enforcement and similar) — compliance deferred from 2 August 2026 to 2 December 2027.
AI embedded in products already covered by EU product-safety law under Annex I — deferred to 2 August 2028.
What did not move: the Article 50 transparency and labelling obligations took effect on schedule on 2 August 2026. GPAI provider obligations have applied since 2 August 2025. The Article 5 prohibitions have applied since 2 February 2025, with the new imagery-related prohibitions from 2 December 2026.
The deferral is a relief on the hardest compliance work, not a suspension of the Act. Businesses still need to classify their AI systems now, because the deferred deadlines assume classification and readiness work is already under way, and any high-risk system placed on the market before the new dates is treated as pre-existing only until it is substantially modified — at which point the full obligations apply immediately.
Cyprus institutional architecture
Cyprus designated its national competent authorities by Council of Ministers decision on 22 January 2025, ahead of the 2 August 2025 deadline under Article 70 of the Act.
The Deputy Ministry of Research, Innovation and Digital Policy coordinates overall implementation and represents Cyprus on the European Artificial Intelligence Board.
The Commissioner of Electronic Communications and Postal Regulation was designated as the notifying authority, a market surveillance authority, and the national single point of contact — a centralised model, in contrast to Member States that have split these functions across multiple bodies.
Separately, the Commissioner for Personal Data Protection retains supervisory authority wherever an AI system processes personal data, under the GDPR and Law 125(I)/2018.
Secondary legislation finalising the national penalty regime and the precise powers of the various authorities is still expected before the Cypriot Parliament.
The AI Act and GDPR are not the same test
Most AI systems that fall within the Act's scope also process personal data, and the two frameworks impose distinct — and cumulative — obligations. Passing an Article 22 risk assessment under the AI Act does not discharge a business's obligations under the GDPR, and vice versa.
In practice this means:
A data protection impact assessment under Article 35 GDPR may be required alongside the AI Act's own risk management and conformity assessment obligations for high-risk systems.
Automated decision-making provisions under Article 22 GDPR continue to apply where an AI system produces legal or similarly significant effects on an individual — this exists independently of whether the system is classified as high-risk under the AI Act.
Lawful basis, data minimisation and purpose limitation apply to the training and operation of AI systems as they would to any other processing activity, regardless of the system's AI Act risk tier.
The Commissioner for Personal Data Protection and the Commissioner of Electronic Communications and Postal Regulation can each open independent lines of enquiry into the same deployment.
Businesses building compliance programmes around one framework in isolation are exposed on the other.
Penalties
The Act sets three tiers of administrative fines: up to €35 million or 7% of global annual turnover, whichever is higher, for breaches of the Article 5 prohibitions; up to €15 million or 3% for breaches of most other obligations, including the high-risk regime and GPAI provider duties; and a lower tier for supplying incorrect, incomplete or misleading information to a competent authority. These sit alongside, and are enforced separately from, GDPR fines for the same conduct where personal data is involved.
What this means in practice
For international businesses operating in or through Cyprus, three things follow from the above.
First, classification cannot wait for the deferred deadlines. Knowing whether a system is prohibited, high-risk, limited-risk or minimal-risk determines which obligations apply and when — and that analysis takes time businesses should start now rather than in late 2027.
Second, the transparency obligations are live. Any business using chatbots, generative content tools, or synthetic media in a Cyprus-facing or EU-facing service should already have disclosure and labelling in place — this was not deferred and enforcement has started.
Third, AI governance needs to be built as a single programme covering both the AI Act and GDPR, with clear ownership of the interface between the Commissioner of Electronic Communications and Postal Regulation and the Commissioner for Personal Data Protection, rather than as two separate compliance exercises that happen to touch the same system.
This article is provided for general informational purposes only and does not constitute legal advice. Specific legal advice should be sought before taking any action in reliance on the contents of this article.




Comments