The EU AI Act in Cyprus

Last reviewed: 30 August 2026

The EU AI Act is in force across the European Union, including Cyprus. Parts of it already apply to businesses of every size — not only to technology companies, and not only to organisations building AI systems. If your business uses an AI tool, some obligations are already yours.

This page sets out what applies today, what was postponed in July 2026, and what is coming next.

Much of the guidance you will read is out of date

The AI Act was amended on 27 July 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which moved several major deadlines.

A great deal of published material — including advice still circulating from consultants and software vendors — describes the timetable as it stood before that amendment. In particular, you may have read that obligations for high-risk AI systems applied from August 2026. They do not. They were deferred.

Getting this wrong is expensive in either direction: preparing for a deadline that has moved wastes money, and assuming everything was postponed leaves you exposed to the parts that were not.

What applies right now

Prohibited practices (Article 5) — since 2 February 2025. Certain uses of AI are banned outright, including social scoring, inferring emotions in the workplace or in education, biometric categorisation to infer protected characteristics, and untargeted scraping of facial images to build recognition databases. Two further prohibitions take effect on 2 December 2026.

AI literacy (Article 4) — since 2 February 2025. Providers and deployers must take measures to support a sufficient level of AI literacy among the people operating AI systems on their behalf. The Digital Omnibus softened the wording of this duty, but it remains binding.

Transparency (Article 50) — since 2 August 2026. This is the obligation most businesses have missed. If people interact with your AI system directly — a website chatbot, for example — they must be told they are dealing with a machine. AI-generated image, audio and video content must be marked as artificially generated in a machine-readable format. Deepfakes must be disclosed. AI-generated text published to inform the public on matters of public interest must be disclosed as such, unless it has been through human review and a person or organisation holds editorial responsibility for it.

Generative systems already on the market have until 2 December 2026 to meet the marking and detection requirements.

What was postponed

Obligations for high-risk AI systems listed in Annex III — including systems used in recruitment, credit scoring, education and access to essential services — moved from 2 August 2026 to 2 December 2027.

Obligations for high-risk AI embedded in already-regulated products under Annex I — medical devices, machinery, toys — moved to 2 August 2028.

The reason was practical rather than political: the harmonised technical standards that would allow providers to demonstrate compliance were not ready in time.

Does the AI Act apply to my business?

Probably, and to a greater extent than most owners expect.

The Act distinguishes between providers, who develop AI systems and place them on the market, and deployers, who use them under their own authority. Almost every Cypriot business using AI is a deployer rather than a provider — and deployers carry obligations of their own.

You are likely in scope if your website uses a chatbot, if you publish content produced with AI assistance, if your staff use generative AI tools in their work, or if software you already licence has AI features built into it. The last of these catches more businesses than the rest combined, because the feature usually arrives in an update nobody read.

What the penalties are

Breaching the prohibitions in Article 5 carries fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher. Most other breaches, including the transparency obligations, carry up to €15 million or 3%. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%.

For comparison, the upper tier under the GDPR is 4%.

Where the AI Act meets the GDPR

The two operate together. Where an AI system processes personal data, the GDPR applies in full and is not displaced by the AI Act: you still need a lawful basis, the processing still belongs in your record of processing activities, the provider is still a processor requiring Article 28 terms, and processing likely to result in a high risk still requires a Data Protection Impact Assessment.

Article 22 GDPR also continues to apply to decisions made about people by automated means, without meaningful human involvement.

In practice, most AI Act questions turn out to have a data protection question underneath them.

How we can help

We work with Cypriot businesses on exactly this: establishing which obligations are yours, closing the gaps, and putting governance in place before anyone asks to see it.

Our AI Act services include a transparency check against Article 50, a full readiness assessment, AI acceptable use policies and system registers, staff AI literacy training, and vendor and tool assessment.

See our AI Act & AI Governance services

We advise; we do not implement. We sell no software and take no vendor commissions, so our recommendation is the whole product. And where we act as your Data Protection Officer, we will not build systems that we would then have to audit.

Ask us about the AI Act

This page is general information about the EU AI Act and its application in Cyprus. It is not legal advice. The AI Act is being actively amended; the position stated here was verified on 30 August 2026.