Your AI hiring tool might be high-risk under the AI Act. Here's what that means.
AI Act transparency rules apply from August 2, 2026. High-risk employment AI rules apply from December 2, 2027. Practical preparation guide.
A fraudulent email or voice can sound polished and know internal details. That is not identity proof. AI phishing is not always convincing either. Look for an account change, urgency, an unfamiliar domain, or an unusual request. FBI IC3.
Cybersecurity is no longer just about firewalls and antivirus software. It's about whether your people can recognize a well-crafted attack.
Traditional phishing was relatively easy to spot. Poor grammar, suspicious sender, generic message. AI phishing is a different league.
AI can analyze publicly available information about the target (LinkedIn profile, company website, social media) and create an email that looks like it was written by a specific person from the company. No typos, the right tone, relevant context.
One of the traditional warning signs was poor language in phishing emails. With LLM models, this warning disappears. AI generates fluent, grammatically correct text including industry terminology.
How many of your employees would be able to distinguish a perfectly written phishing email from a real internal message?
Attackers combine AI with OSINT (open source intelligence). They monitor public procurements, company changes, financial statements. The phishing email then arrives at the right time with relevant content.
In 2025, cases emerged where attackers used deepfake voices for calls to managers:
A voice and caller ID do not establish identity. Verify changed payment details using a known contact from an existing contract and independent approval.
Technology alone isn't enough. Without established internal procedures, it's only half the solution.
When a request changes banking details, a safer system flags it for verification through a second channel and records the change in an audit log. The rule should be evaluated from confirmed incidents and false positives, not an unsupported marketing anecdote.
If more than two items are missing, assign an owner and a date for an exercise. It should test both reporting and the response. We can help with the scenario and training.
AI Act transparency rules apply from August 2, 2026. High-risk employment AI rules apply from December 2, 2027. Practical preparation guide.
Companies either ignore AI or try to change everything at once. Both are wrong. Here's a realistic 30-day plan.

Choose a first automation by scoring the work, data, risk, ownership, and reversibility. Then validate one pilot before you expand it.