SEC536: Adversarial AI - Penetration Testing AI Systems


The paper argues the comparison holds in part: both are extraterritorial, horizontal laws enforced through national competent authorities, but the AI Act requires triaging which systems and activities are covered, rather than the near-universal obligations GDPR imposed.
Yes. A deployer that fine-tunes, rebrands, or repurposes a third-party AI system can be reclassified as its provider, taking on a far heavier set of obligations than it had as a deployer.
High-risk obligations for standalone AI systems apply from 2 December 2027. Obligations for high-risk AI embedded in regulated products apply from 2 August 2028.
No. Total GDPR fines reach approximately €7 billion, but that figure is concentrated in a handful of large penalties against major platforms, and the paper argues the real, lasting impact of GDPR was organisational change, not fines.
It covers AI system inventories, risk classification, governance responsibility, and expected strategic impact, plus whether prior GDPR experience helped organisations prepare this time.
About 10 to 15 minutes.
Yes. Individual responses are confidential and reported only in aggregate.