EU AI Act: Pressure on IT and data managers in the AI sector remains high

Companies should not wait for a possible extension of the Digital Omnibus deadline
Sascha Uhl, „Senior Solutions Architect, Technical Alliances“ bei Cloudian
Sascha Uhl, „Senior Solutions Architect, Technical Alliances“ bei Cloudian, Bild: Cloudian

This EU legislation on the use of AI places high demands on data management, which can only be efficiently met using suitable platforms – Cloudian advises on curbing ‘data sprawl’ and regaining control over data through modern data and storage systems

Even though the EU postponed some of the deadlines for the ‘EU AI Act’ as part of its ‘Digital Omnibus’, those responsible within companies would be well advised never to sit back and relax. In a recent statement, Cloudian warned that, as long as this postponement has not yet been finalised, the original deadlines remain in force – and some of these expired already in August 2026.

The ‘EU AI Act’ sets strict requirements for so-called high-risk AI

It appears that more and more companies are developing their own AI systems – whether to achieve optimal results in their own specific use cases, to have greater control over the AI’s decisions, or to reduce their reliance on external providers.

As a result, however, more and more companies have come to fall under the scope of the ‘EU AI Act’, which, as is well known, sets out strict requirements for so-called high-risk AI. Responsibility for this is shared across several roles – from ‘compliance’ and ‘data protection’ to ‘AI teams’ and ‘storage and infrastructure management’, which provides the appropriate data infrastructure.

However, as the requirements of the ‘EU AI Act’ can only be met in part at the model and application levels, Cloudian argues that suitable storage platforms are needed to facilitate implementation. The ‘data sprawl’ that exists in many places, with widely dispersed data sets – some even managed by different platforms – is, in any case, more of a hindrance. When modernising their ‘data and storage environments’, IT and data managers must therefore pay particular attention to ‘data governance’ throughout the entire data lifecycle.

High-quality and representative data is required for AI training

The ‘EU AI Act’ expressly requires high-quality and representative data for the training, validation and testing of AI models (see Article 10). In order to be able to select and prepare suitable data, companies should therefore already know exactly what data they have at their disposal, where it is located, what sources it comes from, and how balanced and appropriate it is for the specific use case.

It is only with the help of such platforms – which support metadata, version control and ‘data lineage’ – that it has become possible to trace the origin and changes throughout the entire data lifecycle, carry out bias checks and compile optimal ‘data sets’.

Furthermore, such platforms also help to identify and remove specific data records containing personal data when data subjects exercise their right to erasure under the GDPR – without affecting the entire ‘data set’ or the AI model trained on it.

Audit trails for AI operations must be robust and immutable

In order to monitor the behaviour of AI and enable the authorities to carry out checks, companies would have to automatically record logs of all relevant events – throughout the entire lifecycle of the AI system (see Article 12).

However, these logs would only be truly reliable if it were ensured that they had not been altered, either deliberately or accidentally.

Companies therefore are in need of platforms with so-called WORM functionality (‘Write Once, Read Many’) – after all, an audit trail is only trustworthy if it is immutable – and thus tamper-proof.

Protecting AI training data from manipulation

An AI model can only ever be as good as the data used to train it. However, it is not only the selection of suitable training data that is of particular importance, but also its protection, as cybercriminals could use manipulation to ensure that the AI delivers inaccurate or incorrect results.

Companies must prevent this ‘data poisoning’, according to Article 15 of the ‘EU AI Act’. Platforms with WORM functionality could also help to ensure the immutability – and thus the trustworthiness – of the training data. At the same time, companies could use this approach to protect their training and input data from being encrypted by ransomware.

Role-based access controls, multi-factor authentication and monitoring functions also ensure that only authorised users can access the data and that all access is documented in a traceable manner. Ideally, these controls should be implemented at the infrastructure level.

Local data storage for compliance and cost control in the use of AI

Although the ‘EU AI Act’ does not specify where companies must store data for AI, the requirements for ‘data governance’, record-keeping, robustness and cybersecurity can be implemented much more easily ‘on-premises’.

At the same time, local data storage also facilitates compliance with obligations arising from the GDPR, NIS2 and the ‘Cyber Resilience Act’ – which, together with the ‘EU AI Act’, are intended to create a comprehensive EU legal framework for secure, resilient and trustworthy IT systems.

Furthermore, companies with on-premises infrastructure, in particular, could benefit in terms of digital sovereignty and cost control, as the public cloud often poses the risk of unexpected cost increases and 84 per cent of companies have exceeded their budgets for cloud storage. There is therefore a clear business case for repatriating data back to one’s own data centre.

The need for AI data infrastructure is a priority

Sascha Uhl, ‘Senior Solutions Architect, Technical Alliances’ at Cloudian, concludes: “The ‘EU AI Act’ is leading companies to think more carefully about where their data is stored, who can access it and how it is used – and that’s a good thing!”

He advises: “If storage managers want to curb ‘data sprawl’ and regain control over their data, they need modern data and storage platforms.”

In conclusion, Uhl points out: “However, these should not be set up under time pressure or only once AI projects are already underway. When it comes to developing and deploying their own AI systems, those responsible must address the issue of data infrastructure as a matter of priority.”

Key findings from the DS editorial team

  • As long as the extension of the deadline in the context of the EU’s ‘Digital Omnibus’ is not official, those responsible must take the existing ambitious deadlines into account.
  • In particular, the ‘EU AI Act’ now requires a methodical approach to tackling any potential ‘data proliferation’.
  • There are many good reasons for repatriating data back to one’s own data centre – alongside regulatory compliance, for example, there is also data sovereignty.
  • From ‘Obligation’ to ‘Choice’: A data inventory – i.e. the collection of all operational data and its classification by type, quantity, quality, and storage location, among other criteria – is a prerequisite for robust data security strategies.
  • AI systems should be understood and used as useful virtual tools – their quality depends on effective training data.

Further information

DATENSICHERHEIT.DE, 08|02|2026
Entwicklung zur verlässlichen Geschäftstechnologie: KI-Kennzeichnung gemäß EU AI Act erst der Anfang

DATENSICHERHEIT.DE, 08|02|2026
AI Act: Ab 2. August 2026 weitere Regeln in Kraft – indes noch viele offene Fragen

DATENSICHERHEIT.DE, 07|22|2026
KI-Dilemma: EU AI Act – Bremsklotz oder Erfolgsbooster

Weitere Beiträge