Next Article in Journal
A Systematic Review on Hybrid AI Models Integrating Machine Learning and Federated Learning
Previous Article in Journal
Denial-of-Service Attacks on Permissioned Blockchains: A Practical Study
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

A Framework for Compliance with Regulation (EU) 2024/1689 for Small and Medium-Sized Enterprises

by
Sotirios Stampernas
and
Costas Lambrinoudakis
*
Department of Digital Systems, University of Piraeus, 18532 Piraeus, Greece
*
Author to whom correspondence should be addressed.
J. Cybersecur. Priv. 2025, 5(3), 40; https://doi.org/10.3390/jcp5030040
Submission received: 13 May 2025 / Revised: 22 June 2025 / Accepted: 25 June 2025 / Published: 1 July 2025

Abstract

The European Union’s Artificial Intelligence Act (EU AI Act) is expected to be a major legal breakthrough in an attempt to tame AI’s negative aspects by setting common rules and obligations for companies active in the EU Single Market. Globally, there is a surge in investments to encourage research, development and innovation in AI that originates both from governments and private firms. The EU recognizes that the new Regulation (EU) 2024/1689 is difficult for start-ups and SMEs to cope with and it announced the release of tools, in the near future, to ease that difficulty. To facilitate the active participation of SMEs in the AI arena, we propose a framework that could assist them to better comply with the challenging EU AI Act during the development life cycle of an AI system. We use the spiral SDLC model and we map its phases and development tasks to the legal provisions of Regulation (EU) 2024/1689. Furthermore, the framework can be used to promote innovation, improve their personnel’s expertise, reduce costs and help the companies avoid the proposed substantial fines described in the Act.
Keywords: EU AI Act; Regulation 2024/1689; compliance; SMEs; risk assessment; framework EU AI Act; Regulation 2024/1689; compliance; SMEs; risk assessment; framework

Share and Cite

MDPI and ACS Style

Stampernas, S.; Lambrinoudakis, C. A Framework for Compliance with Regulation (EU) 2024/1689 for Small and Medium-Sized Enterprises. J. Cybersecur. Priv. 2025, 5, 40. https://doi.org/10.3390/jcp5030040

AMA Style

Stampernas S, Lambrinoudakis C. A Framework for Compliance with Regulation (EU) 2024/1689 for Small and Medium-Sized Enterprises. Journal of Cybersecurity and Privacy. 2025; 5(3):40. https://doi.org/10.3390/jcp5030040

Chicago/Turabian Style

Stampernas, Sotirios, and Costas Lambrinoudakis. 2025. "A Framework for Compliance with Regulation (EU) 2024/1689 for Small and Medium-Sized Enterprises" Journal of Cybersecurity and Privacy 5, no. 3: 40. https://doi.org/10.3390/jcp5030040

APA Style

Stampernas, S., & Lambrinoudakis, C. (2025). A Framework for Compliance with Regulation (EU) 2024/1689 for Small and Medium-Sized Enterprises. Journal of Cybersecurity and Privacy, 5(3), 40. https://doi.org/10.3390/jcp5030040

Article Metrics

Back to TopTop