EU AI Act Whistleblowing: What Changed on August 2, 2026

Legal & Compliance

Alaa El-Shaarawi - FaceUp Copywriter and Content Manager

Alaa El-Shaarawi

Copywriter and Content Manager

Published

2026-09-24

Reading time

9 min

Table of contents

    Subscribe to our newsletter

    EU AI Act Whistleblowing: What Changed on August 2, 2026

    Your employees have opinions about the AI tools you've rolled out. Until recently, a lot of them had nowhere to take those opinions except a review site.

    Mentions of AI in Glassdoor reviews jumped 240% between May 2025 and May 2026, and the tone has shifted. In 2019, 81% of those mentions were positive. In 2026, that's down to 43%, and 53% of reviews mention AI only as a downside. About one in ten of the critical comments is about how the company uses AI internally, including monitoring and surveillance.

    It isn't only an American concern. A 2024 Eurobarometer survey of 26,415 people found that 62% of Europeans view AI at work positively, while 63% take a negative view of it being used to monitor them. Only 18% say their employer has explained the technology in any detail, including its drawbacks and their rights. People generally like the tools, as long as they know how their employer is using them.

    Since August 2, 2026, there's a protected route for those concerns. Reports about EU AI Act  breaches are protected under the EU Whistleblowing Directive, and the European Commission runs its own channel to receive them.

    Let's look at what actually changed, who it applies to, and what it means for your reporting channel.

    EU AU Act Stats.png

    The Whistleblowing Directive hasn't been rewritten

    You'll see this change described as an update to the EU Whistleblowing Directive. It isn't one. The annex of Directive (EU) 2019/1937 has grown as new areas of Union law were added, but its protection provisions read today exactly as they did in 2019.

    What happened is that the AI Act brought itself into the Directive's scope. Article 87 of Regulation (EU) 2024/1689 is a single sentence: the Whistleblowing Directive applies to reports about AI Act breaches and to the people who make them.

    So from August 2, 2026, an employee reporting a suspected AI Act breach has the same protection as one reporting money laundering. There's no new process to set up and no new channel to build. It's one more type of report arriving through the channel you already have.

    Do you need to wait for a national law?

    No, and this is where the detail matters.

    The Whistleblowing Directive is a directive, which is why it reached you through your own country's transposition law, on your country's timetable. The AI Act is a regulation, like GDPR. Regulations apply directly in all 27 member states with no transposition step.

    That means the protection took effect across the EU on the same day, whether or not your national parliament has done anything about it. Protection is still enforced through your national whistleblowing law, and some national laws may need updating to name the AI Act, but there's no implementation window to plan for.

    One question we're asked a lot: didn't the AI Act get delayed? Partly. The digital omnibus (Regulation (EU) 2026/1744), in force since July 27, 2026, moved the high-risk deadlines back to December 2027 and August 2028. It didn't change Article 87.

    Who does this apply to?

    The channel obligation applies to every organization already covered by the Whistleblowing Directive. In practice, that means 50 or more workers, public-sector entities, and the sectors covered regardless of headcount. Protection for the people who report doesn't depend on employer size. 

    It's worth remembering how wide the protected group is, because it goes well beyond your payroll. It includes contractors and suppliers, the self-employed, job applicants and former staff, trainees and volunteers, shareholders and board members. It also covers people who help someone report, and their colleagues and relatives.

    Protection applies as long as the person had reasonable grounds to believe the report was true. If you investigate and find nothing, they're still protected.

    Does this mean you have to accept anonymous reports?

    You may see it written that anonymous reporting of AI Act breaches is now protected. That's worth double-checking against your own national law.

    Article 87 applies the Directive as it stands, and the Directive leaves anonymous reporting up to each member state. Most allow anonymous reports without requiring you to accept them, a few make acceptance mandatory, and a few restrict or exclude them. Your national transposition still decides, and this change didn't touch it.

    It's worth checking the practical side as well as the legal one. Some countries permit anonymous reports while their standard reporting forms still ask for a name.

    What widened here is the subject matter, not the rules about the reporter's identity. If you already offer anonymous reporting, nothing changes for you.

    The EU now has its own reporting channel

    This is the part most coverage has skipped, and it went live eight months before the legal change.

    The European AI Office has run an encrypted whistleblower tool since November 24, 2025. It's designed for insiders: current and former employees, contractors, shareholders and board members connected to providers of general-purpose AI models and certain AI systems. Access inside the Commission is restricted, reports are accepted in any official EU language, and receipt is confirmed within seven working days. Reporters can follow their case and answer follow-up questions without revealing who they are.

    That's a well-built channel, and it's worth knowing what your people are comparing yours to.

    Under the Directive, reporters have never been required to come to you first. They can report internally, externally, or both. For most types of wrongdoing, the external option is a national authority that most employees would have to search for. For AI, it's now a channel the Commission actively publicizes.

    What happens if you find out late

    The AI Act doesn't fine you for having a weak reporting channel. It fines you for the underlying breach, and the amounts are significant: up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for most other obligations. The penalty provisions have applied since August 2025, and fines on GPAI model providers since August 2026.

    The risk tied directly to whistleblowing is a separate one. If someone reports an AI concern and is then dismissed, demoted or sidelined because of it, that's retaliation, and it's penalized under your national law. Article 21(5) of the Directive also reverses the burden of proof in every member state, so it falls to you to show the treatment had nothing to do with the report.

    Then there's timing, which is really what an internal channel gives you. A prohibited use raised internally in week one is something you can still fix. The same issue reaching a market surveillance authority first often means it's been running for months, and the record of it was written by somebody else.

    What an AI Act report looks like

    These reports don't arrive labeled "AI Act, Article 50". They arrive as someone uncomfortable with a tool the company rolled out last quarter. For example:

    • A team uses an AI system in a way the Act prohibits, such as emotion inference on staff at work.
    • Customers interact with an AI system without being told they're talking to one.
    • An AI tool is used in hiring or performance reviews without the governance the Act will require from December 2027.
    • Someone raises a concern about a model's training data and is told to drop it.

    Compare that list with the Glassdoor findings: monitoring, surveillance, tools nobody asked for. These conversations are already happening. The question is whether they reach you.

    How to prepare your reporting channel

    You'll see plenty of advice this autumn saying AI Act compliance means building an AI governance program with training modules and a policy library. That may be worth doing for other reasons, but it isn't what Article 87 asked of you. Article 87 asked your existing channel to handle one more type of report.

    Here's what that involves.

    1. Start with your report form. Read it the way an employee would. If none of the categories fit "I'm worried about how we're using this AI tool", some people will give up there. Whether AI gets its own category or sits inside an existing one matters less than whether the wording makes it clear they're in the right place.

    2. Decide who receives these reports. They often need someone who understands both the Act and the system involved. If you have an AI governance owner, they probably belong in the routing, and you should be able to bring them in without exposing the reporter.

    3. Brief the people who handle reports. The four examples above make a good briefing. Handlers need to recognize that a complaint about a new tool can be a protected report, and to treat it as one straight away.

    4. Keep your existing deadlines. Acknowledgment within seven days, feedback within three months, and confidentiality throughout. AI reports follow the same rules as everything else.

    5. Tell people you want to hear about it. A single line in your speak-up communications or your whistleblowing policy naming AI as something you want raised internally costs nothing, and it's often what decides whether the first report comes to you.

    How FaceUp helps

    FaceUp is an ethics and compliance platform used by organizations in more than 70 countries. If you already run a channel with us, none of this is an implementation project. It's configuration, and most of it you can do yourself.

    • You can change categories and forms yourself. Forms, workflows, categories and languages can all be updated without opening a ticket with us. Adding an AI category, or rewording one so employees recognize it, takes minutes.

    • Reports reach the right people. You choose who can see each one, so an AI case can go to whoever owns AI governance while everyone else stays out of it. Sensitive categories can route to a board committee or an external party if that suits your governance.

    • Reporters choose whether to give their name. Someone can file a report without identifying themselves and keep talking to the case handler through a secure thread. That's what makes anonymity workable in practice: investigators can ask follow-up questions and get answers.

    • Everything is documented. Every report becomes a case with an owner, a status and a full history. If an authority asks how you handled an internal report, that record is your answer.

    • People can report without a laptop. Reports come in through the web, a mobile app or a QR code, in the languages your workforce speaks. Hotline services are available as add-ons if you want a voice option.

    If you're already a customer, your customer success manager can walk through how AI-related reports are categorized today and who they reach in your organization.

    Where this leaves you

    A single sentence of regulation widened what counts as a protected report, and your legal obligations barely moved. What changed is that employees who are uneasy about their employer's AI now have protection for raising AI Act breaches, and, for breaches within the AI Office's remit, a well-publicized EU channel that will take the report anonymously.

    Whether the next one reaches your case management system or a regulator comes down to your report form, your routing, and whether anyone has told your people you want to hear about it.

    Book a demo and we'll walk you through anonymous intake, how a case moves from report to resolution, and what it takes to route AI reports to the right person.

    Blog Footer 1 (v3) - Book a Demo.png

    FAQ