← Global AI Policy Radar · Methodology
Jurisdiction Baseline · AI × Policy

AI Regulation in the European Union.

At a glance
AI-Specific Law
AI Act applies, with obligations phased through 2028
Data Protection
GDPR governs personal data used by AI
Platform Rules
DSA regulates AI features on online services
Cybersecurity Duties
NIS2 adds security duties for covered entities

The EU has an AI-specific law, the AI Act, which is directly binding but takes effect in stages: bans on certain AI practices and AI-literacy duties started on February 2, 2025, general-purpose AI duties on August 2, 2025, and most transparency rules on August 2, 2026. The 2026 Digital Omnibus delayed most high-risk AI requirements to December 2, 2027 for Annex III systems and August 2, 2028 for AI built into regulated products, while the GDPR, Digital Services Act, consumer-protection laws, and NIS2 cybersecurity rules continue to apply.

In force today5 instruments
Artificial Intelligence Act partially in forceAI-specific
The AI Act regulates providers, deployers, importers, and distributors according to the AI system's risk category. Prohibitions, AI-literacy duties, general-purpose AI obligations, governance, penalties, and most transparency rules apply now, while the 2026 Digital Omnibus delayed most high-risk obligations to December 2, 2027 or August 2, 2028.
AI / automated decisionsDisclosureSafety & security
General Data Protection Regulation in force
GDPR applies whenever an AI system processes personal data, including for training, profiling, personalization, monitoring, or automated decision-making. Companies must establish a lawful basis, meet transparency and data-governance duties, respect data-subject rights, conduct impact assessments where required, and manage processors and international transfers.
Data processingDisclosureMinors
Unlock the full baseline

Get the remaining 3 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.

Already subscribed? Unlock →

Digital Services Act in force
The DSA applies to online intermediaries, platforms, marketplaces, and search services offered in the EU, including where AI powers ranking, recommendation, advertising, moderation, or synthetic-content features. It imposes notice-and-action, explanation, transparency, risk-management, advertising, researcher-access, and protections for minors, with enhanced duties for very large platforms and search engines.
Content moderationDisclosureMinors
Unfair Commercial Practices Directive in force
The directive applies when AI is used to market, sell, recommend, personalize, or influence consumer decisions. Misleading claims, hidden commercial intent, deceptive personalization, fake reviews, and materially distorting consumer behavior can trigger enforcement even where the AI Act does not apply.
Consumer protectionDisclosure
NIS2 Directive in force
NIS2 binds covered essential and important entities, including many organizations in digital infrastructure, health, energy, transport, finance, manufacturing, and public administration. Where an AI system supports a covered service, companies may need risk-management controls, incident reporting, supply-chain security, business continuity, and management accountability.
Safety & security
Also worth noting
  • AI Act high-risk rules now apply from December 2, 2027 for Annex III systems and August 2, 2028 for AI embedded in regulated products under Regulation (EU) 2026/1744.
  • The Product Liability Directive, Directive (EU) 2024/2853, is adopted and expected to apply from December 9, 2026, expanding exposure for defective AI-enabled products and software.
  • Track national AI market-surveillance authorities, European AI Office guidance, Article 50 transparency guidance, and GPAI enforcement practice.
Pending and recent legislation8 measures
EU Ares(2026)6387101 AI Strategy for Cultural and Creative Sectors
Introduced · 2026-07-27
The European Commission has opened a call for evidence to inform a strategy on the use of artificial intelligence in Europe’s cultural and creative sectors. The strategy is intended to support innovation, cultural sovereignty, and the broader European cultural sector.
EU Regulation (EU) 2026/1744 Regulation (EU) 2026/1744, Digital Omnibus on AI
Passed · 2026-07-08
This adopted EU regulation amends the AI Act and related sectoral regulations to simplify the implementation of harmonised artificial-intelligence rules. It concerns the practical application of the EU's overarching AI regulatory framework.
EU COM(2026) 577 COM(2026) 577, Action Plan on Cybersecurity and Artificial Intelligence
Introduced · 2026-07-07
The European Commission’s action plan sets out policy and supporting measures to strengthen the cybersecurity of artificial intelligence systems and to use AI to improve cybersecurity capabilities. It serves as a roadmap for future EU initiatives and coordination in these areas.
EU COM(2026) 502 COM(2026) 502, Cloud and AI Development Act
Advancing · 2026-07-03
The European Commission proposes an act to expand Europe’s cloud and AI infrastructure capacity by supporting research and innovation, greening compute infrastructure and data centers, facilitating private investment, and tripling EU data-processing capacity within five to seven
EU Ares(2025)10848343 Rating Scheme for Data Centres in Europe
Introduced · 2026-06-30
This draft delegated regulation would establish a common European Union scheme for rating the sustainability and energy efficiency of data centres under the Energy Efficiency Directive. It would also simplify data-centre reporting requirements introduced by Delegated Regulation (
EU COM(2026) 501 COM(2026) 501, Roadmap for Artificial Intelligence and Digitalisation for Energy (RAID-E)
Introduced · 2026-06-03
This European Commission roadmap sets out how artificial intelligence and other digital technologies can be used to support the energy sector. It outlines policy and implementation priorities for digitalising energy systems.
EU COM(2026) 234 COM(2026) 234, Report on the Need to Review the Lists of Prohibited AI Practices and High-Risk AI Systems
Advancing · 2026-05-20
The European Commission reports to the European Parliament and the Council, pursuant to Article 112(1) of the EU AI Act, on whether the lists of prohibited AI practices and high-risk AI systems in Annex III should be reviewed. The report does not itself amend those lists.
EU Decision (EU) 2026/1080 Council Decision (EU) 2026/1080 on the EU’s Conclusion of the Council of Europe Framework Convention on Artificial Intelligence and Human Ri
Passed · 2026-04-21
The decision approves the conclusion, on behalf of the European Union, of the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. The convention establishes international principles and obligations for ensuring that A

Live from the Global AI Policy Radar.

Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?

Yes. The EU AI Act is directly binding and is being phased in, with prohibitions, AI-literacy duties, and general-purpose AI obligations already applying, while other requirements take effect later.

Who are the key regulators for AI?

Enforcement is led by national authorities, the European AI Office, data-protection regulators, and sector regulators. Their roles depend on the AI system, the organization using it, and the regulated sector involved.

Which rules apply to AI systems today?

The AI Act applies according to the system's risk category, with prohibitions, AI-literacy duties, general-purpose AI obligations, governance, penalties, and most transparency rules applying on the stated timetable. GDPR applies when AI processes personal data, the Digital Services Act applies to covered online services, consumer-protection rules apply to AI-enabled marketing and influence, and NIS2 applies to covered entities and services.

What is coming next, and when?

Most transparency rules apply from August 2, 2026. The 2026 Digital Omnibus delayed most high-risk AI obligations to December 2, 2027 for Annex III systems and August 2, 2028 for AI embedded in regulated products.

What are the enforcement and penalty risks?

Companies may face enforcement from national authorities, the European AI Office, data-protection regulators, and sector regulators. Risk areas include AI Act penalties, GDPR requirements and enforcement, DSA duties, consumer-protection violations such as misleading claims or fake reviews, and NIS2 obligations including incident reporting and management accountability.

Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.

Need a company-specific assessment? Explore Nomos →