A. General Baseline Regulatory Layer

Instrument Applicability Logic What It Regulates AI Relevance Priority
GDPR Mandatory if personal data is processed. Lawfulness, data minimisation, purpose limitation, privacy by design, profiling, automated decision-making, DPIA. Especially important when AI is trained on personal data, infers characteristics about individuals, or has significant impact on a person. Very high
NIS2 Mandatory only for entities falling within national scope. Management body accountability, risk management measures, incident handling, supply chain security, training. Indirectly very important because AI systems must be included in the organisation's overall cybersecurity governance system. High
Commission Implementing Regulation (EU) 2024/2690 Mandatory only for in-scope entities and listed categories. Technical and methodological NIS2 requirements for DNS, cloud services, data centres, MSP/MSSP and related environments. Important when AI services operate in cloud, data centre, or managed-service environments. High
Cyber Resilience Act (CRA) Mandatory if the organisation places products with digital elements on the EU market. Security requirements for products with digital elements, vulnerability management, updates, secure development. Very important for AI software or products containing AI that are placed on the EU market. High
Cybersecurity Act / EUCC Usually voluntary unless required by procurement, contracts, or sectoral expectations. EU cybersecurity certification framework and certification schemes. Useful as evidence of trustworthiness, architecture quality, and procurement assurance. Medium

B. AI-Specific Regulatory Layer

Instrument Status What It Regulates AI Significance Importance
AI Act Main EU AI regulation. Risk-based model covering prohibited practices, transparency requirements, GPAI, high-risk AI, governance, and enforcement. Direct and primary AI regulation. Critical
AI literacy (AI Act Article 4) Horizontal obligation. Competence and understanding of AI risks among staff, operators, and users. Directly shapes the training programme and CAISO mandate. Very high
AI Act transparency obligations Applies to certain AI use cases. User information, transparency for generated content, emotion recognition, deepfakes, and comparable cases. Important for generative AI, chatbots, and media-processing scenarios. High
GPAI obligations / guidance Direct or transitional compliance support, depending on context. Model documentation, information for downstream users, and—where relevant—management of systemic risks. Especially important when the organisation develops, fine-tunes, or provides GPAI models or services. High

C. Sectoral / Conditional Note

DORA should be treated as a sector-specific requirement. It is mandatory for the financial sector and related critical ICT providers. If the organisation is outside that scope, DORA is not a baseline mandatory AI security document, but its provisions can still be used as good practice for third-party risk, operational resilience, and incident management.

Key Regulatory Conclusion

The AI Act is not the only source of AI security requirements. In practice, AI systems must be managed as part of the organisation's broader cybersecurity, data protection, and risk management system.

As a result, AI governance should rely on at least three layers:

  1. legal instruments,
  2. management system standards,
  3. technical controls and auditable evidence.