A. General Baseline Regulatory Layer
| Instrument | Applicability Logic | What It Regulates | AI Relevance | Priority |
|---|---|---|---|---|
| GDPR | Mandatory if personal data is processed. | Lawfulness, data minimisation, purpose limitation, privacy by design, profiling, automated decision-making, DPIA. | Especially important when AI is trained on personal data, infers characteristics about individuals, or has significant impact on a person. | Very high |
| NIS2 | Mandatory only for entities falling within national scope. | Management body accountability, risk management measures, incident handling, supply chain security, training. | Indirectly very important because AI systems must be included in the organisation's overall cybersecurity governance system. | High |
| Commission Implementing Regulation (EU) 2024/2690 | Mandatory only for in-scope entities and listed categories. | Technical and methodological NIS2 requirements for DNS, cloud services, data centres, MSP/MSSP and related environments. | Important when AI services operate in cloud, data centre, or managed-service environments. | High |
| Cyber Resilience Act (CRA) | Mandatory if the organisation places products with digital elements on the EU market. | Security requirements for products with digital elements, vulnerability management, updates, secure development. | Very important for AI software or products containing AI that are placed on the EU market. | High |
| Cybersecurity Act / EUCC | Usually voluntary unless required by procurement, contracts, or sectoral expectations. | EU cybersecurity certification framework and certification schemes. | Useful as evidence of trustworthiness, architecture quality, and procurement assurance. | Medium |
B. AI-Specific Regulatory Layer
| Instrument | Status | What It Regulates | AI Significance | Importance |
|---|---|---|---|---|
| AI Act | Main EU AI regulation. | Risk-based model covering prohibited practices, transparency requirements, GPAI, high-risk AI, governance, and enforcement. | Direct and primary AI regulation. | Critical |
| AI literacy (AI Act Article 4) | Horizontal obligation. | Competence and understanding of AI risks among staff, operators, and users. | Directly shapes the training programme and CAISO mandate. | Very high |
| AI Act transparency obligations | Applies to certain AI use cases. | User information, transparency for generated content, emotion recognition, deepfakes, and comparable cases. | Important for generative AI, chatbots, and media-processing scenarios. | High |
| GPAI obligations / guidance | Direct or transitional compliance support, depending on context. | Model documentation, information for downstream users, and—where relevant—management of systemic risks. | Especially important when the organisation develops, fine-tunes, or provides GPAI models or services. | High |
C. Sectoral / Conditional Note
DORA should be treated as a sector-specific requirement. It is mandatory for the financial sector and related critical ICT providers. If the organisation is outside that scope, DORA is not a baseline mandatory AI security document, but its provisions can still be used as good practice for third-party risk, operational resilience, and incident management.
Key Regulatory Conclusion
The AI Act is not the only source of AI security requirements. In practice, AI systems must be managed as part of the organisation's broader cybersecurity, data protection, and risk management system.
As a result, AI governance should rely on at least three layers:
- legal instruments,
- management system standards,
- technical controls and auditable evidence.