AI Regulation · Enforced Now
EU AI Act 2024
Mandatory AI disclosure before interaction, prohibited practices banned since Feb 2025, high-risk system classification, conformity assessment, CE marking. Full enforcement August 2026.
EU AI Act Art. 5, 6, 13, 50 • Annex III • Recital 58
Data Protection · Enforced
GDPR Art. 22 + Art. 5
Automated decision-making rights, human review obligation, right to explanation and contest. Applies to any AI influencing decisions about individuals. Penalties up to €20M or 4% global turnover.
GDPR Art. 5, 13, 22, 25, 35 • Recital 71 • ICO/CNIL guidance
Electronic Communications · Enforced
ePrivacy Directive 2002/58/EC
Explicit informed consent before recording. Strict opt-in for automated marketing calls. Separate consent for voice biometric processing. Recording without active consent is illegal in most EU member states.
ePrivacy Dir. Art. 5(1), 13 • GDPR Art. 9 • Member state implementations
AI Management System · International
ISO/IEC 42001:2023
First certifiable AI management system standard. Primary conformity mechanism referenced by EU AI Act notified bodies. EU enterprise procurement increasingly requires ISO 42001 certification or documented equivalence.
ISO/IEC 42001 §4.2 §5.2 §6.1.2 §8.2 §8.4 §9.1 §10.2
AI Risk Management · International
NIST AI RMF 2.0 (Mar 2025)
March 2025 update added model provenance, third-party AI supply chain risk, and deployer responsibility. Deploying organisations bear full liability for third-party AI components regardless of vendor contracts.
NIST AI 100-1 • AI RMF 2.0 Mar 2025 • GOVERN 1.5 • MEASURE 2.2
Network Security · Enforced
NIS2 Directive 2022/2555
AI-related incident reporting for essential and important entities. 24-hour notification to national CSIRT. Covers energy, transport, banking, health, digital infrastructure. Board-level accountability required.
NIS2 Art. 20, 21, 23 • ENISA guidance • National transpositions Oct 2024
Sector-Specific Regulators Also Covered
EU AI Act Annex III High-Risk
GDPR Art. 35 DPIA
EBA AI Guidelines
EIOPA AI Principles
ESMA AI Use Policy
ISO/IEC 42001:2023
ISO/IEC 27001:2022
EU Data Act 2023