GovernanceCore

AI Regulation in the European Union

10 policies tracked , of which 9 carry binding duties and 1 are voluntary or emerging. Every entry links to its primary source.

8 Regulations1 Framework1 Guideline
Must ComplyGuidelineEUUnacceptable risk

EU Prohibited Practices Guidelines

Commission Guidelines on Prohibited AI Practices

The Commission's official reading of the AI Act's Article 5 bans: manipulative techniques, social scoring, emotion recognition at work and untargeted facial scraping. The reference point for scoping prohibited-use reviews.

European Commission & national market-surveillance authoritiesFeb 2, 2025
Must ComplyRegulationEU

EU DSA

Digital Services Act

Governs recommender systems and algorithmic amplification with transparency, risk-assessment and audit duties for large platforms. It is a core rulebook for AI-driven content ranking and moderation.

European Commission & national Digital Services CoordinatorsFeb 17, 2024
Must ComplyRegulationEU

EU Data Act

Governs access to and sharing of data generated by connected products, and mandates cloud-switching rights. Sets the terms on which AI developers can lawfully obtain industrial and IoT training data.

National competent authorities & the European Data Innovation BoardSep 12, 2025
Must ComplyRegulationEU

EU Data Governance Act

Creates trusted routes for reusing protected public-sector data and for data intermediation and altruism. Relevant wherever AI training data is sourced from public bodies or shared data spaces.

National competent authorities & the European Data Innovation BoardSep 24, 2023
Must ComplyRegulationEU

EU DMA

EU Digital Markets Act

Imposes ex-ante conduct rules on designated gatekeeper platforms, including fairness and transparency duties over ranking and self-preferencing. These constraints bite directly on AI-driven recommendation.

European Commission (DG COMP & DG CNECT)Mar 7, 2024
Must ComplyRegulationEUHigh risk

EU GDPR (Art. 22)

General Data Protection Regulation (automated decision-making)

Article 22 gives individuals the right not to be subject to solely automated decisions producing legal or similarly significant effects, plus rights to information, human review and to contest. It is a key constraint on AI-driven decisioning.

European Data Protection Board & national data protection authoritiesMay 25, 2018
Must ComplyRegulationEUHigh risk

EU AI Act

EU Artificial Intelligence Act

The world's first comprehensive, risk-based AI law. Classifies AI by risk tier (prohibited, high-risk, limited, minimal) and imposes graduated obligations, with most high-risk rules and enforcement starting 2 August 2026.

European AI Office & national market-surveillance authoritiesAug 2, 2026
Must Comply from Jan 20, 2027RegulationEUHigh risk

EU Machinery Regulation

Sets safety requirements for machinery placed on the EU market, treating AI-based safety functions as high-risk components. Machinery in scope also triggers high-risk duties under the AI Act.

National market-surveillance authoritiesJan 20, 2027
Must Comply from Dec 9, 2026RegulationEU

EU Product Liability Directive

EU Revised Product Liability Directive

Extends EU strict product liability expressly to software and AI systems, and eases the burden of proof for claimants in technically complex cases. The main civil-liability exposure sitting alongside the AI Act.

National courts of EU member statesDec 9, 2026
VoluntaryFrameworkEU

EU GPAI Code of Practice

General-Purpose AI Code of Practice

The Commission-facilitated code that GPAI model providers can sign to demonstrate compliance with the AI Act's transparency, copyright and systemic-risk duties. Voluntary in form, near-default in practice.

European AI OfficeAug 2, 2025

Other jurisdictions

Search and filter all policies →