AI and its legal maze: a guide to navigating the new wave of regulations

The EU AI Act now coexists with the GDPR, Data Act, DSA, DMA and NIS2 Directive. We explain how each rule fits, which obligations apply to companies, professionals and public bodies using AI, and the practical steps you can take to comply without freezing innovation.

The new regulatory ecosystem for AI

Artificial intelligence is not governed by a single rule. The EU Regulation 2024/1689 (AI Act) is the centrepiece, but coexists with a growing stack of overlapping rules: GDPR, Data Act, Data Governance Act, Digital Services Act (DSA), Digital Markets Act (DMA), NIS2 Directive, Cyber Resilience Act, and the upcoming AI Liability Directive.

For companies, professionals and public bodies using AI, the challenge is not to comply with one rule, but to orchestrate compliance across several regulatory layers at once.

> Practical note: if your organisation develops, integrates or uses AI systems, you need an integrated compliance map, not a stand-alone reading of the AI Act.

The AI Act: four risk levels

The Regulation classifies systems into four tiers:

  1. Unacceptable risk (banned): social scoring, subliminal manipulation, mass biometric identification in public spaces save for narrow exceptions.
  2. High risk: AI in critical infrastructure, education, employment, essential services, justice, borders, biometrics. Requires conformity assessment, EU database registration, risk management and human oversight.
  3. Limited risk: chatbots, deepfakes, emotion recognition. Transparency obligation (inform the user).
  4. Minimal risk: spam filters, video games. No specific obligations, although self-regulation is encouraged.

How the other rules fit in

GDPR: the foundation on which everything is built

Any AI system processing personal data remains fully subject to the General Data Protection Regulation. The AI Act does not replace the GDPR; it complements it. A Data Protection Impact Assessment (DPIA) is mandatory in most AI deployments.

Data Act and Data Governance Act

Govern access and reuse of data generated by connected devices (IoT) and public-sector data. Essential for model training.