What is covered
Four instruments today, chosen because they share a fact base and land on the same solutions. Three done properly beat ten done thinly, and thin is what a reader notices first.
The instruments #
| Instrument | Reference | Rules | Weakest check |
|---|---|---|---|
| Artificial Intelligence Act | Regulation (EU) 2024/1689 | 21 | corroborated |
| Cyber Resilience Act | Regulation (EU) 2024/2847 | 9 | corroborated |
| General Data Protection Regulation | Regulation (EU) 2016/679 | 11 | corroborated |
| NIS2 Directive A directive: binds through national law |
Directive (EU) 2022/2555 | 5 | corroborated |
| Data Act | Regulation (EU) 2023/2854 | 8 | corroborated |
| Digital Services Act | Regulation (EU) 2022/2065 | 12 | corroborated |
| Digital Operational Resilience Act | Regulation (EU) 2022/2554 | 6 | corroborated |
| European Accessibility Act A directive: binds through national law |
Directive (EU) 2019/882 | 6 | corroborated |
Dates that bind #
Every date this ruleset knows, across all four instruments, in order. Dates moved by an amending instrument are marked.
| Date | What happens | Instrument |
|---|---|---|
| 2018-05-25 | Applies | General Data Protection Regulation |
| 2019-06-07 | Published in the Official Journal | European Accessibility Act |
| 2022-06-28 | Member States were required to transpose it | European Accessibility Act |
| 2022-11-16 | Enters into force | Digital Services Act |
| 2023-01-16 | Enters into force | NIS2 Directive |
| 2023-01-16 | Enters into force | Digital Operational Resilience Act |
| 2023-08-25 | Applies to designated very large platforms and search engines | Digital Services Act |
| 2024-01-11 | Enters into force | Data Act |
| 2024-02-17 | Applies to all intermediary services | Digital Services Act |
| 2024-08-01 | Enters into force | Artificial Intelligence Act |
| 2024-10-17 | Member States were required to transpose it | NIS2 Directive |
| 2024-12-10 | Enters into force | Cyber Resilience Act |
| 2025-01-17 | Applies | Digital Operational Resilience Act |
| 2025-02-02 | Prohibitions and AI literacy apply | Artificial Intelligence Act |
| 2025-06-28 | Obligations apply to products and services placed on the market from this date | European Accessibility Act |
| 2025-08-02 | General-purpose model obligations, governance and penalties apply | Artificial Intelligence Act |
| 2025-09-12 | Applies: data access, switching and interoperability obligations | Data Act |
| 2026-08-02 | Transparency obligations apply and enforcement begins | Artificial Intelligence Act |
| 2026-09-11 | Reporting obligations for actively exploited vulnerabilities apply | Cyber Resilience Act |
| 2026-09-12 | Access by design applies to connected products placed on the market from this date | Data Act |
| 2026-12-02 | Marking applies to systems already on the market; new prohibitions apply This date was moved by an amending instrument. | Artificial Intelligence Act |
| 2027-01-12 | Switching charges prohibited entirely | Data Act |
| 2027-09-12 | Unfair terms provisions reach contracts concluded before 12 September 2025 | Data Act |
| 2027-12-02 | High-risk obligations apply to Annex III systems This date was moved by an amending instrument. | Artificial Intelligence Act |
| 2027-12-11 | The remaining obligations apply | Cyber Resilience Act |
| 2028-08-02 | High-risk obligations apply to Annex I systems This date was moved by an amending instrument. | Artificial Intelligence Act |
| 2030-06-28 | Transitional period ends for services under earlier contracts | European Accessibility Act |
Where instruments meet #
The part rarely written down: obligations from different instruments that must be reconciled rather than run in parallel. Each fires on a combination of facts, never on one instrument alone.
Two conformity assessments under one CE marking
AI Act Articles 43 and 48 · CRA Articles 32 and 30
A product carrying digital elements and an AI safety component must satisfy both regimes and affix a single CE marking. Plan one technical file and one assessment route rather than two projects that meet at the end.
One incident, three reporting duties on different clocks
GDPR Articles 33 and 34 · NIS2 Article 23 · AI Act Article 73
The same event can require an early warning within 24 hours, a personal data notification within 72, and a serious incident report under the AI Act, to different authorities. One runbook, one decision tree, one owner; the Data Omnibus proposes a single entry point but has not been adopted.
A data protection impact assessment and a fundamental rights impact assessment
GDPR Article 35 · AI Act Article 27
Two assessments with overlapping evidence and different questions. The AI Act permits building on an existing data protection assessment rather than repeating it; the fundamental rights questions are additional, not a subset.
Automated decisions meet AI Act transparency
GDPR Article 22 · AI Act Articles 26(11) and 86
A person subject to an automated decision has rights under both: meaningful information about the logic, and an explanation of the role the system played. The two duties are satisfied together or not at all.
Product security requirements and processing security
CRA Annex I · GDPR Article 32
The CRA sets requirements for the product; Article 32 sets them for the processing. Evidence for one is usually evidence for the other, and a single control set mapped to both saves the second audit.
A directive and a regulation in the same programme
NIS2 Article 41
The regulations bind identically across the Union; NIS2 binds as each Member State transposed it. A single compliance programme therefore has one part that travels and one part that does not, and the second must be checked per country.
DORA displaces NIS2 for a financial entity's ICT risk
DORA Article 1(2) · NIS2 Article 4
Where DORA covers the same ground, it applies as the more specific law and NIS2's corresponding duties do not stack on top. That is a reason to map the two rather than run two programmes, and a reason not to assume the NIS2 obligation has simply vanished: the displacement is provision by provision, not wholesale.
Advertising transparency meets lawful processing
DSA Articles 26 and 28 · GDPR Articles 6, 9 and 22
The DSA requires an advertisement to be identifiable and its targeting parameters disclosed; the GDPR governs whether that targeting may happen at all. Special-category profiling is prohibited under both, and disclosing unlawful targeting does not make it lawful.
Data sharing under the Data Act meets data protection
Data Act Articles 4, 5 and 1(5) · GDPR Articles 6 and 20
A user's right to have product data sent to a third party is not itself a lawful basis for processing anyone else's personal data caught up in it. Where the data set mixes personal and non-personal data, both regimes apply to the same transfer.
Cloud switching rights meet financial exit strategies
Data Act Chapter VI · DORA Articles 28 to 30
Both regimes reach the same cloud contract from opposite directions: one gives the customer a right to leave, the other requires the financial customer to have a documented exit strategy and specific contractual terms. One contract review satisfies both if it is scoped that way; two separate ones usually contradict each other.
Accessibility requirements meet AI transparency duties
EAA Annex I · AI Act Article 50(1)
Telling a person they are speaking to an AI system only counts if they can perceive the notice. A disclosure delivered in a way that fails the accessibility requirements satisfies neither instrument.
A consumer platform is covered twice over
DSA Article 14 · EAA Annex I
The DSA requires terms in plain, intelligible language; the Accessibility Act requires the interface delivering them to be perceivable and operable. Plain language in an inaccessible interface fails the second test while passing the first.
An AI system inside a regulated product
AI Act Article 6(1) · CRA Article 12
Being a product with digital elements does not by itself make the AI high-risk, and being high-risk does not by itself trigger the CRA. Check both routes separately; they share a technical file but not a test.
Proposed, not law #
Tracked so that a plan is not built on a proposal. None of the following binds anyone today.
The Data Omnibus would amend the GDPR, ePrivacy, NIS2, DORA and the Data Act
General Data Protection Regulation · proposed 2025-11-19
Still in negotiation as of August 2026 and not law. Reported changes include single-click consent, a moratorium on re-prompting, a longer breach notification window and a single incident reporting point. Plan against the obligations that are in force today.
The Data Omnibus proposes streamlined incident reporting through a single entry point
NIS2 Directive · proposed 2025-11-19
Would let one report satisfy notifications under NIS2, the GDPR and DORA. Not adopted; report separately until it is.
The Digital Omnibus proposes exemptions from the switching regime for custom-made services and a lighter regime for smaller providers
Data Act · proposed 2025-11-19
Reported as covering custom-made services other than infrastructure services for contracts concluded before 12 September 2025. Not adopted; the obligations above apply as they stand.
The Data Omnibus proposes a single entry point for incident reporting across DORA, NIS2 and the GDPR
Digital Operational Resilience Act · proposed 2025-11-19
Still in negotiation. Report separately until it is adopted.
What is not covered #
Eight instruments are encoded. Sectoral regimes that need their own expert, medical devices, machinery and automotive among them, are deliberately out of scope rather than thinly covered, as are the ePrivacy rules, which are mid-reform. The next candidates are the Machinery Regulation for products already caught by the CRA, and the ePrivacy regime once the Data Omnibus settles it.
If an instrument is not listed on this page, this service says nothing about it, and silence here is not a finding that it does not apply to you.