We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The EU AI Act is the spine. Around it sit data protection, cybersecurity, operational resilience, product safety, and a widening set of foreign regimes, each written separately, for a different purpose. We map at the level of the obligation, not the framework, so one body of evidence holds across all of them.
A single high-risk decision in a bank meets the AI Act as a high-risk system, the GDPR as automated processing of personal data, NIS2 and DORA as resilience matters, and the Product Liability Directive as a potential defect. One incident can trigger reporting duties under three of them, on different clocks.
The hard part isn't the number of rules. It's that they were written by different bodies for different purposes, so satisfying one does not satisfy the others, and occasionally they pull against each other. A checklist that maps a control to a named act cannot reconcile purposes it does not understand. Reconciliation needs a map at the level of the obligation.
Hard law, regulator guidance, standards, and soft law across AI, data, cyber, financial, and product-safety regimes. Hover or tap a region in the table to light it on the map.
| Theme | EU | UK | US | Intl / std | APAC | MEA / Gulf | Africa | LatAm | Total |
|---|---|---|---|---|---|---|---|---|---|
| AI-specific | 22 | 12 | 72 | 81 | 44 | 14 | 8 | 9 | 304 |
| Data protection | 7 | 10 | 12 | 2 | 26 | 16 | 7 | 6 | 109 |
| Cybersecurity | 16 | 5 | 12 | 6 | 24 | 4 | 10 | 5 | 101 |
| Identity, rights & governance | 57 | 17 | 6 | 4 | 6 | · | · | · | 94 |
| Financial resilience | 13 | 2 | 1 | 1 | · | 1 | · | 1 | 19 |
| Product safety & liability | 6 | 5 | 1 | 4 | · | · | · | · | 17 |
| All themes | 121 | 51 | 104 | 98 | 100 | 35 | 25 | 21 | 644 |
Source: SI obligation corpus 2026-07-18 · region groupings approximate the freeform jurisdiction field · totals span all 18 regions including Canada and instruments not shown by column
Each has its own page: what it governs, who owes what, the timeline, the penalties, and where it meets the AI Act.
The horizontal spine. Risk-tiered obligations for providers and deployers, phasing in to December 2027.
Read the guide →Data protection. Lawful basis, DPIAs, and the rights that attach whenever AI touches personal data.
Read the guide →Cyber resilience for essential and important entities. Duties land personally on the management body.
Read the guide →Operational resilience of the financial system. ICT risk, third-party oversight, resilience testing.
Read the guide →Patient safety and clinical performance. AI medical devices run one conformity assessment across two regimes.
Read the guide →The biggest sector-specific regimes: model risk in finance, hiring and platform-work rules, and clinical AI.
Read the guide →From 9 December 2026, software, AI included, is a product under EU liability law. Liability turns strict and no-fault, defect is presumed where a system breaches its safety rules or the AI Act, and the technical documentation you keep for the regulator becomes the evidence you must disclose in court. The governance file stops being only a compliance artefact and becomes your legal defence, or, if it has a gap, the presumption against you.
Read the full guide →