European Union - Market Insights
Law Over Borders Comparative Guide: Artificial Intelligence Law Guide
Artificial Intelligence Law Guide
Navigating the EU’s converging digital rulebook as it revisits rules on AI
The EU’s digital rulebook is converging and doing so against a set of live regulatory deadlines that are already upon organisations. With the AI Act’s high-risk obligations phasing in from August 2026, this chapter maps the interlocking regulatory architecture that boards and legal counsel must now navigate which spans the AI Act, the Digital Omnibus package (including the Digital Omnibus and Digital Omnibus on AI), cybersecurity and consumer protection frameworks, and identifies the integrated governance response those frameworks demand. Across all of these frameworks, a single theme emerges: the era of siloed, instrument-by-instrument compliance is over, and organisations that have not yet built an integrated compliance architecture are already behind.
The EU’s AI architecture
Changing landscape. When the AI Act (www.linklaters.com/insights/blogs/digilinks/2024/may/eu---the-ai-act-reaches-the-finish-line---10-key-points) was first proposed in 2021, the geopolitical landscape looked markedly different: AI was largely a research and development story, regulatory vacuum was the global norm, and the competitive stakes appeared manageable. Today, widespread enterprise adoption of generative AI, the emergence of agentic AI, and intensifying US–China rivalry have shifted the landscape. Concerns over the EU’s overreliance on US tech and cloud providers have come to the forefront in times of increasing geopolitical volatility and active investigations into major US tech companies.
EU’s digital rulebook. “Digital sovereignty”, which is the imperative of retaining control over data, digital infrastructure and technology choices, has become a strategic priority for the EU. Its announced investments into AI infrastructure, its Cybersecurity Strategy and the emerging Data Union Strategy are a direct response and a deliberate effort to ensure that the EU can build, run and protect its digital technologies and data under its own rules, rather than relying on foreign providers.
Against this background, and building on the General Data Protection Regulation (GDPR)’s foundations while also being driven by consumer protection and antitrust concerns about Big Tech dominance, the EU has developed a broad digital rulebook, spanning not only the AI Act but also the Digital Services Act (DSA) (www.linklaters.com/insights/blogs/digilinks/2023/february/the-eu-digital-services-act---a-new-era-for-online-harms-and-intermediary-liability), Digital Markets Act (DMA) (www.techinsights.linklaters.com/post/102inrf/dma-insight-9-the-designated-few-no-surprises-and-a-few-decisions-still-in-th), Data Act (www.linklaters.com/insights/blogs/digilinks/2024/january/eu--the-data-act---new-rules-on-switching-cloud-services-and-iot-data) and Data Governance Act (www.techinsights.linklaters.com/post/102ifni/spain-sets-out-hefty-fines-under-the-eu-data-governance-act-and-amends-its-data-p). These regulations overlap in subject matter and are interconnected. As such, the AI Act does not operate in isolation.
The extent of the framework has led critics to argue that the AI Act’s extensive and layered obligations risk stifling European innovation and deterring investment, precisely when speed and scale matter most.
The Digital Omnibus package: addressing regulatory rigidity. In response to such criticism, the Digital Omnibus’ proposals (www.techinsights.linklaters.com/post/102lwbw/the-eu-digital-omnibuses-ai-and-the-amish) aim to reduce duplication, streamline reporting and align obligations across AI, product liability, digital services, digital markets, cyber resilience and data, thereby addressing concerns that the existing rules are too rigid and supporting the emergence of European digital champions.
With respect to AI, the proposals tie the most onerous high-risk obligations to harmonised standards, common specifications and Commission guidelines as and when they become available, making compliance more workable while keeping core safety and accountability safeguards in place. More broadly, the Digital Omnibuses clarify how the various regimes overlap, interact and apply cumulatively to the same systems, data and governance processes, thus reflecting and reinforcing an integrated and interlocking EU digital rulebook.
At the moment, the Digital Omnibus package remains a legislative proposal: it has not yet been formally adopted, and its provisions remain subject to amendments through the ordinary legislative process. For organisations seeking to plan their compliance programmes against firm AI Act deadlines that are already approaching, this creates a material layer of uncertainty. Such uncertainty demands contingency planning rather than reliance on proposed relief that may not materialise in its current form. This is illustrated, for example, by the AI literacy obligation: where the Digital Omnibus would transform it into an obligation on the Commission and Member States to encourage providers and deployers to take measures to improve AI literacy, the European Parliament has proposed a compromise under which providers and deployers would themselves need to take measures to promote AI literacy, falling short of guaranteeing a specific outcome.
What the AI Act does, and when it bites. Even with the Digital Omnibus on AI’s proposed adjustments, the AI Act remains the EU’s primary and most comprehensive regulatory instrument for artificial intelligence, and its fundamental obligations are not diminished by the recalibration described above. The AI Act establishes a risk-based, “technology-neutral” regime (regulating outcomes and functions, not tools) that classifies AI systems across four tiers (unacceptable, high, limited and minimal risk).
Higher-risk applications face strict requirements on data governance, risk assessments, transparency and human oversight; the most dangerous use cases are prohibited outright.
The AI Act’s reach extends well beyond EU borders: any provider whose system’s output is intended for use in the EU falls within scope of the AI Act, regardless of where it is established, much like the GDPR with respect to data protection.
Pursuant to the first version of the AI Act, obligations for standalone high-risk AI systems would phase in from 2 August 2026, with product-embedded systems following from 2 August 2027. Prohibitions on the most dangerous use cases, AI literacy requirements and General-Purpose AI (GPAI) obligations are already in force. However, as part of the Digital Omnibus deliberations, the European Parliament has voted on delaying such obligations for high-risk AI systems to 2 December 2027 and product-embedded systems to 2 August 2028. It is now up to the Council of the EU to formally vote this extension into existence.
The risk-based framework described above was developed against the backdrop of generative AI. Understanding how it reaches the newer category of agentic AI systems requires examining what distinguishes the two, and why that distinction carries material regulatory consequences.
Agentic AI versus generative AI
How AI develops in practice. Under the AI Act, generative AI is principally regulated through the GPAI model provisions, which impose transparency, documentation and, for models posing systemic risk, additional safety obligations on providers. Unlike generative AI, which produces outputs like text, images and video in response to user prompts, agentic AI operates with a greater degree of autonomy: once a goal is set, it can plan, act, call external tools and application programming interfaces (APIs), and iterate without further human instruction.
According to Deloitte, agentic AI commerce alone could drive up to USD 17.5 trillion in global commerce by 2030 (www.deloitte.wsj.com/cio/how-agentic-ai-is-transforming-commerce-and-payments-4b085cd8).
For legal and compliance functions, these figures are not merely projections: they represent the scale of autonomous commercial activity that will fall within, or press against the boundaries of, existing liability, consumer protection and financial regulation frameworks, many of which were not designed with machine-initiated transactions in mind.
How the AI Act reaches agentic AI. The AI Act does not explicitly mention agentic AI, but the nature of these systems means they would clearly be covered by the AI Act’s broad definition of AI systems.
What obligations apply to AI agents will depend on the sectors in which they are deployed, with healthcare and finance attracting the highest scrutiny. High-risk agentic systems must meet requirements on record keeping, transparency and human oversight, but the reduced human involvement and ability to interact with real-world tools and other systems inherent in AI agents means their risk profile is significantly higher than that of generative AI.
Boards and legal counsel should not assume a regulatory gap exists for agentic systems. Organisations should begin mapping their agentic AI against the AI Act’s risk classification framework now, ensuring governance, oversight and liability arrangements are in place before deployment at scale. Mapping agentic systems against the AI Act’s risk classification framework, stress-testing existing oversight mechanisms against scenarios in which the system acts without real-time human instruction and ensuring that liability and accountability chains are clearly documented before deployment are baseline requirements.
Any mapping exercise should not take place in isolation: AI systems sit at the intersection of the AI Act and a range of adjacent digital frameworks, each of which imposes its own overlapping obligations.
AI and the adjacent digital frameworks
Addressing cyber security concerns. Geopolitical instability and the widespread adoption of generative and agentic AI have altered the threat landscape, expanding the attack surface and introducing novel vectors (including AI-powered attacks and indirect prompt injection) that make data, cyber and AI risk inseparable and demand holistic governance.
Within the EU, the Network and Information Security 2 Directive (NIS 2) (www.linklaters.com/insights/blogs/digilinks/eu-nis2----three-difficult-implementation-issues), the Digital Operational Resilience Act (DORA) (www.linklaters.com/services/financial-regulation-group/operational-resilience), the Cyber Resilience Act (www.techinsights.linklaters.com/post/102mmlo/eu-cyber-resilience-act-commission-issues-first-draft-guidance-10-key-points-y), the GDPR (www.linklaters.com/insights/blogs/digilinks/our-guide-to-the-gdpr---fully-updated) and the AI Act create overlapping, mutually reinforcing obligations spanning incident reporting, supply chain security, ICT resilience, and personal liability for management bodies that demand a single, integrated compliance architecture rather than siloed responses.
NIS 2 establishes the baseline for incident reporting and risk management, with personal liability attaching to management bodies. DORA specialises this for financial sector entities, adding ICT resilience and third-party risk requirements. The Cyber Resilience Act extends security-by-design obligations to manufacturers of AI-enabled products. The GDPR’s breach notification obligations run in parallel wherever a cyber incident involves personal data, while the AI Act adds transparency, human oversight and post-market monitoring requirements to the same systems. The result is a regulatory architecture in which a single incident may trigger concurrent obligations under multiple frameworks, each with its own timelines, reporting channels and supervisory authorities, thereby reinforcing the case for a unified compliance architecture.
Consumer protection and online transparency. Consumer protection concerns have been a primary driver of the EU’s broader digital rulebook. The Omnibus Directive strengthens enforcement of existing consumer rights in digital markets, while the DSA imposes transparency and content-moderation obligations on platforms, with AI-generated content and recommender systems squarely in its sights.
Together with the AI Act’s transparency requirements for consumer-facing AI, these frameworks collectively raise the baseline for how AI-driven products and services must be presented to, and governed in the interests of, end users. The revised Product Liability Directive, in force since December 2024, reinforces this baseline by extending strict liability to AI-enabled products and easing the burden of proof for victims of defective products.
Strategic priorities based on the EU’s AI architecture
The obligations described above are not a future planning exercise: they are being phased in now. Organisations that treat each regulatory instrument in isolation risk duplicating effort, missing interdependencies, and failing to build the integrated governance architecture that regulators and boards will expect. Three strategic themes emerge from the convergence of these frameworks.
First, organisations should map and classify their AI systems (both generative and agentic) against the AI Act’s risk tiers now, building compliance programmes around the statutory deadlines of August 2026 and August 2027. The Digital Omnibus legislative process warrants close monitoring, as proposed amendments (not yet enacted) would extend these deadlines as described above, but organisations should not plan on that basis.
Second, organisations should build integrated governance architectures that span the converging frameworks, being the AI Act, GDPR, NIS 2, DORA, the Cyber Resilience Act, the DSA and the DMA, rather than maintaining siloed, instrument-by-instrument compliance programmes. Boards should also place the competition dimension of AI regulation, including DMA obligations and enforcement against AI-enabled bundling and data exclusivity, on their horizon-scanning agenda.
Third, boards should treat regulatory credibility as a strategic asset and competitive differentiator. In a market where investors, counterparties and regulators assess an organisation’s fitness to deploy AI at scale, demonstrable compliance readiness underpinned by robust governance, transparent documentation and board-level accountability is a source of competitive advantage.
Conclusion
The EU’s digital rulebook is not a collection of discrete instruments: it is an integrated system of obligations, coherent, demanding and increasingly extraterritorial. Organisations that invest now in governance architectures designed for convergence will be best placed to deploy AI at scale, and to turn regulatory readiness into lasting competitive advantage.