Multi-regulation EU compliance for AI products
50+ EU Laws Can Reach Your AI Product. Most Founders Know One.
The EU AI Act gets the headlines. The other 57 regulations are already in force, already reaching non-EU companies, and nobody is mapping them against the product you are actually shipping.
We do.
Non-EU providers · European lawyer · Fixed-price engagements

58+ EU laws. Most founders know just one of them.
If your AI system reaches EU users — through direct access, API, enterprise contracts, or a reseller — EU regulation reaches you. And not just the EU AI Act but also:
- The regulation that governs your product’s security.
- The one that governs your liability for its outputs.
- The one that governs the data it generates.
- The one that determines whether you need a named lawyer inside the EU before your first European customer.
Most commercial AI products are subject to between three and eight simultaneously without their builders knowing it.
We work with founders and product teams from the European Union, as well as US, UK, Canada, Switzerland, India, Ukraine, and Israel who are building AI products for the European market. We tell them which laws apply to their specific product, what those laws require, and in what order to act.
Not a checklist. Not AI-generated PDF. A lawyer who has read every one of these regulations at drafting level and can map them against what you are actually shipping.
50+ EU frameworks. Each one applied at product level.
The EU AI Act gets the attention. The Cyber Resilience Act, DORA, the revised Product Liability Directive, the Data Act, the Digital Services Act, and 57* more frameworks can reach the same product simultaneously — and most AI companies have mapped none of them.
EU AI Act
The primary AI-specific regulation — risk classification, prohibited practices, technical documentation, conformity assessment, and the Authorised Representative requirement for non-EU providers. High-risk obligations apply from August 2026. Article 5 prohibited practices are already in force.
→ EU AI Act compliance
Revised Product Liability Directive
Strict liability for defective AI outputs causing damage — extended to software for the first time. No fault required. The liability exposure for AI products making consequential decisions is potentially larger than the regulatory fine exposure. In force.
→ Product Liability compliance
Cyber Resilience Act
Security-by-design obligations for every AI product delivered as software connecting to a network or device. Applies from September 2026. Most AI software products are in scope. CE marking required. Most teams have not started.
→ CRA compliance
Data Act
Data sharing obligations, switching rights, and IoT data access rules for AI products generating or processing machine data. Obligations applying from September 2025. Most companies have not determined whether they are a data holder, recipient, or third party.
→ Data Act compliance
* Not counting regional regulations, such as Swiss nFADP or UK GDPR.
Digital Operational Resilience Act
ICT risk management, incident reporting, and third-party oversight obligations for financial sector AI — and for the AI companies that supply financial entities. In force since January 2025.
→ DORA compliance
Digital Services Act
Algorithmic transparency, risk assessment, and content moderation obligations for AI-powered platforms and recommendation systems. Very Large Online Platform designation triggers the most demanding requirements.
→ DSA compliance
How We Work
A scoping call. A fixed-price engagement. A documented position you own. No open-ended retainers or hourly billing.
Step 1 — Scoping call (free, 15 minutes)
We confirm which frameworks reach your product, whether you need an EU Authorised Representative, and which engagement makes sense. If nothing applies, we tell you clearly.
Step 2 — Assessment
A lawyer-built assessment of your product against every applicable framework — risk classification, obligation mapping, role determination, gap analysis, and a prioritised remediation roadmap. Delivered as a written record you can put in front of a regulator, investor, or acquirer.
Step 3 — Documentation
Template pack or full documentation support — technical file, risk register, FRIA, data governance checklist, conformity assessment records — structured the way a notified body or market surveillance authority expects to see them.

Find out which EU laws apply to your AI product
A free 15-minute scoping call confirms which frameworks reach your product, whether you need an EU Authorised Representative, and which engagement makes sense — before any commitment.
No obligation · Responds within 2 business days · Fixed-price engagements only
Frequently Asked Questions
We have compiled a list of frequently asked questions to help you find instant answers to your queries
Does EU regulation apply to my company if we are based outside the EU?
Yes, if your AI product reaches EU users. The EU AI Act, Cyber Resilience Act, DORA, the revised Product Liability Directive, the Data Act, and the Digital Services Act all apply based on where your product is used or where its output reaches — not where your company is incorporated. The same extraterritorial logic that made GDPR reach US companies reaches your AI product today under multiple frameworks simultaneously.
Which EU laws apply to my AI product?
It depends on what your product does, how it connects, who uses it, and in what context. The EU AI Act applies based on risk classification. The CRA applies if your software connects to a network or device. DORA applies if your product is used by or supplied to EU financial entities. The revised PLD applies where your AI output causes damage. The Data Act applies where your product generates or processes machine data.
Most AI products are subject to at least three of these simultaneously. The scoping call establishes which ones reach yours.
How many EU regulations do you cover?
EU AI Liability Directive (AILD), General Data Protection Regulation (GDPR), ePrivacy Directive, Data Governance Act (DGA), EU-US Data Privacy Framework, NIS2 Directive, Resilience Directive (CER), Digital Markets Act (DMA), nFADP, Platform-to-Business Regulation (P2B), General Product Safety Regulation (GPSR), CE Marking framework, MiFID II, AMLD6, PSD2 / PSD3, AMLAR — Anti-Money Laundering Authority Regulation, Insurance Distribution Directive (IDD), Solvency II, EBA/ESMA/EIOPA, Medical Device Regulation (MDR), In Vitro Diagnostic Regulation (IVDR), European Health Data Space (EHDS), Clinical Trials Regulation, Machinery Regulation, Radio Equipment Directive (RED), Low Voltage Directive, Electromagnetic Compatibility Directive, Construction Products Regulation (CPR), Ecodesign for Sustainable Products Regulation (ESPR), Platform Work Directive, EU Charter of Fundamental Rights, Whistleblower Protection Directive, Artificial Intelligence and Fundamental Rights Impact Assessment framework (FRIA), Copyright in the Digital Single Market Directive (DSM), Database Directive, Trade Secrets Directive, European Accessibility Act (EAA), Cloud and AI Development Act (CADA), EU Chips Act, European Electronic Communications Code (EECC), ISO/IEC 42001:2023, ISO/IEC 27001, ISO/IEC 23894, ETSI EN 303 645, CEN/CENELEC harmonised standards under AI Act, Corporate Sustainability Reporting Directive (CSRD), and more.
The honest check: 57+ binding instruments applicable to digital and AI products, depending on what the product does, who it serves, and what sector it operates in. Good news: no single AI product is subject to all of them.
What is the difference between the EU AI Act and the Cyber Resilience Act?
The EU AI Act governs the AI system itself — its risk classification, prohibited practices, technical documentation, and human oversight requirements. The CRA governs the security of the product — security by design, vulnerability handling, and incident reporting obligations for software products connecting to networks or devices.
Most AI software products are subject to both simultaneously. They overlap in technical robustness and post-market monitoring but impose distinct and non-overlapping obligations in other areas.
Do I need an EU Authorised Representative?
If you are a non-EU provider of a high-risk AI system or GPAI model placing it on the EU market, yes — under Article 22 of the EU AI Act, before your first EU customer. If your product also falls under MDR, the Machinery Regulation, or other EU product regulations, separate AR appointments may be required under those regimes. The scoping call confirms whether and which AR obligations apply to your product.
What is a fixed-price engagement and what does it include?
Every engagement has a defined scope and a fixed price agreed before any work begins. No hourly billing, no open-ended retainers, no surprise invoices. The scope covers exactly what is described on each product page. Work outside that scope — additional systems, additional frameworks, legal representation in proceedings — is a separate engagement quoted and agreed separately before we proceed.
How long does an assessment take?
The EU AI Act single-system assessment delivers within five working days of completed intake. The cross-framework assessment delivers within ten working days. Timelines start from receipt of a completed intake checklist, not from payment. A short scoping call precedes every engagement to confirm scope and timeline before work begins.
What do I receive at the end of an assessment?
A written assessment memo, a risk classification report, an obligation map covering every applicable Article or provision across every framework in scope, a role determination, a gap analysis ranked by enforcement risk, a prioritised remediation roadmap, and an audit-ready compliance data room setup. A deliverable you own, not a summary that lives in someone else’s system.
Can one Authorised Representative cover all 27 EU Member States?
Yes. A single Authorised Representative established in any EU Member State can act on behalf of a non-EU provider across all 27 Member States. The AR’s mandate is recognised throughout the Union, and the representative serves as the single point of contact for any Member State market surveillance authority. Multilingual capability is operationally important, because authorities are entitled to correspond in the official language of their Member State. Providers do not need to appoint a separate AR per country.
