Key EU Rules for Software and AI Development

Last reviewed: 30 September 2026.

EU rules for software and artificial intelligence (AI) do not form a single checklist. Which obligations apply depends on the product or service, the data it processes, the organisation’s role, its users and sector, and the relevant application dates. This overview highlights seven EU frameworks that may be relevant; it is not legal advice.

1. General Data Protection Regulation (GDPR)

The GDPR governs the processing of personal data. It applies to organisations established in the EU or European Economic Area (EEA) when they process personal data, and can also apply to organisations outside the EEA that offer goods or services to, or monitor the behaviour of, people in the EEA. Processing needs an appropriate legal basis: consent is one possibility, not a universal requirement. Organisations must also consider transparency, security, and applicable rights such as access, rectification, and erasure. See the European Data Protection Board’s GDPR guide and the European Commission’s guide to legal grounds for processing.

2. AI Act

The AI Act sets risk-based rules for AI systems and general-purpose AI models; obligations vary by use case and by whether an organisation provides or deploys them. It entered into force on 1 August 2024, but its provisions apply in stages. Certain prohibitions and AI-literacy obligations started on 2 February 2025; obligations for general-purpose AI models started on 2 August 2025; and most other provisions became applicable on 2 August 2026. Under the current timetable, rules for high-risk use cases in Annex III apply from 2 December 2027, while those for AI embedded in regulated products under Annex I apply from 2 August 2028. See the European Commission’s AI Act overview and timeline.

3. Digital Services Act (DSA)

The DSA addresses providers of online intermediary services, including hosting services, online marketplaces, and social platforms; it is not a general rule for every software product. Its general application date was 17 February 2024. Obligations vary with the type and scale of service, with additional duties for designated very large online platforms and search engines. The rules cover issues such as handling illegal content, user redress, and transparency. See the European Commission’s DSA questions and answers and application timeline.

4. Cybersecurity Act

The Cybersecurity Act established an EU-wide framework for cybersecurity certification of information and communications technology products, services, and processes. It does not require every software provider to obtain a certificate. The first EU scheme, the European Common Criteria-based Cybersecurity Certification scheme (EUCC), has applied on a voluntary basis since 27 February 2025. Other laws may impose separate security obligations on particular products or organisations. See the European Commission’s certification framework overview.

5. Cyber Resilience Act (CRA)

The CRA addresses hardware and software products with digital elements made available on the EU market, subject to its scope and exclusions. It sets cybersecurity requirements for product design and vulnerability handling, primarily for manufacturers. Its reporting obligations for actively exploited vulnerabilities and severe security incidents began on 11 September 2026; the main product requirements apply from 11 December 2027. See the European Commission’s CRA summary and implementation timeline.

6. NIS2 Directive

NIS2 requires EU Member States to set cybersecurity risk-management and significant-incident reporting rules for covered entities. As a rule, it concerns medium-sized and large organisations in specified sectors, including health, energy, transport, finance, and digital infrastructure; some exceptions and national details matter. It is an entity- and sector-based framework, not a blanket requirement for every software product. See the European Commission’s NIS2 overview and the applicable national implementing law.

7. Data Governance Act (DGA)

The DGA has applied since 24 September 2023. It sets conditions for reusing certain protected data held by public bodies, regulates data-intermediation services, and supports voluntary data altruism. It does not require every software company to share data or make protected public data openly available. Where personal data is involved, the GDPR still applies. See the European Commission’s DGA explanation and application announcement.

Conclusion

Before treating any of these frameworks as a compliance requirement, identify the organisation’s role, the product or service, the data involved, the relevant sector, and the applicable dates. Then check the current legal text and, for directives such as NIS2, national implementing law. This overview is a starting point, not a determination that any particular product is compliant.