A curated, plain-language index of the laws, treaties and frameworks shaping artificial intelligence across the EU, Ireland, the United States, Nigeria and the United Kingdom. Each entry links to the official full text — the authoritative, current version — so you are never reading a stale copy.
The 12 provisions that determine whether your AI deployment is compliant. Plain-English summaries with key obligations. Full official text on EUR-Lex ↗
Summaries are practitioner-focused and not legal advice. Always verify against the official text. Amended by the Digital Omnibus (formally adopted by the EU Council 29 June 2026; OJ publication pending).
The cornerstone regime. A risk-based framework banning certain AI practices, imposing strict obligations on "high-risk" systems, and setting transparency rules for general-purpose AI. In force since 1 Aug 2024; prohibitions applied Feb 2025; GPAI obligations Aug 2025. The Digital Omnibus amendment was formally adopted by the EU Council on 29 June 2026 (Official Journal publication pending); it postpones Annex III high-risk obligations from Aug 2026 to Dec 2027, Annex I (product-regulated) to Aug 2028, and adds a new prohibition on AI-generated non-consensual intimate imagery and CSAM (effective Dec 2026).
The voluntary framework operationalising the AI Act's Article 50 transparency duties — machine-readable marking and detection of synthetic audio, image, video and text (Art. 50(2)), and labelling of deepfakes and AI-generated public-interest text (Art. 50(4)/(5)). The Commission and the AI Board have confirmed it as an adequate tool to demonstrate compliance: signing carries a presumption of conformity that shifts the evidentiary burden onto market-surveillance authorities. To appear on the initial-signatories list published before the 2 August 2026 start date, signature forms must be submitted by 22 July 2026, 18:00 CEST. A standardised EU icon set accompanies the code.
The data-protection backbone underpinning AI compliance in Europe — lawful basis, automated decision-making (Art. 22), DPIAs and data-subject rights all bear directly on how AI systems process personal data.
Ireland's national law giving effect to the GDPR and establishing the Data Protection Commission — the lead supervisory authority for many of the world's largest technology platforms headquartered in Dublin.
Ireland's national strategy for trustworthy, ethical AI adoption across the economy and public service, now aligned to EU AI Act implementation and the designation of national competent authorities.
Ireland's domestic AI law, formally published 17 June 2026. Establishes Oifig IS na hÉireann (AI Office of Ireland) as an independent statutory market-surveillance authority, the national competent authority for the EU AI Act, and a single point of contact for AI governance in Ireland — all operational by 1 August 2026. Provides enforcement powers and penalties aligned to Regulation (EU) 2024/1689.
The Commission's proposed directive adapting civil liability rules for AI-caused harm was formally withdrawn in February 2025 after EU institutions failed to reach agreement. Civil AI liability in the EU is now governed by the revised Product Liability Directive (EU) 2024/2853 (in force 9 December 2024; transpose by 9 December 2026), which explicitly classifies software and AI systems as "products" subject to strict no-fault liability. The specific fault-based rebuttable-presumption mechanism the AI Liability Directive would have created no longer exists.
Replaces NIS1 — expands cybersecurity obligations to a far wider range of sectors (energy, transport, health, digital infrastructure, managed services, public administration). Directly relevant to AI system operators: AI pipelines, training infrastructure and automated decision systems are in scope where they underpin essential or important services. Incident notification within 24 hours.
Governs who can access and use data generated by connected devices and related services — creating data-sharing obligations, limiting vendor lock-in, and setting rules for public-sector access to private-sector data in emergencies. For AI practitioners: directly affects access to training data, data portability between AI vendors, and the legality of data-sharing arrangements between AI systems.
Imposes due-diligence obligations on online platforms — including algorithmic transparency, risk assessments for systemic risks, and audit obligations for very large platforms and search engines (100M+ EU users). Where AI-driven recommender systems or content-moderation systems are deployed on large-scale platforms, the DSA is a parallel compliance layer running alongside the AI Act.
Directs federal agencies to pursue a deregulatory, pro-innovation policy and to challenge state AI laws seen as inconsistent with it — establishing an AI Litigation Task Force and a review of "burdensome" state measures.
The first US state comprehensive AI law, substantially revised and re-enacted by SB 26-189, signed by the Governor on 14 May 2026. The revised law shifts scope from "high-risk AI systems" to "automated decision-making technology" (ADMT) used for consequential decisions (employment, credit, housing, healthcare, education). Obligations move to consumer disclosures, post-adverse-outcome explanations, correction rights, and human review; enforcement by the Colorado Attorney General only. Takes effect 1 January 2027.
The de-facto US standard for operationalising trustworthy AI — Govern, Map, Measure, Manage. Voluntary, but widely referenced in contracts, procurement and as evidence of reasonable care.
Nigeria's blueprint for AI: national AI principles, a proposed AI governance/regulatory body, responsible-development guidelines, and a risk-management framework — building on the August 2024 draft.
Nigeria's principal data-protection statute and the legal foundation for AI accountability — establishing the NDPC, data-subject rights, and obligations on data controllers and processors that AI deployments must satisfy.
Several bills are advancing — efforts to merge the National AI & Robotic Sciences Bill (HB 601) and the Control of Usage of AI Technology Bill (HB 942) into a comprehensive National AI Act, alongside a bill to establish a National AI Commission able to license high-risk systems and run a national AI registry.
Anticipated technical specifications for conformity assessment and bias auditing — the practical compliance layer beneath the national strategy and any forthcoming AI Act.
The UK's foundational approach: five cross-sector principles applied by existing regulators (ICO, Ofcom, CMA, FCA) rather than a dedicated AI law — supplemented by the 2025 AI Opportunities Action Plan.
A bill that would create a central "AI Authority" and statutory principles — a marker for the comprehensive UK AI Bill anticipated in 2026.
The first legally binding international treaty on AI — aligning the AI lifecycle with human rights, democracy and the rule of law. Opened for signature 5 Sep 2024; entered into force 1 Nov 2025 after crossing the ratification threshold. The EU ratified on 15 May 2026. Parties include the EU, UK, US, Canada, Norway, France and others.
The most widely adopted soft-law principles for trustworthy AI (OECD), and the first certifiable AI management-system standard (ISO/IEC 42001) — increasingly the practical yardstick for AI governance programmes.
It can. Article 2(1)(c) extends the Act to providers and deployers outside the EU whose AI system's output is used within the Union. We advise both Nigerian companies entering EU markets and European companies using Nigerian AI/data vendors on where the obligation attaches — see the Nigeria–EU corridor page.
Under the provisional Digital Omnibus package (not yet law), Annex III high-risk is deferred to 2 December 2027 and Annex I high-risk to 2 August 2028. Neither is in force until Official Journal publication.
Not yet as of this page's last review. The final act was signed 8 July 2026; Official Journal publication and entry into force are expected to follow shortly. Provisions marked "Omnibus" here are provisional until then.
From EU AI Act readiness to a cross-border governance programme, Adesanya AI Advisory helps you move from text to compliance.
Begin in writing →