ADESANYA AI ADVISORY
Resource Library

AI Legislation & Regulation Library

A curated, plain-language index of the laws, treaties and frameworks shaping artificial intelligence across the EU, Ireland, the United States, Nigeria and the United Kingdom. Each entry links to the official full text — the authoritative, current version — so you are never reading a stale copy.

Regulation (EU) 2024/1689 — as amended by the Digital Omnibus (May 2026)

EU AI Act — key articles, readable here.

The 12 provisions that determine whether your AI deployment is compliant. Plain-English summaries with key obligations. Full official text on EUR-Lex ↗

Summaries are practitioner-focused and not legal advice. Always verify against the official text. Amended by the Digital Omnibus (formally adopted by the EU Council 29 June 2026; OJ publication pending).

🇪🇺 European Union & Ireland

The EU AI Act is the world's first comprehensive, horizontal AI law — and the benchmark most other jurisdictions are measured against.
Phasing in 2025–2028

EU Artificial Intelligence Act

Regulation (EU) 2024/1689 · as amended by the Digital Omnibus (formally adopted 29 June 2026)

The cornerstone regime. A risk-based framework banning certain AI practices, imposing strict obligations on "high-risk" systems, and setting transparency rules for general-purpose AI. In force since 1 Aug 2024; prohibitions applied Feb 2025; GPAI obligations Aug 2025. The Digital Omnibus amendment was formally adopted by the EU Council on 29 June 2026 (Official Journal publication pending); it postpones Annex III high-risk obligations from Aug 2026 to Dec 2027, Annex I (product-regulated) to Aug 2028, and adds a new prohibition on AI-generated non-consensual intimate imagery and CSAM (effective Dec 2026).

Voluntary code · signatory window

Code of Practice on Transparency of AI-Generated Content

European Commission / AI Office · final text published 10 June 2026

The voluntary framework operationalising the AI Act's Article 50 transparency duties — machine-readable marking and detection of synthetic audio, image, video and text (Art. 50(2)), and labelling of deepfakes and AI-generated public-interest text (Art. 50(4)/(5)). The Commission and the AI Board have confirmed it as an adequate tool to demonstrate compliance: signing carries a presumption of conformity that shifts the evidentiary burden onto market-surveillance authorities. To appear on the initial-signatories list published before the 2 August 2026 start date, signature forms must be submitted by 22 July 2026, 18:00 CEST. A standardised EU icon set accompanies the code.

In force

General Data Protection Regulation

Regulation (EU) 2016/679 (GDPR)

The data-protection backbone underpinning AI compliance in Europe — lawful basis, automated decision-making (Art. 22), DPIAs and data-subject rights all bear directly on how AI systems process personal data.

In force

Data Protection Act 2018 (Ireland)

Number 7 of 2018

Ireland's national law giving effect to the GDPR and establishing the Data Protection Commission — the lead supervisory authority for many of the world's largest technology platforms headquartered in Dublin.

National strategy

AI — Here for Good (Irish National AI Strategy)

Government of Ireland · refreshed 2024

Ireland's national strategy for trustworthy, ethical AI adoption across the economy and public service, now aligned to EU AI Act implementation and the designation of national competent authorities.

Before Oireachtas · June 2026

Regulation of Artificial Intelligence Bill 2026 (Ireland)

Government of Ireland · published 17 June 2026

Ireland's domestic AI law, formally published 17 June 2026. Establishes Oifig IS na hÉireann (AI Office of Ireland) as an independent statutory market-surveillance authority, the national competent authority for the EU AI Act, and a single point of contact for AI governance in Ireland — all operational by 1 August 2026. Provides enforcement powers and penalties aligned to Regulation (EU) 2024/1689.

Withdrawn · 2025

AI Liability Directive

COM(2022) 496 · withdrawn by the Commission, February 2025

The Commission's proposed directive adapting civil liability rules for AI-caused harm was formally withdrawn in February 2025 after EU institutions failed to reach agreement. Civil AI liability in the EU is now governed by the revised Product Liability Directive (EU) 2024/2853 (in force 9 December 2024; transpose by 9 December 2026), which explicitly classifies software and AI systems as "products" subject to strict no-fault liability. The specific fault-based rebuttable-presumption mechanism the AI Liability Directive would have created no longer exists.

In force · transposed Oct 2024

NIS2 Directive

Directive (EU) 2022/2555 · Ireland: SI 322 of 2024

Replaces NIS1 — expands cybersecurity obligations to a far wider range of sectors (energy, transport, health, digital infrastructure, managed services, public administration). Directly relevant to AI system operators: AI pipelines, training infrastructure and automated decision systems are in scope where they underpin essential or important services. Incident notification within 24 hours.

Applies Sep 2025

EU Data Act 2023

Regulation (EU) 2023/2854 · applies from 12 Sep 2025

Governs who can access and use data generated by connected devices and related services — creating data-sharing obligations, limiting vendor lock-in, and setting rules for public-sector access to private-sector data in emergencies. For AI practitioners: directly affects access to training data, data portability between AI vendors, and the legality of data-sharing arrangements between AI systems.

In force · applies 2023–2024

Digital Services Act

Regulation (EU) 2022/2065 · VLOPs/VLOSEs from Feb 2023; all others Feb 2024

Imposes due-diligence obligations on online platforms — including algorithmic transparency, risk assessments for systemic risks, and audit obligations for very large platforms and search engines (100M+ EU users). Where AI-driven recommender systems or content-moderation systems are deployed on large-scale platforms, the DSA is a parallel compliance layer running alongside the AI Act.

🇺🇸 United States

No single federal AI statute. Governance is a shifting mix of executive action, sector regulators, voluntary frameworks and fast-moving state laws — with active federal/state tension in 2026.
Executive action

EO: National Policy Framework for AI

Executive Order · 11 Dec 2025

Directs federal agencies to pursue a deregulatory, pro-innovation policy and to challenge state AI laws seen as inconsistent with it — establishing an AI Litigation Task Force and a review of "burdensome" state measures.

Enacted · effective 1 Jan 2027

Colorado Artificial Intelligence Act

SB 24-205, as revised and replaced by SB 26-189 (signed 14 May 2026)

The first US state comprehensive AI law, substantially revised and re-enacted by SB 26-189, signed by the Governor on 14 May 2026. The revised law shifts scope from "high-risk AI systems" to "automated decision-making technology" (ADMT) used for consequential decisions (employment, credit, housing, healthcare, education). Obligations move to consumer disclosures, post-adverse-outcome explanations, correction rights, and human review; enforcement by the Colorado Attorney General only. Takes effect 1 January 2027.

Voluntary framework

NIST AI Risk Management Framework

NIST AI RMF 1.0 (2023)

The de-facto US standard for operationalising trustworthy AI — Govern, Map, Measure, Manage. Voluntary, but widely referenced in contracts, procurement and as evidence of reasonable care.

🇳🇬 Nigeria

Nigeria is moving from strategy to statute — a national AI strategy is in place, data-protection law is in force, and several AI bills are progressing through the National Assembly.
National strategy

National Artificial Intelligence Strategy

NCAIR / NITDA · updated 19 Sep 2025

Nigeria's blueprint for AI: national AI principles, a proposed AI governance/regulatory body, responsible-development guidelines, and a risk-management framework — building on the August 2024 draft.

In force

Nigeria Data Protection Act 2023

NDPA 2023 · Nigeria Data Protection Commission

Nigeria's principal data-protection statute and the legal foundation for AI accountability — establishing the NDPC, data-subject rights, and obligations on data controllers and processors that AI deployments must satisfy.

Proposed / before Assembly

National AI Commission & related AI Bills

HB 601 · HB 942 · NAIC (Establishment) Bill

Several bills are advancing — efforts to merge the National AI & Robotic Sciences Bill (HB 601) and the Control of Usage of AI Technology Bill (HB 942) into a comprehensive National AI Act, alongside a bill to establish a National AI Commission able to license high-risk systems and run a national AI registry.

Forthcoming

NITDA Code of Practice for AI

NITDA · expected 2025–2026

Anticipated technical specifications for conformity assessment and bias auditing — the practical compliance layer beneath the national strategy and any forthcoming AI Act.

🇬🇧 United Kingdom & International

The UK favours a principles-based, regulator-led approach over a single statute — while binding and soft-law international instruments increasingly set the global baseline.
Policy framework

A Pro-Innovation Approach to AI Regulation

UK Government White Paper (2023)

The UK's foundational approach: five cross-sector principles applied by existing regulators (ICO, Ofcom, CMA, FCA) rather than a dedicated AI law — supplemented by the 2025 AI Opportunities Action Plan.

Before Parliament

Artificial Intelligence (Regulation) Bill [HL]

UK Private Member's Bill · re-introduced 2025

A bill that would create a central "AI Authority" and statutory principles — a marker for the comprehensive UK AI Bill anticipated in 2026.

In force · 1 Nov 2025

Council of Europe Framework Convention on AI

CETS No. 225 · in force 1 Nov 2025

The first legally binding international treaty on AI — aligning the AI lifecycle with human rights, democracy and the rule of law. Opened for signature 5 Sep 2024; entered into force 1 Nov 2025 after crossing the ratification threshold. The EU ratified on 15 May 2026. Parties include the EU, UK, US, Canada, Norway, France and others.

Standard / principles

OECD AI Principles & ISO/IEC 42001

OECD (2019, rev. 2024) · ISO/IEC 42001:2023

The most widely adopted soft-law principles for trustworthy AI (OECD), and the first certifiable AI management-system standard (ISO/IEC 42001) — increasingly the practical yardstick for AI governance programmes.

How to use this library. Entries link to the official source so you always read the current, authoritative text. This page is reviewed periodically (last reviewed: 15 July 2026) and is provided for general information only — it is not legal advice and does not create a lawyer–client relationship. AI law is moving quickly; verify the current status of any instrument before relying on it, and seek qualified advice for your specific circumstances.

Frequently asked

Does the EU AI Act apply to a Nigerian company selling AI or data services into Europe?

It can. Article 2(1)(c) extends the Act to providers and deployers outside the EU whose AI system's output is used within the Union. We advise both Nigerian companies entering EU markets and European companies using Nigerian AI/data vendors on where the obligation attaches — see the Nigeria–EU corridor page.

What's the difference between the Annex I and Annex III high-risk deadlines?

Under the provisional Digital Omnibus package (not yet law), Annex III high-risk is deferred to 2 December 2027 and Annex I high-risk to 2 August 2028. Neither is in force until Official Journal publication.

Is the Digital Omnibus already law?

Not yet as of this page's last review. The final act was signed 8 July 2026; Official Journal publication and entry into force are expected to follow shortly. Provisions marked "Omnibus" here are provisional until then.

Need to turn one of these into an action plan?

From EU AI Act readiness to a cross-border governance programme, Adesanya AI Advisory helps you move from text to compliance.

Begin in writing →