← Back to Playbooks

Part 2 — Other EU Rules SMBs Using AI Should Know

The regulations that arrive alongside the AI Act — and the ones you can ignore

The AI Act rarely arrives alone. Most SMBs using AI already sit inside one or two of the EU’s other digital rules, and they usually meet them in the same week — in a single vendor contract, not in five separate projects. This is orientation, not a compliance program: enough to know which apply, and which you can safely ignore.

Regulation Who it hits What it asks for Relevant if you…
GDPR Any org processing EU residents’ personal data Records of processing, impact assessments for high-risk processing, data processing agreements with vendors, 72-hour breach reporting Use AI on customer data, profiling, or automated decisions — i.e. almost every SMB using AI
NIS2 Around 160,000 entities across 18 sectors — energy, healthcare, finance, digital infrastructure, and their supply chains A risk-management program across 10+ security domains, supply-chain security assessments, 24-hour incident early warning Are in a covered sector, or supply into one — an AI vendor to a hospital or utility, for instance
Cyber Resilience Act Manufacturers and distributors of “products with digital elements,” phasing in through 2027 Vulnerability handling, a software bill of materials, documented incident response Build or sell software or connected products — including a SaaS or AI tool you ship to customers
Data Act Businesses generating data from connected products, or acting as cloud or data-processing providers Rights for users to access and port data from connected products; easier cloud switching Sell or use connected/IoT products, or offer cloud or data services
DORA Financial entities and their ICT suppliers specifically An ICT risk framework, contractual audit rights with vendors Sell AI or ICT services into financial institutions, or are one

The overlap is the real story

A single AI vendor relationship can trigger a GDPR data processing agreement, a NIS2 supplier assessment if you’re in a covered sector, and AI Act due diligence — all from one contract. The practical fix isn’t three separate compliance projects. It’s one vendor-onboarding checklist, which is what Playbook 2 (Vendor & Procurement) already does. One line worth adding there: the vendor questionnaire should ask about GDPR, and about NIS2 or the CRA where your sector or the vendor’s position makes either relevant.

What not to worry about

If you’re a typical SMB, DORA is someone else’s problem — unless you sell AI or ICT services into financial institutions, or are one. Most of NIS2 won’t apply either, unless you sit in one of its eighteen sectors or supply into one. Their appearance in enterprise-oriented “EU compliance stack” articles doesn’t mean every SMB needs a DORA program. Most don’t.

Sources: analyses of the 2026 EU compliance stack covering GDPR, DORA, NIS2 and the AI Act; EU tech regulation compliance deadline trackers.