All regulations that affect AI in companies
Not only the AI Act: data protection, cybersecurity, product liability, employment, consumer and copyright rules also decide how you may use AI. Filter by EU or Slovenia, topic and status.
26 regulations
The world’s first comprehensive AI law. It sorts AI systems by risk: some practices are banned, high-risk systems must meet strict requirements, some systems must be transparent, and most everyday uses have no new duties.
Details, examples and sources →An amending regulation that simplified the AI Act and postponed the high-risk rules. In force since 27 July 2026.
Details, examples and sources →A proposal for special civil liability rules for damage caused by AI. The Commission withdrew it in 2025.
Details, examples and sources →The EU’s data protection law. It applies whenever AI processes personal data — in prompts, uploaded documents, training data or outputs.
Details, examples and sources →The data part of the Digital Omnibus would amend GDPR (e.g. a clearer legitimate interest for AI training, a narrower definition of personal data), move cookie rules into GDPR and simplify the Data Act. It is still a proposal.
Details, examples and sources →Gives users of connected products (machines, vehicles, smart devices) access to the data they generate, limits unfair data terms between companies and makes it easier to switch cloud providers.
Details, examples and sources →Gives patients digital access to their health data across the EU and creates rules for reusing health data for research, innovation and AI development.
Details, examples and sources →Requires companies in 18 sectors (energy, transport, health, digital infrastructure, manufacturing, food, waste, postal and more) to manage cyber risks and report incidents. In Slovenia implemented by ZInfV-1.
Details, examples and sources →Cybersecurity requirements for hardware and software products sold in the EU — from smart devices to apps — for their whole life cycle.
Details, examples and sources →ICT risk management, incident reporting, resilience testing and oversight of ICT providers for banks, insurers, investment firms, payment institutions and their critical ICT suppliers.
Details, examples and sources →Strict (no-fault) liability for damage caused by defective products now explicitly covers software and AI systems, including updates and the lack of security updates.
Details, examples and sources →Safety rules for consumer products not covered by specific laws — including connected products and online marketplaces.
Details, examples and sources →Replaces the Machinery Directive. Safety components with fully or partially self-evolving behaviour using machine learning require third-party conformity assessment.
Details, examples and sources →Improves working conditions in digital labour platforms (delivery, ride-hailing, micro-tasks) and sets the first EU rules on algorithmic management: automated monitoring and decisions about work.
Details, examples and sources →Rules for online intermediaries and platforms: notice and action on illegal content, transparency of recommender systems and ads, protection of minors, and extra duties for very large platforms.
Details, examples and sources →Political ads must be labelled with a transparency notice (sponsor, cost, election). Targeting with personal data is heavily restricted.
Details, examples and sources →Online shops, banking, e-books, transport ticketing and electronic communications must be accessible to people with disabilities.
Details, examples and sources →A planned consumer law on dark patterns, addictive design, influencer marketing and unfair personalisation. The Commission plans the proposal for the fourth quarter of 2026.
Details, examples and sources →AI training on copyrighted works is allowed as text and data mining unless the rightholder has reserved the right in a machine-readable way (opt-out). Research organisations have a wider exception.
Details, examples and sources →The Slovenian law that makes the AI Act enforceable: it names the supervisory authorities, the single point of contact, procedures, offences and fines.
Details, examples and sources →Media content created fully or partly with generative AI must be clearly recognisable, separated from other content and labelled at its beginning and end. Publishers must explain how they use AI.
Details, examples and sources →Supplements GDPR in Slovenia — with special rules on video surveillance, biometrics, monitoring at work and processing in the public sector.
Details, examples and sources →Transposes NIS2 into Slovenian law. Essential and important entities must register, manage cyber risks and report incidents.
Details, examples and sources →Slovenian employment law protects workers’ personal data and dignity and gives workers’ representatives a say when new technologies are introduced.
Details, examples and sources →Protects consumers against misleading and aggressive practices, unfair terms and gives rights in distance selling.
Details, examples and sources →Slovenia’s AI strategy prepared by the Ministry of Digital Transformation: AI should serve people and the public interest; focus on sovereign infrastructure, a national AI platform, Slovenian language models and adoption in companies.
Details, examples and sources →General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.