HARNESS D1.1 Atlas of AI and Data Regulatory Frameworks - version 1

The governance of artificial intelligence (AI) and data-intensive technologies has emerged as one of the central legal and constitutional challenges of the contemporary digital economy. The European Union has responded with an ambitious and wide-ranging regulatory programme, producing a dense ecosystem of instruments for regulating AI risks, data protection, data governance and data sharing, platform accountability, market regulation, cybersecurity, product safety and related areas. This deliverable, which represents the first output of Work Package 1 of the HARNESS Doctoral Network, presents the first version of an analytical Atlas of this framework. Rather than constituting a descriptive inventory of legislation, the Atlas systematically maps the relationships between the main regulatory instruments, identifying areas of complementarity, overlap, ambiguity, regulatory gaps, and emerging misalignment. It focuses on EU instruments of horizontal application, including the AI Act, the General Data Protection Regulation (GDPR), the Data Governance Act (DGA), the Data Act, the Digital Services Act (DSA), the Digital Markets Act (DMA), the Cyber Resilience Act (CRA), the NIS2 Directive, the Revised Product Liability Directive (rPLD), copyright instruments, and other selected related legislation. Although these instruments pursue legitimate and sometimes complementary objectives, their cumulative interaction creates legal and practical challenges for regulators, enforcement authorities and regulated actors. Understanding these interactions is essential for achieving the EU’s broader objectives of fostering trustworthy AI, promoting innovation, and protecting fundamental rights. However, no widely adopted analytical framework currently exists for systematically analysing how actors, obligations, rights, and deterrence mechanisms are allocated across the EU AI and data regulatory framework as a whole, or the extent to which these instruments, when considered collectively, operate as a coherent and integrated regulatory framework. The main contribution of this deliverable is therefore the development and application of a structured cross-regulatory framework for analysing that coherence. Against this background, the deliverable addresses two research questions. The first examines whether, and to what extent, the EU AI and data regulatory framework provides a coherent and legally certain allocation of actors and their roles, obligations, rights, and deterrence mechanisms across overlapping regulatory instruments [RQ1]. The second considers the extent to which the regulatory framework remains aligned with the technical and market realities of contemporary AI and data-intensive technologies [RQ2]. To answer these questions, the deliverable adopts a doctrinal legal methodology supplemented by socio-legal and interdisciplinary analysis. In responding to RQ1, it combines a systematic mapping of the regulatory framework with a multidimensional assessment of regulatory coherence. The analysis is complemented by two appendices providing (i) a visual map of the regulatory interactions between the analysed instruments (Appendix A); and (ii) a comparative overview of their regulatory goals, key actors, obligations, rights and deterrence mechanisms (Appendix B). In responding to RQ2, the deliverable examines the role of harmonised standards in operationalising legal obligations, situating them within the broader co- and meta-regulatory architecture of the EU AI and data regulatory framework. It then considers two selected examples illustrating how the framework may become partially misaligned with evolving technological and market realities. The analysis produces four main findings. First, the EU has developed a comprehensive and interconnected regulatory framework. Across the instruments analysed, common regulatory logics repeatedly emerge, including risk management, transparency, documentation, technical security measures, and ex ante compliance mechanisms. This suggests that what might appear to be a fragmented collection of legislative acts reflects, at a deeper level, a shared regulatory grammar grounded in a common preventive governance strategy. Secondly, the multidimensional coherence analysis demonstrates that regulatory coherence is neither absolute nor uniform, as the degree of coherence varies depending on the dimension being examined. The framework exhibits moderate levels of conceptual and normative coherence: the analysed instruments generally allocate actors, obligations, and responsibilities consistently with their respective regulatory objectives and pursue complementary goals centred on trustworthiness, the protection of rights, and the promotion of innovation. Direct conflicts between legal instruments appear comparatively rare, although the coexistence of multiple, often competing legitimate rights and interests requires continuous balancing through regulatory and judicial interpretation. Moreover, coherence becomes significantly weaker at the intersections among instruments, where overlapping actor categories and divergent legal concepts coexist. The main challenges arise at the operational and institutional levels, where overlapping compliance obligations, fragmented supervisory arrangements, parallel enforcement mechanisms, and insufficiently harmonised deterrence mechanisms increase regulatory complexity and legal uncertainty for regulated actors. Thirdly, the effectiveness of the framework increasingly depends upon implementation mechanisms. Because legal obligations are formulated at a relatively high level of abstraction, harmonised and technical standards play a central role in translating legal requirements into operational practice. This increasingly positions standards as key instruments of co-regulatory and meta-regulatory governance, while also raising questions concerning participation, legitimacy, and the translation of legal principles and values into engineering practice. Finally, the deliverable identifies emerging areas in which the assumptions underpinning the current framework may require reassessment. The dynamic nature of many AI systems challenges traditional ex ante conformity assessment models, while the growing importance of computational resources, cloud infrastructure and foundation models suggests that facilitating access to data alone may not achieve the competitive outcomes originally envisaged by the European Strategy for Data. These developments indicate that maintaining the effectiveness of the framework will require continual adaptation as technology, markets and governance arrangements evolve. The findings presented in this deliverable establish the legal foundation for subsequent HARNESS research on compliance, AI governance, legal ontologies, and sector-specific applications, in particular, Deliverables D1.4, D1.5, D2.2, and D2.6.

Paper

The full text of this publication is not hosted on 44B due to licensing.

Read it at OpenAlex

Similar papers

© 2026 NYSGPT2525 LLC