HARNESS D2.6 Analysis of the AI and Data Regulatory Framework

The European Union has established a broad and complex regulatory framework governing artificial intelligence, data, and cybersecurity, including the AI Act, GDPR, Data Act, Data Governance Act, NIS2, Cyber Resilience Act, DORA, and EHDS. While these instruments define comprehensive legal obligations, they are intentionally expressed in technology-neutral language that leaves significant room for interpretation during implementation. Positioned between the legal analysis of Deliverable D1.1 and the compliance-tool survey of D2.2, this deliverable provides an engineering-oriented interpretation of the regulatory landscape, focusing on what technical systems must do to satisfy legal requirements rather than on legal doctrine itself. The deliverable develops a structured technical mapping of the regulatory framework, organised into data and cybersecurity clusters that reflect technical dependencies rather than legislative chronology. It translates legal concepts into engineering requirements, identifies the harmonised standards supporting implementation, and analyses areas where regulatory obligations overlap, conflict, or remain insufficiently specified. It also examines the evolving technical roles defined across the legislation, surveys existing machine-readable vocabularies for representing compliance knowledge, and demonstrates that no integrated cross-regulatory compliance framework currently exists. By relating these requirements to the current compliance-tooling ecosystem, the report highlights significant differences in implementation maturity across regulations and identifies several open research challenges, including explainability, machine unlearning, meaningful human oversight, and continuous compliance. The deliverable is intended as a practical reference for engineers, researchers, and system architects, enabling them to identify applicable regulatory obligations, relevant standards, and available compliance tools for a given system. Its mapping tables provide reusable foundations for compliance tooling and ontology development within the HARNESS project. Looking ahead, the analysis will require updates to reflect forthcoming legislative changes, particularly under the Digital Omnibus package, while the identified research gaps—especially integrated cross-regulation compliance reasoning and machine-readable compliance profiles—define key priorities for future work.

Paper

The full text of this publication is not hosted on 44B due to licensing.

Read it at OpenAlex

Similar papers

© 2026 NYSGPT2525 LLC