Cybersecurity / Source date:

EU Compliance Fatigue: GDPR + DORA + NIS2 + AI Act = Complexity Crisis

The simultaneous implementation of GDPR, DORA, NIS2, and the EU AI Act has created a compliance complexity crisis — with overlapping requirements, conflicting timelines, and finite internal resources.

Illustration of shared evidence with separate GDPR, DORA, NIS2 and AI Act folders.

In two weeks the main body of the European artificial intelligence regulation becomes applicable, joining a stack that already includes the data protection regulation, the operational resilience regulation for financial entities, the network and information security directive as transposed in each member state, and the cyber resilience obligations arriving behind them. Compliance teams that were built to run one framework are now running four with overlapping scopes, different supervisors and incompatible vocabularies. The fatigue is real and it is not a failure of will. It is a structural consequence of regulating the same organisation four times from four directions without anyone reconciling the evidence requirements.

Four regulations asking the same organisation four versions of the same question is not four times the work. It is four times the work only if you answer each one separately, which is exactly what everybody is doing

Here is where the obligations actually overlap, and how to collapse the effort.

What each one is really asking

Strip away the vocabulary and the four regimes converge on a small set of underlying questions. What do you have, and who is responsible for it? An inventory with ownership — of personal data, of systems, of suppliers, of artificial intelligence systems and their intended purposes. Four regimes, four inventories, one underlying register if you build it that way. How do you know it is working? Risk assessment, testing, monitoring and the documentation of all three, on different cadences and to different templates. What happens when it breaks? Incident identification, assessment and notification, with materially different clocks — the fastest reporting obligations bite in hours, not days, and the differences between them are real. Who is accountable? Named responsibility at management level, which several of these regimes now make personal rather than corporate.

Where consolidation genuinely works

The inventory layer, almost entirely. One asset and supplier register with attributes for each regime is achievable and eliminates the largest duplication. The evidence layer, substantially. Access logs, change records, test results and training records serve multiple regimes with different framing. The governance layer, partly. One risk committee with a properly structured agenda can discharge several sets of oversight obligations, provided the minutes are specific enough to evidence each.

Reuse records, retain regime-specific decisionsArticle-derived operating approach, not a legal equivalence matrix. Confirm which regimes apply before using any evidence or timetable.
Shared recordKeep specific
Asset and supplier registerScope and required attributes
Tests and change recordsRequired cadence and evidence format
Governance minutesEach applicable oversight duty
Incident recordTrigger, authority and deadline
AI use inventoryPurpose and use-specific classification

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Where it does not

Incident notification. The clocks and thresholds genuinely differ, and an organisation that builds one process to a single timeline will miss an obligation. Build a notification matrix that maps trigger to authority to deadline, and accept that this part cannot be simplified. Also, the artificial intelligence obligations attach to a use of a system rather than to the system itself, which does not map onto asset-based thinking. The same model used for two purposes can fall in two different categories, and that determination has to be made per use.

Practical Guidance for EU Compliance Consolidation Strategy

  • Build one register with per-regime attributes, not four.
  • Map obligations to evidence, then find the duplicates.
  • Keep a notification matrix; do not consolidate the clocks.
  • Classify artificial intelligence systems by use, not by system.
  • Name accountable individuals once, across regimes.
  • Reuse testing evidence with per-regime framing.
  • Track transitional dates; several obligations phase in later.
  • Assign one owner for the consolidated programme.

The Regional Angle

The first reason this matters to Gulf-headquartered businesses is that the obligations follow the market rather than the office. A regional company selling into Europe, processing European customer data, or supplying software or services to European firms inherits a large part of this stack without any European establishment, and the artificial intelligence regulation in particular reaches providers outside the union whose systems are used within it. Establish which regimes actually apply to you before assuming distance protects you, because for most exporters the honest answer is at least two. The second concerns the supplier position, which is where most regional companies will feel this first. European customers are pushing obligations down their supply chains through contract, so a Gulf software vendor or service provider will receive questionnaires, audit rights and notification requirements derived from regulations it is not directly subject to. The effective response is to build the evidence set once and reuse it across customers, rather than treating each diligence pack as a bespoke exercise — which is the same consolidation argument applied commercially. The third is about the convergence that regional firms should exploit. Saudi and Emirati data protection frameworks, sector regulators' technology risk expectations and national cybersecurity requirements ask for recognisably similar evidence: an inventory, a risk assessment, incident notification and named accountability. A company building the consolidated register for European purposes is most of the way to satisfying its regional supervisors as well, provided it structures the register by attribute rather than by regime from the start.

The objection worth taking seriously

The strongest objection is that consolidation is a false economy because the regulators do not consolidate. Each supervisor examines against its own framework, expects its own documentation and takes no comfort from evidence prepared for someone else, and an organisation presenting a unified register during an inspection may find itself reconstructing regime-specific documentation under time pressure. The safe approach — and the one most advisers recommend — is to maintain each programme separately so that every examination finds exactly what it expects. That reflects real experience with how inspections proceed, and the point about supervisors not crediting other regimes' work is accurate. The distinction that resolves it is between the underlying record and the presentation of it. Nobody should walk into an inspection with a unified compliance document; what consolidation means is that the supplier register, the access logs and the risk assessments are maintained once and rendered into whichever format a given supervisor expects. Four separately maintained registers do not produce four better answers — they produce four registers that disagree with each other, which is a worse inspection outcome than a single accurate one presented in the right frame. The consolidation is in the data, not in the deliverable, and confusing the two is why the objection feels stronger than it is.

Common Questions

Does the artificial intelligence regulation apply to us if we only buy systems?

Deployer obligations are real and include use logging and human oversight requirements for higher-risk categories. They are lighter than provider obligations, not absent.

Can one incident process serve all regimes?

One detection and assessment process, yes. One notification timeline, no — the deadlines differ materially and the matrix approach is the only reliable answer.

Where should a small compliance team start?

The inventory. Everything else depends on it, and it is the single largest source of duplicated effort.

What should we expect over the next twelve months?

Expect the first supervisory activity under the new artificial intelligence obligations to focus on transparency and documentation rather than model behaviour. Expect further high-risk obligations to phase in later rather than now. Expect European customers to keep pushing requirements down supply chains. And expect consolidation tooling to be marketed heavily and to solve less than it claims.


EU Compliance Consolidation Strategy — we build the register once and render it four ways, which is the only part of this that actually consolidates.

Continue reading

Talk to OPS

Start with the operating problem.