The AI Act has no size threshold. NIS2 starts at 50 employees. CSRD, after the Omnibus I rewrite, kicks in at 1,000 employees and €450M turnover. A 200-person manufacturer importing aluminium and selling software with an AI component could face four of these seven regulations at once, each with its own deadlines, its own penalty ceiling, and its own definition of who is responsible.
The table below puts all seven side by side. Filter by sector and timeline to see which ones land on your desk. Each row expands to show the obligations that matter, with Article references and the regulatory overlaps that create double-reporting risk.
The enforcement column is the one worth reading closely. None of these seven regulations has produced a confirmed final administrative fine. DORA has been fully applicable since January 2025. The AI Act fine mechanism under Article 99 activates on 2 August 2026. NIS2 should have been enforceable since October 2024, but 23 member states missed the transposition deadline. The fines in the table are statutory ceilings. The actual enforcement track record, for every regulation listed, is zero.
Every figure traces to a specific Article on EUR-Lex. Where a deadline depends on legislation not yet formally adopted, the tool flags it with ⚠️ and cites the status.
Seven Source Texts, Zero Confirmed Fines
The tool draws on the full text of seven regulations: Reg. (EU) 2024/1689 (AI Act), Dir. (EU) 2022/2555 (NIS2), Reg. (EU) 2022/2554 (DORA), Dir. (EU) 2022/2464 as amended by Dir. (EU) 2026/470 (CSRD Omnibus I), Reg. (EU) 2023/956 as amended by Reg. (EU) 2025/2083 (CBAM), Reg. (EU) 2024/2847 (CRA) and Reg. (EU) 2023/1115 as amended by Reg. (EU) 2025/2650 (EUDR). Every penalty figure, scope threshold and deadline cited in the expanded detail panel references a specific Article.
The sector filter maps each regulation to the industries it primarily affects. “Financial services” shows DORA, NIS2 and the AI Act. “Importing carbon-intensive goods” shows CBAM alone. The timeline filter groups regulations by when their core obligations take effect.
GDPR is not included. It predates this cohort by eight years and operates on an enforcement track that has already produced over €7 billion in cumulative fines. CSDDD, the Data Act and the Digital Services Act are tracked separately in the EU Compliance Deadline Tracker.
Frequently Asked Questions
Which EU compliance regulations apply to my company?
The scope thresholds vary so widely across these seven regulations that a mid-sized company can easily fall under four of them while being exempt from the other three. NIS2 catches medium enterprises (50+ employees or €10M+ turnover) across 18 sectors listed in Annex I and II. CSRD, post-Omnibus I, only applies above 1,000 employees and €450M net turnover. CBAM has no size threshold but only covers importers of six commodity categories. The AI Act applies to anyone deploying an AI system in the EU regardless of headcount or revenue. In our assessment the sector filter on this tool is the fastest way to see which combination hits you, because the thresholds do not follow any shared logic.
What are the maximum fines under these EU regulations?
The AI Act has the highest statutory ceiling at €35M or 7% of global annual turnover for prohibited practices (Article 99(3)). NIS2 caps essential entities at €10M or 2% (Article 34). DORA defers entity-level fines to national law but penalises critical ICT third-party providers at 1% of average daily worldwide turnover per day, for up to six months (Article 35(6)). CBAM charges €100 per tonne of CO₂ equivalent not surrendered (Article 26). The CRA sets €15M or 2.5% for essential cybersecurity breaches (Article 64(2)). EUDR requires member states to set penalties of at least 4% of EU-wide annual turnover (Article 25). CSRD fines are left entirely to national law with no EU-wide floor. Worth noting: DORA’s 1%-per-day compounding structure can exceed the AI Act’s headline figure within weeks for a large ICT provider. The ceiling that reads lowest on paper is not necessarily the ceiling that hurts least.
Are any of these regulations being enforced yet?
None of the seven has produced a confirmed final administrative fine as of June 2026. DORA has been fully applicable since 17 January 2025, but supervisory authorities spent 2025 on dialogue rather than enforcement. The AI Act fine mechanism under Article 99 does not activate until 2 August 2026. NIS2 transposition is incomplete in most member states (23 of 27 missed the October 2024 deadline, and CJEU infringement referrals are underway). One unverified report of a German BSI fine (€850,000 in February 2026) has not been corroborated by primary sources. Our read is that the enforcement gap does not signal leniency. It signals a system that is still assembling its enforcement infrastructure. Once the first confirmed fine lands under any of these seven, it will set the precedent that moves the rest.
The matrix shows penalty ceilings and enforcement status at a glance. For the decision-by-decision record, every confirmed fine under the Big 8 is logged with its primary source and updated fortnightly.
How do NIS2 and DORA overlap for financial entities?
DORA is lex specialis to NIS2, meaning financial institutions follow DORA instead of NIS2 for cybersecurity (DORA Article 1(2)). A bank subject to DORA does not separately comply with NIS2 Articles 21 and 23. But that only resolves the cybersecurity overlap. If that same bank deploys AI systems, it also faces the AI Act. If it uses cloud infrastructure designated as a critical third-party provider, DORA’s CTPP oversight regime applies on top. The overlap tags in the expanded detail view show these intersections. In practice, “lex specialis” resolves less than it promises, because the regulations stack rather than substitute.
What changed with CSRD after the Omnibus I amendment?
Dir. (EU) 2026/470, published in the Official Journal on 26 February 2026, raised the scope threshold from 250 employees to more than 1,000 employees and more than €450M net turnover. Listed SMEs are fully exempt. The Commission estimates this removes roughly 80% of companies from the original scope. First reporting applies to financial years beginning on or after 1 January 2027, with reports due in 2028 under a simplified ESRS (delegated act expected June 2026). For the companies that remain in scope, the obligations have not softened. Double materiality, limited assurance and digital XBRL tagging all still apply. The Omnibus narrowed who reports. It did not narrow what they report.
The AI Act High-Risk Deadline Moved to December 2027
The original date for high-risk system obligations under Annex III was 2 August 2026. The Digital Omnibus package, which reached political agreement on 7 May 2026, defers this to 2 December 2027. That is 16 extra months. The catch: this deferral has not been formally adopted into law as of June 2026. It remains a political agreement between Parliament and Council. The tool marks this with ⚠️. The AI literacy obligation under Article 4 and the prohibition of certain practices under Article 5 are already in force and are not affected. For providers of high-risk AI systems, the question is whether to plan against December 2027 (likely) or August 2026 (legally still the fallback). In our assessment the political agreement is stable enough to plan against, but not stable enough to cite in a board paper without the caveat.
CRA Vulnerability Reporting Starts September 2026
The Cyber Resilience Act (Reg. (EU) 2024/2847) covers all products with digital elements placed on the EU market. Its first live obligation is Article 14: manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA/CSIRT within 24 hours, starting 11 September 2026. Full application, including CE marking, begins 11 December 2027. Open-source software stewards are fully exempt from fines (Article 64(10)(b)). The regulation creates a supply chain link that matters beyond its own scope: CRA conformity produces a presumption of conformity with the AI Act’s cybersecurity requirements under Article 15 (via AI Act Article 42(2)). For NIS2 entities, this means their software suppliers need to be CRA-compliant, adding a procurement due diligence layer.
Does CBAM apply below 50 tonnes per year?
The 2025 simplification amendment (Reg. (EU) 2025/2083) introduced a 50-tonne per year de minimis, but only for four of the six CBAM sectors: iron and steel, aluminium, fertilisers and cement. Importers of electricity and hydrogen have no de minimis regardless of volume. The definitive regime has been live since 1 January 2026, and importers of in-scope goods needed authorised declarant status by 31 March 2026. The first actual certificate surrender deadline is 30 September 2027, covering 2026 imports. Q1 2026 certificate price was €75.36 per tonne.
Where Each Regulation Has Its Own Tool
The AI Act Readiness Assessment scores your position against the AI Act’s obligations in five minutes.
The EU Compliance Deadline Tracker shows every obligation date across all regulations on a single timeline.
The NIS2 Applicability Checker walks through sector, size and entity classification to tell you whether NIS2 applies.
The DORA Compliance Assessment benchmarks your ICT risk management against DORA’s framework.
The AI Act Fines Calculator computes the exact fine ceiling based on your turnover and infringement type.
This tool provides general guidance based on published EU regulatory texts. It is not legal advice. EU regulations are subject to member state transposition and interpretation. Consult qualified legal counsel for your specific situation.
