Whitepaper Overview:
The integration of Artificial Intelligence (AI) into connected products is rapidly transforming industries across the European Union (EU) and the US, offering enhanced functionalities and unprecedented levels of automation. From smart home devices and industrial machinery to connected vehicles and medical equipment, AI is increasingly embedded to improve performance, personalize user experiences, and drive innovation.
This surge in AI-powered connected products has coincided with the development of a comprehensive and evolving regulatory framework within the EU, designed to address the unique challenges and risks presented by these technologies. This framework encompasses not only sector-specific regulations but also horizontal legislation such as the EU Artificial Intelligence Act (AI Act), the Data Act, the General Data Protection Regulation (GDPR), and the Cybersecurity Act, creating a complex web of compliance obligations for businesses operating in this space.
In the US, regulation in this area is dynamic, with ongoing discussions and potential for new legislation. Like its EU counterpart, there is a growing emphasis on “security by design,” meaning that security should be built into connected products from the initial development stage, with various states introducing their own laws focusing on key areas such as personal data protection, IoT, cybersecurity, and AI.
This whitepaper provides a comprehensive overview of the legal and regulatory landscape governing AI in connected products within the EU and the US. It draws upon legal expertise and AI-driven analysis to offer an up-to-date perspective on the key definitions, principles, and requirements outlined in relevant legislation. The objective is to equip companies with a clear understanding of their legal responsibilities and the strategic considerations necessary to navigate this evolving environment.
The integration of AI into connected devices necessitates a proactive and informed approach to legal compliance, as the regulatory landscape is still maturing. Companies must understand that compliance is not a singular effort but an ongoing process requiring continuous monitoring and adaptation to new guidance and enforcement priorities.
This Whitepaper Covers:
- EU Artificial Intelligence Act (AI Act) and its risk-based approach
- Data Act and its focus on data access and portability
- General Data Protection Regulation (GDPR) and its implications for personal data processing
- Cybersecurity Act and Cyber Resilience Act, and their emphasis on security by design
- General Product Safety Regulation (GPSR) and the revised Product Liability Directive, and their impact on consumer protection and liability
- Internet of Things Cybersecurity Improvement Act of 2020
- NIST SP 800-213
- NISTIR 8259
- Colorado’s AI Act
- California IoT Security Law (SB-327)
- California Al Transparency Act (SB 942)
- Oregon IoT Security Law (HB 2395)
- Virginia High-Risk AI Developer and Deployer Act (HB 2094)
*This whitepaper was originally published on 26th March, 2025. Further regulatory developments may have occurred after publication. To keep up-to-date with the latest compliance news, sign up to our newsletter.
Authors

Dila Şen
Senior Regulatory Compliance Specialist
Leading global regulatory compliance with expertise in artificial intelligence (AI) and batteries.