Two EU regulations decide how you build AI systems and how you ship digital products.
Regulation (EU) 2024/1689 in working form. The four risk tiers, the practices that are banned outright, what you owe as a provider or a deployer, the GPAI rules, and the full implementation timeline.
The security obligations that come with selling a digital product in the EU. SBOM requirements and the SPDX 2.3 implementation guide, vulnerability disclosure, the reporting deadlines, and a plain-language explainer if you are starting cold.