Region — EU profile
Two instruments, and a clock that starts at awareness.
The profile with the most mapped obligation of the four, and the only one where a missed deadline is measured in days rather than in supervisory patience.
What applies together
- EU AI Act
- Fourteen clauses, scored over the obligations that currently apply — Article 50 transparency from August 2026, with the Annex III high-risk duties deferred to December 2027 and stated beside the number rather than averaged into it.
- GDPR
- Eleven clauses, including Art. 32(1)(d) — regularly testing the effectiveness of technical measures — which almost nothing evidences because it asks for a result rather than a process.
- DORA, and sector rules
- Not mapped. The platform contributes to third-party risk and to the record an incident report is assembled from, and nothing to resilience testing or continuity — which is most of DORA.
The Article 73 clock
Fifteen days from awareness, ten where a death may have been caused, and two for widespread infringement or a serious and irreversible disruption of critical infrastructure. The class is a legal judgement and stays yours; the platform records who made it and computes the deadline that follows.
It counts from the moment the provider became aware, not from the event — so learning of an incident three weeks late gives you a deadline from that day rather than one already blown.
What resolving a profile actually changes
A market profile is not a locale setting. Changing it changes what the platform is permitted to do, what it looks for, what it scores you against and how long it keeps a record — and moving a workspace between profiles is itself a governed act with a name against it.
And a workload can be under more than one at once. The profile resolves per decision — narrowest wins — and is sealed into the record, so a pack states which laws this deployment believed applied at the moment the decision was made. How that works →