09-11-2026 Article

EU DIGITAL LAW 2027: What Is Currently Being Discussed and Decided in Brussels

Update Data Protection No. 264

The regulation of digital services and artificial intelligence at the European Union level remains in flux. In addition to the application of already existing regulatory frameworks such as the Digital Services Act (DSA), the Digital Markets Act (DMA), and the Regulation on Artificial Intelligence (AI Act), numerous further initiatives are currently progressing through the legislative process. These include the so-called Data Omnibus aimed at simplifying data law, as well as several legislative acts to strengthen digital sovereignty in the cloud sector. At the same time, recent developments in enforcement are becoming more pronounced, notably the designation of ChatGPT, Reddit, and Roblox as particularly large services under the DSA at the end of August 2026, as well as the first requests for information issued by the AI Office to a larger number of providers, following the entry into force of enforcement powers vis-à-vis providers of general-purpose AI models (GPAI) on 2 August 2026. For the coming half-year, a coexistence of ongoing supervision and advancing legislation is therefore to be expected. The following article provides an overview of the key developments and initiatives at EU level in the coming months from a data protection and data law perspective.

I. Supervision of AI Services Under the DSA and the AI Act

At the center of recent developments is the increasing supervision of AI and platform services under already applicable law, as evidenced by a designation decision under the Digital Services Act (DSA) and the first enforcement measures taken by the AI Office under the AI Act.

On 31 August 2026, the Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE) and Reddit and Roblox as Very Large Online Platforms (VLOP) within the meaning of the DSA. All three services had declared that they reach at least 45 million average monthly users in the EU, thereby exceeding the threshold for such designation. The designation of ChatGPT is of particular significance, as it extends a legal framework originally tailored to social networks, search engines, and marketplaces for the first time to a general-purpose AI assistant. For other AI services with comparable functionality and reach, the decision could set a precedent.

The designation means that the affected services must comply with the additional obligations for particularly large services within four months, in particular the annual assessment and mitigation of systemic risks, independent audits, and data access for research purposes. Indirectly, all companies that have integrated ChatGPT or comparable services into their own business processes may be affected by this decision – for example, in customer communications or content creation – since the adjustments required for compliance may impact response generation, search functionality, or data processing. This applies particularly to providers that integrate such services into their own products via application programming interfaces (APIs). It is therefore advisable to inventory the use of such services, including API integrations, and to review contracts with AI providers with regard to provisions on regulatory changes, liability, and data access.

In parallel, enforcement of the AI Act vis-à-vis model providers has commenced. In early September 2026, the AI Office announced that it had sent initial requests for information to more than 30 AI model providers, following the entry into force of enforcement powers with respect to providers of general-purpose AI models (GPAI) on 2 August 2026. According to the Commission, the requests concern both safety issues relating to the most advanced models and questions of copyright and transparency. Since the AI Office may impose fines for inaccurate or incomplete responses, even the answering of these requests carries considerable significance. For companies deploying AI systems, the transparency obligations under Article 50 of the AI Act have also been applicable since 2 August 2026, requiring disclosure of interaction with an AI system and machine-readable labeling of synthetic content. For legacy systems, a transitional period applies until 2 December 2026.

These measures fit into a broader debate on protection against problematic design practices, in the context of which the Commission has already addressed the potentially addictive design of certain platforms as well as issues of youth protection and age verification. A proposal for a Digital Fairness Act (DFA) is also expected for the fourth quarter of 2026, which would further develop digital consumer protection, for example with regard to manipulative user interfaces (so-called dark patterns) and the protection of minors. Whether there is a need for such legislation is disputed, as critics argue that the gaps to be closed by the DFA are narrowing as DSA enforcement progresses.

II. Simplification and Consolidation of Data Law

In addition to the supervision of existing services, the Commission is advancing several initiatives to simplify and consolidate data law. The basis is the "Digital Omnibus" presented in November 2025, which aims to consolidate key digital legislation and make it more practical. The part of this package relating to the AI Regulation (AI Omnibus) already entered into force on 27 July 2026 (as reported in Data Protection Update No. 256). The focus for the coming months is therefore on the so-called Data Omnibus, which aims at simplifying data law including the General Data Protection Regulation (GDPR) and is still at an early procedural stage.

In terms of substance, the Data Omnibus proposal envisages, in particular, establishing the Data Act as the central legal framework in data law and integrating adjacent regulatory frameworks such as the Data Governance Act and the Open Data provisions into it. Targeted amendments are planned for the GDPR, including a clarification of the concept of special categories of personal data, an explicit legal basis for training AI systems based on legitimate interests subject to technical safeguards, and simplified information and notification obligations for smaller enterprises (as reported in Data Protection Update No. 223). As a complementary measure, a central European notification portal is intended to consolidate multiple notifications under the GDPR, NIS-2, DORA, and the Cyber Resilience Act (CRA). The initiatives are not designed as a substantive reduction of the level of protection but rather as a structural simplification; for companies, the practical benefit lies primarily in more uniform terminology, less regulatory overlap, and clearer allocation of responsibilities.

Procedurally, the Data Omnibus has not yet entered into final negotiations. In the European Parliament, the amendments tabled by Members have been available since mid-July 2026 and are expected to be incorporated into the Commission’s proposal by February 2027.

Criticism of the Data Omnibus comes particularly from the data protection sector. The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) had already expressed reservations about individual proposals at the beginning of the process and warned against a reduction of the data protection level, specifically with regard to interventions in core concepts such as personal data and pseudonymization. Further adjustments are therefore to be expected in the ongoing proceedings. Regardless of the outcome, the already applicable obligations under the Data Act, whose key provisions have been directly applicable since 12 September 2025, remain binding for the affected companies.

III. Digital Sovereignty and Cloud

A further focal point of EU digital policy is the strengthening of digital sovereignty, particularly in the cloud sector. The central initiative is the proposal for a Cloud and AI Development Act (CADA), presented by the Commission on 3 June 2026, which forms part of a broader sovereignty package. The aim of the initiative is to expand cloud and AI infrastructure in the EU and to reduce dependencies on third-country providers, especially in critical areas. The core element of the draft is a tiered system of so-called sovereignty levels (Union assurance levels) that links security, resilience, and sovereignty requirements to the permissibility of use in the public sector.

The legislative process for the CADA is still at an early stage. The proposal is currently being deliberated in the Council and the European Parliament, with divergent views already emerging – particularly on how strictly the concept of sovereignty should be interpreted and whether large non-European providers (hyperscalers) should be excluded. The Commission is also collecting feedback on the initiative until the end of October 2026, meaning that substantive adjustments in the further proceedings are to be expected.

As a complementary measure, the Commission has announced a reform of European procurement law, with stronger legal anchoring of sovereignty criteria; a corresponding proposal for a Public Procurement Act is expected to be presented in September 2026. Also assigned to the sovereignty objective is the Chips Act 2.0, presented in early June 2026, which aims to strengthen domestic chip production.

In parallel with these legislative initiatives, a first-time application of the Digital Markets Act (DMA) to cloud services is taking shape. On 25 June 2026, the Commission preliminarily determined that Amazon Web Services (AWS) and Microsoft Azure, as the two largest cloud services in the EU, should be designated as gatekeepers within the meaning of the DMA. Notably, the Commission did not base this preliminary finding on the quantitative thresholds of the DMA, which both services do not meet, but rather on a qualitative overall assessment, according to which both services constitute an important gateway between businesses and their customers in the EU. A final decision is expected by the end of 2026. Should it confirm the preliminary assessment, AWS and Azure would be the first cloud services subject to the obligations of the DMA and would have to comply, within a transitional period, with requirements regarding interoperability and facilitating provider switching, among others. For companies using the cloud services of these providers, this could indirectly lead to greater ease in switching providers and in interconnecting various services.

IV. Conclusion and Outlook

The developments outlined above demonstrate that EU digital policy is currently moving on two levels simultaneously. On one level, the application of already existing law is gaining clearer contours, as evidenced by the designation of ChatGPT, Reddit, and Roblox under the DSA, the first requests for information by the AI Office, and the emerging extension of the DMA to cloud services. On the other level, several legislative procedures remain pending with the Data Omnibus and the sovereignty initiatives in the cloud sector, the outcome and timeline of which are still uncertain.

For companies, this means that the practically relevant requirements are increasingly arising not solely from future legislation but from the enforcement of the existing legal framework. Anyone deploying AI or cloud services, or integrating them into their own products, should therefore continuously monitor the developments described above – in particular the implementation of the expanded DSA obligations by the affected providers, the applicability of the transparency obligations under Article 50 of the AI Act, and a potential designation of AWS and Azure as gatekeepers. Immediate action is also triggered by two key dates in September 2026: the notification obligations under Article 14 of the Cyber Resilience Act, effective as of today (11 September 2026) (further information available here), and the access-by-design obligation under Article 3(1) of the Data Act for newly placed connected products, effective from tomorrow (12 September 2026) (further information available here). At the same time, it is advisable to follow the deliberations on the Data Omnibus, as the amendments to the GDPR and data law envisaged therein may have direct medium-term implications for compliance structures and data use.

This article was created in collaboration with our student employee Emily Bernklau.

Download as PDF

Contact persons

You are currently using an outdated and no longer supported browser (Internet Explorer). To ensure the best user experience and save you from possible problems, we recommend that you use a more modern browser.