EU Digital Law: These New Requirements Will Apply to Companies from August 2026
Update Data Protection No. 258
In August and September 2026, several EU legal provisions will take effect that have immediate practical significance for companies with digital products and services. These include the transparency obligations for AI-generated content, the application of the e-Evidence Regulation, the reporting obligations for actively exploited vulnerabilities and serious security incidents under the CRA, as well as the obligation to provide data access by design pursuant to Art. 3(1) of the Data Act for connected products and related services. These regulatory frameworks pursue different objectives, but their implementation frequently affects the same areas: product design, internal processes, and contractual documentation. At the same time, key questions of interpretation have so far been clarified neither by the courts nor conclusively specified through regulatory guidance, meaning companies must implement their compliance measures amid continuing legal uncertainty. This article provides an overview of the respective changes and their effects, and shows what preparations companies should make in the short term.
I. Transparency Obligations under Art. 50 AI Act
From 2 August 2026, the transparency obligations of Art. 50 of the AI Act will apply. Unlike the other provisions of the AI Act, this provision is not based on the risk classification of the system, but instead generally covers AI systems that interact with humans or generate content for them. Both providers and deployers of such systems are subject to obligations.
Providers must design AI systems intended for direct interaction with natural persons in such a way that users are informed that they are interacting with an AI (para. 1). If a system generates synthetic audio, image, video, or text content, it must also ensure that the outputs are marked in a machine-readable format and are recognizable as artificially generated or manipulated (para. 2). Deployers, on the other hand, are subject to a disclosure obligation where they distribute deepfakes or publish AI-generated texts in order to inform the public about matters of public interest (para. 4). Pursuant to para. 5, the disclosure must be made clearly and distinctly, at the latest at the time of the first interaction or exposure.
The Code of Practice on Transparency of AI-Generated Content of the European Commission serves as an implementation aid. For providers, it generally provides for a multi-layered labelling approach consisting of digitally signed metadata and an imperceptible watermark, supplemented by a detection solution that must be made available free of charge to authorities, media, and research institutions. For deployers, it contains requirements regarding the design and placement of the label; an EU icon is available for free use, which distinguishes between fully AI-generated content and content that has merely been AI-modified. The code is not legally binding and, even where fully complied with, does not constitute conclusive proof of conformity, but it is likely to be used as a benchmark in supervisory practice.
Finally, it should be noted that the postponement of the AI Act’s application deadlines envisaged under the Digital Omnibus does not affect the substance of the transparency obligations under Art. 50 of the AI Act (as we reported in Data Protection Update No. 256). These continue to apply unchanged from 2 August 2026. Only for providers of generative AI systems that have already placed their systems on the market before this date is a transitional period provided for implementing the technical labelling measures under para. 2. However, the date given for this, 2 December 2026, is not yet finally fixed but is part of the ongoing Digital Omnibus negotiations, in which 2 November 2026 and 2 February 2027 are also under discussion. Companies should therefore not assume that the implementation pressure will generally ease as a result of the Omnibus.
II. Entry into Force of the e-Evidence Regulation
On 18 August 2026, the core provisions of Regulation (EU) 2023/1543 (the “e-Evidence Regulation”) will become applicable. For the first time, the regulation allows law enforcement authorities to request electronic evidence directly from service providers in other Member States, without having to take the previously customary route via European Investigation Orders or other mutual legal assistance requests.
The regulation is built around two core instruments. Using a European Production Order (EPOC), judicial authorities can require the transmission of electronic data; the deadline is generally ten days, or just eight hours in emergency cases. The European Preservation Order (EPOC-PR), on the other hand, requires the provisional preservation of data for an initial period of 60 days in order to prevent its deletion or alteration pending a later production order.
The substantive requirements depend on the category of data concerned: while subscriber data can generally be requested in the case of any suspected criminal offense, access to traffic and content data requires an offense punishable in the issuing state by a custodial sentence of at least three years, or certain internet-related offenses.
The scope of addressees is broad. The concept of “service provider” under Art. 3 No. 3 of the e-Evidence Regulation follows a functional approach and covers, in addition to traditional telecommunications companies, messenger and email services, domain name and IP service providers, as well as other information society services. The latter already include platforms with a merely integrated communication function, such as online marketplaces with messaging systems or gaming offerings, as well as cloud and hosting services where data storage or processing forms an essential part of the service. Even ostensibly free-of-charge services fall within the scope, since data-driven business models satisfy the requirement of remuneration.
III. Reporting Obligations under Art. 14 CRA
The Cyber Resilience Act (“CRA”) establishes, for the first time, binding cybersecurity requirements for products with digital elements. The regulation will not become fully applicable until 11 December 2027 (as we reported in Data Protection Update No. 243). However, the reporting obligations under Art. 14 CRA already apply from 11 September 2026 and are therefore the first set of obligations that manufacturers must comply with in practice.
The CRA is addressed to all economic operators that make products with digital elements available on the Union market. The focus of the regulation is on manufacturers. These include not only traditional hardware producers, but also software providers and companies that market products under their own brand. According to the European Commission’s FAQ, both standalone software and firmware, as well as numerous hardware products, may be covered, while pure websites and standalone SaaS offerings generally do not fall under the CRA, unless they are part of a remote data processing solution that forms part of a product with digital elements. The reporting obligations under Art. 14 CRA apply exclusively to manufacturers.
In terms of content, Art. 14 CRA requires the reporting of two types of events: actively exploited vulnerabilities in a product with digital elements, and serious security incidents affecting its security. Reporting takes place in stages, via a single reporting platform, to the competent CSIRT and to ENISA. First, an early warning must be submitted within 24 hours of becoming aware of the event; within 72 hours, this is followed by a vulnerability or incident notification containing further details on the nature, impact, and remedial measures taken; a final report must be submitted within one month of the notification in the case of vulnerabilities, and within one month of the 72-hour notification in the case of security incidents. In addition, affected users must be informed of the incident and any necessary corrective measures.
For practical implementation, in addition to the CRA FAQ, which is maintained as a continuously updated document, the implementing provisions on the technical design of the reporting procedure should in particular be consulted.
IV. Obligation to Provide Access under Art. 3(1) Data Act
The Data Act has already applied since 12 September 2025. However, pursuant to Art. 50(3) of the Data Act, the obligation to provide data access by design under Art. 3(1) of the Data Act only applies to connected products and related services placed on the market after 12 September 2026. Existing products remain unaffected in this respect; by contrast, the user’s right of access against the data holder under Art. 4(1) of the Data Act could already be asserted from September 2025.
Art. 3(1) of the Data Act requires that connected products and related services be designed, manufactured, and provided in such a way that the datagenerated through their use is, by default, easily, securely, and free of charge accessible to the user, and in a comprehensive, structured, commonly used, and machine-readable format. Where relevant and technically feasible, access must be possible directly from the product or service. The manufacturer is the addressee of this obligation. Since this requirement must already be taken into account during product development, it affects product architecture, interfaces, and data formats, and can generally not be retrofitted without significant effort. It is supplemented by the pre-contractual information obligations under Art. 3(2) and (3) of the Data Act, which require, among other things, information on the type, scope, and format of the data generated, as well as on the ownership of trade secrets.
V. Recommendations for Companies
1. Clarify Whether You Are Affected
The new obligations are tied to roles that do not always correspond to a company’s previous self-classification. A company that merely has a chatbot developed for it and deploys it under its own name may qualify as a provider under the AI Act; a platform with a mere messaging function may be a service provider (e-Evidence); pure software providers are also manufacturers (CRA). Companies should therefore review their product and service portfolio and determine, for each offering, which obligations apply. In corporate group structures, it must additionally be clarified which company is subject to the obligation and who implements it operationally.
2. Initiate Technical and Organizational Implementation in Good Time
Many of the requirements cannot be caught up on short notice. Labelling solutions for AI-generated content, data access interfaces in connected products, or processes for vulnerability detection must be developed, tested, and integrated into existing systems. Likewise, templates and standard wording for notices and reports should be prepared in advance, and contracts and product information should be adapted. Where deadlines are short – for example, eight hours for production orders in emergency cases, or 24 hours for the early warning in the case of actively exploited vulnerabilities – an established process is more important than a detailed procedural description.
3. Assign Responsibilities and Document Implementation
The obligations are spread across product development, IT security, legal, marketing, and communications. Companies should determine which function is responsible for which requirement, and who is reachable and authorized to make decisions at short notice in the event of an order or an incident; for the e-Evidence Regulation, the designation of an addressee is in any case a statutory requirement. Measures taken and the underlying considerations should be documented in a traceable manner, so that they can be demonstrated to authorities and contractual partners. Since the Commission’s guidelines, codes of conduct, and FAQs are continuously being supplemented, and further changes are foreseeable under the Digital Omnibus, a regular review of the implementation status is recommended.
VI. Conclusion and Outlook
August and September 2026 will bring companies with digital products and services a number of directly applicable obligations. Despite differing regulatory objectives, the implementation requirements overlap: they concern product design, technical interfaces and labelling solutions, internal reporting and response processes, as well as accompanying documentation. Companies that have so far dealt with these issues separately should consider whether effort can be reduced by taking a joint approach.
At the same time, the legal situation remains in flux. Key concepts have so far been clarified neither by the courts nor conclusively specified through regulatory guidance, and further changes are on the horizon under the Digital Omnibus, the final shape of which cannot currently be foreseen. In practice, this means that compliance frameworks should be designed to be adaptable and reviewed at regular intervals.
This article was created in collaboration with our student employee Emily Bernklau.