The European Legal Framework for the Digital World
Six regulatory regimes — regulations, a family of directives and a live reform package. Drafted separately, overlapping deliberately, enforced by institutions of wildly unequal capacity.
Thirteen vessels, twenty-two paths. Touch one to read it — or take them in order.
Reading the current state of play…
One system, read six ways
This brief reads them as a single system: what each one actually requires, where the requirements collide, what enforcement has really produced as opposed to what was announced, and where the serious objections lie — including the ones coming from inside the European institutions themselves.
The architecture: how Europe decided to regulate software
Legal basis and what it forces · the GDPR template replicated · four design choices · the structural critique
Before the individual instruments, the grammar. Every act in the EU digital rulebook is built from the same handful of moves, and once you can see the moves you can predict most of the detail. The reverse is also true: nearly every serious criticism of the rulebook is a criticism of one of these moves, not of a drafting choice inside one regulation.
The internal-market legal basis and what it forces
The EU has no general competence to legislate on speech, safety or morality. What it has is Article 114 TFEU — the power to harmonise national rules that fragment the internal market. Almost the entire digital rulebook is built on that basis; the principal exception is the GDPR itself, which rests on Article 16 TFEU, the Union's data-protection competence. This is not a technicality; it shapes the substance. It explains why the DSA is framed as a Single Market for Digital Services regulation rather than a content law, why the AI Act is structured as product-safety legislation with conformity assessment and CE marking rather than as a fundamental-rights charter, and why almost everything comes as a Regulation (directly applicable, no transposition) rather than a Directive. The DSA's own selling point is that it replaces twenty-seven national regimes with one framework, which is a single-market claim before it is a safety claim.
The consequence is a persistent mismatch between the stated legal purpose (removing barriers to trade) and the actual regulatory ambition (governing how attention is allocated, how models are trained, how markets are structured). That mismatch is the raw material for most litigation risk in the system, and we will come back to it repeatedly.
The GDPR template, replicated
Scholars have described what followed the GDPR as act-ification and GDPR mimesis: a rapid series of instruments each reproducing the same institutional shape. Papakonstantinou and De Hert identified the pattern early — a specialised vocabulary, a set of principles, case-specific rights, and a supervisory apparatus, reproduced across the DGA, DSA, DMA and AI regulation. In practice every instrument in this brief instantiates the same five slots:
Loading the comparison…
Four design choices that generate almost every criticism
Risk-based tiering. Rather than uniform rules, obligations scale with size or danger: the DSA's graduated pyramid from intermediary to , the AI Act's prohibited / high-risk / transparency-risk / minimal-risk ladder, the DMA's binary designated-or-not switch. Tiering is proportionate in principle and produces cliff edges in practice. The 45-million-user threshold, the 10,000-business-user DMA presumption and the 10^25 systemic-risk presumption are all administrable numbers standing in for unadministrable concepts, and each has already produced litigation or gaming.
Turnover-based penalties. Percentage-of-global-revenue ceilings were designed so that penalties bite firms whose EU revenue is a fraction of their worldwide revenue. They are also the single most inflammatory feature of the rulebook internationally, and — as the GDPR record shows — the headline number and the collected number are very different things.
Extraterritorial reach through the marketing criterion. Each instrument applies to conduct directed at the Union irrespective of the provider's establishment. The Data Act reaches non-EEA SaaS providers with EU customers; the AI Act reaches providers whose outputs are used in the Union; the GDPR reaches controllers established anywhere that offer goods or services to, or monitor the behaviour of, people in the Union. This is the mechanism behind the so-called Brussels effect, and equally behind the charge that Europe regulates firms it does not host.
Co-regulation through codes, guidelines and delegated acts. The primary texts are frequently incomplete by design, with the operative detail arriving later through Commission guidelines, delegated acts, codes of practice and harmonised standards. The Code of Practice, the DSA Article 40 delegated act on researcher access and the (still incomplete) harmonised standards for high-risk AI are all load-bearing. This buys flexibility and costs legal certainty — and, as Part VIII shows, it also means the effective content of the law can shift without the legislature reconvening.
Two of these delegated instruments have already landed, and their timing shows how the pattern plays out in practice.expand
The GPAI Code of Practice — the operative detail behind AI Act Articles 53 and 55 — was finalised on 10 July 2025 after three drafts and a final text. The DSA's Article 40 delegated act on vetted-researcher data access entered into force on 29 October 2025, three years after the DSA itself. In both cases the primary Regulation was in force well before the instrument that actually tells firms what to do.
That gap is not a drafting failure; it is the mechanism working as designed — flexibility bought at the price of a period where the law's content is genuinely unsettled. Part III and Part V return to what each of these two instruments actually changed once it arrived.
GDPR: the gravitational centre, and the cracks in it
What it requires · compliance reality · the one-stop-shop pathology · announced vs collected · the competitiveness critique
Regulation (EU) 2016/679 is not merely the oldest instrument here; it is the one every other instrument either builds on, carves an exception from, or has to be reconciled with. Understanding the GDPR's enforcement pathology is a prerequisite for judging whether anything else in the rulebook will work.
What it actually requires
The operative architecture is compact. Article 5 sets six processing principles plus accountability: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality. Article 6 provides the exhaustive list of lawful bases — consent, contract, legal obligation, vital interests, public task, legitimate interests — and Article 9 prohibits processing of special categories absent a narrow derogation. Articles 12–22 create the data-subject rights (information, access, rectification, erasure, restriction, portability, objection, and the Article 22 protection against solely automated decisions with legal or similarly significant effects). Chapter IV builds the compliance machine: Article 25 data protection by design and by default, Article 30 records of processing, Articles 33–34 breach notification, Article 35 data protection impact assessments, Articles 37–39 the DPO. Chapter V governs international transfers. Article 83 sets the two-tier penalty ceilings.
Two of these matter disproportionately for the rest of this brief. Article 22 is the pre-existing European law of automated decision-making — it did not wait for the AI Act, and the two classify independently. A system the AI Act places in the minimal-risk band, owing it no obligations under that Act, is still caught by Article 22 if it makes solely automated decisions with legal or similarly significant effects. Neither regime switches the other off. Article 35 DPIAs are the conceptual ancestor of the DSA's Article 34 systemic risk assessment and the AI Act's Article 27 fundamental rights impact assessment; an organisation running all three separately is duplicating work the regulators themselves now acknowledge is duplicated.
The compliance reality
For most organisations GDPR compliance resolves into four durable artefacts: a processing inventory that is actually maintained, a defensible lawful-basis analysis per processing purpose, a rights-request workflow that meets the one-month deadline, and a breach-response process capable of a 72-hour notification decision. The enforcement data shows where organisations fail. Analysis of the CMS Enforcement Tracker corpus finds three violation categories account for roughly 94% of all fine value, with transparency failures under Articles 12–14 prominent enough that the EDPB made them the subject of a 2026 coordinated enforcement action across twenty-five authorities. Regulators are now processing an average of 443 breach notifications per day, a 22% year-on-year increase — which is to say the enforcement pipeline is deepening faster than enforcement capacity.
The enforcement pathology: one-stop-shop, and the gap between announced and collected
Article 56 gives the supervisory authority of the controller's main establishment the lead role in cross-border cases, with Article 60 cooperation and Article 65 EDPB dispute resolution behind it. Because Meta, Google, Apple, Microsoft, TikTok and LinkedIn all placed their European headquarters in Dublin, this made one national regulator the lead authority for most of the global platform economy. The numbers are stark: cumulative GDPR fines have passed roughly EUR 7.1 billion since 2018, of which the Irish DPC alone accounts for about EUR 4.04 billion — roughly 57% of all fine value — and eight of the ten largest fines still standing (the other two are the Dutch authority's, both against Uber). Spain, by contrast, leads by number of decisions with over a thousand.
The critique of this arrangement is old, and the legislative answer has only just arrived: Regulation (EU) 2025/2518, which harmonises the admissibility of complaints, the parties' procedural rights and the time limits for draft decisions in cross-border cases, entered into force on 1 January 2026 and applies from 2 April 2027, its investigation rules to complaints lodged after that date. In 2021 the Irish Council for Civil Liberties called Ireland the GDPR's worst bottleneck, documenting failure to transmit draft decisions to peer authorities in the great majority of major cross-border cases, and noting that Spain issued roughly ten times as many decisions on a smaller budget. Max Schrems and other campaigners make the same structural argument: cases take years, penalties arrive late, and complainants have limited procedural standing. The DPC has grown to nearly 300 staff by 2026 and moved to a three-Commissioner structure partly to address single-point-of-decision bottlenecks, but the architecture remains.
Roughly half a percent of the figure above — the DPC's own published position, per Annex B.
DSA: the platform constitution and its enforcement problem
The four-tier pyramid · Articles 16, 34-35 and 40 · the enforcement record · four serious objections
Regulation (EU) 2022/2065 replaced the liability core of the 2000 e-Commerce Directive with a graduated due-diligence regime. It is the instrument that most clearly reveals what the EU rulebook is actually trying to do — govern the design of systems rather than adjudicate individual pieces of content — and the one under the heaviest political fire.
The pyramid: who owes what
The DSA stacks obligations cumulatively across four tiers. Every tier inherits the tier below it.
| Tier | Core obligations | Anchor articles |
|---|---|---|
| All intermediary services | Conditional liability exemptions preserved; no general monitoring obligation; single point of contact; legal representative for non-EU providers; clear terms and conditions with fundamental-rights regard; compliance with orders to act against illegal content and orders to provide information; annual transparency reporting | Arts. 4-10, 11-15 |
| Hosting services | Notice-and-action mechanisms that are easy to access, user-friendly and electronic; statements of reasons for every restriction; notification of suspicions of criminal offences | Arts. 16-18 |
| Online platforms | Internal complaint-handling; out-of-court dispute settlement; trusted flaggers; measures against misuse; ban on dark patterns; advertising transparency; recommender-system parameter disclosure; minors protection including a ban on targeted advertising to children; trader traceability for marketplaces | Arts. 20-32 |
| VLOPs / VLOSEs (45m+ monthly EU users) | Annual systemic risk assessment; proportionate mitigation; crisis response; independent audit; a non-profiling recommender option; enhanced ad repository; vetted-researcher data access; independent compliance function; supervisory fee | Arts. 33-43 |
Micro and small enterprises are exempt from most online-platform obligations (Art. 19) unless they are designated as very large platforms.
The three provisions that carry the regime
Article 16 — notice and action, and the manufacture of knowledge
Article 16 requires hosting providers to operate electronic notice mechanisms facilitating sufficiently precise and adequately substantiated notices. Its critical paragraph is 16(3): a compliant notice gives rise to actual knowledge or awareness for the purposes of the Article 6 liability exemption where it allows a diligent provider to identify the illegality without a detailed legal examination. This is the hinge on which platform liability now turns. It also creates the structural incentive that critics of the DSA emphasise most: because knowledge triggers liability exposure and over-removal carries no equivalent penalty, the rational response to a borderline notice is removal. The DSA's counterweights — statements of reasons, internal appeals, out-of-court settlement — are procedural, not substantive. Article 14(4) does require providers to act diligently, objectively and proportionately, with due regard to users' fundamental rights, which gives over-removal a legal cost in principle.
Article 34-35 — systemic risk, the deliberately open concept
Article 34 obliges VLOPs and VLOSEs to diligently identify, analyse and assess systemic risks stemming from the design or functioning of their service, including algorithmic systems, at least annually and before deploying functionalities likely to have a critical impact. The enumerated categories are dissemination of illegal content; negative effects on fundamental rights; negative effects on civic discourse, electoral processes and public security; and effects relating to gender-based violence, public health, minors, and physical and mental well-being. Article 34(2) requires assessment of how recommender design and other algorithmic systems influence those risks, including through intentional manipulation and inauthentic use. Article 35 then requires proportionate, effective mitigation — with the choice of measures left to the provider.
This is the most consequential and most criticised provision in the DSA. Its openness is deliberate: a closed list would be obsolete within a product cycle. But AlgorithmWatch's research on the provision found that stakeholders struggled to determine whether a given harm was systemic enough, that Recitals 79-89 were often seen as confusing rather than clarifying, and that overly specific criteria would risk platforms optimising for metrics rather than real harms while overly vague ones leave the concept unadministrable. Both failure modes are live.
Article 40 — data access, and the gap between promise and delivery
Article 40 was described in the research community as the holy grail of renewed data availability. It creates two pathways: Article 40(12) access to publicly available data beyond voluntary platform tools, and Article 40(4) access to non-public data — exposure logs, moderation records, recommendation metrics — for vetted researchers, requested through the national Digital Services Coordinator of establishment rather than from the platform directly. Both are purpose-limited to research contributing to the detection, identification and understanding of systemic risks under Article 34(1), and for 40(4) also to assessing mitigation measures under Article 35. A delegated act entered into force on 29 October 2025, establishing a centralised DSA Data Access Portal, procedural safeguards and platform data catalogues.
The enforcement record, in order
| Date | Action | Significance |
|---|---|---|
| 5 Dec 2025 | X fined EUR 120 million — first DSA non-compliance fine | Deceptive design in the paid blue checkmark (Art. 25), non-functional ad repository (Art. 39), obstruction of researcher access (Art. 40(12)). 183-page decision. |
| 5 Dec 2025 | TikTok commitments made binding | Ad-repository failings cured by commitment rather than fine — the Commission's stated priority is compliance, not revenue. |
| 6 Feb 2026 | TikTok preliminary findings — addictive design | Among the first enforcement actions targeting platform architecture — infinite scroll, autoplay, personalised recommenders — rather than illegal content. |
| 28 May 2026 | Temu fined EUR 200 million | Failure to diligently assess the systemic risks from the sale of illegal products. |
| 10 Jul 2026 | Meta preliminary findings — addictive design | Instagram and Facebook. Proposed remedies include disabling autoplay and infinite scroll by default. |
| 20 Jul 2026 | AliExpress fined EUR 550 million — largest DSA fine to date | Action plan due by 20 October 2026; AliExpress has said it will challenge the decision. |
| 24 Jul 2026 | TikTok preliminary findings — minors' safety | Minors' accounts default to public; 16-17 year-olds' content recommended in the For You feed. |
Note also the counter-current: in September 2025 the General Court annulled the 2023 supervisory-fee decisions for Facebook, Instagram and TikTok, because the methodology for counting users should have been adopted by delegated act rather than by implementing decision. It found no error in the platforms' obligation to pay and provisionally maintained the decisions' effects, and the Commission has appealed both judgments. The DSA is not winning every point.
DMA: ex ante competition law, and the limits of proceduralism
Designation and Articles 5-7 · what the Apple and Meta decisions established · the 2026 review · the case against
Regulation (EU) 2022/1925 is the rulebook's cleanest conceptual break. Traditional competition law under Article 102 TFEU is ex post: prove dominance, prove abuse, prove effects, litigate for a decade. The DMA discards all of that. Designate the firm, and a list of prohibitions and obligations applies immediately, with no requirement to demonstrate anticompetitive effect in the individual case.
Designation and the obligation set
Article 3 designates gatekeepers by quantitative presumption: an undertaking providing a core platform service with substantial EU turnover or market capitalisation, at least 45 million monthly active end users and 10,000 yearly active business users in the Union, sustained over three financial years. The core platform service categories in Article 2 — intermediation, search, social networking, video sharing, communications, operating systems, browsers, virtual assistants, cloud, advertising — are the scope-defining list. Seven undertakings have been designated to date: Alphabet, Amazon, Apple, Booking, ByteDance, Meta and Microsoft.
The substance sits in three articles. Article 5 contains the self-executing prohibitions: no combining personal data across core platform services without consent, with a genuinely equivalent less-personalised alternative for those who refuse (5(2)); no anti-steering — business users must be free, free of charge, to communicate and promote offers to end users and conclude contracts with them outside the platform (5(4)); no requiring use of the gatekeeper's identification, payment or browser engine as a condition of access (5(7)); no preventing business users from raising non-compliance with national authorities (5(6)). Article 6 contains the obligations susceptible of further specification: no self-preferencing in ranking (6(5)); permitting third-party app stores and sideloading (6(4)); free and effective interoperability with the same hardware and software features available to the gatekeeper's own services (6(7)); data portability (6(9)); business-user access to their own performance data (6(10)). Article 7 imposes interoperability on number-independent interpersonal communications services. Article 11 requires a compliance report within six months of designation, updated at least annually; Article 13 adds the anti-circumvention duty, Article 14 the duty to inform the Commission of intended concentrations, and Article 15 the independently audited description of consumer-profiling techniques.
What enforcement has actually established
On 23 April 2025 the Commission adopted its first non-compliance decisions: EUR 500 million against Apple under Article 5(4) and EUR 200 million against Meta under Article 5(2). Both are on appeal, but the interpretive content of the Apple decision — published in non-confidential form on 26 May 2025 — is the most important doctrinal output of the DMA so far. Three principles emerge:
• The standard is proactive enablement, not mere non-obstruction. Article 5(4) obliges gatekeepers to enable steering contractually and technologically. It is not enough to provide the effective possibility of steering by not impairing it — which might have sufficed under Article 102 TFEU.
• Formal compliance fails. The Commission found Apple's user-facing choices were not genuinely meaningful because developers faced fees and technical barriers. Link-outs were permitted but carried commissions of up to 17% on sales within seven days.
• Compliance cannot be averaged. The existence of one set of terms permitting steering did not compensate for other sets that did not; each set of business terms must independently comply.
The Meta decision applied the same logic to consent. The binary pay or consent model — roughly EUR 9.99-12.99 per month for an ad-free service, or consent to full data combination — was found not to provide the genuinely equivalent, less data-intensive alternative Article 5(2) requires. In December 2025 the Commission acknowledged Meta's undertaking to give EU users, from January 2026, a choice between fully personalised advertising and a less-personalised option that shares less of their data.
Two further developments define the current position. First, Article 6(7) specification proceedings: in September 2024 the Commission opened two proceedings on Apple's interoperability obligation for iOS and iPadOS; on 19 March 2025 it adopted two specification decisions, one setting out how Apple must open nine iOS connectivity features to third-party connected devices, the other how it must handle developers' interoperability requests. Second, on 8 July 2026 the General Court dismissed Apple's gatekeeper-designation challenges in full, confirming the App Store and iOS obligations and closing the route by which designated gatekeepers could contest interoperability obligations at the designation stage. Apple's response has been to escalate politically, publicly arguing the DMA does not work and should be repealed, and signalling delayed European deployment of new AI features.
The 2026 review: what the Commission chose not to do
Article 53 required a review by 3 May 2026. The Commission's report, informed by over 450 consultation contributions, concluded the DMA adds value against the counterfactual of fragmented national rules, imposes no direct obligations on SMEs, and fits coherently with the rest of the digital rulebook. Crucially, despite substantial stakeholder demand — BEUC among others called for extending interoperability to social media, cloud and AI infrastructure — the review concluded that future work should concentrate on enforcing what exists rather than expanding scope. The Commission aims to conclude the AWS and Azure investigations within twelve months of their 18 November 2025 opening — around November 2026 — and to report on the sector-wide investigation within eighteen months, around May 2027. These are targets, not legal deadlines.
AI Act: the risk pyramid, the compute threshold, and the delay
Four tiers · Chapter V and general-purpose AI · the compute-threshold argument · the AI Omnibus and what actually moved
Regulation (EU) 2024/1689 entered into force on 1 August 2024 as the world's first comprehensive horizontal AI law. It is, structurally, product-safety legislation: conformity assessment, technical documentation, notified bodies, CE marking, post-market monitoring. That choice determines both its strengths and the specific way it is currently failing to arrive on schedule.
The four tiers
Unacceptable risk (Article 5) — applicable since 2 February 2025: manipulative or deceptive techniques materially distorting behaviour; exploitation of vulnerabilities based on age, disability or socio-economic situation; social scoring leading to detrimental treatment in unrelated contexts; individual criminal-risk prediction based solely on profiling; untargeted scraping of facial images for facial recognition databases; emotion inference in workplaces and educational institutions; biometric categorisation inferring sensitive attributes; and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions.
High risk (Article 6 and the annexes) — two routes in. Article 6(1): the system is a safety component of a product covered by Union harmonisation legislation in Annex I. Article 6(2): the system falls within Annex III — biometrics; critical infrastructure; education; employment and worker management; access to essential services including creditworthiness and insurance pricing; law enforcement; migration and border control; administration of justice and democratic processes. Article 6(3) provides the filter: an Annex III system is not high-risk where it does not pose a significant risk of harm — but the provider must document that assessment and register the system. Chapter III then imposes the substantive obligations: risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency to deployers (Art. 13), human oversight (Art. 14), accuracy and cybersecurity (Art. 15), conformity assessment (Art. 43), registration (Art. 49). Article 25 is the trap most often missed: a distributor, importer or deployer becomes a provider — assuming the full obligation set — if it puts its name or trademark on a high-risk system, substantially modifies it, or modifies its intended purpose.
Transparency risk (Article 50) — disclosure duties: users must be informed they are interacting with an AI system; synthetic content must be marked in a machine-readable format; deep fakes and AI-generated text on matters of public interest must be disclosed.
Minimal risk — no obligations specific to the tier, although the Article 4 AI-literacy duty applies to providers and deployers of all AI systems. The Commission's own position is that the vast majority of AI systems currently used in the Union — spam filters, AI-enabled video games — fall here. This is worth stating plainly against the common claim that the AI Act regulates all AI: it does not, and never claimed to.
Chapter V: general-purpose AI, and the argument about compute
Chapter V (Articles 51-56) is a separate regime layered on top, and it is where the frontier-model questions live. Article 3(63) defines a model as one trained on broad data, displaying significant generality, capable of competently performing a wide range of distinct tasks and integrable into downstream systems — with the Commission's July 2025 guidelines adding an indicative criterion of more than 10^23 training . Every provider owes Article 53: Annex XI technical documentation; an Annex XII information pack for downstream providers; a policy to comply with Union copyright law; and a sufficiently detailed public summary of training content. Article 53(2) partially exempts models released under a genuinely free and open-source licence — but that exemption evaporates entirely for systemic-risk models.
Article 51 then classifies a subset as with systemic risk: models with high-impact capabilities (51(1)(a)), or designated by Commission decision (51(1)(b)). Article 51(2) supplies the operative presumption: cumulative training compute greater than 10^25 . Article 55 then adds the frontier obligations: model evaluation against standardised protocols including documented adversarial testing; assessment and mitigation of systemic risks at Union level; tracking and prompt reporting of serious incidents; adequate cybersecurity protection. Because Articles 53 and 55 are drafted at a high level of abstraction, the operative detail lives in the Code of Practice, finalised on 10 July 2025 after three drafts and a final text. Analysts at Georgetown's CSET assessed that the safety and security chapter sets a minimum standard for frontier risk management that goes considerably beyond then-current industry practice — provided it is widely adopted. That proviso is doing real work: the Code is voluntary. Voluntary is not the same as legally irrelevant — adherence is the route the Commission and the AI Board have confirmed as an adequate means of demonstrating compliance with the Chapter V obligations, so a provider that declines it does not escape the obligations, only this way of discharging them.
Timeline, enforcement, and the delay that actually happened
The staggered application: prohibitions and AI-literacy obligations from 2 February 2025; obligations and governance structures from 2 August 2025; the general date of application from 2 August 2026; Annex I embedded systems originally from 2 August 2027. Then the schedule slipped. The AI Omnibus, proposed 19 November 2025, split from the wider Digital Omnibus precisely because the August 2026 deadlines were approaching. Parliament adopted its mandate on 26 March 2026 by 569 votes to 45; the Council its general approach on 13 March. The second political trilogue on 28 April 2026 collapsed after roughly twelve hours — notably not over the delay itself, on which all three institutions had already converged, but over how the AI Act interlocks with existing sectoral product-safety law. Agreement followed on 7 May, Parliament approved on 16 June, the Council gave final approval on 29 June, and the regulation entered into force on 27 July 2026, six days before the deadline it was amending. The delay is real, partial, and unequal across the tier. Prohibitions, duties and transparency all remain on or near the original track. Within the high-risk tier the two routes moved by different amounts: Annex III stand-alone systems went from 2 August 2026 to 2 December 2027, sixteen months; Annex I product-embedded systems went from 2 August 2027 to 2 August 2028, twelve. The Omnibus also added two new Article 5 prohibitions applying from 2 December 2026 and rewrote the Article 4 AI-literacy duty from an obligation to ensure a sufficient level into one to take measures supporting it — so the same instrument delayed, expanded and softened at once.
Data Act: prising open the machine economy
The chapters · cloud switching · phasing · the trade-secret tension
Regulation (EU) 2023/2854 is the least discussed and, for anyone operating cloud or connected products, among the most operationally disruptive instruments in the rulebook. Where the GDPR governs personal data, the Data Act governs product and service data as such — personal or not, though predominantly non-personal, industrial and machine-generated, with the GDPR prevailing wherever personal data is involved — and reallocates control over it by default.
Cloud switching: the sharpest edge
Chapter VI is nine articles (Arts. 23–31) out of fifty and, for the software industry, is most of the regulation's practical weight. It requires providers of data processing services to remove all pre-commercial, commercial, technical, contractual and organisational obstacles inhibiting a customer from switching to another provider or to on-premise infrastructure. Article 25 prescribes the mandatory contractual content, and the numbers are hard-edged: maximum notice period to initiate switching, two months; transitional period during which switching occurs, 30 calendar days (or, where technically unfeasible, a justified alternative not exceeding seven months); data retrieval period after the transitional period, at least 30 days; full erasure of all exportable data after retrieval ends. For IaaS, providers must enable functional equivalence in the new environment. From 12 January 2027, all switching charges are prohibited outright.
Phasing, and why the dates matter more than usual
| Date | What applies |
|---|---|
| 11 Jan 2024 | Entry into force |
| 12 Sep 2025 | General application: Ch. III data-access; Ch. IV unfair terms; Ch. VI switching |
| 12 Sep 2026 | Art. 3(1) design obligation — connected products must be built so data is accessible by default |
| 12 Jan 2027 | Switching charges prohibited entirely |
| 12 Sep 2027 | Ch. IV unfair-terms rules extend to long-term B2B contracts concluded on or before 12 Sep 2025 |
The cyber layer: NIS2, CER, DORA, CRA — and the transposition failure
Four instruments · Article 20 management liability · what the transposition failure proves
Cybersecurity is the part of the rulebook where the EU chose directives over regulations, and it is paying for that choice. The substantive obligations are reasonable and largely uncontroversial; the delivery has been the worst in the entire digital acquis.
| Instrument | Form | Status |
|---|---|---|
| — Directive (EU) 2022/2555 | Directive | Transposition due 17 Oct 2024. Widely missed. |
| — Directive (EU) 2022/2557 | Directive | Same transposition deadline, same delays. |
| — Regulation (EU) 2022/2554 | Regulation | Applicable since 17 Jan 2025. No transposition patchwork. |
| — Regulation (EU) 2024/2847 | Regulation | In force 10 Dec 2024. Vulnerability reporting from 11 Sep 2026; full application 11 Dec 2027. |
Article 21 sets ten baseline risk-management measures including risk analysis, incident handling, business continuity, supply chain security, cyber hygiene, cryptography policy and multi-factor authentication. Article 23 sets the reporting cascade: early warning within 24 hours, incident notification within 72 hours, final report within one month. Article 20 is the provision that changes behaviour: management bodies must approve and oversee the risk-management measures and can be held liable for the entity's infringements (Art. 20(1)); for essential entities, Article 32(6) additionally requires that the natural persons responsible can be held liable for breaching their duties. For essential entities, Member States must set maximum fines of at least EUR 10 million or 2% of global turnover.
The simplification turn: the Digital Omnibus and what it reveals
Two tracks · the regulators' pushback · the Council stall · the Omnibus as diagnostic
On 19 November 2025 the Commission published the Digital Omnibus. It is the most significant development in this field since the GDPR, not because of its content but because of what it concedes: that the rulebook the Union spent six years building is sufficiently burdensome and internally inconsistent that it requires structural repair before it has finished arriving.
The two tracks, and their very different fates
The package split immediately. The AI Omnibus (COM(2025) 836) was separated because the August 2026 AI Act deadlines were imminent; it entered into force on 27 July 2026. The Data Omnibus (COM(2025) 837) — carrying the GDPR, ePrivacy, Data Act, DGA and amendments — has not. It remains before the Council. The Commission's four principal GDPR reforms were: an entity-relative test for personal data in Article 4(1); a new Article 41a empowering the Commission to set, by implementing acts, the means and criteria for determining when pseudonymised data ceases to be personal data; relocation of cookie consent into a new Article 88a GDPR; and a new Article 88c providing an explicit legitimate-interest basis for AI model training.
The regulators pushed back, hard
The EDPB and EDPS adopted Joint Opinion 1/2026 on the AI Omnibus and Joint Opinion 2/2026 on the Data Omnibus. They supported the simplification objectives generally, but on the core of the Data Omnibus (Joint Opinion 2/2026) they were unambiguous: the personal-data definition change goes far beyond a targeted modification and would significantly narrow the concept; the Article 41a implementing-act power should not be entrusted to the Commission; Article 88c is unnecessary because existing EDPB opinion already confirmed legitimate interest can serve as a basis for AI development. The Council's response has moved in both directions. By May 2026 successive Cypriot Presidency compromise texts had deleted three of the Commission's four principal GDPR reforms, and in late June the Presidency withdrew its text from COREPER when it lacked a qualified majority. The Irish Presidency's revised compromise of 3 September 2026 (ST 12535/26, a restricted document published by noyb) then restored an AI legitimate-interest clause as a new Article 88 bis — without the Commission's safeguards, including the unconditional right to object — moved the treatment of pseudonymised data into a new Article 25a modelled on EDPS v SRB, and returned cookie consent to the ePrivacy Directive. As of 25 September 2026 the Council has no mandate and trilogues have not begun.
Synthesis: six structural tensions, and how to read the system
The analytical takeaways worth retaining
Read as a whole rather than as seven separate compliance projects, the European digital framework exhibits six tensions that explain most of what happens next.
1. The capacity-ambition gap is the master variable
Every instrument here promises more supervision than its supervisor can deliver. Expect enforcement to remain selective, slow and concentrated on a small number of very large firms.
2. Announced enforcement and delivered enforcement are different quantities
Roughly 40% of announced GDPR fine value is annulled or contested; the Irish DPC has collected on the order of EUR 20 million against more than EUR 4 billion levied. When you read a headline number, ask three questions: is it final, is it collected, and did the conduct change? The third often answers yes when the first two answer no. Behavioural change is the real output. Revenue is not.
3. Vagueness is delegation, and delegation moves power to the executive
Systemic risk, high-impact capabilities, effective interoperability, genuinely equivalent alternative — the operative standards of this rulebook are almost all open-textured. The effective content of the law is set by Commission guidelines, delegated acts, codes of practice and harmonised standards, rather than by the legislature.
4. Overlap is deliberate, and its cost is borne by the compliant
A single recommender system can simultaneously engage GDPR Articles 6, 22 and 35, DSA Articles 27, 34, 35 and 38, AI Act transparency duties, and DMA Article 5(2) if the operator is a gatekeeper. The rational compliance strategy is to build one control set mapped to several regimes.
Loading the recorded interactions…
5. The rulebook is now a foreign-policy object
Every designated gatekeeper undertaking and nearly every is non-European. This shapes the timing of decisions, the choice between fines and commitments, and the political viability of expanding scope.
6. The pendulum has swung, and it will swing again
2016-2024 was the accumulation phase. 2025-2027 is the consolidation phase. But consolidation is contested from within: the Council has yet to agree a mandate on the Commission's own GDPR reforms, while the co-legislators used the AI Omnibus to add new prohibitions even as they delayed the high-risk tier. Simplification and expansion are happening in the same instrument.
Innovation and the future: can Europe regulate and build at the same time?
The Draghi diagnosis · the Tech Sovereignty Package · what Europe should actually do
Everything in Parts I to IX describes a Union that legislates well and produces little. That is now the official diagnosis, not a critique from outside.
The diagnosis: what Draghi actually said
Mario Draghi's The Future of European Competitiveness (September 2024) is the hinge document of this period. Draghi is explicit that the EU-US productivity divergence is largely explained by the tech sector. Around 70% of foundational AI models have been developed in the US since 2017, and three US hyperscalers account for over 65% of the global and European cloud market — the largest European operator holds just 2% of the EU market, and European providers' combined share of it had fallen below 16% by 2021. Draghi's blunt assessment was that the bloc has lost the cloud market. But he identified segments where European firms retain a credible position — autonomous robotics at roughly 22% of worldwide activity, AI services at around 17% — and argued the decisive play is vertical integration of AI into European industrial strengths: pharmaceuticals, energy, automotive. Crucially, Draghi named the rulebook itself as part of the problem: a complex web of overlapping rules producing an innovation gap.
The response: the Tech Sovereignty Package
On 3 June 2026 the Commission published the European Technological Sovereignty Package — positioning von der Leyen's second Commission as pivoting from regulatory superpower to production powerhouse. Its centrepiece, the Cloud and AI Development Act, rests on a dual legal basis: Article 114 TFEU (internal market) and Article 173(3) TFEU (industrial competitiveness) — the same pairing on which the Chips Act (Regulation (EU) 2023/1781) already rests.
What the evidence suggests Europe should actually do
1. Fix the physical layer first — permitting, grid connection and time-to-energise are the measurable European disadvantage and are entirely within European policy control.
2. Prioritise adoption over creation — Europe is unlikely to win the foundation-model race; it can plausibly win productivity by integrating existing models vertically into industries where it already leads.
3. Solve scale-up capital, not seed capital — the recurring failure mode is European firms founding successfully and then failing to scale.
4. Make sovereignty risk-assessed rather than declarative — identify which specific sovereignty threats to prioritise, quantify likelihood and consequence.
5. Reduce cumulative burden through architecture, not exemptions — the Omnibus's failure so far suggests substantive carve-outs without institutional reform achieve little.
Assessment: does the EU do what it claims — and does it restrain the state?
A scorecard against its own claims · the competence ceiling · the Hungary test · the counterweights
Two questions, deliberately kept apart because they have different answers. First: measured against its own stated objectives, is the rulebook working? Second: does this body of law constrain state power over citizens, or build the infrastructure for it?
Part one: a scorecard against the EU's own claims
The pattern is consistent: the EU is very good at defining obligations and establishing norms that travel internationally, moderately good at forcing behavioural change in large firms, and poor at timely, final, collectible enforcement. It systematically over-promises on speed and under-resources supervision. That is a real critique, but it is a critique of execution, not of sincerity — there is no serious evidence that the stated objectives are pretextual.
Part two: the vertical question — companies versus states
Here the picture changes sharply. Almost every instrument in this brief regulates private power. The constraints on public power are thinner, and thinnest exactly where the stakes are highest. Article 4(2) TEU reserves national security to the Member States, and the AI Act does not apply to AI systems placed on the market, put into service or used exclusively for military, defence or national security purposes (Art. 2(3)). The Court of Justice has, however, refused to let a national-security purpose take outside EU law national legislation requiring providers to forward communications data to intelligence agencies (Privacy International, C-623/17), which limits how far the carve-out can stretch. CDT's analysis identifies the specific danger: the AI Act defines law enforcement broadly enough to overlap with national security, so an authority can potentially escape the real-time biometric identification restrictions simply by invoking national security.
The counterweights are real, and should not be discounted
The Charter of Fundamental Rights binds Member States when implementing EU law, and the CJEU has repeatedly used it against surveillance measures — most consistently in the data retention line running from Digital Rights Ireland through Tele2 to La Quadrature du Net. The Article 5 prohibitions bind public authorities too: social scoring by government, predictive policing based solely on profiling, and emotion recognition in workplaces and schools are prohibited outright, for states as well as firms — few comparable jurisdictions have enacted a binding list of this breadth. Independent supervision is structurally entrenched: the EDPS supervises the EU institutions themselves and has publicly opposed the Commission's own legislative proposals. And the European Parliament has been the most consistent institutional defender of privacy across this period.
Compliance calendar: what lands when
| Date | Instrument | Event |
|---|---|---|
| 11 Sep 2026 | Reporting of actively exploited vulnerabilities and serious incidents begins. | |
| 12 Sep 2026 | Data Act | Article 3(1) design obligation — connected products must make data accessible by default. |
| Nov 2026 | DMA | Commission's target for concluding the AWS and Azure gatekeeper investigations. |
| 2 Dec 2026 | AI Act | New Art. 5 prohibitions (AI-generated non-consensual intimate imagery and CSAM) apply; end of the transition for Art. 50(2) marking by systems already on the market before 2 August 2026. |
| 9 Dec 2026 | Product Liability Directive | Revised PLD applies — software and AI within strict product liability. |
| 12 Jan 2027 | Data Act | All cloud switching charges prohibited. |
| 2 Apr 2027 | GDPR procedural regulation | Regulation (EU) 2025/2518 applies to cross-border complaints lodged from this date. |
| May 2027 | DMA | Commission's target for the final report of the cloud market investigation. |
| 12 Sep 2027 | Data Act | Chapter IV unfair-terms rules extend to pre-existing long-term B2B contracts. |
| 2 Dec 2027 | AI Act | Annex III stand-alone high-risk systems. |
| 11 Dec 2027 | Full application. | |
| 2 Aug 2028 | AI Act | Annex I product-embedded high-risk systems. |
A note on method
Figures for cumulative fine totals differ materially by source and methodology — the CMS Enforcement Tracker Report and enforcementtracker.com produce different counts and totals for the same period, and two large September 2025 French decisions (Google EUR 325m, Shein EUR 150m) are frequently miscounted as GDPR fines when they were issued under the French ePrivacy regime rather than through the . Where this brief cites a total, it cites the most widely reported figure and flags the uncertainty. Enforcement figures in a fast-moving field should be treated as indicative of magnitude, not as audited accounts.
The URLs in the original source document were checked on 19 August 2026; the site’s own records carry their own verification dates, shown in each “Why this claim?” evidence drawer. Primary legal texts should be consulted in their consolidated versions on EUR-Lex.
Method, and the use of AI in building this
The research, the conceptual framework, the structure and the analysis in this project were conceived and carried out by the author. Artificial-intelligence tools were used in parts of the work, and this note records where and on what terms, because a reader entitled to ask where a claim comes from is equally entitled to ask how the thing making the claim was built.
The choice was deliberate rather than expedient. AI is treated here not as a way of doing the same work faster, and not as a substitute for thinking, but as augmentation: a means of iterating, refining and implementing, and of holding clarity and consistency across a document that would otherwise drift. The value of that arrangement does not lie in an output generated on its own. It lies in the exchange between human judgement and computational assistance. Setting the objectives, framing the questions, assessing what came back and deciding what stands are human responsibilities, and they were not delegated.
On the writing. AI-assisted tools — specifically Claude Opus 5 and ChatGPT 5.5 — supported the review and refinement of written content, and its translation and adaptation into formal English.
On the code. The site was built through a vibecoding approach, with Claude Opus 5 assisting in the production and iterative development of the JavaScript, CSS and HTML. Substantial parts of the coding were delegated to the model. The direction was not. The objectives, the information architecture, the content structure, the functional requirements, the creative direction and the assessment of what was actually produced remained the author's.
On research tooling. The repository also contains an experimental multi-agent pipeline (a weekly Source Scout, a verifier, an orchestrator and a private control plane) designed to surface candidate sources and propose changes for human review. As of 26 September 2026, no content on this site has been added or changed through that pipeline: every change to the text and the data was made in editing sessions directed by the author, in the way described above. Candidates the pipeline surfaces are not sources until a human has read them.
AI was therefore an implementation layer inside a human-directed process, not an autonomous author of it. The code may be AI-assisted; the purpose, the structure, the content, the research logic and the creative direction were defined independently and supervised throughout.
Every AI-assisted output was reviewed and checked afterwards for accuracy, internal consistency, functional coherence and agreement with what the project is actually trying to say. The distinctions this brief insists on elsewhere — that entry into force is not application, that an announced fine is not a collected one, that unknown is not zero — are the same distinctions applied to its own making: assistance is not authorship, and delegation is not abdication.
On the mechanics/critique labelling: the source PDF uses green shaded boxes for mechanics and orange for critique. This edition preserves that distinction as an interactive reading lens, reconstructed from each box's own title and content — the plain-text extraction used to build this site carries no colour metadata, so treat the mechanics/critique split as this site's own classification, not literal data pulled from the PDF.