EU digital rules widen compliance burden for global companies
The EU’s digital regulatory framework is expanding across AI, data governance and cybersecurity, creating new obligations for companies outside Europe that sell into, operate in or otherwise touch the EU market. The EU AI Act, in force since August 2024, applies to EU-based providers and deployers as well as third-country operators whose AI system output is used in the EU. Key requirements are being phased in through 2027-2028, with companies expected to assess risk categories, transparency duties, human oversight and conformity assessment needs.
Data rules are also changing. The Digital Omnibus package would amend the GDPR and ePrivacy framework by codifying “relative identifiability,” extending data breach notification deadlines from 72 to 96 hours, integrating cookie consent rules into the GDPR and adding a legal basis for AI development under legitimate interests. The EU Data Act, applicable since September 2025, adds access and sharing duties for connected product makers, related service providers and cloud/SaaS providers serving EU customers.
Cybersecurity obligations are tightening under the Cyber Resilience Act and NIS2 Directive. The CRA entered into force in December 2024, with reporting obligations starting in September 2026 and full compliance required by December 2027. Non-compliance can trigger fines of up to EUR 15 million or 2.5% of global annual turnover. International groups are advised to review products, services, contracts, supply chains and local enforcement developments for compliance gaps.