Regulatory changelog

What changed in EU digital regulation

A dated, sourced log of EU digital regulation — the AI Act, GDPR, NIS2, DORA, the Data Act, the Cyber Resilience Act and the DSA — covering law, guidance, enforcement and case-law. Every entry links to its primary source.

Coverage last updated 3 Aug 2026 · 26 changes tracked
AI Act3 Aug 2026Art. 53, Art. 55

Fourth GPAI Signatory Taskforce meeting

Automatically summarised from the primary source — not yet editorially verified. Read the primary source ↗
Detected guidance relating to AI Act: “Fourth GPAI Signatory Taskforce meeting”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
AI Act31 Jul 2026Art. 50

Commission starts enforcing AI Act rules and new transparency requirements on 2 August

European Commission communication marking the start of enforcement of the AI Act from 2 August 2026 — including the Article 50 transparency obligations for chatbots and AI-generated content and the general-purpose AI (GPAI) obligations. See the primary source for scope and detail.
What to do: If you operate chatbots, generate AI content or provide/deploy general-purpose AI, confirm your Article 50 transparency measures and GPAI obligations are in place — they now apply.
AI Act31 Jul 2026Art. 50(2), Art. 50(4)

Strong backing for the Code of Practice on Transparency of AI-generated Content

European Commission announcement of strong stakeholder backing for the Code of Practice on the transparency of AI-generated content, which supports the Article 50 marking and disclosure obligations. See the primary source for detail.
What to do: If you generate or deploy AI-generated content, review the Code of Practice as a route to demonstrate compliance with the Article 50 transparency duties.
GDPR27 Jul 2026Art. 2, Art. 5, Art. 6, Art. 9, Art. 10

Judgment of the Court (Grand Chamber) of 14 July 2026. — AR and Others v Österreichische Datenschutzbehörde…

Court of Justice (Grand Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): material scope (Article 2), the principles relating to processing and its lawfulness (Articles 5 and 6), the concept of data concerning health (Article 9) and personal data relating to criminal convictions (Article 10). See the primary source for the Court's operative findings.
What to do: If you process health data or data on criminal convictions under the GDPR, read this ruling against your lawful-basis and special-category analysis and record whether any change is needed.
GDPR27 Jul 2026

Judgment of the Court (Fifth Chamber) of 9 July 2026. — ND v Legal Newsdesk Sweden AB, anciennement…

Court of Justice (Fifth Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): its scope where information on criminal convictions is made available to the public online in return for remuneration, and reconciling the right to protection of personal data with the right to freedom of expression and information. See the primary source for the Court's operative findings.
What to do: If your service publishes personal data, including data on criminal convictions, weigh this ruling against your data-protection and freedom-of-expression balancing and record whether any change is needed.
Digital Services Act24 Jul 2026

Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for…

Preliminary finding by the European Commission that TikTok breaches the Digital Services Act by failing to ensure safe accounts for minors. This is a preliminary finding, not a final decision; TikTok can respond before the Commission concludes. See the primary source for details.
What to do: If you operate an online platform under the DSA, note this enforcement direction on the safety of minors and review your own measures.
GDPR23 Jul 2026

EDPB calls for legal basis for cross-regulatory information sharing

Detected guidance relating to GDPR: “EDPB calls for legal basis for cross-regulatory information sharing”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your personal-data processing and record the source in your compliance dossier.
Source: EDPB ↗
AI Act21 Jul 2026

Commission Implementing Regulation (EU) 2026/1755 of 20 July 2026 on detailed arrangements for the conduct of…

Commission Implementing Regulation (EU) 2026/1755 sets detailed procedural arrangements for how the Commission conducts certain proceedings under the AI Act (Regulation (EU) 2024/1689). Published in the Official Journal.
What to do: Relevant if the Commission may open proceedings on your AI systems. Note the procedural rules and review the primary source.
AI Act20 Jul 2026Art. 50

Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems

Detected guidance relating to ai act: “Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Source: European Commission ↗ · v20 Jul 2026
Digital Services Act20 Jul 2026

Commission fines AliExpress €550 million for breaching the Digital Services Act

Detected enforcement relating to Digital Services Act: “Commission fines AliExpress €550 million for breaching the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: No direct compliance change follows from this enforcement action against a platform. Review it for DSA enforcement context and note any implications relevant to your services.
Source: European Commission ↗ · v20 Jul 2026
GDPR17 Jul 2026Art. 6, Art. 9(2)

EDPB: how the GDPR applies to web scraping and anonymisation for generative AI

On 8 July 2026 the EDPB published guidance on when data counts as anonymous and how the GDPR applies to web scraping used to train generative AI. Data is anonymous only if individuals cannot be singled out, linked across records, or inferred - and that assessment can differ per recipient. Scraping personal data must respect purpose limitation, transparency, accuracy and data minimisation, and special-category data still needs both an Article 6 lawful basis and an Article 9(2) exception. The anonymisation and web-scraping guidelines are open for public consultation until 30 October 2026 and may still change; the accompanying blockchain guidelines were adopted in final form.
What to do: If you train or fine-tune generative AI on scraped or web-sourced data, document the Article 6 lawful basis and confirm no special-category data is used without an Article 9(2) exception. Re-test any data you treat as anonymised against the singling-out, linkability and inference criteria. Keep records of purpose limitation, source reliability (timestamps), accuracy validation and data-minimisation measures for your scraping pipeline.
Source: EDPB ↗
NIS29 Jul 2026

Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose…

An enforcement action related to NIS2/cybersecurity regulation: “Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity”. See the primary source for the authoritative text.
What to do: No direct action for your own systems — this is an enforcement step against a Member State, not a new obligation. Note it for awareness only.
NIS29 Jul 2026

Supporting NIS2 implementation through actionable guidance

ENISA published NIS2 implementation guidance: NIS2 Technical Implementation Guidance plus a companion on cybersecurity roles and skills for essential and important entities.
What to do: If you are an essential or important entity under NIS2, use this guidance to shape your implementation. Review the primary source.
Source: ENISA ↗
AI Act9 Jul 2026Art. 50(2), Art. 50(4)

Commission publishes Code of Practice on marking and labelling AI-generated content

The Commission published a Code of Practice on marking and labelling AI-generated content. It supports the Article 50 transparency obligations: machine-readable marking and detectability of synthetic content by providers (Art. 50(2)) and disclosure/labelling of AI-generated or manipulated content by deployers (Art. 50(4)).
What to do: If you provide or deploy generative AI, review this Code against your Article 50(2) marking duty (providers) and your Article 50(4) disclosure duty (deployers) and record how you meet them.
AI Act2 Feb 2025

Prohibition (no formal case yet)

The ban on AI emotion recognition in the workplace and education applies since 2 February 2025 (Art. 5 AI Act). Enforcement is still nascent — no major formal case yet. Fines for prohibited practices are the highest in the regulation.
What to do: Confirm no system implements an Art. 5 prohibited practice; the penalty ceiling is up to EUR 35 million or 7 percent of worldwide turnover.
Source: EC / national authorities ↗ · v2 Feb 2025
ECHR / fundamental rights5 Feb 2020

SyRI (Nederlandse staat)

The SyRI welfare-fraud risk system breaches Article 8 ECHR: insufficiently transparent and not proportionate. Use prohibited.
What to do: If you run automated risk-profiling on individuals, test it against fundamental-rights safeguards (proportionality, transparency); the court struck down SyRI for lacking them.
Source: District Court of The Hague ↗ · v5 Feb 2020
GDPR1 Dec 2021

Belastingdienst

Years of unlawful and discriminatory processing of applicants' (dual) nationality for childcare benefits; nationality wrongly used as a risk indicator.
What to do: Review automated profiling for unlawful or discriminatory use of personal data; ensure necessity, proportionality and a clear lawful basis.
Source: Dutch DPA (AP) ↗ · v1 Dec 2021
GDPR3 Sep 2024

Clearview AI

Unlawful database of billions of facial images scraped from the internet for facial recognition, without a valid legal basis; processing of biometric personal data.
What to do: Do not use facial-recognition data obtained by untargeted scraping; where you process biometric data, confirm a valid basis and carry out a DPIA.
Source: Dutch DPA (AP) ↗ · v3 Sep 2024
GDPR20 Dec 2024

OpenAI (ChatGPT)

ChatGPT trained on personal data without a valid legal basis, breach of transparency duties, failure to report a data breach (March 2023) and missing age verification.
What to do: If you process personal data through a generative-AI service, verify your lawful basis, your transparency notice to users, and any age checks.
Source: Garante (IT) ↗ · v20 Dec 2024
AI Act19 Nov 2025Art. 6, Annex III

Digital Omnibus — high-risk deferral

Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. The binding high-risk application dates are 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
What to do: Re-baseline affected systems and contracts against Regulation (EU) 2026/1744, keep non-high-risk workstreams on their applicable dates, and preserve the decision trail from before entry into force.
Source: European Union ↗ · v19 Nov 2025
AI Act10 Jul 2025art. 53, art. 55

GPAI Code of Practice

Voluntary code of practice for providers of general-purpose AI models (Art. 53/55), with three chapters: transparency, copyright and safety/security. Signatories (incl. Anthropic, Google, Microsoft, OpenAI, IBM) use it to demonstrate compliance; Meta did not sign.
What to do: If you build on a general-purpose AI model, obtain and keep the provider transparency and copyright information you rely on (Art. 53), and check whether your provider signed the Code.
Source: AI Office / European Commission ↗ · v10 Jul 2025
AI Act4 Feb 2025art. 5

Guidelines on prohibited AI practices

The Commission's official guidance on the prohibited practices (Art. 5): manipulation, exploitation of vulnerabilities, social scoring, untargeted facial scraping, emotion recognition at work/education, biometric categorisation and certain real-time biometric identification. Non-binding; the CJEU has the final say.
What to do: Check that none of your AI systems fall under the Art. 5 prohibitions (e.g. social scoring, untargeted facial scraping, emotion recognition at work or school); record that assessment.
Source: European Commission ↗ · v4 Feb 2025