2026 is a watershed year for EU technology regulation. Several major regulations are entering full application, compliance deadlines are arriving, and a new generation of frameworks is beginning to shape the longer-term landscape. This article summarises the key developments for technology companies and growing businesses operating in or selling into the EU.
Already In Force: Full Application in 2026
EU AI Act — High-Risk AI (August 2026)
The EU AI Act's most demanding requirements — those applying to high-risk AI systems — enter full application in August 2026. This is the final phase of the AI Act timeline:
- February 2025: Prohibited AI provisions (Article 5)
- August 2025: GPAI model obligations
- August 2026: Full high-risk AI requirements
What applies from August 2026:
- High-risk AI systems in Annex III categories must have completed technical documentation (Annex IV)
- Conformity assessment must be completed before deployment
- EU AI database registration required for providers
- Post-market monitoring systems must be operational
- Deployers of high-risk AI must have fundamental rights impact assessments where required
- Human oversight mechanisms must be in place
For companies that have not started their AI Act compliance programme: August 2026 is not far away.
NIS2 — Enforcement Ramping Up
NIS2 entered application in October 2024 when member states were required to have transposed it. In 2026:
- Most member states will have fully operational NIS2 competent authorities
- Enforcement activities are ramping up — expect more incident investigations and compliance checks
- NIS2 incident reporting statistics are being aggregated at EU level (ENISA)
- Supply chain security assessments are being developed (Member State competent authorities are conducting risk assessments of specific ICT products and services)
DORA — First Full Reporting Cycle
2025 was the first full year of DORA application (entered force January 2025). In 2026:
- Financial entities' first full Register of Information submissions are due
- ECB and NCAs are conducting DORA-specific supervisory reviews of significant institutions
- TLPT frameworks are fully operational in major EU jurisdictions
- Enforcement actions for DORA non-compliance are expected to begin
CSRD Wave 2 — First Reports
Wave 2 companies (large companies, 250+ employees, €40M+ turnover) file their first CSRD reports in 2026 covering financial year 2025. This is the first year that thousands of non-PIE companies must publish ESRS-aligned sustainability reports with limited assurance.
New Developments in 2026
EU Artificial Intelligence Liability Directive (AI Liability)
The AI Liability Directive creates a civil liability framework for AI-related harm. Key provisions:
- Disclosure of evidence: Courts can order AI providers and users to disclose documentation for liability proceedings
- Presumption of causality: If a claimant can establish fault and a plausible causal link between the fault and the damage, causality is presumed — reducing the burden of proof for AI harm victims
- Interaction with Product Liability Directive: Products containing AI (IoT devices, vehicles) that cause harm face both the AI Liability Directive and the revised Product Liability Directive
For AI providers and deployers: document your safety measures and compliance. The liability framework makes non-compliance directly costly.
EU Cyber Resilience Act (CRA) — Coming Into Application
The EU Cyber Resilience Act — covering security requirements for products with digital elements — enters application in late 2027 (24 months after entry into force). In 2026:
- Manufacturers of connected products begin compliance preparation
- Interaction with the Data Act and NIS2 supply chain requirements creates a compound obligation for IoT manufacturers
CSDDD — First Large-Company Applications
The Corporate Sustainability Due Diligence Directive (CSDDD) enters application for the largest companies (1,000+ employees, €450M+ global turnover) from mid-2027. Compliance programmes should be in preparation in 2026.
Key Deadlines Calendar for 2026
| Date | Deadline |
|---|---|
| Q1 2026 | DORA Register of Information first submission |
| Q2 2026 | CSRD Wave 2: first sustainability report published |
| August 2026 | EU AI Act: high-risk AI full application |
| Ongoing 2026 | NIS2 enforcement activities ramping up |
| Q4 2026 | CSDDD compliance preparation underway for largest companies |
What Has Not Changed in 2026
GDPR is still the foundational framework. Enforcement is not declining — it is increasing. The EDPB continues to issue significant cross-border decisions, and national DPAs are maintaining active enforcement calendars.
The Data Act is in its first year of application (from September 2025). 2026 will see the first data access requests, the first challenges to contractual lock-in provisions, and the beginning of enforcement framework development.
UK GDPR and Swiss FADP remain separate frameworks. Companies with UK and Swiss operations must maintain separate compliance for each — neither is subsumed by EU GDPR.
The Medium-Term Outlook (2027–2028)
September 2027: Data Act egress fee elimination (cloud providers must eliminate switching egress fees entirely).
Late 2027: EU Cyber Resilience Act applies — digital product security requirements.
From 2027: CSDDD applies to large companies; supply chain due diligence becomes mandatory.
2028: CSRD Wave 4 — non-EU companies with €150M+ EU turnover and large EU presence must file CSRD reports.
The trajectory is clear: EU regulatory requirements for technology companies will continue to expand. Building a scalable compliance programme now — rather than reacting to each deadline — is the more efficient strategy.