Skip to content
EU Compliance

The EU Regulatory Landscape in 2026: What's New

5 min readUpdated 4 November 2026

2026 is a watershed year for EU technology regulation. Several major regulations are entering full application, compliance deadlines are arriving, and a new generation of frameworks is beginning to shape the longer-term landscape. This article summarises the key developments for technology companies and growing businesses operating in or selling into the EU.


Already In Force: Full Application in 2026

EU AI Act — High-Risk AI (August 2026)

The EU AI Act's most demanding requirements — those applying to high-risk AI systems — enter full application in August 2026. This is the final phase of the AI Act timeline:

  • February 2025: Prohibited AI provisions (Article 5)
  • August 2025: GPAI model obligations
  • August 2026: Full high-risk AI requirements

What applies from August 2026:

  • High-risk AI systems in Annex III categories must have completed technical documentation (Annex IV)
  • Conformity assessment must be completed before deployment
  • EU AI database registration required for providers
  • Post-market monitoring systems must be operational
  • Deployers of high-risk AI must have fundamental rights impact assessments where required
  • Human oversight mechanisms must be in place

For companies that have not started their AI Act compliance programme: August 2026 is not far away.

NIS2 — Enforcement Ramping Up

NIS2 entered application in October 2024 when member states were required to have transposed it. In 2026:

  • Most member states will have fully operational NIS2 competent authorities
  • Enforcement activities are ramping up — expect more incident investigations and compliance checks
  • NIS2 incident reporting statistics are being aggregated at EU level (ENISA)
  • Supply chain security assessments are being developed (Member State competent authorities are conducting risk assessments of specific ICT products and services)

DORA — First Full Reporting Cycle

2025 was the first full year of DORA application (entered force January 2025). In 2026:

  • Financial entities' first full Register of Information submissions are due
  • ECB and NCAs are conducting DORA-specific supervisory reviews of significant institutions
  • TLPT frameworks are fully operational in major EU jurisdictions
  • Enforcement actions for DORA non-compliance are expected to begin

CSRD Wave 2 — First Reports

Wave 2 companies (large companies, 250+ employees, €40M+ turnover) file their first CSRD reports in 2026 covering financial year 2025. This is the first year that thousands of non-PIE companies must publish ESRS-aligned sustainability reports with limited assurance.


New Developments in 2026

EU Artificial Intelligence Liability Directive (AI Liability)

The AI Liability Directive creates a civil liability framework for AI-related harm. Key provisions:

  • Disclosure of evidence: Courts can order AI providers and users to disclose documentation for liability proceedings
  • Presumption of causality: If a claimant can establish fault and a plausible causal link between the fault and the damage, causality is presumed — reducing the burden of proof for AI harm victims
  • Interaction with Product Liability Directive: Products containing AI (IoT devices, vehicles) that cause harm face both the AI Liability Directive and the revised Product Liability Directive

For AI providers and deployers: document your safety measures and compliance. The liability framework makes non-compliance directly costly.

EU Cyber Resilience Act (CRA) — Coming Into Application

The EU Cyber Resilience Act — covering security requirements for products with digital elements — enters application in late 2027 (24 months after entry into force). In 2026:

  • Manufacturers of connected products begin compliance preparation
  • Interaction with the Data Act and NIS2 supply chain requirements creates a compound obligation for IoT manufacturers

CSDDD — First Large-Company Applications

The Corporate Sustainability Due Diligence Directive (CSDDD) enters application for the largest companies (1,000+ employees, €450M+ global turnover) from mid-2027. Compliance programmes should be in preparation in 2026.


Key Deadlines Calendar for 2026

DateDeadline
Q1 2026DORA Register of Information first submission
Q2 2026CSRD Wave 2: first sustainability report published
August 2026EU AI Act: high-risk AI full application
Ongoing 2026NIS2 enforcement activities ramping up
Q4 2026CSDDD compliance preparation underway for largest companies

What Has Not Changed in 2026

GDPR is still the foundational framework. Enforcement is not declining — it is increasing. The EDPB continues to issue significant cross-border decisions, and national DPAs are maintaining active enforcement calendars.

The Data Act is in its first year of application (from September 2025). 2026 will see the first data access requests, the first challenges to contractual lock-in provisions, and the beginning of enforcement framework development.

UK GDPR and Swiss FADP remain separate frameworks. Companies with UK and Swiss operations must maintain separate compliance for each — neither is subsumed by EU GDPR.


The Medium-Term Outlook (2027–2028)

September 2027: Data Act egress fee elimination (cloud providers must eliminate switching egress fees entirely).

Late 2027: EU Cyber Resilience Act applies — digital product security requirements.

From 2027: CSDDD applies to large companies; supply chain due diligence becomes mandatory.

2028: CSRD Wave 4 — non-EU companies with €150M+ EU turnover and large EU presence must file CSRD reports.

The trajectory is clear: EU regulatory requirements for technology companies will continue to expand. Building a scalable compliance programme now — rather than reacting to each deadline — is the more efficient strategy.

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →