This week’s regulatory update covers key developments in privacy, AI regulation, digital markets, and cybersecurity.

This regulatory update highlights several important developments across privacy, AI regulation, digital markets, and cybersecurity, including new regulatory actions, policy changes, and emerging compliance priorities.

EU

GDPR

The EDPB and the EU’s new Anti-Money Laundering Authority (AMLA) announced plans to jointly develop guidelines on information sharing between AML-obliged entities and authorities. The guidance will clarify how Article 75 of the AML Regulation applies alongside the GDPR. A public consultation on the draft guidelines is planned for the first half of 2027.

Read More

AI Act

The Council of the EU formally adopted the Digital Omnibus on AI on 29 June, giving final approval to the package previously approved by Parliament on 16 June (423–57). High-risk AI obligations under Annex III are deferred to 2 December 2027, while obligations under Annex I are deferred to 2 August 2028. Watermarking requirements and the new CSAM/nudifier ban apply from 2 December 2026. GPAI and Article 50 transparency obligations remain on the original schedule.

Read More

DMA

The European Commission held a stakeholder roundtable on 1 July concerning cloud computing services as part of its DMA market investigation. The discussion covered interoperability, financial conditions, and contractual terms between cloud providers and customers. A final investigation report is expected by May.

Read More

Sweden

NIS2

NCSC formally assumed responsibility for all NIS2/cybersäkerhetslagen regulatory activities from MCF on 1 July. This includes regulations, guidance, incident reporting, and supervisory coordination. From this date, all NIS2 entity registrations and incident reports are submitted directly to NCSC through CERT-SE and the national cyber portal.

Read More

Continue reading
Need help?
Contact Us