Europe · Digital regulation
Europe's digital rule book: how eight new laws are reshaping data, AI and platforms
From the AI Act to the reformed Product Liability Directive, the EU has built the most comprehensive digital regulation package in any major jurisdiction. Here is what is in force, what is coming, and where the fights now are.
The European Union now has, in force or coming into force, at least eight major laws governing how digital products are built, how data flows, and how platforms operate within its single market. The package, much of it built under the European Commission's 2020 Strategy for Data and its successor digital initiatives, represents the most ambitious attempt by any major regulatory power to write a comprehensive rule book for the digital economy. The laws touch everything from the training of artificial intelligence models to the cybersecurity of a connected thermostat, from the data a smart fridge generates to the way a smartphone operating system ranks competing apps.
Each statute addresses a different layer of the digital stack, and they are designed to interlock. The result, once fully applied, is a regulatory environment in which a single product launch may require compliance with at least five different regimes at once. That ambition is also the package's biggest political vulnerability: the same companies that once pressed for clear rules now complain about cumulative cost, and Brussels's trading partners regard the architecture as a form of regulatory export.
A rule book for the entire stack
The legislation falls into roughly three groups, with a cross-cutting cybersecurity and liability layer beneath them. Three laws regulate products and the systems that produce them: the AI Act, the Cyber Resilience Act, and the reformed Product Liability Directive. Two laws govern data: the Data Act and the Data Governance Act. Two further laws address platform behaviour: the Digital Markets Act and the Digital Services Act. Underpinning all of it is the NIS2 Directive, the second iteration of the EU's cybersecurity baseline, which has expanded the scope of mandatory security and incident reporting obligations to cover most medium and large companies in critical sectors.
The architecture reflects an attempt by Brussels to legislate for the entire digital stack, from hardware to algorithm, rather than sector by sector. That is a significant departure from the approach taken in the early 2010s, when EU digital policy consisted largely of the General Data Protection Regulation, the ePrivacy framework and a handful of sector-specific rules. The new laws explicitly build on GDPR, which remains the foundation for personal data protection and is not formally part of the post-2020 strategy.
AI and the safety of connected products
The AI Act is the centrepiece in political terms, though not yet in operational terms. It entered into force in August 2024, but its provisions phase in over a two-year period. Prohibitions on the most harmful uses, including social scoring by public authorities and untargeted scraping of facial images from the internet, began applying in February 2025. Obligations for general-purpose AI providers and for high-risk systems will apply from August 2026. Penalties for breaches of the prohibited practices can reach 35 million euro or 7% of global annual turnover, whichever is higher. The Act creates a European Artificial Intelligence Board, housed within the Commission, to coordinate national regulators and advise on implementation.
The Cyber Resilience Act, by contrast, focuses on the mundane but enormous universe of connected products. From December 2027, manufacturers of any product with digital elements sold in the EU, from routers to baby monitors, will have to assess cybersecurity risks throughout the product lifecycle, maintain a vulnerability handling process, and provide a software bill of materials. The Commission has estimated that the number of affected products runs into the hundreds of millions each year. The Act complements rather than replaces NIS2, which covers organisations rather than products, and member states are still finalising conformity assessment procedures.
Who owns the data machines generate
The Data Act and the Data Governance Act represent Brussels's attempt to treat data as a resource that should be shared more widely, rather than hoarded by the manufacturers of connected devices or held behind proprietary interfaces. The Data Act, which becomes applicable in September 2025, gives users rights over data generated by their connected products, requires interoperability for cloud switching, and prohibits certain unfair contractual terms imposed by cloud providers on their customers. The Data Governance Act, in force since September 2023, established a supervisory framework for so-called data intermediation services, set up a single EU-wide register for the reuse of public sector data, and created a framework for organisations that collect and share data for altruistic purposes.
The economic logic behind both laws is that European industry is data-rich but data-poor in usable form. Industrial machines, vehicles and consumer devices generate vast quantities of telemetry, but most of it is held by the manufacturer or the platform operator. Whether the new rights translate into a genuine market for business-to-business data sharing remains untested. The Commission has been monitoring uptake closely, and a first review of the Data Governance Act was completed in 2024, with mixed findings on user awareness.
Reining in the gatekeepers
The Digital Markets Act and the Digital Services Act are the most operational of the package, in the sense that they have moved furthest from paper into enforcement. The DMA, which became fully applicable in March 2024, designates the largest platforms as gatekeepers and imposes a list of do's and don'ts covering self-preferencing, app store rules, default settings and interoperability. The European Commission has so far designated seven gatekeepers: Alphabet, Amazon, Apple, Booking Holdings, ByteDance, Meta and Microsoft, covering 22 core platform services. Several gatekeepers have been hit with preliminary findings of non-compliance, and a number of them have challenged their designation in the General Court of the European Union.
The Digital Services Act, applicable in full to the largest platforms since August 2023, focuses on content moderation transparency, illegal content removal procedures, and risk assessments for systemic risks such as the dissemination of illegal content or the intentional manipulation of platforms. National regulators handle enforcement against smaller intermediaries; the Commission handles the largest, including X, Meta's Facebook and Instagram, TikTok and others. Fines under the DSA can reach 6% of global turnover, and under the DMA 10%, with separate procedures for non-compliance with interim measures.
Liability, cybersecurity and the cumulative burden
NIS2, the update to the original Network and Information Security Directive, expanded its scope from a narrow set of critical infrastructure operators to roughly 160,000 entities across 18 sectors, including energy, transport, health, digital services, public administration and manufacturing of certain critical products. Member states were required to transpose the directive into national law by October 2024, though several, including Germany, Italy and Portugal, missed the deadline. The directive introduces personal accountability for senior managers of essential entities and tightens the timeline for incident reporting to 24 hours for an early warning and 72 hours for an initial assessment.
The reformed Product Liability Directive, adopted in 2024 and due for transposition by the end of 2026, extends the strict liability regime that has governed physical products in the EU for forty years to software, AI systems and digital services. It treats software explicitly as a product, clarifies how damage caused by AI can be attributed between manufacturer, developer and operator, and lowers the threshold of proof for claimants.
The combined effect, if the package is implemented as intended, is that a company placing a connected, AI-enabled product on the EU market from 2027 onwards will need to comply with product cybersecurity rules on the hardware, AI rules on the system, data access rights for the user, content rules on any platform functionality, baseline cybersecurity for the organisation, and a clarified liability regime for harm. Few companies, particularly mid-cap manufacturers and software vendors, have built their compliance functions with all of this in mind.
What comes next
Two pressures are likely to shape the next phase. The first is enforcement. The Commission has signalled that gatekeeper compliance under the DMA will be a priority, and AI Act enforcement begins in earnest in 2026. Several member states have warned that they lack the resources to supervise smaller actors under NIS2 and the AI Act simultaneously, and the Commission has proposed a technical support facility to help. A second pressure is external. The Trump administration has criticised the DMA, the DSA and the AI Act as discriminatory against American companies, and the outcome of the EU-US trade negotiations will determine whether the package becomes a flashpoint or a template adopted abroad.
A third, quieter pressure is internal. European industry has begun to ask for consolidation rather than additional rules, and the Commission's own regulatory fitness agenda has flagged the cumulative compliance burden. Calls for a horizontal simplification law, similar in spirit to past omnibus measures in agriculture and cohesion policy, are growing louder, particularly from Germany's Mittelstand and from the French and Italian governments. The Commission's first omnibus simplification proposal for digital rules is expected before the end of 2025, with NIS2 reporting obligations the most likely target.
For the moment, the EU is alone in having all of this in force at once. China's data laws, while extensive, are organised around national security and information control rather than market access. The United States has sectoral privacy rules at state level and a federal AI executive order, but no horizontal data act, no platform contestability law, and no general product cybersecurity statute. Whether the European model proves durable will depend on whether the package is enforced as written, whether companies find it workable in practice, and whether other jurisdictions choose to converge.
Sources
Organisations
European Commission · European Union · European Artificial Intelligence Board