European Union

On May 28, 2026, the European Union Agency for Cybersecurity (“ENISA”) published the third edition of its NIS360 report, an annual benchmarking tool that assesses the cybersecurity maturity of entities in the sectors set out in Annex I of the NIS2 Directive (which includes certain entities in the energy, transport, healthcare, digital

Continue Reading ENISA’s NIS360 2026 report highlights both the criticality of the European space sector, and flags a persistent cybersecurity maturity gap

On 19 May 2026, the European Commission published its long-awaited draft, non-binding guidelines on the classification of high-risk AI systems (“HRAIs”) under the EU AI Act (the “Guidelines”). Across three documents—covering general principles, high-risk classification in the context of regulated products (Annex I), and high-risk use cases (Annex III)—the Commission sets out its approach to one of the AI Act’s central questions: when does an AI system fall within the high-risk regime (and, just as importantly, when does it not)?

Continue Reading EU AI Act Update: The European Commission Publishes Draft Guidelines on HRAIs

On June 3, the European Commission published its Tech Sovereignty Package, a set of legislative and policy initiatives designed to address what the Commission characterizes as Europe’s technological dependencies on non-European suppliers. The Package marks a further step in the evolution of the EU’s technology policy, with initiatives spanning the full tech stack—from chips and infrastructure to software, cloud, and artificial intelligence. Through this “ecosystem” approach, the Commission seeks to reduce supply-side dependencies by strengthening domestic capabilities in Europe and stimulating demand in downstream sectors.

The Package comprises four components: two legislative proposals—(i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0—as well as two non-legislative initiatives—(iii) the EU Open Source Strategy and (iv) a Strategic Roadmap for Digitalisation and AI in Energy.

This blog post provides an initial, high-level overview of the four initiatives through which the Commission seeks to advance a “European way” to tech sovereignty, with potential implications for industrial ecosystems in Europe and beyond, including cloud, telecoms, automotive, aeronautics, and defense sectors.

Continue Reading EU Tech Sovereignty Package

On 27 May 2026, the European Commission (“Commission”) published its proposal for a Regulation on the authorisation of systems providing mobile satellite services (“MSSs”) in the harmonised 2 GHz frequency band (1980–2010 MHz and 2170–2200 MHz) (the “MSS Regulation Proposal”). The existing rights of use in the band are due to expire in May 2027, and the Commission is using that deadline to overhaul the framework for granting spectrum authorisations for MSS provides. This Proposal will therefore be of particular interest to MSS providers wishing to expand their footprint in the EU, as well as terrestrial mobile network operators contemplating satellite partnerships, and other space sector participants, as it may increase the number of operators in the European MSS sector.
Continue Reading A Single EU Authorisation for Satellite Spectrum: The Commission’s Proposal for a New 2 GHz Mobile Satellite Services Regulation

On 7 May 2026, negotiators from the Council of the European Union, the European Parliament, and the European Commission reached a provisional agreement on the terms of the Digital Omnibus on AI, marking the first set of amendments to the EU AI Act since its adoption in June 2024. The final package of amendments reflects

Continue Reading EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions

On May 8, 2026, the European Commission (“Commission”) published draft guidelines (“Guidelines”) on the implementation of the transparency obligations under Article 50 of the EU Artificial Intelligence Act (“AI Act”), opening a targeted consultation that runs until June 3, 2026.

The Guidelines are non-binding, but they are the first Commission instrument to provide interpretive guidance across the full scope of Article 50. They were prepared in parallel with the related, but more narrowly scoped, Code of Practice on Transparency of AI-Generated Content (“Code of Practice” or “Code”), the second draft of which was published on March 5, 2026.

Continue Reading 10 Takeaways: European Commission Draft Guidelines on AI Transparency under the EU AI Act
On 19 March 2026, Advocate-General Capeta issued an opinion in the case of Elisa Eesti AS v Estonian Government Security Committee (C-354/24). This case concerned, among other things, whether a 2022 order from the Estonian Government for Elisa Eesti AS—a 5G network operator—to remove Huawei components from its network for national security reasons was subject to EU law, constituted a lawful restriction on the right to offer an electronic communications network, and amounted to a “deprivation of property” requiring compensation. AG Capeta concluded that the relevant Estonian regime was within scope of EU law—specifically the European Electronic Communications Code (“EECC”)—even though that regime allowed for the imposition of orders on electronic communications network (“ECN”) providers for national security reasons. She also concluded that the requirement to obtain prior authorization from the Estonian government for use of network equipment constituted a restriction on the freedom to provide an ECN, but that this could be justified on national security grounds if the decision was based on a genuine risk assessment that meets the requirements for proportionality under EU law. She stated that this determination should be left to the referring court. Finally, she concluded that the Estonian Government’s order did not amount to a “deprivation” of property for which compensation would be required, as it was instead a mere “restriction” on the use of property. Below, we describe these non-binding conclusions in more detail. The Court’s final ruling in this case will have significant implications for the European Commission’s proposed revisions to the EU Cybersecurity Act, which as drafted would—among other things—allow the Commission to require ECN providers to remove and cease using components from designated high-risk jurisdictions in their networks. See our prior blog post on the proposal for a revised Cybersecurity Act here. Continue Reading CJEU Advocate-General indicates that communications network operators can lawfully be required to remove Chinese components, and that compensation is not required

In June 2025, the European Parliament (“EP”) published its draft report on “Copyright and generative artificial intelligence – opportunities and challenges” (available here). The draft report calls on the European Commission to make a series of changes to the way that copyright is protected in the age of generative AI (“GenAI”). The EP notes the challenges in finding a balance between respecting existing laws and protecting the rights of content creators on the one hand, while not hindering the development of AI technologies in the European Union on the other. In its report, the EP focuses on the perceived copyright-related risks posed at the GenAI training stage and the GenAI output stage.

Continue Reading European Parliament Proposes Changes to Copyright Protection in the Age of Generative AI

On 21 January 2026, the European Commission (“Commission”) unveiled its landmark proposal for the Digital Networks Act (“DNA Proposal”), an ambitious attempt to overhaul the framework for the regulation and development of electronic communications networks and services across the EU. The Commission’s stated aim with the DNA Proposal is to establish a “modern and simplified legal framework that incentivises the transition from legacy networks to fibre, high quality 5G and 6G networks, and cloud-based infrastructures, as well as increased scale through service provision and cross-border operation.” To do this, the DNA Proposal would replace and consolidate several existing EU laws, including the European Electronic Communications Code (“EECC”), the BEREC Regulation, and parts of the Open Internet Regulation and e-Privacy Directive.

A key theme of the proposal is harmonization of rules—arising first and foremost from the fact that this is a directly-applicable Regulation rather than a Directive like the current European Electronic Communications Code. Several of the substantive provisions in the DNA Proposal may take a significant amount of influence over the communications networks and services away from Member State governments and up to EU level. In turn, the Commission clearly hopes to promote larger-scale communications network and service providers that can operate across the EU, and that have the funds to invest in modern communications infrastructure. The DNA Proposal could, therefore, have a substantial and long-lasting impact on the connectivity and communications markets in the EU, although we anticipate significant debate about many of the provisions of the DNA Proposal throughout the legislative process.

Below, we summarize seven of the most eye-catching changes to the regulatory framework for communications providers in the DNA Proposal.

Continue Reading Seven Major Changes in the European Commission’s Proposal for an EU Digital Networks Act

The Commission has issued a call for evidence in relation to its 2026 evaluation and review of the Audiovisual Media Services Directive (“AVMSD”). 

The AVMSD came into force in 2010 and establishes the EU’s regulatory framework for audiovisual media services.  It governs the EU level coordination of national legislation on all audiovisual media, including traditional TV broadcasts and on-demand services.

The first review of the AVMSD was carried out in 2018 and resulted in the introduction of new provisions governing video sharing platforms.

Under Article 33 of AVMSD, the Commission is required to assess the impact and added value of the AVMSD and present an ex-post evaluation report, accompanied where appropriate by proposals for reviewing the Directive, by 19 December 2026.  This second review of the AVMSD is also part of the Commission’s commitments in the recently announced European Democracy Shield, which aims to foster the EU media sector to achieve stronger and more resilient democracies. 

Continue Reading The European Commission calls for evidence ahead of its 2026 evaluation and review of the Audiovisual Media Services Directive