From Regulation to Strategy: Europe’s New Tech Agenda
Written by Efi Thoma, Senior Global Legal Counsel
Europe’s approach to technology regulation is entering a
more practical phase. After several years of ambitious rule-making, Brussels is
increasingly focused on implementation, enforcement and simplification. For
technology companies, the key question is no longer simply “What does the
law require?” but “How do we make these requirements work in practice
without unnecessarily slowing innovation?”
For businesses, the practical approach is to embed AI governance into existing processes rather than create an entirely separate compliance structure. AI inventories, risk classification, procurement controls, human oversight and clear internal accountability can increasingly become part of normal product and business governance.
The EU Data Act (Regulation (EU) 2023/2854), applicable since September 2025, introduces important rules around access to data generated by connected products and related services, cloud switching and contractual terms concerning data sharing.
The practical question for companies is therefore not only “Who owns or can access the data?” but also “How can we use data responsibly to improve products, partnerships and customer value?” Reviewing data architecture and contractual arrangements early can help avoid compliance becoming a barrier when new products or services are launched.
The Digital Markets Act (Regulation (EU) 2022/1925) and Digital Services Act (Regulation (EU) 2022/2065) demonstrate that Brussels is increasingly looking beyond policies and contractual terms to how digital products and platforms actually operate.
Transparency, online choice, platform behavior and user experience are therefore becoming part of the regulatory conversation. The practical lesson is straightforward: legal and compliance teams should be involved earlier in product development, particularly where design choices may affect consumers, competition or transparency.
The NIS2 Directive (Directive (EU) 2022/2555) and Cyber Resilience Act (Regulation (EU) 2024/2847) reinforce the direction toward stronger cybersecurity governance and greater accountability throughout the lifecycle of digital products.
Cybersecurity should therefore increasingly be viewed as a business resilience issue rather than simply an IT responsibility. Clear ownership, supplier oversight, incident-response processes and security-by-design can help companies manage both regulatory and operational risk.
Looking toward 2027 and beyond, the direction from Brussels appears increasingly pragmatic: maintaining strong safeguards while also supporting innovation, investment and European competitiveness.
For technology companies, the opportunity is to move beyond a checklist approach to compliance. The more sustainable strategy is to build regulatory thinking into product, data and business decisions early-making compliance easier to manage while turning trust, security and responsible innovation into a competitive advantage.
Efi Thoma is Senior Global Legal Counsel

Comments
Post a Comment