From Regulation to Strategy: Europe’s New Tech Agenda

Written by Efi Thoma, Senior Global Legal Counsel 

Europe’s approach to technology regulation is entering a more practical phase. After several years of ambitious rule-making, Brussels is increasingly focused on implementation, enforcement and simplification. For technology companies, the key question is no longer simply “What does the law require?” but “How do we make these requirements work in practice without unnecessarily slowing innovation?”

The EU AI Act (Regulation (EU) 2024/1689) establishes a risk-based framework covering areas such as transparency, governance, human oversight and high-risk AI systems. As implementation progresses, the emphasis is increasingly on making the framework workable in practice, including through regulatory sandboxes and measures supporting implementation.

For businesses, the practical approach is to embed AI governance into existing processes rather than create an entirely separate compliance structure. AI inventories, risk classification, procurement controls, human oversight and clear internal accountability can increasingly become part of normal product and business governance.

The EU Data Act (Regulation (EU) 2023/2854), applicable since September 2025, introduces important rules around access to data generated by connected products and related services, cloud switching and contractual terms concerning data sharing.

The practical question for companies is therefore not only “Who owns or can access the data?” but also “How can we use data responsibly to improve products, partnerships and customer value?” Reviewing data architecture and contractual arrangements early can help avoid compliance becoming a barrier when new products or services are launched.

The Digital Markets Act (Regulation (EU) 2022/1925) and Digital Services Act (Regulation (EU) 2022/2065) demonstrate that Brussels is increasingly looking beyond policies and contractual terms to how digital products and platforms actually operate.

Transparency, online choice, platform behavior and user experience are therefore becoming part of the regulatory conversation. The practical lesson is straightforward: legal and compliance teams should be involved earlier in product development, particularly where design choices may affect consumers, competition or transparency.

The NIS2 Directive (Directive (EU) 2022/2555) and Cyber Resilience Act (Regulation (EU) 2024/2847) reinforce the direction toward stronger cybersecurity governance and greater accountability throughout the lifecycle of digital products.

Cybersecurity should therefore increasingly be viewed as a business resilience issue rather than simply an IT responsibility. Clear ownership, supplier oversight, incident-response processes and security-by-design can help companies manage both regulatory and operational risk.

Looking toward 2027 and beyond, the direction from Brussels appears increasingly pragmatic: maintaining strong safeguards while also supporting innovation, investment and European competitiveness.

For technology companies, the opportunity is to move beyond a checklist approach to compliance. The more sustainable strategy is to build regulatory thinking into product, data and business decisions early-making compliance easier to manage while turning trust, security and responsible innovation into a competitive advantage.

Efi Thoma is Senior Global Legal Counsel


Comments

Popular posts from this blog

Ombudsman inquiry on Commission President’s text messages is a wake-up call for EU

European Commission refers Poland to the Court of Justice to protect judges from political control

The Title Deed Issue in Cyprus and the "Trapped Buyers" Phenomenon

Amendment of Articles of Association in Cyprus: Between Corporate Freedom and Abuse of Right – A Comparison with the Corresponding Regulation in Germany

Greek Administrative Court rules state liable for Covid-19 vaccine side effects due to "excessive sacrifice"

Access to documents: the Commission decision refusing a journalist of The New York Times access to the text messages exchanged between President von der Leyen and the CEO of Pfizer is annulled (CJEU)

International Criminal Court removes Prosecutor Karim Khan over serious misconduct