Dispatch from Brussels: Updates on EU Tech Policy

Welcome to this edition of the Dispatch from Brussels. The past two weeks have been dominated by negotiations rather than announcements: Member States failed at the last minute to agree their position on the Digital Omnibus, the Cloud and AI Development Act picked up its first amendments in Parliament, and the KIDS Act had its first outing in the Council. On the UK–EU front, preparations for the summit are gathering pace, with Made in Europe firmly on the agenda. Below is a more detailed overview of what has kept the EU tech policy space busy.
Digital Simplification
Council fails to agree its position on the Digital Omnibus: On 7 October, EU ambassadors were expected to adopt the Council’s negotiating mandate on the Digital Omnibus, the Commission’s package amending the GDPR, ePrivacy rules and the Data Act to simplify the EU’s digital rulebook and reduce compliance burdens (see techUK’s overview of the proposal). The vote was postponed after Germany, joined by France, once again mounted a last-minute push for stronger protection of trade secrets under the Data Act, the regulation giving users of connected devices greater control over the data they generate and setting rules on data sharing. This was despite several revised compromise texts from the Irish Presidency, which had been aiming for a mandate in October. Ambassadors are expected to meet again in the coming days to try to close a deal.
Artificial Intelligence
Commission rules out a new AI liability proposal “at this stage”: On 8 October, the Commission told POLITICO it is not planning “at this stage” to reintroduce a proposal on AI liability, after OpenAI’s Sam Altman called for a liability framework for the most capable AI models, adding fuel to renewed calls for legislative intervention. The AI Liability Directive, which would have made it easier for people harmed by AI systems to claim compensation by easing the burden of proof, was withdrawn by the Commission in 2025. In the meantime, the AI Act, the EU’s risk-based rulebook for AI is now being actively enforced for general-purpose AI models, with the AI Office having sent its first requests for information to more than 30 providers on 1 September.
Commission opens a targeted consultation on copyright and AI: On 29 September, the Commission launched a targeted consultation on the effect of technology on copyright. It covers the use of protected content to train generative AI and for research, online piracy of live events, and remuneration for sound recordings by non-EU nationals. It will feed into the review of the 2019 Copyright in the Digital Single Market Directive, which notably introduced the text and data mining exceptions that AI developers rely on, subject to rightsholders’ ability to opt out. The consultation closes on 3 November.
Tech Sovereignty
Cloud and AI Development Act gets its first Parliament Opinion: The Cloud and AI Development Act (CADA), proposed on 3 June as part of the EU’s Tech Sovereignty Package, aims to boost EU data centre and cloud capacity and introduces a tiered framework of sovereignty requirements for cloud and AI services, notably in public procurement (see techUK’s analysis of what it means for UK tech). The file is starting to take shape in both institutions. According to press reports, the draft opinion (which is non-binding) of the Legal Affairs Committee rapporteur, Sergey Lagodinsky (Greens), proposes to cut the four-level sovereignty framework down to two, to reserve at least 80% of new data centre capacity in “acceleration zones” for EU players, and to scrap the route for vetting third-country providers. In the Council, national experts met on 6 October to hear clarifications from the Council Legal Service, and were reportedly told that it considers the proposal compatible with the EU’s WTO commitments, subject to some adjustments to its “Buy European” provisions. The lead committees are expected to present their joint draft report on 1 December. techUK is preparing a report on the impact of CADA on UK companies. Should you have any insights to share on the potential impact of the proposed legislation on your business, do not hesitate to get in touch.
Standards
Commission proposes to speed up European standardisation: On 6 October, the Commission adopted its proposal to revise the Standardisation Regulation, the framework governing how the Commission requests European standards from the European standardisation organisations (CEN, CENELEC and ETSI) and how these harmonised standards are used to demonstrate compliance with EU law. The aim is to cut the average time needed to develop a harmonised standard from six to four years through clearer deadlines for standardisation requests, interim deliverables and, under defined conditions, greater use of other technical specifications. It also clarifies the use of Commission-adopted “common specifications” as a fallback where European standards are not delivered, and creates a new Expert Centre on European Standardisation. The proposal now goes to Parliament and Council.
Online Platforms
KIDS Act gets its first hearing in the Council: On 2 October, the Commission presented the KIDS Act, its proposal harmonising rules on children’s access to online services through minimum ages for social media, safe-by-design obligations and age verification (see our previous update), to national experts in the Council (meeting notice). Several Member States are nonetheless pressing ahead with their own measures: Portugal has notified a draft national law to the Commission, Greece plans an under-15 ban from January 2027, and Austria has notified a draft law setting a minimum age of 14 for certain video-sharing platforms. Others, such as Estonia, have come out against general bans and a single EU age-verification method. In Parliament, MEPs debated the KIDS Act with Executive Vice-President Virkkunen on 6 October, where the proposal was broadly well received but age-verification measures raised reservations. Ministers are reportedly due to hold their first political discussion at the Education, Youth, Culture and Sport Council on 20 November.
Consumer authorities target in-game currencies: At the end of September, the Consumer Protection Cooperation (CPC) Network of national consumer authorities announced coordinated action against nine video game companies, including King, Mojang, Riot Games, Supercell and Ubisoft. Authorities will examine how in-game virtual currencies are priced and sold, withdrawal rights, parental controls and marketing to children. With the Digital Fairness Act, the Commission’s upcoming proposal to tackle dark patterns, addictive design and unfair personalisation online, reportedly scheduled for 11 November, this is a clear sign that consumer enforcement on video games is stepping up.
US Government seeks to join X’s challenge to its DSA fine: On 25 September, it emerged that the US Department of Justice has asked the EU General Court for permission to intervene in support of X’s legal challenge to the €120 million fine imposed in December 2025 under the Digital Services Act, the EU’s rulebook on illegal content, transparency and systemic risks on online platforms. The Commission said it is ready to defend its decision in court. This is a further sign of how EU digital rulebooks have become a point of friction in transatlantic relations.
Cybersecurity
Cybersecurity Act revision moves forward in both institutions: At the end of September, EU governments seem to have agreed to drop the 36-month deadline for phasing out high-risk suppliers in their negotiations on the revision of the Cybersecurity Act, which strengthens ENISA’s mandate, reforms the EU cybersecurity certification framework and introduces measures to reduce dependence on high-risk ICT suppliers (see techUK’s overview of the proposal). In Parliament, rapporteur Markéta Gregorová presented her draft reports on the Cybersecurity Act and accompanying NIS2 amendments to the Industry Committee (ITRE) on 8 October.
Telecoms and Connectivity
Digital ministers to focus on satellite connectivity: EU telecoms ministers will meet informally in Limerick on 12–13 October, with the Digital Networks Act, the proposal to modernise EU telecoms rules on spectrum, copper switch-off and end-user rights (see techUK’s overview), on the agenda alongside subsea cables and network resilience. According to press reports, a Presidency discussion paper also asks how Europe can support European satellite champions without unduly restricting access to satellite services from third countries. This comes as Member States work on the Commission’s proposal on 2 GHz mobile satellite services, which would create a new EU-level authorisation for these frequencies and is moving quickly as current rights expire in May 2027.



