11 Sep 2026
by Theo Maiziere

Dispatch from Brussels: Updates on EU Tech Policy

Welcome to this edition of the Dispatch from Brussels. The EU institutions are now back at work and things are picking up. The EU AI office has issued its first formal requests for information under the AI Act, the EU Commission has decided to classify ChatGPT under its strictest tier within the Digital Services Act, and also proposed a key piece of legislation to change its procurement rules. You can find all updates below.  

UK-EU Trade Report

techUK publishes its new report Towards a UK-EU Partnership for a New Age: On 10 September, techUK launched Towards a UK–EU Partnership for a New Age at the UK Ambassador's Residence in Brussels, ahead of the UK–EU Summit. The report argues that European sovereignty must be built with trusted partners, not in isolation. It highlights the scale of interdependence: bilateral trade in digitally deliverable services worth over $350 billion in 2024, and a UK cyber sector that is Europe's largest, with revenues above €10.3 billion in 2025. It also warns that divergence is already costly, with the loss of automatic recognition of conformity assessments creating dual compliance burdens that fall hardest on SMEs, and exclusion from SAFE weakening defence supply chains.

Its recommendations span defence and security, regulatory interoperability, digital standards and sovereignty. Key asks include UK participation in SAFE, mutual recognition agreements in high-compatibility sectors, and recognition of UK firms as trusted partners under files such as the Cloud and AI Development Act and the public procurement revision. You can find the full report on the techUK website.  

Artificial Intelligence

EU AI office issues first requests for information to General Purpose AI providers: On 29 August (and further detailed on 1 September), the EU Commission announced it had sent requests for information to 30 GPAI providers. This is an important step as it marks the first use of the EU Commission’s new powers enabled by the AI Act since they became applicable on 2 August. The EU Commission has indicated that it had contacted these different GPAI providers with two different sets of questions.

The first set concerns safety and security and was directed at the most advanced model providers, while the second set concerns copyright and transparency, and targeted providers that jad not published a training data summary or taken part in informal compliance dialogues with the AI office. While this EU Commission has framed these as simple requests for information and dialogue, it jad indicated that all unanswered requests could be escalated. It is therefore a clear sign that companies providing GPAI models should treat the training data summary and copyright policy obligations as actively supervised at this stage.

EU Single Market and Competitiveness

EU Commission proposes a single Public Procurement Act with a European preference framework: On 9 September, the Commission proposed a Public Procurement Act that would replace the three 2014 Directives with a single, directly applicable Regulation. Alongside simplification and a common digital procurement ecosystem, the proposal introduces a horizontal framework for European preference. Public buyers could voluntarily restrict participation to "covered" operators and goods, meaning those from the EU, WTO GPA parties, or countries with EU trade agreements containing procurement commitments. However, preference could become mandatory through delegated acts or sector-specific legislation, whose rules would prevail. A new security chapter would also require resilience measures for contracts involving NIS2 entities or critical infrastructure, and allow exclusion of operators on security grounds.

For UK companies, GPA membership and the TCA should mean coverage in principle, but exclusion remains possible through sector files such as the Cloud and AI Development Act, the Cybersecurity Act revision and Chips Act 2.0. We would therefore welcome techUK member views on these sectoral developments as we seek to address any upcoming challenges.

Online Platforms

EU Commission designates ChatGPT, Reddit, and Roblox under the DSA: On 31 August the Commission the Commission designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act, each having declared at least 45 million average monthly EU users. ChatGPT becoming the first AI chatbot to be designated as a very large online search engine marks an important step. The EU Commission’s rationale is that the AI chatbot offers a hybrid service that falls within the search engine category because if its ability to search the web in response to user prompts and queries. When it comes to Reddit and Roblox, it was determined that they are platforms that enable users to disseminate third-party content to the public, making them qualify under the DSA. All three entities now have four months (from notification) to comply with the additional obligations they now find themselves under. Those obligations include annual systemic risk assessments and mitigation covering illegal content, effects on minors, users’ physical and mental wellbeing, fundamental rights, electoral processes and public security (among other requirements). As a reminder, non-compliance with those requirements can lead to fines of up to 6% of global annual turnover.

French President Macron calls for EU wide ban on social media for children under 15: In a letter sent on 29 August but only recently disclosed, French President Macron has called for the EU Commission to bring forward the new EU legislation meant to harmonise a ban on social media access for children under 15. The call follows The request follows the French Constitutional Council's decision of 14 August striking down France's own under-15 ban, which had been due to take effect at the start of the school year, on freedom of expression and privacy grounds. The letter cites addictive design, inadequate account safety for minors and exposure to pornography, and France has said it will also bring forward revised national legislation in the autumn. Continued pushes by larger member states such as France on this issue means we will likely hear more about EU wide plans for social media bans next week during the EU Commission President’s State of the EU address (outlining key priorities for the next 12 months).  

Cyber Resilience

Cyber Resilience Act reporting obligations enter into application: From 11 September, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform, with an early warning within 24 hours of awareness, a full notification within 72 hours, and a final report within 14 days of a corrective measure for vulnerabilities or one month for incidents. The obligation reaches products already on the EU market, not only new ones. In the final fortnight before the deadline, ENISA closed several gaps that members had flagged. On 4 September it published the long-outstanding list of CSIRTs designated as coordinators for all 27 Member States (updated again on 10 September) and rewrote the SRP FAQ, expanding the mandatory fields at the 24-hour stage to include a title, a summary and the product version. On 5 September it issued version 1.1 of the SRP Glossary, and between 7 and 10 September it revised the notification submission guidance, published an Assigned Representative user manual and platform terms and conditions, and added a fifth guidance page on Particularly Exceptional Circumstances. 

European Cybersecurity Competence Centre opens €96 million Digital Europe call: On 1 September, the ECCC opened a call for proposals under the Digital Europe Programme with seven topics: AI-based cybersecurity tools for national authorities, CSIRTs and NIS2 entities (€15 million); AI-powered cybersecurity solutions for SMEs (€20 million); coordinated preparedness testing and other preparedness actions under the Cyber Solidarity Act (€15 million); Regional Cable Hubs for undersea cable security (€5 million); strengthening the National Coordination Centres (€11 million); support for implementing the CRA, NIS2, DORA, the Cybersecurity Act and the AI Act's cybersecurity requirements (€20 million); and dual-use cybersecurity technologies (€10 million). Proposals can be submitted until 14 January 2027. All topics are subject to Article 12(5) of the Digital Europe Programme Regulation, which imposes security-related eligibility conditions on participating entities. UK-established entities are not eligible under Digital Europe in the absence of UK association; members with EU-established subsidiaries should check eligibility before investing effort. 


Theophile Maiziere

Theophile Maiziere

Policy Manager - EU, techUK


techUK International Policy and Trade Programme activities

techUK supports members with their international trade plans and aspirations. We help members to understand market opportunities, tackle market access barriers, and build partnerships in their target market. Visit the programme page here.

 

 

Upcoming events

Latest news and insights 

Learn more and get involved

 

International Policy and Trade updates

Sign-up to get the latest updates and opportunities from our International Policy and Trade programme.

 

Here are the five reasons to join the International Policy and Trade Programme

Download

Join techUK groups

techUK members can get involved in our work by joining our groups, and stay up to date with the latest meetings and opportunities in the programme.

Learn more

Become a techUK member

Our members develop strong networks, build meaningful partnerships and grow their businesses as we all work together to create a thriving environment where industry, government and stakeholders come together to realise the positive outcomes tech can deliver.

Learn more

 

Meet the team 

Sabina Ciofu

Sabina Ciofu

International Policy and Strategy Lead, techUK

Theophile Maiziere

Theophile Maiziere

Policy Manager - EU, techUK

Archie Breare

Archie Breare

Policy Manager - Trade, techUK

 

Authors

Theo Maiziere

Theo Maiziere

Policy Manager - EU, techUK

Theo joined techUK in 2024 as EU Policy Manager. Based in Brussels, he works on our EU policy and engagement.

Theo is an experienced policy adviser who has helped connect EU and non-EU decision makers.

Prior to techUK, Theo worked at the EU delegation to Australia, the Israeli trade mission to the EU, and the City of London Corporation’s Brussels office. In his role, Theo ensures that techUK members are well-informed about EU policy, its origins, and its implications, while also facilitating valuable input to Brussels-based decision-makers.

Theo holds and LLM in International and European law, and an MA in European Studies, both from the University of Amsterdam. 

Read lessmore