regulation · Effective Jan 1, 2026
EU regulates AI through Commission Cybersecurity Resilience and Capabilities Package 2026.
Commission Cybersecurity Resilience and Capabilities Package 2026 · effective 2026
Updated 60 days ago · 2 sources · confidence: medium
Overview
The European Union has positioned itself as a global frontrunner in Artificial Intelligence regulation, adopting a distinctive human-centric and risk-based approach to govern the development, deployment, and use of AI systems. This comprehensive strategy, articulated through foundational policy documents such as the 2020 White Paper on AI and the 2021 Communication on Fostering a European approach to Artificial Intelligence, aims to strike a delicate balance between fostering innovation and ensuring the protection of fundamental rights, safety, and democratic values. The cornerstone of this regulatory landscape is the Artificial Intelligence Act (Regulation (EU) 2024/1689), which officially entered into force on August 1, 2024, with its provisions becoming applicable in a phased manner. This landmark legislation is designed to create an ecosystem of both excellence and trust, ensuring that AI technologies deployed within the Union are not only technologically advanced but also ethically sound and legally compliant. The EU's proactive stance reflects a recognition of AI's transformative potential across various sectors, from healthcare to manufacturing, while simultaneously addressing the inherent risks associated with opaque decision-making, discrimination, and privacy intrusions. The EU's overall approach is characterized by its ambition to set global standards for trustworthy AI, promoting multilateral engagement and international cooperation to shape global AI governance. This is evident in its active participation in international initiatives, such as the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, which the EU authorized for signing in August 2024. The regulatory framework is continuously evolving, with ongoing efforts to simplify and streamline digital rules through initiatives like the Digital Omnibus Package, which seeks to reduce administrative burdens while maintaining high standards of protection across AI, cybersecurity, and data. This iterative process, supported by dedicated bodies like the European AI Office and the European Artificial Intelligence Board, underscores the EU's commitment to creating a coherent, adaptable, and robust regulatory environment that can respond to rapid technological advancements and emerging societal challenges.
Regulatory approach
The European Union's regulatory approach to AI is predominantly horizontal, risk-based, and a blend of binding legislation and soft law instruments. The Artificial Intelligence Act (AI Act) serves as the primary horizontal legal framework, applying across all sectors where AI systems are developed, placed on the market, or used. This Act categorizes AI systems into four risk levels: unacceptable, high, limited, and minimal, with obligations escalating in stringency commensurate with the identified risk. Prohibited AI practices, deemed to pose an unacceptable risk to fundamental rights, are outright banned, while high-risk AI systems face stringent requirements regarding risk management, data governance, technical documentation, transparency, human oversight, robustness, accuracy, and cybersecurity. This risk-based methodology aims to ensure proportionality, focusing regulatory burdens on areas with the greatest potential for harm, thereby fostering innovation in lower-risk applications. Complementing the binding provisions of the AI Act, the EU employs a range of soft law instruments, including guidelines and codes of practice, to provide practical guidance and promote best practices. Examples include the Commission Guidelines on the definition of an 'AI system', the Guidelines regarding prohibited AI practices, and the Guidelines on the scope of obligations for providers of General-Purpose AI models. Furthermore, the General-Purpose AI Code of Practice offers a voluntary framework for GPAI providers to demonstrate compliance with AI Act obligations, providing a streamlined route to conformity. The regulatory landscape also integrates with existing sectoral legislation, such as the revised Directive on liability for defective products, which now explicitly covers software and AI, and the General Data Protection Regulation (GDPR), ensuring a cohesive and comprehensive legal ecosystem. This multi-faceted approach allows for flexibility and adaptability, enabling the EU to address the complex and rapidly evolving nature of AI technologies while upholding its core values. The European Union has established a multi-layered governance and institutional framework to ensure the effective and consistent implementation and enforcement of its AI regulations. Central to this is the European AI Office, formally established by a Commission Decision in January 2024 within the Directorate-General for Communication Networks, Content and Technology (DG CONNECT). The AI Office serves as the EU's center of AI expertise, with a primary mission to support the implementation and enforcement of the AI Act, particularly concerning general-purpose AI models. Its tasks include developing tools and methodologies for evaluating GPAI models, monitoring the application of rules, investigating infringements, coordinating with other Union supervisory powers, and supporting the implementation of rules on prohibited practices and high-risk systems. It also plays a key role in fostering international cooperation and developing guidance and standardized protocols. Further strengthening the governance structure is the European Artificial Intelligence Board (AI Board), created by the AI Act and composed of representatives from each EU Member State. The AI Board acts as a key advisory body, supported by the AI Office, to ensure the effective implementation of the AI Act across the EU. Its mandate includes coordinating national competent authorities, sharing technical and regulatory expertise, providing advice on AI policy and innovation, and contributing to the development of delegated and implementing acts under the AI Act. This collaborative body aims to foster a coherent and forward-looking AI policy framework. Additionally, the EU Agency for Cybersecurity (ENISA) plays a crucial role in enhancing cybersecurity across the EU, which is intrinsically linked to AI security. ENISA is entrusted with administering the EU Cybersecurity Reserve and operates as the technical backbone for a new single-entry point for cybersecurity incident reporting across multiple regulations, as envisioned by the Digital Omnibus Package. The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) are vital for ensuring that AI regulations align with data protection and privacy principles, providing joint opinions on legislative proposals and overseeing AI systems used by EU institutions. National competent authorities in each Member State are responsible for local supervision, enforcement, and market surveillance, working in conjunction with these EU-level bodies.
Enforcement & penalties
The EU AI Act establishes a robust system of penalties and enforcement mechanisms designed to ensure compliance with its provisions, with administrative fines varying significantly based on the nature and severity of the infringement. Non-compliance with the prohibitions on unacceptable AI practices, as outlined in Article 5 of the AI Act, carries the highest administrative fines, potentially reaching up to EUR 35,000,000 or 7% of the undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher. Infringements related to the obligations for high-risk AI systems or general-purpose AI (GPAI) models can also result in substantial fines, with specific caps for GPAI providers set at up to EUR 15 million or 3% of global turnover. These penalties are intended to be effective, proportionate, and dissuasive, reflecting the EU's commitment to upholding fundamental rights and safety standards in the AI domain. Member States are required to adopt national rules on penalties and enforcement measures and notify them to the Commission. Enforcement is primarily carried out by national competent authorities, including market surveillance authorities, in coordination with the European AI Office. The AI Office itself is granted exclusive enforcement powers over general-purpose AI models and systems integrated into Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs), aiming to prevent fragmentation of oversight. The Commission also has powers to initiate formal antitrust investigations, as demonstrated by the probe into Meta's WhatsApp AI policy, under EU competition rules (Article 102 TFEU), which can lead to significant fines and behavioral or structural remedies if abuse of a dominant position is found. For high-risk AI systems, providers must undergo conformity assessments, maintain technical documentation, and implement risk management systems, with market surveillance authorities empowered to request information, conduct evaluations, and impose corrective actions. The iterative monitoring and evaluation framework, supported by ongoing stakeholder consultations and the work of the AI Board, ensures that enforcement mechanisms remain adaptable and responsive to technological advancements and market developments.
Data protection
The overarching data protection framework in the European Union is the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), which sets stringent rules for the processing of personal data. The EU's AI regulatory landscape is meticulously designed to interact with and complement the GDPR, ensuring that the development and deployment of AI systems fully respect individuals' rights to data protection and privacy. The AI Act explicitly preserves the applicability of EU data protection law, meaning that any processing of personal data by AI systems must comply with GDPR principles, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. This integration is particularly critical for high-risk AI systems, which often process large volumes of data, including sensitive personal data. The AI Act mandates robust data governance requirements for such systems, including measures to assess the suitability of training, validation, and testing datasets, and to address potential biases. The interplay between the AI Act and GDPR is further elaborated through guidance and legislative proposals. The EDPB-EDPS Joint Opinion 1/2026, for instance, critically assesses the 'Digital Omnibus on AI' proposal, emphasizing that any simplification of AI Act implementation must not compromise fundamental rights, especially data protection and privacy. It provides recommendations on sensitive data processing for bias detection, stressing the need for 'strict necessity' and clear circumscription to prevent abuse. The Digital Omnibus Package itself aims to clarify data processing rules for AI model training, explicitly expanding legitimate interest grounds for such activities, thereby providing legal certainty for this critical use case while maintaining data protection safeguards. The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) play crucial advisory and supervisory roles, ensuring that data protection principles are deeply embedded into the evolving AI regulatory framework and that national Data Protection Authorities (DPAs) retain their ability to act and coordinate effectively with new AI-specific bodies like the AI Office.
Sector-specific rules
While the EU AI Act provides a horizontal framework, its risk-based approach inherently leads to sector-specific considerations, particularly for high-risk AI systems. The Act identifies several critical sectors where AI applications are deemed high-risk due to their potential impact on fundamental rights and safety. These include AI systems used in critical infrastructure (e.g., water, gas, electricity, road traffic control), education and vocational training (e.g., for assessing learning outcomes or directing individuals), employment, workers management and access to self-employment (e.g., for recruitment, promotion, or task allocation), and access to and enjoyment of essential private and public services (e.g., credit scoring, dispatching emergency services). Furthermore, AI systems in law enforcement, migration, asylum, and border control management, as well as the administration of justice and democratic processes, are explicitly categorized as high-risk, necessitating stringent compliance requirements. This targeted approach ensures that sectors with unique sensitivities and potential for harm receive appropriate regulatory scrutiny, aligning with existing sectoral safety and ethical standards. Beyond the AI Act, other EU legislation directly addresses AI in specific contexts. The recently revised Directive (EU) 2024/2853 on liability for defective products, for example, explicitly extends strict liability to include software, AI systems, and digital manufacturing files. This modernization ensures that victims of harm caused by defective AI products can seek redress, harmonizing liability rules across the digital economy. While the AI Act sets out requirements for AI in medical devices, the AI Board's sixth meeting specifically discussed the interplay between the AI Act and other sectoral regimes, notably medical devices, indicating ongoing efforts to ensure coherence and avoid duplicative burdens. Similarly, the Commission Cybersecurity Resilience and Capabilities Package 2026 aims to enhance ICT supply chain security, which has significant implications for AI systems embedded in critical infrastructure. These complementary legislative and policy instruments collectively create a robust framework that addresses AI's unique challenges within various sectors, ensuring both safety and legal clarity.
International alignment
The European Union is actively shaping the global governance of AI through a concerted strategy of international alignment and standard-setting. A significant step in this direction was the Council Decision (EU) 2024/2218, adopted on August 28, 2024, which authorized the signing, on behalf of the European Union, of the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. This Convention, adopted by the Council of Europe in May 2024, establishes binding international principles and obligations for AI governance, complementing the EU AI Act by addressing AI at the intersection of human rights, democracy, and the rule of law. The EU's engagement in this multilateral instrument underscores its commitment to promoting its human-centric and values-based approach to AI on the international stage, fostering common standards and cooperation among signatory states. The EU AI Act itself is widely recognized as a pioneering legal framework with significant global influence, inspiring similar legislative initiatives and regulatory discussions worldwide. The EU's strategy, rooted in the 2018 Communication 'Artificial Intelligence for Europe' and subsequent policy documents, consistently emphasizes the Union's ambition to become a global standard-setter for trustworthy AI. This involves active engagement with international organizations like the OECD, promoting the OECD AI Principles, and fostering bilateral dialogues with key trade partners. The European AI Office is tasked with ensuring a strategic, coherent, and effective European approach to AI at the international level, becoming a global reference point. Through these efforts, the EU seeks to ensure that AI development and deployment globally align with democratic values, fundamental rights, and a shared commitment to ethical and responsible innovation, preventing regulatory fragmentation and promoting interoperability.
What's next
The European Union's AI regulatory landscape is dynamic, with several key developments and pending legislation anticipated to further refine and streamline its framework. A major ongoing initiative is the Digital Omnibus Package, formally announced in November 2025, which aims to simplify EU digital rules across AI, cybersecurity, and data. This package includes targeted amendments to the AI Act, GDPR, and cybersecurity directives (NIS2, DORA, CER) with the goal of reducing administrative complexity and compliance costs, particularly for SMEs. Key measures include simplifying high-risk AI system compliance by linking deadlines to the availability of support tools and standards, introducing a single-entry point for cybersecurity incident reporting, and clarifying data processing rules for AI model training. The legislative process for this package is ongoing, requiring approval by both the European Parliament and the Council, with substantive amendments expected before final adoption. Further future developments include ongoing efforts to operationalize specific aspects of the AI Act and related policies. For instance, the Commission launched a stakeholder consultation in December 2025 to identify and agree on machine-readable opt-out protocols for Text and Data Mining (TDM) rights, aiming to provide technical clarity for GPAI providers in complying with copyright obligations. The Code of Practice on AI-Generated Content Transparency is also a proposed initiative, currently under public consultation, which aims to establish a common framework for transparent AI-generated content through clear labeling, disclosure, and traceability. These initiatives reflect the EU's iterative approach to regulation, where ongoing consultations, guidelines, and codes of practice continuously adapt the framework to technological advancements and emerging challenges. The European AI Office and the AI Board will continue to play crucial roles in monitoring implementation, identifying emerging bottlenecks, and recommending further adjustments to ensure the EU's AI governance remains evidence-based and responsive.
regulation · Effective Jan 1, 2026
guideline · Effective Jan 1, 2026
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
regulation · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
policy · Effective Jan 1, 2024
EU institutions
policy · Effective Jan 1, 2024
regulation · Effective Jan 1, 2024
act · Effective Jan 1, 2023
act · Effective Jan 1, 2022
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2021
guideline · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
guideline · Effective Jan 1, 2019
policy · Effective Jan 1, 2018
act · Effective n/a
Sources:
policy · Effective n/a
enforcement
Supports the implementation and enforcement of the AI Act, especially for general-purpose AI models; fosters trustworthy AI and international cooperation.
advisory
Advisory body composed of Member State representatives; ensures effective and consistent implementation of the AI Act across the EU.
advisory
Enhances cybersecurity in Europe, supports cyber policy, ensures ICT trustworthiness, and builds resilience against cyber threats.
data_protection
Ensures consistent application of the GDPR and the Law Enforcement Directive, and promotes cooperation among national data protection authorities.
data_protection
Supervises the processing of personal data by EU institutions and bodies, and advises on data protection matters.
advisory
Responsible for EU policy on competition and enforcing EU competition rules to ensure fair and open markets.
No tracked timeline events yet
Last checked May 26, 2026
No tracked international memberships yet
Last checked May 26, 2026