The bulletin
EU digital policy watch — Q3 2026: what changed and why it matters
Three developments from Brussels this quarter that touch companies far outside the tech sector: AI Act transparency duties now in force, 'chat control' still unresolved, and an EU-wide age limit for social media on the table.
A short quarterly note on EU digital rules that land on ordinary companies — not only on Big Tech. Dates and sources are given so you can check for yourself.
1. AI Act: transparency duties applied on 2 August 2026 — the high-risk deadline moved
What happened. The AI Act's transparency obligations (Article 50) became applicable and enforceable on 2 August 2026: users must be told when they are interacting with an AI system, and AI-generated or manipulated content — text, images, audio, video, deepfakes — must be disclosed and, for generative systems, marked in a machine-readable way. Two more things switched on the same day: the Commission's enforcement powers over general-purpose AI models (it can request technical documentation, evaluate models, impose mitigations or withdrawal, and fine up to 3% of global turnover or EUR 15 million), and the general sanctions regime for prohibited practices (up to EUR 35 million or 7% of global turnover). Separately, the "Digital Omnibus on AI" (Regulation (EU) 2026/1744, in force 27 July 2026) postponed the high-risk obligations: to 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for AI embedded in regulated products. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to implement machine-readable marking.
Why it matters to you. If your company runs a chatbot on its website, generates marketing images or text with AI, or publishes AI-produced content, the transparency duties apply now regardless of whether you build the AI or merely use it. The common mistake this summer was assuming the Omnibus delay covered everything; it covered high-risk only. One precision worth having: for companies that use AI rather than build it, the disclosure duty bites on deepfakes and on AI-generated text published to inform the public — an internal or client report drafted with AI assistance and reviewed by a person is not in that category. It is still good practice to say so; we do it on our own reports. And a distinction to keep straight: the AI Act is a product-safety law with user rights on top, not a privacy law — that remains the GDPR, with overlap only around biometrics and confidentiality.
2. "Chat control": no permanent law yet, temporary scanning revived to 2028
What happened. The permanent Child Sexual Abuse Regulation ("Chat Control 2.0"), proposed in 2022, went through five trilogue rounds between December 2025 and 29 June 2026 without agreement; talks resume in the autumn. The Council's position (26 November 2025, under the Danish presidency) dropped mandatory client-side scanning in favour of a "voluntary" scanning framework plus age-verification and risk-mitigation duties; Parliament's position rejects indiscriminate scanning and wants judicial authorisation targeted at suspects. Meanwhile the interim regulation that let providers scan unencrypted messages voluntarily expired on 3 April 2026 after Parliament declined to extend it; the Council relaunched it in July and Parliament failed to block it (314 to 276, short of the absolute majority required), so a revived interim regime is heading back to the Council.
Why it matters to you. Nothing in force today requires breaking end-to-end encryption, and the Parliament has repeatedly voted against mass scanning — but the permanent regulation is still open, and "voluntary" detection with regulatory pressure is the live proposal. For a business, the practical question is where your internal communications run and under whose rules; it is one of the reasons we keep our own support chat self-hosted in the EU.
3. Social media age limits: from national bans to an EU-wide "Kids Act"
What happened. Australia's under-16 ban took effect on 10 December 2025 and set off a wave in Europe. Denmark announced an under-15 limit (7 November 2025); France's National Assembly voted an under-15 ban on 26 January 2026 (116 to 23), with the Senate passing a differing text still to be reconciled; Greece set 1 January 2027 for under-15s; Norway is preparing a bill for an age limit applying from the year a child turns 16. The European Parliament adopted a non-binding resolution on 26 November 2025 calling for an EU-wide minimum age of 16 (13 to 16 with parental consent). On 16 September 2026, in her State of the Union speech, Commission President von der Leyen announced an EU-wide proposal — no social media under 13, no personal account under 15, supervised "mini accounts" in between — with age verification via an EU app or national solutions; the draft must now be negotiated by member states and Parliament.
Why it matters to you. Mostly as a signal: age verification is becoming infrastructure, and the same EU-wide age-verification mechanism will end up in front of many services, not only social networks. Companies operating consumer-facing platforms should expect verification duties; everyone else should expect to see the mechanism appear in their supply chain.
Sources
AI Act: Official Journal, Regulation (EU) 2026/1744 (24 July 2026); Regulation (EU) 2024/1689 Articles 50, 99 and 101; EU AI Act explainer on Article 50; European Commission draft Guidelines on Article 50. Chat control: European Newsroom (15 October 2025); Max-Planck-Gesellschaft; Council documents 15318/25 and 9139/26; European Parliament votes of 26 March and 9 July 2026. Social media: Euronews (7 and 26 November 2025, 1 April and 15 September 2026); Reuters (26 January 2026); European Commission, State of the Union 2026.
We write these notes because our clients ask; they are not legal advice. For what applies to your company, your counsel has the final word — we just try to make the technical part easier to follow.
