×

EU Policy Update – May 2026

EU Policy Updates 08-06-2026

In a nutshell: The European Commission published the EU Tech Sovereignty Strategy, including the Open Source Strategy and the proposal for the Cloud and AI Development Act. The European Commission is also seeking views on the Copyright Directive and the application of the MiCA Regulation. The co-legislators finalised the work on the AI Omnibus. ENISA published its NIS360 report. The NIS Cooperation Group adopted common templates for incident reporting. European political groups published their position papers on EU Tech Sovereignty.

The European Commission published a Tech Sovereignty strategy

On 3 June, the European Commission published a Tech Sovereignty strategy. The strategy recalls the Draghi Report (see our previous reporting here), noting that 80% of EU digital products, services, infrastructure, and intellectual property come from non-EU providers. The strategy defines technological sovereignty as “Europe’s ability to develop, control and scale the critical technologies, infrastructure, services and data, including digital ecosystems, that underpin its economy, security and society, while derisking and diversifying supply chains and technological exposure to reduce strategic dependencies and resist foreign interference”. Technological sovereignty should not equate to isolation, protectionism or tech decoupling. To ensure Europe’s technological sovereignty, the EU should boost its industrial capacity and autonomy in digital supply chains, diversify its supply chains beyond a limited number of non-EU suppliers, and gain control over data infrastructures and critical data. The EU should also lead the standard setting for further unspecified key strategic technologies. Interoperability, portability and widespread adoption of open standards should promote users’ choice and allow for the scaling of technological solutions without prohibitive costs.

The European Commission published the EU Open Source Strategy

On 3 June, the European Commission published the EU Open Source Strategy as a part of the Tech Sovereignty package. The strategy notes that Free and Open-Source Software (FOSS) “crucially contributes to achieving the EU’s technological sovereignty”, and boosts the EU’s “competitiveness by accelerating innovation, lowering technology costs and reducing dependence on foreign vendors”. The strategy notes that the EU FOSS ecosystem faces challenges such as a lack of sustained funding, uncertainty regarding maintenance, accessing capital for scaling-up, low brand recognition, and barriers in public procurement. The Commission intends to facilitate the adoption of existing EU sovereign alternatives, including by scaling-up the “Open Internet Stack”, a project under the Commission’s Next Generation Internet initiative, intending to deliver FOSS building blocks on digital identity, cybersecurity and decentralised platforms, among others. The Commission also intends to promote the development of European FOSS solutions, including building blocks for Web 4.0 and architectural frameworks for virtual worlds. The Commission, with the support of ENISA, will create a list of the most exposed open source software and infrastructure dependencies and establish an “Open Source Maintenance Instrument” for its sustained financial support. The Commission will develop guidelines and best practices to support EU public authorities in incorporating FOSS in procurement procedures. The Commission intends to use the upcoming revision of the EU Standardisation Regulation to better integrate FOSS processes and communities into the EU standard-setting processes. The European Commission also noted that it will itself use and develop more FOSS and open technologies. The implementation of this strategy will span several years. Therefore, the Commission will discuss the progress on an annual basis with the Member States, and report to the European Parliament every three years.

The European Greens/EFA and S&D groups published position papers on the European Tech Sovereignty

In the course of May, the Greens/EFA and the Socialists and Democrats groups in the European Parliament finalised their respective positions on European Tech Sovereignty. Greens/EFA position paper notes the need to build a sovereign European digital ecosystem across every essential layer of technology. European sovereign tech should be founded on decentralised governance models, where open standards, interoperability and privacy by design are the basic principles. For a company to be considered sovereign, it needs to have its headquarters in Europe. The EU should build and expand its digital infrastructure by investing in European alternatives based on Free and Open Source Software (FOSS), create demand for EU tech companies via public procurement, and enforce its digital rulebook to address market distortions. The S&D group position paper notes that digital sovereignty can only be secured by controlling all layers of technology, including hardware, software, and shared standards for identity and security. The document supports working towards a secure and interoperable “Digital Public Infrastructure” (DPI). The DPI should be based on European standards and designed in accordance with rights-based, privacy-respecting, and accountable principles. The EU should also reduce exposure to the extraterritorial application of third-country laws, such as the US CLOUD Act that could affect the confidentiality, accessibility and control of data stored or processed in the cloud. Funding should also go towards ethical AI, FOSS, and secure, interoperable infrastructure.

Intellectual Property

The European Commission opened a call for evidence on copyright

On 13 May, the European Commission opened a call for evidence on the review of the Copyright in the Digital Single Market (CDSM) Directive and on the EU’s copyright framework in general. The review of the CDSM Directive shall assess whether and how the Directive facilitated the use of copyright-protected content in the digital environment, improved licensing practices, and fostered a fairer copyright marketplace. Among others, the call for evidence focuses on online piracy of live events, which remains a problem for the creative and sports sectors. The call for evidence notes that increasingly, online piracy takes place through IPTV and specialised apps, in addition to websites. Without intervention, online piracy would remain the same or increase due to the professionalisation and accessibility of services providing access to pirated content. For this reason, additional actions will be explored, including improving enforcement actions available to rightsholders, with a special focus on live content. The review of the CDSM Directive should be accompanied by an external study. The call for evidence is open until 25 June 2026, with the expected introduction of the follow-up legislative initiative in Q1 2027.

Financial regulation

The European Commission opened a targeted consultation on the review of the Regulation on the Markets in Crypto Assets

On 20 May, the European Commission opened a targeted consultation on the review of the Regulation on the Markets in Crypto-Assets (MiCA). The consultation intends to evaluate MiCA in light of market and policy developments since its application. The result of the consultation will be a Commission report on MiCA application that may be accompanied by a new legislative proposal to amend and complement the existing Regulation if needed. The consultation notes that financial regulation should remain technology-neutral, to guarantee the freedom of choice for market participants. Furthermore, the Commission services consider that the review of the Payment Services Directive has largely addressed and clarified issues emerging from the interplay between the payment services legislation and MiCA. Among other areas of concern, the consultation also asks for feedback with regard to cross-border enforcement and supervisory challenges within the EU. The consultation is open until 31 August 2026.

Artificial Intelligence

The European Commission published the Cloud and AI Development Act

On 3 June, the European Commission published the Cloud and AI Development Act. The aim of the proposal is to address the limited and geographically concentrated availability of computing capacity in the EU and the risks associated with dependence on non-EU cloud and AI. The EU’s limited data centre capacity poses a threat to its ability to benefit from the digital transformation, as this lack of capacity forces EU companies to rely on foreign cloud infrastructure, which accounts for 85% of the market. Specifically, the proposal aims to increase computing capacity and AI developed and deployed in the EU; ensure attractive conditions for cloud and AI deployment; address concerns regarding data sovereignty and operational continuity of cloud and AI, including via a single EU-wide sovereignty framework; and make the supply of cloud computing services more resilient with a particular focus on the public sector. The proposal introduces four assurance levels for cloud service providers. Level 1 includes obligations on data processing and storage in the EU, while level 4 providers should have full transparency and control over their software supply chain with no interference from a third country. To determine which assurance level is needed, Member States and the EU institutions shall carry out risk assessments to identify the public sector activities intending to rely on cloud, which contribute to the preservation of public order in sectors of high criticality and other critical sectors under the NIS 2 Directive, and in the area of national security, among others. EU entities and public sector bodies whose activities do not contribute to the preservation of public order shall use cloud services with an assurance level of 1. Otherwise, the public sector entities are obliged to use cloud services with the assurance levels of 2-4. Entities operating in the sector of high criticality under the NIS 2 Directive, which are not a part of the public sector, may carry out similar impact assessments. The Commission may oblige NIS 2 entities to adopt similar risk mitigation measures through a delegated act, after consultation with the Member States. The EU and Member States shall also encourage the reuse of open standards and components released under an open source license when building their cloud and AI ecosystems.

The European Parliament and Council of the EU agreed on the AI Omnibus

On 7 May, the European Parliament and the Council of the EU concluded the interinstitutional negotiations on the AI Omnibus (see our previous reporting here). The co-legislators agreed to add a new provision prohibiting AI practices of generating non-consensual sexual and intimate content or child sexual abuse material. The AI Omnibus sets a fixed timeline for the delayed application of rules applicable to high-risk AI systems, such as those on risk management systems or transparency obligations, with the new dates being 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products. The latest text reinstates the obligation for providers of AI systems to register in a EU database for high-risk AI systems, and apply the standard of strict necessity for the processing of special categories of personal data for bias detection and correction. The next steps are formal votes in the Parliament and the Council of the EU.

Cybersecurity

ENISA published the NIS360 report

On 28 May, ENISA published a NIS360 report, providing insight into the cybersecurity maturity of NIS sectors of high criticality (see our previous reporting here). The digital infrastructure sector is central to the functioning of most essential services. Telecommunications and trust services remain the most mature sub-category within the digital infrastructure sector, while core internet (incl. TLD registries), cloud, and data centres are at an upper-moderate level. The overall maturity level for the core internet has not improved since the last assessment. The report notes that the digital infrastructure sector has strong interdependence among its sub-sectors and relies on third-party providers and complex supply chains. It also notes that targeted cyber activities exploiting vulnerable network devices to manipulate traffic remain a persistent threat to telecom and core infrastructure. With regards to policy framework and guidance, the core internet has a moderate maturity level. In terms of risk management and good practices, the report notes that governance in the digital infrastructure sector is generally well established, with most entities having defined roles and responsibilities and formal cybersecurity policies. With regard to collaboration and information sharing, the core internet has a high level of maturity, thanks in part to systematic engagement in ISACs and industry associations. The report notes that “[c]ore internet services benefit from largely community-driven arrangements for collaboration”. In terms of operational preparedness, the core infrastructure is considered to have moderate maturity. The report also suggests that entities in the digital infrastructure sector should improve risk mitigation by prioritising and addressing risks in practice through a more consistent implementation of security measures. These include vulnerability patching, network segmentation, and data security. The entities should also regularly test incident response, business continuity, and disaster recovery plans.

The NIS Cooperation Group adopted common templates for incident reporting

On 26 May, the NIS Cooperation Group adopted common templates for incident reporting under the NIS 2 Directive. The adoption took place during the 39th Plenary meeting in Cyprus. The templates attempt to provide “a clear, uniform format for reporting cyber incidents”, and aim to reduce “efficiently the administrative burden of companies”. As a next step, the European Commission plans to adopt these templates through an implementing act, making them mandatory for all Member States. The agreed common templates have not yet been made publicly available.

Published By Filip Lukáš
Filip is the Policy Advisor at CENTR, advising members on relevant EU policy and liaising with governments, institutions and other organisations in the internet ecosystem.
Published By Polina Malaja
Polina Malaja is the Policy Director at CENTR, leading its policy work and liaising with governments, institutions and other organisations in the internet ecosystem.