The Regulatory Stack Is Growing. Your Architecture Should Too.
Five years ago, GDPR was the only EU regulation most software teams cared about. That era is over.
Six major EU regulations now shape how software gets built, deployed, and operated across Europe. GDPR. The AI Act. NIS2. DORA. The Data Act. And the Cyber Resilience Act.
On top of that sit two different files both nicknamed “Digital Omnibus,” and mixing them up is the fastest way to plan against the wrong deadline. The Digital Omnibus on AI is law: Regulation (EU) 2026/1744 entered into force on July 27, 2026 and rewrote the AI Act’s timeline. The other one, aimed at GDPR and ePrivacy, is still just a proposal sitting in the Council.
Most of the stack is already in force. The rest lands between now and 2028.
Miss a deadline, and you’re looking at fines up to 7% of global revenue. Not theoretical. The EDPB’s 2025 annual report puts that year’s fines at around €1.15 billion, with TikTok’s €530 million from Ireland’s DPC for unlawful transfers to China as the headline case.
France piled on separately, under a different law. The CNIL fined Google €325 million and Shein €150 million in September 2025 for dropping cookies without valid consent, and in Google’s case for injecting ads between Gmail messages too. Those run on the ePrivacy rules rather than GDPR.
The enforcement machinery is running.
This guide maps the regulatory terrain for software teams. Not legal theory. Practical requirements, real deadlines, and architecture patterns that keep you compliant.
GDPR in 2026: Still the Foundation, But Evolving
GDPR turns eight this year. Most teams think they’ve got it covered. Many don’t.
The Commission’s Digital Omnibus proposal for GDPR and ePrivacy (November 2025) is the half of the package that has gone nowhere fast. The EDPB and EDPS issued a joint opinion in February 2026 backing simplification while flagging concerns. Since then it has sat in a Council working party absorbing compromise texts.
No general approach. No trilogue. No adoption date.
The narrower definition of “personal data,” the most contested change in the package, is still unresolved. So is the Records of Processing Activities exemption that would lift the threshold from organizations under 250 employees to those under 750. If you were counting on that relief, keep maintaining your RoPA.
Plan for the GDPR you have, not the one the Omnibus keeps promising.
Enforcement, meanwhile, is intensifying around dark patterns, AI-driven processing, and consent manipulation. The EDPB’s 2026 coordinated enforcement priority is transparency under Articles 12-14. Regulators are specifically targeting software design choices that nudge users toward sharing more data than necessary.
What this means for your architecture:
- Consent management needs granular controls and immutable audit trails. Not a cookie banner. A real system that tracks what each user agreed to, when, and for what purpose.
- Right to deletion (Article 17) requires cascade deletion across every system that holds a copy. Backups included. If your data lives in six microservices and a data warehouse, you need deletion logic in all seven.
- Data portability (Article 20) means export APIs in structured, machine-readable formats. JSON or CSV, available on demand.
For a deeper dive into building privacy into your stack from the start, see our guide on GDPR-compliant software architecture.
The EU AI Act: The Postponement Is Law. Here’s the New Timeline.
The EU AI Act is the world’s first major AI regulation, and its timeline changed this summer. Not as a proposal. As binding law.
The Digital Omnibus on AI was published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744 and entered into force three days later. It moved the deadline most teams were building toward.
Annex III high-risk obligations now apply from December 2, 2027. That’s an extra sixteen months on the deadline everyone was panicking about. AI acting as a safety component of products already regulated under Annex I slips a year, to August 2, 2028.
Transparency is the part that didn’t move. Article 50 duties have applied since August 2, 2026. Article 50(2) machine-readable marking of AI-generated content applies from August 2, 2026 for systems placed on the market from that date, and generative systems already on the market before then have until December 2, 2026.
The Omnibus also added obligations instead of only relaxing them. New Article 5 bans on AI systems that generate non-consensual intimate imagery and child sexual abuse material apply from December 2, 2026.
Everything already in force stayed in force. Prohibited AI practices became illegal in February 2025. General-purpose AI obligations followed on August 2, 2025, and the penalty framework went live the same day.
So the extra time is real. It’s also narrower than the headlines suggested, and nothing you were already violating got forgiven.
If your system uses social scoring, real-time biometric surveillance in public spaces, or exploitation of vulnerable groups, you’re already in violation. That date passed in February 2025.
The risk categories matter
The Act classifies AI systems into four tiers:
- Unacceptable risk. Banned outright. Social scoring, manipulative AI targeting vulnerable groups, untargeted facial recognition databases.
- High risk. Heavy obligations for AI in hiring, credit scoring, critical infrastructure, education, law enforcement, and migration. Conformity assessments, technical documentation, human oversight, and EU database registration are all required.
- Limited risk. Transparency requirements. Chatbots must disclose they’re AI, deepfakes need machine-readable watermarks, and emotion recognition systems must notify users.
- Minimal risk. No specific obligations. Most business software falls here.
The catch: “AI system” is defined broadly. Traditional machine learning, rule-based systems under certain conditions, and even some advanced analytics could qualify.
Bitkom found German enterprise AI use jumped from 17% in 2025 to 41% in 2026. It doubled in a single year.
But most still have no formal inventory. Without one, risk classification is guesswork.
Most SMBs are deployers, not providers. Your obligations are lighter, but they still include transparency, human oversight for high-risk systems, and AI literacy training for your team. Article 4’s literacy duty has been in force since February 2025.
Fines for non-compliance reach EUR 35 million or 7% of global annual revenue. Whichever is higher.
Two later deadlines sit behind the Annex III date, and they’re easy to conflate.
Full GPAI compliance for models placed on the market before August 2025 is still due August 2, 2027. That one did not move. Article 6(1) obligations, covering high-risk AI embedded in regulated products, went out to August 2, 2028.
Read our detailed AI Act breakdown for software teams.
NIS2: Cybersecurity Is Now a Board-Level Responsibility
Germany adopted NIS2 into national law on December 6, 2025. No transition period. The statutory BSI registration deadline of March 6, 2026 has passed, and so has the grace period the BSI granted to July 31, 2026. If you qualified and didn’t register, you’re behind.
The scope expansion is dramatic. The number of regulated entities in Germany jumped from roughly 4,500 to around 29,500. Eighteen industry sectors are now covered: energy, transport, health, digital infrastructure, ICT service management, public administration, food, manufacturing, chemicals, and waste management.
Germany isn’t an outlier in pace, just in execution. In spring 2025, the European Commission sent reasoned opinions to 19 member states for failing to notify full NIS2 transposition. If you operate across the EU, your compliance baseline shifts country by country.
Italy moved early. France, Spain, the Netherlands, and others are still catching up.
Two categories of entities exist:
- Essential entities. Large organizations in critical sectors. Fines up to EUR 10 million or 2% of global annual revenue.
- Important entities. Medium-sized organizations in a broader set of sectors. Lower fines, but the same technical requirements.
What NIS2 demands from your software
The technical requirements are concrete. Risk management measures must address: risk analysis for information systems, incident detection and response, business continuity and backup management, supply chain security, network security and access control, encryption, vulnerability management, and cyber hygiene training.
Incident reporting follows a strict timeline. You have 24 hours to submit an initial notification after becoming aware of a significant incident. A full report is due within 72 hours.
And cybersecurity is no longer just an IT department concern. Management bodies carry personal liability for compliance failures.
Every in-scope entity must register with the BSI (Germany’s Federal Office for Information Security) within three months of qualifying. Registration happens via the BSI portal that opened on January 6, 2026, using an Elster organization certificate.
Our NIS2 compliance technical guide walks through the architecture patterns and implementation steps.
The EU Data Act: Access by Design Is Live Now
The EU Data Act has been in application since September 12, 2025. The unfair-terms ban on data-sharing contracts kicked in then. So did the cloud-switching rules with their three-year transition.
The milestone that hits product teams has already passed. Since September 12, 2026, every connected product newly placed on the EU market has had to incorporate “access by design” under Article 3(1).
If you build or sell IoT devices, connected machinery, smart home products, or any hardware that generates data during use, this applies to you.
The core requirement: users must be able to access their data “easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, continuously and in real time.” That’s a direct quote from the regulation.
This covers both personal and non-personal data. Raw sensor outputs. Pre-processed information. Everything generated during product use.
Related services are also in scope. Mobile apps, cloud analytics platforms, and remote control systems that enable connected products to function must facilitate data access, not restrict it.
The business model implications are significant. If your revenue depends on locking users into your data ecosystem, the Data Act forces a rethink. Data portability and third-party access become mandatory.
For a technical breakdown of what this means for your product architecture, see The EU Data Act: What It Means for Connected Products and IoT.
DORA and the Cyber Resilience Act: Two More You Should Know
Two regulations that didn’t exist for most teams a year ago now do.
DORA, the Digital Operational Resilience Act, has been in application since January 17, 2025. It covers banks, insurers, payment institutions, crypto-asset service providers, and the ICT vendors that serve them.
The five pillars: ICT risk governance, incident reporting, third-party risk registers, threat-led penetration testing, and information sharing. Penalties hit 2% of annual worldwide turnover for financial entities, 1% of average daily turnover for designated critical ICT providers.
If you build software for European finance, DORA is already shaping your contracts.
The Cyber Resilience Act is the broader play. It applies to almost any product with digital elements sold in the EU. The CRA entered into force on December 10, 2024, with a phased application schedule.
The first phase is already live. Article 14 reporting for actively exploited vulnerabilities and severe incidents has applied since September 11, 2026. Full compliance for all new products lands on December 11, 2027.
If you ship hardware, firmware, or even certain SaaS components into the EU, mark these dates.
How These Regulations Overlap (And Why That Helps)
Here’s something most compliance guides miss: these regulations are converging, not diverging.
The pending Data Omnibus proposal aims to consolidate breach reporting. Instead of filing separate reports under GDPR, NIS2, and DORA, the plan is a unified reporting mechanism through ENISA. One report, multiple regulators.
AI Act enforcement is moving the other way, toward the centre. Regulation (EU) 2026/1744 rewrote Article 75 to give the AI Office supervisory competence over AI systems built on a general-purpose model from the same provider, and over AI embedded in the very large platforms already supervised under the DSA. Data protection authorities keep the narrower role they already had under Article 74(8), over high-risk systems in biometrics, law enforcement, migration and justice.
NIS2 and GDPR align on security measures. If your architecture meets NIS2’s technical requirements for encryption, access control, and monitoring, you’re covering most of GDPR’s security obligations too.
This convergence is good news for teams that build compliance into their architecture rather than bolting it on regulation by regulation.
Building Compliance Into Your Architecture
Compliance as an afterthought costs 5-10x more than compliance by design. That’s not a guess. It’s what we see in every project where security and privacy were “phase two.”
Privacy by design
Data minimization isn’t just a GDPR principle. It’s good architecture. Collect only what you need. Store it only as long as necessary.
Encrypt it at rest and in transit. Field-level encryption for PII. Pseudonymization where full identification isn’t required.
Security by design
NIS2 and DORA demand it. But even without regulation, zero-trust architecture, network segmentation, and immutable audit logging are baseline requirements for any production system in 2026. If your deployment doesn’t have centralized security logging and anomaly detection, you’re behind.
Audit trails everywhere
Every regulation requires demonstrating compliance. That means logging who accessed what, when, and why. Immutable logs. Tamper-evident storage. Retention policies that match your regulatory obligations.
Read more about embedding security into your development process in our Security by Design guide.
Data Residency: Where Your Data Lives Matters
GDPR doesn’t strictly require EU data residency. But the practical reality in 2026 makes it the simplest compliance path.
The US CLOUD Act allows US law enforcement to compel US-based companies to hand over data regardless of where it’s physically stored. Storing data in Frankfurt with a US-owned hyperscaler doesn’t guarantee sovereignty.
For regulated industries (healthcare, finance, government), data sovereignty is increasingly non-negotiable. DORA requires financial institutions to manage third-party ICT concentration risk. Relying entirely on a single US hyperscaler is now a compliance problem.
European cloud alternatives exist: OVHCloud, Hetzner, IONOS, Scaleway. They’re not AWS or Azure in feature breadth, but for many workloads, they’re more than sufficient. Hybrid architectures (EU-sovereign for sensitive data, hyperscaler for everything else) are the pragmatic middle ground.
Our guide on data residency in the EU covers the decision framework in detail.
Your Compliance Checklist: What to Do Now vs. What Can Wait
Already binding (go check you actually do these)
-
AI Act transparency. Since August 2, 2026: chatbots must disclose they’re AI, emotion recognition and biometric categorisation systems must tell the people subjected to them, and deepfakes must be disclosed as artificially generated. Article 50(2) marking covers any generative AI system you’ve placed on the market since that date.
-
Data Act access by design. Connected products placed on the EU market since September 12, 2026 must let users pull their data out, free and in real time.
-
CRA incident reporting. Article 14 pipelines for actively exploited vulnerabilities and severe incidents have been live since September 11, 2026.
-
NIS2 registration. Germany’s statutory BSI deadline closed on March 6, 2026, and the BSI’s grace period ran out on July 31, 2026. If you qualify and missed it, register now and document the delay.
Do now
-
Inventory your AI systems. Map every ML model, automated decision system, and AI-powered feature. You can’t classify what you’ve never listed, and December 2027 is closer than it reads.
-
Audit your data flows. Know where personal data lives, who processes it, and which sub-processors are involved.
-
Review incident response. Can you detect a breach and report it within 24 hours? If not, fix that first.
Do by December 2, 2026
-
Machine-readable marking for generative AI systems you already had on the market before August 2, 2026.
-
Confirm nothing you ship falls under the new Article 5 bans on generating non-consensual intimate imagery or child sexual abuse material.
Do by August 2, 2027
- Full GPAI compliance for general-purpose AI models placed on the market before August 2025. This date did not move.
Do by December 2, 2027
- Technical documentation, human oversight mechanisms, and conformity assessments for Annex III high-risk AI systems.
Do by December 11, 2027
- Full Cyber Resilience Act compliance for any new product with digital elements sold in the EU.
Do by August 2, 2028
- Article 6(1) obligations for high-risk AI embedded in products already regulated under Annex I.
Ongoing
-
Every new feature processing personal data at scale needs a DPIA. Not optional.
-
NIS2 requires you to assess the cybersecurity posture of your vendors. Third-party risk management is now a regulatory requirement.
-
Build AI literacy (AI Act), cybersecurity hygiene (NIS2), and privacy awareness (GDPR) into onboarding.
The Bottom Line
The EU’s regulatory framework is complex. But it’s also more coherent than it looks.
The common thread across every regulation: build secure, privacy-respecting software that gives users control over their data. Document what you do and why. Report incidents quickly.
Teams that treat compliance as an architecture concern rather than a legal afterthought will spend less, move faster, and sleep better.
The deadlines aren’t slowing down. Neither should your preparation.
Navigating EU compliance for your software project? Let’s map out your requirements together. We build GDPR and AI Act-compliant software by default.



