To help organizations stay on top of the main developments in European digital compliance, Morrison Foerster’s European Digital Regulatory Compliance team reports on some of the main topical digital regulatory and compliance developments that have taken place in the third quarter of 2024.
This report follows our previous updates on European digital regulation and compliance developments for 2023 (Q1, Q2, Q3, Q4), 2024 (Q1, Q2, Q3, Q4), 2025 (Q1, Q2, Q3, Q4) and Q1 2026
In this issue, we cover a busy quarter for digital regulation across the EU, UK, and Germany. On the AI front, we examine the EU’s finalized Digital Omnibus on AI and proposed Cloud and AI Development Act, alongside new UK initiatives on AI regulation and a significant German ruling on liability for AI-generated search summaries. In online safety, we track proposed UK measures including an under-16 social media ban and restrictions on AI chatbots, as well as Germany’s recommendations on digital child safety and draft legislation targeting digital violence. We also cover broader developments affecting digital businesses, including a landmark CJEU ruling on intermediary liability, new EU consumer rules and the Commission’s first DMA review, as well as the UK’s growing focus on Smart Data, synthetic media, deepfakes, and digital verification.
1. CJEU: Landmark Judgment Further Clarifies the Scope of the Hosting Safe Harbor
3. EU Cloud and AI Development Act: Sovereignty Becomes a Market-Access Test
4. Digital Omnibus on AI: Political Agreement Resets the High-Risk Calendar
5. Commission's First DMA Review
6. Simpler, Clearer, Better Enforced: The Commission’s Plan to Overhaul the EU Rulebook
7. German Expert Commission Issues 56 Recommendations on Digital Child Safety
8. Germany Unveils Draft Legislation to Tackle Digital Violence
10. UK AI Regulation Continues with Sectoral Approach
On June 16, 2026, the Court of Justice of the European Union (CJEU or “Court”) delivered a landmark judgment providing important guidance on two cornerstones of EU digital regulation: the country-of-origin principle under the e-Commerce Directive and, more significantly, the scope of the hosting liability exemption for online intermediaries (joined cases C-188/24 and C-190/24); see our blog post.
The judgment provides important clarification on when providers may lose the hosting safe harbor under Article 14 of the e-Commerce Directive (now Article 6 of the Digital Services Act (DSA)). The Court reiterated earlier CJEU case law (notably case C-324/09), stating that the two conditions under which the liability exemption may cease to apply, i.e., “knowledge” of and “control” over user-uploaded materials, are to be understood as separate concepts. A provider may therefore exercise control over hosted content even where it has no knowledge of the specific illegal content at issue.
Regarding the concept of control, the Court held that the assessment must focus on whether the provider plays an active role in determining how content is disseminated to users. In particular, the Court pointed to the algorithmic presentation of content and to whether the provider determines the parameters governing its visibility, prioritization, or dissemination. Where it exercises such decisive influence over the distribution of content, a provider may no longer qualify as acting as a neutral intermediary and may therefore fall outside the scope of the hosting safe harbor.
Separately, the Court reaffirmed the country-of-origin principle, holding that Member States may not impose abstract and generally applicable obligations on providers established in another Member State without complying with the derogation mechanism under the e-Commerce Directive.
The judgment is likely to influence future litigation on the scope of intermediary liability under EU law. At the same time, its implications for the DSA remain uncertain. While Article 6 of the DSA largely reproduces the hosting liability exemption under the e-Commerce Directive, the DSA also expressly regulates online platforms that typically rely on algorithmic recommendation systems and other content-ranking functionalities, while at the same presupposing that such providers nonetheless benefit from the hosting safe harbor. It therefore remains to be seen how the Court’s interpretation of the concept of “control” will be reconciled with the DSA’s liability framework. Providers operating recommendation or advanced ranking systems should continue to monitor developments closely.
As of June 19, 2026, Directive (EU) 2023/2673 has become fully applicable across the EU. The Directive amends the Consumer Rights Directive 2011/83/EU by introducing an electronic withdrawal function for distance contracts concluded through an online interface and new rules for distance financial services. We tracked its proposal, adoption, and German implementation in our Q1 2023, Q4 2023, and Q4 2025 updates.
The broadest change is the electronic withdrawal function. For distance contracts concluded through an online interface and subject to a right of withdrawal, traders must enable consumers to withdraw online. The function must remain available throughout the withdrawal period, be prominent and easily accessible, and use “withdraw from contract here” or an unambiguous equivalent. Consumers must submit their withdrawal statement through a confirmation function. The trader must then acknowledge receipt without undue delay on a durable medium, including the content of the statement and the date and time of its submission. As previously reported in our Q1 2023 update, these requirements apply to all distance contracts generally.
The Directive also modernizes rules specifically applicable to distance financial services. It introduces updated pre-contractual information requirements, a right for consumers to request human intervention where traders rely on fully automated online processes, and an express prohibition on using online interfaces that manipulate or materially impair the consumers’ ability to make a free and informed decision. These changes are now integrated into the Consumer Rights Directive, repealing the Consumer Financial Services Directive 2002/65/EC.
Although Member States were required to adopt and publish their implementing measures by December 19, 2025 and apply them from June 19, 2026, the pace of implementation has varied across the EU. As a result, businesses operating across multiple Member States should verify the national rules applicable in each market in which they operate. This is particularly important because, unlike EU regulations, directives generally need to be transposed into national law before they impose obligations on private businesses. Where implementation is incomplete, existing national law may nevertheless apply and should, where possible, be interpreted consistently with the Directive.
On June 3, 2026, the European Commission published its proposal for the Cloud and AI Development Act (CADA), a key pillar of its broader European Technological Sovereignty Package. Alongside measures to boost European cloud and data center capacity, CADA introduces a new EU-wide framework for assessing the “sovereignty” of cloud services, potentially reshaping access to strategically important public-sector contracts; see our detailed alert.
CADA would translate the EU’s sovereignty ambitions into a detailed set of requirements for cloud providers. Key elements include:
Cloud and AI providers should start assessing their position under the proposed sovereignty levels, including EU establishment, data location, subcontractor controls, and software supply chains. Providers under third-country control should also monitor whether their home jurisdiction could qualify as an “associated third country.” The proposal may still change as it moves through the legislative process, but with technological sovereignty at the top of the EU agenda, companies should prepare for potentially fast-moving legislation and a market in which being “sovereign-ready” increasingly matters.
In Q2, EU lawmakers reached an agreement on the Digital Omnibus on AI. Following a political agreement during the night of May 6–7, the European Parliament adopted the compromise on June 16 and the Council of the European Union approved it on June 29. The separate Digital Omnibus on the Digital Acquis remains in a distinct legislative procedure.
When we last reported in our 2026 Q1 Update, trilogue negotiations were still under way and several issues remained unresolved. Those negotiations have now concluded, and the final text confirms the agreed amendments.
Key changes to the AI Act include the following:
While the Digital Omnibus on AI entered into force as Regulation (EU) 2026/1744 on July 27, 2026, postponing the application of core high-risk rules, several key AI Act requirements still took effect on August 2, 2026. These include the transparency obligations under Article 50—requiring certain AI systems and AI-generated or manipulated content to be appropriately disclosed—as well as the Commission’s enforcement powers for providers of general-purpose AI models. The existing rules on prohibited AI practices and the AI literacy obligation continue to apply, albeit with a different scope.
On April 28, 2026, the European Commission published its first review of the Digital Markets Act (DMA). The headline message is clear: the DMA is working as intended. While implementation is still at an early stage, the Commission concludes that the Regulation has already made digital markets fairer and more contestable and does not currently require legislative amendments. Instead, the focus will shift towards rigorous enforcement, practical guidance, and ensuring the DMA remains fit for emerging technologies such as AI and cloud services.
Nearly two years into the DMA’s application, the Commission concludes that the new regulatory framework is beginning to deliver tangible results. The review highlights several key findings and priorities for the next phase of implementation:
The review confirms that the Commission’s priority is now effective implementation rather than new legislation. While legislative reform is off the table for now, businesses should expect further guidance and active enforcement as the Commission seeks to unlock the Regulation’s full potential. Looking ahead, the Commission will focus on ensuring that the DMA keeps pace with rapidly evolving digital markets, particularly in the areas of AI and cloud computing.
On April 28, 2026, the European Commission published a communication titled “A Simpler, Clearer and Better Enforced EU Rulebook” (COM(2026) 380). Regarded as the most ambitious reform of EU policymaking since the Better Regulation agenda launched in 2002, the communication sets out a strategy to modernize how EU laws are designed, implemented, and enforced.
The Commission’s key actions are organized around five pillars:
1. Simplicity by design
To prevent fragmentation from the outset, the Commission will prioritize exhaustive regulations and full harmonization for single-market issues, where legally feasible. It also aims to embed enforcement by design, including through sunset clauses paired with standardized monitoring mechanisms.
2. A better regulation framework
The Commission will require proportionate impact assessments for a broader range of initiatives, reviewed by the Regulatory Scrutiny Board. It will enhance stakeholder engagement through earlier consultations and calls on co-legislators to adopt a common methodology for assessing the cost impact of substantial amendments, bringing transparency to compliance cost drivers that currently emerge late in the legislative process.
3. Regulatory deep cleaning
Under the Action Plan for Regulatory Deep Cleaning, 12 priority areas, including free movement of goods and services, financial services, customs, taxation, digital, energy, and transport, will be examined in 2026–2027 to reduce complexity. A review of delegated and implementing acts has already led to approximately 30% of planned acts for 2026 being deprioritized. A new Simplification Platform will convene national authorities, social partners, businesses, and civil society to guide these efforts.
4. Tackling gold-plating
To help Member States identify and avoid imposing stricter national requirements than EU law mandates, thereby raising costs and distorting competition (gold-plating), the Commission will develop a best-practices toolkit and enhance detection through the European Semester and the Single-Market Enforcement Taskforce.
5. Faster and more robust enforcement
The Commission has identified 11 single-market focus areas in which it will proactively investigate Member States and pursue infringement procedures. AI tools will be piloted in 2026 to accelerate national transposition checks, and the Commission will propose systematically higher financial penalties to strengthen deterrence.
The new approach will now be implemented gradually, pending revision of the Better Regulation Guidelines and Toolbox. The regulatory environment is set to become simpler in design and stricter in enforcement.
On June 24, 2026, the Independent Expert Commission on “Child and Youth Protection in the Digital World,” established in September 2025 by the German Ministry of Education, Family, Senior Citizens, Women, and Youth, published 56 recommendations on digital child safety.
The recommendations build on a status report published in April 2026 and are structured based on two complementary perspectives: a development-oriented perspective spanning six life phases from birth to adulthood and a responsibility-based perspective assigning accountability to specific actors. Both are connected by the central triad of protection, empowerment, and participation.
Key compliance-related recommendations include:
The Commission calls for all recommendations to be consolidated into a coherent strategy for digital child and youth protection, accompanied by an immediate action program by end of 2026, structured implementation formats, a digital feedback channel, and binding impact monitoring. A permanent interdisciplinary expert panel is to be established to monitor developments, advise policymakers, and track implementation progress. It is yet unclear whether, to what extent, and at what legislative level the German government will actually pursue these recommendations.
On April 16, 2026, the German Federal Ministry of Justice published the ministerial draft of the Act Against Digital Violence (Gesetz zur Stärkung des zivilrechtlichen und strafrechtlichen Schutzes vor digitaler Gewalt (“GgdG”); see our detailed alert). The proposal responds to rising levels of online abuse and persistent enforcement gaps, particularly in light of evolving technologies such as AI-generated deepfakes. Instead of expanding content moderation obligations, the draft shifts the focus from platform-led moderation to court-led enforcement, while introducing targeted new criminal offenses.
The draft introduces a number of notable changes, including:
The stakeholder consultation has concluded and the draft is expected to proceed through the German legislative process later this year. Although amendments remain possible, platforms should begin assessing whether their internal processes are capable of responding efficiently to judicial disclosure, evidence preservation, and account-related orders.
On May 28, 2026, the Regional Court of Munich I (LG München I) issued a noteworthy judgment addressing liability for AI-generated search summaries. The case concerned allegedly defamatory statements generated by an online search engine’s “AI Overview” feature and provides important guidance on the application of the Digital Services Act (DSA) to generative AI outputs.
The Court held that the AI Overview constituted the provider’s own attributable content rather than a mere reproduction of third-party information. While the AI Overview was based on information available on third-party websites, it independently summarized, combined, and evaluated that information, presenting it as a new, self-contained narrative. In the Court’s view, this distinguished AI Overviews from traditional search results or autocomplete suggestions, which merely facilitate access to third-party content.
On that basis, the Court rejected the provider’s reliance on the hosting liability exemption under Article 6(1) of the Digital Services Act (DSA). According to the Court, the AI-generated summary was not information stored at the request of a recipient of the service, but rather new content generated by the provider’s own AI system. Consequently, the provider could not benefit from the reduced liability framework applicable to hosting providers or the notice-and-action regime under the DSA.
The Court further distinguished existing German case law limiting liability for traditional search engines, reasoning that AI-generated overviews go beyond making third-party content searchable, because they independently generated answers based on the weighting, evaluation, and synthesis of information from multiple sources.
The judgment was issued in preliminary injunction proceedings and remains subject to appeal. Nevertheless, it is among the first decisions to address the liability framework applicable to AI-generated outputs and may have broader implications beyond AI-powered search. While it specifically concerned AI-generated summaries of search results, the Court’s reasoning raises the broader question of when AI-generated content should be treated as the provider’s own content rather than third-party information protected by the DSA hosting safe harbor. Providers deploying generative AI features should therefore closely monitor further judicial developments in this area.
In the second quarter of 2026, the UK government reaffirmed its preference for regulating AI through existing laws and sector regulators, using targeted secondary legislation to emphasize the ICO’s remit over AI and automated decision-making (ADM) and a new proposed bill to enable cross-economy sandboxes.
The recent Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 requires the Information Commissioner’s Office (ICO) to prepare a code of practice on AI and ADM, providing clear and practical guidance on transparency and explainability, bias and discrimination, and rights and redress. This builds on the ICO’s March 2026 AI and biometrics strategy update, which announced draft guidance on ADM and profiling (“Draft Guidance”) and also touched on ongoing scrutiny of 11 major AI foundation model developers, with whom the ICO is currently engaged to mitigate privacy harms.
More broadly, the King’s Speech in May announced a Regulating for Growth Bill (the “Bill”), which is intended to strengthen regulators’ duties to support growth and give ministers powers to issue strategic steers. The Bill would also introduce cross-economy sandbox powers, allowing existing rules to be temporarily “relaxed” under controlled conditions so that businesses can test AI and other emerging technologies in real-world settings. The government has also launched an advisory AI Growth Lab sandbox, bringing together relevant regulators to help businesses navigate existing requirements. The first sector to participate will be legal services—involving the Council for Licensed Conveyancers, the Solicitors Regulation Authority, the Information Commissioner’s Office, and the Legal Services Board—and the ICO has also announced its intention to join the collaboration.
Organizations should keep a close watch on the finalization of these initiatives (as well as the new AI Taskforce created from the recent government reshuffle). In particular, the Draft Guidance consultation closed in May and will likely be updated this year, with the statutory code of practice on AI and ADM to follow in the future.
On June 15, 2026, the UK government has announced plans to ban under-16s from accessing social media, following the model adopted by Australia in late 2024. The ban would capture platforms whose purpose is to enable social interaction through user-generated content and algorithms—including Instagram, TikTok, YouTube, Snapchat, Facebook, and X—but would exclude messaging services such as WhatsApp and Signal. However, potentially affected services face uncertainty as the new prime minister has not yet addressed these proposals, which were announced under the previous administration.
“Further than a blanket ban” – what else is proposed?
The new laws will also address other features that have been deemed harmful and include “safety-by-design” measures, as announced on July 15, 2026. These aim to prevent a “cliff edge” at 16 years of age.
When could the measures take effect?
The announcements anticipated the first regulations being laid before Parliament by the end of 2026. The government would use secondary legislation powers through the Children’s Wellbeing and Schools Act 2026, with measures expected to come into force in spring 2027.
However, both announcements were made by the previous Labour government. The succeeding administration may amend the scope of the proposals, widening the categorization of affected providers, or adding new banned functionalities.
What about the existing online safety landscape?
The proposals build on the existing framework, set out in the Online Safety Act 2023. The OSA already requires “user-to-user” services to protect children through risk assessments, age assurance, and safety-by-design measures, and Ofcom has been actively enforcing these duties (see our Q4 2025 update).
The UK is part of a broader European trend towards regulating platform design, not only access. France has combined age restrictions with digital curfew proposals for minors. Germany’s Independent Expert Commission has recommended default restrictions on algorithmic feeds and engagement-driven features (see section [7] above). At the EU level, the Digital Services Act already requires very large online platforms to mitigate risks to minors, and the proposed Digital Fairness Act is expected to address addictive design more broadly (see our Q3 2025 update).
Ofcom has been asked to conduct a study on effective age assurance for verifying whether someone is over 16, and to publish an enforcement strategy, both key building blocks for any future ban. Platforms offering social media, gaming, livestreaming, or AI chatbot services to younger users should monitor developments closely, particularly given the spring 2027 target date.
The Department for Business and Trade has published a call for evidence(“Call for Evidence”) on how Smart Data schemes should be prioritized, designed and delivered across retail, transport, trade, agrifood, and property.
Smart Data involves the secure sharing of customer data, at the customer’s request, with authorized third-party providers. A Smart Data scheme provides the policy, regulatory or contractual, technical, and governance framework for secure, standardized data sharing and may be mandatory or voluntary.
It is particularly relevant to organizations that hold or use customer, product, pricing, transaction, logistics, property, or compliance data, including retailers, transport and logistics providers, property professionals, agrifood businesses, technology companies, authorized third-party providers, regulators, and industry bodies.
The Data (Use and Access) Act 2025 (DUAA) gives the government powers to introduce legal requirements for the creation and governance of data-sharing schemes. Following publication of the Smart Data 2035 Strategy, the government is now moving from strategy into scheme design and delivery. Its targets are to establish five or more active Smart Data schemes by 2030 and at least 20 interoperable schemes by 2035.
The potential use cases remain exploratory. Before any regulatory change, they will be subject to feasibility and design work, including assessment of data availability, governance models, and legal applicability under the DUAA, followed by formal consultation.
What does the Call for Evidence cover?
The Call for Evidence seeks views on sector readiness, potential use cases, scheme design, cross-economy alignment, governance and international best practice:
Across all sectors, the government is seeking evidence on data quality and availability, commercial incentives, technical and contractual barriers, cybersecurity, liability, competition, and impacts on SMEs and new entrants. It also considers cross-sector standards, accreditation, accountability, consumer protection, and redress, together with lessons from overseas schemes and opportunities for international alignment.
The Call for Evidence closes at 11:59 p.m. on October 1, 2026. A high-level summary is expected in early 2027, followed by sector-specific publications during 2027. A separate consultation on long-term, cross-economy governance is also planned for early 2027, and any use cases taken forward will be subject to formal consultation before regulatory change.
Affected organizations should consider what relevant data they hold, whether it is accurate and available in standardized formats, and what technical, contractual, or commercial barriers could affect future sharing. They should also assess how participation could affect existing operating models, data-based services, and relationships with customers, suppliers, and third-party providers.
The Digital Regulation and Co-operation Forum (DRCF)—a cross-sector body made up of the UK Competition and Markets Authority, Ofcom, the Information Commissioner’s Office, and the Financial Conduct Authority—has launched its latest call for input (the “Consultation”).
The Consultation focuses on the theme of digital authentication and trust, specifically in the following areas:
The call for input closes on August 14, 2026, after which the DRCF will analyze responses and may convene further webinars, roundtables, and other stakeholder engagement activities. While no immediate regulatory obligations are expected to arise from the exercise, the Consultation provides a clear indication that synthetic media, deepfakes, and digital verification technologies are becoming strategic priorities across the UK’s digital regulatory landscape.
For businesses developing or deploying AI-generated content, identity verification, or authentication technologies, the Consultation offers an early opportunity to help shape regulatory expectations before more formal guidance or regulatory interventions emerge. Organizations should also expect increasing collaboration among the DRCF member regulators, as these technologies continue to blur the traditional boundaries between privacy, online safety, consumer protection, financial regulation, and competition law.
Marcus Holding London Trainee Solicitor and Berlin research assistants Felicitas Lampe and Nina Funke contributed to the drafting of these alerts.