European Digital Compliance: Key Digital Regulation & Compliance Developments
To help organizations stay on top of the main developments in European digital compliance, Morrison Foerster’s European Digital Regulatory Compliance team reports on some of the main topical digital regulatory and compliance developments that have taken place in the third quarter of 2024.
This report follows our previous updates on European digital regulation and compliance developments for 2023 (Q1, Q2, Q3, Q4), 2024 (Q1, Q2, Q3, Q4), 2025 (Q1, Q2, Q3, Q4) and Q1 2026
In this issue, we cover a busy quarter for digital regulation across the EU, UK, and Germany. On the AI front, we examine the EU’s finalized Digital Omnibus on AI and proposed Cloud and AI Development Act, alongside new UK initiatives on AI regulation and a significant German ruling on liability for AI-generated search summaries. In online safety, we track proposed UK measures including an under-16 social media ban and restrictions on AI chatbots, as well as Germany’s recommendations on digital child safety and draft legislation targeting digital violence. We also cover broader developments affecting digital businesses, including a landmark CJEU ruling on intermediary liability, new EU consumer rules and the Commission’s first DMA review, as well as the UK’s growing focus on Smart Data, synthetic media, deepfakes, and digital verification.
EU
1. CJEU: Landmark Judgment Further Clarifies the Scope of the Hosting Safe Harbor
3. EU Cloud and AI Development Act: Sovereignty Becomes a Market-Access Test
4. Digital Omnibus on AI: Political Agreement Resets the High-Risk Calendar
5. Commission's First DMA Review
6. Simpler, Clearer, Better Enforced: The Commission’s Plan to Overhaul the EU Rulebook
DE
7. German Expert Commission Issues 56 Recommendations on Digital Child Safety
8. Germany Unveils Draft Legislation to Tackle Digital Violence
UK
10. UK AI Regulation Continues with Sectoral Approach
EU
1. CJEU: Landmark Judgment Further Clarifies the Scope of the Hosting Safe Harbor
On June 16, 2026, the Court of Justice of the European Union (CJEU or “Court”) delivered a landmark judgment providing important guidance on two cornerstones of EU digital regulation: the country-of-origin principle under the e-Commerce Directive and, more significantly, the scope of the hosting liability exemption for online intermediaries (joined cases C-188/24 and C-190/24); see our blog post.
What’s new?
The judgment provides important clarification on when providers may lose the hosting safe harbor under Article 14 of the e-Commerce Directive (now Article 6 of the Digital Services Act (DSA)). The Court reiterated earlier CJEU case law (notably case C-324/09), stating that the two conditions under which the liability exemption may cease to apply, i.e., “knowledge” of and “control” over user-uploaded materials, are to be understood as separate concepts. A provider may therefore exercise control over hosted content even where it has no knowledge of the specific illegal content at issue.
Regarding the concept of control, the Court held that the assessment must focus on whether the provider plays an active role in determining how content is disseminated to users. In particular, the Court pointed to the algorithmic presentation of content and to whether the provider determines the parameters governing its visibility, prioritization, or dissemination. Where it exercises such decisive influence over the distribution of content, a provider may no longer qualify as acting as a neutral intermediary and may therefore fall outside the scope of the hosting safe harbor.
Separately, the Court reaffirmed the country-of-origin principle, holding that Member States may not impose abstract and generally applicable obligations on providers established in another Member State without complying with the derogation mechanism under the e-Commerce Directive.
What’s next?
The judgment is likely to influence future litigation on the scope of intermediary liability under EU law. At the same time, its implications for the DSA remain uncertain. While Article 6 of the DSA largely reproduces the hosting liability exemption under the e-Commerce Directive, the DSA also expressly regulates online platforms that typically rely on algorithmic recommendation systems and other content-ranking functionalities, while at the same presupposing that such providers nonetheless benefit from the hosting safe harbor. It therefore remains to be seen how the Court’s interpretation of the concept of “control” will be reconciled with the DSA’s liability framework. Providers operating recommendation or advanced ranking systems should continue to monitor developments closely.
2. Distance Financial and Other Services: EU Withdrawal Function and Related Consumer Rules Now Apply
As of June 19, 2026, Directive (EU) 2023/2673 has become fully applicable across the EU. The Directive amends the Consumer Rights Directive 2011/83/EU by introducing an electronic withdrawal function for distance contracts concluded through an online interface and new rules for distance financial services. We tracked its proposal, adoption, and German implementation in our Q1 2023, Q4 2023, and Q4 2025 updates.
What’s new?
The broadest change is the electronic withdrawal function. For distance contracts concluded through an online interface and subject to a right of withdrawal, traders must enable consumers to withdraw online. The function must remain available throughout the withdrawal period, be prominent and easily accessible, and use “withdraw from contract here” or an unambiguous equivalent. Consumers must submit their withdrawal statement through a confirmation function. The trader must then acknowledge receipt without undue delay on a durable medium, including the content of the statement and the date and time of its submission. As previously reported in our Q1 2023 update, these requirements apply to all distance contracts generally.
The Directive also modernizes rules specifically applicable to distance financial services. It introduces updated pre-contractual information requirements, a right for consumers to request human intervention where traders rely on fully automated online processes, and an express prohibition on using online interfaces that manipulate or materially impair the consumers’ ability to make a free and informed decision. These changes are now integrated into the Consumer Rights Directive, repealing the Consumer Financial Services Directive 2002/65/EC.
What’s next?
Although Member States were required to adopt and publish their implementing measures by December 19, 2025 and apply them from June 19, 2026, the pace of implementation has varied across the EU. As a result, businesses operating across multiple Member States should verify the national rules applicable in each market in which they operate. This is particularly important because, unlike EU regulations, directives generally need to be transposed into national law before they impose obligations on private businesses. Where implementation is incomplete, existing national law may nevertheless apply and should, where possible, be interpreted consistently with the Directive.
3. EU Cloud and AI Development Act: Sovereignty Becomes a Market-Access Test
On June 3, 2026, the European Commission published its proposal for the Cloud and AI Development Act (CADA), a key pillar of its broader European Technological Sovereignty Package. Alongside measures to boost European cloud and data center capacity, CADA introduces a new EU-wide framework for assessing the “sovereignty” of cloud services, potentially reshaping access to strategically important public-sector contracts; see our detailed alert.
What’s new?
CADA would translate the EU’s sovereignty ambitions into a detailed set of requirements for cloud providers. Key elements include:
- Four levels of sovereignty: At the heart of the proposal is a new four-tier classification system with progressively stricter Union Assurance Levels (“UAL 1” through “UAL 4”). UAL 1 focuses on EU-based data processing and storage, while UAL 2 adds stronger cybersecurity and software supply-chain requirements. UAL 3 introduces stricter personnel and ownership-control restrictions and UAL 4 sets the highest bar, including enhanced safeguards against third-country interference and greater control over software components.
- Recognition and ongoing scrutiny: Cloud services would need formal recognition at each UAL. While UAL 1 relies on self-assessment, UALs 2–4 require independent audits and annual reviews, turning recognition into an ongoing compliance exercise.
- Limited flexibility for non-EU providers: CADA provides two narrow escape routes where European cloud capacity falls short. Public authorities may exceptionally procure services below the required UAL where no suitable alternative exists or costs would be disproportionate. In addition, providers controlled from designated “associated third countries” may qualify for UAL 3.
- Part of a much bigger sovereignty push: CADA sits alongside the proposed Chips Act 2.0 and other initiatives aimed at strengthening European capabilities across semiconductors, cloud, AI, and open source. Its UAL framework draws on the Cybersecurity Act’s existing certification architecture but goes beyond technical cybersecurity by adding sovereignty criteria around control, localization, and third-country interference.
What’s next?
Cloud and AI providers should start assessing their position under the proposed sovereignty levels, including EU establishment, data location, subcontractor controls, and software supply chains. Providers under third-country control should also monitor whether their home jurisdiction could qualify as an “associated third country.” The proposal may still change as it moves through the legislative process, but with technological sovereignty at the top of the EU agenda, companies should prepare for potentially fast-moving legislation and a market in which being “sovereign-ready” increasingly matters.
4. Digital Omnibus on AI: Political Agreement Resets the High-Risk Calendar
In Q2, EU lawmakers reached an agreement on the Digital Omnibus on AI. Following a political agreement during the night of May 6–7, the European Parliament adopted the compromise on June 16 and the Council of the European Union approved it on June 29. The separate Digital Omnibus on the Digital Acquis remains in a distinct legislative procedure.
When we last reported in our 2026 Q1 Update, trilogue negotiations were still under way and several issues remained unresolved. Those negotiations have now concluded, and the final text confirms the agreed amendments.
What’s new?
Key changes to the AI Act include the following:
- The application of core high-risk rules is postponed to December 2, 2027 for Annex III systems and to August 2, 2028 for Annex I product-related systems; most other provisions remain on schedule. The Commission’s proposal to link application to harmonized standards described in our Q4 2025 update did not survive.
- Providers classifying Annex III systems as non-high-risk must still document and register that decision. Database filing is now reduced by removing the required summary of the provider’s reasoning and the list of Member States where the system is available.
- From December 2, 2026, specified AI systems that generate or manipulate realistic non-consensual intimate material involving identifiable persons or child sexual abuse material are prohibited.
- Providers and deployers must support AI literacy but do not need to guarantee a prescribed individual level.
- The AI Office gains exclusive supervision over certain same-group GPAI-based systems and systems integrated into or constituting very large online platforms or search engines under the DSA.
- The reference to machinery law moves from Annex I, Section A to Section B and is updated to Regulation (EU) 2023/1230, applicable from January 20, 2027. AI-enabled machinery may still qualify as high-risk, but the relevant AI safety requirements will be integrated into the Machinery Regulation through delegated acts, applying by August 2, 2028.
- Selected SME benefits extend to small mid-cap enterprises, including simplified technical documentation and penalty protection. Regulatory-sandbox access is expanded.
What’s next?
While the Digital Omnibus on AI entered into force as Regulation (EU) 2026/1744 on July 27, 2026, postponing the application of core high-risk rules, several key AI Act requirements still took effect on August 2, 2026. These include the transparency obligations under Article 50—requiring certain AI systems and AI-generated or manipulated content to be appropriately disclosed—as well as the Commission’s enforcement powers for providers of general-purpose AI models. The existing rules on prohibited AI practices and the AI literacy obligation continue to apply, albeit with a different scope.
5. Commission's First DMA Review
On April 28, 2026, the European Commission published its first review of the Digital Markets Act (DMA). The headline message is clear: the DMA is working as intended. While implementation is still at an early stage, the Commission concludes that the Regulation has already made digital markets fairer and more contestable and does not currently require legislative amendments. Instead, the focus will shift towards rigorous enforcement, practical guidance, and ensuring the DMA remains fit for emerging technologies such as AI and cloud services.
What’s new?
Nearly two years into the DMA’s application, the Commission concludes that the new regulatory framework is beginning to deliver tangible results. The review highlights several key findings and priorities for the next phase of implementation:
- The DMA remains fit for purpose: Despite calls from some stakeholders for legislative changes, the Commission concludes that the existing framework remains appropriate and that its built-in “future-proofing” mechanisms are sufficient to address evolving digital markets.
- Early benefits are becoming visible: The review highlights increased user choice, greater data portability, improved interoperability, more transparent digital advertising, and new business opportunities for developers and smaller market participants, including through alternative app stores and messaging services.
- AI and cloud services are moving up the agenda: As digital markets evolve, the Commission intends to closely monitor developments in both sectors, using market investigations, regulatory dialogue, and specification proceedings to address emerging issues under the existing DMA framework.
- Enforcement remains key: While acknowledging positive progress, the review stresses that effective implementation will require continued regulatory dialogue, rigorous supervision, and targeted enforcement where compliance falls short.
What’s next?
The review confirms that the Commission’s priority is now effective implementation rather than new legislation. While legislative reform is off the table for now, businesses should expect further guidance and active enforcement as the Commission seeks to unlock the Regulation’s full potential. Looking ahead, the Commission will focus on ensuring that the DMA keeps pace with rapidly evolving digital markets, particularly in the areas of AI and cloud computing.
6. Simpler, Clearer, Better Enforced: The Commission’s Plan to Overhaul the EU Rulebook
On April 28, 2026, the European Commission published a communication titled “A Simpler, Clearer and Better Enforced EU Rulebook” (COM(2026) 380). Regarded as the most ambitious reform of EU policymaking since the Better Regulation agenda launched in 2002, the communication sets out a strategy to modernize how EU laws are designed, implemented, and enforced.
What’s new?
The Commission’s key actions are organized around five pillars:
1. Simplicity by design
To prevent fragmentation from the outset, the Commission will prioritize exhaustive regulations and full harmonization for single-market issues, where legally feasible. It also aims to embed enforcement by design, including through sunset clauses paired with standardized monitoring mechanisms.
2. A better regulation framework
The Commission will require proportionate impact assessments for a broader range of initiatives, reviewed by the Regulatory Scrutiny Board. It will enhance stakeholder engagement through earlier consultations and calls on co-legislators to adopt a common methodology for assessing the cost impact of substantial amendments, bringing transparency to compliance cost drivers that currently emerge late in the legislative process.
3. Regulatory deep cleaning
Under the Action Plan for Regulatory Deep Cleaning, 12 priority areas, including free movement of goods and services, financial services, customs, taxation, digital, energy, and transport, will be examined in 2026–2027 to reduce complexity. A review of delegated and implementing acts has already led to approximately 30% of planned acts for 2026 being deprioritized. A new Simplification Platform will convene national authorities, social partners, businesses, and civil society to guide these efforts.
4. Tackling gold-plating
To help Member States identify and avoid imposing stricter national requirements than EU law mandates, thereby raising costs and distorting competition (gold-plating), the Commission will develop a best-practices toolkit and enhance detection through the European Semester and the Single-Market Enforcement Taskforce.
5. Faster and more robust enforcement
The Commission has identified 11 single-market focus areas in which it will proactively investigate Member States and pursue infringement procedures. AI tools will be piloted in 2026 to accelerate national transposition checks, and the Commission will propose systematically higher financial penalties to strengthen deterrence.
What’s next?
The new approach will now be implemented gradually, pending revision of the Better Regulation Guidelines and Toolbox. The regulatory environment is set to become simpler in design and stricter in enforcement.
Germany
7. German Expert Commission Issues 56 Recommendations on Digital Child Safety
On June 24, 2026, the Independent Expert Commission on “Child and Youth Protection in the Digital World,” established in September 2025 by the German Ministry of Education, Family, Senior Citizens, Women, and Youth, published 56 recommendations on digital child safety.
The recommendations build on a status report published in April 2026 and are structured based on two complementary perspectives: a development-oriented perspective spanning six life phases from birth to adulthood and a responsibility-based perspective assigning accountability to specific actors. Both are connected by the central triad of protection, empowerment, and participation.
What’s new?
Key compliance-related recommendations include:
- Risk-based and design-based regulation: The Commission recommends a binding clarification of Article 28(1) DSA and presents two alternatives: (1) a statutory minimum age of 13 for social media accounts, with effective age verification and tiered protection for ages 13–16 and 16–18; or (2) no uniform age limit, but service- and function-specific restrictions based on risk assessments (e.g., algorithmic feeds, open contact features, livestreams).
- Youth protection by design and by default: Platforms should be required to implement safe default settings for minors’ accounts, including a prohibition on algorithmic and infinite-scroll feeds, personalized advertising, and manipulative design patterns such as autoplay and confirm-shaming.
- Effective and privacy-compliant age verification: The EU and federal government should define permissible age verification methods on a risk-based basis, requiring separation of data subject and verifier, selective disclosure (age threshold only), on-device biometric processing, and no use of data for advertising or tracking.
- AI-specific measures: A statutory age limit of 13 is recommended for AI companions, along with provider obligations including reliable age verification, age-appropriate defaults, protection against emotional dependence, and clearly visible notices that the interaction does not constitute a human relationship. National youth protection laws should be updated to cover AI-related risks such as generative image creation and chatbot interactions.
What’s next?
The Commission calls for all recommendations to be consolidated into a coherent strategy for digital child and youth protection, accompanied by an immediate action program by end of 2026, structured implementation formats, a digital feedback channel, and binding impact monitoring. A permanent interdisciplinary expert panel is to be established to monitor developments, advise policymakers, and track implementation progress. It is yet unclear whether, to what extent, and at what legislative level the German government will actually pursue these recommendations.
8. Germany Unveils Draft Legislation to Tackle Digital Violence
On April 16, 2026, the German Federal Ministry of Justice published the ministerial draft of the Act Against Digital Violence (Gesetz zur Stärkung des zivilrechtlichen und strafrechtlichen Schutzes vor digitaler Gewalt (“GgdG”); see our detailed alert). The proposal responds to rising levels of online abuse and persistent enforcement gaps, particularly in light of evolving technologies such as AI-generated deepfakes. Instead of expanding content moderation obligations, the draft shifts the focus from platform-led moderation to court-led enforcement, while introducing targeted new criminal offenses.
What’s new?
The draft introduces a number of notable changes, including:
- A broad scope aligned with the DSA. The proposal applies to online platforms and hosting services within the meaning of the Digital Services Act (DSA), as well as to internet access providers. Rather than creating a new legal concept of “digital violence,” it applies to an exhaustive list of underlying criminal offenses committed online, including defamation, hate speech, stalking, and image-based abuse.
- A new court-driven enforcement regime. Victims of certain forms of online abuse could obtain court orders requiring online platforms, hosting providers, and internet access providers to disclose user information, preserve evidence, and, where necessary, implement account suspensions. These measures are intended to address one of the key enforcement challenges in digital violence cases: identifying anonymous perpetrators and securing evidence before it is deleted. To ensure compatibility with the DSA’s country-of-origin principle, the draft frames these measures as case-specific judicial orders rather than general regulatory obligations, allowing German courts to issue binding orders in individual cases, including against providers established in other EU Member States.
- New criminal offenses targeting digital abuse. The proposal would expand Germany’s criminal law framework to address emerging forms of online harm, including AI-generated intimate images (“deepfakes”), deceptive manipulated content capable of causing significant reputational harm and certain forms of digital surveillance.
What’s next?
The stakeholder consultation has concluded and the draft is expected to proceed through the German legislative process later this year. Although amendments remain possible, platforms should begin assessing whether their internal processes are capable of responding efficiently to judicial disclosure, evidence preservation, and account-related orders.
9. Regional Court of Munich Ruled on Provider Liability for AI Summaries in Search Engine’s Search Results: May 28, 2026
On May 28, 2026, the Regional Court of Munich I (LG München I) issued a noteworthy judgment addressing liability for AI-generated search summaries. The case concerned allegedly defamatory statements generated by an online search engine’s “AI Overview” feature and provides important guidance on the application of the Digital Services Act (DSA) to generative AI outputs.
What’s new?
The Court held that the AI Overview constituted the provider’s own attributable content rather than a mere reproduction of third-party information. While the AI Overview was based on information available on third-party websites, it independently summarized, combined, and evaluated that information, presenting it as a new, self-contained narrative. In the Court’s view, this distinguished AI Overviews from traditional search results or autocomplete suggestions, which merely facilitate access to third-party content.
On that basis, the Court rejected the provider’s reliance on the hosting liability exemption under Article 6(1) of the Digital Services Act (DSA). According to the Court, the AI-generated summary was not information stored at the request of a recipient of the service, but rather new content generated by the provider’s own AI system. Consequently, the provider could not benefit from the reduced liability framework applicable to hosting providers or the notice-and-action regime under the DSA.
The Court further distinguished existing German case law limiting liability for traditional search engines, reasoning that AI-generated overviews go beyond making third-party content searchable, because they independently generated answers based on the weighting, evaluation, and synthesis of information from multiple sources.
What’s next?
The judgment was issued in preliminary injunction proceedings and remains subject to appeal. Nevertheless, it is among the first decisions to address the liability framework applicable to AI-generated outputs and may have broader implications beyond AI-powered search. While it specifically concerned AI-generated summaries of search results, the Court’s reasoning raises the broader question of when AI-generated content should be treated as the provider’s own content rather than third-party information protected by the DSA hosting safe harbor. Providers deploying generative AI features should therefore closely monitor further judicial developments in this area.
UK
10. UK AI Regulation Continues with Sectoral Approach
In the second quarter of 2026, the UK government reaffirmed its preference for regulating AI through existing laws and sector regulators, using targeted secondary legislation to emphasize the ICO’s remit over AI and automated decision-making (ADM) and a new proposed bill to enable cross-economy sandboxes.
What’s new?
The recent Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 requires the Information Commissioner’s Office (ICO) to prepare a code of practice on AI and ADM, providing clear and practical guidance on transparency and explainability, bias and discrimination, and rights and redress. This builds on the ICO’s March 2026 AI and biometrics strategy update, which announced draft guidance on ADM and profiling (“Draft Guidance”) and also touched on ongoing scrutiny of 11 major AI foundation model developers, with whom the ICO is currently engaged to mitigate privacy harms.
More broadly, the King’s Speech in May announced a Regulating for Growth Bill (the “Bill”), which is intended to strengthen regulators’ duties to support growth and give ministers powers to issue strategic steers. The Bill would also introduce cross-economy sandbox powers, allowing existing rules to be temporarily “relaxed” under controlled conditions so that businesses can test AI and other emerging technologies in real-world settings. The government has also launched an advisory AI Growth Lab sandbox, bringing together relevant regulators to help businesses navigate existing requirements. The first sector to participate will be legal services—involving the Council for Licensed Conveyancers, the Solicitors Regulation Authority, the Information Commissioner’s Office, and the Legal Services Board—and the ICO has also announced its intention to join the collaboration.
What’s next?
Organizations should keep a close watch on the finalization of these initiatives (as well as the new AI Taskforce created from the recent government reshuffle). In particular, the Draft Guidance consultation closed in May and will likely be updated this year, with the statutory code of practice on AI and ADM to follow in the future.
11. New UK Online Safety Rules Result in U16 Social Media Ban, Safety-by-Design for U18s, and AI Chatbot limitations
What’s new?
On June 15, 2026, the UK government has announced plans to ban under-16s from accessing social media, following the model adopted by Australia in late 2024. The ban would capture platforms whose purpose is to enable social interaction through user-generated content and algorithms—including Instagram, TikTok, YouTube, Snapchat, Facebook, and X—but would exclude messaging services such as WhatsApp and Signal. However, potentially affected services face uncertainty as the new prime minister has not yet addressed these proposals, which were announced under the previous administration.
“Further than a blanket ban” – what else is proposed?
The new laws will also address other features that have been deemed harmful and include “safety-by-design” measures, as announced on July 15, 2026. These aim to prevent a “cliff edge” at 16 years of age.
- U16s: Banned from so-called harmful functions, such as livestreaming and stranger communication. These features would be restricted for under-16s across a wider range of online services, including gaming.
- 16–17-year-olds: Nighttime curfews (midnight to 6 a.m.) to be enabled by default.
- 16–17-year-olds: Addictive features (e.g., autoplay and personalized content) to be turned off by default.
- U18s: Banned from AI “romantic companion” chatbots or other intimate functionalities on chatbots.
- U18s: Regular breaks when using AI chatbots.
- U18s: Banned from any chatbots presenting a serious threat to children.
When could the measures take effect?
The announcements anticipated the first regulations being laid before Parliament by the end of 2026. The government would use secondary legislation powers through the Children’s Wellbeing and Schools Act 2026, with measures expected to come into force in spring 2027.
However, both announcements were made by the previous Labour government. The succeeding administration may amend the scope of the proposals, widening the categorization of affected providers, or adding new banned functionalities.
What about the existing online safety landscape?
The proposals build on the existing framework, set out in the Online Safety Act 2023. The OSA already requires “user-to-user” services to protect children through risk assessments, age assurance, and safety-by-design measures, and Ofcom has been actively enforcing these duties (see our Q4 2025 update).
The UK is part of a broader European trend towards regulating platform design, not only access. France has combined age restrictions with digital curfew proposals for minors. Germany’s Independent Expert Commission has recommended default restrictions on algorithmic feeds and engagement-driven features (see section [7] above). At the EU level, the Digital Services Act already requires very large online platforms to mitigate risks to minors, and the proposed Digital Fairness Act is expected to address addictive design more broadly (see our Q3 2025 update).
What’s next?
Ofcom has been asked to conduct a study on effective age assurance for verifying whether someone is over 16, and to publish an enforcement strategy, both key building blocks for any future ban. Platforms offering social media, gaming, livestreaming, or AI chatbot services to younger users should monitor developments closely, particularly given the spring 2027 target date.
12. Smart data schemes” Government Consultation on Scheme Design Across Retail, Transport, Trade, Agrifood, and Property
The Department for Business and Trade has published a call for evidence(“Call for Evidence”) on how Smart Data schemes should be prioritized, designed and delivered across retail, transport, trade, agrifood, and property.
Smart Data involves the secure sharing of customer data, at the customer’s request, with authorized third-party providers. A Smart Data scheme provides the policy, regulatory or contractual, technical, and governance framework for secure, standardized data sharing and may be mandatory or voluntary.
It is particularly relevant to organizations that hold or use customer, product, pricing, transaction, logistics, property, or compliance data, including retailers, transport and logistics providers, property professionals, agrifood businesses, technology companies, authorized third-party providers, regulators, and industry bodies.
The Data (Use and Access) Act 2025 (DUAA) gives the government powers to introduce legal requirements for the creation and governance of data-sharing schemes. Following publication of the Smart Data 2035 Strategy, the government is now moving from strategy into scheme design and delivery. Its targets are to establish five or more active Smart Data schemes by 2030 and at least 20 interoperable schemes by 2035.
The potential use cases remain exploratory. Before any regulatory change, they will be subject to feasibility and design work, including assessment of data availability, governance models, and legal applicability under the DUAA, followed by formal consultation.
What does the Call for Evidence cover?
The Call for Evidence seeks views on sector readiness, potential use cases, scheme design, cross-economy alignment, governance and international best practice:
- Transport: Addressing fragmented data and inconsistent standards across freight, rail, and multi-modal transport, including journey planning, ticketing, network coordination, infrastructure management, and electric vehicle charging;
- Trade: Supporting trade digitalization, reducing repetitive and duplicative data submissions, and improving data flows across international supply chains, primarily by unlocking private-sector data;
- Retail: Supporting product traceability, personalized consumer services, and access to pricing, stock, and local offer information. The government’s work has so far focused mainly on grocery retail and cost-of-living use cases;
- Agrifood: Reducing duplicated reporting, improving traceability, and enabling better use of production, logistics, sustainability, and compliance data; and
- Property: Improving homebuying and selling through secure sharing and reuse of trusted data, with possible applications in rental and commercial property, property management, building lifecycle management, and planning.
Across all sectors, the government is seeking evidence on data quality and availability, commercial incentives, technical and contractual barriers, cybersecurity, liability, competition, and impacts on SMEs and new entrants. It also considers cross-sector standards, accreditation, accountability, consumer protection, and redress, together with lessons from overseas schemes and opportunities for international alignment.
What’s next?
The Call for Evidence closes at 11:59 p.m. on October 1, 2026. A high-level summary is expected in early 2027, followed by sector-specific publications during 2027. A separate consultation on long-term, cross-economy governance is also planned for early 2027, and any use cases taken forward will be subject to formal consultation before regulatory change.
Affected organizations should consider what relevant data they hold, whether it is accurate and available in standardized formats, and what technical, contractual, or commercial barriers could affect future sharing. They should also assess how participation could affect existing operating models, data-based services, and relationships with customers, suppliers, and third-party providers.
13. Joined Up Regulatory Thinking Regarding Synthetic Media, Deepfakes, and Digital Verification Services
What’s New?
The Digital Regulation and Co-operation Forum (DRCF)—a cross-sector body made up of the UK Competition and Markets Authority, Ofcom, the Information Commissioner’s Office, and the Financial Conduct Authority—has launched its latest call for input (the “Consultation”).
The Consultation focuses on the theme of digital authentication and trust, specifically in the following areas:
- Authentication and trust are a regulatory priority: The Consultation forms part of the DRCF’s new Thematic Innovation Hub, which aims to help regulators engage earlier with emerging technologies. The latest workstream focuses on how regulators can foster trust in digital services while supporting innovation, reflecting growing concern that advances in AI are making it increasingly difficult for users to distinguish genuine content and identities from manipulated or synthetic alternatives.
- Synthetic media and deepfakes come under the spotlight: The DRCF is seeking evidence on the opportunities and risks associated with AI-generated content, adopting Ofcom’s definitions of both “synthetic media” (i.e., an umbrella term for video, image, text, or voice that has been generated in whole or partly by AI algorithms) and “deepfakes” (i.e., forms of audio-visual content that have been generated or manipulated using AI, which misrepresent someone or something). The Consultation recognizes the legitimate uses of synthetic media, including education, accessibility support, gaming, advertising, and personalized financial services, while also highlighting concerns around fraud, impersonation, disinformation, consumer protection, and online safety.
- Digital verification services receive increased regulatory attention: Alongside synthetic media, the DRCF is examining private-sector digital verification services, focusing on technologies used to verify identity attributes rather than the government’s wider digital ID program. The Consultation seeks to explore how verification services can improve trust and reduce fraud while balancing privacy, competition, accessibility, and consumer protection considerations.
- A coordinated regulatory approach continues to develop: Rather than considering these technologies through one single regulatory regime, the DRCF is bringing together the expertise of each of the member regulators. This is an expected reaction to the increasingly multidimensional nature of complex tech, where issues relating to competition, consumer protection, privacy, online safety, and financial services frequently overlap and require regulators to work together on the same matters.
- Industry engagement will shape future regulatory work: The DRCF is inviting responses from businesses developing and/or deploying these technologies, legal and compliance professionals, academics, and civil society and advocacy groups. Although the exercise is expressly information-gathering rather than guidance-setting, responses are expected to inform future regulatory research, stakeholder engagement, and potentially more formal policy initiatives.
What’s Next?
The call for input closes on August 14, 2026, after which the DRCF will analyze responses and may convene further webinars, roundtables, and other stakeholder engagement activities. While no immediate regulatory obligations are expected to arise from the exercise, the Consultation provides a clear indication that synthetic media, deepfakes, and digital verification technologies are becoming strategic priorities across the UK’s digital regulatory landscape.
For businesses developing or deploying AI-generated content, identity verification, or authentication technologies, the Consultation offers an early opportunity to help shape regulatory expectations before more formal guidance or regulatory interventions emerge. Organizations should also expect increasing collaboration among the DRCF member regulators, as these technologies continue to blur the traditional boundaries between privacy, online safety, consumer protection, financial regulation, and competition law.
Marcus Holding London Trainee Solicitor and Berlin research assistants Felicitas Lampe and Nina Funke contributed to the drafting of these alerts.










