EU
GDPR
The EDPB and the EU’s new Anti-Money Laundering Authority (AMLA) announced plans to jointly develop guidelines on information sharing between AML-obliged entities and authorities. The guidance will clarify how Article 75 of the AML Regulation applies alongside the GDPR. A public consultation on the draft guidelines is planned for the first half of 2027.
AI Act
The Council of the EU formally adopted the Digital Omnibus on AI on 29 June, giving final approval to the package previously approved by Parliament on 16 June (423–57). High-risk AI obligations under Annex III are deferred to 2 December 2027, while obligations under Annex I are deferred to 2 August 2028. Watermarking requirements and the new CSAM/nudifier ban apply from 2 December 2026. GPAI and Article 50 transparency obligations remain on the original schedule.
DMA
The European Commission held a stakeholder roundtable on 1 July concerning cloud computing services as part of its DMA market investigation. The discussion covered interoperability, financial conditions, and contractual terms between cloud providers and customers. A final investigation report is expected by May.
Sweden
NIS2
NCSC formally assumed responsibility for all NIS2/cybersäkerhetslagen regulatory activities from MCF on 1 July. This includes regulations, guidance, incident reporting, and supervisory coordination. From this date, all NIS2 entity registrations and incident reports are submitted directly to NCSC through CERT-SE and the national cyber portal.
.png)