Back to Articles

The EU Digital Law Pipeline: What Is Coming After the 2026 Deadlines

European Parliament hemicycle during a sitting

Most compliance content covers rules that already apply. That is useful for the next audit and useless for planning, because the expensive decisions are architectural and architecture gets set eighteen months before a deadline.

This is the other half of the picture: what is currently moving through the European legislative machine, roughly when it lands, and which of it should actually influence what you build now.

A warning up front. Proposals change, some die, and dates slip. Nothing here is a reason to build against an unadopted text. It is a reason to avoid building something that an obviously incoming rule will make expensive.

How to read the stages

European law moves through predictable stages, and where a file sits tells you how much to trust it.

Announced in the Work Programme. The Commission has said it intends to propose something. No text. Directionally useful, nothing more.

Proposal published. There is a text. It will change, often substantially, but the shape and the definitions are now visible.

Council general approach and Parliament mandate. Both co-legislators have positions. The negotiating range is now visible: anything both sides agree on is very likely to survive.

Trilogue. Closed-door negotiation between Parliament, Council and Commission. Outcomes are usually somewhere between the two mandates.

Political agreement, then formal adoption, then entry into force, then application. The gap between adoption and application is where you actually do the work, and it is typically eighteen months to three years.

The practical rule: once both co-legislators have published mandates, the parts they agree on are safe to plan around. Before that, treat everything as directional.

In trilogue now

The Digital Omnibus

The largest simplification package in the current cycle, proposed in November 2025. It touches GDPR, the AI Act, the Data Act, ePrivacy and cybersecurity reporting.

The parts that matter most to product teams are proposed Articles 88a and 88b, which would move cookie consent rules out of the ePrivacy Directive and into GDPR itself, widen the exemptions where no consent is required, introduce a six month silence period after a refusal, and make browser-level machine-readable consent signals legally binding.

Trilogues continued into mid 2026. This is the single most likely near-term change to how consent works in practice, and we covered our reading of it in cookie consent after the Digital Omnibus.

Who should care: anyone running a consent management platform, analytics, advertising or personalisation.

The digital euro package

Council position December 2025, Parliament committee mandate approved 43 to 14, trilogues opened July 2026, with all three institutions aiming to finish during 2026. The ECB pilot runs from the second half of 2027 with a target of first issuance in 2029.

Full detail in our digital euro implementation guide.

Who should care: banks, payment service providers, e-commerce platforms, point of sale vendors.

Financial Data Access, known as FiDA

The open finance file. It extends open-banking-style data access beyond payment accounts into investments, pensions, insurance and mortgages, and creates a new regulated category of financial information service provider.

FiDA has had the most troubled passage of anything in this list. Trilogue negotiations stalled in early 2026 and then restarted. Realistic application is phased somewhere between 2027 and 2030.

Who should care: fintech, insurtech, wealth platforms, anyone whose product would benefit from permissioned access to financial data beyond current accounts.

Agreed but not yet applying

PSD3 and the Payment Services Regulation

Council and Parliament reached provisional political agreement on the payments framework on 27 November 2025. This is the overhaul of PSD2: stronger fraud prevention obligations, a broader liability allocation for certain fraud types including impersonation fraud, changes to strong customer authentication, performance requirements for open banking interfaces, and a merger of the payment institution and e-money institution regimes.

Because it is a Regulation plus a Directive, part applies directly and part has to be transposed. Expect application towards the end of the decade rather than immediately.

Who should care: any product that initiates payments, holds customer funds, or consumes open banking APIs.

Proposed, positions forming

The European Business Wallet

Proposed as the corporate counterpart to the EU Digital Identity Wallet. Where the EUDI wallet holds a person's credentials, the business wallet holds a company's: registration data, mandates, representation rights, certificates, and the ability to exchange signed documents across borders.

The Council adopted its negotiating position on 9 June 2026 and the ambition is political agreement by the end of 2026. Member states would be expected to accept business wallets for administrative procedures within 24 months of entry into force, with an extra year for more complex functionality.

Detail in our European Business Wallet guide.

Who should care: anyone building B2B onboarding, procurement, supplier verification, e-invoicing or regulated business processes.

The Cloud and AI Development Act

A flagship of the Commission's technology sovereignty agenda, targeted for the first part of 2026. The stated aims are to strengthen Europe's capacity to develop, deploy and scale cloud and AI, to address regulatory gaps, to promote interoperability, and to establish an EU-wide cloud policy for public administrations and public procurement.

The subtext is dependency on non-European cloud providers, and the mechanism most likely to have teeth is public procurement rather than direct regulation of private buyers.

Detail in our Cloud and AI Development Act guide.

Who should care: cloud providers, anyone selling software to European public sector buyers, and anyone whose architecture assumes a single hyperscaler.

The Digital Networks Act

Introduced in January 2026 after several postponements. It rewrites telecoms governance: spectrum harmonisation, the single market for electronic communications, network security standards, and the long-running argument about whether large traffic originators should contribute to network costs.

Who should care: telecoms operators, CDN and connectivity providers, and any service whose economics depend on cheap transit.

The Digital Fairness Act

Targeted for the fourth quarter of 2026, so a proposal rather than a law for some time yet. It is aimed squarely at dark patterns, addictive design, influencer marketing, and personalisation practices that exploit consumer vulnerability, including personalised pricing.

This one deserves attention well before it applies, because it targets interface patterns that many products currently depend on for conversion. Detail in our Digital Fairness Act guide.

Who should care: consumer-facing products of every kind, especially subscription, gaming, marketplace and social.

Chips Act revision

A legislative initiative revisiting the European Chips Act was placed in the 2026 Work Programme. The first Chips Act was widely seen as underpowered relative to its ambition, and the revision is expected to address that. The funding side is covered in our Chips Act funding guide.

Who should care: semiconductor and hardware companies, and anyone tracking European industrial policy money.

Public procurement reform

A Public Procurement Act was placed in the 2026 Work Programme with an explicit European preference dimension for strategic sectors. If you sell to European public buyers, procurement rules are the mechanism through which a surprising amount of technology policy actually reaches you.

Who should care: anyone with public sector revenue in Europe.

Announced, still shapeless

Several initiatives have been signalled without a text: a Quantum Act, a Space Act, further work on AI in science, and continuing work on the European Health Data Space rollout. There is also the long-running child sexual abuse regulation, commonly called chat control, which has repeatedly stalled over client-side scanning and remains unresolved.

Treat these as radar items. Knowing they exist is worth something. Designing around them is not.

What has gone the other way

It is worth knowing what has been withdrawn or deprioritised, because a lot of published commentary has not caught up.

The AI Liability Directive was withdrawn. The ePrivacy Regulation, which spent years going nowhere, was abandoned and its subject matter is being handled through the Digital Omnibus instead. The Green Claims Directive has had a difficult passage and its final shape is not settled, though the related Empowering Consumers Directive applies from September 2026 regardless.

Simplification is now an explicit political theme. That does not mean less regulation in aggregate, but it does mean some files are being consolidated rather than added.

How to use this without wasting effort

The temptation with a list like this is to build a tracker and assign an owner to each row. That produces a spreadsheet.

What actually works:

Sort by whether it requires a design decision. Consent architecture, identity and credential handling, payment method abstraction and data access interfaces are expensive to retrofit. Reporting processes and documentation are not. Only the first category justifies acting before adoption.

Look for the shared substrate. Consent infrastructure built well serves the Digital Omnibus changes. Credential verification built for the EUDI wallet largely serves the business wallet. Payment method abstraction serves instant payments, Wero and the digital euro alike. Three files, one piece of platform work.

Watch mandates, not proposals. When Council and Parliament both publish positions, the overlap is the safe zone. That is the moment to start building, not the day a proposal is published.

Write down what you decided and when. Most of these regimes expect you to be able to explain your reasoning. A short architecture decision record with a date beats a policy document written afterwards.

Where we fit

We build and maintain software for companies operating in Europe, which increasingly means building systems that can absorb regulatory change without a rewrite. The work is mostly unglamorous: abstraction at the right seams, explicit state, and configuration where the law has left a number deliberately adjustable.

If you want a view on which of these files actually touches a specific product, write to office@c9group.dev. The rules that already apply are mapped in our 2026 EU digital compliance guide, and more about our European work is on the EU market entry page.

We are engineers, not lawyers, and this is a planning map rather than legal advice. Everything above is a moving target until it is in the Official Journal.