Technology Law Shorts - July 2026
30. Juli 2026
Technology Law Shorts - July 202630. Juli 2026 In this update, we highlight key developments in EU technological sovereignty, global cyber resilience regulation and the trends affecting data centers, alongside global AI regulatory changes (check out our Middle East deep dive!) Over the last quarter:
For global technology businesses, this means reviewing external technology dependencies and cloud infrastructure against evolving EU sovereignty standards, strengthening cyber resilience and AI governance frameworks to meet heightened expectations and monitoring developing regulation to keep apace. Commercial technology developments: what do I need to know?EU: EU Technological Sovereignty PackageOn 3 June 2026, the European Commission presented the Technological Sovereignty Package to reduce Europe’s dependence on non-EU technology providers. The package comprises four pillars:
The proposals introduce the first formal EU-level definition of digital sovereignty and will now be examined by the European Parliament and Council. Our Judith Vieberink comments: “Hyperscalers are already adjusting their offering in response to this shifting landscape. That said, businesses should not take sovereignty claims at face value, whether they come from American or European providers. There is currently no ISO standard or comparable certification against which such claims can be objectively assessed, so businesses considering a "sovereign cloud" offering would be well advised to carry out their own due diligence before relying on it.” Impact: Businesses should review external technology dependencies, assess cloud infrastructure against the four-tier sovereignty classification, and evaluate semiconductor supply chain exposure. The package is expected to benefit EU-based tech, cloud, and industrial players whilst reducing reliance on non-EU suppliers. Deeper dive: see LinkedIn Global: Cyber Reporting and Resilience Rules TightenCyber incident reporting and resilience obligations are advancing globally. In the UK, the proposed Cyber Security and Resilience Bill and the NCSC’s updated Cyber Assessment Framework signal a shift towards more prescriptive, outcome-focused security standards with expanded scope and stronger supply chain accountability. The EU’s Cyber Resilience Act introduces a mandatory security-by-design framework for products with digital elements, with incident reporting requirements coming into force in September 2026 and further product security standards following in December 2027. Changes on the horizon under the European Commission’s proposed Digital Omnibus will streamline incident reporting. Meanwhile, in the US, the finalisation of mandatory cyber incident reporting rules under CIRCIA will bring critical infrastructure operators under a formal federal enforcement regime for the first time, with tight reporting windows and civil penalty exposure. With “town halls” having taken place and stakeholder feedback under review, we expect the final position around Autumn 2026 and suggest what businesses can do now to prepare. Impact: These developments reflect a regulatory trend towards mandatory, enforceable cyber resilience standards and accelerated incident disclosure. Businesses operating across jurisdictions should review their incident response procedures, reporting workflows and supply chain oversight arrangements to ensure they can meet increasingly short reporting deadlines and demonstrate security maturity. Early preparation and Board engagement is key. Deeper dive: UK: Cyber Resilience Landscape – An Update to Practical Implementation EU: Executive Compliance Guide: Cyber Resilience Act | Navigating EU Law US: US: Delays to cyber incident reporting rules Middle East: UAE centralises AI and data regulation under new federal authorityLast month, the UAE established the Federal Artificial Intelligence and Data Authority, creating a single national body responsible for AI, data and digital government. The Authority consolidates several existing functions, will lead national AI and data strategy, and has powers to propose legislation, policies and regulatory programmes. It may also accelerate long-awaited developments under the UAE's federal data protection framework, including implementing regulations, guidance and enforcement activity. Impact: Businesses operating in or with the UAE should review their AI and data governance frameworks and monitor for new regulatory requirements, guidance and enforcement developments that could affect compliance obligations. Global: The Trends Shaping Data CentersData centers are becoming a critical part of digital infrastructure, driven by AI, cloud computing and high-performance workloads. Growth is creating new pressure on power availability, planning, grid capacity, cooling, supply chains, construction delivery and insurance. It is also reshaping investment and M&A, with greater focus on access to energy, specialist equipment and operational resilience. Our Nils Muller comments “in Germany, demand for computing capacity is surging because of AI and cloud workloads drive higher-density requirements. This growth is constrained by grid connection delays, planning bottlenecks and tightening sustainability rules. That said, regulation across the EU is becoming more aligned, more demanding and more closely enforced. For data centers, success will depend on moving beyond reactive compliance to a more integrated, forward-looking approach that brings together cybersecurity, resilience and operational strategy”. Impact: Businesses should treat data center projects as cross-functional risk issues, not standalone real estate or IT assets. Early alignment across legal, energy, construction, finance, insurance and procurement teams will be key to protecting value, maintaining deal certainty and delivering projects at pace. Deeper dive: see Legal Telescope: Building the infrastructure of tomorrow – market, regulatory and delivery trends shaping data centers Global: AI regulatory updateIn the July edition of our global AI bulletin, we looked at: Global – A final supervisory toolkit for AI use in capital markets, setting out a risk-based framework for proportionate oversight of AI across the system lifecycle. Asia – Hong Kong's circular on AI-enabled cybersecurity threats to licensed firms; Hong Kong expanding its annual compliance checks on organizations using AI, with new guidance on agentic AI; and Singapore's updated Model AI Governance Framework for Agentic AI. EU – A call for clarity on how the AI Act interacts with existing insurance sector regulation; an agreement to simplify and delay key high-risk AI Act timelines; and political agreement on the Digital Omnibus on AI, intended to reduce compliance complexity without diluting regulatory standards. Middle East – The UAE Cabinet's adoption of a national AI healthcare policy and direction for related legislation covering data governance, safety, licensing, and liability. UK – A report on AI-driven workforce transformation; the Government's rejection of a broad copyright exception for AI training and its shift toward a licensing-market approach; guidance on risks associated with agentic AI adoption; a foresight paper on regulating agentic AI across existing legal frameworks; and the publication of The Mills Review, examining how AI may transform retail financial services by 2030 and beyond. US – An Executive Order promoting advanced AI innovation while addressing national security risks; the FTC's commencement of enforcement under the TAKE IT DOWN Act targeting nonconsensual AI-generated intimate imagery; Colorado's overhaul of its AI antidiscrimination statute amid the first federal constitutional challenge to a state AI law; Connecticut's enactment of a broad, multi-sector AI regulatory package; and Illinois's landmark legislation mandating independent audits for frontier AI safety. Deeper dive: see Global AI Regulatory Update - July 2026 and The Mills Review – what FCA-regulated firms should do now on AI, outsourcing and operational resilience Further resources:Commission call for evidence - AI Continent – new cloud and AI development act; Chips Act 2 Commission proposes tech sovereignty package to strengthen Europe's digital autonomy and resilience Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) | CISA Ansprechpartner
Simon Lightman Partner London, Vereinigtes Königreich Nils Müller Partner München, Deutschland | Hamburg, Deutschland Olaf van Haperen Partner Rotterdam, Netherlands Caroline Lyannaz Partner Paris, France Nichola Donovan Partner London, Vereinigtes Königreich Judith Ledeboer-Vieberink Principal Associate Rotterdam, Netherlands Madhulika Kanaujia Principal Associate Nottingham, Vereinigtes Königreich Jessica Jesson Senior Associate Nottingham, Vereinigtes Königreich Angela Kindness Principal Associate Nottingham, Vereinigtes Königreich Sara C. Ellis Professional Support Lawyer Birmingham, Vereinigtes Königreich Kirath Bharya Knowledge Lawyer Birmingham, Vereinigtes Königreich Publikationen
News
Events und Trainings
client news 30. Juli 2026 Eversheds Sutherland Advises Johnson Matthey on Acquisition of CORMETECH In... client news 24. Juli 2026 Advising Johnson Matthey on completion of the sale of its Catalyst Technolo... client news 10. Juli 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... kanzlei-news 10. Juli 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... virtual UAE - Employment law in the Dubai International Financial Centre 10. September 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know 10. September 2026 9.30am - 1.00pm (BST) London, Vereinigtes Königreich in-person Basic foundations of US employment law 17. September 2026 9.30am - 4.30pm (GMT) London, Vereinigtes Königreich in-person 2026 BDC Roundtable 23. September 2026 Washington DC, Vereinigte Staaten von Amerika |