Technology Law Shorts - July 2026
July 30, 2026
Technology Law Shorts - July 2026July 30, 2026 In this update, we highlight key developments in EU technological sovereignty, global cyber resilience regulation and the trends affecting data centers, alongside global AI regulatory changes (check out our Middle East deep dive!) Over the last quarter:
For global technology businesses, this means reviewing external technology dependencies and cloud infrastructure against evolving EU sovereignty standards, strengthening cyber resilience and AI governance frameworks to meet heightened expectations and monitoring developing regulation to keep apace. Commercial technology developments: what do I need to know?EU: EU Technological Sovereignty PackageOn 3 June 2026, the European Commission presented the Technological Sovereignty Package to reduce Europe’s dependence on non-EU technology providers. The package comprises four pillars:
The proposals introduce the first formal EU-level definition of digital sovereignty and will now be examined by the European Parliament and Council. Our Judith Vieberink comments: “Hyperscalers are already adjusting their offering in response to this shifting landscape. That said, businesses should not take sovereignty claims at face value, whether they come from American or European providers. There is currently no ISO standard or comparable certification against which such claims can be objectively assessed, so businesses considering a "sovereign cloud" offering would be well advised to carry out their own due diligence before relying on it.” Impact: Businesses should review external technology dependencies, assess cloud infrastructure against the four-tier sovereignty classification, and evaluate semiconductor supply chain exposure. The package is expected to benefit EU-based tech, cloud, and industrial players whilst reducing reliance on non-EU suppliers. Deeper dive: see LinkedIn Global: Cyber Reporting and Resilience Rules TightenCyber incident reporting and resilience obligations are advancing globally. In the UK, the proposed Cyber Security and Resilience Bill and the NCSC’s updated Cyber Assessment Framework signal a shift towards more prescriptive, outcome-focused security standards with expanded scope and stronger supply chain accountability. The EU’s Cyber Resilience Act introduces a mandatory security-by-design framework for products with digital elements, with incident reporting requirements coming into force in September 2026 and further product security standards following in December 2027. Changes on the horizon under the European Commission’s proposed Digital Omnibus will streamline incident reporting. Meanwhile, in the US, the finalisation of mandatory cyber incident reporting rules under CIRCIA will bring critical infrastructure operators under a formal federal enforcement regime for the first time, with tight reporting windows and civil penalty exposure. With “town halls” having taken place and stakeholder feedback under review, we expect the final position around Autumn 2026 and suggest what businesses can do now to prepare. Impact: These developments reflect a regulatory trend towards mandatory, enforceable cyber resilience standards and accelerated incident disclosure. Businesses operating across jurisdictions should review their incident response procedures, reporting workflows and supply chain oversight arrangements to ensure they can meet increasingly short reporting deadlines and demonstrate security maturity. Early preparation and Board engagement is key. Deeper dive: UK: Cyber Resilience Landscape – An Update to Practical Implementation EU: Executive Compliance Guide: Cyber Resilience Act | Navigating EU Law US: US: Delays to cyber incident reporting rules Middle East: UAE centralises AI and data regulation under new federal authorityLast month, the UAE established the Federal Artificial Intelligence and Data Authority, creating a single national body responsible for AI, data and digital government. The Authority consolidates several existing functions, will lead national AI and data strategy, and has powers to propose legislation, policies and regulatory programmes. It may also accelerate long-awaited developments under the UAE's federal data protection framework, including implementing regulations, guidance and enforcement activity. Impact: Businesses operating in or with the UAE should review their AI and data governance frameworks and monitor for new regulatory requirements, guidance and enforcement developments that could affect compliance obligations. Global: The Trends Shaping Data CentersData centers are becoming a critical part of digital infrastructure, driven by AI, cloud computing and high-performance workloads. Growth is creating new pressure on power availability, planning, grid capacity, cooling, supply chains, construction delivery and insurance. It is also reshaping investment and M&A, with greater focus on access to energy, specialist equipment and operational resilience. Our Nils Muller comments “in Germany, demand for computing capacity is surging because of AI and cloud workloads drive higher-density requirements. This growth is constrained by grid connection delays, planning bottlenecks and tightening sustainability rules. That said, regulation across the EU is becoming more aligned, more demanding and more closely enforced. For data centers, success will depend on moving beyond reactive compliance to a more integrated, forward-looking approach that brings together cybersecurity, resilience and operational strategy”. Impact: Businesses should treat data center projects as cross-functional risk issues, not standalone real estate or IT assets. Early alignment across legal, energy, construction, finance, insurance and procurement teams will be key to protecting value, maintaining deal certainty and delivering projects at pace. Deeper dive: see Legal Telescope: Building the infrastructure of tomorrow – market, regulatory and delivery trends shaping data centers Global: AI regulatory updateIn the July edition of our global AI bulletin, we looked at: Global – A final supervisory toolkit for AI use in capital markets, setting out a risk-based framework for proportionate oversight of AI across the system lifecycle. Asia – Hong Kong's circular on AI-enabled cybersecurity threats to licensed firms; Hong Kong expanding its annual compliance checks on organizations using AI, with new guidance on agentic AI; and Singapore's updated Model AI Governance Framework for Agentic AI. EU – A call for clarity on how the AI Act interacts with existing insurance sector regulation; an agreement to simplify and delay key high-risk AI Act timelines; and political agreement on the Digital Omnibus on AI, intended to reduce compliance complexity without diluting regulatory standards. Middle East – The UAE Cabinet's adoption of a national AI healthcare policy and direction for related legislation covering data governance, safety, licensing, and liability. UK – A report on AI-driven workforce transformation; the Government's rejection of a broad copyright exception for AI training and its shift toward a licensing-market approach; guidance on risks associated with agentic AI adoption; a foresight paper on regulating agentic AI across existing legal frameworks; and the publication of The Mills Review, examining how AI may transform retail financial services by 2030 and beyond. US – An Executive Order promoting advanced AI innovation while addressing national security risks; the FTC's commencement of enforcement under the TAKE IT DOWN Act targeting nonconsensual AI-generated intimate imagery; Colorado's overhaul of its AI antidiscrimination statute amid the first federal constitutional challenge to a state AI law; Connecticut's enactment of a broad, multi-sector AI regulatory package; and Illinois's landmark legislation mandating independent audits for frontier AI safety. Deeper dive: see Global AI Regulatory Update - July 2026 and The Mills Review – what FCA-regulated firms should do now on AI, outsourcing and operational resilience Further resources:Commission call for evidence - AI Continent – new cloud and AI development act; Chips Act 2 Commission proposes tech sovereignty package to strengthen Europe's digital autonomy and resilience Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) | CISA Key contacts
Simon Lightman Partner United Kingdom Nils Müller Partner Munich, Germany | Hamburg, Germany Olaf van Haperen Partner Rotterdam, Netherlands Caroline Lyannaz Partner Paris, France Nichola Donovan Partner United Kingdom Judith Ledeboer-Vieberink Principal Associate Rotterdam, Netherlands Madhulika Kanaujia Principal Associate United Kingdom Jessica Jesson Senior Associate United Kingdom Angela Kindness Principal Associate United Kingdom Sara C. Ellis Professional Support Lawyer United Kingdom Kirath Bharya Knowledge Lawyer United Kingdom Latest Insights
Latest News
Latest Events
legal updates July 30, 2026 Technology Law Shorts - July 2026 legal updates July 27, 2026 EU adopts its 21st sanctions package against Russia and Belarus legal updates July 24, 2026 Global payment matters - July 2026 legal updates July 23, 2026 AI Governance Bill: Malaysia’s Next Step Towards the First AI Rulebook client news July 24, 2026 Advising Johnson Matthey on completion of the sale of its Catalyst Technolo... client news July 10, 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... firm news July 10, 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... client news July 09, 2026 Eversheds Sutherland advises Costello Medical on transition to employee own... virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States |