×

EU Policy Update – June 2026

EU Policy Updates 06-07-2026

In a nutshell: The upcoming Council of the EU presidencies unveiled their programmes. The Council of the EU published progress reports on ongoing legislative files. Member States published declarations on the EU digital agenda. The European Commission presented a law enforcement package, Code of Practice on the transparency of AI-generated content, and reached a preliminary position on cloud service providers. European Parliament committees moved further on Digital Omnibus, and EU Inc. The SIRIUS project published guidelines on e-Evidence for competent authorities. European Supervisory Authorities published a report on major ICT-related incidents.

The upcoming Council of the EU presidencies unveiled their programme

In June, the upcoming Irish presidency at the Council of the EU published a policy programme for its six-month presidency from July to December 2026. The programme supports the One Europe, One Market roadmap, and further ‘simplification’ of rules (see our previous reporting here). With regard to security, the presidency supports the Commission’s roadmap on Access to Data, which offers solutions for lawful access to data for law enforcement (see our previous reporting here). The presidency also intends to progress on the Digital Networks Act, the European Business Wallet, and the Cloud and AI Development Act, and aims to reach an agreement with the European Parliament on the Digital Omnibus package by the end of 2026. The presidency views the proposal for the Cybersecurity Act 2.0 (CSA 2.0) as “pivotal” in ensuring that ENISA’s mandate reflects the tasks assigned to it through the legislative framework on cybersecurity. The presidency also intends to advance ICT supply chain discussions, with the aim of aligning the revised CSA 2.0 with the supply chain priorities of the ProtectEU Strategy, while avoiding unnecessary duplication. The start of the Irish presidency also marks the beginning of the new “trio” in the Council of the EU, together with Lithuania and Greece, spanning from July 2026 to December 2027. The programme of the trio includes support for strengthening the EU’s economic security and reducing high-risk dependencies in strategic supply chains. The trio also intends to reinforce the resilience of critical infrastructure, including payments, against physical and digital threats.

Member States published declarations on the EU digital agenda

On 8 June, the ministers of the D9+ Group of EU Member States, including Luxembourg, the Czech Republic, Denmark, Estonia, Spain, Finland, Cyprus, Ireland, the Netherlands, Poland, Portugal, Sweden, Belgium and Slovenia, published a ministerial declaration on EU Digital policy. The declaration highlights the need to reduce existing critical dependencies and increase European digital capacities, while maintaining an open and pragmatic approach. The EU should support public-private partnerships and EU-based companies as suppliers. D9+ Member States underline the need to maintain momentum and increase the ambition of the current simplification agenda, including through a more in-depth analysis of the digital acquis in the Digital Fitness Check. D9+ Member States also highlight the “simplification-by-design-and-by-default” approach, which should include adequate impact assessments that cover the cumulative administrative burden and the competitiveness impacts of the proposals. The declaration also notes that the upcoming Digital Fairness Act should focus on addressing dark patterns and addictive features of online services, without duplicating existing rules. The document also supports investment in education and media literacy. Finally, the declaration calls for a European approach to protecting minors online. In parallel, France and Germany published a joint paper on Digital Sovereignty, where they highlight that EU digital sovereignty does not imply protectionism or isolationism, but rather that the EU should continue cooperating with trusted international partners.

Simplification

The Council of the EU published progress reports on ongoing legislative files

On 5 June, the Council of the EU released progress reports on ongoing legislative files, such as the Digital Omnibus and the Cybersecurity Act 2.0 (CSA 2.0). With regard to the Digital Omnibus, the document notes that Member States expressed concerns towards the establishment of a single-entry point for cyber incident reporting at the EU level, the transfer of current rules applicable to cookies under GDPR, and the definition of personal data. With regard to the proposal for the CSA 2.0, the document notes that Member States welcomed the proposal and generally supported its overall objectives, notably the strengthening of ENISA’s support to Member States’ operational cooperation. Member States supported streamlining the certification framework and welcomed its voluntary nature. With regard to the provisions on the trusted ICT supply chain framework, Member States called for further clarifications on the methodology and procedures for identifying key ICT assets and high-risk suppliers, as well as on the scope and possible impact of the proposed measures. Member States also noted the need to maintain an appropriate level of their involvement in the process.

European Parliament committees moved further in the discussions on the Digital Omnibus

In June, the European Parliament’s Committee on Industry Research and Energy (ITRE) and the Committee on Civil Liberties, Justice and Home Affairs (LIBE) published a joint Draft Report on the Digital Omnibus. The Draft Report asks the Commission to adopt common templates drafted by the European Data Protection Board (EDPB) for the purposes of personal data breach notification, and for preparing the data protection impact assessment. The proposed amendments also call on the EDPB to establish a list of personal data processing activities that would require a data protection impact assessment. Regarding the NIS 2 Directive, the amendments ask the European Commission, ENISA, and the NIS Cooperation Group to issue guidance on the harmonised interpretation of “key obligations” under the NIS 2 Directive to ensure its consistent application. In the meantime, the Committee on Internal Market and Consumer Protection (IMCO) published its Draft Opinion on the Digital Omnibus. The Rapporteur for the Opinion expressed his doubts that the proposed changes in the Digital Omnibus would benefit consumers or the functioning of the internal market. For this reason, the Draft Opinion includes amendments aimed at balancing simplification and consumer protection. The Draft Opinion, for example, deletes the amended definition of personal data as proposed in the original Commission proposal.

Data access

The European Commission presented a law enforcement package

On 24 June, the European Commission presented a law enforcement package which includes a proposal for a Regulation on Europol, a proposal for a Regulation on Eurojust.  By renewing and expanding the mandates of Europol and Eurojust, the European Commission intends to strengthen the EU’s response to an evolving criminal landscape. The Europol proposal includes provisions on secure information exchange, stronger operational support for Member States and a focus on cooperation with international partners. The proposal notes that cybercrime and cyber-enabled criminal activities constitute a central component of the threat landscape affecting the EU’s internal security. Europol should, through its European Cybercrime Centre, support Member States in preventing and combating cybercrime and in responding to cyberattacks. Europol should also contribute to the development and deployment of methods in the area of digital forensics, lawful access and the processing and analysis of encrypted data. The proposal on Eurojust focuses on stronger capabilities and operational support, and providing further support in emerging areas of crime, such as cybercrime.

The SIRIUS project published guidelines for e-Evidence

On 15 June, the SIRIUS project published guidelines for competent authorities for completing the European Production Order Certificate and the European Preservation Order Certificate. The goal of the guidelines is to improve the quality, clarity, and completeness of the certificates, prevent delays and refusals in the execution of the orders, facilitate efficient and timely cooperation with service providers, and promote consistent application of the e-Evidence Regulation. The explanatory document notes that the guidelines might also be used in contexts outside the e-Evidence Regulation, such as cooperation with service providers outside its scope, handling of voluntary data disclosure requests, or mutual legal assistance frameworks.

Cybersecurity

European Supervisory Authorities published a report on major ICT-related incidents

On 3 June, the European Supervisory Authorities (ESA), European Banking Authority, European Insurance and Occupational Pensions Authority, and the European Securities and Markets Authority published a report on major ICT-related incidents in 2025. The authorities are jointly responsible for supervising financial entities under the Digital Operational Resilience Act (DORA). The report is based on major incident reports submitted by financial entities to competent authorities. Major incidents mostly affected the credit (60%) and payment (16%) sectors. Of the incidents, 33% were DDoS and 31% data exfiltration and manipulation incidents, including identity theft. Half of the major incidents were caused by system failures or malfunctions, with almost a third of the cases originating from failures on the part of the ICT third-party providers. The document underlines a need for robust third-party risk management, effective oversight of outsourced activities, and close coordination with service providers during incident response and remediation. For the next steps, the ESAs will continue to monitor and analyse major incidents, and offer further guidance to competent authorities to support supervisory activities under DORA, including ICT risk management.

Competitiveness

JURI published its Draft Report on EU Inc proposal

On 29 June, the Committee on Legal Affairs of the European Parliament (JURI) published a Draft Report on the EU Inc proposal. The proposal introduces a new type of EU-wide legal entity (see our previous reporting here). Among other things, the Draft Report amends the scope of economic activities EU Inc companies are eligible to pursue. Companies seen as having limited scale-up value, such as construction, should not be eligible to establish an EU Inc entity. The Draft Report slightly amends the types of data necessary to establish an EU Inc company, by requiring mail address from the EU Inc companies. The Draft Report also suggests the establishment of “EU Inc Digital Platform”, an open access digital platform with easily accessible and publicly available information for companies, investors and other relevant stakeholders. The EU Inc Digital Platform shall be interoperable with, and connected to the e-Justice portal, BRIS and the EU central interface. The digital platform shall also be interoperable with and include the public database of Union and national case law relating to EU Inc. companies. To that end, the Commission shall ensure the availability of high-quality machine translation tools and develop an AI-powered search and analysis tool as well as a notification system for updates to national laws affecting EU Inc. companies. The EU Inc Digital Platform shall be established by the European Commission.

The European Commission reached a preliminary position on cloud service providers under the DMA

On 25 June, the European Commission reached a preliminary position on designating Amazon and Microsoft as gatekeepers under the Digital Markets Act (DMA) for their cloud services. The Commission designated AWS and Microsoft Azure as gatekeepers under the DMA even though they did not reach the quantitative limit for being labelled as such. The Commission's reasoning is the outsized influence these companies have, as they are the two largest cloud service providers on the EU market. The Commission notes that both companies have “vast and entrenched user bases and appear to benefit from lock-in effects and high switching costs”. Amazon and Microsoft now have the possibility to appeal this preliminary finding. If the designation of AWS and Microsoft Azure as gatekeepers prevails, the DMA would then oblige them to allow third parties to interoperate with their services in certain instances.

AI

The European Commission published a Code of Practice on the transparency of AI-generated content

On 10 June, the European Commission published a voluntary Code of Practice on the transparency of AI-generated content. The Code intends to help providers and deployers of generative AI systems to comply with the AI Act’s obligations for labelling and marking of AI-generated content according to Article 50. The Code was drafted by two working groups composed of academics and AI providers and deployers. The Code will be complemented by Commission guidelines on transparency obligations stemming from the AI Act.

Published By Filip Lukáš
Filip is the Policy Advisor at CENTR, advising members on relevant EU policy and liaising with governments, institutions and other organisations in the internet ecosystem.
Published By Polina Malaja
Polina Malaja is the Policy Director at CENTR, leading its policy work and liaising with governments, institutions and other organisations in the internet ecosystem.