Home 5 Insights 5 EU data sovereignty in 2026: New rules for your infrastructure
Compliance

EU data sovereignty in 2026: New rules for your infrastructure

2026-07-29
Throughout 2025 and into 2026, several European regulations moved from political agreement to active enforcement. If you run or buy infrastructure in Europe, the landscape looks noticeably different from a year ago. This is a snapshot of where things stand as of July 2026.

The Data Act and cloud switching

The Data Act has been in effect since 12 September 2025. It covers cloud switching rights, restrictions on vendor lock-in, and protections against data access by non-EU governments. EU countries have been setting up enforcement since then, though progress varies.

This means providers are now legally required to remove many of the technical and contractual barriers that have traditionally made switching difficult.

Key dates ahead: Products released after 12 September 2026 must be designed so that user data is accessible by default. From 12 January 2027, providers can no longer charge you for switching.

NIS2 has moved into national enforcement

More EU countries have finalized their national NIS2 laws, and regulators are starting to supervise and prepare for audits. Organizations are now expected to have governance, supply chain security, and incident reporting in place.

In the Nordics, Finland moved first with its Cybersecurity Act (124/2025), which took effect on 8 April 2025. Sweden followed on 15 January 2026 with a broader scope: it covers your entire IT environment, requires a 24-hour early warning and 72-hour incident report, and holds management personally accountable.

Both countries make management responsible for cybersecurity. One of the biggest changes is the focus on supply chain security. Organizations are now expected to assess and manage cybersecurity risks introduced by the ICT providers and service partners they rely on.

The Cyber Resilience Act reaches first deadline

The Cyber Resilience Act (CRA) took effect on 10 December 2024, but the first real deadline is just around the corner. From 11 September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours. For you as a customer, this means faster disclosure from the vendors behind the hardware, firmware, and software in your stack. By December 2027, products sold in the EU will need to meet a baseline set of security requirements.

If you build and sell digital products yourself, the September deadline hits you directly. Any actively exploited vulnerability in your product must be reported to ENISA within 24 hours, with a full report within 72 hours. This covers products already on the market, not just new releases.

AI Act: what moved and what didn't

The AI Act’s timeline shifted in the first half of 2026. The Commission proposed the Digital Omnibus on AI to simplify parts of the Act, and final approval was made in late June 2026.

The main change is that stricter rules for high-risk AI systems have been pushed back from 2 August 2026 to 2 December 2027. The deadlines regarding high-risk AI built into regulated products (like medical devices) have been delayed even further, to 2 August 2028.

That said, 2 August 2026 is still an active deadline. If users interact directly with an AI system without it being obvious, they must be informed that they are interacting with AI. And if you offer a generative AI product, content-watermarking rules are enforced by 2 December 2026.

DORA and your cloud contracts

Financial institutions across the EU are now operating under DORA, and regulators are paying close attention to how well organizations can prove they’re resilient. In November 2025, EU regulators classified the first major cloud providers as critical to the financial system and placed them under direct oversight, meaning they can now inspect and assess those providers directly, rather than only through their customers.

If you’re in the financial sector, DORA means your cloud contracts need to include audit rights, exit strategies, and termination rights. If you’re an infrastructure provider serving financial customers, the same rules apply in reverse.

US data transfers under pressure

On 29 June 2026, the US Supreme Court ruled that the President can remove FTC commissioners at will, ending 90 years of the FTC operating independently from the White House. That independence was one of the main reasons the EU approved the current data transfer agreement with the US in 2023.

The privacy organization noyb, founded by Max Schrems, has asked the Commission to withdraw the agreement, arguing it no longer holds up. If that happens, companies storing or processing personal data in the US would need to find another legal way to do so, or move those workloads to Europe.

On 3 June 2026, the European Commission proposed the Cloud and AI Development Act as part of a broader Tech Sovereignty Package. The idea is to create an EU-wide way of assessing how sovereign a cloud or AI service actually is, with graded levels for providers serving the public sector. If it passes, “sovereign cloud” would go from being a sales pitch to a regulated standard.

The proposal still has to make it through Parliament and Council, so the details will change. But the direction is clear: the EU wants to define what sovereignty means in practice, not leave it to providers to interpret.

How Glesys fits in

As the regulatory bar keeps rising, your choice of provider increasingly decides how much of that complexity you carry yourself. Glesys operates data centers in Sweden and Finland under European ownership and jurisdiction. Data sovereignty, portability, and access controls have been part of how we work from the start. If you’re reviewing your setup against what’s changed, our compliance team is happy to help.