The EU Council of Ministers has approved supporting details for the Digital Services Act (DSA) and Digital Markets Act (DMA), requiring very large online platforms to establish risk audits and transparency reports. According to Brussels officials, after the AI Act takes effect, companies will conduct data provenance and human supervision labeling for generative models according to risk levels.
Regarding cross-border data flows, the EU is extending adequacy agreement negotiations with Japan and South Korea, aiming to ensure cloud service availability while maintaining privacy. Multiple cloud service providers are preparing to add locally controlled regions in Germany and France to meet "data residency" requirements. Financial and medical institutions are required to complete critical data mapping and encryption upgrades by 2027.
- Platform obligations: Risk assessments, illegal content response timeframes, and advertising transparency must be disclosed quarterly.
- AI compliance: High-risk models require explainability documentation and human supervision records; sandbox programs open to small and medium enterprises.
- Data strategy: Data space projects encourage industry sharing of non-sensitive data, improving supply chain visibility.
Analysis indicates that new rules increase compliance costs in the short term but provide unified market standards for Europe's digital industry, potentially attracting more trusted cloud and cybersecurity investment.