Regulatory Watch Wednesday — April 1, 2026
Regulatory Watch Wednesday — EU General/Consumer Protection
April 1, 2026 | Curated EU regulatory updates
AI Act
The EU AI Act is seeing significant timeline updates:
- December 2, 2027: High-risk AI systems (employment, education, law enforcement) must comply
- August 2, 2028: AI systems in regulated products (e.g., medical devices) must comply
- November 2, 2026: Deadline for watermarking AI-generated audio, image, video, and text
The European Parliament adopted its position on March 26, 2026. Trilogue negotiations are underway with a targeted final agreement by April 28, 2026.
New prohibition: Systems capable of generating or manipulating non-consensual intimate imagery of identifiable individuals will be banned under Article 5.
GDPR
2026 Coordinated Enforcement Priority: Transparency and information duties. The EDPB has made this the top shared investigation focus for national DPAs.
Recent Fines
| Entity | Amount | Violation |
|---|---|---|
| Google (France) | €325M | Invalid cookie consent |
| Shein (France) | €150M | Invalid cookie consent |
| Major Italian bank | €31.8M | Insider breach undetected for 2 years; inadequate security, late breach notification |
| Experian (Netherlands) | €2.7M | GDPR violations |
| Kruidvat (Netherlands) | €600K | Pre-ticked consent boxes |
Digital Services Act (DSA) / Digital Markets Act (DMA)
Both acts are now in active enforcement:
- DMA Gatekeepers: Google, Amazon, Apple, Meta, and Microsoft under scrutiny for self-preferencing, interoperability, data access, and app store restrictions
- DSA: Major platforms facing compliance checks on content moderation, recommender system disclosures, advertising transparency, and risk assessments
- National Digital Services Coordinators are actively investigating complaints across Member States
European Accessibility Act (EAA)
The EAA has been enforceable since June 28, 2025, with full compliance required by June 28, 2030.
Key requirements (via EN 301 549): - Products must be usable without vision, with limited vision, without hearing, with limited mobility, or limited cognition - No multi-finger gestures, no time limits without extensions - Mandatory accessibility statements and VPAT reports
Scope: E-commerce, banking, transport apps, kiosks, and other consumer-facing digital services sold or used in the EU.
This briefing will be sent weekly on Wednesdays. Contact the team for corrections or additions.