Skip to main content
Welcome to Deloitte
If we have selected the wrong experience for you, please change it above.

Digital Regulation Back-to-school 2026

A round-up of the key digital regulatory developments in the UK and EU over summer 2026

Introduction

This summer offered a clear reminder, if it were needed, that developments in digital regulation remain central to the broader societal, economic and geopolitical agenda. Topics such as the online protection of minors, AI frontier-model governance and data centre deployment have been at the forefront of public debate in many countries around the globe. The potential implications of this activity go much further than pure regulatory compliance, requiring affected companies to balance a complex set of issues that encompass commercial, legal, regulatory and sustainable development considerations.

Cleary, we cannot cover all of this in one briefing. In this note we therefore identify the implications of a number of important developments in the UK and EU which we think should be high on the agenda for affected firms, with a particular emphasis on the digital platform, cloud and AI ecosystem. In so doing, we focus on five core areas (namely protection of minors, online safety implementation, AI governance, sovereignty & resilience and audiovisual media regulation).

We provide a high-level summary of the main developments that we cover in each of these areas in Figure 1 below. To ensure a forward-looking approach, we also include a timeline for each in the relevant section, providing a snapshot of what to expect in the weeks and months ahead. Taken together, we hope this helps to unpack what has been a busy July and August, as well as providing a snapshot of how to prepare for what is likely to come next.

Figure 1 - Overview of UK and EU developments that we cover in this note

1. Protection of Minors

With potential social media bans on the horizon, there is still much that affected services can do to address regulatory expectations in the meantime

While guidance, supervision and enforcement activity continue to clarify what compliance with existing requirements under the UK Online Safety Act (OSA) and EU Digital Services Act (DSA) looks like in practice, recent political developments in Europe point to potential new rules above and beyond existing regimes. So-called social media bans form part of a wider shift towards age-differentiated online experiences, turning child safety increasingly into a product design challenge. And, of course, European politicians and regulatory officials alike will have been closely monitoring relevant developments in US litigation over the summer. Indeed, Coimisiún na Meán has stated that “From our initial analysis, it appears that many of the elements of the settlement are in line with the European Commission guidelines for platforms to comply with Article 28 of the DSA, which Coimisiún na Meán played a key role in drafting.”

In the UK, the Government announced plans in July for default overnight curfews and restrictions on features such as autoplay and infinite scrolling for 16- and 17-year-olds. This builds on prior proposals to prevent under-16s from accessing social media, restrictions on specific AI chatbot functionalities and restrictions on certain high-risk features like livestreaming and communication with strangers. The implications extend beyond social media to AI, gaming and other services offering potentially risky functionalities.

In the EU, a specially commissioned panel provided recommendations to the European Commission in July, including an EU-wide restriction on under-13s’ autonomous access to social media and other digital services exposing minors to risky features or content, alongside age-appropriate safeguards for older teenagers. The Commission has stated that it intends to bring forward proposals after the summer. Member State initiatives also continue to evolve in parallel, although France’s under-15 ban was struck down in August on freedom of expression, proportionality and privacy grounds. The judgment illustrates the legal and practical constraints that future access restrictions will need to navigate. Nonetheless, platforms should continue to prepare for the potential interaction between EU-wide measures and additional national requirements.

Taken together, these developments should enable companies to begin mapping relevant services and features against emerging requirements, designing age-tiered product experiences and stress-testing their age assurance arrangements. Age assurance will be central to compliance, but platforms should not assume that existing approaches will automatically satisfy future requirements, particularly for those in scope of the proposed social media ban. In fact, Ofcom is preparing a rapid assessment of how highly effective age checks could work in practice to determine whether someone is over 16, which may prove more difficult than assessing whether someone is an adult. Ofcom’s July report also presented early findings on limitations in some approaches, including age inference, and emphasised that no single method eliminates circumvention risk.

Platforms should therefore assess current methods against emerging regulatory expectations on effectiveness, privacy, security, accessibility, proportionality and user experience, while considering issues such as cost, scalability and attempted circumvention. In the EU, the Commission has already stated that it has developed a privacy-preserving age-verification solution that is interoperable with future EU Digital Identity Wallets, designed to enable age-verification functionality to be integrated into them. Monitoring the rollout and planning for integration within the emerging digital identity ecosystem could help future-proof age-assurance strategies.

2. Online Safety Implementation

A crescendo of enforcement activity under the DSA, with UK implementation continuing at pace in the context of overarching regime reviews

While rules to protect children online continue to dominate the European online safety agenda, implementation and enforcement of existing rulebooks have continued apace.

In July, Ofcom published its register of categorised services under the OSA, identifying the services that will face additional obligations beyond the Act's baseline requirements. Alongside the register, Ofcom launched consultations on the detail of several of those obligations, covering fraudulent advertising and additional duties, including user empowerment, identity verification and protections for news publisher content, journalistic content and content of democratic importance.

In our view, enhanced transparency requirements should be an immediate priority for categorised services, something we have previously written about at Online Safety Act Transparency: Responding to Ofcom’s Bespoke Approach. Developing bespoke transparency reports in response to Ofcom’s incoming notices will require robust data, consistent reporting and appropriate governance and sign-off processes. Services should also devote sufficient resources to responding to draft notices, which provide the main opportunity to influence the final legally binding requirements. Certain services will also be required to provide Ofcom with up-to-date risk assessments and publish summaries of these. Companies should prepare for potential public scrutiny and reputational implications associated with these transparency measures.

Complying with wider duties will ultimately require coordination across product, operational, legal and compliance teams, supported by clear accountability and senior oversight. Services may be able to build on existing OSA risk assessment approaches when conducting new assessments relating to fraudulent advertising indicators, user empowerment and freedom of expression and privacy. However, some proposed measures may require new or expanded systems and functionality, including user controls, identity verification, advertising moderation and ad libraries. Existing DSA infrastructure, such as platform advertisement repositories, may provide a starting point in some areas, but companies will need to assess differences between the regimes.

Beyond the specifics of this element of the OSA, Ofcom’s Chair announced a wide-ranging review of the regulator’s approach to online safety in July, including its structure, operating model, capabilities and enforcement approach. Also in July, the House of Lords Communications and Digital Committee launched an inquiry into the OSA’s implementation and impact. Both could influence how the overall regime is ultimately supervised and enforced.

In the EU, the second annual report on systemic risks and mitigation measures, alongside a crescendo of enforcement activity during July, demonstrated the growing maturity of DSA supervision. The report highlighted systemic risks arising from illegal and harmful content, platform design, recommender and AI systems, and their effects on fundamental rights and wider society. Enforcement developments included a non-compliance decision and fine concerning failures to assess and mitigate the risks associated with illegal products, acceptance of a compliance action plan relating to transparency obligations and researcher access, and preliminary findings concerning minors and addictive design. Together, these developments signal increasing regulatory scrutiny of how services are designed, operated and governed. Companies will need to demonstrate not only that they have identified systemic risks, but that their mitigation measures effectively address them in practice.

At Member State level, activity by Digital Services Coordinators in relation to online marketplaces in Germany and the Netherlands also illustrated that services not designated as VLOPs or VLOSEs still remain subject to significant DSA obligations and national scrutiny.

3. AI Governance

With high-profile safety and cybersecurity incidents in the spotlight, supervisory activity is expected to develop quickly

Alongside significant AI regulatory developments, a series of high-profile safety and cybersecurity incidents intensified the debate around frontier-model governance in both the UK and EU. This prompted statements from both the European Commission and the UK AI Safety Institute on the topic. In the EU, the Commission confirmed in August that it had sent its first information requests to leading AI companies concerning safety and transparency measures, providing an early indication that supervisory activity is expected to develop quickly.

The interaction between the DSA and AI Governance was again made clear with the first designation of an AI system that can engage with and respond to users' prompts and queries, including by searching the web, at the end of August. As the European Commission set out in its accompanying public statement, the Commission has therefore treated it as a hybrid service that qualifies as an online search engine under the DSA.

Given the ongoing activity in relation to EU AI Act implementation, we focus on this element for the remainder of this section. The AI Omnibus, the implications of which we have previously written about at The AI Omnibus: what it means for AI strategies, entered into force in July, confirming delays to high-risk obligations. However, emerging guidance and technical standards are beginning to provide greater clarity on how those requirements could translate into practical compliance expectations. As we have previously set out, the extended timetable provides more preparation time but should certainly not be mistaken for a reason to pause implementation.

Most transparency requirements also became applicable in the EU on 2 August, despite limited transitional arrangements for certain systems already on the market. Supported by Commission guidance and a Code of Practice, these obligations extend well beyond the largest AI providers. Organisations deploying chatbots or using AI-generated or manipulated content should assess whether their use of AI is in scope and, if so, whether it is disclosed appropriately across products and services.

At the same time, enforcement powers are now available for key parts of the AI Act, giving the European Commission’s AI Office new tools to request information, access models and conduct evaluations. Companies in scope should therefore ensure that model documentation, testing, incident-management arrangements and governance processes can stand up to regulatory scrutiny.

4. Sovereignty & Resilience

Developments during the summer demonstrate the need for companies to approach digital sovereignty, AI and resilience in a joined-up way

The emphasis on digital sovereignty continued in both the UK and EU over the summer period. It increasingly encompasses questions of data, cloud, compute, AI infrastructure, supply chains and dependence on external technology providers, reflecting growing concern about strategic dependencies and the resilience of critical infrastructure. Earlier in the summer, the European Commission took a significant step towards operationalising this agenda in the EU through its Tech Sovereignty Package (with the proposed sovereignty framework in the Cloud and AI Development Act a central element of this, something we have written about at Responding to the new EU Tech Sovereignty Package – implications for cloud and AI ). The situation is not quite as advanced in the UK, with the Parliamentary Science, Innovation and Technology Committee calling for more Government action in this area in July, in particular that it must “set out a strategy to achieve sovereign AI capabilities”.

Activity in the EU during July also highlighted the centrality of AI to the sovereignty debate. The Commission’s call for tenders to establish up to seven new AI Gigafactories aims to support the development of advanced AI on European infrastructure. The initiative may ultimately expand European access to advanced compute and create opportunities for firms across the cloud and AI ecosystem seeking to develop, procure or invest in European AI infrastructure. The initiative sits alongside the EU Action Plan on Cybersecurity and AI, which aims to strengthen European capabilities in model evaluation, testing and compute. Particularly given the frontier-AI concerns discussed above, these initiatives illustrate how AI governance is becoming increasingly intertwined with wider questions of infrastructure, resilience and strategic autonomy.

The resilience lens is also important in this context. The designation of the first four Critical Third Parties to the UK financial services sector brings key technology providers within direct regulatory oversight for the first time. For designated providers, this means preparing for direct regulatory engagement and stronger assurance over services supporting critical financial-sector functions, potentially drawing on relevant experience under the EU’s Digital Operational Resilience Act. The UK Cyber Security and Resilience Bill, currently making its way through Parliament, would extend similar oversight beyond financial services by allowing regulators to designate critical suppliers to essential and digital services and impose security duties on them.

For firms, the strategic message is that digital sovereignty, AI and cyber resilience are increasingly interconnected. Companies should expect greater scrutiny of critical technology dependencies, third-party concentration, access to compute and model assurance. At the same time, this may create opportunities to invest in sovereign infrastructure or for European providers to position for future procurement. Firms that develop an integrated view of sovereign capability, cyber risk and operational resilience will be better placed to identify risks and opportunities, respond to future scrutiny and make more informed technology investment and procurement decisions.

5. Media Ecosystem

New UK rules edge closer, with a profound debate on the role of audiovisual media regulation in the online environment continuing to play out in both the UK and EU

In the UK, the summer saw further progress in relation to implementation of the UK Media Act. Fifteen connected TV platforms were formally designated as Television Selection Services, bringing requirements on the prominence and availability of public service broadcaster content to the fore. This reinforces the need for affected services to consider any technical, commercial and governance implications associated with future prominence requirements.

Alongside this, Ofcom consultations on a new Tier 1 Standards Code and Accessibility Code closed in August. The proposals would ultimately bring large streaming services closer to the regulatory model long applied to traditional broadcasters, introducing new expectations around content standards, audience protection and accessibility. As Ofcom develops the final Codes, affected services should assess the implications for governance, compliance processes, accessibility provision and broader UK operating models.

At the same time, given the change in viewing habits from linear broadcasting into the online world, there remains an active debate on how media regulation should respond to this change more broadly. Although launched in June, the Government’s media Green Paper consultation remained open throughout July and August. It considers whether platforms should make designated ‘trustworthy’ news more visible and discoverable, including on social media. In other words, the emerging debate is not only about what platforms should take down, but what they may be expected to put in front of users. This could have implications for recommendation systems, ranking practices, discoverability and broader platform governance.

In the EU, the European Media Board presented suggestions for a revision of the Audiovisual Media Services Directive (AVMSD), stressing the need for the framework to keep pace with changes in the audiovisual ecosystem. Its recommendations include considering whether content creators, audio services such as podcasts and user interfaces should be brought within scope, alongside adapting advertising rules and strengthening the prominence of services of general interest. If taken forward, these proposals could also materially broaden the scope and requirements of EU audiovisual media regulation. The Commission’s formal outcome of its review of the AVMSD, expected by the end of December, is therefore eagerly awaited.

Conclusion

The abovementioned developments highlight the huge variety of issues facing companies in this space. The pace of changes remains significant, vividly illustrated by the fact that in relation to online safety and media, the UK regimes are essentially now being reviewed at the same time the prevailing regulation is being implemented. Taken together, this creates a complex web of challenges – but also opportunities – for affected companies to respond to. It therefore remains vitally important to respond to these issues in a strategic, joined-up way. We hope that this note has been helpful in pulling at least some of the key strands together, over what has been a very busy summer period indeed.

If you would like to receive our updates directly, please do subscribe to our quarterly ECRS Digital Regulation Newsletter, bringing together our latest publications, insights and events across the ever-evolving UK and EU digital regulatory agenda.

[1]. Future dates included in timelines reflect expected timings at the time of writing and may change.

Subscribe to our quarterly ECRS Digital Regulation Bytes Newsletter.