The European regulatory framework for digital matters has entered a phase of concrete application since the summer of 2026. AI Act, Cyber Resilience Act, Data Act: several major texts now impose operational obligations on technology companies and manufacturers of digital products. Meanwhile, issues of cybersecurity, online protection of minors, and data sovereignty continue to shape the high-tech news in France and Europe.
AI Act: transparency obligations applicable since August 2026
Since August 2, 2026, part of the obligations of the European AI Act has come into effect. Users must now be informed when they interact with an artificial intelligence system.
Content generated or manipulated by AI, including deepfakes, must be labeled as such. European authorities have new powers to monitor the relevant systems.
This transparency aspect constitutes the first genuinely binding layer of the regulation. Platforms that integrate chatbots or image generation tools are the primary targets. Following the evolution of these issues on specialized resources like goinformation.info allows for measuring the concrete impact of these new rules on the tech sector.
However, the available data does not yet allow for conclusions about the actual level of compliance among market players. Initial field feedback varies on this point: some companies already display clear mentions, while others seem to be stalling.

Cyber Resilience Act: reporting digital vulnerabilities starting September 2026
The Cyber Resilience Act imposes security requirements on software and connected device manufacturers. Its vulnerability reporting obligations came into effect on September 11, 2026, well before the majority of obligations set to take effect on December 11, 2027.
This two-phase timeline creates a unique situation. Manufacturers of digital products (smartphones, connected objects, consumer software) must now report security flaws that are actively exploited. The compliance burden is increasing for manufacturers like Samsung, Apple, or Amazon’s connected device makers.
What this changes for everyday products
A smartphone or a connected speaker sold in Europe must now comply with a standardized reporting process. The manufacturer can no longer simply publish a silent patch.
- Any actively exploited vulnerability must be reported to the relevant authorities within a timeframe defined by the regulation
- Software manufacturers are subject to the same obligations as hardware manufacturers, significantly broadening the scope
- Low-cost connected objects, often neglected in terms of updates, fall under the regulation’s scope
The question of compliance costs for small manufacturers remains open. Field feedback varies between those who already have dedicated cybersecurity teams and those who are just discovering these obligations.
Data Act and data governance in France: a system under construction
France is preparing its national implementation framework for the Data Act. This European text introduces a challenge of data governance and competition among cloud providers that goes beyond the sole scope of the CNIL.
The Data Act aims to facilitate switching cloud providers and to regulate access to data generated by connected objects. For French companies, this means new rules on data portability and contractual conditions imposed by large platforms.
Cloud portability and digital sovereignty
The text directly impacts companies’ cloud strategies. Until now, migrating from one provider to another remained technically and contractually complex. The Data Act imposes facilitation obligations that could redistribute part of the market.
French sovereign cloud players are closely monitoring these developments. The question of which national authority will oversee the implementation of the text in France has not yet been resolved, creating uncertainty for companies looking to anticipate.

Online protection of minors: France adjusts its approach
France has submitted a revised plan to the European Union regarding access to social networks for those under 15 years old. Rather than a total ban, the chosen approach focuses on feature restrictions while requiring age verification for all users, including adults.
This change in method reflects a persistent technical challenge. Reliable and privacy-respecting age verification systems remain a challenge. Platforms like Meta or services related to Apple and Samsung products must adapt their systems to the French framework, which differs from the British or Australian approaches.
- Restrictions apply to specific features (notifications, algorithmic recommendations) rather than complete access to platforms
- The system still needs to prove its technical effectiveness before any potential large-scale deployment
Data on the effectiveness of age verification systems deployed in other countries do not yet allow for definitive conclusions. The debate between protecting minors and widespread surveillance remains lively in the digital world.
Security flaws and data leaks: a recurring issue
Cybersecurity incidents affect both tech giants and public organizations. The Cyber Resilience Act arrives in this context of increasing attacks, but its concrete effects will only be measurable in the medium term.
The pace of data leaks is accelerating without protective technologies progressing at the same rate. For users, vigilance against phishing attempts remains the first line of defense, well before any regulatory framework.



