← Back to all articles

Three developments shaped the week for anyone advising on EU technology law. The AI Act reached its long-anticipated 2 August milestone, and the obligations everyone had been preparing for were not the ones that took effect. A Munich court handed rightsholders the first European judgment holding that training an AI model abroad can still infringe copyright at home. And the European Data Protection Board asked Brussels to look again at whether the EU-US Data Privacy Framework still holds after a US Supreme Court ruling on the independence of the Federal Trade Commission. Here is what happened and why it matters for practice.

I. AI Regulation and Governance (EU)

The AI Act train crossed 2 August 2026, but high-risk obligations took the bus. For two years, 2 August 2026 sat in every compliance roadmap as the date the AI Act's high-risk regime would apply. The goalpost, however, was moved a bit. Under the Digital Omnibus on AI that the Council approved on 29 June 2026, part of the "Omnibus VII" simplification package, the co-legislators fixed new application dates: 2 December 2027 for stand-alone high-risk systems under Annex III, and 2 August 2028 for AI embedded in regulated products under Annex I. What did apply on schedule are the Article 50 transparency obligations, the duty to tell people when they are dealing with an AI system and to mark AI-generated content, with a short grace period on watermarking for existing systems until 2 December 2026. The same regulation adds a new Article 5 prohibition on AI systems that generate non-consensual intimate imagery and child sexual abuse material, moves the deadline for national regulatory sandboxes to 2 August 2027, and reinforces the AI Office's supervisory and enforcement powers.

The practical exposure for most providers and deployers of high-risk systems has shifted by more than a year, but the transparency layer is live now, and the nudifier and CSAM ban carries a hard December deadline. Our view is that the deferral buys implementation time rather than relief. The Act's structure is unchanged, harmonised standards are still coming, and the organisations that read December 2027 as a reason to pause will find themselves repeating this summer's scramble. The more interesting signal is institutional: the AI Office emerges from this package with sharper teeth, including inspection and fining powers and clearer competence over systems built on general-purpose models by the same provider.

The Cloud and AI Development Act consultation is open, with responses due 29 August 2026. The Commission's proposed Cloud and AI Development Act (CADA), first published on 3 June 2026 as the centrepiece of the Tech Sovereignty Package, is now in its feedback phase, with the consultation window closing on 29 August. CADA aims to triple EU data-centre capacity over five to seven years and to reduce dependence on a handful of non-EU cloud providers, whose European market share the Commission puts at roughly 15 percent. Its most consequential mechanism is a cloud sovereignty framework built on graduated "Union assurance levels" that would condition access to public-sector contracts on security, resilience and protection from foreign control.

CADA codifies an "AI first" and "AI promotion" logic that sits in tension with the AI Act's risk-based caution, and its sovereignty tests would reach directly into public-sector procurement across the Union. For CEE clients weighing hyperscaler dependence against local capacity, the assurance-level design is worth reading now while the text is still open to comment, because the criteria that survive the consultation will shape procurement eligibility for years.

II. Intellectual Property (EU)

Munich rules that offshore AI training can infringe: GEMA v. Suno. On 31 July 2026, the Landgericht München I (Munich District Court I) issued the first major European judgment holding that training an AI model on protected musical works without a licence can infringe copyright even when the training happens outside the EU (case no. 42 O 763/25). The claimant, German collecting society GEMA, largely prevailed against US music-generation provider Suno on injunctive relief, information and a declaration of liability for damages. The court accepted international jurisdiction over the US training acts under Section 131 of the German Collecting Societies Act, a forum available only to collecting societies. It found that the works were memorised in model versions stored on German servers, that memorisation is a reproduction under Section 16 of the Copyright Act, and that the text and data mining exception in Section 44b did not apply. It held Suno, not its users, responsible for the outputs, and, applying US fair use under the territoriality principle, found fair use inapplicable because simple prompts produced outputs substantially similar to the originals. Notably, the court held that AI Act compliance under Article 53 is not a defence to copyright liability. The judgment is not final and can be appealed; the earlier GEMA v. OpenAI decision from the same court is already before the Munich Court of Appeals.

Why it matters?

The decision removes two of the defences AI developers have leaned on hardest. Structuring training offshore no longer guarantees insulation from a German collecting society's claim, and the court was willing to run a full US fair-use analysis itself rather than defer to it, distinguishing the US rulings in Bartz v. Anthropic and Kadrey v. Meta on the facts. In our opinion, the memorisation theory (that a model which can reproduce protected content on a plain prompt is itself evidence of an unlawful reproduction inside the model) is the doctrinally significant move, and it has now survived at first instance twice. It is worth reading against the Hamburg Court of Appeals' more developer-friendly TDM reasoning from December 2025, which shows German courts are not aligned, and against the pending CJEU reference in C-250/25 Like Company, where the Advocate General's opinion is expected on 3 September 2026. GEMA is pairing litigation with licensing, having launched its PLAI licensed music dataset on 23 July, which tells you where the commercial endgame sits.

III. Data Protection

The EDPB asks Brussels to re-examine the EU-US Data Privacy Framework after Trump v. Slaughter. By a letter dated 31 July 2026 to Commissioner Michael McGrath, widely reported and analysed this week, the European Data Protection Board requested that the Commission examine whether the US Supreme Court's decision in Trump v. Slaughter affects the continued validity of the EU-US Data Privacy Framework. In that ruling, handed down on 29 June 2026 by a 6-3 majority, the Court held that statutory restrictions on the President's power to remove Federal Trade Commission commissioners are unconstitutional, overruling the 1935 precedent in Humphrey's Executor. The EDPB's point is narrow and precise: the existence and effective operation of independent supervisory authorities in a third country is a key factor in an adequacy assessment, and the FTC is one of the enforcement bodies underpinning the framework.

For now, nothing changes operationally. The Data Privacy Framework remains valid unless and until the Commission amends or withdraws its adequacy decision or a court strikes it down, so transfers can continue on the current basis. The significance is that the issue is now formally on the Commission's desk, from the body whose opinion carries the most weight in adequacy debates. Anyone who lived through Schrems I and II will recognise the pattern, and our advice to clients relying solely on the DPF is the same as it was in 2023: keep Standard Contractual Clauses and transfer impact assessments as a live fallback rather than a historical artefact. The independence of a foreign regulator is not usually a boardroom topic, but it is exactly the kind of structural fact that adequacy turns on.

The EDPB's draft anonymisation guidelines remain open for comment. As a shorter note for those tracking guidance, the EDPB's Guidelines 02/2026 on anonymisation, adopted for public consultation on 7 July 2026, are open until 30 October 2026. They set a single legal standard for when data is genuinely anonymous and therefore outside the GDPR, an assessment that matters directly to how training datasets and analytics pipelines are built. If anonymisation sits anywhere in your data strategy, this is the consultation to feed into before the window closes.

Sources

This article is general information about legal developments, not legal advice on any specific matter.