Technology

On 3 June 2026, the European Commission published several legislative and policy measures wrapped up in one “tech sovereignty” package (see our posts summarising the package as a whole here, and diving deeper into the Cloud and AI Development Act here). But the EU’s tech sovereignty drive has a long history, and is by no means limited to this package.

In this post, we take a closer look at the current and forthcoming EU legislative measures aimed at increasing the resilience of services provided in the EU against external, malicious influence, a key aspect of tech sovereignty. Relevant legislation falls into two broad categories: (1) laws promoting cyber resilience generally, to prevent malicious actors from disrupting services and critical infrastructure; and (2) laws focused on building supply chain resilience and reducing dependencies on certain external actors by building European industrial capacity in key tech sectors.

Continue Reading Looking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilience

On June 4, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a sweeping discussion draft of their Great American Artificial Intelligence Act. The latest bipartisan AI legislation quickly met bipartisan skepticism, particularly concerning the draft’s approach to federal preemption of state AI rules, with many House Democrats opposing the broad preemption for frontier model developers, while many House Republicans and other stakeholders lamented the bill’s omission of preemption for state laws reaching other parts of the AI ecosystem. 

The bill would also establish mandatory disclosure and risk-mitigation requirements for frontier models and task the Center for Artificial Intelligence Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) with oversight of federal AI-related research and analysis, standards and guidelines development, and risk-mitigation activities.  

Continue Reading Backlash to Bipartisan AI Omnibus Illustrates Preemption Impasse

Executive Summary

2026 has been a dynamic year so far for federal regulation of automotive safety. Federal regulators have demonstrated a sustained commitment to regulatory reform and innovation, while simultaneously advancing efforts to facilitate the deployment of autonomous vehicles. Congress has also renewed its focus on vehicle safety and automation

Continue Reading Federal Vehicle Safety at Midyear: Regulatory Relief, Legislative Momentum, and the Road to the Broader AV Deployment

Since our prior post on Singapore’s Model AI Governance Framework for Agentic AI, Singapore’s Infocomm Media Development Authority (“IMDA”) has published an updated version (Version 1.5) (the “Updated Framework”), incorporating feedback from over 60 organizations.

The Updated Framework, published on May 20, 2026, retains the same four-pillar structure—(1) assess and bound the risks upfront, (2) make humans meaningfully accountable, (3) implement technical controls and processes, and (4) enable end-user responsibility—but expands the guidance in several notable respects. These include a new discussion of multi-agent systemic risks, more granular guidance on technical controls, and real-world case studies illustrating how the Framework can be applied across sectors. We summarize some of the key updates below.

Continue Reading Singapore Updates Model AI Governance Framework for Agentic AI

The UK Government today announced that it intends to ban social media platforms from offering services to children under 16, alongside wider restrictions on certain online functionalities that the Government has identified as harmful to children.

The announcement follows the conclusion of the Department for Science, Innovation and Technology’s (“DSIT”) consultation, “Growing up in the online world,” which received more than 116,000 responses (we originally wrote about that consultation here). The Government intends to bring the first regulations to Parliament before the end of the year using powers created by the Children’s Wellbeing and Schools Act 2026 (“CWSA”), with protections expected to come into force in Spring 2027. Today’s announcement is the latest in a series of significant developments reshaping the UK’s online safety framework. We summarize some of these latest developments below.

Continue Reading Online Safety in the UK: Social Media Ban for Under 16s and Other Recent Developments

On 3 June 2026, the European Commission (“Commission“) published its proposal for a Regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem—the Cloud and AI Development Act (“CADA Proposal“). The CADA Proposal sits at the heart of the Commission’s broader Tech Sovereignty Package (which we describe at a high level here), and aims to address what the Commission perceives as two critical vulnerabilities in the EU’s digital landscape: a structural deficit in data centre capacity and a dependence on a limited number of non-EU cloud computing service providers.

Continue Reading The EU Cloud and AI Development Act in Depth

On 19 May 2026, the European Commission published its long-awaited draft, non-binding guidelines on the classification of high-risk AI systems (“HRAIs”) under the EU AI Act (the “Guidelines”). Across three documents—covering general principles, high-risk classification in the context of regulated products (Annex I), and high-risk use cases (Annex III)—the Commission sets out its approach to one of the AI Act’s central questions: when does an AI system fall within the high-risk regime (and, just as importantly, when does it not)?

Continue Reading EU AI Act Update: The European Commission Publishes Draft Guidelines on HRAIs

California’s new autonomous vehicle regulations create the state’s first pathway for testing and deploying heavy-duty AVs while imposing a more rigorous permitting, safety-case, reporting, and enforcement framework for all AV manufacturers.

Finalized by the California Department of Motor Vehicles (the DMV) on April 28, 2026, the regulations (the Regulations) introduce significant new safety and oversight requirements, and expand California’s AV framework to include heavy-duty vehicles over 10,000 pounds, which had previously been excluded. The Regulations do not alter the California Public Utilities Commission requirements that separately apply to AV companies operating robotaxis in the state.

Continue Reading California’s New AV Rules Open Door to Heavy-Duty Deployment While Imposing Significant New Compliance Obligations

On June 3, the European Commission published its Tech Sovereignty Package, a set of legislative and policy initiatives designed to address what the Commission characterizes as Europe’s technological dependencies on non-European suppliers. The Package marks a further step in the evolution of the EU’s technology policy, with initiatives spanning the full tech stack—from chips and infrastructure to software, cloud, and artificial intelligence. Through this “ecosystem” approach, the Commission seeks to reduce supply-side dependencies by strengthening domestic capabilities in Europe and stimulating demand in downstream sectors.

The Package comprises four components: two legislative proposals—(i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0—as well as two non-legislative initiatives—(iii) the EU Open Source Strategy and (iv) a Strategic Roadmap for Digitalisation and AI in Energy.

Continue Reading EU Tech Sovereignty Package

EU Member States are currently designing two possible new Important Projects of Common European Interest (“IPCEIs”) to support the development of AI and compute infrastructure in the EU (together the “Digital IPCEIs”), subject to European Commission (“Commission”) approval.

On 10 March 2026, the “matchmaking” phase under the IPCEI on Artificial Intelligence (“IPCEI-AI”) was officially launched in Berlin. It brings together companies whose AI projects have been pre-selected through national calls for expressions of interest (“CEIs”) in each participating Member State. Its objective is to form European consortia eligible for State co-funding under the IPCEI-AI. National CEIs in 17 participating Member States are now closed; Finland and Lithuania are still expected to launch their CEIs.

A second digital IPCEI on Compute Infrastructure Continuum (“IPCEI-CIC”) was launched in late 2025 by 15 Member States. Several of these participating Member States – including Belgium, Croatia, Estonia, Finland, France, Germany, Hungary, Lithuania, the Netherlands, Romania, Slovakia, and Spain – have not yet launched their CEIs.  

Continue Reading Important Projects of Common European Interest (IPCEIs) on Artificial Intelligence and Compute Infrastructure Continuum