UK law
UK government calls for evidence about digital product records policy
The UK government has launched a call for evidence on a potential UK digital product records (DPR) policy. The government is asking for views about the potential benefits, costs and practical implications of DPRs to inform the development of future UK policy. It is also asking about the impact of existing digital product record requirements, including the EU Digital Product Passport, and if a UK approach should align with international frameworks. The key topics discussed are implementation priorities, business costs, supply chain readiness, consumer impacts, sustainability, interoperability and the types of product information that could be included. The call for evidence ends on 21 September 2026.
NCSC issues guidance on responding to and recovering from highly disruptive cyber attacks
The National Cyber Security Centre (NCSC) has published guidance on how to respond to, and recover from, highly disruptive cyber attacks. Section 1 sets out the immediate activities to undertake in the first few hours to contain and assess damage, implement governance, and establish lines of communication. Section 2 describes how to set up and run a recovery programme and supporting activities during the first few days, and potentially weeks. The recovery programme will develop dynamically as new information from the investigation emerges. It will focus on measures that support rebuilding an organisation to minimum viable operations and helping its people. Section 3 focuses on the organisational rebuild phase, when an organisation starts to recover its processes and return to business as usual.
House of Commons’ Digital and Communications Committee launches inquiry into Online Safety Act 2023
The House of Lords Digital and Communications Select Committee has launched an inquiry into the Online Safety Act 2023. It will examine whether the Online Safety Act has begun to make online services safer for UK users. The Committee will consider Ofcom’s implementation and enforcement of the Act’s provisions, the changes made by regulated online services, and what further action may be needed to improve the UK’s online safety regime. Serious concerns have been raised that the regime is currently ineffective. Ofcom has faced criticism for not going far enough or fast enough in its efforts to hold online services and tech companies to account. At the same time, new harms continue to emerge as technologies evolve. The deadline for written submissions is 7 September 2026
EU law
AI Omnibus in force as of 27 July 2026
On 27 July 2026, the AI Omnibus entered into force across the EU, extending timelines and introducing administrative simplification. The AI Omnibus, proposed as part of the digital omnibus package on 19 November 2025, is aimed at delivering a targeted simplification of the AI rulebook while preserving strong safeguards for people’s safety and fundamental rights. It also aims to support innovation and competitiveness by easing compliance for smaller businesses, extending timelines, expanding testing and experimentation opportunities, and providing greater legal clarity for companies developing and deploying AI in Europe. Much of the wider AI Act comes into force on 2 August 2026.
European Commission publishes new guidance to support businesses’ implementation of the Cyber Resilience Act
The European Commission has issued new guidance on how to apply the Cyber Resilience Act, aimed at helping businesses prepare for mandatory cybersecurity requirements and reporting obligations. The guidance explains how the rules apply in practice. It clarifies which products fall within the scope of the Act, what constitutes a substantial modification, how support periods should be understood, and how to meet reporting obligations and risk assessment requirements. It also responds to questions raised by businesses, giving particular attention to microenterprises and small and medium-sized enterprises. It includes practical examples and use cases to help reduce unnecessary administrative burden. It highlights that recent developments in frontier AI models with cybersecurity capabilities make swift and correct implementation of the Cyber Resilience Act even more important. The Cyber Resilience Act, in force since December 2024, sets mandatory cybersecurity requirements across the full lifecycle of digital products, with reporting obligations applying from 11 September 2026. Organisations must comply by December 2027.