Choose your location?
  • Global Global
  • Australian flag Australia
  • Canadian flag Canada (FR)
  • French flag France
  • German flag Germany
  • Irish flag Ireland
  • Italian flag Italy
  • Polish flag Poland
  • Qatar flag Qatar
  • Spanish flag Spain
  • UAE flag UAE
  • UK flag UK

Regulations that will change the way you do business in 2026

27 July 2026
The latest article, as part of our Legal Operations regulatory insights, explores key regulatory developments. The regulatory landscape across the UK and European Union continues to shift at pace. Here are five of the most consequential developments from June 2026 that your compliance and legal teams need on their radar right now.

EU AI Act transparency obligations – Code of Practice issued, August deadline approaching

On 10 June 2026, the European Commission issued a voluntary Code of Practice on the marking and labelling of AI-generated content to help providers and deployers of AI systems comply with transparency obligations under Article 50 of the EU AI Act, which applies from 2 August 2026. The Code sets out practical measures to ensure that AI-generated or AI-manipulated content – including deepfakes and text on matters of public interest – is clearly labelled, and that users are informed when interacting with AI systems such as chatbots. It distinguishes between obligations for AI providers and those who deploy AI in their operations.

August 2026 is not a distant deadline – it is weeks away. Any organisation using AI in a customer-facing or content-generating capacity needs to assess its disclosure practices against the Code now. The distinction between providers and deployers is particularly important: businesses that deploy AI built by third parties cannot assume that compliance obligations rest with their technology supplier alone.

UK Cyber Security and Resilience Bill – Now in the House of Lords

On 17 June 2026, the UK Cyber Security and Resilience (Network and Information Systems) Bill completed its passage through the House of Commons and received its First Reading in the House of Lords, advancing to the Second Reading stage. The Bill amends the Network and Information Systems Regulations 2018 to strengthen cybersecurity and resilience requirements for operators of essential services and certain digital service providers. Critically, it expands the scope of regulated entities, enhances incident reporting obligations, strengthens regulatory oversight and enforcement powers, and introduces new measures to improve the security and resilience of network and information systems supporting essential activities.

The Bill's passage through the Commons means it is on the cusp of becoming law. Businesses in digital infrastructure, managed services, and critical supply chains – many of which did not fall within the original NIS Regulations – need to assess now whether they will be in scope and what obligations will apply. Waiting for Royal Assent before beginning that assessment will not leave adequate time to comply.

New Data Protection Complaint-Handling Framework – Already in force

On 23 June 2026, the UK Information Commissioner's Office confirmed that new statutory requirements for handling data protection complaints had come into force on 19 June 2026, following implementation of the relevant provisions of the Data (Use and Access) Act 2025. The framework requires organisations to maintain accessible procedures for receiving and handling complaints, acknowledge complaints within prescribed timeframes, investigate concerns appropriately, and communicate outcomes clearly to complainants. The ICO also issued guidance covering common complaint types, including subject access requests, data accuracy concerns, and direct marketing issues.

This is not a consultation or a proposal – it is already law. Organisations that do not have a compliant internal data protection complaints process in place are in breach of their statutory obligations as of 19 June 2026. Given that effective complaints handling is one of the ICO's stated criteria when assessing regulatory action, the absence of a compliant process is an immediate and quantifiable risk.

UK Deforestation Due Diligence Framework – New obligations on the horizon

On 23 June 2026, the UK Department for Environment, Food & Rural Affairs (DEFRA) published a policy paper setting out the UK's proposed approach to deforestation regulation in Great Britain. DEFRA intends to introduce legislation requiring businesses with annual turnover exceeding £1 million that use specified forest-risk commodities – including wood, cattle, cocoa, coffee, palm oil, rubber, and soy – to conduct due diligence, maintain evidence of compliance with relevant local laws, establish due diligence systems, report on relevant activities, and collect geolocation data on product origins. The proposed framework is intended to operate consistently with the EU Deforestation Regulation and implementation is expected in 2027.

While the operative date is 2027, the due diligence and traceability infrastructure that this framework requires takes considerable time and investment to build. Businesses in food manufacturing, retail, logistics, and agricultural supply chains that have not yet assessed their exposure to forest-risk commodities need to begin that work now. Supply chain traceability at the commodity origin level is not something that can be retrofitted in a matter of weeks.

EU e-Declaration system for posted workers – Provisional agreement reached

On 23 June 2026, the Council of the European Union and the European Parliament reached a provisional agreement on a regulation establishing an EU-wide e-Declaration system for posted workers. The system would require the European Commission to create a multilingual public interface enabling businesses to submit posting declarations electronically, reducing administrative burdens and supporting compliance with the Posted Workers Directive. The agreement provides for a standardised e-Declaration form, limits additional information requests by Member States, and introduces functionalities enabling employers to upload supporting documents and give posted workers electronic access to their declaration information.

This content has been prepared based on regulatory and legislative updates identified across UK and EU jurisdictions as of June 2026. It is intended for awareness purposes and does not constitute legal advice.

TAKE A LOOK AT LAST MONTH'S ARTICLE

Further Reading