This page tracks the status of every major EU law that determines where AI systems can process private communications, what jurisdiction governs that processing, and what compliance obligations fall on the companies deploying AI tools. Eight legislative files are on our watchlist: the CSA Regulation (Chat Control), the EU AI Act and its 2026 Omnibus amendments, the EU Data Act, the proposed ePrivacy Regulation (withdrawn), the EUCS cloud certification scheme, the NIS2 Directive, and DORA. The quick-reference table below gives the current snapshot; each section gives the context you need to understand what the law actually does and what it means for call and meeting data.
Quick-reference status table
| Law | Status | Last move | Next milestone |
|---|---|---|---|
| Chat Control 1.0 (ePrivacy derogation) | In force | Extended 9 Jul 2026 to Apr 2028; E2E encryption explicitly excluded | April 2028 expiry |
| Chat Control 2.0 (CSA Regulation) | Trilogue stalled | June 2026 round collapsed; carve-out in 1.0 not binding on 2.0 | September 2026 resume, Irish presidency |
| EU AI Act (base regulation) | In force | General application 2 Aug 2026; high-risk Annex III deferred by Omnibus | Annex III: 2 Dec 2027. Annex I: 2 Aug 2028 |
| AI Omnibus amendments | Adopted | Parliament 16 Jun 2026; Council 29 Jun 2026. Awaiting OJ publication | Entry into force on OJ publication |
| EU Data Act | In force | Generally applicable 12 Sep 2025 | 12 Sep 2026: data-by-design for new connected products |
| ePrivacy Regulation | Withdrawn | Withdrawn Feb 2025. Digital Omnibus replacement under negotiation | Digital Omnibus agreement targeted late 2026 |
| EUCS (Cloud Cybersecurity Certification) | Draft / impasse | CSA2 review ongoing; sovereignty tiers unresolved | No binding timeline |
| NIS2 Directive | Transposing | Most states transposed; first penalties Q1 2026 | October 2026 full compliance deadline for covered entities |
| DORA | In force | Active supervisory enforcement cycle, 2026 | ICT register audits ongoing; critical provider designations |
CSA Regulation (Chat Control)
Chat Control 1.0 extended 9 July 2026 to April 2028 with E2E encryption excluded. Permanent CSA Regulation (2.0) stalled after June 2026 trilogue collapse. Resumes September 2026.
The EU's Child Sexual Abuse Regulation (CSA Regulation, formally COM(2022)209) proposes binding detection orders compelling messaging and email providers to scan private communications for child sexual abuse material and grooming. Because scanning at that scale requires inspecting messages before encryption or circumventing encryption via client-side scanning, it became the most contested EU legislative proposal of the period. Understanding it requires distinguishing two separate instruments.
Chat Control 1.0 is the temporary derogation from the ePrivacy Directive (Regulation (EU) 2021/1232) permitting providers to voluntarily scan unencrypted messages for child abuse material. The Council adopted a revised version on 2 July 2026 and Parliament voted on whether to block it on 9 July 2026. The rejection motion received 314 votes against 276, but second-reading procedure required an absolute majority of all 720 MEPs (361 votes) to block the text. The motion fell 47 votes short and the extension stands until April 2028. A critical amendment was adopted alongside: communications protected by end-to-end encryption are explicitly excluded from the derogation's scope. WhatsApp, Signal, and iMessage are formally outside Chat Control 1.0's reach for this extension period.
Chat Control 2.0 is the permanent regulation, still in trilogue. After five negotiating rounds, the fifth session under the Cyprus Council presidency collapsed in June 2026 over the scope of "voluntary" scanning provisions and the path toward detection orders on encrypted services. Negotiations resume under the Irish Council presidency from September 2026. The encryption carve-out achieved in the 1.0 extension creates political pressure on negotiators but establishes no legal precedent binding the permanent regulation talks.
EUR-Lex procedure 2022/0155(COD) for the permanent CSA Regulation. EDPS/EDPB joint opinion, 28 July 2022. Fight Chat Control civil society tracker for vote tallies and procedural records.
What this means for call and meeting data
Chat Control 1.0 covers unencrypted messages only, and participation is voluntary. Encrypted calls themselves are outside scope. The question for organizations is what happens to call outputs once they leave the encrypted session: action item emails, CRM notes, transcript attachments shared over messaging platforms. If a covered provider's unencrypted messaging service carries meeting outputs, voluntary scanning under 1.0 could reach that content. The permanent regulation (2.0) remains the larger risk: if detection orders extend to business communications platforms, the jurisdiction of the court that can issue such an order against your meeting AI vendor becomes immediately operative. Our deeper analysis: Chat Control, Explained and After Chat Control: Why Where Your Conversations Get Processed Now Decides Everything.
EU AI Act and AI Omnibus
Base regulation in force since 1 Aug 2024. AI Omnibus adopted by Parliament 16 Jun 2026 and Council 29 Jun 2026, awaiting OJ publication. High-risk AI (Annex III) deadline deferred to 2 Dec 2027.
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, with obligations phased over four application dates. It is the world's first binding AI law and the framework governing AI systems used in employment, biometric identification, critical infrastructure, and general-purpose model deployment within the EU.
Three application dates are already past:
- 2 February 2025: Prohibited AI systems (Article 5) became applicable. These include AI that manipulates people using subliminal techniques, social scoring systems by public authorities, and certain biometric categorization systems. Systems in these categories must be removed from service.
- 2 August 2025: General-purpose AI (GPAI) model rules (Chapter V) and governance bodies became operational. GPAI providers must register, document capabilities, and, for models above the 10^25 FLOPs systemic-risk threshold, conduct adversarial testing and report serious incidents.
- 2 August 2026: General provisions apply to most AI systems, except high-risk systems under Annexes I and III, which the AI Omnibus deferred.
The AI Omnibus package reached provisional political agreement on 6-7 May 2026, was formally adopted by Parliament on 16 June 2026 and by the Council on 29 June 2026, and is awaiting Official Journal publication. It made two categories of changes:
Deadline deferrals: High-risk AI systems in Annex III (stand-alone applications including recruitment AI, AI assessing creditworthiness, AI for decisions about access to education or essential services, and AI monitoring workplace performance) now apply from 2 December 2027 instead of 2 August 2026. High-risk AI embedded in regulated products under Annex I (medical devices, machinery, aviation equipment, vehicles) applies from 2 August 2028 instead of 2 August 2027.
New prohibitions: AI-generated non-consensual intimate imagery and AI-generated child sexual abuse material are added to the Article 5 prohibited practices list, effective on OJ publication of the Omnibus.
EUR-Lex, Regulation (EU) 2024/1689 (AI Act). Council of the EU press release, 7 May 2026, on provisional AI Omnibus agreement. Council final adoption communiqué, 29 June 2026. European AI Office guidance: digital-strategy.ec.europa.eu.
What this means for call and meeting data
Call intelligence tools that analyze recordings to assess employee performance, score salespeople, or inform personnel decisions are candidates for high-risk status under Annex III. The Omnibus buys companies until December 2027 before the full obligations kick in: conformity assessment, technical documentation, human oversight mechanisms, transparency disclosures. Building audit trails and data governance into AI meeting tools now avoids a compliance redesign under a 2027 deadline. GPAI providers whose models underlie meeting AI (large language models used for transcription, summarization, and coaching) are already under the AI Act's GPAI obligations if they exceed systemic-risk thresholds. See our sovereignty guide: What Is Sovereign AI?
EU Data Act
Applicable since 12 Sep 2025. Data-by-design requirement for new connected products arrives 12 Sep 2026, two months from this update.
The EU Data Act (Regulation (EU) 2023/2854) establishes who may access and use data generated by connected products and related services within the EU. It entered into force on 11 January 2024 and became generally applicable on 12 September 2025.
The critical 2026 milestone: from 12 September 2026, connected products placed on the EU market must be designed so users can easily, securely, and directly access the data they generate, in real time and free of charge where technically feasible. This "data by design" requirement applies to any connected device that generates, processes, or transmits data in connection with its use, including smart meeting room systems, AI-enabled conferencing hardware, connected webcams and microphone arrays, and IoT devices that capture or process meeting audio or video. Products placed on the market before 12 September 2026 are exempt until 12 September 2027.
Data portability is central to the regulation: users have the right to have data generated by a covered product ported directly to a third-party service provider of their choice. For meeting AI, this means the data generated by conferencing hardware may be subject to portability obligations, depending on whether the device qualifies as a covered connected product. Provisions on unfair contractual terms in B2B data-sharing contracts apply from 12 September 2027.
EUR-Lex, Regulation (EU) 2023/2854. European Commission Digital Strategy: digital-strategy.ec.europa.eu/en/policies/data-act.
What this means for call and meeting data
The September 2026 data-by-design deadline is two months away as of this update. If your organization uses AI-enabled conferencing hardware, check with manufacturers whether their devices qualify as connected products under the Data Act and whether they have built the required data access architecture. For software-only meeting AI (cloud services that process audio without dedicated hardware), the direct obligations are narrower, but the portability provisions and contractual restrictions on data reuse will shape vendor contract negotiations through 2027.
ePrivacy Regulation
Formally withdrawn February 2025 after eight years of stalled negotiations. Digital Omnibus package proposes moving cookie rules into GDPR. Omnibus under negotiation; ePrivacy Directive still in force.
The proposed ePrivacy Regulation (COM(2017)10) would have replaced the ePrivacy Directive (2002/58/EC) with a unified regulation governing electronic communications privacy across the EU. The European Commission formally withdrew it in its 2025 Work Programme, published 11 February 2025, ending eight years of negotiation. Successive deadlocks arose over cookie consent rules, surveillance access for law enforcement, and the scope of communications metadata protections.
The Commission's replacement approach is the Digital Omnibus package (proposed November 2025). The relevant provisions would move cookie and consent rules from the ePrivacy Directive into the GDPR as new Articles 88a and 88b. Key proposed changes: a mandatory single-click reject button for non-essential cookies (matching the "accept all" button), a prohibition on re-displaying consent requests for six months after a user declines, and a requirement to honor browser-level consent signals. These provisions are under Council and Parliament negotiation, with agreement targeted for late 2026.
Until the Digital Omnibus passes and its provisions on electronic communications privacy enter into force, the existing ePrivacy Directive and its national transpositions remain in force. This includes the derogation mechanism that Chat Control 1.0 operates under.
European Commission Work Programme 2025, February 2025 (withdrawal entry). European Commission Digital Omnibus proposal, November 2025. EUR-Lex, Directive 2002/58/EC (current ePrivacy Directive, still in force).
What this means for call and meeting data
The ePrivacy Directive currently governs consent requirements for electronic communications within the EU. Recording a business call and processing it through AI requires consent compliant with national ePrivacy transpositions. The Digital Omnibus changes are not yet law, so current obligations are unchanged. When the Digital Omnibus does pass, consent architecture for web-based meeting interfaces may need updating if browser-level consent signals extend to WebRTC and similar communication protocols. The withdrawal of the standalone ePrivacy Regulation removes a potential communications-specific layer from the EU privacy framework and places more weight on the GDPR's general consent rules.
EUCS: EU Cybersecurity Certification for Cloud Services
Candidate scheme under development by ENISA since 2019. Not yet formally adopted. Sovereignty tiers still contested. CSA2 (revised Cybersecurity Act) would add binding development timelines.
The EU Cybersecurity Certification Scheme for Cloud Services (EUCS) is a candidate certification scheme under the EU Cybersecurity Act (Regulation (EU) 2019/881), developed by ENISA (the EU Agency for Cybersecurity). Once adopted, it would create tiered certifications (Basic, Substantial, High) for cloud services used in sensitive contexts, with requirements around security standards, incident management, and, at the highest proposed tier, data residency and operational sovereignty.
The most contested element is whether any sovereignty conditions survive into the final scheme. Earlier drafts included explicit requirements around provider headquarters jurisdiction, exclusion of non-EU law subpoenas, and operational independence from non-EU entities. These provisions were removed in more recent drafts under trade and political pressure. Whether any form of sovereignty condition re-enters through complementary legislation or member state requirements remains an open question.
The revised Cybersecurity Act (CSA2), part of the Digital Omnibus package, would introduce binding timelines requiring ENISA to complete scheme development within 12 months of a Commission request. This could accelerate EUCS adoption, but the substantive content of each tier, particularly the sovereignty question, must still survive the political negotiation.
ENISA EUCS candidate scheme documentation: enisa.europa.eu/publications/eucs-cloud-service-scheme. European Parliament think tank analysis on EUCS and CSA2, January 2026. Centre for European Policy, "EU Cloud Certification at an Impasse," 2026.
What this means for call and meeting data
EUCS matters because EU public sector bodies and regulated private entities increasingly require their cloud suppliers to hold EU cybersecurity certifications. If a High tier with meaningful sovereignty conditions is eventually adopted, it will determine whether major cloud providers can support regulated AI workloads including meeting AI for financial services, healthcare, and government clients. Until EUCS is formally adopted and the sovereignty tier is settled, organizations in sensitive sectors should monitor this actively and favor cloud providers positioned to pursue the highest certification tier when it exists. We covered the cloud sovereignty backdrop in The US CLOUD Act and the EU Data Center Loophole.
NIS2 Directive
Member state transposition deadline was October 2024. Most states have transposed; Commission pursuing infringement action against laggards. First enforcement penalties Q1 2026. Company compliance deadline October 2026.
The Network and Information Security Directive 2 (Directive (EU) 2022/2555, NIS2) replaced the original NIS Directive with significantly broader scope, stricter security requirements, and direct management-body liability. Member states had until 17 October 2024 to transpose it into national law. Most have now done so, though France, Ireland, Luxembourg, the Netherlands, and Spain were still finalizing their legislative procedures into 2026. The European Commission has launched infringement proceedings against non-transposing states. First administrative penalties against covered entities appeared in Q1 2026.
NIS2 distinguishes "essential entities" (energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management) from "important entities" (postal and courier services, waste management, manufacturing of critical goods, food, chemicals, digital providers). Many enterprise software companies and their large customers fall into at least one category.
Key obligations for organizations using AI meeting tools:
- Supply chain security (Article 21): Covered entities must assess and address risks arising from their relationships with suppliers and service providers. An AI meeting assistant that processes recordings of board calls, legal calls, or sensitive customer conversations is part of the ICT supply chain and must appear in the supply chain security assessment.
- Incident reporting (Article 23): Significant incidents trigger a three-stage process: early warning within 24 hours, incident notification within 72 hours (with severity assessment and indicators of compromise), and a final report within 30 days. A breach of meeting recordings or AI-processed call transcripts qualifies for most covered entities.
- Management liability (Article 20): Management bodies must approve cybersecurity risk management measures and can be held personally liable for infringements. This places board-level accountability on AI vendor selection, including the choice of jurisdiction for call data processing.
EUR-Lex, Directive (EU) 2022/2555. ECSO NIS2 Transposition Tracker: ecs-org.eu/policy/nis2-directive-transposition-tracker. National authority guidance from BSI (Germany), ANSSI (France), NCSC-NL (Netherlands).
What this means for call and meeting data
If your organization is subject to NIS2, your AI meeting vendor appears in your supply chain risk assessment. The practical questions: does the vendor have the contractual architecture to support your 24-hour early warning obligation? Can you get audit rights? Is the vendor's security certification sufficient for your national regulator, or will NIS2 guidance require something more specific? A vendor whose processing happens under EU jurisdiction, with EU-law audit rights, simplifies the compliance position compared to a US vendor requiring GDPR Article 46 transfer mechanisms layered on top of a NIS2 supply chain risk justification.
DORA: Digital Operational Resilience Act
Applicable from 17 January 2025 for financial entities. Active supervisory enforcement cycle in 2026. ICT register audits underway. Critical ICT provider designation framework operational.
The Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA) establishes binding ICT risk management requirements for EU financial entities: banks, investment firms, insurance companies, payment institutions, crypto-asset service providers, and others listed in the regulation. It became applicable on 17 January 2025. Unlike NIS2, DORA is a Regulation applying directly without member state transposition.
National competent authorities (BaFin in Germany, the AFM and DNB in the Netherlands, the ACPR and AMF in France) are running active supervisory review cycles in 2026. The second annual ICT third-party register submission cycle completed, with regulators flagging register completeness and accuracy as an enforcement priority. Supervisors have begun auditing incident classification systems and reporting timelines.
Key elements for organizations with financial entity clients or customers using AI meeting tools:
- ICT third-party register: Financial entities must maintain a complete register of all contractual arrangements with ICT third-party providers (the ITRE), submitted annually to national competent authorities. An AI meeting assistant used for earnings call preparation, board meetings, deal intelligence, or sales calls within a financial entity is in scope and must appear in the register with full contractual details.
- Critical ICT provider oversight: DORA empowers the European Supervisory Authorities (EBA, ESMA, EIOPA) to designate specific ICT providers as "critical" and subject them to direct supervisory oversight, including audit rights and mandatory remediation timelines. Major AI platforms serving the financial sector could receive this designation.
- Concentration risk: DORA explicitly requires financial entities to address concentration risk from over-reliance on single ICT providers. If all call intelligence processing routes through one US hyperscaler or US AI API, that concentration is documented and must be justified in the ICT risk framework.
- Incident reporting: Major ICT incidents require initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within 30 days. A breach of AI-processed meeting recordings or deal intelligence qualifies as a major ICT incident for most financial entities.
EUR-Lex, Regulation (EU) 2022/2554. European Banking Authority DORA Q&A and implementing technical standards. Joint ESA supervisory oversight framework documentation, 2025.
What this means for call and meeting data
For financial services organizations, DORA is the most immediately binding framework on AI meeting tool procurement. The ICT register is not optional: it is an annual supervisory submission. Every AI vendor in the meeting and call intelligence stack needs a contract that supports DORA's audit rights, incident notification timelines (4 hours for major incidents), and concentration risk documentation. Processing under EU jurisdiction with EU-law enforcement of data handling gives the in-house legal and compliance team a substantially cleaner answer when supervisors ask about ICT supply chain resilience.
What the full picture means for call and meeting data
Read these eight files together and the regulatory direction is consistent. The EU is not trying to prevent AI from processing business communications. It is requiring organizations to know three things: where that processing happens, under whose legal authority, and who can reach the data through that jurisdiction's legal process.
Chat Control puts scanning architecture on the political agenda in a way that is not going away. The permanent CSA Regulation remains unresolved. The mechanism the law is designed around, detection orders enforceable against communication providers, is jurisdiction-dependent by design. The encryption carve-out in the 1.0 extension is real progress, but it applies to the temporary derogation, not to the permanent regulation still in trilogue.
The AI Act's Omnibus deferrals buy time for high-risk AI compliance, not indefinitely. Prohibited AI and GPAI obligations are already in force. High-risk call intelligence tools face December 2027. Building transparency documentation and human oversight mechanisms now avoids a compressed rebuild under deadline pressure in late 2027.
The Data Act's September 2026 data-by-design deadline is two months from this update. For any organization that runs meetings through connected hardware, the clock is already running. NIS2 and DORA are in active enforcement. The AI meeting vendor is in the risk register. Supervisors are auditing it.
The practical question is not whether to comply with any of this. It is whether the AI tools on your call stack give you the contractual and documentary position to answer the regulator's next question with a single clear document rather than a chain of transfer agreements, jurisdictional risk assessments, and cross-border subpoena analyses. Numi processes meeting audio, transcripts, and coaching data on EU-jurisdiction infrastructure. Our data-flow map is at the compliance page.