Regulatory & Technology Tracker

What changes, when — and what it means.

Key EU and Polish regulatory milestones for technology-driven businesses. Every entry is dated, sourced and reviewed.

National implementations rolling

NIS2 — cybersecurity duties for essential and important entities

Risk management measures, incident reporting and management accountability — with national implementations, including Poland’s amended KSC Act, now in force and phasing in obligations.

EU Applicable Act now Last verified: 2026-07-18
Guidance evolving

GDPR × AI — supervisory practice keeps moving

Legal bases for training data, automated decision-making and data-subject rights in AI contexts are being shaped by EDPB opinions and national decisions — assumptions age quickly.

EU Guidance pending Monitor Last verified: 2026-07-18
Stable regime

P.S.A. — Poland’s simple joint-stock company as a venture vehicle

Flexible share structure, board-of-directors option and low capital requirements make the P.S.A. a practical vehicle for startups and advisory firms — with governance discipline as the price of credibility.

PL Applicable Monitor Last verified: 2026-07-18
2024-02-17Applies since

DSA — platform duties under active enforcement

Notice-and-action, trader traceability, transparency reporting and ad rules apply to intermediaries and marketplaces — with Commission enforcement setting precedents.

EU Applicable Monitor Last verified: 2026-07-18
2025-01-17Applies since

DORA — digital resilience in the financial sector

Applicable since January 2025: ICT risk management, incident reporting, resilience testing and register of ICT third-party arrangements. Supervisory attention is now on evidence, not policies.

EU Applicable Act now Last verified: 2026-07-18
2025-09-12Applies since

Data Act — access, sharing and cloud switching

Applicable since 12 September 2025: user access to connected-product data, B2B sharing terms, unfair-clause limits and cloud switching rights that reshape vendor contracts.

EU Applicable Prepare next Last verified: 2026-07-18
2026-07-01Transition periods ended (max)

MiCA — crypto-asset markets fully in the licensed era

Fully applicable since December 2024; national grandfathering for existing CASPs ended by 1 July 2026. Operating without authorisation is now a market-access and partner-risk issue.

EU Applicable Act now Last verified: 2026-07-18
2026-09-11Reporting obligations apply

Cyber Resilience Act — reporting duties land first

From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents (24h early warning). Full secure-by-design obligations follow 11 December 2027.

EU In force Act now Last verified: 2026-07-18
2027-07-10Applies from

AMLR — the EU single rulebook for AML/CFT

Directly applicable from 10 July 2027: harmonised CDD, 25% UBO threshold, €10,000 cash cap, expanded obliged entities. One year left for risk assessment, data and vendor readiness.

EU Published Act now Last verified: 2026-07-18
2027-12-02Annex III high-risk (per omnibus agreement)

EU AI Act — timeline reshaped by the digital omnibus

Prohibitions and GPAI duties already apply. The provisional omnibus agreement moves Annex III high-risk obligations to 2 Dec 2027 and embedded systems to Aug 2028; content-transparency lands 2 Dec 2026.

EU Partly applicable Act now Last verified: 2026-07-18
2028-01-01Direct supervision begins

AMLA — the EU AML authority ramps up

Operational in Frankfurt, publishing technical standards and preparing to directly supervise selected high-risk financial entities from 2028.

EU Applicable Prepare next Last verified: 2026-07-18