DORA
highEU · Operational resilience · In force · Jan 2025
Manage ICT concentration risk and prove a tested exit from every critical provider.
Relevance to your stack
If you are a financial entity, every critical ICT provider needs a documented, tested exit plan. Concentration on a single US hyperscaler is the exact risk the regime was written to address.
Read the official text→NIS2
highEU · Cybersecurity · Transposing · 2024 to 2026
Be accountable for the security and sovereignty of your whole supply chain.
Relevance to your stack
Management is personally accountable for supply chain security. That extends past your direct vendors to the sub-processors they rely on.
Read the official text→EU AI Act
criticalEU · AI governance · Phasing · full application Aug 2026
Document AI data governance, sources and audit trails for high-risk systems.
Relevance to your stack
Applies to UK businesses placing AI systems on the EU market. Requires system classification, conformity assessment and an inventory of what data reaches which model.
Read the official text→Artificial Intelligence (Regulation) Bill
mediumUK · AI governance · Private member's bill · introduced Mar 2025
Prepare for a UK cross-sector AI framework, while sector regulators act under existing law.
Relevance to your stack
The UK still has no cross-sector AI statute. This is a private member's bill rather than a government one, so treat it as direction of travel. Existing regulators already expect an AI inventory and risk documentation under current law.
Read the official text→GDPR / UK GDPR
criticalEU/UK · Data protection · In force · since 2018
Have a lawful basis, a record of processing, and control over every processor you use.
Relevance to your stack
Every US tool holding personal data is a processor you must document, contract with and be able to account for. The obligation does not stop at your direct vendor.
Read the official text→Schrems II transfers
criticalEU/UK · International transfers · In force · CJEU ruling Jul 2020
Run a Transfer Impact Assessment before relying on any US-jurisdiction processor.
Relevance to your stack
Using a US-jurisdiction SaaS tool requires a documented Transfer Impact Assessment showing whether supplementary measures are sufficient given US surveillance law. Most organisations have never written one.
Read the official text→US CLOUD Act
criticalUS · Government data access · In force · since 2018
Understand that EU data residency does not by itself put data beyond US legal reach.
Relevance to your stack
US authorities can compel a US-headquartered provider to produce data it controls, wherever in the world that data is stored. Choosing an EU region from a US provider does not remove this exposure.
Read the official text→EU Data Act
mediumEU · Data governance · Applicable · 12 Sep 2025
Remove cloud lock-in and block unlawful third-country government access to EU data.
Relevance to your stack
Gives you switching and portability rights against your cloud provider, and obliges providers to resist unlawful third-country access requests. Useful leverage when negotiating an exit.
Read the official text→Data (Use and Access) Act 2025
mediumUK · Data protection · In force · Part 5 from 5 Feb 2026
Work to the reformed UK regime, including its own test for international transfers.
Relevance to your stack
UK reform is done, not pending. The Act introduces a UK data protection test for transfers rather than the EU essential equivalence test. EU adequacy for the UK was renewed in December 2025 and runs to 27 December 2031.
Read the official text→EUCS
mediumEU · Cloud certification · Framework · Oct 2025
Meet residency, key-control and transparency criteria for cloud sovereignty.
Relevance to your stack
The common yardstick buyers increasingly ask about. Residency, key control and resistance to foreign legal compulsion are scored separately, so EU hosting alone does not pass.
Read the official text→eIDAS 2.0
lowEU · Digital identity · In force · wallet rolling out
Move toward sovereign identity and EU Digital Identity Wallet readiness.
Relevance to your stack
If your identity layer is Okta, Auth0 or Microsoft Entra, wallet acceptance and sovereign identity support become a roadmap question rather than a switch you can flip.
Read the official text→EU Digital Markets Act
lowEU · Competition · In force · Mar 2024
Use your new portability and interoperability rights against gatekeeper platforms.
Relevance to your stack
Works in your favour. If you depend on a designated gatekeeper, portability and interoperability obligations make an exit materially cheaper than it was.
Read the official text→Cloud & AI Development Act
mediumEU · Cloud certification · Proposed · 3 Jun 2026 · around Q4 2027
Prepare for four sovereignty assurance tiers tied to procurement eligibility.
Relevance to your stack
Grades sovereignty across four assurance levels and ties them to public procurement eligibility. If you sell to the public sector, your own stack becomes a bid qualifier.
Read the official text→Why this matters
6 critical or high-impact regimes are already in force or applying. Each shapes how lawfully, and how easily, you can keep running on US-jurisdiction providers. A formal compliance review with qualified counsel is the right next step.