Half-Year Review: Digital Regulation Now and in the Near Future
- Katri Aarnio

- Jun 17, 2025
- 4 min read
EU digital regulation has undergone a major transformation in recent years. New legislation has been introduced at a rapid pace in areas ranging from online services and artificial intelligence to data use and cybersecurity. Nor does the pace appear to be slowing, as further obligations will become applicable in the near future.
Below, we have compiled an overview of recent developments in digital regulation and the new obligations on the horizon.
Major online platforms under scrutiny
The EU Digital Services Act, or DSA, entered into application in stages during 2023 and 2024. It imposes extensive obligations on various digital service platforms, including requirements to address illegal content and improve transparency towards users. The European Commission and national supervisory authorities have already initiated their first enforcement actions. X, for example, is being investigated for potential infringements relating to practices that manipulate users and a lack of transparency in advertising.
Very large online platforms acting as so-called gatekeepers have also had to update their practices since May 2023 as a result of the EU Digital Markets Act, or DMA. The DMA aims to improve competition and transparency within the ecosystems of major technology platforms. In April 2025, the European Commission imposed the first fines under the DMA. Apple was fined EUR 500 million for restrictions imposed in its App Store that prevented application developers from making sufficient use of alternative distribution channels. Meta was fined EUR 200 million for its “consent or pay” model, which required Facebook and Instagram users to pay in return for more limited processing of their personal data.
Towards risk-based AI regulation With enthusiasm around artificial intelligence at its peak, the first obligations under the EU AI Act became applicable in February 2025. The development, provision and use of AI systems involving prohibited practices must now be discontinued. Organisations have also had to consider what types of training and other measures are needed to meet their obligation to ensure an adequate level of AI literacy.
To clarify some of the questions left open by the AI Act, the Commission published non-binding guidance in early 2025 on matters including the definition of an AI system, prohibited AI practices and the AI literacy obligation. Further changes are approaching rapidly, as the remaining obligations under the AI Act will become applicable in stages between 2025 and 2027. The requirements concerning high-risk AI systems will have a particularly significant effect on both providers and deployers.
Fairer rules for the data market As data plays an increasingly important role in society, the EU has sought to facilitate its free movement between different operators within the internal market. A key legislative initiative supporting this strategy is the Data Act, most of whose obligations will apply from 12 September 2025. The regulation focuses particularly on connected products and Internet of Things devices. In future, users of these devices must be given access to the data generated by them. The Data Act also prohibits the use of unfair contractual terms relating to data where such terms have been unilaterally imposed on another business.
The Data Act will also affect cloud services, and vendor lock-in situations are expected largely to become a thing of the past. Among other things, switching charges that restrict customers from changing cloud service providers will gradually be abolished. Cloud service providers will be required to assist customers with switching services, and customers will be entitled to terminate a cloud service with two months’ notice. The near future will show how the detailed contractual practices develop and what effects the obligations under the Data Act will have, for example, on the pricing of cloud services.
Preparing for cybersecurity threats through regulation
The obligations under the long-awaited NIS2 Directive entered into force in Finland on 8 April 2025, when the Directive was finally implemented nationally through the Cybersecurity Act. As cybersecurity threats increase, organisations operating in critical sectors now have statutory obligations to manage cybersecurity risks and notify the authorities of significant security incidents. The new cybersecurity regulatory framework does not end with the Cybersecurity Act. Further requirements will follow in the coming years under the Cyber Resilience Act, or CRA. The CRA will apply to hardware and software products with digital elements that can be connected, either directly or indirectly, to another device or network. Operators falling within its scope still have time to prepare. The obligations concerning the reporting of vulnerabilities will apply from 11 September 2026, while the requirements concerning the cybersecurity features of products will apply from 11 December 2027.
Cybersecurity threats have also been addressed through sector-specific regulation. In particular, the Digital Operational Resilience Act, or DORA, which became applicable on 17 January 2025, has had a significant impact both on financial-sector entities and on IT service providers supplying services to the financial sector. The beginning of the year saw an extensive round of contract updates as the requirements of DORA were negotiated into agreements between financial entities and IT service providers. The Commission has also drafted and published several regulatory technical standards specifying the requirements of DORA in greater detail. Supervisory authorities are currently carrying out criticality assessments aimed at identifying the critical IT service providers that will become subject to direct regulatory oversight. The designations are expected to take effect in autumn 2025.
What does the future hold?
Within just a few years, the EU’s digital regulatory framework has developed into an extensive body of legislation with a genuine impact on companies’ day-to-day operations. The breadth of the reforms and the speed at which they have been implemented have prompted many organisations to review their processes, contracts and technical solutions. There is no pause in sight. The Commission and national authorities have also demonstrated their willingness to intervene where shortcomings are identified. Enforcement can therefore be expected gradually to extend beyond the largest operators.
For organisations, this means above all that they must remain alert. New regulation is not merely an administrative obligation. It is often also a strategic question. How can services be designed to be user-oriented and competitive while also complying with regulatory requirements? Although the amount of regulation may feel burdensome, it also offers opportunities for differentiation. Operators that address the new requirements and opportunities at an early stage may be able to turn their regulatory obligations into a competitive advantage.
As regulation becomes more stringent, clear direction and practical interpretation are more important than ever. We support our clients with both.

Katri Aarnio
Counsel
050 306 2031
To receive our articles directly by email, subscribe to the Folks newsletter here.



