Tech Policy & Regulation Weekly — Jul 30, 2026
Photo: lyceumnews.com
Week of July 30, 2026
The Big Picture
Calendars, court filings, and control points defined the week. This was not a wholesale regulatory reset; it was the kind of incremental movement that hardens into next year’s compliance plan. The European Union clarified when its toughest artificial-intelligence obligations may arrive, China expanded its export-control perimeter, and privacy and competition regulators began developing a shared vocabulary for cases where data power becomes market power.
This Week's Stories
📅 Europe’s AI Compliance Calendar Is Finally Coming Into Focus
The European Union’s artificial-intelligence compliance calendar is starting to lock in. GamingTechLaw reports that the Digital Omnibus package was published on July 24 with fixed deadlines for two important categories of high-risk artificial-intelligence systems. Under the reported timetable, standalone systems covered by Annex III face obligations from December 2, 2027, while artificial intelligence embedded in regulated products under Annex I follows on August 2, 2028. (EU’s Digital Omnibus Quietly Resets AI Act Deadlines)
The distinction is consequential. Annex III covers uses such as employment, education, credit, and access to essential services; Annex I addresses artificial intelligence inside products already governed by European Union safety rules. A fixed calendar lets developers decide which products to redesign, document, register, restrict, or retire. It also gives procurement teams firmer dates for demanding evidence from suppliers.
More time, however, can quickly become more procrastination. The test is whether companies begin building risk-management files, human-oversight controls, and technical documentation before 2027 rather than treating the extension as permission to wait. Early contractual demands from European customers will provide the clearest signal that the market’s deadline is arriving before the legal one. (European Regulators Begin Joint Privacy-and-Competition Guidelines Process)
China’s Export-Control List Is Becoming a Corporate Map
China is drawing its export-control boundaries around named companies. On July 24, China’s Ministry of Commerce added 14 European Union entities to an export-control list, immediately prohibiting exports of dual-use goods—items, software, and technology that can serve civilian and military purposes—to those organizations. Reuters reported that China framed the measure as retaliation for the European Union’s latest Russia-related sanctions.
The important change is precision. Commodity-wide restrictions disrupt entire markets; entity-level bans can isolate particular defense, aerospace, and advanced-manufacturing supply chains with far less collateral damage. If China continues using named lists this way, export controls become a tool for targeting individual corporate networks rather than merely conserving strategic materials.
The controls matter only if they produce shortages, customs delays, denied licenses, or expensive supplier substitutions. Broad exemptions or readily available alternatives would blunt their effect. Watch European Union trade data, licensing decisions from China’s Ministry of Commerce, and disclosures from the 14 listed entities for evidence that the restrictions are reaching production lines rather than remaining diplomatic theater. (China Targets 14 EU Firms With New Dual‑Use Export Controls)
Europe Is Preparing to Regulate Data Power From Both Directions
Europe’s privacy and competition regulators are moving toward the same problem from opposite directions. The European Data Protection Board and the European Commission are jointly developing guidelines on the interaction between data-protection and competition law. The European Data Protection Board has opened an expression-of-interest process for a stakeholder event scheduled for October 15; it has not yet published draft guidelines. (European Regulators Begin Joint Privacy-and-Competition Guidelines Process)
The project confronts a recurring platform-regulation problem: access to personal data can reinforce market power, while an antitrust remedy requiring broader data access can create General Data Protection Regulation risks. If the final guidance supplies a workable method for balancing those rules, product decisions involving consent, interoperability, advertising, and data portability could face review under two legal theories at once.
Success would mean specific instructions for investigations and remedies—not another recital of broad principles. Failure would mean guidance so abstract that the European Commission’s competition officials and national data-protection authorities continue reaching incompatible conclusions. The October event and the eventual draft will show which path the regulators have chosen. (European Regulators Begin Joint Privacy-and-Competition Guidelines Process)
Anthropic Says Google’s Antitrust Remedy Could Squeeze AI Funding
Google’s antitrust remedy could reshape artificial-intelligence financing. TechShots reported on July 25 that Anthropic told the federal court overseeing the Google search antitrust case that parts of the United States Department of Justice’s proposed remedies could stifle artificial-intelligence investment. According to the report, Anthropic objected to potential advance-notice requirements and restrictions affecting investments or commercial arrangements involving Google.
The dispute exposes an uncomfortable second-order effect. A remedy designed to restrain Google could also make it harder for smaller artificial-intelligence developers to secure capital, cloud capacity, and distribution from Google—potentially strengthening companies with their own infrastructure instead. Antitrust relief aimed at one market could quietly reshape financing in another.
Anthropic’s argument remains a litigant’s position, not the court’s conclusion. The remedy order will provide the decisive signal: if the court narrows investment restrictions or creates exceptions for minority funding and ordinary cloud agreements, Anthropic’s warning landed. If broad notice and approval requirements survive, major artificial-intelligence investments involving dominant platforms could begin functioning like transactions subject to continuing regulatory supervision.
Europe’s VPN Ruling Separates the Tool From the Conduct
Europe’s top court has drawn a line between a technical tool and the conduct that may misuse it. TechRadar reports that the Court of Justice of the European Union, in litigation concerning the Anne Frank diaries, treated virtual private networks as lawful technical tools and declined to equate VPN use by itself with copyright infringement. A VPN encrypts traffic and routes it through another server, commonly for security, privacy, or remote access. (EU Court Says VPNs Are Lawful Tools in a Landmark Copyright Case)
The distinction reaches well beyond media streaming. Corporate security systems, testing environments, and privacy services all rely on routing technology that can also be used to cross territorial boundaries. Treating the tool itself as unlawful would have exposed infrastructure providers to sweeping liability theories based on possible misuse rather than demonstrated infringement.
The ruling’s practical reach will depend on how national courts apply it. If later decisions focus on specific infringing acts, the tool-versus-conduct distinction will hold. If copyright enforcement instead migrates into licensing contracts, geo-blocking requirements, and account restrictions, VPNs will remain lawful while their everyday uses become more contractually constrained.
⚡ What Most People Missed
- The privacy-and-competition collision: The European Data Protection Board–European Commission process could determine whether data-sharing remedies open markets—or simply exchange an antitrust problem for a General Data Protection Regulation violation.
- Delhi’s early training-data defense: On July 24, the Delhi High Court denied ANI Media’s request for an interim injunction against OpenAI in ANI Media Pvt. Ltd. v. OpenAI OpCo LLC. The ruling provisionally treated storage of publicly available ANI Media material for ChatGPT training as potentially protected by India’s fair-dealing doctrine, but it was an interim decision rather than a final judgment.
- Apple’s pleading-bar victory: On July 24, the United States Court of Appeals for the District of Columbia Circuit affirmed Apple’s win in PhantomALERT Inc. v. Apple Inc., holding that PhantomALERT had not plausibly defined the relevant antitrust market. The decision does not broadly validate Apple’s App Store conduct; it shows that exclusion from a platform is not enough without a market theory that survives the opening round.
- The Pentagon’s information-control fight: The Washington Post reports that news organizations including Fox News rejected a Pentagon press policy they said would constrain access and reporting. The fight is adjacent to technology regulation rather than a core legal-tech development, but it matters to defense contractors operating where classification rules, disclosure duties, and public communications already overlap.
- NOYB’s 1,741-consent test: NOYB alleges that dict.cc attempted to collect 1,741 consents through a single action. The complaint turns a familiar cookie-banner irritation into a sharper legal question: at what point does the sheer number of bundled choices make “informed” consent implausible?
📅 What to Watch
- If European customers begin demanding AI Act documentation before the 2027 and 2028 deadlines, procurement contracts—not regulators—will set the real compliance calendar.
- If China grants few exceptions to the 14 listed European Union entities, entity-level export controls are becoming a repeatable method for disrupting specific corporate supply chains.
- If the European Data Protection Board and European Commission propose rules for data-access remedies, privacy review will become part of antitrust remedy design rather than a separate compliance exercise.
- If the Google remedy order preserves broad oversight of artificial-intelligence investments, federal antitrust judgments can become a durable approval layer for technology financing.
- If European copyright disputes shift from claims against VPN technology to account terms and licensing restrictions, the Court of Justice of the European Union protected the tool while moving the fight into contract enforcement.
- If the Delhi High Court’s interim reasoning is adopted in a final judgment, India could become one of the first major jurisdictions to give artificial-intelligence developers a meaningful statutory defense for training on publicly available material.
The Closer
A compliance officer circling 2028 in red ink, a customs agent inspecting a crate of dual-use components, and a copyright lawyer glaring at a perfectly legal VPN walk into the same regulatory week.
Meanwhile, Europe is preparing a rulebook for when antitrust demands your data and privacy law tells you to keep your hands off it—which should make for a relaxing October workshop.
Keep the counsel close.
Forward this to the person still calling all of this “just a product issue.”