EU Digital Rules Enforcement Intensifies – DMA, DSA, GDPR, AI Act
EU AI Act enforcement began Aug 2, 2026, with transparency and labeling obligations for deployers taking immediate effect—no grace period. Article 50 obligations now active; penalties up to €15M or 3% turnover; machine-readable marking extended to December. Germany has split enforcement. EU AI Omnibus enters into force with clarified deadlines: high-risk Annex III rules delayed to Dec 2027. EU fines Google €890M under DMA with 60-day compliance deadline, extends to AI Overviews. DSA charges Meta; TikTok probe; ChatGPT and Roblox designated as DSA VLOPs; EC fines AliExpress €550M; artist challenges Meta account deletion under DSA. Trade tensions with US escalate: Trump announces Section 301 investigation into EU tech fines, threatening tariffs or retaliation. July 2026 roundup: CJEU upheld Apple's DMA gatekeeper; DSA preliminary findings against Meta/TikTok; CSAM detection reinstated until 2028; AI Omnibus bans CSAM generation. GDPR reform moving on four fronts; entity-relative anonymization accepted but vague. Regulators shift to proactive AI surveillance of ads. New: Italy fines TIM $10.9M for consent laundering via spoofed calls—landmark GDPR enforcement for ad tech lead-gen networks, rejecting code-of-conduct defense. A recent deep dive on GDPR procedural reform highlights complainant rights and DPA discretion shifts. Privacy regulations continue to drive ad-tech consolidation. New: France's under-15 social media ban with mandatory age verification and ad restrictions, enforced by ARCOM—major escalation in EU child safety regulation directly impacting ad targeting and platform compliance. New: EU AI Act enforcement powers now live—Commission can demand pre-release evaluations and fine up to 3% turnover, directly impacting US AI labs like Anthropic and OpenAI, with extraterritorial reach and requirement for an EU representative. The AI Office now has exclusive competence for certain sanctions, with asymmetry between EU and national enforcement levels, and cost recovery mechanisms. New: European Commission preliminary finds TikTok in breach of DSA for default public accounts and recommendation of minors' content, reinforcing child safety enforcement under DSA. New: Apple loses EU DMA challenge, forcing App Store opening—reshaping in-app ad markets and data access. New: EU AI labeling rules now mandatory as of Aug 2, with specific disclosure requirements for AI-generated ads and synthetic content in publishing. A recent article on AI content disclosure rules provides practical compliance guidance for ad tech and digital marketing. Britain's light-touch AI regulation contrasts sharply with the EU's approach; the UK minister signaled openness to future regulation if voluntary testing fails. New: EU Commission orders Google to share anonymized search data with rivals and improve Android AI assistant interoperability under DMA—key enforcement action with implications for ad tech and AI competition. New: Top 5 GDPR fines in 2026 roundup highlights Reddit £14.47M fine for children's data and age assurance failures, IQVIA €5M for pseudonymised data still being personal data, and basic security failures—directly relevant to ad tech compliance. New: Roblox may become first gaming platform under EU DSA, expanding VLOP regulation to gaming and requiring systemic risk assessments, non-profiling feeds, ad transparency, and data sharing. New: UK PM Burnham signals tougher cyber and AI regulation, closer alignment with EU AI Act, challenging previous light-touch approach. New: The era of unlabeled AI content in Europe is ending—music industry implications highlight that copyright disputes remain unresolved but labeling obligations create new compliance risks for ad tech using AI-generated audio. New: Europe's Summer of DSA Enforcement analysis highlights the challenge of translating fines into actual design changes, directly relevant to ad tech compliance since design remedies affect recommendation systems and ad targeting. The framework for harm prevention, mitigation, and governance is useful for understanding regulatory expectations. New: Digital Omnibus details: watermarking extension to Dec 2026, CSAM/revenge porn prohibition, GDPR reform proposals including pseudonymisation safeguards. New: Meta's automated ad review failed to detect AI-generated CSAM ads, exposing DSA duties of care and Section 230 exceptions. New: EU AI labels enforcement analysis with geopolitical context (China, Australia, Japan). New: Switzerland FADP vs GDPR comparison for cross-border compliance.