Europe prepares for a regulatory rearmament of the digital: the new frontier of power is in the algorithms

Brussels prepares for the return a regulatory rearmament on the digital agenda, cybersecurity, and telecommunications while the Twenty-Seven elevate technological sovereignty to the highest political level.

8 minutes

ILUSTRACIONES (1200 x 675 px) (1200 x 675 px)
Add DEMÓCRATA to Google

Published

8 minutes

The digital wallet has monopolized a good part of the conversations in Brussels over the last few months, but no one considers the discussions closed in view of the new political course. Community legislators are preparing for a new technological offensive in a long-range battle with which the European Union aims to strengthen its digital sovereignty and reduce its strategic dependencies.

New regulatory frameworks for Artificial Intelligence, cybersecurity, and telecommunications will again take center stage in much of the community debates after the holiday break. The objective is no longer solely to regulate the risks associated with new technologies, but to determine who controls the infrastructures, the providers, and the industrial capacities that will sustain the European economy in the coming decades.

According to what Demócrata has been able to confirm, digital matters have acquired such magnitude that the president of the European Council would have conveyed to the heads of State and Government of the Twenty-Seven his intention to, for the first time, include a specific item on the agenda of an upcoming European Council summit in Brussels dedicated to advances in disruptive new technologies.

European Council -

Digital transformation has thus become one of the major legislative priorities of the second term of the president of the European Commission, Ursula von der Leyen, and Brussels is willing to elevate its processing and political discussion to the highest institutional level.

In a letter addressed to the heads of Government of the Twenty-Seven in February, the president of the community Executive acknowledged that "digital and Artificial Intelligence will profoundly transform all aspects of our economies". A statement that summarizes the shift in focus that European technology policy has experienced: from sectoral regulation to a cross-cutting strategy directly linked to competitiveness, economic security, and strategic autonomy.

From regulatory leadership to "technological rearmament"

The truth is that, little by little, the European Commission has been showing its cards in what can already be defined as a «European technological rearmament». After an initial period in which the continent was a world pioneer in regulating areas such as Artificial Intelligence, Brussels has begun to review how to apply that regulatory framework without compromising the ability of European companies to compete.

Last November, the Commission adopted what is known as "Digital Omnibus", with the intention of simplifying or adjusting certain elements of the European Artificial Intelligence framework. The review came at a particularly sensitive moment, with the implementation of new regulatory obligations and the growing pressures from the industry to prevent bureaucratic burdens from becoming a competitive disadvantage.

In practice, the process involved extending certain flexibilities and adaptation mechanisms, especially for small and medium-sized enterprises, while opening an intense debate about the limits of regulatory simplification.

If the co-legislators were able to come away with something to celebrate from those negotiations, it was the introduction of the prohibition of certain "deepfake" tools and systems known as "nudification" through Artificial Intelligence. The measure responds to the attempt to strengthen protection against the generation of non-consensual sexual content and child abuse material.

The battle in the negotiation room revolved precisely around avoiding excessive delays in the implementation of the new obligations. Ultimately, the timeline ended up consolidating an extension for certain elements over the next two years, without giving up on incorporating new prohibitions related to the most harmful uses of Artificial Intelligence.

Laura Ballarín - European Parliament -

"At the same time that the prohibition of these nudification systems through Artificial Intelligence was included, we managed to maintain the obligation of digital literacy," said Laura Ballarín, the MEP and negotiator for the Socialist Group, in a conversation with Demócrata.

The position of the Eurochamber, as the socialist explained, was to defend that "this omnibus could not serve to roll back" the guarantees already achieved during the negotiation of the European legislation on Artificial Intelligence.

The new "cookies"

At the same time, Brussels reinforced its strategy with the presentation of a plan to create a European single window aimed at simplifying compliance with cybersecurity incident notification obligations.

The approach aims to reduce the regulatory fragmentation that many companies currently face, forced in certain cases to report the same incident to different national and European authorities depending on the applicable legislation.

The proposed simplification also ended up extending to the consent system for "cookies", one of the main symbols of everyday digital bureaucracy for citizens and businesses. The goal is to reduce the number of notices that appear during browsing and allow users to indicate certain preferences through a more centralized system.

The model would allow, among other issues, to save consent settings through browsers and reduce the repetition of requests, although the legal debate on data protection and the effective scope of consent remains open.

Cybersecurity, the core of strategic autonomy

The other major axis of the community digital offensive has focused on cybersecurity. During the last political term, the European Executive presented various initiatives aimed at deploying a new legal and operational framework to respond to the increasing sophistication of digital threats.

Through the EU Action Plan on Cybersecurity and Artificial Intelligence, Brussels seeks to define mechanisms to assess and mitigate the risks associated with advanced AI models, while strengthening the capabilities of the European Union Agency for Cybersecurity, ENISA. The Commission foresees, in this line, the development of a European platform for testing Artificial Intelligence applied to cybersecurity, with the aim of analyzing both the defensive potential of these technologies and the new attack vectors they may generate.

One of the most sensitive points of the reforms lies in the future European Cybersecurity Law, especially regarding the management and protection of telecommunications networks.

Sophie Viger, coding school 42's Director, left, and Henna Virkkunen, center, durign a visit to coding school 42, in Paris, France. -

The Commission has promoted a mandatory reduction of risks in mobile networks, particularly regarding those providers considered to be “high risk”. A matter that directly affects companies like Huawei and has generated friction between Brussels and some member states.

This issue has a direct impact in Spain, where the Government maintains active contracts with Chinese companies. During the last quarter of the past political term, the community Executive issued a warning to Spain regarding the dependencies that could arise from a concession linked to the storage of telephone interceptions from the SITEL system.

The community Executive has already identified on several occasions the Chinese operators Huawei and ZTE as suppliers that present “significantly greater risks” compared to other players in the 5G network market. Consequently, Brussels has committed to limiting their access to certain avenues of European funding and to strengthening the protection of corporate and institutional communication networks on the continent.

In light of this legislative file, sources from Moncloa consulted by Demócrata defended that it should be the member States themselves who maintain decision-making capacity on whether a country, a supplier, or a product poses excessive structural risks.

A position that also extends to decisions on which assets and information and communication technologies should be considered essential from a security standpoint.

We argue that this classification should be based on objective, proportionate, and viable technical criteria that guarantee legal security for all parties and respect national sovereignty,” they stated during the negotiations from the Ministry for Digital Transformation and Public Function, led by Óscar López.

The major telecommunications reform

At the same time, at the beginning of this year, the cabinet of the executive vice president Henna Virkkunen announced its proposal for a Digital Networks Regulation, intended to replace, once it comes into force, the current European Electronic Communications Code.

The initiative aims to update the regulatory framework for telecommunications to adapt it to a scenario marked by the deployment of very high-capacity networks, the expansion of data centers, the development of cloud computing, and the increasing dependence on critical digital infrastructures.

"The European innovation begins with a truly connected Europe. A resilient and high-performance digital infrastructure is essential to reinforce Europe's leadership in innovation, competitiveness, and digital sovereignty", noted Virkkunen during the presentation of the proposal in Strasbourg.

The message summarizes the philosophy of the new community stage: connectivity has ceased to be considered solely an economic service to become a strategic infrastructure.

Chips, cloud, open source, and quantum computing

The last link in this chain before the political rentrée was the presentation of the Technology Sovereignty Package, aimed at strengthening the industrial capacity of the continent and consolidating a European digital infrastructure capable of competing with the United States and China.

The strategy is articulated around several pillars:

  • Chips Regulation: aimed at reinforcing production, supply, and European resilience in the field of semiconductors.

  • Cloud Development Law: aimed at significantly increasing European data center capacity and promoting infrastructure and storage solutions considered strategic.

  • Open Source Strategy: designed to reinforce European autonomy in software, digital tools, and reusable technologies.

  • European Quantum Law: conceived to boost research, industrial development, and the deployment of European capabilities in computing and quantum technologies.

The new community bet implies, in practice, a paradigm shift in the digital policy of the European Union.

Brussels seeks to abandon a merely reactive position, fundamentally focused on resilience and response to external risks, to adopt a more assertive strategy aimed at controlling the critical technologies that will determine the economic, industrial, and political balance of the coming decades.

Kaja Kallas, Ursula von der Leyen, and António Costa, from left to right -

The ultimate aspiration is that the European Union can continue to be a global partner open to trade and international cooperation, but that, at the same time, has the necessary technological tools to act autonomously when its strategic interests require it.

In a context marked by technological rivalry between the United States and China, the European Commission seems to have definitively assumed that digital sovereignty has ceased to be an exclusively industrial or regulatory issue.

The control of networks, data, semiconductors, Artificial Intelligence, the cloud, and quantum technologies has become a central element of the economic and geopolitical security of the European project. And, after the holiday break, Brussels is preparing to take that battle to a new political dimension.