Brussels Effect Falters as Europe Votes to Weaken AI and Data Rules
The EU's Digital Omnibus revises the AI Act and GDPR to spur competitiveness, but it raises a critical debate over whether the bloc is weakening the very rules that make its regulatory influence global.
cnn.com
In this article
On 29 June 2026, the Council of the European Union gave its final green light to a regulation that rewrites key provisions of the Artificial Intelligence Act, the bloc's flagship legislation on high-risk AI systems. The vote, which concluded the legislative track for the so-called Digital Omnibus on AI, was not a formality; it marked the culmination of a bruising six-month negotiation that saw member states and the European Parliament deadlocked through most of April, with talks stretching across roughly twelve hours before collapsing and pushing into May. The final text, now published in the Official Journal, alters the AI Act's compliance deadlines for high-risk systems, narrows the scope of certain transparency obligations, and recalibrates the enforcement powers of national competent authorities. For a bloc that has spent the better part of a decade building the world's most ambitious digital regulatory architecture, the Omnibus represents something unfamiliar: a step backward, taken deliberately, in full public view.
The legislative manoeuvre is the centrepiece of a broader competitiveness agenda that has reshaped Brussels policymaking since the Draghi report on European competitiveness landed in September 2024. That report argued, in blunt terms, that Europe's regulatory burden was becoming a structural disadvantage, and the Commission under President Ursula von der Leyen's second mandate has taken the message to heart. The Digital Omnibus package, first published on 19 November 2025, proposed amendments to the AI Act, the General Data Protection Regulation (GDPR), the ePrivacy Directive, and several other digital rulebooks. As The Next Web reported in a sharp analysis by Ana-Maria Stanciuc, the package amounts to a deliberate dismantling of regulatory ambition: "The EU's Digital Omnibus weakens the AI Act and GDPR in the name of competitiveness." The question now, for policymakers from Brasília to Tokyo, is what Europe's self-correction means for the rest of the world.
The premise of the Brussels Effect, as articulated by Columbia Law School professor Anu Bradford in her 2020 book of the same name, is that the European Union regulates global markets not through coercion but through market size and institutional capacity. Multinational firms, facing the choice between maintaining a single global production standard or bifurcating their operations into an EU-compliant track and a rest-of-world track, typically choose the former. Compliance with EU rules becomes the de facto global standard; the regulation is exported without Brussels ever needing to ask. Bradford's thesis was built on cases such as the GDPR, which by 2024 had inspired broadly similar data-protection frameworks in more than a dozen jurisdictions including Brazil, Japan, South Korea, and California, and the REACH chemicals regulation, which had reshaped supply chains from Shenzhen to São Paulo.
If the Brussels Effect were a simple, unidirectional force, the events of the first half of 2026 would read as a powerful confirmation. On 8 July, the General Court of the European Union dismissed Apple's challenge to its designation as a gatekeeper under the Digital Markets Act (DMA), a ruling that affirms the Commission's authority to impose interoperability mandates, data-portability requirements, and anti-self-preferencing rules on the world's largest technology platforms. The same week, on 10 July, the Digital Omnibus on AI entered into force, bringing with it the first enforceable provisions of the AI Act: the chatbot transparency rules, the ban on certain AI practices deemed to carry unacceptable risk, and the delayed but now legally binding timetable for high-risk system compliance. The enforcement machinery is no longer theoretical; it is producing binding court judgments and regulatory deadlines that companies must meet or face fines.
On the sanctions side, the Commission has been equally active. On 28 May 2026, it fined the Chinese e-commerce platform Temu €200 million, roughly $232 million, for failing to prevent the sale of illegal and unsafe products to EU consumers, including baby toys containing toxic materials and faulty electronics. The penalty, reported by the Associated Press, was the second ever issued under the Digital Services Act (DSA), after the €120 million fine imposed on X, formerly Twitter, in December 2025. It was also the first DSA enforcement action against a Chinese-headquartered platform, a signal that the Commission intends the DSA to apply with full extraterritorial reach, regardless of where a platform's engineering headquarters happens to be located. A week later, on 1 July, the EU introduced a €3 customs handling fee on low-value e-commerce parcels, a measure widely understood as targeting Shein, Temu, and AliExpress, whose business models depend on shipping vast volumes of small, duty-free packages directly from Chinese warehouses to European doorsteps.
These enforcement actions suggest a regulator that is not only writing rules but policing them, and doing so against both American and Chinese firms with an impartiality that few other jurisdictions can muster. The DMA's first review, published by the European Commission on 28 April 2026 alongside a staff working document, concluded that while it was still too early to assess the regulation's full market impact, the designation process had already compelled gatekeeper platforms to make changes to their operating systems, app stores, and data practices that would not have occurred absent legal obligation. The review, analysed in detail by JD Supra, placed particular emphasis on cloud computing and artificial intelligence services as sectors where gatekeeper power is consolidating and where future DMA designations may be warranted.
Yet the Brussels Effect was never supposed to be measured solely by enforcement record. The mechanism Bradford described is regulatory diffusion: foreign jurisdictions adopt EU-style rules because the cost of regulatory divergence exceeds the cost of alignment. And here the picture grows considerably more complicated. The same Digital Omnibus that the Council approved on 29 June does not merely adjust compliance timetables; it alters the substantive scope of the AI Act, narrowing the definition of what constitutes a high-risk system and reducing the obligations on general-purpose AI model providers in ways that bring the regime closer to the more permissive frameworks advanced by the United Kingdom and Singapore. For a jurisdiction that, until very recently, positioned itself as the gold standard in AI governance, the Omnibus is an admission that the gold standard may have been set too high, and that the cost of compliance was beginning to deter the very investment the EU needed to attract.
The Omnibus as a signal to the world
This is the crux of the matter. If the Brussels Effect operates through the mechanism of unilateral regulatory ambition, what happens when the ambition is scaled back? One possibility is that the effect is self-correcting: the EU overshot on the AI Act, the compliance burden proved disproportionate, and the Omnibus simply recalibrates to a level that is both enforceable at home and exportable abroad, a kind of regulatory equilibrium that preserves the EU's influence while acknowledging that the first draft was too ambitious. This is the optimistic reading, and it finds support in the fact that the Omnibus was shepherded through the legislative process with broad support from the European People's Party and Renew Europe, the two largest blocs in the Parliament, as well as a majority of member states in the Council.
The pessimistic reading is that the Omnibus fractures the credibility of the European regulatory model. If the EU itself concludes that its AI rules were too strict, why should legislatures in Brazil, India, or Indonesia, all of which have studied the AI Act closely, adopt its pre-Omnibus provisions? The answer is that they may not. Several jurisdictions that had been expected to follow the EU model are now pausing. South Korea's AI Basic Act, passed in December 2024, already diverged from the AI Act on several key definitions, and the Omnibus has widened that gap. Canada's Artificial Intelligence and Data Act (AIDA), still under parliamentary review as of mid-2026, has been explicitly revised in committee to avoid what one Liberal MP described, in a committee hearing covered by the Canadian Press, as "the Brussels overreach problem." The EU's regulatory corrections are being watched, and they are being factored into foreign legislative calculus in real time.
The Omnibus negotiations also exposed a deeper tension within European digital policy that has been building for years. The GDPR, long the crown jewel of the Brussels Effect, is now the subject of a parallel simplification track that has pitted the European Data Protection Board (EDPB) against the Commission's Directorate-General for Justice. On 8 June 2026, Tech Times reported that senior data protection regulators from across the bloc convened in Brussels for what it described as a "high-stakes debate" on proposed changes to the GDPR's personal data definition, changes that the Digital Omnibus would introduce as part of its broader simplification mandate. The privacy watchdogs' concern is that narrowing the definition of personal data to reduce compliance costs would, as a side effect, shrink the GDPR's jurisdictional reach, undermining the very mechanism by which the regulation became a global benchmark.
There is a further complication, and it concerns the relationship between different pieces of the EU digital rulebook. In April 2026, The Next Web reported on a collision between the EU's child safety legislation and its privacy architecture: the ePrivacy derogation that had allowed platforms to conduct voluntary scanning for child sexual abuse material (CSAM) had expired, and the proposed CSAM Regulation, intended to create a new legal basis for such scanning, remained stalled in trilogue negotiations. The result was a legal vacuum in which platforms faced contradictory obligations: child safety laws that required them to detect and remove CSAM, and privacy laws that prohibited the scanning necessary to do so. The impasse illustrates a structural problem with the Brussels Effect thesis: it assumes coherence. But European regulation is not always coherent, and when it is not, the export model breaks down.
What carries, and what does not
A more granular accounting of the Brussels Effect in mid-2026 suggests that it operates unevenly across regulatory domains. The DMA's gatekeeper designation framework, with its bright-line thresholds and sector-specific obligations, has proven relatively portable; the United Kingdom's Digital Markets, Competition and Consumers Act, which received royal assent in May 2024, borrows heavily from the DMA's structural approach, and Japan's Smartphone Software Competition Act, enacted in June 2024, reflects a similar design philosophy. The DSA's systemic risk assessment requirements are being studied by lawmakers in Australia and India, though neither has yet adopted a comparable framework. The AI Act, by contrast, is proving harder to export, both because its risk-tiered structure is complex to transpose into domestic law and because the Omnibus has introduced a moving target problem: foreign legislators cannot copy a text that is still being rewritten.
The GDPR remains the strongest case for the Brussels Effect, but even here the evidence is mixed. The regulation has unquestionably reshaped global privacy practice; Apple's App Tracking Transparency framework, Google's consent management platform, and the proliferation of cookie banners across the English-language web are all artefacts of GDPR compliance that non-European users encounter daily. Yet the specific provisions of the GDPR have not been adopted uniformly. California's privacy regime, while inspired by the GDPR, diverges on the definition of sensitive data, the right to deletion, and the private right of action. India's Digital Personal Data Protection Act of 2023 takes a strikingly different approach to consent and data localisation. The EU's regulatory influence is real, but it is neither automatic nor uniform; it is mediated by domestic political economies, and it weakens when the EU's own commitment to its rules appears to waver.
What the first half of 2026 has made clear is that the Brussels Effect has a twin, and the twin is the Brussels Cost. The Draghi report quantified that cost in terms of foregone investment and lost productivity; the Omnibus is the legislative response. But every regulatory simplification that reduces the cost of doing business in Europe also reduces the incentive for firms to adopt European standards globally. If the post-Omnibus AI Act is less demanding, a company that complies with it is doing less than a company that complied with the pre-Omnibus text would have done, and the global standard, such as it is, sinks accordingly. This is not a failure of the Brussels Effect; it is a feature of it. The effect works only when the EU's rules are stringent enough, and the EU's market attractive enough, that alignment is worth the cost. Adjust either variable and the calculus shifts.
The e-commerce customs fee of €3 per parcel, introduced on 1 July 2026, is a different kind of regulatory export altogether. It is not a standard that foreign firms can adopt globally; it is a border adjustment that applies only to goods entering the EU customs union. In that sense it is the inverse of the Brussels Effect: rather than shaping behaviour through market access conditional on compliance, it shapes behaviour through a price mechanism that makes the market itself more expensive to serve. Temu and Shein cannot comply their way out of the fee; they can only absorb it, pass it on to consumers, or restructure their logistics to hold inventory within the EU. The fee is a reminder that not everything Brussels does is designed to be exported. Some tools are strictly territorial, and their effectiveness depends on the EU's willingness to use them unilaterally.
The procedural calendar for the remainder of 2026 will test both the Brussels Effect and the Brussels Cost in concrete ways. The Digital Omnibus on GDPR is expected to enter trilogue negotiations in September, with a target of final adoption by the end of the year. The EDPB has indicated that it will issue a formal opinion on the personal data definition changes before the summer recess ends, and the opinion is likely to be critical. The DMA's enforcement directorate, housed within DG Competition, is expected to issue its first non-compliance decisions against designated gatekeepers before the end of the third quarter. And the AI Act's high-risk system obligations, now confirmed for phased entry into force beginning in February 2027, will require the first wave of conformity assessments to be underway by the end of this year. Each of these milestones will be watched not only in Brussels but in every capital where legislators are writing, or revising, their own digital rulebooks.
The Brussels Effect was never a law of nature. It was an observation about market incentives, and incentives can change. The European Union spent the first half of this decade building an extraordinarily ambitious regulatory architecture. It is now spending the second half deciding which parts of that architecture it can afford to keep. The rest of the world is watching, and it is taking notes, not only on what Brussels builds but on what it tears down.