Dispatch from Brussels: Updates on EU Tech Policy

28 Aug 2026 01:00 PM

Welcome to this edition of the Dispatch from Brussels. The institutions are slowly emerging from their recess and the legislative machinery is preparing for a busy September. Below is a roundup of some of the developments that have taken place over the past two weeks and a quick look ahead at what to expect for September.  

Artificial Intelligence  

EU AI Act Service Desk sets out how the Act applies to AI agents: The Commission's AI Act Service Desk has published guidance addressing a question many have raised repeatedly. It opens by conceding that "AI agent" is used inconsistently in public debate and has no legal definition, while noting broad agreement that an agent must at minimum be able to take in and process input from its environment and then execute actions that interact with or affect that environment. The conclusion is that agents are not a distinct regulatory category. The existing definitions of an AI system in Article 3(1) and of a general-purpose AI model in Article 3(63) are treated as sufficient to capture them, on the basis that an agent will typically contain at least a GPAI model and will constitute an AI system because it usually has an interface, which counts as a system component. The consequences follow from that classification rather than from anything agent specific. 

EU AI Office reports on the fourth Signatory Taskforce meeting under the GPAI Code of Practice: The AI Office has published its account of the Taskforce's 17 July session, which addressed the Safety and Security Chapter and the Copyright Chapter. On safety and security, the Office set out how analysis of model usage can form part of post-market monitoring under Measure 3.5. Its reasoning is that evidence of how a model is actually used, and how it behaves in use, is complementary to pre-deployment evaluation rather than a substitute for it, and feeds into several stages of systemic risk assessment. Participants also discussed so-called marginal-risk clauses, the provisions under which a provider might contemplate matching a competitor that has pushed capability frontiers by releasing an unsafe model. The Office was clear that any such clause could be relied on only in exceptional circumstances, and subject to appropriate evidentiary and procedural safeguards. Members whose organisations are signatories, or who are weighing signature, should read that qualification carefully, as it narrows the clause considerably from how it is sometimes characterised. On copyright, the discussion focused on Measure 1.3(4), under which signatories commit to publishing information allowing affected rightsholders to identify which web crawlers the provider uses and how those crawlers read robots.txt directives, and to notify rightsholders automatically when that information changes. 

Data 

EU Commission publishes overview of Digital Europe Programme data projects: On 20 August, the EU Commission set out how a set of Digital Europe Programme actions are supporting secure and efficient data sharing and reuse by businesses, public authorities and researchers. The page provides a useful overview of projects the EU Commission has funded alongside some open calls.  

Some key developments to look out for in September