New rules on data, cybersecurity, AI and exports
The Data Act and the first parts of the AI Act have applied in the EU since 2025, and further obligations follow in stages. COBACK reads publications from legislators and authorities such as the EDPB and the BSI, checks them against your products, services and markets and turns a relevant change into tasks.

Topics and rules
What is changing, who in the company works with it and which legal acts are behind it.
Data protection and data transfers
The GDPR and the German Federal Data Protection Act govern how product development, support and marketing may process personal data. Many companies base transfers to the US on the adequacy decision for the EU-US Data Privacy Framework, and the EU General Court dismissed an action for its annulment in September 2025. The Commission proposed changes to the GDPR in its digital omnibus of November 2025, and the procedure is still running.
Examples
- Regulation (EU) 2016/679 (GDPR)
- German Federal Data Protection Act (BDSG)
- Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework)
- Data (Use and Access) Act 2025 (United Kingdom)
Data access and digital services
The Data Act has applied since 12 September 2025. Connected products placed on the market after 12 September 2026 must make their data accessible to users by design, and providers of cloud services may no longer charge switching fees from 12 January 2027. Providers of intermediary services such as hosting or online platforms also have obligations under the Digital Services Act. Product management, sales, contracting and legal are affected.
Examples
- Regulation (EU) 2023/2854 (Data Act)
- Regulation (EU) 2022/2065 (Digital Services Act)
- Digitale-Dienste-Gesetz (DDG, Germany)
Cybersecurity in your organisation
Germany's act implementing the NIS2 Directive has applied since 6 December 2025. Besides cloud providers, data centres and managed service providers it covers many other companies, requires risk management measures and a first report of significant incidents within 24 hours at the latest, and holds management responsible. Information security, IT operations and management are affected.
Examples
- Directive (EU) 2022/2555 (NIS2)
- German BSI Act (BSIG)
Security of products with digital elements
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents in their products through the single reporting platform to the competent CSIRT and ENISA, starting with an early warning within 24 hours. The main requirements of the Cyber Resilience Act apply from 11 December 2027. Implementing Regulation (EU) 2025/2392 gives the technical descriptions of the important and critical product categories. Product management, engineering, product security and support are affected.
Examples
- Regulation (EU) 2024/2847 (Cyber Resilience Act)
- Implementing Regulation (EU) 2025/2392
Artificial intelligence
The first prohibitions of the AI Act have applied since February 2025, the obligations for general-purpose AI models since August 2025 and most transparency obligations since August 2026. Under amending Regulation (EU) 2026/1744, obligations for high-risk AI under Annex III apply from 2 December 2027 and for high-risk AI in products under Annex I from 2 August 2028. Product management, data science, legal and data protection are affected.
Examples
- AI Act (EU) 2024/1689
- Regulation (EU) 2026/1744
Export control and sanctions
The Dual-Use Regulation controls exports of dual-use items, software and technology. The update of Annex I in force since 15 November 2025 added quantum computers and semiconductor manufacturing equipment among other items. Items of US origin, and in some cases foreign-made items with US content, are also subject to the US Export Administration Regulations. The Russia embargo prohibits supplying enterprise management software and industrial design and manufacturing software to the Russian government and to companies established in Russia. Export control, sales, product management and legal are affected.
Examples
- Regulation (EU) 2021/821 (Dual-Use Regulation)
- Delegated Regulation (EU) 2025/2003
- Export Administration Regulations (EAR, US)
- Council Regulation (EU) No 833/2014, Article 5n
Product liability and accessibility
The new Product Liability Directive expressly covers software and applies to products placed on the market after 9 December 2026. Since 28 June 2025, Germany's Accessibility Strengthening Act has required e-commerce services for consumers to be accessible, including the websites and apps they are offered through. Services provided by microenterprises are exempt. Product management, engineering, design and legal are affected.
Examples
- Product Liability Directive (EU) 2024/2853
- Directive (EU) 2019/882 (European Accessibility Act)
- Barrierefreiheitsstärkungsgesetz (BFSG, Germany)
The path of a change
Example: new Cyber Resilience Act product categories
01Law database
The EU Official Journal publishes Implementing Regulation (EU) 2025/2392 with the technical descriptions of the categories of important and critical products with digital elements.
02Relevance
COBACK checks it against the twin: according to the product pages in Confluence, your company sells identity and access management software. The score is 88 out of 100, with reasoning that cites the class I category for identity management systems.
03Open questions
Whether the software is shipped for installation or runs only as a cloud service is not in the twin, so COBACK asks instead of guessing. Product management answers, and the head of compliance marks the change as relevant.
04Task
Tasks follow: product management documents the classification by 20 October 2026. Product security plans the conformity assessment within 8 weeks. Information security checks the reporting process for actively exploited vulnerabilities within 2 weeks.
Working with COBACK
Rules for your products
COBACK checks new publications against the products, services and markets that the digital twin knows from Confluence, SharePoint, Google Drive, Slack and your website.
A score with its reasoning
Every publication gets a score from 0 to 100 with the reasoning, the sources it relied on and the facts about your company it used.
Questions instead of assumptions
Whether a service is installable or runs only in the cloud often decides which obligations apply. Where that fact is missing, COBACK asks. A person decides whether a change is relevant.
Tasks for product, security and legal
A relevant change becomes tasks with steps, owners and deadlines, for example for product management, information security, data protection or export control.
Frequently asked questions
Does COBACK screen our customers against export or sanctions lists?
No. COBACK does not screen business partners against lists. It reads new legal acts, such as amendments to the Dual-Use Regulation or the Export Administration Regulations, and shows which of them affect your products and markets.
We also make hardware. Does COBACK help with substance restrictions?
There is an optional product compliance module for that. It checks bills of materials against substance lists such as the REACH candidate list (SVHC), REACH Annex XVII, RoHS and PFAS, shows data gaps and produces reports.
Will COBACK tell us whether NIS2 or the Cyber Resilience Act applies to us?
COBACK scores new publications for your company and gives the reasoning, the sources and the facts it used. A person at your company makes the decision, and COBACK does not give legal advice.
How does COBACK know our products?
From its digital twin, which is filled from connected systems such as Confluence, SharePoint, Google Drive or Slack, public registers, your website and a questionnaire. Nobody has to upload files by hand.










