The Next Phase of Europe's AI Rulebook: What the EU's Latest Digital Enforcement Means for Business
- THEMIS 5.0

- Jul 14
- 3 min read

For the past two years, organisations have been preparing for the EU AI Act. Compliance programmes have been launched, governance frameworks designed, and risk assessments updated. Yet, as we approach the next major milestone in the AI Act's implementation, a broader picture is emerging. Europe is not simply regulating AI, it is reshaping the competitive landscape for digital markets.
Last week, the European Commission issued binding measures requiring Google to open key Android functions and certain search data to rival AI providers under the Digital Markets Act (DMA). The decision is designed to reduce barriers to competition and enable third-party AI assistants to compete more effectively with Google's own services.
Taken together with the AI Act's phased implementation, which becomes fully applicable from 2 August 2026 for most provisions, these developments demonstrate that European regulators are moving from legislation to active enforcement.
A Shift from Regulation to Market Design
Many organisations have viewed the AI Act primarily as a compliance exercise. That is understandable. The legislation introduces obligations around transparency, risk management, documentation, human oversight and governance for AI systems depending on their level of risk.
However, recent DMA enforcement shows that Brussels is pursuing a broader objective.
Rather than simply restricting AI, the EU is attempting to create greater interoperability between digital platforms; increased consumer choice; lower barriers for emerging AI providers; and more competitive digital ecosystems.
This represents an important evolution. AI regulation is no longer only about safety, it is becoming industrial policy.
Why Businesses Should Care
For legal teams and corporate decision-makers, this matters for three reasons.
1. AI Governance Cannot Sit in Isolation
Organisations increasingly need to consider the interaction between multiple EU regimes:
AI Act
Digital Markets Act
Digital Services Act
GDPR
Data Act
NIS2
Cyber Resilience Act
Compliance is becoming an ecosystem rather than a single regulatory project.
Legal, privacy, cybersecurity and technology teams must work together rather than operating in separate compliance silos.
2. Competition Law Is Becoming an AI Issue
Historically, competition law and AI governance were treated as distinct disciplines.
That distinction is fading. Questions around interoperability, access to data, model deployment and platform neutrality increasingly sit at the intersection of competition law and AI regulation.
Businesses developing AI-enabled products should expect regulators to examine not only whether AI is safe, but also whether markets remain open and contestable.
3. Compliance Can Become a Competitive Advantage
Many organisations still regard AI governance as a regulatory burden. Forward-looking businesses are beginning to view it differently. Robust governance frameworks can:
Improve procurement opportunities;
Strengthen customer trust;
Simplify cross-border deployment;
Reduce litigation risk; and
Demonstrate responsible innovation to regulators and investors.
As enforcement increases, organisations that invested early in governance are likely to find themselves better positioned than those waiting for investigations to drive change.
Looking Ahead
Europe's digital regulatory framework is entering a new phase. The conversation is no longer simply about whether organisations understand the AI Act. Instead, the question is whether businesses are prepared for an environment where AI regulation, competition policy and digital governance increasingly operate as a single framework. For organisations operating across Europe, success will depend not only on complying with new rules but on embedding governance into business strategy from the outset.
The THEMIS Perspective
At THEMIS, we believe effective AI governance should not be viewed as a box-ticking exercise. It is a strategic capability that enables innovation while managing legal, ethical and operational risk. As EU regulators move from drafting legislation to active enforcement (Europe's AI Rulebook), organisations should ensure their governance frameworks are capable of adapting, not just to today's requirements, but to tomorrow's regulatory landscape.
The businesses that succeed in Europe's AI economy are unlikely to be those asking, "What is the minimum we need to do?" They will be those asking, "How can governance become a competitive advantage?"




Comments