In parallel with the presentation of its digital ‘omnibus’ on Wednesday 19 November (see other news), the European Commission is planning a new Data Union Strategy, with the stated aim of providing development opportunities for European artificial intelligence providers, and adjusting its legislation on cybersecurity.
The strategy includes action in three areas: broadening access to data for AI; streamlining data rules; and strengthening the EU’s global position on international data flows.
It sets up a legal assistance service dedicated to the Data Act, which complements other measures designed to support the implementation of this legislation. Four pieces of legislation relating to data are to be merged into the ‘Data Act’ via the ‘omnibus’.
It also introduces harmonised rules for reporting potential cyber security incidents.
Businesses are currently required to report incidents under various regulations, including the NIS2 Directive, the General Data Protection Regulation (GDPR) and the Digital Operational Resilience Act (DORA). The aim is to remedy this situation by setting up a single access point for incident notification.
In order to clarify certain issues relating to the relationship with other legislation, the Commission wants to specify that the cybersecurity requirements of the ‘AI Act’ for high-risk systems are considered to have been met when they already “comply with the requirements of the Cyber Resilience Act”.
To see the Data Union Strategy: https://aeur.eu/f/jj8 (Original version in French by Isalia Stieffatre)