Tech Sovereignty, Spyware Enforcement & SME Compliance

This content was generated with AI

Overview

This report covers Parliamentary Questions (PQs) and Commission replies published from 09.08.2026 till 16.08.2026. The principal policy areas addressed include cybersecurity resilience, 5G infrastructure de-risking, the regulation of frontier AI, and the emerging compliance burdens associated with the digital product passport and the European AI Office. The institutional tone of the Commission remains firm and legally cautious; it aggressively asserts its mandate to secure critical European infrastructure and promote tech sovereignty, while strictly deferring to Member States on matters of national security and law enforcement. These developments matter for digital-policy professionals because they highlight the growing tension between the EU’s ambitious technological sovereignty agenda and the practical, jurisdictional limits of enforcement and SME compliance.

🌐

Cybersecurity, Tech Sovereignty & Infrastructure

❗ Commission Defends De-Risking and Mandatory Exclusion of High-Risk 5G Suppliers

In Parliamentary Question E-002140/2026, the Commission was asked to address the awarding of transport and telecommunication contracts to Huawei in Spain. In a response on 10 August 2026, Executive Vice-President Henna Virkkunen confirmed that the Commission does not comment on national procurement decisions but reiterated that Huawei and ZTE present materially higher risks than other suppliers. The reply positions the proposed revised Cybersecurity Act as a mechanism for mandatory de-risking in European networks, framing this as essential to protecting critical infrastructure from untrusted entities.

❗ Commission Outlines AI and Cybersecurity Action Plan to Address Frontier Risks

In Parliamentary Question E-001844/2026, MEPs inquired about measures to secure European infrastructure against emerging artificial intelligence threats. In a response on 12 August 2026, Executive Vice-President Henna Virkkunen detailed the newly adopted Action Plan on Cybersecurity and AI, which tasks ENISA with piloting a Critical Open Source Resilience Campaign. The Commission indicates a strong focus on tech sovereignty, citing plans to boost equity investments in advanced technologies and the launch of an EU Grand Challenge on AI-assisted vulnerability handling.

⚖️

Fundamental Rights & Law Enforcement

❗ Commission Defers Spyware Enforcement to National Authorities

In Parliamentary Question P-002126/2026, the Commission was pressed on its handling of the alleged illegal use of spyware following the PEGA committee’s recommendations. In a response on 12 August 2026, Commissioner Michael McGrath stated that while the Commission condemns unlawful interception of communications, investigation and prosecution remain the responsibility of competent national authorities. The reply notes that the Commission continues to monitor these developments through the 2025 Rule of Law Report, maintaining a strict adherence to jurisdictional boundaries under EU law.

💼

Core Legislative Frameworks & SME Compliance

❓ MEPs Question the Expansion of the European AI Office and SME Burden

In Parliamentary Question E-003134/2026, Mathilde Androuët (PfE) asked the Commission to clarify the legal and democratic basis for extending the powers of the European AI Office amidst growing regulatory entanglement involving the GDPR, Data Act, and AI Act. The inquiry raises concerns regarding technocratic centralisation, Member State sovereignty, and the disproportionate compliance costs placed on European SMEs, asking if a simplification audit will be conducted. A response from the Commission is pending.

❓ Commission Pressed on Digital Product Passport Exemptions for Micro-Enterprises

In Parliamentary Question E-003207/2026, Christine Singer (Renew) asked the Commission how it intends to ensure proportionality in the upcoming delegated act for the digital product passport (DPP) regarding handcrafted textiles. The question highlights the lack of digital infrastructure among micro-enterprises and asks what exemptions or simplified requirements the Commission is considering to prevent disproportionate administrative burdens for bespoke and small-batch production. A response from the Commission is pending.

📈

Convergence & Analysis

The Commission’s recent replies suggest a highly structured approach to digital sovereignty, carefully balancing aggressive EU-level mandates with strict adherence to national competences. In areas of critical infrastructure and telecommunications, the Commission positions itself as a driver of mandatory de-risking, utilizing legislative tools like the proposed revised Cybersecurity Act to limit dependencies on high-risk suppliers. Conversely, regarding the surveillance of citizens and the use of spyware, the institution firmly frames enforcement and investigation as the exclusive purview of Member States, indicating a reluctance to overstep jurisdictional boundaries.

Furthermore, the Commission’s rhetoric indicates a strategic pivot toward integrating artificial intelligence into systemic cybersecurity resilience. By tasking ENISA with campaigns targeting open-source software and launching initiatives like the EU Grand Challenge on AI-assisted vulnerability, the Commission frames AI as both a primary threat vector and a necessary defensive capability. This approach suggests that future funding and policy initiatives will increasingly blend AI development with cybersecurity mandates.

Overall, this material reveals a digital policy environment where the implementation of sweeping frameworks is increasingly characterized by a push for technological self-reliance. For public affairs professionals, this indicates that the Commission is prioritizing structural resilience and targeted investments in critical sectors, even as it faces mounting parliamentary scrutiny over the cumulative compliance burdens these frameworks place on European small and medium-sized enterprises.

All Parliamentary Questions and Commission Answers are accessible via Policy-Insider.AI.

Your subscription could not be saved. Please try again.
Your subscription has been successful.

PQ Insights 

EU Health

Stay Ahead in EU Health Policy

Get a weekly analysis of key European Parliamentary questions on health, delivered straight to your inbox.

This will close in 0 seconds

This will close in 0 seconds

Your subscription could not be saved. Please try again.
Your subscription has been successful.

PQ Insights 

EU Energy

Stay Ahead in EU Energy Policy

Get a weekly analysis of key European Parliamentary questions on energy, delivered straight to your inbox.

This will close in 0 seconds

Your subscription could not be saved. Please try again.
Your subscription has been successful.

PQ Insights 

EU AI & Tech

Stay Ahead in EU AI & Tech Policy

Get a weekly analysis of key European Parliamentary questions on AI and Tech, delivered straight to your inbox.

This will close in 0 seconds

Tell us what you need to monitor

No spam. No automatic sign-up. We will contact you directly to discuss your setup.