The date is set: 12 January 2027, Brussels
On 12 January 2027 the European Commission convenes the Data Union Conference at the Charlemagne building in Brussels.
The announcement is dated 18 September 2026 and comes from the Commission's official portal[1], which opens the expression of interest and confirms live streaming. Admission remains subject to approval.
The verifiable fact here is a political calendar, rather than a new rule. The meeting brings together public decision-makers, businesses, experts and researchers around a single question: how to turn European data policy into more data for AI, into growth and into competitiveness. The Commission presents it as a contribution to a wider debate on the future of European data policy.
For compliance functions that date carries the weight of a deadline. The framework against which they are calibrating access to data for industrial AI today goes into public discussion right there, in front of the people who write the EU rules on data and AI.
The rulebook companies are working with now
The Data Act, Regulation (EU) 2023/2854, has applied across the Union since 12 September 2025. It governs access to data generated by connected products and related services, with sharing duties towards the user and towards the third parties the user designates.
Alongside it sits Regulation (EU) 2024/1689, the AI Act, in force since 1 August 2024 and applicable in phases. The transparency obligations of Article 50 and the rules for high-risk systems under Annex III each follow their own timetable.
Layered on top of these two texts are the GDPR, the Data Governance Act and the open data directive.
The result is a structure built in successive strata. Each stratum brings its own regulator, its own legal basis, its own date of application. A European company crosses every stratum the moment it trains a model on industrial data collected from machines, vehicles or plants.
The Digital Omnibus opens the agenda
The Commission places simplification first among the three themes on the programme.
The Digital Omnibus aims to streamline Europe's data rulebook, reduce administrative burden and support innovation, building on the Data Act and on legislation already in force. The order of the agenda items communicates a political priority, before it communicates any technical content.
This desk's reading stays blunt: those who sign public contracts weigh on the enforcement calendar more than they admit. The slippage of high-risk obligations towards December 2027 belongs to politics before it belongs to engineering. A vendor that slows a deadline buys time for the entire supply chain that depends on it.
The word simplification carries a precise operational consequence. A compliance set-up calibrated on an obligation that changes shape becomes oversized on one front and exposed on another. The audit is still required; what changes is the audit's perimeter.
Data for industrial AI: the Data Act put to the test
The second item on the agenda concerns access to high-quality data through the Data Act. The Data Union Strategy sets out practical measures to increase data availability and strengthen European infrastructure.
The question for the General Counsel here is concrete: on what legal basis does the company use the industrial data that feeds its models.
The Data Act grants access rights to the user of the connected product and duties to the data holder. A model trained on those flows inherits those rights along the whole chain. A supply contract signed in 2023 often ignores the subject entirely.
Companies that re-read their data sharing clauses now arrive in 2027 with a ready inventory and a map of consents. The others arrive with a discovery exercise to open under pressure, while the regulator asks for documents. The cost of the same activity differs sharply between the two scenarios.
International flows: the third item
The third theme concerns open and trusted data flows and fair treatment for European companies in foreign markets.
The Commission states that it is working to facilitate cross-border transfers and to address the unfair restrictions that Union companies encounter elsewhere. What we have here is a negotiating position, before it is a binding text.
For the Chief Risk Officer the point touches the supplier map. A model hosted outside the Union, trained on European customer data, depends on a transfer tool that is valid under Chapter V of the GDPR. That tool lives on political decisions that mature in venues like this one.
The governance signal
The governance signal: the Commission opens its own data rulebook before the heaviest phase of the AI Act comes fully into effect.
Anyone designing a compliance programme today is therefore working on a moving text. That changes how internal procedures should be written: better a versioned cross-reference to the obligation than a frozen copy of the article inside a manual.
One clarification is due. The 12 January 2027 appointment is a conference, so it produces political direction and negotiating signals. Regulatory changes then go through the ordinary procedure, with Parliament and Council, on their own timelines. Treating an agenda as law in force is a category error, with consequences for the compliance budget.
Three decisions for the board
First decision: which role, named and in writing, answers for access to the data used to train the company's models. A framework without a name produces documentation, rather than governance.
Second decision: what disclosure the Audit and Risk Committee takes to shareholders while the obligations calendar remains under review. A regulatory risk described as stable, during a phase in which the texts are being reopened, exposes directors on transparency grounds.
Third decision: what compliance spend the CEO authorises now, in the wake of the conference. Organisations that build named accountability, audit trails and risk classification today gain an 18-24 month advantage the moment enforcement enters its full phase. AI compliance works as a competitive lever, rather than a cost line.
Regulatory horizon
Current status: the Data Act has applied since 12 September 2025; the AI Act has been in force since 1 August 2024, with staggered application by system category. Jurisdiction: European Union, 27 Member States.
Next public milestone: 12 January 2027, Charlemagne building, Brussels, with the agenda to be published on the Commission's Digital Strategy portal[1] and live streaming announced.
The question of what Europe asks of companies on data was answered in the texts of 2023 and 2024. A second question has now opened: how long that answer will last.
This article was written by an AI editorial author under human supervision, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- Commission's official portal 18 Sep 2026 (digital-strategy.ec.europa.eu)