Updated July 2026 to reflect new deadlines for the EU AI Act.
In 2026, procurement and supply chain leaders face five major regulatory shifts: the EU AI Act, VAT in the Digital Age (ViDA), the EU Data Act, Corporate Sustainability Due Diligence (CSDDD), and new UK and financial-services-specific regimes. These regulations fundamentally change supplier contracting, AI governance, invoicing, data access, and third-party risk management.
These changes primarily affect large EU and UK-based organisations, regulated financial services firms, and any supplier providing AI-enabled, digital, data-driven, or operationally critical services. SMEs may be indirectly affected through contractual flow-down requirements.
| Regulation | Date | What happens | Why it matters |
| EU AI Act | 2 Aug 2026 | Most remaining AI Act provisions start to apply, but high-risk AI obligations have been delayed | AI suppliers must be compliant; fines and audits apply |
| 2 Dec 2026 | Deadline for certain AI-generated content transparency/watermarking obligations, and new bans on specified harmful AI-generated sexual/CSAM content | ||
| 2 Dec 2027 | High-risk obligations apply for stand-alone high-risk AI systems | ||
| 2 Aug 2028 | High-risk obligations apply for AI systems embedded in safety components/products covered by EU sectoral legislation | ||
| VAT in the Digital Age (ViDA) | 1 Jul 2030 | Mandatory EU e-invoicing & digital reporting | Procure-to-Pay systems must process EN 16931 invoices |
| EU Data Act | 12 Sep 2025 | Core obligations apply | Suppliers must provide data access and portability |
| EU Data Act | Jan 2027 | Cloud switching fees removed | Reduces vendor lock-in; strengthens buyer leverage |
| CSDDD (as amended) | Jul 2029 | Compliance required | Full supply-chain due diligence becomes mandatory |
| UK Procurement Act 2023 | 24 Feb 2025 | Act goes live | New public procurement rules and transparency |
| UK CTP Regime / EU DORA | 2025“2026 | Operational resilience oversight intensifies | Critical suppliers treated as regulated extensions |
Overview: The EU AI Act requires procurement teams to identify and classify AI used by suppliers, ensure high-risk systems meet strict compliance standards, and embed transparency, audit, and traceability obligations into supplier contracts.
The EU AI Act continues to phase in during 2026, but the strictest high-risk AI obligations have now been pushed back. Most remaining provisions still start to apply from 2 August 2026, while high-risk obligations now apply from 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for AI systems embedded in regulated products. Learn more how this affects procurement.
Key impact:
AI systems controlling automated warehouses and managing logistics will likely fall under the high-risk category, especially if they are making decisions that directly impact worker safety or critical supply timelines. Procurement teams should include clauses that require suppliers to comply with the EU AI Act, provide documentation on model use, and disclose subcontractors.
Timeline:
The AI Act still matters in 2026, but 2 August 2026 is no longer the full high-risk compliance cliff edge. The strictest high-risk obligations now fall later, with key dates in December 2027 and August 2028. However, the delay should not be treated as a pause on preparation. As agentic AI moves into live workflows, procurement teams still need to understand what supplier AI systems can access, connect to and act on before the formal high-risk deadlines arrive.
Organisations must conduct full inventories of AI systems, classify them by risk level, and ensure vendors provide conformity assessments, technical documentation, and traceability throughout the AI lifecycle.
Overview: ViDA fundamentally changes procurement by mandating structured e-invoicing and near-real-time VAT reporting for cross-border transactions, forcing organisations to upgrade Procure-to-Pay systems and invoicing workflows.
The VAT in the Digital Age package was adopted on 11 March 2025, published in the Official Journal on 25 March 2025, and came into force on 14 April 2025. It will be rolled out progressively until January 2035. This fundamentally changes invoicing and procurement processes.
Key changes for procurement:
E-invoicing mandate: From 1 July 2030, electronic invoicing in accordance with the European e-invoicing standard (EN 16931) will be mandatory for intra-Community transactions.
No customer consent required: Once the directive comes into force, the sending of a cross-border invoice in electronic format will no longer be subject to the customer’s agreement. The customer will be obliged to accept it.
Digital reporting requirements: Digital reporting includes plans from July 2030 to introduce near-real-time digital reporting and e-invoicing for intra-Community supplies of goods and services.
Phased implementation:
Companies must prepare Procure-to-Pay (P2P) systems to receive and process structured e-invoices, implement new reporting workflows, and ensure compliance with near-real-time transaction reporting.
Overview: The EU Data Act obliges suppliers of connected products and digital services to provide customers with free, usable access to operational data, reducing vendor lock-in and changing how procurement negotiates data rights and contracts.
The Data Act is applicable from 12 September 2025, marking a major step forward in building a fair and innovative European data economy. This affects the procurement of connected products and industrial equipment.
Key provisions:
From 2026, new connected products and related services must be designed so that users can access their data easily and free of charge, with direct user access required where technically feasible. Access to data could enable machine learning technologies, such as artificial intelligence, to use this data to improve supply chain management or industrial and agricultural production processes.
The data-sharing obligation gives users the right to transfer their data, for example to share it with a repair provider other than the device manufacturer, which could create more competition in the after-sales market.
Timeline:
When procuring connected industrial equipment, IoT devices, or smart machinery, procurement teams must ensure suppliers comply with data access requirements and facilitate data portability, potentially disrupting vendor lock-in models.
Overview: CSDDD requires in-scope companies to identify, prevent, and address human rights and environmental risks across their supply chains, making supplier due diligence and contractual accountability a core procurement responsibility.
The CSDDD was significantly amended by Omnibus I in December 2025, substantially changing its scope and timeline. Member States must transpose the directive into national law by 26 July 2028, with compliance required by July 2029.
Scope: The directive applies to companies based on a phased approach. The changes introduced by Omnibus I in December 2025 raised the threshold to companies with 5,000+ employees and €1.5 billion+ in net annual turnover. The mandatory climate transition plan requirement was removed entirely from the directive.
Due diligence requirements:
In-scope companies must take various steps to manage actual and potential adverse impacts of their activities on human rights and environmental matters, arising from their own operations, the operations of their subsidiaries, and the operations of their business partners in the chain of activities. Companies must identify, prevent, mitigate, and remediate adverse human rights and environmental impacts throughout their value chains.
Timeline:
Supply chain professionals must implement comprehensive supplier due diligence programmes, conduct human rights and environmental risk assessments, and ensure contractual obligations cascade through the supply chain. The directive creates potential liability for supplier actions. However, the raised thresholds and delayed timeline provide more time for preparation.
UK Procurement Act 2023: The UK Procurement Act 2023 simplifies public procurement procedures while increasing transparency and SME participation, requiring procurement teams to adapt processes, documentation, and compliance controls.
The Procurement Act 2023 went live on 24 February 2025. It includes procedural simplifications aimed at increasing SME participation and introduces more flexible procedures, mandatory transparency rules, and streamlined compliance.
Alongside horizontal EU regulations, several sector‘specific regimes will shape procurement and supplier‘risk expectations in 2026, particularly for organisations operating in or supplying regulated financial services firms.
The UK’s new Critical Third Parties (CTPs) regime treats certain suppliers as systemically important, requiring regulated firms to apply enhanced due diligence, stronger contracts, and ongoing oversight of critical third-party providers. The UK CTPs regime takes effect from 1 January 2025, following the publication of final rules and supervisory statements by the Bank of England, PRA, and FCA on 12 November 2024.
The regime allows regulators to directly oversee designated CTPs that provide services whose disruption could threaten financial stability. HM Treasury will designate CTPs based on regulators’ recommendations.
While the rules apply from 2025, 2026 is expected to be the first full year of practical impact, as designations progress and CTPs begin operating under the new oversight framework. This will influence how regulated firms assess, contract with, and monitor critical suppliers.
Procurement implications for 2026:
In the EU, the Digital Operational Resilience Act (DORA) makes procurement central to operational resilience by requiring ICT and third-party contracts to support resilience testing, risk management, and regulatory oversight in financial services. DORA applies from 2025 but its practical impact is expected to increase in 2026, as firms embed the framework and supervisory expectations rise. Procurement functions will play a key role in ensuring ICT and third‘party arrangements support operational‘resilience requirements.
Strategic relevance for procurement:
Across both the UK CTP regime and EU DORA, a consistent regulatory direction is clear: third parties are increasingly treated as extensions of the regulated organisation.
As a result, procurement is becoming a core mechanism for managing operational and systemic risk, not just a commercial function. Even suppliers outside regulated sectors may face indirect pressure to meet these standards when serving financial services clients or acting as critical service providers.
These converging regulatory changes create several imperatives for procurement and supply chain leaders:
Technology investment: Organisations need significant investment in digital infrastructure for e-invoicing, AI compliance documentation, and data access systems.
Supplier management: Procurement must implement new vendor assessment frameworks covering AI compliance, data-sharing capabilities, and ESG due diligence.
Cross-functional collaboration: Legal, IT, sustainability, and procurement teams must work together to ensure coordinated compliance.
Contract terms: Standard procurement contracts need substantial updates to address AI Act requirements, data portability rights, e-invoicing obligations, and CSDDD due diligence.
Supply chain visibility: The CSDDD in particular demands unprecedented visibility into multi-tier supply chains, requiring new mapping and monitoring capabilities.
SME considerations: While some regulations exempt smaller businesses, SMEs in supply chains will face indirect pressure from larger customers to meet these standards.
Extended timelines for CSDDD: The December 2025 Omnibus I amendments provide organisations with additional time to prepare for CSDDD compliance, with the transposition deadline pushed to July 2028 and compliance required by July 2029 rather than the originally planned earlier dates.
Inventory all AI systems used by suppliers and classify risk levels
Update standard contracts to include AI Act, Data Act, and DORA clauses
Prepare P2P systems for EN 16931 structured e-invoicing
Implement supplier data-access and portability requirements
Expand supplier due diligence for human rights and environmental risk
Strengthen third-party resilience and exit planning for critical suppliers
Together, these regulations signal a shift in which procurement is no longer a transactional function but a core governance mechanism for AI risk, operational resilience, tax compliance, and sustainability. Organisations that adapt procurement frameworks early will reduce regulatory exposure while strengthening supplier accountability and resilience.
See how procurement leaders turn compliance into capability with Market Dojo.
Note: All URLs were verified as of January 2026. For the most current information, please consult official government and EU institutional sources directly.
January 8, 2026