Welcome back to the Centre for Democracy & Technology Europe’s Tech Policy Brief! This edition covers the most pressing technology and internet policy issues under debate in Europe and gives CDT’s perspective on the impact to digital rights. To sign up for CDT Europe’s AI newsletter, please visit our website. Do not hesitate to contact our team in Brussels.
👁️ Security and Surveillance
Sandbox Event with the Civil Society Digital Security Network
Our Security and Surveillance Programme Director Rand Hammoud participated in the 2nd edition of Sandbox organized by the Civil Society Digital Security Network. The conference brought together individuals and organisations who have experienced digital attacks or are at heightened risk due to the nature of their work, alongside experts who provide support in areas such as digital security, legal protection, and psychological support. By fostering dialogue and knowledge-sharing, the Sandbox Conference aims to strengthen cyber resilience, raise awareness of emerging risks, and explore effective responses to digital repression.
Discussions on CSAM Regulation continue
As the CSAM trilogues progress, with the first meeting held on 11 May and the second, supposedly conclusive, session scheduled for 29 June, the European Parliament and the Cypriot Presidency moved closer together on detection scope, blocking injunctions, and removal deadlines. That said, the most contested elements remain to be resolved: the Cypriot Presidency has yet to table a text on the content detection model, and age verification remains an open question, with reports suggesting it may ultimately be excluded from the CSAR and addressed later under separate legislative frameworks. This is unfolding alongside a broader political push on children’s online protection. On 12 May, Commission President Ursula von der Leyen signalled for the first time a clear intention to legislate on a European digital age of majority, with a proposal potentially coming before the end of the summer. The Commission is also advancing its online age-verification application, an approach reinforced by a recommendation issued on 29 April. CDT Europe has serious concerns about this trajectory: the EU Age Verification Solution is being fast-tracked as the primary compliance pathway without sufficient independent privacy, security, or human rights assessment, risking the anchoring of a Union-wide framework on a solution that is not yet fit for purpose, with lasting consequences for the rights of every European internet users. We will closely follow these developments and continue our engagement with the co-legislators as the negotiations enter their final stretch.
Recommended read: Access Now, Access Now urges the Ninth Circuit to protect encryption from NSO’s spyware
💬 Online Expression & Civic Space
The DSA as a Tool for Tackling Tech-Facilitated Gender-Based Violence
As part of the DSA Observatory learning call series, which brings together researchers and practitioners to discuss current developments and emerging questions related to the Digital Services Act, CDT Europe’s Secretary General Asha Allen took part in an expert exchange on how to use the DSA to combat gender-based violence. Alongside Dr Carlotta Rigotti, Assistant Professor at eLaw at the Center for Law and Digital Technologies at Leiden University, participants exchanged on how the lack of tech-facilitated gender-based violence (TFGBV) related enforcement decisions thus far, yet assessed that with the upcoming transposition of the EU Directive on Violence against Women in 2027, experts expect this to change. Participants also assessed the impact of recent cases of deepfake non-consensual intimate imagery (NCII) and how the adoption of specific bans in the latest AI Omnibus will work in practice. Mindful that the EU, at present, has the most comprehensive regulatory framework to address TFGBV, participants concluded that a nuanced approach will be necessary to ensure that enforcement of these rules works effectively to provide victims with concrete redress whilst pushing online platforms to implement clear safety by design measures to preventatively mitigate harm.
“Platforms’ Accountability to Strengthen the Digital Public Sphere” at EuroDIG 2026
On 27 May, CDT Europe’s Secretary General Asha Allen spoke on a panel dedicated to exploring platform accountability to strengthen the digital public sphere at this year’s European Dialogue on Internet Governance (EuroDIG). She suggested a reframing of current conversations by reminding the audience of the positive effect that civic discourse online could have for societal progress, allowing for movements such as #MeToo and #BlackLivesMatter to flourish. She questioned the false dichotomy between innovation and fundamental rights, reminding the audience of the business case for user protection and trust. She highlighted the importance for European sovereignty to ensure that the fast roll-out of new technologies, including AI, does not come at the expense of fundamental rights. She further focused on the co-regulatory framework at the heart of the DSA and on the crucial role of civil society embedded within the text, allowing it to hold both platforms and regulators to account.

Recommended read: Interface, Social Media Age Gating in the EU: Perspectives on Member States laws restricting minors’ access to social media platforms
⚖️ Equity and Data
Civil society roundtable on AI governance with US Senator Peters
CDT Europe organised an AI governance roundtable bringing together representatives of civil society organisations with US Senator Gary Peters. The exchange focused on lessons learned from the EU’s effort to regulate AI, remaining challenges to be addressed, and areas of transatlantic opportunity. In particular, the roundtable discussed safeguards for public sector AI use in Europe, the misuse of AI for surveillance and censorship, and combatting AI-facilitated disinformation and foreign interference campaigns.
Discussions on the AI Omnibus
In May, Programme Director Laura Lazaro Cabrera spoke at various events addressing the potential harms of the AI Omnibus. The day before the final trilogue on the AI Omnibus, Laura spoke at BEUC’s conference on “Upholding Consumers’ Digital Rights in the Omnibus Era” event, underscoring the negative implications of excluding AI systems regulated under product safety legislation from the scope of the AI Act. The week of CPDP, Laura participated in a closed roundtable discussion organised by the office of the UN High Commissioner for Human Rights addressing the international implications of the AI Omnibus proposal, the motivations underlying the proposed changes, and the ways in which the AI Act has had a trickle-down effect in other jurisdictions.

Recommended read: Abeba Birhane et al., Big AI’s regulatory capture: mapping industry interference and government complicity
🖥️ Computers, Privacy and Data Protection Conference (CPDP 2026)
Last week, CDT Europe’s team attended the 2026 edition of the Computers, Privacy and Data Protection Conference (CPDP), convening in Brussels a global community across research, policy, practice, civil society, and technology to engage with cutting-edge developments in privacy and data protection. This year marks the tenth anniversary of the GDPR, so the intent of the conference was to take stock of its achievements and limitations, amid growing calls for “simplification” and deregulation in the name of innovation and competitiveness. At the same time, it invited conversations on several other pressing concerns connected to tech and policy development, bringing together different perspectives and creating a space of constructive exchange. Our team was busy with panels, workshops and radio interviews, where they discussed issues ranging from fairness and non-discrimination in AI, age-gating and online protection of minors, to image-generated abuse and CSAM. We also had the pleasure to host two colleagues from CDT US, Aliya Bathia and Miranda Bogen, who joined our events with their invaluable contributions. A big thank you goes to all the speakers, participants and the CPDP organisers, already looking forward to next year’s conference!

🚀 The Comms Commune Launch Event
On 26 May, our Advocacy & Communications team, Aimee Duprat-Macabies and Giulia Papapietro, together with other 3 civil society organisations – EAPN, ERGO and Eurodiaconia -, launched The Comms Commune, a community of communicators working in the civil society space in Brussels. The event was the first step in creating a space grounded in shared values, where to exchange ideas and learn from each other. It was an evening full of inspiring chats, light-hearted memes, and a lot of comms-fails judging. If you would like to know more about it, and are interested in joining the Commune, you can reach out at thecommscommune@gmail.com.

⏫ Upcoming Events
“Article 21 of the DSA in Practice” Webinar: On 3 June, our Online Expression & Civic Space Programme Director Christian Cirhigiri is speaking in a webinar organised by User Rights on their first Transparency Report, which provides detail insight into their operations, cooperation with platforms, and the effectiveness of out-of-court dispute settlement (ODS) under Article 21 of the DSA. The discussion will cover what is working, what isn’t, why, and what needs to happen to ensure that Article 21 of the DSA is implemented effectively. You can register to attend the webinar here.
“Fight for Us, not for Them” Summit: On 23 June, CDT Europe is co-organising the summit “Fight for Us, not for Them: A public interest vision for EU tech policy”, taking place in Brussels and online. Together with other 11 civil society organisations, we will jointly convene European lawmakers, regulators, journalists, and key civil society voices to lay out our bold alternative vision for tech laws, policies and practices that truly center the public interest, in an era of simplification and deregulation. The summit will explore the Digital Omnibus, the Digital Fitness Check, the future of EU digital regulation, and practical alternatives to deregulation that support innovation without weakening rights.
Confirmed speakers include Anita Gurumurthy, Executive Director of IT for Change, Brando Benifei, Member of the European Parliament who co-led negotiations on the AI Act, and Diana Vlad-Calcic, Team Leader for Regulatory Simplification at the European Commission (DG CONNECT). The event will be moderated by author and journalist Dave Keating, and will conclude with a speech and interactive Q&A from Professor Shoshana Zuboff, thought leader and author of ‘The Age of Surveillance Capitalism’. Find out more about the event and register now to join us online here.
🗞️📻 In the Press & Media