Hi all,
Honestly, on age verification, it feels like everybody and their aunt have
published a position or a proposal. The debate is now a cacophony.
Meanwhile the parliament is trying to fix open government data in the
Digital Omnibus. Also, the Commission has presented its Tech Sovereignty
package, which includes an “open source first” principle for public sector
software built with public funding.
Dimi
=== Digital Omnibus & Open Data ===
Reminder: the digital omnibus wants to simplify personal data provisions
and open government data laws. The Legal Affairs (JURI) committee has
published its draft report
<https://communia-association.org/wp-content/uploads/2026/06/JURI-PA-789142_…>
on the Digital Omnibus. The section most relevant to us concerns open
government data. JURI's amendments 57–60 seek several things, including to
protect non-discriminatory re-use, interoperability and the use of standard
and open licences. The issue with the Commission proposal is that it
suggests public sector bodies use non-standard licenses for very large
enterprises, which would be incompatible with the open licences we use.
Wikimedia Europe, Creative Commons and Communia have a position on this
<https://communia-association.org/wp-content/uploads/2026/02/One-pager-Digit…>
.
—
Communia’s assessment
<https://communia-association.org/2026/06/22/juri-tries-to-save-open-governm…>
of JURI's approach is that it identifies the right problem but gets the
solution wrong. The concern is that the amendments, while well-intentioned,
could inadvertently restrict the ability to combine and re-use public
sector information across borders and sectors — particularly if they are
read as permitting fragmented licensing practices in the name of addressing
imbalances linked to the economic power of very large market actors.
—
On the Council side, national ambassadors tried to hammer out a final
negotiating position on 26 June, but a block of them, led by Germany, is of
the opinion that the simplification efforts don’t go far enough, so the
Irish Council Presidency will have to take over from Cyprus and try to find
a way forward.
=== CSAM Directive & Regulation ===
Two separate but easily confused files have reached important milestones
this month, so it is worth reminding ourselves which is which.
—
The Directive on combating the sexual abuse and sexual exploitation of
children and child sexual abuse material <https://law-tracker.europa.eu/#>
(a.k.a. CSAM Directive) is a criminal law instrument setting minimum
standards for offences and penalties related to child sexual abuse for EU
countries. There will be increased minimum penalties and the period during
which offences can be prosecuted will be longer, according to the agreement
reached between the Council
<https://www.consilium.europa.eu/en/press/press-releases/2026/06/22/combatti…>
and the Parliament
<https://www.europarl.europa.eu/news/en/press-room/20260622IPR45906/combatin…>.
We passively followed this legislative procedure, as it is not addressed at
platforms, but some of the language may have been relevant for our
projects. Both institutions technical teams will now finalise the legal
text, then they need to vote on it formally and it will proceed to be
published in the Official Journal. Member states will then have three years
to transpose the directive into national law.
—
The CSAM Regulation is the far more contested proposal dealing with
platform obligations to detect, report and remove CSAM, including the
question whether chat messages should also be scanned. The final political
trilogue was scheduled yesterday. As a reminder, here’s Wikimedia’s initial
position
<https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/1…>
on this.
—
Last night, alongside watching football I presume, Parliament and Council
spent six hours trying to hash out their differences, but a deal was not
reached. Both houses now have the protection of end-to-end encryption in
their positions, which is a positive change as compared to the initial
proposal and interim versions. From what we hear, negotiators are still
trying to distinguish between public and non-public content and hence draw
the line on what must be scanned and how. We also expect that
age-verification will be part of the final text, but as a voluntary and
optional measure.
NB: What a segue to the next section!
=== Age Verification ===
The cacophony mentioned in the introduction is real. Here is an attempt to
impose some order on it.
—
The Commission's expert panel on child safety
<https://commission.europa.eu/topics/digital-economy-and-society/protecting-…>
online held its final meeting on 16 June, examining three surveys. The
panel's chairs, Maria Melchior and Jörg Fegert, will now produce a
recommendation due on 13 July. The direction, according to people involved,
is not a simple recommendation for age restrictions but something more
holistic. The emphasis from industry, civil society and EU capitals alike
has been on the need for EU-wide measures to avoid fragmentation.
—
Germany's independent expert commission presented its recommendations
<https://www.bmbfsfj.bund.de/bmbfsfj/expertenkommission-veroeffentlicht-hand…>
on 30 June, and avoided making a clear recommendation on a minimum age.
Instead it set out two options: introduce a minimum age of 13 with
graduated protection standards up to 18; or no minimum age but targeted
restrictions on specific functions and services depending on their risk
level. Crucially, the German experts explicitly said that "national
go-it-alone solutions should be avoided."
—
At the international level, the G7 published common principles for
protecting minors online emphasising that data protection principles —
including proportionality, data minimisation and purpose limitation — must
be observed in any age verification mechanism. The European Commission went
out and publicly welcomed
<https://digital-strategy.ec.europa.eu/en/news/commission-welcomes-g7-agreem…>
this. Interestingly, the data protection authorities of the G7 countries also
met
<https://www.cnil.fr/en/emerging-technologies-and-protection-children-g7-dat…>
during the summit.
—
Back in Europe, Estonia's Digital Minister Liisa-Ly Pakosta broke with the
D9+ coalition's joint call for EU-wide age verification
<https://gouvernement.lu/dam-assets/images-documents/actualites/2026/06-juin…>,
calling the "just ban" approach "a little bit populist" and arguing for
education alongside proper DSA enforcement. Czechia continues to oppose
strict bans, despite signing the above declaration. Also noteworthy: Italy's
Prime Minister Meloni said that a ban risks "partially transferring the
problem onto families" and that governments should instead put more
pressure on platforms to take their responsibilities seriously.
—
On the national legislative front, the picture is fragmenting rapidly —
which is precisely what the expert panel and industry are warning against.
Sweden published its government report proposing a ban on under-15s
accessing platforms that allow users to discover, connect and communicate
with the general public. Crucial for us is that Wikipedia is explicitly
excluded
<https://www.regeringen.se/contentassets/d1b21d5210774bfba9797e08883c9633/so…>
(p. 200): "digital encyclopedias, such as Wikipedia, which are based on
content shared by end users... fall outside the law's scope of
application." The reasoning is that this "corresponds to the interest of
not restricting freedom of expression and information more than necessary".
This is an argument worth citing elsewhere. Also a shoutout to Wikimedia
Sverige and Eric Luth, who never got tired to explain Wikipedia and its
sister projects to policymakers.
—
Austria is also set to publish a new age verification law. It is expected
to take a different approach, based on audio-visual and media regulation.
It will focus on platforms with specific functionalities such as autoplay
and streaks rather than a blanket ban, and with privacy-preserving
requirements for the verification mechanism itself. We are waiting for the
actual legal proposal. Stay tuned.
—
The UK is preparing to announce a ban
<https://www.gov.uk/government/news/social-media-to-be-banned-for-under-16s-…>
on under-16s accessing certain social media, alongside restrictions on
livestreaming, disappearing messages and functions enabling communication
with adult strangers.
—
Two significant judicial developments this month will shape how national
age verification laws can be applied across borders. The CJEU's Grand
Chamber ruled
<https://curia.europa.eu/site/upload/docs/application/pdf/2026-06/cp260087en…>
on 16 June in joined cases WebGroup Czech Republic and NKL Associates
and Coyote
System that member states may impose age verification obligations on
platforms established in other member states — but only if they first
request that the member state of establishment takes action, and also
notify the Commission and that member state in advance, except in cases of
urgency. This narrows but does not eliminate the country-of-origin
principle.
—
The second part of the ruling is potentially more far-reaching: the Court
held that a platform which uses an algorithm to determine under what
conditions and in what order content is shown exercises control over that
content and therefore cannot claim the hosting liability exemption. Legal
scholars are divided on how broadly to read this — LSE's Martin Husovec
called it an "overruling of a decade of settled case law”. Others caution
against over-interpretation. Either way, this judgment will certainly
generate further litigation.
=== Copyright Consultation ===
Wikimedia Europe submitted its contribution
<https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/1…>
to the Commission's targeted consultation on the Copyright in the Digital
Single Market (CDSM) Directive review ahead of the 25 June deadline. The
consultation covers four issues: challenges for creators linked to AI;
online piracy of live events; sound recordings of third-country nationals;
and the scope of the scientific research exception.
—
We focused on questions one and four, skipping the middle two. AI and
copyright we shared that the current framing of the issue sees the
challenge primarily in terms of rightholders' difficulty in controlling and
licensing as well as in securing remuneration for their works and that this
does not capture the situation of the open, non-profit projects and
infrastructure curated by human volunteer contributors. We suggested that
share-alike principles and public domain safeguards could be ways to avoid
commercial lock-in of the commons.
—
As WMEU is a member of COMMUNIA, I want to also share their contribution
<https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/1…>.
Our responses regarding the scientific research exception are largely based
on their work. Among others, we suggest improving cross-border access to
scientific research and to introduce a EU-level secondary publishing right
for publicly funded research.
=== Communication on European Tech Sovereignty ===
As opposed to some fears, the European Commission has published its
Communication
on European Tech Sovereigntly
<https://digital-strategy.ec.europa.eu/en/policies/eu-tech-sovereignty> and
a EU Open Source Strategy
<https://digital-strategy.ec.europa.eu/en/policies/open-source-strategy> is
indeed part of the package. Now, I have seen my share of communications and
strategies in Brussels, and many just get forgotten after a bit, so I am
not exactly holding my breath.
—
More concretely, the package comes with two legislative proposals, Chips
Act 2.0 and a Cloud and AI Development Act (CADA). If adopted the new rules
would give governments across the EU much more leeway in preferring local
companies in public tenders. This would be achieved by introducing four
levels of sovereignty. The lowest level demands that “data must be stored
physically in the EU” (level 1), the scale then goes up to “provider must
be owned and controlled within the EU” (level 3) and “complete control over
the entire software supply chain” (level 4). I expect a lot of
back-and-forth about which level applies to which public sector activity,
e.g. law enforcement, military, public health, education.
—
Relevant for us is that CADA introduces an "open source first" mandate. Any
software built with public funding must be openly available for reuse. This
is something that some countries already have and the results are OK but
not overwhelming. Perhaps scaling it to the EU level will help. The act
would further allocate over €2 billion toward maintaining shared,
open-source critical digital infrastructures. According to the proposal
this funding will be targeted at "frontier” AI, industrial AI, and
specialised AI models tailored specifically for European public service and
industrial needs.
===END===
--
Wikimedia Europe ivzw
Hi all,
The Brussels meeting for Wikimedians interested in public policy and
advocacy will take place on 2 & 3 October (Friday & Saturday) this year.
The programme will still need to be confirmed, but it won't be
surprising that it will include the topics of AI and child protection.
Information about the venue and more is available on Meta-Wiki:
https://meta.wikimedia.org/wiki/Wikimedia_Europe/Advocacy/Big_Fat_Brussels_…
You may add your name if you intend to participate. Participation is open,
there is no other registration.
Cheers,
Dimi
--
Wikimedia Europe ivzw
Hi all,
On 13 May 2026 the European Commission published a *call for evidence*
<https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/1…>
expecting feedback related to the statutory review of the 2019 Copyright in
the Digital Single Market Directive.
Our engagement with the last EU copyright reform was to a large extent
driven community members. I know there are many, many experts among us. If
anyone would like to contribute to the current consultation, I have set up
a Meta-Wiki page for this:
https://meta.wikimedia.org/wiki/Wikimedia_europe/Advocacy/Consultations/Cal…
This is early stages and I personally don't expect a new copyright reform
to be kicked off soon. At this stage it is about raising issues and
directing attention.
Thanks,
Dimi
--
Wikimedia Europe ivzw
Hi all,
To all the veterans of the last EU copyright reform: It’s time to warm up
again, the Commission is starting a review of the 2019 copyright directive.
The Court of Justice has redefined the definition of systemic risk under
the DSA. And Czechia and Estonia have come out as skeptics of a social
media ban for children.
=== Copyright: CDSM Review ===
The review of the 2019 Copyright in the Digital Single Market Directive
(CDSM) is gathering pace. The statutory review trigger kicks in next month,
and the Commission has been moving on multiple fronts. Still, this is very
early stages and an actual legislative proposal is likely years away.
—
Five EU member states have written to Brussels
<https://drive.google.com/file/d/1UIYY9A5nyXu1ah0WQFJucO6bI77ZglC4/view?usp=…>
to push for a review of the bloc's copyright rules with regards to AI. This
is consistent with the direction signalled last month by Emmanuelle du
Chalard, head of copyright at the European Commission, at an event
<https://www.aepo-artis.org/aepo-artis-wraps-up-successful-conference-on-7-y…>
organised by AEPO-ARTIS. She confirmed that evidence is being gathered for
the CDSM review, that a study comparing impact across countries is underway.
—
Indeed, the Commission has now launched the targeted public consultation
<https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/1…>
on four specific issues: challenges resulting from AI and market
developments; online piracy of live events; sound recordings; and the scope
of the scientific research exception. The consultation closes 25 June 2026.
Wikimedia Europe will respond. In parallel there is a EU wide survey
<https://horizons.confirmit.eu/wix/p181452076573.aspx> underway to
contribute to the aforementioned study. We will also submit answers.
—
Of particular relevance to us is the scientific research exception
<https://wikimedia.brussels/why-wikimedia-supports-secondary-publication-rig…>,
which is directly linked to open access to knowledge. The questions about
AI training are also of interest to our work and projects. They connect to
the ongoing debate about text and data mining exceptions flagged in last
month's report on the Parliament's AI and copyright own-initiative report.
The consultation further allows other issues to be raised, so we might
namecheck a few exceptions and limitations :)
=== Open Source Strategy ===
The European Commission appears to have quietly dropped the open source
strategy from its upcoming tech sovereignty package
<https://digital-strategy.ec.europa.eu/en/policies/eu-tech-sovereignty>,
though it is unclear whether the strategy was scrapped altogether, delayed
or folded into another initiative. The Commission has not commented. Cloud
provider Nextcloud argued that only open source software "prevents
dependencies on individual providers and allows independent security
audits," and called for procurement reform as a minimum.
—
The package is expected to be presented on 2 June and many drafts are
circulating in Brussels. The overarching question for our movement is
whether the EU will structurally move to more open source software and
content and what kind of tech investments will be prioritised. Imagine the
package as a cluster of legislative proposals on procurement rules, cloud
and AI infrastructure as well as strategic documents.
=== Age Verification ===
The political temperature remains high, but some cracks in the consensus
are starting to show.
—
Greece notified the Commission
<https://technical-regulation-information-system.ec.europa.eu/en/notificatio…>
of its draft law introducing a social media ban for minors. This follows
the anonymity ban proposal reported last month. Portugal has a bill in the
making
<https://www.parlamento.pt/ActividadeParlamentar/Paginas/DetalheIniciativa.a…>,
though we assess that it doesn’t scope Wikimedia projects in its current
version. The UK has launched a national consultation
<https://www.gov.uk/government/consultations/growing-up-in-the-online-world-…>
on children and online life.
—
On the other end, Czechia stands out as a dissenting voice. The government
publicly opposes strict social media bans for children, says it is focused
on freedom of speech and concerned about overblocking. Estonia is also very
sceptical of a social media ban.
—
Somewhere in the middle is Germany's position that calls for beefed-up
protection of minors, though Berlin continues to prefer waiting for an
EU-level framework before acting nationally on age verification.
—
The French law, as we noted last month, explicitly excludes online
encyclopedias and educational resources (and even open source code
repositories) from its scope. We are monitoring each national development
carefully to ensure Wikimedia projects aren’t in scope, and engage where
necessary.
=== Blurry Images on Commons ===
A small but useful development. Wikimedia Commons is introducing a content
descriptor system
<https://commons.wikimedia.org/wiki/Commons:Village_pump#Wikimedia_Commons_c…!>
that, among other things, enables the selective blurring of sensitive
images. This is relevant to our policy work: as age verification and minor
protection discussions increasingly focus on image-based harm. Having a
documented, functional content moderation mechanism on Commons is something
we can point to in conversations with regulators.
=== CSAM ===
Talks on the permanent Child Sexual Abuse Material Regulation, dubbed
“chatcontrol” by critics, continue. Very slowly. Negotiators met in May and
made progress on several elements of the proposal, but the central and most
contested question — detection orders and scanning of personal messages —
was not on the agenda. There is one political trilogue left before the
summer, scheduled for 29 June, with the Cypriot Presidency still hoping for
a breakthrough on that date.
=== DSA: CJEU Reinterprets Systemic Risks ===
A significant development for anyone following DSA enforcement. In November
2025, the Court of Justice delivered its judgment in Amazon v. European
Commission
<https://curia.europa.eu/juris/document/document.jsf?docid=306323>, and the
DSA Observatory has now published a thorough analysis
<https://dsa-observatory.eu/2026/05/06/what-makes-a-risk-systemic-the-cjeus-…>of
what it means for the concept of systemic risks under the DSA.
—
The core holding is this: systemic risks under the DSA are about
large-scale societal impact. A risk is systemic if it could "affect a
significant part of the population of the European Union." The Court also
implied — though did not state outright — that the list of systemic risks
in Article 34(1) of the DSA is exhaustive rather than open-ended.
—
Why it matters for Wikimedia: The Wikimedia Foundation does have to go
through an annual DSA's systemic risk exercise for Wikipedia. A narrower,
scale-and-impact-based definition could mean that the WMF can be more
proportionate and more focused in this work.
=== Digital Omnibus ===
The Digital Omnibus (covering the GDPR, NIS2, Data Act and others) is
inching. The deadline for tabling amendments in the relevant parliamentary
committees is 15 July. Compromise amendments are expected to be forged
between October and December. A final committee vote is pencilled in for
February 2027. Civil society groups continue to press that simplification
must not come at the expense of fundamental rights protections,
particularly on GDPR. Industry would like more than just a few symbolic
steps. Wikimedia Europe follows the process and reiterates its position
<https://wikimedia.brussels/editorial-wmeu-on-the-digital-omnibus-the-russme…>
where appropriate, including sharing amendment proposals with relevant
lawmakers.
=== EU Democracy Shield ===
The Commission opened a targeted stakeholder consultation
<https://commission.europa.eu/strategy-and-policy/policies/justice-and-funda…>
on the European Democracy Shield, a non legislative initiative aiming at
safeguarding democracy in Europe. There were three specific strands: Safety
in politics, AI in electoral processes and anti-SLAPPs. We submitted our
positions with regard to the use of AI in elections
<https://commons.wikimedia.org/wiki/File:WMEU_Contribution_Democracy_Shield_…>
and on how to address the phenomenon SLAPPs
<https://commons.wikimedia.org/wiki/File:WMEU_Democracy_Shield_Targeted_Cons…>.
=== DEM-Debate ====
The last deliverable of the DEM-Debate research project, which looked at
information integrity on Wikipedia during the last European Parliament
elections, has been recently finalised: The Recommendations Report
containing a set of policy recommendations for lawmakers. Some
recommendations suggest targeted interventions on the DSA given its future
review by the end of 2027. Others draw inspiration from the Wikipedia model
and offer broader solutions that may inform future policy-making on
platform regulation.
You may read the full report
<https://drive.google.com/file/d/1c0oYidLZH29j1zwW4L6YETRHJ8PvJk0d/view?usp=…>
and the executive summary
<https://drive.google.com/file/d/1mBRyluTxX-aK4HNxjM28qUo2QMEPoqCW/view?usp=…>
.
=== Anti-SLAPP ===
On the 7th of May, the deadline to transpose the anti-SLAPP Directive
expired and only a few member states managed to adopt it on time. There is
a good overview
<https://eur-lex.europa.eu/legal-content/EN/NIM/?uri=CELEX:32024L1069> of
the process and adopted measures. Most countries took a minimalistic
approach and did not adopt laws introducing comprehensive protections
against SLAPPs.
—
On the topic of SLAPPs, WMEU and WMDE organised a workshop at CPDP
<https://www.cpdpconferences.org/workshops/a-perfect-slapp-how-the-do-paco-c…>,
particularly focused on the Do Paço case. It was a great opportunity to
explain the Wikipedia model and highlight some contradictions between the
implementation of GDPR and the freedom of expression. The presentation
<https://commons.wikimedia.org/wiki/File:CPDP_Workshop_Presentation_May_2026…>
is accessible on Commons.
===END===
--
Wikimedia Europe ivzw