This week we look at:
- EU Deforestation Regulation: updated commodities list
- Updated EBA guidelines on management of third-party risk related to non-ICT services
- EU proposes KIDS Act to strengthen online child safety
- EU Corporate sustainability reporting
EU Deforestation Regulation: updated commodities list
On 18 September 2026 Delegated regulation - EU - 2026/2102 came into force, amending the list of specific commodities that are subject to the EU Deforestation Regulation.
The Deforestation Regulation applies to large and medium operators and traders from 30 December 2026, and to micro and small enterprises from 30 June 2027. The first operator to place in-scope products on the EU market will need to produce a “due diligence” statement that they have not led to deforestation or forest degradation anywhere in the world after 31 December 2020.
The Delegated Regulation:
- clarifies the types of cattle, palm oil, rubber and wood within scope
- makes it clear that product samples “of negligible value and quantity”; products for examination, analysis and testing; waste, second hand and used products; packaging materials; and products used in the manufacture of medicinal products are out of scope
- removes from scope raw hides and skins of cattle, tanned cattle skins and hides, cattle leather, soybeans for sowing, retreaded tyres, certain articles of vulcanised rubber, conveyor and transmission belts and aircraft and motor vehicle seats
- adds frozen cattle tongues, soluble coffee and certain palm oil derivatives into scope with effect from 30 December 2027
The European Commission has also updated its guidance to reflect the changes.
Businesses should review their product portfolios against the Delegated Regulation and guidance, to ensure that they understand which products and commodities are within scope of the Deforestation Regulation and when compliance obligations start to apply.
Updated EBAguidelines on management of third-party risk related to non-ICT services
On 18 September 2026 the European Banking Authority (EBA) published its final report, sharing draft Guidelines on the management of third-party risk related to non-ICT services. The Guidelines are an updated version of the EBA’s 2019 guidelines on outsourcing, and are aimed at establishing a simpler, more proportionate and consistent framework that is aligned with the Digital Operational Resilience Act (DORA).
The Guidelines adopt a risk-based approach to the full lifecycle of relationships with third party service providers, including due diligence, risk assessment, contract requirements, subcontracting arrangements, ongoing monitoring, record-keeping and exit planning. They focus primarily on third-party arrangements that support critical or important functions (CIFs), i.e. functions whose disruption would materially impair the operation of a regulated financial entity, thereby reducing compliance and supervisory burdens for less material arrangements.
Once the Guidelines are in final form there will be a two-year transitional period to support implementation.
In-scope firms should review the Guidelines to understand their compliance obligations, noting that the revised Guidelines will apply to a broader category of firms than the 2019 version.
EU proposes KIDS Act to strengthen online child safety
On 17 September 2026, the European Commission adopted a proposal for the EU Keeping Internet Digital Spaces Accountable and Trustworthy (KIDS) Act, a new EU regulation aimed at strengthening protections for children online.
The proposal seeks to protect children from risks posed by digital services and AI systems, uphold the EU’s digital single market and maintain a coherent EU-wide regulatory framework and enforcement structure for the protection of children online. The proposed regulation would sit alongside existing legislation, including the Digital Services Act and the EU AI Act.
Notably, the proposal seeks to limit autonomous social media account creation by children below the age of 15 years – specifically prohibiting accounts for children under 13, providing for parent-supervised accounts at ages 13 and 14, and establishing 15 as the minimum age for holding an independent account.
The proposal would also impose “safety by design” requirements for online social networking services, video-sharing platform services, online games, AI companions and chatbots, and app stores, including restrictions on features considered addictive and safeguards designed to reduce risks to minors. In addition, the proposal establishes a clear framework, criteria and safeguards for age assurance.
If adopted, the KIDS Act would represent a significant expansion of online child safety regulation across the EU and could require substantial changes to platform design, age assurance measures and AI-enabled services. Businesses operating social media platforms, online gaming services, app stores and other AI-driven consumer products should monitor the proposal closely and assess whether existing child safety and age verification measures would meet the direction of travel indicated by the Commission.
More detailed analysis to follow from our specialists.
EU Corporate sustainability reporting
On 21 September 2026 two delegated Acts relating to the Corporate Sustainability Reporting Directive (CSRD) were published in the OJEU.
These cover: (i) simplified European Sustainability Reporting Standards under CSRD, coming into force on 10 November 2026 and applying for financial years beginning on or after 1 January 2027; and (ii) voluntary sustainability reporting standards for smaller companies (with less than 1000 employees) that are not required to report under CSRD. This also establishes a ‘value chain cap' that prevents companies in-scope of CSRD from requiring more information from below-threshold value-chain partners than what is covered by the voluntary standard. The European Financial Reporting Advisory Group has also published updated guidance on the voluntary standard.
These delegated acts are intended to reduce sustainability reporting requirements, with the Commission saying that reporting costs should be reduced by around 30%, and are part of the Omnibus I simplification package.
For more information on CSRD see our tracker: Home - EU Corporate Sustainability Reporting Directive CSRD. CSRD reporting requirements are changing, but the practical implications will vary between organizations and jurisdictions. The Omnibus I Directive could significantly affect which companies are required to report, when they need to report and how businesses approach voluntary sustainability disclosures. Our CSRD tracker brings together the key points businesses need to understand, including what has changed, expected timelines and implementation status by jurisdiction.