Round-up of knowledge
Welcome to Commercially Connected shorts, our weekly bitesize newsletter summarising the latest updates in UK and EU commercial law.
This week we look at:
UK plans faster route to market for innovative businesses
On 8 July 2026 the UK government announced that the Regulation for Growth Bill will introduce new statutory regulatory sandbox powers, allowing businesses to test innovative products and services in real-world environments under regulatory oversight. Whilst we await sight of the Bill, we can say that the reforms are designed to reduce regulatory barriers, accelerate commercialisation and support investment across sectors including AI, life sciences, autonomous technologies and advanced delivery services. The package will also strengthen regulators' growth duties and build on the government's wider drive to reduce regulatory burdens on business. In tandem, guidance: Regulatory sandboxes: what businesses can expect - GOV.UK has been published providing further detail on the sandbox initiative, eligibility (open to all projects with a genuine element of innovation), safeguards to manage risk, and benefits/opportunities.
These proposals are further referenced in the July Regulation Action Plan Progress Report which sets out the Government's progress in reforming the UK's regulatory system to support economic growth, innovation and investment while maintaining key protections. To date, the Government considers delivery of its plan to be progressing well, with a significant proportion of regulatory and departmental commitments either completed or on track, alongside measures intended to improve UK competitiveness, support investment and make regulation more innovation-friendly. The report highlights growth priorities for regulators in the areas of digital and technology, advanced manufacturing and aerospace, clean energy, and life sciences. It also proposes greater regulatory accountability through minister-led reviews, a public performance dashboard, a regulator sponsorship charter (which sets out expectations for sponsoring departments) and increased use of KPIs and oversight measures.
For innovative sectors such as AI, life sciences, advanced manufacturing, autonomous systems and clean energy, these reforms could mean faster approvals, lower compliance burdens, easier market entry and a quicker route from testing to commercial deployment.
EU Deforestation Regulation: Commission updates product scope and compliance tools
On 13 July 2026 the European Commission adopted measures to support implementation and simplification of the EU Deforestation Regulation (EUDR) from December 2026. Changes include:
- removing certain derived products (such as leather, re-treaded tyres and soybeans for sowing) from scope
- adding products to scope (including soluble coffee and some palm oil derivatives)
- introducing targeted exemptions for certain categories of product (including waste, second-hand products and products used in the manufacture of medicines)
These are captured in the Delegated Act with the new products added to scope not subject to the EUDR until 30 December 2027.
The Commission has also updated the EUDR Information System, including simplified reporting for some smaller operators and updated technical specifications for automated application programming interfaces (by way of an Implementing Act).
Businesses should review whether affected products move into or out of scope and ensure supply chain due diligence and reporting processes align with the updated rules before the EUDR starts to apply.
Cyber Resilience: UK and EU Raise the Bar
7 July 2026 marked a significant day for cyber policy on both sides of the Channel, with the UK and EU each announcing initiatives aimed at bolstering resilience in an increasingly AI-driven threat landscape.
In the UK, the Government launched the Cyber Resilience Pledge, a voluntary commitment designed to strengthen board-level accountability and supply chain security. Meanwhile, the European Commission published its Action Plan on cybersecurity and AI, building on existing legislation—including the AI Act, NIS2 Directive, DORA, Cyber Resilience Act and Cyber Solidarity Act—to prepare European infrastructure for AI-enabled threats and opportunities.
Both frameworks emphasise similar priorities:
- Board engagement and governance: The UK Pledge requires signatories to implement the Cyber Governance Code of Practice, complete the National Cyber Security Centre (NCSC) Cyber Governance Training and register for the NCSC’s Early Warning service. The EU Action Plan similarly underscores governance-level preparedness across critical sectors.
- Supply chain and SME resilience: The UK Pledge calls for a risk-based approach to Cyber Essentials certification across the supply chain, while the EU plan places immediate focus on supporting SMEs and preparing supply chains for AI-enabled cyber threats.
- AI-powered capabilities and investment: The UK National Cyber Action Plan (which the UK Pledge precedes) will include investment in AI-powered defensive capabilities, adoption of secure tech, and measures to tackle cyber-crime (the latter to be set out in the National Security Bill). Similarly, the EU plan focuses on scaling European AI and cybersecurity capabilities through investment, skills development and support for sovereign AI technologies. The EU also wants to implement an ‘evaluation capacity’ for frontier AI to be safely evaluated, accessed, tested and deployed for cybersecurity purposes by 2027.
- Partnership and cooperation: Both the UK and EU initiatives signal a desire to strengthen ties with like-minded partners (nationally and/or internationally) to promote a trusted and secure global approach to AI and cybersecurity.
For businesses operating across the UK and EU, these parallel developments underscore the growing regulatory expectation that cyber resilience—particularly in the context of AI—be embedded at board level, across supply chains and throughout critical operations.
For more on cyber compliance in the EU, see our Executive Compliance Guide: Cyber Resilience Act | Navigating EU Law.
Executive Compliance Guide: Ecodesign for Sustainable Products Regulation (ESPR)
On 19 July 2026 the EU's ban on destroying unsold clothing, clothing accessories and footwear takes effect – and companies must publicly disclose what they discard. If your business sells products in the EU, the time to act is now.
The EU Ecodesign for Sustainable Products Regulation (ESPR) introduces sweeping sustainability requirements for products sold in the EU, placing new obligations on manufacturers, importers and distributors.
Key leadership considerations:
- prepare for the ban on destroying unsold clothing, accessories and footwear, including excess stock and customer returns.
- ensure your first disclosure on discarded unsold consumer products is ready before year-end 2026, even ahead of the standardised reporting format.
- start planning for the Digital Product Passport and product-specific ecodesign requirements phasing in from 2027–2028.
With implementation milestones already underway and product-specific delegated acts on the horizon, the time to prepare is now. Read our compliance guide: Executive Compliance Guide: Ecodesign for Sustainable Products Regulation (ESPR) | Navigating EU Law