Loading...
Skip to main content

Like many websites, BSA’s websites use cookies to ensure the efficient functioning of those websites and give our users the best possible experience. You can learn more about how we use cookies, and how you can change your browser's cookie settings, in our cookies statement. By continuing to use this site without changing your cookie settings, you consent to our use of cookies.

X

MAR 11, 2026 | EUROPEAN UNION | EUROPE, MIDDLE EAST AND AFRICA

BSA: The EU Should Go Further in Simplifying Digital Rules

BRUSSELS - The Business Software Alliance (BSA) today called on the European Commission to go one step further in simplifying the EU’s digital rulebook, reinforcing the risk-based approach to AI and delivering deeper alignment across cybersecurity legislation.

In its response to the Digital Fitness Check consultation, BSA welcomed the general objective of the Commission’s Simplification Agenda to make rules simpler and therefore easier for companies to navigate and apply. However, meaningful simplification, BSA stressed, requires more than structural adjustments.

On artificial intelligence, BSA emphasized that the AI Act’s risk-based foundation must remain intact. High-risk regulatory requirements should stay focused on genuinely high-risk uses of AI and avoid unintentionally capturing lower-risk systems. Where meaningful human oversight is built in — with a person reviewing outputs and retaining the final decision — the AI system functions as a support tool, thereby mitigating the high-risk setting. That reality should be reflected in high-risk classification requirements.

On cybersecurity, BSA noted that a single reporting entry point is a welcome first step. However, companies operating across frameworks such as the CRA, NIS2, and DORA still face fragmented definitions, inconsistent reporting timelines, and duplicative audit requirements.

“The Commission has taken an important first step on simplification, but it shouldn’t stop there,” said Hadrien Valembois, Director, Policy – EMEA at BSA. “For companies building AI and cybersecurity solutions, clarity and coherence matter just as much as ambition. The AI Act should stay focused on real risk, especially where meaningful human oversight already limits harm. And on cybersecurity, reporting once should truly mean reporting once, with consistent definitions, reporting timelines across digital laws. Europe should not be afraid to go further; simplification is what will make its digital framework truly work in practice.”

BSA’s submission underscores that regulatory coherence, proportionality, and alignment across digital legislation are essential to strengthening Europe’s competitiveness, resilience, and innovation ecosystem.

TAGS:

ABOUT BSA

The Business Software Alliance (www.bsa.org) is the global trade association of the enterprise software industry, representing companies that are leaders in artificial intelligence, cybersecurity, cloud computing, quantum, and other breakthrough technologies. We work in over 20 markets in the US, Europe, and Asia, advocating for policies that build trust in technology so that every industry sector and the public can benefit from innovation. 

MEDIA CONTACTS

Michael O’Brien

For Media Inquiries

MEDIA CONTACTS

Media Inquiries

MEDIA CONTACTS

Media Inquiries

CONTACTO DE PRENSA

Media Inquiries