The most defensible EU compliance statistics for 2026 are figures published by EU institutions with a stated period and denominator. This review therefore removes market-size forecasts, unsourced readiness percentages, consulting-price estimates, and cumulative private enforcement trackers. It keeps a smaller set of official figures that can be checked directly.
The figures below were verified on 8 August 2026. A “2026 statistic” may describe activity in 2025 or an earlier survey reference year; each row states the period so readers do not confuse publication date with measurement date.
Headline figures
| Topic | Verified figure | Period and denominator | Official source |
|---|---|---|---|
| GDPR fines | EUR 1.15 billion | Total value of fines issued by national data protection authorities during 2025, as reported by EDPB | EDPB Annual Report 2025 |
| GDPR cross-border cooperation | 414 cases | Cross-border cases created in the EDPB case register during 2025 | EDPB Annual Report 2025 |
| GDPR one-stop-shop | 1,299 procedures; 572 final decisions | Article 60 procedures triggered during 2025 and those leading to final decisions | EDPB Annual Report 2025 |
| Enterprise AI adoption | 20.0% | EU enterprises with at least 10 employees/self-employed persons using AI technologies in 2025 in covered NACE sectors | Eurostat |
| Enterprise ICT incidents | 21.5% | EU enterprises in the Eurostat survey that experienced an ICT security incident with consequences in 2023 | Eurostat |
| Enterprise security measures | 93% | EU enterprises in the 2024 Eurostat survey using at least one listed ICT security measure | Eurostat |
| ENISA threat sample | 4,875 incidents | Incidents analysed for 1 July 2024–30 June 2025; this is an analysed sample, not all EU incidents | ENISA Threat Landscape 2025 |
| NIS2 sector coverage | 18 critical sectors | Sectors in the EU framework described by the Commission; entity scope still depends on type, size rules, exceptions, and national law | European Commission |
| DORA critical providers | 19 names | Providers in the initial Union list published by the ESAs on 18 November 2025 | EBA / ESAs |
GDPR enforcement in 2025
The EDPB's 2025 Annual Report supplies an official annual snapshot:
- national data protection authorities issued fines with a combined value of EUR 1.15 billion in 2025;
- 414 cross-border cases were created in the EDPB case register;
- 1,299 Article 60 one-stop-shop procedures were triggered; and
- 572 led to final decisions.
These figures should not be added to private “GDPR fine tracker” totals without checking coverage, currency, appeal status, and double counting. The annual fine value is not a count of fines, and it does not measure the value of corrective orders, bans, warnings, or private claims.
Enterprise AI adoption
Eurostat reported that 20.0% of EU enterprises in its covered population used at least one listed AI technology in 2025. That was 6.5 percentage points higher than the 13.5% reported for 2024.
The denominator matters: the survey covers enterprises with at least 10 employees or self-employed persons in specified NACE sectors. It does not mean that 20% of every EU company, public authority, or individual used AI, and it is not an AI Act compliance-rate measure.
For governance planning, the useful inference is limited: AI use is material enough that inventories cannot rely only on systems purchased by a central technology team. This is an inference from adoption data, not a legal statistic.
Cybersecurity measures and incidents
Eurostat's 2024 enterprise survey reported:
- 93% of EU enterprises used at least one listed measure to protect the integrity, availability, and confidentiality of data and ICT systems;
- strong password authentication was reported by 84%;
- backup to a separate location or cloud by 79%; and
- network access control by 65%.
The same survey series reported that 21.5% of EU enterprises experienced an ICT security incident with consequences in 2023. Those consequences include non-malicious hardware or software failures as well as malicious events, so the number must not be presented as a cyberattack rate.
The Eurostat population covers enterprises with at least 10 employees or self-employed persons in specified sectors. It excludes many microenterprises and does not prove that any particular control was adequate or tested.
ENISA threat-landscape sample
ENISA Threat Landscape 2025 analysed 4,875 incidents across the period from 1 July 2024 to 30 June 2025. Within that analysed set:
- distributed denial-of-service attacks accounted for 77% of incidents;
- hacktivism accounted for almost 80% of the incident count; and
- phishing was identified as an initial intrusion-access point in 60% of the relevant analysis, followed by vulnerability exploitation at 21.3%.
These shares describe ENISA's dataset and method. They are not the probability that an EU organisation will experience an incident, and they should not be combined with the Eurostat enterprise survey as if both measured the same population.
NIS2: what can be counted safely
The European Commission describes NIS2 as creating a common framework across 18 critical sectors. As a rule, medium-sized and large entities of covered types are in scope, with exceptions and special cases.
An estimate of the number of entities is less reliable than the sector figure because NIS2 is implemented through national law, Member States identify and register entities, and scope depends on entity type, size, and exceptions. This page therefore uses the official sector count and does not estimate a total number of in-scope entities.
DORA: implementation facts
DORA has applied since 17 January 2025. The ESAs published the initial Union list of designated critical ICT third-party providers on 18 November 2025. The official list contains 19 named providers.
That number is a point-in-time count of designations, not the number of ICT providers serving EU finance and not the number of financial entities subject to DORA. The ESAs are required to publish and update the list; use the current version for any decision.
AI Act dates, not speculative compliance rates
Official sources support the following dates:
- most original prohibited-practice rules have applied since 2 February 2025;
- governance and GPAI provisions began applying on 2 August 2025;
- the general application date and Article 50 transparency duties passed on 2 August 2026;
- under the narrow Article 111(4) transition, providers of synthetic-content systems placed on the market before 2 August 2026 have until 2 December 2026 to take the necessary steps to comply with Article 50(2);
- Regulation (EU) 2026/1744 moved the Chapter III high-risk rules to 2 December 2027 for Article 6(2)/Annex III systems; and
- the corresponding date for Article 6(1)/Annex I product-related systems is 2 August 2028.
This page does not publish a percentage of organisations that are “AI Act compliant.” No official EU-wide measure with a consistent denominator was identified for that claim.
CSRD scope numbers changed in 2026
The amended EU-level CSRD framework uses both EUR 450 million net turnover and an average of more than 1,000 employees for the principal EU undertaking/group scope from FY 2027, subject to the detailed framework and Member State transposition.
Directive (EU) 2025/794 moved the former second wave to FY 2027. Directive (EU) 2026/470 then narrowed scope and removed the listed-SME wave. Any statistic based on the former “about 50,000 companies” perimeter is therefore not a reliable current scope count and has been removed here.
How to cite these figures responsibly
- State the source organisation and publication.
- State the measurement period, not only the publication year.
- State the denominator and exclusions.
- Distinguish an administrative count, survey estimate, legal threshold, and analysed incident sample.
- Do not combine annual fine values into a cumulative total without a documented method.
- Archive the cited version or access date for board and audit work.
- Recheck mutable lists and dashboards before publication.
Methodology
The review accepted primary legal texts, official statistics, and publications from EU institutions or agencies. It excluded:
- consultancy and vendor surveys as general market facts;
- private fine trackers as an official cumulative total;
- unattributed salary, consulting-price, market-size, and readiness figures;
- projections presented as observations; and
- figures without a clear population or reference period.
This makes the page shorter than the earlier version but materially more reproducible.
Sources and review
This statistics page was substantively reviewed on 8 August 2026. Figures should be rechecked before reuse because annual reports, dashboards, and designation lists change.
- EDPB — Annual report 2025 enforcement figures
- Eurostat — 20% of EU enterprises used AI technologies in 2025
- Eurostat — 93% of EU businesses applied ICT security measures in 2024
- Eurostat — 21.5% of EU enterprises had ICT security incidents in 2023
- ENISA Threat Landscape 2025
- European Commission — NIS2 Directive
- EBA — initial list of designated DORA critical ICT third-party providers
- Regulation (EU) 2026/1744 — Digital Omnibus on AI
- Directive (EU) 2026/470 — Omnibus I sustainability amendments
For help turning official data and applicable legal requirements into a scoped programme and management dashboard, see Vision Compliance's regulatory compliance service.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.