
Any company operating in a country of the European Union must comply with a set of legal procedures that condition the validity of its operations. This framework covers registration, the chosen legal form, reporting obligations, and, recently, rules on non-financial reporting or artificial intelligence. The framework is evolving quickly: two texts adopted between 2023 and 2026 are reshaping the landscape for SMEs as well as large groups.
The 28th European Company Law Regime and Its Practical Consequences
The European Commission has proposed a system sometimes referred to as the “28th regime,” which aims to create a unique legal framework for companies wishing to operate in multiple member states. The principle is simple: a digital registration valid in all 27 countries, without repeating national formalities for each establishment.
In practice, a French company opening a subsidiary in Germany and then in Portugal previously had to deal with three distinct commercial registers, three sets of translated and certified documents, and three filing schedules. The 28th regime provides for 100% online creation and modification procedures, with a common European identifier.
This evolution directly transforms the legal structuring strategy. An SME that is hesitating between creating a local subsidiary or a branch now has a third, lighter option in terms of formalities. Information regarding this new framework and the associated procedures is detailed on the Europe Entreprises website, which lists obligations by type of structure.

Omnibus Directive 2026: New Reporting Thresholds for SMEs
The so-called “Omnibus” directive, which came into effect on March 18, 2026, has profoundly modified the non-financial reporting obligations arising from the CSRD. The application thresholds have been raised: only companies with more than 1,000 employees and 450 million euros in annual net revenue will be subject to sustainability reporting starting from the 2027 fiscal year.
Listed SMEs, which were initially required to produce this reporting starting in 2027, are now completely exempt. This reduction in the scope of obligation does not mean that small structures can ignore the subject.
Cascade Effect on Subcontractors and Suppliers
Large companies subject to the CSRD will continue to request ESG data from their suppliers, including SMEs that are not subject to it. Contractual pressure replaces regulatory constraints. An industrial SME working with a contractor of more than 1,000 employees has every interest in structuring its environmental and social data, even without a direct legal obligation.
The duty of vigilance has followed the same tightening logic: it now only concerns companies with more than 5,000 employees. For others, compliance remains more of a competitive advantage than a constraint, but it requires regular legal monitoring.
Regulation of Artificial Intelligence in Business: The AI Act
The European AI Act classifies artificial intelligence systems into several risk categories. Companies that develop or deploy AI tools in their processes (automated recruitment, customer scoring, predictive maintenance) must identify the applicable risk category and comply with it.
- Systems with unacceptable risk are prohibited: generalized social scoring, behavioral manipulation targeting vulnerable individuals, real-time remote biometric identification in public spaces (except for regulated exceptions).
- High-risk systems (recruitment, credit, justice) require technical documentation, permanent human oversight, and a compliance assessment before being brought to market.
- Limited-risk systems (chatbots, deepfakes) impose a transparency obligation: the user must know they are interacting with an AI.
For an SME using an application sorting software or a product recommendation tool, the first legal step is to map its AI usage and verify their classification. Ignoring this step exposes the company to graduated sanctions.

Mandatory Electronic Invoicing: Calendar and European Standards
Several European countries have already made electronic invoicing mandatory between businesses. Italy was a pioneer, with Belgium and Spain following similar timelines. In France, the gradual rollout initially concerns large companies, then intermediate structures and SMEs.
The chosen technical standard is based on structured formats (Factur-X, UBL, CII) transmitted via partner dematerialization platforms approved by the tax administration. Each invoice issued or received passes through a platform that guarantees its authenticity and integrity.
What This Changes for Cross-Border Operations
A French company invoicing a Spanish client must verify compatibility between national platforms. The formats are standardized at the European level, but transmission obligations, deadlines, and sanctions remain defined by each member state. Monitoring national calendars is a legal process in its own right, not just a simple accounting adjustment.
- Verify the effective date in each country where the company issues invoices.
- Select a dematerialization platform compatible with local standards.
- Adapt internal information systems to produce invoices in the required structured format.
The legal procedures for companies in Europe are no longer limited to registration and the choice of a legal form. The 28th regime simplifies cross-border creation, the Omnibus directive reshapes reporting thresholds, the AI Act imposes a mapping of technological uses, and electronic invoicing changes the flows between business partners. Each European text generates distinct national obligations, making regulatory monitoring country by country essential for any structure active in the European market.