Article image
The 2026 European Accessibility Act: What Agencies Actually Need to Track
The theoretical discussions around web accessibility are over. The European Accessibility Act (EAA) became enforceable on June 28, 2025, and more than a year into enforcement, the pattern is clear: this is no longer a "nice-to-have" feature request — it's a mandatory market law for products and services sold into the EU, backed by real courts, real regulators, and a growing pile of case law.
For web design agencies, MSPs, and freelance developers, the EAA is both an operational headache and a recurring-revenue opportunity. Because it applies to non-EU companies selling to EU consumers just as much as it applies to businesses headquartered in the bloc, agencies everywhere — not just in Europe — are being asked to prove their clients' sites are compliant.
But solving accessibility isn't a one-and-done project. It requires ongoing subscriptions, code-level remediation, and recurring audits — and the agencies that manage this well are the ones treating it as a tracked, recurring asset rather than a project they can mark "done."
The grace period is over — but the "fines are already flying" story is a myth
As of mid-2026, there is no grace period, and enforcement infrastructure is active across all 27 EU member states. But it's worth being precise about what "enforcement" has actually looked like so far: as of mid-2026, no confirmed monetary fines have been issued under any EAA-transposed national law. What's happened instead is formal legal notices, civil society lawsuits, regulatory information requests, market-surveillance inspections, and private warning letters. That's how EU enforcement typically starts — regulators usually move from notice to remediation order before they start collecting fines, and the heaviest penalties tend to land on companies that ignore repeated warnings, not first-time offenders.
That's not a reason for complacency. It's arguably a bigger warning sign: the legal machinery is now built and running in every member state, and 2026–2027 is when regulators are expected to shift from monitoring to formal sanctions.
What's actually happened, country by country
France — civil society is leading, not regulators. On July 7, 2025, four disability-focused NGOs sent formal legal notices to four major retailers — Auchan, Carrefour, E.Leclerc, and Picard — demanding accessible websites and apps. When the response was judged insufficient, the NGOs filed emergency injunctions on November 12, 2025.
The Auchan case was heard in May 2026 and dismissed on procedural grounds — the court acknowledged Auchan's site didn't conform to accessibility standards (which Auchan didn't dispute) but declined to treat it as an "obvious unlawful breach" in summary proceedings. The NGOs are appealing to the Douai Court of Appeal.
The Carrefour case was heard in June 2026. The Caen Judicial Court ordered Carrefour France to make both carrefour.fr and its mobile app fully accessible, with a daily fine for continued delay, and gave the company six months to comply. Carrefour argued it already met 71% of the criteria under France's national accessibility standard (RGAA). The court rejected that as insufficient — under RGAA and the EAA, all applicable criteria must be met; partial accessibility isn't compliance.
Germany — enforced through competition law, not just regulators. Under the Barrierefreiheitsstärkungsgesetz (BFSG), Germany's EAA transposition, private law firms began sending e-commerce operators warning letters within weeks of the law taking effect, treating non-compliance as grounds for unfair-competition claims. Fines under the BFSG can reach €100,000 per violation.
Netherlands — global reach, formal enforcement approaching. The Dutch Consumer and Market Authority (ACM) allowed voluntary self-reporting until October 15, 2025, after which reporting became mandatory. It has since sent information requests to e-commerce operators worldwide, including companies with no EU headquarters that simply sell to Dutch consumers. Formal enforcement is expected in the second half of 2026. Dutch fines can reach €900,000 or 10% of annual revenue.
Sweden — active regulatory inspections. The Swedish Post and Telecom Authority (PTS) opened its first cases in October 2025, reviewing the homepages, a product page, and search functionality of larger retailers (apps weren't in scope for this first round). PTS has logged 124 public complaints so far — 110 about services (mostly e-retail sites) and 14 about physical products like ATMs, showing consumers are actively using the complaint mechanisms the law created.
Ireland — the only member state with criminal liability. Penalties reach €60,000 with the possibility of six months' imprisonment for severe or repeat breaches.
Other confirmed penalty ranges: Spain and Italy up to €1,000,000; Hungary up to €1.26 million or 5% of annual turnover; Poland from around €21,000 or 10% of turnover. Every member state was required to set penalties that are "effective, proportionate and dissuasive," but the actual numbers vary widely, which is exactly why a client operating across five EU countries has five different exposure profiles.
One exemption worth knowing: microenterprises — fewer than 10 employees and under €2 million in annual turnover — are exempt from the EAA's service requirements. Product requirements still apply, and both conditions must be met, so an 8-person company with €3 million in revenue does not qualify.
The technical baseline is shifting under your feet
The EAA's technical requirements are anchored to the harmonized standard EN 301 549. The current version (v3.2.1, published March 2021) points to WCAG 2.1 Level AA. That's the baseline most agencies have been building to.
That's about to move. EN 301 549 v4.1.1, expected in 2026, is set to incorporate WCAG 2.2 Level AA — nine new success criteria focused on cognitive disabilities, low vision, and mobile/touch interactions (and one old criterion, 4.1.1 Parsing, dropped as obsolete). Once the new version is formally referenced in the EU's Official Journal, it becomes the binding technical standard for both the EAA and the Web Accessibility Directive — that reference step is what actually changes the legal obligation, not the publication of the standard itself.
Practically, that means agencies still selling "WCAG 2.1 AA compliance" as the finish line are already building to a standard that's about to be superseded. It's worth targeting WCAG 2.2 AA now so clients don't need a second remediation pass in twelve months.
The underlying POUR framework hasn't changed:
Perceivable — text alternatives for images, captions for video, a minimum 4.5:1 contrast ratio for normal text.
Operable — full keyboard navigation, no seizure-triggering flashing content.
Understandable — predictable interaction patterns, clear form validation and error messages.
Robust — semantic HTML that works with screen readers and other assistive tech.
The widget trap: why a script tag isn't a compliance strategy
This is the part most "how to sell EAA compliance" guides skip, and it's become one of the highest-risk pieces of advice an agency can give a client in 2026.
AI-driven overlay widgets — accessiBe, UserWay, and similar tools — are marketed as a fast way to bolt accessibility features onto an existing site: contrast adjustment, text resizing, animation pausing. They're easy to sell and easy to install. They are not, on their own, a defensible compliance strategy, and the regulatory and legal record on this has gotten considerably worse for the overlay industry over the past two years:
In April 2025, the FTC fined accessiBe $1 million for misrepresenting its AI-powered widget's ability to make websites conform to WCAG, and for using fake customer reviews to sell that claim.
UserWay is facing a class-action lawsuit from a small online flower retailer (BloomsyBox), alleging fraud and breach of contract. The company had purchased UserWay's widget on the strength of marketing promising a "$1,000,000 litigation warranty," was sued anyway by a screen-reader user who couldn't navigate the site, and says it was denied the promised support.
Industry tracking firm UsableNet found that roughly 25% of digital accessibility lawsuits filed in 2024 specifically cited an installed overlay or widget as a barrier to access, not a fix for one — and that pattern continued into 2025. Plaintiffs' firms reportedly scan for overlay script signatures (like userway.js) as a signal that a site is worth targeting, since the presence of a widget often means the underlying code was never actually remediated.
Major disability advocacy organizations, including the National Federation of the Blind, have publicly opposed overlay products, arguing they can actively interfere with screen readers rather than help them.
None of this means widgets are useless as a UX feature — offering visitors a way to adjust contrast or text size is a reasonable convenience layer. The problem is selling (or buying) one as the compliance solution. Real EAA/WCAG conformance is a code-level property: semantic markup, proper ARIA usage, accessible PDFs, and keyboard-operable interfaces, verified through manual testing with actual assistive technology. If your agency is currently positioning a widget subscription as "EAA compliance" in client contracts, that language is now a liability, not just a stretch.
What agencies should actually be tracking
Given the above, the realistic service stack for 2026 has two components, and they need to be tracked as separately as a domain name and an SSL certificate:
Manual audits and remediation, against EN 301 549 / WCAG 2.2 AA. This is the actual compliance work — semantic HTML, ARIA, accessible documents, and verification with screen readers and keyboard-only navigation. If a client's last audit predates June 2025, or was only run against WCAG 2.0/2.1, it's out of date on two counts now.
Optional overlay/widget subscriptions, sold honestly as a UX convenience layer — not as a substitute for the audit, and not marketed to clients as legal protection it can't actually provide.
The SOP for tracking these as ongoing assets
Centralize license and ownership data. Know, for every client, whether the agency or the client owns the accessibility tooling account, and whose payment method is on file. A lapsed card on a widget subscription — or a missed audit renewal — is the same category of risk as a lapsed domain registration, just with a regulator on the other end instead of a 404 page.
Track audit renewal timelines like SSL certificates. An audit from January 2025 needs a follow-up scheduled well before January 2026 — and going forward, "current" means tested against WCAG 2.2 AA, not 2.1.
Maintain the accessibility statement and complaint mechanism. Publishing a public accessibility statement and a functioning complaint channel is a baseline EAA requirement in its own right, and its absence is an easy, visible enforcement trigger for regulators and NGOs alike. Track the date it was last updated and refresh it alongside every audit.
Plan for the two dates still ahead. Legacy content and products published before June 28, 2025 have until June 28, 2030 to reach compliance — that deadline should already be in every client's roadmap, not treated as distant. Emergency communications services come into EAA scope starting June 2027. Neither date is urgent today, but both belong in the tracking system now so they don't get missed later.
Document everything. Regulators and courts evaluating EAA complaints want to see an active, demonstrable pattern of remediation work, not a one-time certificate. A dated log of audits, fixes, and statement updates is what lets a client show a regulator "we've been actively working on this" instead of "we paid for a badge once."
Building the tracking system
Spreadsheets get missed. The agencies handling dozens of client sites without dropping a renewal are the ones running this through a proper asset-tracking system rather than institutional memory:
Map each accessibility asset to its domain, alongside hosting and DNS, so a single client view shows exactly what's active and what's about to expire.
Automate expiration alerts — 30 to 60 days out for audit renewals, and enough lead time on any widget subscription to catch a failed payment before the tool silently disappears from the site.
Log the "last audited against" standard, not just the date — noting WCAG 2.1 AA vs. 2.2 AA matters once EN 301 549 v4.1.1 lands.
Keep the historical record, so if a regulator or client ever asks "what have you done about this," the answer is a dated list, not a memory.
The bottom line
The first year of EAA enforcement confirmed two things agencies should plan around: the direction of travel is toward real penalties, even though none have landed yet, and the "install a widget and call it done" playbook is now actively backfiring in court. The agencies positioned well for 2026–2027 are the ones selling — and tracking — real audits against a technical standard that's about to move to WCAG 2.2, with clean documentation to show for it, not the ones relying on a script tag and hoping nobody checks.
Sources referenced
Level Access, "EAA Enforcement, One Year In: What's Happened and What Comes Next" (June 2026)
Web Accessibility Checker, "EAA Fines & Penalties by Country (2026 Update)"
Wikipedia / ETSI, EN 301 549 standard documentation
W3C Web Accessibility Initiative, WCAG 2.2 / ISO 40500 status pages
UserWay compliance documentation (userway.org)
Federal Trade Commission action against accessiBe (April 2025)
Law Office of Lainey Feingold, reporting on the UserWay/BloomsyBox class action
KHA Creation USA, "The Overlay Trap" (2026)
This article reflects publicly reported information as of July 2026. EAA enforcement is moving quickly and unevenly across member states — verify current fine amounts and case outcomes with a qualified accessibility or legal specialist before publishing client-facing compliance claims.
Top comments (0)