As POS systems and telematic cash registers are linked more tightly, the fiscal upside is clear, but so are the questions around liability, intermediaries, privacy, competition, and merchants who act in good faith.
France’s move on social-network access for teens has revived a harder question: if the risk lives in games, chatbots, and betting too, what exactly does a single age gate solve?
Italy’s cyber environment is still under strain in early 2026, but the move to regular incident notification is beginning to shape how defenders see, sort, and answer risk.
Italy’s financial supervisor is pressing supervised institutions to treat AI as an operational risk problem, not a slow compliance exercise, as the gap between vulnerability discovery and exploitation keeps narrowing.
Privacy sanctions in the energy sector are turning automated credit scoring into a governance test, where data quality, transparency, and the right to challenge a decision matter as much as the score itself.
The European Commission has issued new guidance to help providers and users meet AI Act transparency duties, pushing AI disclosure from policy language into product and deployment practice.
The policy is simple on paper, but enforcing it means building age controls that are accurate, privacy-preserving, and hard to game.
Italy’s NIS2 debate around article 17 turns security vendors, test labs, and threat-intelligence partners into a governed information-sharing channel, not just a procurement relationship.
The EU court’s C-474/24 ruling shows why context, not just labels, can decide whether an online record becomes sensitive health information.
The move from compliance to operational capability is forcing organizations to prove they can keep working when a real crisis hits, not just when paperwork looks complete.
ANPR access through PDND is turning a once-manual administrative routine into a governed digital lookup, with efficiency gains matched by sharper demands on identity, logging, and purpose control.
The move to bring non-accredited private outpatient clinics into FSE 2.0 is chiefly a compliance-and-integration challenge, but it also raises the stakes for document integrity, selective disclosure, and privacy logging.
AGCOM’s 2026 outlook treats artificial intelligence as a structural layer in information delivery, where visibility, sourcing, and pluralism matter as much as content production.
A sanction involving Lidl and Italy’s data protection authority shows how access rights under the GDPR can be undermined by the very forms and internal channels meant to manage them.
Financial intermediaries are being asked to prove how they manage cyber risk, protect technology layers, and keep operations running under pressure, with a 31 December 2026 submission date on the table.
A convergence between a Vatican AI text and a policy manifesto is pushing the real debate away from slogans and toward controls: human review, traceable data, and accountable deployment.
An EU-level registry for TDM opt-outs could make reserved rights easier to spot, but the final design and impact remain unsettled.
Two closely linked rulings sharpen a simple rule: naming a processor is not enough unless the controller also checks how that processor works.
Italy’s privacy authority has closed its inquiry into Wind Tre with a seven-figure sanction, but the most interesting part is what remains unconfirmed: whether a human compromise, an API path, or both helped turn a localized incident into a personal-data case.
A new Italian health-data project is trying to do what Europe has struggled to achieve for years: make clinical records usable for AI research while keeping privacy risk under control.