A narrow postponement for certain high-risk AI rules can look like breathing room, but the broader obligation to train staff still matters for governance, data handling, and Shadow AI control.
ACN’s latest clarification pushes compliance out of the document cabinet and into the audit trail, where organizations must show that controls are actually working.
The Kids Online Safety Act has picked up some momentum, yet its path through Congress remains uncertain despite growing political pressure.
NIS2 and DORA are pushing organizations toward proof, not promises, and NSPM sits in the gap between what security teams intend and what their networks actually enforce.
When personal data has already shaped an AI system, erasing the record is only the first step - the harder problem is removing its influence from the model itself.
The latest FAQ update for NIS subjects is a policy clarification, but it also shows how supervisory language can shape security governance, documentation, and accountability.
Under NIS 2, the method used to manage risk is not a side issue - it shapes how an organization reads its exposure, chooses measures, and proves that its security system hangs together.
The EU’s Savings and Investments Union and Retail Investment Strategy are less about headlines than about mechanics: how money moves, how products are judged, and how retail savers are protected along the way.
A months-long exposure around a qualified signature shows how identity workflows can inherit risk from the browser layer, even when trust frameworks appear to be in place.
The Cyber Resilience Act is pushing open-source ecosystems toward named roles, traceable dependencies, and formal incident workflows long before many teams are ready.
A tighter compliance mix around AGCOM, Digital Chart IAP, ATECO classification and INPS clarifications is pushing creator marketing toward clearer responsibility and cleaner disclosure.
Enterprise AI is racing ahead of governance, leaving CIOs to solve a harder problem than adoption: visibility, budget control, and trustworthy measurement.
A ransomware-linked victim listing for Supportive Insurance Services shows how public claims can create immediate business risk, even when the technical facts remain unconfirmed.
The security question is no longer only how fast a team can contain an alert, but how quickly it can translate that alert into operational impact, supplier risk, communication needs, and the cost of interruption.
The policy balance is shifting: fewer reporting burdens for many firms, but stronger pressure on banks to treat ESG risk as part of lending decisions.
GDPR pushed privacy into the boardroom, but the real test is no longer paperwork: it is whether systems collect less, protect more, and resist misuse by design.
In GDPR language, "shall" is more than grammar: it marks a binding obligation for the data controller to turn privacy principles into adequate protection.
A debate about Made in Italy is really a debate about how far ESG compliance can stretch before it starts reshaping production, supplier oversight, and competitiveness.
In a NIS2 context, resilience is framed less as a backup checklist and more as the discipline of deciding what must restart first, how fast it must return, and how much data loss can be tolerated.
ISO management-system work is expanding beyond routine control checks, with climate-related context, risk, and emergency planning becoming part of what auditors are expected to examine.