Governance, Risk & Compliance
-

Twenty-four hours to report: what starts on 11 September under the Cyber Resilience Act
The Cyber Resilience Act applies in full from 11 December 2027, but not everything waits for that date. From 11 September 2026, six weeks from now, manufacturers of products with digital elements will have to notify actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware of them, through a single platform run…
-

Labelling today what will be marked in December: AI content transparency after 2 August
Since 2 August 2026 the transparency obligations in Article 50 of the AI Act have been enforceable. Two days earlier, on 31 July, the European Commission published the list of signatories to the Code of Practice on Transparency of AI-generated Content: about one hundred and ninety organisations, of which eighty-three signed the section addressed to…
-

Quality management systems for high-risk AI: what Article 17 requires and how much time is left
Article 17 of the AI Act requires providers of high-risk artificial intelligence systems to put in place a documented quality management system. Until a few weeks ago that obligation would have become enforceable on 2 August 2026, and the technical means of building it did not yet exist. Within a month the two swapped places:…
-

A digital strategy for schools: what the Irish model teaches
The debate on AI literacy at school benefits from comparison with national experiences that are already structured. Ireland offers a telling case: a multi-year digital strategy for schools, backed by €200 million in capital funding, an implementation plan with measurable actions and, most recently, dedicated guidance on the use of AI. We retrace its design,…
-

AI literacy: the Digital Omnibus rewrites Article 4 of the AI Act
On 24 July 2026 the Official Journal of the European Union published Regulation (EU) 2026/1744 (EUR-Lex), the Digital Omnibus on AI, in force from 27 July. Among its amendments to the AI Act is the full rewriting of Article 4, the provision on AI literacy: the obligation on providers and deployers is not repealed, but…
-

The Digital Markets Act put to the test by Google: €890 million for self-preferencing and steering
On 23 July 2026 the European Commission adopted two decisions finding that Google had failed to comply with the Digital Markets Act, and imposed fines totalling €890 million: €460 million for favouring its own services in search, and €430 million for restricting developers’ freedom to point users towards alternative offers on Google Play. The figure…
-

A score decides the supply: the Garante and the right to know the score
Four companies fined a total of 7.72 million euro because an automated system decided, on the basis of a reliability score, whether or not to activate an electricity and gas supply; and the customers who were turned down could not find out how that score had been built. In its press release of 21 July…
-

Digital Omnibus on AI in the Official Journal: Regulation (EU) 2026/1744 is published
The Digital Omnibus on AI is now law. On 24 July 2026 the Official Journal of the European Union (OJEU) published Regulation (EU) 2026/1744 of 8 July 2026, amending Regulation (EU) 2024/1689 (the AI Act) together with Regulations (EU) 2018/1139 and (EU) 2023/1230, to simplify the implementation of the harmonised rules on artificial intelligence. The…
-

Under the Digital Services Act, a fine is a stage, not the finish line
In the space of a few days the European Commission has shown the two faces of Digital Services Act enforcement. On 20 July 2026 it fined AliExpress €550 million for failing to diligently assess and mitigate the risks of illegal, unsafe or counterfeit products spreading through its e-commerce platform. Five days earlier it had accepted…
-

Making regulators talk to one another: the EDPB calls for a legal basis to share information
Meeting in Dublin on 16 and 17 July 2026, Europe’s data protection authorities put a clear request to the European Commission: give the Union a legal basis that lets authorities with different remits share information, including confidential information, in order to enforce their respective rules. The request, made by the European Data Protection Board (EDPB)…