Governance, Risk & Compliance
-

Buying artificial intelligence knowing how much it consumes: the energy data of general-purpose models and contracts
Since 2 August 2025, providers placing general-purpose AI models on the market have had to comply with the obligations of Regulation (EU) 2024/1689, the AI Act (European Commission). These include drawing up technical documentation which, under Annex XI, Section 1, point 2(e), comprises the “known or estimated energy consumption of the model” (AI Act Service…
-

NIS2 and manufacturing: when an undertaking not listed by code enters the scope through REACH
Legislative Decree No 138 of 4 September 2024, which transposed Directive (EU) 2022/2555, the NIS2 Directive, has been in force since 16 October 2024 and requires the entities falling within its scope to register, or to update their registration, on the platform of the Italian National Cybersecurity Agency (ACN) from 1 January to 28 February…
-

The environmental management system becomes an obligation for industrial installations: Article 14a of the Industrial Emissions Directive
Directive (EU) 2024/1785 of 24 April 2024, published in the Official Journal of the European Union on 15 July 2024, inserted into Directive 2010/75/EU on industrial emissions Article 14a, under which “Member States shall require the operator to prepare and implement, for each installation falling within the scope of this Chapter, an environmental management system”…
-

ChatGPT a search engine, Reddit and Roblox platforms: the designations under the Digital Services Act
On 31 August 2026 the European Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms under the Digital Services Act. The striking classification is the first: a conversational assistant built on artificial intelligence enters the regulation on digital services not as a platform, but in…
-

A platform still without an address: the Cyber Resilience Act reporting obligation starts on 11 September
On 11 September 2026 manufacturers of products with digital elements will have to notify actively exploited vulnerabilities and severe incidents within twenty-four hours, as required by Article 14 of the Cyber Resilience Act. The channel through which they must comply, the single reporting platform run by ENISA, still has no public address, no dates for…
-

Data on people who are not under investigation: the EDPS on the Europol and Eurojust package
Between 10 and 11 August 2026 the European Data Protection Supervisor adopted four Opinions on the legislative package that the European Commission presented on 24 June 2026 to strengthen Europol and Eurojust and to overhaul the cross-border gathering of evidence. The press releases came out between 12 and 14 August, in the middle of the…
-

Frontier artificial intelligence reaches the board: a report due by 31 December
On 16 July 2026 the Official Journal of the European Union published a warning of the European Systemic Risk Board describing frontier artificial intelligence models as a source of systemic risk for the Union’s financial system. The following day the Bank of Italy and IVASS asked the boards of supervised intermediaries and of insurance undertakings…
-

Inspections without suspicion: ACN sets out how NIS 2 supervision works
On 11 August 2026 the Italian National Cybersecurity Agency added to its NIS frequently asked questions a section on monitoring, supervision and enforcement, made up of answers MVE.1 to MVE.5 and announced by the Agency on the same day. This is not new legislation and it adds no further obligations: it is the soft law…
-

Ten notifications and no more: the operating instructions for the Cyber Resilience Act platform
The reporting obligation under the Cyber Resilience Act applies from 11 September 2026 and runs through a single channel, the single reporting platform operated by ENISA. On 14 August the Agency updated the operating instructions for that platform and added a rule that did not appear in its July answers: a representative whose association with…
-

Italy implements the AI Act: who supervises, what it costs and where the workplace ban stops
On 4 August 2026 the Italian Council of Ministers gave final approval to the two legislative decrees that align Italian law with Regulation (EU) 2024/1689, under the delegation contained in Article 24 of Law no. 132 of 23 September 2025. The first decree covers the use of artificial intelligence in policing and the related civil…