Governance, Risk & Compliance
-

Digital product passport: the presumption of conformity reaches the infrastructure, not the data
On 15 July 2026 the Official Journal of the European Union published the references of six harmonised standards for the digital product passport, under Commission Implementing Decision (EU) 2026/1736, adopted the previous day. From that date, anyone building a passport that conforms to those standards can rely on the presumption of conformity with the requirements…
-

Transparency of AI-generated content: the signing calendar, and what signing does not guarantee
The countdown to the transparency obligations for AI-generated content has entered its decisive phase. Article 50(2), (4) and (5) of the AI Act becomes applicable on 2 August 2026, and the code of practice meant to facilitate compliance has received its adequacy assessment: on 8 July through the Commission’s opinion, and the following day through…
-

Cookie banners and the right to complain: the EDPB sends the VRT case back to the merits
In a binding decision of 28 May 2026, made public on 14 July, the European Data Protection Board (EDPB) has ruled that a supervisory authority cannot dispose of a cookie banner complaint by branding it an abuse of the right to complain. The Belgian authority, acting as lead on a complaint brought by the Austrian…
-

Cyber accountability reaches the board, but the standards to prove it are still out to tender
On 14 July 2026 the Italian National Cybersecurity Agency (ACN) updated its FAQs on the obligations of the management bodies of NIS entities, clarifying that the approval of cybersecurity risk management measures cannot be delegated and that responsibility for the way that function is exercised stays with those who sit on the board. The day…
-

Minors, AI and platforms: the default, the design and the prohibition
Within a single week three different authorities, applying three different regulations, have intervened on the same object: the child in front of an interface designed to hold their attention. On 9 July 2026 the Italian Data Protection Authority fined Character Technologies Inc. 158,000 euros, identifying concerns regarding safeguards for minors and age verification mechanisms. On…
-

Transparency of AI-generated content: an adequate code that is no presumption of conformity
On 8 July 2026 the European Commission concluded that the Code of Practice on Transparency of AI-generated content adequately covers the obligations laid down in Article 50(2), (4) and (5) of the AI Act and facilitates their effective implementation. The following day the AI Board adopted its own adequacy assessment. In the very same weeks,…
-

Agentic AI: technical autonomy does not create legal autonomy
Artificial Intelligence systems no longer merely generate content: they act, they send, they modify, they commit. This is the starting point of “Agentic AI: Technical Autonomy, Human Responsibility, and Legal Governance”, the book by Nicola Fabiano published in July 2026, whose thesis is declared from the opening pages and runs through the entire work: technical…
-

AI Machine Learning Engineer: the profile Europe seeks above all others, and the technical debt only it sees
The European analysis of Artificial Intelligence skills needs uses, for one profile alone, the adverb “especially”: the machine learning engineer. This is the figure who turns models into production systems and keeps them alive; the technical literature, from Google to the NeurIPS conference, explains why it is so difficult, and so sought after. If one…
-

AI Security Specialist: attacks that resemble no other, and those who must stop them
Prompt injection, data poisoning, model evasion: Artificial Intelligence systems have an attack surface of their own, so specific that it has earned dedicated taxonomies from NIST, the OWASP project and MITRE. Guarding it is the craft of the AI Security Specialist, in a European market where security specialists are already in short supply, even before…
-

Chief AI Officer: the role that answers for Artificial Intelligence, from Washington to European business
In the United States, every federal agency is required to designate one, by executive directive; in Europe, it is the organisational answer to the most uncomfortable question of the moment: who is ultimately accountable for the Artificial Intelligence an organisation uses? A portrait of the Chief AI Officer – between the American mandate, Europe’s demand…