Governance, Risk & Compliance
-

The Garante’s 2026 inspection plan: the areas in the spotlight and the lessons of the Emirates case
By deliberation No. 797 of 30 December 2025 the Italian Garante planned its inspection activity for the first half of 2026: artificial intelligence in schools, data breaches of public databases, whistleblowing, health dossiers, energy-sector telemarketing, and anonymisation of Telco big data. And the recent Emirates fine shows that even a lawful legal basis does not…
-

ISO/IEC 42001 and the AI Act: why certification is not (yet) a presumption of conformity
On 18 March 2026 EN ISO/IEC 42001:2026 was published, the European adoption of the standard on Artificial Intelligence management systems, while the work of CEN-CLC/JTC 21 on harmonised standards supporting the AI Act proceeds rapidly. But beware of confusing the levels: the AIMS of ISO/IEC 42001 is not the quality-management system required by Article 17…
-

NIS 2 put to the test: notifications, categorisation and security measures in the 2026 roll-out
2026 marks the shift of the Italian transposition of the NIS 2 Directive from the declaratory phase to the implementation phase: the duty to notify significant incidents to CSIRT Italia, the first window for the categorisation of activities and services, and the deadline for adopting baseline security measures. How to find one’s way among ACN…
-

The AI Act and the Digital Omnibus: the new high-risk timeline, between simplification and fundamental rights
Update (24 July 2026): the Digital Omnibus on AI has been published in the Official Journal as Regulation (EU) 2026/1744, in force from 27 July 2026. Read the news on the publication. On 16 June 2026 the European Parliament gave final approval to the amendment of Regulation (EU) 2024/1689 within the so-called “Digital Omnibus on…
-

AI governance, a titanic effort: approaches compared
From the Law & Technology review · agendadigitale.eu.
-

Auditing as a tool for AI governance: how to do it
From the Law & Technology review · agendadigitale.eu.
-

-

Whistleblowing: Model 231 and new obligations for SMEs and public bodies
From the Law & Technology review · agendadigitale.eu.
-

SAI – Intelligent Administrative Systems. After the Public Digital Identity System (SPID): virtuous profiles and criticalities of digital citizenship
From the Law & Technology review · astrea.com.ar.
-

Commercial law in the age of digitalisation: between borderless trade and the protection of e-consumers
From the Law & Technology review · fder.edu.uy.