Cyber Resilience Act: under three weeks to 11 September
In July we explained why the CRA's first binding deadline is 11 September 2026, not 2027. Now time is up: from 11 September the 24 and 72-hour clocks for exploited vulnerabilities start. The final checklist, no theory.
The AI Act's Article 50 is live: what actually changed on 2 August
In July it was a deadline to prepare for, now it is applicable law: from 2 August chatbots, generated content and deepfakes must be disclosed, and on 31 July the Commission confirmed enforcement would begin. What we fixed across client projects in half a day.
Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026
The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.
Your AI vendor can be switched off by a government you do not vote for
On 12 June a US export-control order switched off a frontier model for everyone, everywhere, for eighteen days. What that means for a European SME with a feature in production, and how you actually defend against it.
The AI Act omnibus is law: what slipped and what starts on 2 August
The Digital Omnibus took effect on 27 July and pushes the high-risk rules out to December 2027. Article 50 did not move: from 2 August 2026 chatbots, generated content and deepfakes must be disclosed, and in Italy ACN does the enforcing.
EU AI Act for SMEs: what kicks in during 2026 and what to do now
The EU AI regulation phases in over time. Many SMEs assume it doesn't touch them. Often it does. Here's what matters if you build AI features.
EAA eleven months in: what really changed on Italian sites
The European Accessibility Act has been in force since June 28, 2025. In May 2026 the picture is clearer: few fines, many audits, a few surprises.
NIS3: what's moving in the EU for the next cybersecurity wave
Informal EU Parliament discussions on NIS3. Nothing official, many signals. What they reveal.
One year of NIS2: what we actually learned implementing it
Twelve months after Italian Decree 138/2024 came into force, we walked seven companies through the path. Five things that make the difference, and three that can be skipped.
ESG software for Italian SMEs: what's really needed in 2025
CSRD widens its reach, sustainability demands flow from the supply chain. What we built (and bought) for six clients.
AI Act: what the first general-purpose model compliance looks like
The first rules on foundation models kick in May 2025. What providers, integrators and end-customers must do.
NIS2 in Italy: October 17 is here, and Decree 138/2024 is reality
Italian Decree 138/2024 is now in the Official Gazette. What it operationally means for companies in the NIS2 scope, and what to do in the next 90 days.
WCAG 2.2: AA is not optional (and not hard, either)
WCAG 2.2 has been official since October 2023. With the European Accessibility Act landing in June 2025, AA is a baseline, not a target. Here is what changes.
NIS2: the new EU cybersecurity directive (and why it hits SMEs too)
The NIS2 directive lands in Italy in 2024. The scope is far wider than NIS1: who is affected, what to do, and where to start.
EU AI Act: what the December deal actually contains
After 38 hours of trilogue, on December 8 2023 the political deal landed. What changes for AI builders and users in Europe.
Cookie banners and the Italian DPA: what to fix before 2024
The Italian DPA is again going after non-compliant cookie banners. Between dark patterns, scroll-as-consent and Google Analytics, here are the rules we apply to every client site.