TopicSEM Devs

compliance

16 articles on this topic

← Back to blog
cracompliancesicurezza

Cyber Resilience Act: under three weeks to 11 September

In July we explained why the CRA's first binding deadline is 11 September 2026, not 2027. Now time is up: from 11 September the 24 and 72-hour clocks for exploited vulnerabilities start. The final checklist, no theory.

2 min read
ai-actcomplianceai

The AI Act's Article 50 is live: what actually changed on 2 August

In July it was a deadline to prepare for, now it is applicable law: from 2 August chatbots, generated content and deepfakes must be disclosed, and on 31 July the Commission confirmed enforcement would begin. What we fixed across client projects in half a day.

3 min read
cracompliancesicurezza

Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026

The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.

3 min read
aisovranita-digitalerisk-management

Your AI vendor can be switched off by a government you do not vote for

On 12 June a US export-control order switched off a frontier model for everyone, everywhere, for eighteen days. What that means for a European SME with a feature in production, and how you actually defend against it.

3 min read
ai-actcomplianceai

The AI Act omnibus is law: what slipped and what starts on 2 August

The Digital Omnibus took effect on 27 July and pushes the high-risk rules out to December 2027. Article 50 did not move: from 2 August 2026 chatbots, generated content and deepfakes must be disclosed, and in Italy ACN does the enforcing.

3 min read
ai-actcomplianceai

EU AI Act for SMEs: what kicks in during 2026 and what to do now

The EU AI regulation phases in over time. Many SMEs assume it doesn't touch them. Often it does. Here's what matters if you build AI features.

3 min read
accessibilityeaacompliance

EAA eleven months in: what really changed on Italian sites

The European Accessibility Act has been in force since June 28, 2025. In May 2026 the picture is clearer: few fines, many audits, a few surprises.

2 min read
nis3compliancecybersecurity

NIS3: what's moving in the EU for the next cybersecurity wave

Informal EU Parliament discussions on NIS3. Nothing official, many signals. What they reveal.

2 min read
nis2sicurezzacompliance

One year of NIS2: what we actually learned implementing it

Twelve months after Italian Decree 138/2024 came into force, we walked seven companies through the path. Five things that make the difference, and three that can be skipped.

3 min read
esgcsrdsostenibilità

ESG software for Italian SMEs: what's really needed in 2025

CSRD widens its reach, sustainability demands flow from the supply chain. What we built (and bought) for six clients.

2 min read
ai-actcomplianceai

AI Act: what the first general-purpose model compliance looks like

The first rules on foundation models kick in May 2025. What providers, integrators and end-customers must do.

2 min read
nis2sicurezzacompliance

NIS2 in Italy: October 17 is here, and Decree 138/2024 is reality

Italian Decree 138/2024 is now in the Official Gazette. What it operationally means for companies in the NIS2 scope, and what to do in the next 90 days.

2 min read
accessibilitywcageaa

WCAG 2.2: AA is not optional (and not hard, either)

WCAG 2.2 has been official since October 2023. With the European Accessibility Act landing in June 2025, AA is a baseline, not a target. Here is what changes.

2 min read
nis2sicurezzacompliance

NIS2: the new EU cybersecurity directive (and why it hits SMEs too)

The NIS2 directive lands in Italy in 2024. The scope is far wider than NIS1: who is affected, what to do, and where to start.

2 min read
ai-actcomplianceai

EU AI Act: what the December deal actually contains

After 38 hours of trilogue, on December 8 2023 the political deal landed. What changes for AI builders and users in Europe.

2 min read
gdprcomplianceprivacy

Cookie banners and the Italian DPA: what to fix before 2024

The Italian DPA is again going after non-compliant cookie banners. Between dark patterns, scroll-as-consent and Google Analytics, here are the rules we apply to every client site.

2 min read