Cyber Resilience Act: under three weeks to 11 September
In July we explained why the CRA's first binding deadline is 11 September 2026, not 2027. Now time is up: from 11 September the 24 and 72-hour clocks for exploited vulnerabilities start. The final checklist, no theory.
The AI Act's Article 50 is live: what actually changed on 2 August
In July it was a deadline to prepare for, now it is applicable law: from 2 August chatbots, generated content and deepfakes must be disclosed, and on 31 July the Commission confirmed enforcement would begin. What we fixed across client projects in half a day.
Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026
The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.
The AI Act omnibus is law: what slipped and what starts on 2 August
The Digital Omnibus took effect on 27 July and pushes the high-risk rules out to December 2027. Article 50 did not move: from 2 August 2026 chatbots, generated content and deepfakes must be disclosed, and in Italy ACN does the enforcing.
NIS3: what's moving in the EU for the next cybersecurity wave
Informal EU Parliament discussions on NIS3. Nothing official, many signals. What they reveal.
AI Act: what the first general-purpose model compliance looks like
The first rules on foundation models kick in May 2025. What providers, integrators and end-customers must do.
EU AI Act: what the December deal actually contains
After 38 hours of trilogue, on December 8 2023 the political deal landed. What changes for AI builders and users in Europe.