BLOGSEM Devs
Articles on software development, web and technology
Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026
The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.
Your AI vendor can be switched off by a government you do not vote for
On 12 June a US export-control order switched off a frontier model for everyone, everywhere, for eighteen days. What that means for a European SME with a feature in production, and how you actually defend against it.
The AI Act omnibus is law: what slipped and what starts on 2 August
The Digital Omnibus took effect on 27 July and pushes the high-risk rules out to December 2027. Article 50 did not move: from 2 August 2026 chatbots, generated content and deepfakes must be disclosed, and in Italy ACN does the enforcing.
EU AI Act for SMEs: what kicks in during 2026 and what to do now
The EU AI regulation phases in over time. Many SMEs assume it doesn't touch them. Often it does. Here's what matters if you build AI features.
EAA eleven months in: what really changed on Italian sites
The European Accessibility Act has been in force since June 28, 2025. In May 2026 the picture is clearer: few fines, many audits, a few surprises.
NIS3: what's moving in the EU for the next cybersecurity wave
Informal EU Parliament discussions on NIS3. Nothing official, many signals. What they reveal.
One year of NIS2: what we actually learned implementing it
Twelve months after Italian Decree 138/2024 came into force, we walked seven companies through the path. Five things that make the difference, and three that can be skipped.