Blog

EU Launches AI Strategies to Boost Competitiveness and Science

EU launches AI strategies to enhance competitiveness and innovation. The Apply AI strategy aims to integrate AI across sectors, while the AI in Science strategy promotes AI's scientific development. Key initiatives include an AI toolbox for public services, an €1 billion funding commitment, and the establishment of the Resource for AI Science in Europe (Raise). The goal is to increase AI adoption from 13.5% to 75% by 2030, support SMEs, and enhance research capabilities.

https://sciencebusiness.net/news/ai/eu-launches-ai-strategies-boost-competitiveness-and-science

Responding to Cloud Incidents: a Step-by-Step Guide From the 2025 Unit 42 Global Incident Response Report

Cloud incidents are increasing and require specific investigation methods focused on cloud assets, identities, and configurations rather than traditional endpoints. Unit 42’s recommended response process includes the following steps:

Scope and Mindset for Cloud Investigations

  • 29% of incidents in 2024 involved cloud or SaaS environments.
  • Cloud investigations prioritize identities, misconfigurations, and service interactions.

Step 1: Triage and Scoping

  • Establish event timeline and detect abnormal activity.
  • Identify affected assets (VMs, IAM, storage, containers).
  • Address logging gaps—enable and retain logs for at least 90 days.

Step 2: Evidence Collection

  • Collect audit/resource logs, VM/container snapshots.
  • Capture volatile artifacts quickly as cloud environments are ephemeral.

Step 3: Identity and Role Forensics

  • Investigate IAM settings, login patterns, escalation attempts.
  • Watch for identity hopping and privilege misuse.

Step 4: Lateral Movement and Persistence

  • Detect movement across regions/services using existing credentials.
  • Use behavioral baselining to spot anomalies, not just failed logins.

Step 5: Containment, Eradication, Recovery

  • Contain compromised assets quickly without alerting attackers.
  • Remove persistence, rotate credentials, and validate remediation.
  • Restore operations, patch vulnerabilities, and monitor for follow-up attacks.

Recommendations

  • Centralize logs, develop IR playbooks, and prepare forensic sandboxes.
  • Institutionalize lessons learned to improve future incident response.
  • Adopt zero trust principles and use specialized security assessments and retainers for support.

https://unit42.paloaltonetworks.com/responding-to-cloud-incidents/

Employees Regularly Paste Company Secrets Into ChatGPT

TLDR

Employees risk data security by sharing sensitive information with ChatGPT, with 45% using generative AI tools and 22% pasting PII/PCI data. This raises compliance and data leakage concerns, as 82% of data shared is from unmanaged accounts. ChatGPT leads AI adoption in enterprises at 43%, while Microsoft Copilot sees low usage (2%). Security measures like enforced Single Sign-On are essential to mitigate risks.

https://www.theregister.com/2025/10/07/gen_ai_shadow_it_secrets/

Seeing Like a Software Company

Extreme TLDR: Organizations prioritize legibility to facilitate tracking and planning, often at the cost of efficiency. This leads to a reliance on both legible (structured, measurable) and illegible (informal, untrackable) work. While small software companies thrive on illegibility for rapid delivery, large companies persist with legibility for benefits like enterprise deal-making, despite inefficiencies. This creates friction between those exploiting illegibility and those adhering to formal processes, highlighting the dual nature of work in tech companies.

https://www.seangoedecke.com/seeing-like-a-software-company/

Is the CISO Chair Becoming a Revolving Door?

The post highlights CISO tenure issues with average roles lasting three years due to stress, burnout, and liability. Larger organizations retain CISOs longer due to resources, while startups experience high turnover. Communication skills are crucial for success, with some CISOs opting for fractional roles or pivoting careers, indicating diverse motivations behind tenure changes.

https://www.csoonline.com/article/4066101/is-the-ciso-chair-becoming-a-revolving-door.html

Cloud Compliance Requirements: What You Need to Know

Cloud compliance is becoming a strategic necessity for businesses operating in multiple regions and sectors. Major regulations, such as GDPR, HIPAA, and PCI DSS, dictate how data is handled, driving system design and vendor selection. Non-compliance can result in severe fines, delayed launches, reputational damage, or even loss of market access. Certifications such as ISO 27001, SOC 2, and FedRAMP are increasingly prerequisites for customer and partner trust, while frameworks like NIST and CIS help ensure daily operational discipline. To keep pace with evolving laws surrounding privacy, AI risk, digital sovereignty, and industry-specific requirements, organizations must integrate compliance into their core cloud strategy, adopt ongoing monitoring, and ensure leadership remains directly involved. This approach turns compliance from a defensive burden into a competitive advantage and a key proof of enterprise readiness.

https://appinventiv.com/blog/cloud-regulatory-compliances-guide/

Are We Paying Enough Attention to the AI Risks?

KPMG Legal Reimagined outlines the primary legal, regulatory, and ethical risks associated with organizations utilizing AI. Key themes and takeaways:

  • Regulatory Landscape: Laws vary; the EU has the AI Act with strict requirements, while the UK is using decentralized, principle-based oversight.
  • Ethical Considerations: Focus on transparency, explainability, bias, and fairness. Ethics boards are used to oversee these issues.
  • Third-Party Risk: AI risk extends to suppliers; due diligence and contracts are vital.
  • Data Protection: Personal data must always comply with laws like GDPR; clear privacy notices are mandated.
  • AI and Copyright: Tension exists between using AI and creative industries’ rights; guidelines limit how legal data and generative AI can be used.
  • Pace of Change: Rapid AI advancements challenge legal professionals to keep up with new technologies and laws.
  • Opportunities for Legal Teams: AI can improve legal workflows and create new skill needs; leaders should plan for evolving roles and tech adoption.

https://kpmg.com/se/en/insights/newsletters/legal-reimagined/2025/are-we-paying-enough-attention-to-the-ai-risks.html

How AI-Powered Emotional Surveillance Can Threaten Personal Autonomy and Democracy

AI emotional surveillance threatens personal autonomy and democracy, with applications in education, border control, and public safety raising privacy concerns. These technologies analyze emotions through facial expressions and physiological cues, risking manipulation and coercion. Current regulations, like the EU AI Act, inadequately address these issues, leaving legal gaps that could undermine individual freedoms. Without proper oversight, emotional surveillance may lead to a society where self-expression is suppressed, jeopardizing democratic values and autonomy.

https://www.techpolicy.press/how-ai-powered-emotional-surveillance-can-threaten-personal-autonomy-and-democracy/

EU Commission to Unveil Its New Sectoral AI Uptake Strategy

EU Commission unveils AI strategy on Oct 8, 2025, promoting ‘AI-first' approach in various sectors. Aims include enhancing productivity, supporting SMEs, and establishing partnerships. Key initiatives target healthcare, manufacturing, public sector, and more, with a focus on training and compliance under the AI Act. EU seeks to ensure competitiveness and foster growth in AI-driven industries.

https://euobserver.com/eu-and-the-world/ar178848e4

European Approach to Artificial Intelligence

EU's official site emphasizes AI strategies focusing on excellence, trust, and safety. Goals include making Europe a world-leading AI hub, encouraging adoption in key sectors, and safeguarding fundamental rights. The AI Continent Action Plan and Apply AI Strategy aim to enhance competitiveness and innovation in AI, especially for SMEs. Legal frameworks like the AI Act ensure safety while the EU invests in AI development to foster a robust, trustworthy ecosystem. Key initiatives, partnerships, and milestones aim to coordinate efforts and improve AI's societal benefits across Europe.

https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence

Scroll to Top