regulation

Italy Enacts First National AI Law in Europe: What Employers and Businesses Need to Know

Italy has enacted its first national AI law, effective October 10, 2025, complementing the EU AI Act. The law emphasizes principles of transparency, accountability, and human oversight in AI, clarifying that AI must support rather than replace human decisions. It mandates disclosure to employees when AI is used in hiring and performance evaluation, and enforces data protection aligned with GDPR. It allows pseudonymized data for research under safeguards, penalizes AI-generated deepfakes, and restricts data mining for copyright compliance. Implementing decrees are expected within a year, requiring businesses to adapt governance frameworks and ensure compliance.

https://www.fisherphillips.com/en/news-insights/italy-enacts-first-national-ai-law-in-europe.html

Compliance Isn’t an Annual Ritual Anymore

In 2025, IT compliance is increasingly critical due to new regulations and updates, indicating IT's maturation akin to other regulated industries. The concept of “CompOps” (Compliance Operations) is evolving to ensure continuous compliance rather than annual audits, necessitating more frequent evidence collection. Organizations must adapt by embedding compliance practices within DevOps processes, focusing on collaboration and communication to meet evolving standards efficiently. The future involves integrating compliance into everyday operations, shifting the perception from an annual chore to a continuous effort essential for business function.

https://securityboulevard.com/2025/10/compliance-isnt-an-annual-ritual-anymore/

EU AI Act – Frequently Asked Questions

EU AI Act is world's first comprehensive AI law promoting innovation and protecting health, safety, and rights. It categorizes AI systems by risk, with compliance phased in by 2027. High-risk systems face stringent obligations; unacceptable risks are prohibited. The Act emphasizes transparency, human oversight, and adapts to technological changes. Support exists for SMEs, ensuring streamlined processes and reduced burdens. AI literacy is critical for compliance. The Act addresses various areas like biometric data and outlines specific prohibitions, ensuring responsible AI use.

https://ai-act-service-desk.ec.europa.eu/en/faq

Interaction of the GDPR and the EU Data Act

Summary: The GDPR and the EU Data Act are laws impacting data sharing and privacy. The GDPR focuses on personal data protection, while the Data Act aims to enhance data accessibility and sharing. Their overlapping scopes create compliance challenges, especially when determining lawful bases for processing personal data within generated data. Cloud service providers and data holders must navigate these complexities to align their practices and documentation with both laws, ensuring accountability and legal compliance.

https://www.taylorwessing.com/en/global-data-hub/2025/eu-digital-laws-and-gdpr/gdh—interaction-of-the-gdpr-and-the-eu-data-act

EU Commission to Unveil Its New Sectoral AI Uptake Strategy

EU Commission unveils AI strategy on Oct 8, 2025, promoting ‘AI-first' approach in various sectors. Aims include enhancing productivity, supporting SMEs, and establishing partnerships. Key initiatives target healthcare, manufacturing, public sector, and more, with a focus on training and compliance under the AI Act. EU seeks to ensure competitiveness and foster growth in AI-driven industries.

https://euobserver.com/eu-and-the-world/ar178848e4

European Approach to Artificial Intelligence

EU's official site emphasizes AI strategies focusing on excellence, trust, and safety. Goals include making Europe a world-leading AI hub, encouraging adoption in key sectors, and safeguarding fundamental rights. The AI Continent Action Plan and Apply AI Strategy aim to enhance competitiveness and innovation in AI, especially for SMEs. Legal frameworks like the AI Act ensure safety while the EU invests in AI development to foster a robust, trustworthy ecosystem. Key initiatives, partnerships, and milestones aim to coordinate efforts and improve AI's societal benefits across Europe.

https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence

CIISec: Most Security Professionals Want Stricter Regulations

69% of security professionals want stricter cybersecurity laws, per a CIISec survey. Major regulations like the Cyber Security and Resilience Bill make senior management liable for breaches. 91% believe boards should be accountable for incidents. The UK plans to ban ransomware payments for certain sectors and enforce mandatory incident reporting.

https://www.infosecurity-magazine.com/news/ciisec-security-professionals/

AI FAQ Series

AI regulation encompasses laws and guidelines for AI development, ensuring safety, ethics, and privacy. Pre-existing and specific laws govern AI use, including the EU AI Act. States are enacting AI laws on ownership, liability, and biases. Ethical responsibilities involve transparency, accountability, and bias mitigation. Compliance requires explaining AI processes and integrating human oversight. Privacy laws impact AI data handling and deletion requests. Ongoing lawsuits may affect AI deployment and liability, necessitating alignment with legal developments.

https://www.orrick.com/en/Insights/2025/08/AI-Regulation-Are-There-Regulations-on-AI-AI-FAQ-Series

Taking the EU AI Act to Practice How the Final GPAI Guidelines Shape the AI Regulatory Landscape

EU AI Act provides regulatory framework for General-Purpose AI (GPAI), clarifying definitions, obligations, and classifications, effective August 2025. Guidelines outline criteria for GPAI models, notably computational thresholds and output modalities. Compliance includes self-assessment, notification procedures, and challenges against classifications. The act covers market implications, model lifecycle responsibilities, and exemptions for open-source models. Key deadlines include conformity by 2027 and enforcement starting 2026.

https://www.twobirds.com/en/insights/2025/taking-the-eu-ai-act-to-practice-how-the-final-gpai-guidelines-shape-the-ai-regulatory-landscape

What the EU AI Act Means for US Tech Companies

EU AI Act, effective Aug 2026, regulates AI, affecting US tech firms in Europe. It classifies AI into four risk categories with varying compliance obligations. High-risk AI requires extensive documentation; firms must prepare proactively. Phenom, a compliant startup, emphasizes early adaptation and client education for success. Non-compliance poses significant risks, necessitating awareness and preparation.

https://technical.ly/civics/how-to-comply-eu-ai-act-guest-post/

Scroll to Top