regulation

EU AI Act Shock: Emotion Recognition Is Now Illegal at Work. So Why Is Your Vendor Still Selling It?

The EU AI Act, effective since February 2025, has made emotion recognition AI in the workplace illegal across the European Union, imposing fines up to €35 million or 7% of global turnover for violations. Despite this, many vendors continue to sell and deploy such technology unlawfully, risking significant penalties, while the law strictly prohibits AI systems that infer employee emotions from biometric data but allows text-only sentiment analysis. Organizations using UC, CX, or employee experience software in Europe are urged to urgently verify vendor compliance and disable prohibited features to avoid imminent enforcement actions.

https://www.uctoday.com/workplace-management/eu-ai-act-shock-emotion-recognition-is-now-illegal-at-work-so-why-is-your-vendor-still-selling-it/

Time for Government, Business Leaders to Figure Out AI Cybersecurity Regulation

Cybersecurity experts warn that the rising capabilities of agentic AI, while useful for combating cybercrime, also pose significant risks as bad actors use AI to exploit vulnerabilities, threatening personal data, the economy, and national security. They emphasize the urgent need for government and business leaders to establish clear AI cybersecurity regulations, balancing innovation with liability and prevention, to better protect against increasingly sophisticated AI-enabled cyberattacks such as phishing and software breaches.

https://news.harvard.edu/gazette/story/2026/04/time-for-government-business-leaders-to-figure-out-ai-cybersecurity-regulation/

The EU’s AI Act: Do You Have the Knowledge to Comply?

The article highlights a critical compliance challenge posed by the EU AI Act, effective from August 2, 2026, for enterprises using AI-driven marketing automation workflows. It warns that while strategic AI governance often exists at the leadership level, many operational AI systems—like customer scoring models and data enrichment flows—are undocumented and lack clear ownership, putting organizations at risk of non-compliance under the Act’s transparency, documentation, and human oversight requirements.

https://www.business-reporter.co.uk/ai–automation/the-eus-ai-act-do-you-have-the-knowledge-to-comply

EU AI Act Compliance: a Technical Audit Guide for the 2026 Deadline

With the August 2026 deadline for the EU AI Act approaching, IT leaders must shift from policy to practical compliance by mapping AI tools across APIs, legacy systems, and model integrations to ensure auditable governance. Organisations need to build comprehensive API inventories, implement continuous monitoring systems, categorise AI endpoints by risk, and rigorously audit high-risk legacy systems for transparency, human oversight, and bias mitigation to meet the stringent regulatory requirements and avoid significant fines and reputational damage.

https://www.raconteur.net/global-business/eu-ai-act-compliance-a-technical-audit-guide-for-the-2026-deadline

EUDR in Practice: How to Correctly Set Up Due Diligence in the Supply Chain

The EU Deforestation Regulation (EUDR) establishes new due diligence requirements for companies dealing with certain commodities, mandating proof that products comply with EUDR and are deforestation-free before entering or leaving the EU market. Companies must collect detailed supply chain information, assess risks, implement mitigation measures if necessary, submit a Due Diligence Statement, maintain an internal due diligence system, and retain documentation for inspections.

https://www.grantthornton.cz/en/news/eudr-in-practice-how-to-correctly-set-up-due-diligence-in-the-supply-chain/

Focus Areas When Implementing Data Protection by Design and by Default in 2026

Data protection by design and by default, a key principle of the EU GDPR, remains inconsistently implemented nearly a decade after its adoption, requiring organizations to consider four main factors—state of the art, cost of implementation, processing context, and risks to individuals—for effective compliance. In 2026, evolving technologies and regulations, especially concerning AI, demand a dynamic, risk-based approach that integrates ongoing assessment and adaptation of technical and organizational measures from the system design stage through deployment to safeguard personal data and uphold individuals' rights.

https://iapp.org/news/a/focus-areas-when-implementing-data-protection-by-design-and-by-default-in-2026

We Are All AI Philosophers Now

The article emphasizes that AI systems inherently carry the biases and values of their creators through design choices, data, and policy decisions, meaning AI is never truly neutral. It calls on IT leaders to recognize that adopting AI is a governance decision that requires disciplined oversight, transparency, and accountability to manage risks and ensure AI-driven decisions align with organizational and societal values.

https://www.cio.com/article/4145026/we-are-all-ai-philosophers-now.html

Autonomous AI Agents and the GDPR: First Detailed Spanish Regulatory Guidance Sets the Bar

The Spanish Data Protection Agency (AEPD) has published the first detailed regulatory guidance on autonomous AI agents under the GDPR, addressing challenges posed by AI systems that independently plan, reason, and execute tasks with limited human oversight. This guidance highlights critical compliance issues, including defining controller and processor roles, transparency obligations, data minimization, automated decision-making risks, and the need for thorough risk assessments, setting a precedent that extends beyond Spain and is relevant for all organizations deploying agentic AI in personal data processing.

https://technologyquotient.freshfields.com/post/102mmys/autonomous-ai-agents-and-the-gdpr-first-detailed-spanish-regulatory-guidance-set

Cybersecurity: New Cyber Strategy; Cybercrime Executive Order

KPMG's new Cyber Strategy outlines long-term federal cybersecurity policies focusing on national security and economic competitiveness, with an emphasis on coordinated public-private efforts. The accompanying Executive Order targets immediate actions against cybercrime, particularly driven by transnational criminal organizations. Key points include interagency coordination, public-private collaboration, enforcement measures, and international engagement. Organizations must enhance their cybersecurity programs to address evolving threats, aligned with established frameworks.

https://kpmg.com/us/en/articles/2026/cybersecurity-new-cyber-strategy-cybercrime-executive-order-reg-alert.html

Cyber Enforcement – When an Incident Is Just the Tip of the Iceberg

The article explains that recent UK enforcement trends show cyber incidents often expose broader compliance failures, making the reported breach only the starting point for regulatory scrutiny. Regulators increasingly focus on security weaknesses, governance gaps, and data-handling practices across the organization, especially after cyberattacks. Fines have risen, and enforcement actions target private-sector companies with inadequate safeguards. The article concludes that organizations must treat cyber resilience, contractual risk allocation, and data protection controls as ongoing obligations because investigations can extend beyond the original incident to encompass broader operational and legal failings. 

https://www.slaughterandmay.com/insights/new-insights/cyber-enforcement-when-an-incident-is-just-the-tip-of-the-iceberg/

Scroll to Top