regulation

What’s Driving Cybersecurity Investments and Where Lie the Challenges?

ENISA's NIS Investments report reveals shifts in cybersecurity spending towards technology over personnel, with ongoing talent shortages. Compliance drives 70% of investments, improving risk management and detection, though NIS2 implementation poses challenges. Patching and cybersecurity assessments lag, particularly for SMEs. Despite improved supply chain management, reliance on third-party services increases risks. Ransomware and supply-chain attacks are primary concerns for organizations. The findings aim to inform EU cybersecurity policy and improve resilience.

https://www.enisa.europa.eu/news/whats-driving-cybersecurity-investments-and-where-lie-the-challenges

US, Allies Urge Critical Infrastructure Operators to Carefully Plan and Oversee AI Use

US and allies issue guidance for critical infrastructure operators on safe AI integration, emphasizing risk assessment, governance, and operational safety protocols. They stress employee education, clear AI use procedures, continuous validation, and human oversight to mitigate AI risks in existing systems.

https://www.cybersecuritydive.com/news/ai-critical-infrastructure-government-guidance/807052/

The Cybersecurity And Resilience Bill Is Coming. Here’s What It Means

UK's Cyber Security and Resilience Bill introduced in November aims to enhance cyber defenses for essential services amid rising cyberattacks. It updates 2018 NIS regulations and imposes new reporting duties with stricter penalties. Broader scope includes managed service providers and critical suppliers. Implementation phases are planned post-approval, mandating organizations to assess compliance and strengthen cyber risk management before laws take effect.

https://insight.scmagazineuk.com/the-cybersecurity-and-resilience-bill-is-coming-heres-what-it-means

NIS2: Much Needed, but Also More Work Pressure

NIS2 Directive increases cybersecurity resilience in the Netherlands, requiring organizations to manage supplier risks. While essential, it imposes administrative burdens on clients and suppliers, potentially exceeding their readiness by the 2026 deadline. Preparing involves suppliers standardizing security documentation and clients assessing supplier risks.

https://ioplus.nl/en/posts/nis2-much-needed-but-also-more-work-pressure

A 2026 Regulatory Survival Guide for the Channel

2026 brings key regulatory deadlines affecting the AIDC sector in food, pharma, and manufacturing. FSMA 204’s food traceability deadline is likely delayed, but large companies still require traceability systems. The EU’s Digital Product Passport launches for batteries, with future expansions planned, while DPP and DSCSA both require advanced data capture and 2D scanning. The EU Deforestation Regulation’s deadline is now December 2026, demanding GPS data capture for supply sourcing. The Cyber Resilience Act’s reporting requirements start in September 2026, requiring rapid vulnerability disclosures. Providers need to audit software for necessary data fields, refresh clients’ scanning hardware, and focus on delivering audit-ready solutions.

https://www.devprojournal.com/software-development-trends/compliance/a-2026-regulatory-survival-guide-for-the-channel/

The Digital Omnibus: Deregulation Dressed as Innovation

EU's Digital Omnibus loosens data and AI safeguards for workers under the guise of fostering innovation, benefiting mainly US tech giants. It consolidates data laws but lacks serious impact assessments, weakening protections and oversight for workers in AI-dominated workplaces. Changes to GDPR and AI regulations allow employers greater control over personal data, limiting workers' rights to transparency and resistance against automated decisions, while reducing oversight and AI literacy obligations. Overall, the document argues that the Omnibus prioritizes competitiveness over worker protections, shifting risks onto vulnerable users.

https://www.socialeurope.eu/the-digital-omnibus-deregulation-dressed-as-innovation

Europe’s Digital Sovereignty Hinges on Smarter Regulation for Data Access

Extreme TLDR: Europe’s digital sovereignty depends on smarter data regulation amid market concentration in AI. Simplifying regulation fails to support new tech entrants, as access to data is key for competitiveness. A proposed European Data Commons could enhance access and legal clarity for start-ups while ensuring compensation for content creators, thus fostering innovation without losing regulatory ambition.

https://www.techpolicy.press/europes-digital-sovereignty-hinges-on-smarter-regulation-for-data-access/

‘Pure Regulatory Chaos’: Move to Help Europe Win Artificial Intelligence Race Misfires

The European Commission has delayed final AI Act rules meant to regulate high-risk AI systems, following pressure from industry. This delay creates significant uncertainty, as required legislative changes may not be completed before the current August 2026 deadline. If lawmakers miss this deadline, confusing legal gaps could arise. The pause could last up to 16 months, but may end sooner, leaving businesses unsure about planning and compliance. Companies and experts describe the situation as chaotic, with some pausing compliance work while others press on. The result is widespread criticism that this uncertainty undermines legal stability and Europe’s tech competitiveness.

https://www.politico.eu/article/eu-ai-race-tech-legal-mess-build-legislators/

Scroll to Top