Skip to main content
All Insights

Regulatory Compliance.

NIS2, DORA, EU AI Act, and cross-border regulatory exposure for enterprises operating in the EU and US.

Regulatory Compliance·9 min read

Eighteen Days to the CRA's Reporting Gate. The Portal Is Not Live Yet. Your Process Has to Be.

CRA Article 14 reporting becomes mandatory on 11 September 2026. ENISA's Single Reporting Platform is still not publicly live. The companies that will meet a 24-hour clock are the ones that have already run the drill.

Read
Regulatory Compliance·9 min read

EU AI Act Article 50 Is Now in Force. It Is the Deadline That Did Not Move.

Article 50 of the EU AI Act became enforceable on 2 August 2026. The deferral never moved it, and it reaches every customer-facing chatbot and genAI pipeline.

Read
Regulatory Compliance·10 min read

Brussels Stopped Treating AI Governance and Cyber Compliance as Two Programs

On 7 July the Commission published its Cybersecurity and AI Action Plan. On 8 July it asked the Court to fine four member states over NIS2. Read together, they set the direction.

Read
Regulatory Compliance·10 min read

The EU AI Act's August 2 High-Risk Deadline Just Moved. Here Is What Actually Comes Due.

The Digital Omnibus (final Council approval June 29) defers the AI Act's high-risk obligations to 2027 and 2028. But August 2 is not cancelled: transparency rules still land.

Read
Regulatory Compliance·11 min read

The Cyber Resilience Act's First Obligation Gate Arrives 11 September. Most Smaller Product Companies Still Cannot Prove They Are Ready.

The CRA has been binding law since December 2024, but its obligations arrive in phases. The conformity-assessment machinery is being stood up now, and the first reporting deadline is 11 September 2026. For most smaller product companies the gap is not capability. It is evidence.

Read
Regulatory Compliance·16 min read

The EU's Single Entry Point Solves the Regulator's Problem. The Operator Still Needs a Crosswalk.

The proposed Digital Omnibus Regulation would consolidate incident reporting into one ENISA-run portal. The proposal is still in negotiation, and the five underlying regimes do not go away. The work moves upstream, into the controls crosswalk.

Read
Regulatory Compliance·9 min read

The EU's High-Risk AI Filter: Inside the May 2026 Draft Guidelines

On 19 May 2026 the European Commission published draft guidelines clarifying when an AI system is high-risk under Article 6. The exceptions are narrower than the market assumed.

Read
Regulatory Compliance·8 min read

Five Frameworks, One Vendor: How NIS2, DORA, CRA, the Revised CSA, and the EU AI Act Create Cross-Framework Exposure

NIS2, DORA, CRA, the revised CSA, and the EU AI Act each evaluate different dimensions of the same vendor. Running them as separate programs hides cross-framework exposure.

Read
Regulatory Compliance·8 min read

Sweden's Cybersecurity Act (2025:1506): NIS2 Is Now Law

Sweden's Cybersecurity Act (SFS 2025:1506) entered into force on 15 January 2026, shifting cybersecurity obligations to entity-wide scope with explicit management accountability requirements and fines up to €10M.

Read
Subscribe