Skip to main content
All Insights

Regulatory Compliance.

NIS2, DORA, EU AI Act, and cross-border regulatory exposure for enterprises operating in the EU and US.

Regulatory Compliance·10 min read

Brussels Stopped Treating AI Governance and Cyber Compliance as Two Programs

On 7 July the Commission published its Cybersecurity and AI Action Plan. On 8 July it asked the Court to fine four member states over NIS2. Read together, they set the direction.

Read
Regulatory Compliance·10 min read

The EU AI Act's August 2 High-Risk Deadline Just Moved. Here Is What Actually Comes Due.

The Digital Omnibus (final Council approval June 29) defers the AI Act's high-risk obligations to 2027 and 2028. But August 2 is not cancelled: transparency rules still land.

Read
Regulatory Compliance·11 min read

The Cyber Resilience Act's First Obligation Gate Is 90 Days Away. Most Smaller Product Companies Still Cannot Prove They Are Ready.

The CRA has been binding law since December 2024, but its obligations arrive in phases. This week the conformity-assessment machinery switched on. The first reporting deadline is 11 September 2026. For most smaller product companies the gap is not capability. It is evidence.

Read
Regulatory Compliance·16 min read

The EU's Single Entry Point Solves the Regulator's Problem. The Operator Still Needs a Crosswalk.

The proposed Digital Omnibus Regulation would consolidate incident reporting into one ENISA-run portal. The proposal is still in negotiation, and the five underlying regimes do not go away. The work moves upstream, into the controls crosswalk.

Read
Regulatory Compliance·9 min read

The EU's High-Risk AI Filter: Inside the May 2026 Draft Guidelines

On 19 May 2026 the European Commission published draft guidelines clarifying when an AI system is high-risk under Article 6. The exceptions are narrower than the market assumed.

Read
Regulatory Compliance·8 min read

Five Frameworks, One Vendor: How NIS2, DORA, CRA, the Revised CSA, and the EU AI Act Create Cross-Framework Exposure

NIS2, DORA, CRA, the revised CSA, and the EU AI Act each evaluate different dimensions of the same vendor. Running them as separate programs hides cross-framework exposure.

Read
Regulatory Compliance·8 min read

Sweden's Cybersecurity Act (2025:1506): NIS2 Is Now Law

Sweden's Cybersecurity Act (SFS 2025:1506) entered into force on 15 January 2026, shifting cybersecurity obligations to entity-wide scope with explicit management accountability requirements and fines up to €10M.

Read
Subscribe