On July 20, 2026, the European Commission (EC) published new Guidelines on Transparency of AI-Generated Content to complement the Code of Practice on Transparency of AI-Generated Content it released on June 10, 2026. The materials arrive just weeks before the AI Act’s transparency obligations take effect on August 2, 2026, and give businesses clearer direction […]
EU Regulators Outline GDPR Requirements for AI Web Scraping
On July 8, 2026, the European Data Protection Board (“EDPB”), the body that coordinates the EU’s national data protection authorities, published its first draft of Guidelines 03/2026 on web scraping in the context of generative AI (the “Guidelines”). The Guidelines address practical compliance challenges for companies that develop AI models or systems and scrape personal […]
European Commission Publishes Draft Guidelines on Classification of High-Risk AI Systems Under the EU AI Act
On May 19, 2026, the European Commission (EC) published draft guidance on how to determine whether an AI system qualifies as a high-risk AI system (HRAIS) under the EU’s Regulation 2024/1689 on artificial intelligence (AI Act). The draft reflects input from stakeholders and EU Member States through the EU AI Board and represents the most […]
Secure Connectivity for Operational Technology—UK NCSC Publishes New Guidance
The UK National Cyber Security Centre (NCSC) published guidance to help organisations design, secure, and manage Operational Technology (OT) environments. It sets out eight core principles to improve resilience, reduce exposure, and support secure architectural decision‑making. The NCSC positions these as goals rather than minimum requirements, and operators of essential services (including those within scope […]
European Commission Publishes Guidance For Companies Implementing the EU Cyber Resilience Act
On December 3, 2025, the European Commission published its first set of technical FAQs on the EU Cyber Resilience Act (‘CRA’). The CRA is an EU-wide law which lays down cybersecurity requirements for ‘products with digital elements’ (‘PDEs’), including IoT devices, hardware components, and certain software. It becomes fully applicable on December 11, 2027, with […]