AI criminal liability is no longer a question of how much a fine would cost, it is a question of who signs off on a system and what happens to that person, and to the company, if the system causes harm.
A cyber attack during holidays is not a harder technical problem than one in March, it is a harder decision-making problem. The systems fail in the same way, the forensics follow the same method, and the regulatory clocks run at the same speed. What changes is that the people named in the incident response plan are unreachable, the supplier that caused the incident is running on a skeleton crew, and whoever happens to be at the desk usually believes they have no authority to act.
The Cyber Resilience Act reaches the gambling sector more widely than most operators assume. Downloadable casino and sportsbook clients, mobile applications, gaming cabinets, self-service betting terminals, kiosks and the software supplied with them all qualify as products with digital elements, and the guidance approved by the European Commission on 27 July 2026 removes much of the uncertainty as to where the perimeter runs.
The EU AI Act for gambling operators, suppliers and affiliates has entered its enforcement phase. Since 2 August 2026 the transparency rules of Article 50 apply, the ban on manipulative AI has been biting for well over a year, and the high risk obligations have moved to 2027 and 2028. Each of these changes lands differently on operators, on suppliers and on affiliates, and the analysis below explains how.
Employee email monitoring can expose companies operating in Italy to heavy GDPR fines, even when it uncovers genuine misconduct.
After years of operating in a regulatory grey zone, online casino gambling is now subject to a formal licensing regime in New Zealand. The Online Casino Gambling Act 2026 (the Act) is now in force, and the Department of Internal Affairs (DIA) has opened the first stage of a competitive process to award a strictly limited number of licences.
Privacy class actions in Italy have moved from theory to practice after the Court of Milan admitted the first GDPR representative action — and the international data shows where this leads.
The AI Act transparency obligations finally have their rulebook: on 20 July 2026, the European Commission published the final guidelines on the implementation of Article 50 of the AI Act. Thirteen days before 2 August 2026 when the relevant provisions of the EU AI Act become applicable.
