The Italian Administrative Supreme Court, the Consiglio di Stato, has changed the regulatory framework for gambling top-up shops in Italy, known as Punti Vendita Ricariche or PVRs.
When your own company’s AI agent is hacked, who is liable for what happens next? This is a question I expect to hear much more often as companies give AI agents access to internal systems, business applications, customer data and, increasingly, the ability to take actions without a human approving every step.
Gambling advertising in Italy remains one of the most closely regulated areas of the country's gambling market. The recent approval of the so-called Decree Accise by the Italian Senate has brought the issue back into focus, particularly because Parliament considered, and rejected, proposals that would have extended the rules to a much wider range of promotional activities.
A data breach caused by an AI agent has now been notified for the first time to a European data protection authority, with the Spanish AEPD receiving the first notification of a personal data breach allegedly carried out using an AI agent.
AI criminal liability is no longer a question of how much a fine would cost, it is a question of who signs off on a system and what happens to that person, and to the company, if the system causes harm.
GDPR data subject rights are becoming a significant enforcement risk for companies, even a single complaint can lead to large fines if it reveals weaknesses in the way personal data is managed across different systems, teams and business processes.
Italian responsible gambling campaigns now have a rulebook and might represent an opportunity for operators to show their brands in highly regulated market which requires a tailored approach.
AI Act investigations have begun, with the European Commission using its enforcement powers for the first time to order leading AI developers to detail their practices on cybersecurity, safety and copyright through information requests.
