The Cyber Resilience Act reaches the gambling sector more widely than most operators assume. Downloadable casino and sportsbook clients, mobile applications, gaming cabinets, self-service betting terminals, kiosks and the software supplied with them all qualify as products with digital elements, and the guidance approved by the European Commission on 27 July 2026 removes much of the uncertainty as to where the perimeter runs.
The EU AI Act for gambling operators, suppliers and affiliates has entered its enforcement phase. Since 2 August 2026 the transparency rules of Article 50 apply, the ban on manipulative AI has been biting for well over a year, and the high risk obligations have moved to 2027 and 2028. Each of these changes lands differently on operators, on suppliers and on affiliates, and the analysis below explains how.
Employee email monitoring can expose companies operating in Italy to heavy GDPR fines, even when it uncovers genuine misconduct.
After years of operating in a regulatory grey zone, online casino gambling is now subject to a formal licensing regime in New Zealand. The Online Casino Gambling Act 2026 (the Act) is now in force, and the Department of Internal Affairs (DIA) has opened the first stage of a competitive process to award a strictly limited number of licences.
Privacy class actions in Italy have moved from theory to practice after the Court of Milan admitted the first GDPR representative action — and the international data shows where this leads.
The AI Act transparency obligations finally have their rulebook: on 20 July 2026, the European Commission published the final guidelines on the implementation of Article 50 of the AI Act. Thirteen days before 2 August 2026 when the relevant provisions of the EU AI Act become applicable.
Google gambling advertising on YouTube can now trigger direct liability under the Italian so-called Dignity Decree, after the ECJ ruled that a platform running a revenue‑sharing partnership with its creators loses the hosting safe harbour.
The EDPB web scraping guidelines finally set out how the GDPR applies to the data that trains generative AI — and they raise open questions that could determine whether AI models can still be built in Europe.
