When your own company’s AI agent is hacked, who is liable for what happens next? This is a question I expect to hear much more often as companies give AI agents access to internal systems, business applications, customer data and, increasingly, the ability to take actions without a human approving every step.
Data Protection & Cybersecurity
Here you can read some articles on Italian and international privacy, cybersecurity and data protection issues drafted by either Giulio Coraggio or the other authors of GamingTechLaw.
28
16
14
07
ENISA’s updated CRA Single Reporting Platform FAQs explain how manufacturers, including gambling operators and supplier, shall report actively exploited vulnerabilities and severe incidents from 11 September 2026, and what companies, including those operating in the gambling sector, need to put in place now to respond within the first 24 hours.
18
A cyber attack during holidays is not a harder technical problem than one in March, it is a harder decision-making problem. The systems fail in the same way, the forensics follow the same method, and the regulatory clocks run at the same speed. What changes is that the people named in the incident response plan are unreachable, the supplier that caused the incident is running on a skeleton crew, and whoever happens to be at the desk usually believes they have no authority to act.
05
The European Commission approved on 27 July 2026 the content of its guidance on the Cyber Resilience Act, which is the most detailed interpretive document published to date on Regulation (EU) 2024/2847. It is formally non-binding, although it sets out the interpretation that market surveillance authorities, notifying authorities and notified bodies are expected to apply across the Union.
30
24
16
13
