GDPR data subject rights are becoming a significant enforcement risk for companies, even a single complaint can lead to large fines if it reveals weaknesses in the way personal data is managed across different systems, teams and business processes.
AI Act investigations have begun, with the European Commission using its enforcement powers for the first time to order leading AI developers to detail their practices on cybersecurity, safety and copyright through information requests.
The Data Act access by design obligation becomes applicable on 12 September 2026 to connected products and related services placed on the market after that date.
A cyber attack during holidays is not a harder technical problem than one in March, it is a harder decision-making problem. The systems fail in the same way, the forensics follow the same method, and the regulatory clocks run at the same speed. What changes is that the people named in the incident response plan are unreachable, the supplier that caused the incident is running on a skeleton crew, and whoever happens to be at the desk usually believes they have no authority to act.
The Cyber Resilience Act reaches the gambling sector more widely than most operators assume. Downloadable casino and sportsbook clients, mobile applications, gaming cabinets, self-service betting terminals, kiosks and the software supplied with them all qualify as products with digital elements, and the guidance approved by the European Commission on 27 July 2026 removes much of the uncertainty as to where the perimeter runs.
The AI Act transparency obligations finally have their rulebook: on 20 July 2026, the European Commission published the final guidelines on the implementation of Article 50 of the AI Act. Thirteen days before 2 August 2026 when the relevant provisions of the EU AI Act become applicable.
