Tech Law & AI Regulation Curator

EU AI Act, cyber resilience, and cloud-security implementation

EU AI Act, cyber resilience, and cloud-security implementation

Key Questions

What key changes do the March 2026 EU AI Act amendments introduce?

The amendments expand requirements around transparency, metadata, bias, and watermarking for AI systems. They also include new draft guidelines on high-risk AI classification covering agentic AI and safety components.

What obligations does the new EU Code of Practice on AI-generated content labelling impose?

Effective August 2026, the Code sets provider and deployer obligations for labelling AI-generated content. It addresses fine-tuning as a grey area while aiming to improve transparency for users.

What topics were covered at the CPDP 2026 panel on AI Act implementation?

The panel discussed simplification of rules, geopolitical tensions, and regulatory sovereignty issues. It highlighted challenges in implementing the AI Act amid evolving global dynamics.

GPAI and Article 50 transparency obligations remain operational alongside Commission guidance and AI-generated-content labelling work. CRA reporting requires 24-hour, 72-hour, 14-day, and one-month workflows, while CISA/NIST guidance addresses cloud identity-token theft and CISA cyber-decoy deployment; organizations must coordinate these controls with NIS2, GDPR, and incident-governance requirements.

Sources (4)
Updated Sep 19, 2026