DORA Exposes Digital Resilience Gaps in EU Finance
DORA has entered its enforcement phase, exposing gaps in ICT risk management, third‑party oversight, and resilience testing across EU financial institutions.
DORA has entered its enforcement phase, exposing gaps in ICT risk management, third‑party oversight, and resilience testing across EU financial institutions.
The EU is advancing a Single Entry Point to centralize security incident reporting across GDPR, NIS2, and other regimes, aiming to reduce complexity while keeping existing legal obligations largely unchanged.
EU policymakers stress that simplifying EU digital laws must preserve strong regulatory interplay between the GDPR, DSA, DMA, and AI rules to ensure consistent enforcement and protect fundamental rights.
The European Parliament has disabled built‑in AI tools on work devices, citing data security and cloud processing risks, underscoring growing institutional caution toward AI use.
The Commission seeks input on a 2026 EU open‑source strategy to reduce digital dependencies, boost competitiveness, and strengthen cybersecurity through coordinated policy and funding measures.
The Commission’s CRA FAQs clarify scope, risk assessments, and overlaps with EU digital laws, helping manufacturers prepare for early reporting in 2026 and full application in 2027.
EU proposal for a Digital Networks Act modernizes connectivity rules, harmonizes spectrum and licensing, mandates copper transition plans, and strengthens security while preserving net neutrality.
The Commission’s CRA implementing regulation clarifies risk‑based categories for products with digital elements, reshaping conformity assessment duties for EU manufacturers.
EU explores legal push to remove Huawei and ZTE from networks Brussels considers binding ban on Chinese telecom vendors Commission weighs enforcement to phase out Huawei and ZTE in EU
EDPS guidance sets technical risk controls for fair, accurate, minimal, and secure AI, stressing interpretability, lifecycle governance, provider transparency, and support for data subject rights.