The Spanish draft law transposing NIS2 is still in parliament in 2026, but the directive's technical obligations have applied since October 2024. Practical map: the ten minimum security measures, the 24-hour, 72-hour and one-month incident notification window, and the new supply-chain security obligations.
After two years of pilots and a year of agents in production, governance has moved from an aspirational committee to an operational control. What audits ask for, what broke in 2025, and which guardrails absorb most incidents.
The European AI Act took effect on 1 August 2024 with a staggered calendar, and its Annex III high-risk rules no longer land in August 2026. The Digital Omnibus, closed by the Parliament and the Council, moves that deadline 17 months to 2 December 2027. Prohibitions since February 2025 and general-purpose AI duties since August 2025 still apply.
The European Accessibility Act became enforceable on 28 June 2025, and the first six months produced sanction files in Spain, Germany and the Netherlands along with several forced mass-remediation projects. Directive 2019/882 covers consumer-facing products and services, and the technical bar regulators apply is EN 301 549, which takes WCAG 2.1 level AA as its baseline.
Accessibility overlays were sold as a magic fix for WCAG and the European EAA directive in one step. In 2025 lawsuits against them have grown and disabled users are speaking out more critically than ever. A look at why they fail and what to do instead.
Since 2 August 2025 the EU AI Act obligations for general-purpose models, national authorities, and the penalty regime are enforceable. A practical look at what changes for those of us deploying AI in Europe.
NIS2 entered force on 17 October 2024. Six months later, companies are in the trenches. I cover what has actually changed in operational security, what was paper theater, and where the directive still bites.
AI governance in a company means a standing committee, written policies, a model and use-case inventory, risk assessment, and audits. The first provisions of the EU AI Act took effect on 2 February 2025, banning practices such as social scoring and requiring minimum AI literacy for staff. Fines reach 35 million euros or 7 percent of global turnover.
The EU AI Act (Regulation 2024/1689) entered force on 1 August 2024. It classifies AI systems into four risk levels with graduated deadlines: prohibitions in February 2025, GPAI obligations in August 2025, and high-risk requirements in August 2026. It applies to any company operating or selling in the EU, with fines exceeding GDPR levels.
The NIS2 directive entered into force on October 17, 2024, but by mid-2026 only part of the member states have fully transposed it: Germany and the Netherlands closed their law, Spain and France remain in process under pressure from Brussels. Here is what already applies and how to prepare without panic.
La EAA entra en vigor en junio de 2025 y afecta a más productos de los que parece. Qué cambia, quién está obligado y cómo planificar con margen suficiente.
In 2023, three frameworks address generative AI regulation differently: the EU AI Act sets four risk tiers with fines up to 6% of global turnover; the US NIST framework is voluntary; the UK delegates to sector regulators. Product teams should inventory AI use cases and document risks now.
The NIS2 Directive expands European cybersecurity from 7 to 18 sectors, mandates 10 minimum technical measures and 24-hour incident notification, and imposes fines of up to 10 million euros or 2% of global turnover, with personal liability for management bodies that fail to comply.
4 min2444.3
We use first- and third-party cookies to analyze site traffic. You can accept them, reject them, or configure your choice.
Learn more about cookies
Cookie preferences
NecessaryEssential for the site to work. Always on.
AnalyticsHelp us understand how the site is used (Google Analytics).