Chief Digital Officers must establish processes by August 2026 to transparently label AI-generated media (images, video, audio), texts and chatbot interactions to minimize deception risks.
Industry associations such as Eco criticise the planned sovereignty criteria as discriminatory, while Cispe calls for stricter measures to exclude misuse.
From July 2025, companies must train all employees in cybersecurity and AI governance under NIS2 and the EU AI Act, with documented programs and penalty risks for non-compliance.
The independence of the FTC was a core component of the EU adequacy decision; with its elimination by the Supreme Court, the Data Privacy Framework loses its legal foundation.
The constitutional authorization of the US President to remove FTC commissioners without cause jeopardizes the FTC as the core supervisory body of the EU-US Data Protection Framework and thus the lawfulness of data transfers to the US.
The Digital Product Passport requires not just IT integration but a permanently operated compliance infrastructure where the choice between in-house development and service provider platforms fundamentally determines cost burden over years.
A US Supreme Court decision declaring independent supervisory authorities unconstitutional jeopardizes the legal basis of the EU-US data transfer agreement.
AI agents with stable, broad permissions become uncontrolled super-users; they should instead be treated like sensitive service accounts with minimal, function-specific, and time-limited access.