Fraunhofer institutes and Globalfoundries Dresden are bringing an open RISC-V security chip into production to enhance digital sovereignty and supply-chain transparency for critical systems.
Organizations must fundamentally adapt their security policies to AI system autonomy and establish differentiated governance controls for each maturity stage (Assistant, Agent, Operator).
Chief Digital Officers must establish processes by August 2026 to transparently label AI-generated media (images, video, audio), texts and chatbot interactions to minimize deception risks.
Passwords have shifted from a security foundation to a primary attack vector; phishing-resistant authentication is no longer a future vision but an operational necessity.
Structural dependence on single cloud platforms without tested continuity plans is a deliberately accepted risk that inevitably fails — and SaaS is subject to this law just like any other infrastructure.
Industry associations such as Eco criticise the planned sovereignty criteria as discriminatory, while Cispe calls for stricter measures to exclude misuse.
AI-generated summaries on Tripadvisor fail to adequately represent food poisoning and hygiene deficiencies reported by hundreds of guests, putting consumers at risk when selecting hotels.
Centralized secrets management with audit logs and automated rotation is becoming mandatory to meet regulatory requirements and reduce attack surfaces in cloud and container environments.
As of January 2025, DORA mandates that financial institutions implement systematic ICT risk management across their entire supply chain with over 350 requirements and requires software-based third-party management processes.