The NIS2 Directive will require approximately 29,500 German companies to meet enhanced cybersecurity standards with stricter requirements for governance, risk management, and incident reporting beginning in October 2026.
The Netherlands establishes an explicit liability regime for cybersecurity under NIS2 from August 2024, affecting 8,000 critical infrastructure operators.
IT security tools such as logging, access control and asset inventory are essential instruments for operationalizing and demonstrating compliance with data subject rights under GDPR.
The NIS2 Directive now requires approximately 30,000 additional companies to implement documented cybersecurity management systems and incident reporting.
The European Commission publishes a working document (SWD/2026/600 final) that supports a proposal to amend EU AI regulations and assists compliance teams in interpreting the requirements.
The EU is introducing mandatory indiscriminate monitoring of instant messengers from April 2028, requiring companies to conduct automated content screening.
Two-thirds of German companies lack mature governance structures for AI agents, despite the need to equip them with the same identity and authorization concepts as employees.
Companies that reduce personnel investment while expanding AI spending weaken their ability to operate AI systems reliably and ensure regulatory compliance.