DORA, NIS2, the AI Act, GDPR and MiCA, read as engineering requirements rather than legal summaries.
57 articles, most recent first within each group.
European Union
- Data Altruism Organisations: The Consent, Logging and Security Rulebook Under the DGA
- IReF: Why the ECB's 2031 Timeline Still Means Starting Your Data Model Now
- EHDS Secondary Use: Preparing Health Data for the Access Bodies Without Breaching GDPR
- EHDS Secondary Use: The Data Permit, Health Data Access Body and Secure Processing You'll Query Through
- CRA Conformity for AI-Enabled Products: Where the CRA and AI Act Assessments Collide
- ESAP for Collection Bodies: How OAMs and NCAs Feed the Single Access Point
- Structured Data for ESAP: The Metadata and Format Requirements Behind the Portal
- ESAP Goes Live 10 July 2027: Making Your Filings Machine-Readable and Discoverable
- The CRA and Open-Source: How the Manufacturer Duty Falls on Commercial Distributors, Not Volunteers
- The CRA Technical File: Assembling the Evidence Pack a Market Surveillance Authority Will Ask For
- CRA for SaaS and Remote Data Processing: When Your Cloud Backend Is In Scope
- The CRA Vulnerability-Handling Process: What 'Free Security Updates for the Support Period' Forces You to Build
- Important vs Critical Products Under the CRA: The Class Test That Decides Your Assessment Route
- CRA Full Application 11 December 2027: The CE-Marking and Conformity Path for Software
- Are You a Deployer or a Provider? The AI Act Role Test That Decides Your Whole Obligation Set
- Human Oversight by Design: Implementing AI Act Article 14 in the Interface, Not the Policy
- Automatic Logging Under AI Act Article 12: Retention, Tamper-Evidence and What to Capture
- Technical Documentation as Living Code: Generating AI Act Annex IV From Your Pipeline
- Conformity Assessment Under the AI Act: Internal Control vs Notified Body, and Which You Actually Need
- Building the FRIA: Turning the Fundamental Rights Impact Assessment Into a Repeatable Template
- The Annex III Reprieve Is a Trap: Why 2 December 2027 Needs Work Started in 2026
- The Data Act Switching Deadline: Egress Fees Disappear on 12 January 2027 — Renegotiate Now
- The EMI/PI Instant Payments Deadline: Getting SEPA Instant Access by 9 April 2027
- Instant Payments 2027: The Non-Euro Member-State Deadlines and What They Trigger
- CRA Annex I: What 'Secure by Design' Actually Requires You to Prove
- The EU's SEAL Framework: Cloud Sovereignty Is Now a Score, Not a Slogan
- What 'Products With Digital Elements' Actually Means Under the CRA
- NIS2 vs CRA: Why 'Entity' and 'Product' Obligations Don't Merge Into One Programme
- The AI Act's Obligations, Translated Into Actual Engineering Deliverables
- The EU Data Act Gave You the Right to Leave Your Cloud Provider — Check Your Contract
- From Voluntary Code to Enforcement: How the GPAI Code of Practice Shapes Expectations
- Training-Data Transparency: What the GPAI Public Summary Template Requires
- The CLOUD Act vs GDPR: The Unresolved Conflict Behind Sovereign Cloud
- CRA for Open-Source Stewards: Understanding the New Steward Category
- The 10^25 FLOP Threshold: How 'Systemic Risk' Gets Defined for AI Models
- CRA Annex I Is a Risk Assessment, Not a Checklist
- SEAL and CADA: How the EU Is Turning Cloud Sovereignty Into a Measurable Score
- Model Lifecycle and 'Placed on the Market': When Fine-Tuning Makes You a Provider
- How to Prove DORA Compliance to a Supervisor
- NIS2 Essential Entities: The Obligations the Highest Tier Actually Carries
- EHDS EHR Certification: The Real Timeline, and Why It Is a Data-Model Problem
- The DORA Contract Clauses Most Vendor Paper Doesn't Have
- The CRA Deadline That Arrives Before the One Everyone Is Watching
- CSRD/CSDDD Omnibus Rollback: What Stays in Scope
- EU AI Act: Six Technology Implications for Financial Services Firms
Regulatory Reporting
- DORA Incident Classification Thresholds in Code: Turning the RTS into a Decision Engine
- Prospectus Simplification and Machine-Readable Filings for ESAP
- Don't forget to file this on the 30th — ETS allowance surrender for the 2025 reporting year
- Don't forget to test the path from your dev team to ENISA before you need it
- Don't forget to name your CRA reporting contact — the 24-hour early-warning clock starts 11 September
- The Board's Cyber-Incident Reporting Map: CRA, NIS2, DORA and Sector Rules in One View
More in this area
- The European Accessibility Act Is Live: Turning WCAG 2.1 AA Into a CI Gate, Not a Year-End Audit
- Wallet-Based Strong Customer Authentication: Where EUDI Meets PSD2/PSD3 KYC
- Accepting the EUDI Wallet: The Relying-Party Integration Every Bank and Platform Faces by 2027
- Don't forget to rewrite the deadline slide you built for the board last year
- Don't forget to disclose your chatbot — Article 50 lands 2 August and it was not deferred
- Cloud Concentration Risk Under DORA, SS1/21 and the CTP Regimes