New rules on cyber risk management across the EU put execs firmly in the crosshairs for noncompliance and are likely to apply to a wider range of organizations than many business leaders may initially think. However, there are also concerns that the rules may become muddled across the wide bloc.ย
Europe
TPRM critical as DORA, new FCA third-party engagement rules come into effect in 2025
New rules that push IT firms providing โcriticalโ services to the U.K.โs financial sector to share more data about cyberattacks and resiliency measures have been welcomed by industry experts. However, concerns remain over how suppliers will be classified and how key data might be gathered and shared.
EU AI Act next GDPR? Proof in the pudding as boardrooms prioritize data governance
Breaches of the EUโs GDPR can cost companies substantial sums and huge reputational damage. Now some are warningย that the implementation of the EUโs AI Act will be just as far-reaching, and could potentially lead to similar numbers of cases.
โFuture-proofingโ products for safety next level of regulation under EU GPSR
Any product that uses AI needs to be safety assessed for its entire lifespan under new rules that went into effect recently across the EU. Experts warned companies using AI to tailor products could be classed as โmanufacturersโ and face the same duty of care as developed.
Overabundance of U.K. AML regulators stretching enforcement resources thin, experts say
The U.K. will struggle to shed its reputation as one of the worldโs biggest conduits for dirty money due to a combination of patchy intelligence-sharing and poorly resourced enforcement agencies, experts told Compliance Week.
U.K., EU enforcement regimes set to escalate, but critics question sanctionsโ effectiveness
With a new political regime ready to take over in the U.S., the effectiveness of sanctions against malign foreign actors like Russia, North Korea, and Iran have come into question. While the European Union and U.K. have increased sanctions pressure, critics have publicly asked: Is it enough?
Good AI governance starts with proactive, continuous risk assessments
Data governance has become a key concern for companies, especially when the EU AI Act and General Data Protection Regulation have put a premium on handling data responsibly and ensuring that artificial intelligence does not cause harm.
EU Deforestation Directive delayed, experts advise compliance managers to not rest on laurels
If your business uses leather, rubber, wood, beef, palm oil, soy, or paper, then you may need to comply with the EU Deforestation Directive, a new rule intended to ensure that no goods traded in the EU contribute to global deforestation.
Spanish telecomm Telefรณnica S.A. fined $85M over bribes to government officials in Venezuela
A subsidiary of Spanish telecommunications provider Telefรณnica S.A. will pay $85.2 million to settle a charge that it violated the Foreign Corrupt Practices Act when it paid bribes to Venezuelan officials to gain preferential access to a currency auction.
Meta-backed EU appeals body facing conflicts of interest concerns
Irelandโs cozy relationship with big business and Big Tech has once again come under scrutiny after the countryโs media regulator allowed a $15 million one-off funding payment from Metaโs Oversight Board Trust to help launch the newly formed Appeal Centre Europe.


