In the decade since the EU’s groundbreaking privacy legislation, the GDPR was approved, companies have faced increased scrutiny over the reasons they collect, retain, and share personal information, as well as the measures they take to ensure its security.
Regulatory Policy
Companies risk violating data, consumer laws over agentic AI use
Companies are at increased risk of violating Europeโs tough privacy laws because boards have little awareness of the different types of AI or their inherent risks. While many organizations are more familiar with predictive and conversational AI tools, such as chatbots that carry little or no discernible risk, they have not grasped that generative AIโand especially agentic AIโare different animals.
No new rules as U.K. financial services sector champions AI
There are no new rules on the horizon as U.K. financial services firms embrace โAI-enabled, continuous and delegated services,โ but a report warns that the technology could reshape the sector by 2030 in terms of how firms operate, consumers make decisions, markets compete, and risks emerge.
Compliance must focus on due diligence as U.K. aligns with EU deforestation laws
Products using wood, cattle, cocoa, coffee, palm oil, rubber and soy are set to come under new U.K. deforestation legislation.
GDPR 10 years on: Data compliance now front of mind
Europeโs landmark privacy legislation, GDPR, was officially adopted ten years ago and has been in force since May 2018. It has forced organizations to change the way they think about personal information and has put privacy risk firmly on the boardโs agenda, especially since the sanctions available under the regime are potentially ruinous
New rules to protect EU workers from toxic chemicals in battery, steel, rubber, and textile industries
New rules protecting workers from dangerous chemicals are set to pass into law in October following EU Council and Parliament agreement, establishing new exposure limits across the battery, steel, chemical, and textile industries and updating protective equipment standards.
EU extends proposals to apply carbon border pricing to downstream products
EU member states have agreed to extend measures to price the carbon emissions of goods imported into the Eurozone to include a wide range of end-products made from steel, aluminum and iron. The current CBAM came into force on Jan. 1 this year and currently applies mainly to high-emission raw materials.
EU Council targets greenwashing with new categories of sustainable investment
The Council of the EU has recommended updates to the Sustainable Finance Disclosure Regulation to combat greenwashing and make it easier for investors to compare products.
The SEC’s crypto taxonomy changes everything. Pending enforcement targets should act now
The SEC’s Division of Corporation Finance published a 68-page interpretive release in March that, for the first time, defines what is and is not a security in the digital asset space.
Bank of England changes stance on stablecoins after cumbersome compliance complaints
The Bank of England has revealed that it is reconsidering two of the more contentious aspects of its proposed stablecoin framework after pressure from many in the crypto asset sector. Crypto companies have complained that the proposed regulations would be too restrictive and would hold back the industry in the U.K. in comparison with other global financial markets.


