Software Is Now a Product: Europe’s New Liability Rules Reach AI, Updates and Data

The revised EU Product Liability Directive (EU 2024/2853), effective from 9 December 2026, includes software and AI as products subject to liability. It outlines that defects can arise post-release, linking cybersecurity to product safety, and introduces mechanisms for evidence disclosure. Manufacturers must prepare by assessing software, security, and ongoing safety responsibilities.

NIS2 Covers Cyber. The CER Directive Covers the Rest of the Failure

The Critical Entities Resilience (CER) Directive enhances Europe’s resilience strategies beyond the NIS2 framework, addressing broader risks such as natural disasters and human threats. Critical entities in various sectors must conduct assessments and report disruptions promptly. This regulatory shift emphasizes the need for comprehensive risk management and operational resilience in essential services.

The AI Act Does Not Replace GDPR: How Europe’s Digital Rules Fit Together

The EU AI Act introduces a risk-based framework for governing artificial intelligence but does not replace existing laws like GDPR. Organisations must navigate overlapping regulations, ensuring compliance across multiple obligations. Effective governance requires a unified approach that integrates risk management, transparency, security, and accountability throughout the AI system's lifecycle.

DORA Is No Longer a Deadline. It Is an Operating Model

The Digital Operational Resilience Act (DORA) is vital for maintaining continuous financial services amidst technological failures. Effective implementation requires a comprehensive approach to ICT risk management, incident handling, testing, supplier oversight, and information sharing. Organisations must prioritise resilience as an ongoing cycle rather than a one-off compliance exercise to adapt to evolving risks.

NIS2 Becomes Dutch Law: What Changes on 15 August 2026

The Netherlands will implement the Cyberbeveiligingswet (Cbw) on 15 August 2026, enforcing the NIS2 Directive to enhance cybersecurity for over 8,000 organisations across various sectors. Key responsibilities include registration, risk analysis, incident reporting, and management accountability, aimed at strengthening overall cyber resilience and integrating security measures into governance.