CompliPath EU Regulatory Intelligence
Live · 14 sources · updated 06:42 CET

Every EU regulation that actually moved today — triaged before your first coffee.

NIS2, GDPR, EU AI Act, DORA and CRA, summarised and prioritised for SMB compliance leads.

Total updates
312
all time · +6 today
Sources
14
active feeds
Critical
9
need action
Last run
06:42 CET
12 min ago · all green
Regulatory updates 312 results
Sort

ENISA publishes binding technical guidance on incident notification timelines under Article 23

Essential entities must now submit an early warning within 24 hours and a full incident report within 72 hours. The guidance clarifies what counts as a "significant incident" and replaces the May 2025 draft that left timing ambiguous.

Action: Update your incident response runbook so the on-call lead can file an early warning to the national CSIRT within 24 hours.

Commission opens consultation on transparency obligations for general-purpose AI models

Providers of GPAI models placed on the EU market will need to publish a sufficiently detailed summary of training data. Consultation closes 30 June; SMB providers fall in scope above the 10 PFLOPs threshold.

Action: If you fine-tune or distribute foundation models, draft a training-data summary template and submit a consultation response before 30 June.

EDPB adopts final guidelines 02/2026 on the interplay between the GDPR and the AI Act

The board confirms that automated decision-making rules under Article 22 GDPR continue to apply alongside the AI Act high-risk obligations. Joint controllership clarified for fine-tuning customer data into vendor models.

Action: Re-review your DPIAs for any AI-assisted decisions affecting customers and confirm the lawful basis still holds.
AI Summaries are AI-generated. Always verify against the original source before acting.