Regulation & Policy
-
ICO complaints duty comes into force
UK organisations must now meet new legal requirements for handling data protection complaints, adding process discipline to privacy, cyber, and customer evidence trails.
-
EU targets AWS and Azure under DMA
The European Commission’s preliminary move to bring AWS and Azure under the Digital Markets Act brings cloud concentration, enterprise dependency, and infrastructure switching into regulatory focus.
-
MPs warn museums remain exposed
The Public Accounts Committee says government-sponsored museums and galleries remain vulnerable to cyber and physical security threats because oversight has been reactive rather than strategic.
-
Bank tests cloud disruption risk
The Bank of England is using CORST26 and SIMEX to examine how disruption at a major cloud provider could affect financial market infrastructure.
-
ICO complaints duty raises accountability
UK organisations must now have a data protection complaints process, adding a formal accountability layer around data handling, security concerns, and post-incident evidence.
-
Bulgaria faces surveillance export scrutiny
Human Rights Watch says Bulgarian authorities licensed exports of surveillance technology to governments with records of repression, exposing weaknesses in Europe’s cyber-surveillance controls.
-
EU warns digital gaps threaten 2030 targets
The Commission’s 2026 Digital Decade report says Europe has made progress, but structural gaps in infrastructure, skills, public services, and business digitalisation remain.
-
ENISA meeting puts AI access in focus
ENISA’s planned meeting with Anthropic comes as European cyber agencies confront access, assurance, and dependency issues around powerful AI models used in security work.
-
France moves spy analytics away from Palantir
France’s DGSI is moving sensitive analytics work from Palantir to ChapsVision, bringing sovereignty, migration risk, and security-critical procurement into practical focus.
-
FCA brings frontier AI into resilience planning
The FCA has directed firms towards CMORG guidance linking frontier AI capability with cyber security, vulnerability handling, and operational resilience in financial services.





