The Digital Omnibus postponed high-risk rules, not training. What the AI Act requires on AI literacy for staff, and since when it is supervised.
The Digital Omnibus postponed high-risk rules, not training. What the AI Act requires on AI literacy for staff, and since when it is supervised.
DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.
Spain’s National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.
The GDPR treats health data as a special category. What it asks of the people in a healthcare organization and what to prove in an audit.
Control 6.3 of ISO 27001:2022 turns awareness into an auditable control. What it requires, what changed since 2013, and how you prove it in an audit.
Since March 1, 2025, Chile’s Law 21,663 sanctions regime is live. What it demands from the board, what from the employee, and how to prove it.
Article 21 of NIS2 requires training for all staff and the management body. What to cover, how to measure it, and how to prove it under audit.
Germany launched IT spotlight inspections over AI risks in the financial sector. Regulation looks at the system. Attackers look at the people.