IDPC Participates in AI Act conference at MDIA
Marco Fagnano, Legal Counsel and AI Regulatory Manager at the Office of the Information and Data Protection Commissioner (IDPC), was recently invited by the Malta Digital Innovation Authority (MDIA) to participate in two panels to contribute on the implementation of the EU Artificial Intelligence Act (AI Act) and its convergence with the EU GDPR. Fagnano echoed the close relationship between the EU AI Act and the General Data Protection Regulation (GDPR), emphasising that strong data protection safeguards provide an important foundation for trustworthy, accountable and compliant AI systems. Addressing public sector stakeholders during the first session - The EU AI Act & Public Administration - he explored the evolving regulatory landscape governing high-risk AI systems and explained how privacy and data protection by design and by default can support compliance with AI regulatory requirements. Fagnano examined the use of health data in AI-powered medical technologies, expressing concern and the challenges of reconciling the doctor-patient relationship with the safeguards surrounding automated decision-making under Article 22 of the GDPR. Incidentally he highlighted the growing interest in privacy-preserving data sanitisation techniques to achieve anonymisation, as a means of enabling AI innovation while protecting patients' fundamental rights. Fagnano noted that, if proven effective from both a privacy-compliance and medical accuracy perspective, such techniques could play an important role in supporting the responsible development and deployment of AI-powered medical technologies.
Read more
ENISA scales up its role in the CVE Program
NATO Communications and Information Agency (NCIA) along with AI and cybersecurity innovator, AISLE join the Common Vulnerabilities and Exposures (CVE) Numbering Authorities (CNAs), under the ENISA Root.
ENISA's role within the CVE™ Program spawns further with the strategic expansion in the global vulnerability management ecosystem and the transition of existing CNAs under the ENISA Root. ENISA retains competence in the EU under the MITRE Root, with 20 CNAs under ENISA Root, including 8 transferred from MITRE Root to the ENISA Root.
The Agency’s contribution to the Program has grown further, attesting to its commitment to acting as a driver and facilitator of vulnerability management at European and international level, through consistent practices, timely identification and trusted coordination among partners.
ENISA Chief Cybersecurity and Operations Officer, Hans de Vries, said: “Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities. Through its role in the CVE Program, ENISA reinforces its operational support to the European and wider vulnerability management community and actively contributes to a more globally representative, resilient, and scalable vulnerability identification ecosystem.”
The addition of new CNAs from across multiple sectors, including CSIRTs, vendors and suppliers, international alliances, and security research organisations, further supports the objectives of the CVE Program of expanding global participation, broadening diversity of participating organisations, improving quality, and increasing operational capacity.
Up next this week: Discussing the evolution of the CVE™ Program
Today, at Black Hat, ENISA’s Head of Sector for Incident and Vulnerability Services, Nuno Rodrigues Carvalho, alongside Lindsey Cerkovnik, Branch Chief for Vulnerability Response and Coordination at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), will discuss the global evolution of the CVE Program, its priorities, and joint initiatives aimed at enhancing its impact on global cybersecurity.
In November 2025, ENISA became a CVE Root for European entities, serving as the central point of contact within the CVE Program for EU Member States’ and EU authorities alike, as well as for EU CSIRTs Network members, and cooperative partners under ENISA mandate. This role is carried out in close coordination with CISA and MITRE, as part of a shared commitment to strengthen the resilience, quality, and long-term sustainability of the global CVE Program.
Through its role as a CVE Root, ENISA recruits, onboards, trains, supports, and manages CNAs within its scope, facilitating their transition where relevant, and ensuring the effective assignment of CVE Identifiers (CVE IDs) and publication of CVE Records. This role also helps ensure that CVE Program rules, guidelines, and processes are followed.
By expanding the number and diversity of CNAs under its Root, ENISA is helping to reinforce the CVE Program as a shared global vulnerability identification backbone relied upon by governments, vendors, researchers, defenders, and the wider cybersecurity community.
The mission of the CVE™ Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. The vulnerabilities are discovered then assigned and published by organizations from around the world that have partnered with the CVE Program. Partners publish CVE Records to communicate consistent descriptions of vulnerabilities. Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.
For press questions and interviews, please contact: press@enisa.europa.eu.
Read more
Preliminary agenda announced for the Open Technology Research Symposium 2026
Preliminary agenda announced for the Open Technology Research Symposium 2026 – Open Source Initiative We’ll never share your details and you can un with a click! Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the r or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network. The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the r or user. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you. The technical storage or access is required to create user profiles to send , or to track the user on a website or across several websites for similar marketing purposes.
Read more
Public call
The overall objective of this consulting services (“the Services”) is to prepare a fully operational, costed, and phased National ERTMS Implementation Plan, compliant with national legislation, EU Regulation (EU) 2023/1695 and aligned with EU railway interoperability policy. The Plan shall be developed as a comprehensive CCS TSI-compliant roadmap covering all requirements of Regulation (EU) 2023/1695, including all relevant Control-Command and Signalling subsystems, interoperability interfaces, certification and authorization processes, migration rules, and institutional arrangements necessary to ensure full system-level compliance beyond ETCS deployment alone.. The detailed Terms of Reference (TOR) for this assignment can be obtained upon request at the e-mail address given below or on the Client website www.gov.me/msa The Ministry of Transport (MoT) through the Technical Service Unit, now invites eligible Consulting Firms (“Consultants”) to indicate their interest in providing the Services. (ii) Required similar contracts presented as reference in (i) above, at least two (2) shall have been delivered in either EU's or an EU accession country; (iii) Professional staff generally available: List of the key staff that is generally available for this kind of work (without submission of bio data or CVs). The number of permanent staff of the consultant (individual company or joint venture overall) working in the fields related to this contract, must be at least 3 for each of the last three years (2023, 2024 and 2025); *For each submitted reference (Contract) the Consultant is required to enclose preferably the statement from the previous Client which unambiguously confirm that assignment has been successfully and substantially implemented. Expressions of interest must be delivered only by e-mail to the address below and in subject must clearly indicate project name, subject number: ERTMS Implementation Plan of Montenegro/ MNE-WBTTFP-94710-CS-CQ-26-2.3.11 Ministry of Finance /Technical Service UnitAttention: Mr.
Read more
European Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for minors
On 24 July 2026, the European Commission sent TikTok preliminary findings indicating that TikTok accounts of minors do not meet the safety standards required under the Digital Services Act (DSA). This setting also allows content published by ‘older' minors (16-17 years old) to be recommended to any other TikTok user through the For You Feed. Even when minors choose private accounts, their accounts can be easily found through the ‘following' and ‘followers' lists of other users, and their profile photos remain accessible to anyone, including users without a TikTok account. Under the DSA, platforms accessible to minors must ensure a high level of privacy, safety, and security on their service. The Commission preliminarily considers that TikTok's account settings fail to meet this standard, as they expose minors' accounts and content too widely. The Commission preliminarily considers that TikTok – in line with the Guidelines on the protection of minors – should adjust the default settings of minors' ‘public' accounts, so that their content is, by default, visible only to TikTok users whom the minor has accepted.
Read more
EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter
EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter | European Data Protection Board EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter Download EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter #International cooperation When you visit our website, if you give your consent, we will use s to allow us to collect data for aggregated statistics to improve our services and remember your choice for future visits. If you don't select any of the two options, no s will be deployed, but the banner will re-appear every time you enter our website.
Read more
Commission starts enforcing AI Act rules and new transparency requirements on 2 August
As of yesterday, 2 August 2026, the European Commission's AI Office, together with national authorities, started enforcing the Artificial Intelligence (AI) Act. On the same date, new transparency rules started to apply, requiring certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it.
Under the new rules, chatbots and other interactive AI systems have to tell users they are dealing with AI, not a human. Deepfakes (images, videos, or audio that have been edited or generated using AI) have to be labelled. AI-generated or altered content also have to carry machine-readable marks so it can be detected more easily.
The measures are intended to reduce deception and manipulation and help people make informed choices. They also give businesses clearer obligations and a practical way to show compliance. The Commission published a first list of more than 180 organisations that have signed the Code of Practice on transparency of AI-generated content that operationalises the rules on transparency of AI-generated content.
As AI grows increasingly capable and integrated into everyday life, the AI Act helps ensure that AI is developed, deployed, and used safely, giving people and businesses across the EU greater confidence in the technology.
The AI Office can now enforce the AI Act's rules for providers of general-purpose AI (GPAI) models. These models can perform many different tasks and can be used in a wide range of tools and services, including AI agents.
The rules also cover the most advanced GPAI models that may pose systemic risks. Their providers must meet additional obligations to address risks of large-scale harm, such as risks linked to chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, harmful manipulation and threats to fundamental rights. They also address risks that have recently drawn public attention, including risks to European cybersecurity and to AI acting outside human control.
All providers of GPAI models must document certain information and provide it to competent authorities or downstream providers. They must also put in place a copyright policy and publish a sufficiently detailed summary of the content used to train their models.
Enforcement also begins for transparency obligations and prohibited AI practices. These ban particularly harmful systems, including systems that manipulate people, exploit vulnerabilities in harmful ways, or unfairly score people in ways that threaten their rights.
Responsibility for enforcing the transparency rules and prohibited practices is shared across three bodies. The AI Office enforces the rules for AI systems offered by the same provider as the underlying general-purpose AI model. It also covers systems integrated into very large online platforms or very large online search engines designated under the Digital Services Act.
National competent authorities enforce the rules for other AI systems. The European Data Protection Supervisor enforces the rules for AI systems used by European Union institutions, bodies and agencies.
Effective enforcement will also depend on Member States ensuring that national competent authorities are properly designated and adequately resourced.
The AI Office and national competent authorities are supported in their enforcement work by the Scientific Panel, an expert advisory body made up of 60 independent AI experts. The panel recently held its first meeting.
The AI Office has also appointed Professor Alessandro Abate of the University of Oxford's Department of Computer Science as Lead Scientific Adviser. He will support the Office's scientific work on general-purpose AI models, including innovation and adoption, as well as model testing and evaluation.
To support enforcement, the AI Office has launched several tools for individuals and businesses. Natural and legal persons can use the Complaint Tool to report alleged infringements of the AI Act by providers of AI systems supervised by the AI Office. People working with providers of AI systems or general-purpose AI models can use the Whistleblower Tool to report possible violations of the Act securely. A dedicated channel is also available for downstream providers that build AI systems on general-purpose models and want to report alleged infringements by the providers of those models. The AI Office will treat information received through these tools confidentially.
Read more
Bridging Policy, Trust and Verifiable Credentials in Gaia-X Data Spaces
As data spaces mature from conceptual frameworks into operational ecosystems, one challenge continues to limit large-scale adoption: how can organisations automatically verify that another participant satisfies access requirements before sharing data, while preserving sovereignty, privacy, and interoperability? A recent research contribution by Gaia-X Lab Tech Lead Yassir SELLAMI, Policy-Driven Data Space Contract Negotiation using the ODRL Verifiable Credential Profile and OpenID4VP, proposes a practical answer. The result is a mechanism that allows data providers to express access requirements as machine-readable policies and enables consumers to automatically prove compliance using credentials stored in digital wallets. Beyond its technical contribution, the work is particularly relevant to Gaia-X because it operationalises several core principles of the Gaia-X Trust Framework: trust, interoperability, verifiability, data sovereignty, and compliance-by-design. This is particularly relevant for Gaia-X Data Exchange initiatives and future Data Usage Agreement implementations, where contractual obligations and policy compliance must be evaluated before data access is granted. It operationalises the principles of sovereignty and interoperability that have guided Gaia-X since its inception and provides a blueprint for future data space implementations in which access decisions are driven not by manual processes but by verifiable evidence and transparent policy evaluation.
Read more