Blog

Insights, guides and news from the compliance and RegTech world

Anchoring your risk register to ACN data (and three ways to get it wrong)

Anchoring your risk register to ACN data (and three ways to get it wrong)

In most SME risk registers, likelihood is an adjective. ACN's monthly Operational Summary lets you replace it with a traceable line of reasoning — provided you avoid three mistakes that ACN itself flags, starting with mistaking the reporting surface for the threat.

What if it happened to your firm tomorrow?

What if it happened to your firm tomorrow?

Fifteen professional firms with compromised databases, more than three thousand clients locked out of their own records, wage support for staff. The Trentino case is not local news: it is a textbook lesson on supply chain risk, business continuity and professional liability.

Deepfakes, privacy and the AI Act: are we asking too much of the GDPR?

Deepfakes, privacy and the AI Act: are we asking too much of the GDPR?

The Italian DPA warned R.T.I. over deepfakes of journalist Enrico Mentana. But is a deepfake really, first and foremost, a data protection problem? Since 2 August 2026, Article 50 of the AI Act offers a different reading: it is not the personal data, it is the deceptive appearance of authenticity.

“The model will be fooled”: what the OWASP GenAI LLM Top 10 2026 teaches

“The model will be fooled”: what the OWASP GenAI LLM Top 10 2026 teaches

For the first time the OWASP Top 10 for LLM applications is tested against 6,639 real incidents. Prompt injection stays first despite the data, Excessive Agency reaches the podium, and Misinformation is the most dangerous gap. How to use the list in your company, from threat modeling to ISO 42001.

Secret governance, public risk: the US frontier AI framework seen from Europe

Secret governance, public risk: the US frontier AI framework seen from Europe

With Executive Order 14409 the US government gets pre-release access to frontier AI models under classified criteria. Why transparent rules are a functional requirement, and how a European company should treat this discretion: as supply-chain risk.

When risk goes out the door and comes back through the window. The Coldcard case and the bitcoin stolen without a hack

When risk goes out the door and comes back through the window. The Coldcard case and the bitcoin stolen without a hack

A 2021 flaw in Coldcard seed generation made never-exposed private keys guessable. Why self-custody does not remove trust, how to assess the risk of self-custody versus third-party custody, and which guarantees actually transfer it.

Authorization moves to the data

Authorization moves to the data

If you cannot guarantee how an AI agent will behave, stop defending behaviour and defend the data: row-level security, masking, ABAC and propagated identity. Third and final article in the agentic security series.

The lethal trifecta: the fire triangle of AI agents

The lethal trifecta: the fire triangle of AI agents

Access to private data, exposure to untrusted content, the ability to communicate externally: when an AI agent has all three ingredients, the fire is only a matter of time. Willison's framework, the GitHub MCP case, and how to break the triangle.

AI-generated content: disclosure becomes mandatory on August 2

AI-generated content: disclosure becomes mandatory on August 2

On 29 July the European Commission adopted its guidelines on Article 50 of the AI Act: from 2 August 2026 chatbots, synthetic content and deepfakes must be disclosed. What changes for SMEs, which exemptions matter and how to prepare.