Il Mondo Maggioli

Le nostre attività integrate affiancano la Pubblica Amministrazione Locale e Centrale, i Liberi Professionisti e le Aziende nel semplificare i processi e migliorare i servizi
Soluzioni e ServiziTecnologia e conoscenza sono da sempre le nostre passioni, il nostro business e il modo con cui siamo sempre riusciti a rispondere alle richieste di un mercato in continua evoluzione
News

Europe’s digital crossroads, how the EU is rewriting the rules for AI, Cybersecurity and digital trust

A new phase for Europe’s digital governance. Europe is entering a decisive phase in the governance of artificial intelligence, cybersecurity, and digital infrastructure.

The past months have revealed a strategic recalibration of the European Union’s digital regulatory framework, reflecting both the scale of technological transformation and the political urgency to ensure that innovation does not outpace public safeguards.

The developments surrounding the AI Digital Omnibus, the evolution of transparency rules for AI generated content, new cybersecurity guidance, and the integration of digital governance into health policy illustrate how the EU is shaping a comprehensive ecosystem of digital regulation. These initiatives are not isolated policies, but part of a broader effort to align technological advancement with democratic values, security priorities, and economic competitiveness.

A key moment in this process arrived on March 11, 2026, when Members of the European Parliament reached a preliminary political agreement that recalibrates the implementation timeline of the EU AI Act.
 

AI Act: realistic timelines and stronger safeguards

One of the most significant outcomes of the negotiations is the extension of compliance deadlines for certain categories of high risk AI systems.

These adjustments provide what industry groups have repeatedly demanded, legal certainty and realistic implementation timelines. Rather than relying on discretionary extensions by the European Commission, the compromise introduces fixed statutory deadlines.

This change is intended to help organizations plan their compliance strategies with greater predictability, particularly in sectors where the integration of AI into products and services requires extensive testing, certification, and oversight.

While the deadline extensions reflect regulatory pragmatism, the agreement also introduces a highly visible new safeguard, the explicit prohibition of AI systems designed to create non consensual intimate deepfakes.
The ban targets technologies capable of generating or manipulating realistic images or videos that depict identifiable individuals in sexually explicit scenarios without their consent.

The prohibition reflects a broader recognition within European institutions that AI generated media can undermine personal dignity, privacy, and democratic discourse. Investigations into recent incidents involving generative AI tools producing explicit deepfakes intensified the political debate, especially when such content involved minors. By introducing a clear ban, lawmakers aim to establish a strong legal barrier against one of the most damaging applications of synthetic media.

However, the regulation also introduces a nuanced compliance incentive. Companies that demonstrate effective safety mechanisms designed to prevent the creation of such content may qualify for conditional exemptions.
This approach encourages proactive technical safeguards, shifting the regulatory focus toward responsible system design rather than relying solely on punitive enforcement.

Another important clarification within the agreement concerns the use of sensitive personal data to detect and mitigate bias in high risk AI systems. Developers will now be permitted to process certain categories of protected data under strict safeguards if the purpose is to identify discriminatory outcomes or improve algorithmic fairness.

This adjustment addresses a longstanding tension between the strict privacy protections of European data law and the practical requirements of bias correction in machine learning systems. Without access to relevant demographic data, developers often struggle to detect discriminatory patterns within algorithms.

The new provision attempts to reconcile privacy protection with the need for fair and accountable AI systems.
 

Transparency for AI-generated content

Parallel to these legislative developments, the European Commission has advanced another crucial element of the AI governance framework, transparency for AI generated content. On March 5, 2026, the Commission published the second draft of a Code of Practice on the marking and labeling of synthetic media. Although the code is voluntary, it plays an important role in helping organizations prepare for the transparency obligations of the AI Act.

The proposed framework introduces a layered technical approach to identifying AI generated content. One element focuses on secure metadata embedding, ensuring that synthetic content carries persistent digital identifiers that reveal its origin. Another approach relies on digital watermarking, which can include visible or invisible markers embedded directly in images, audio, or video.

Additional measures such as fingerprinting, logging, and verification systems provide supplementary tools for tracking and verifying content authenticity. The code places particular emphasis on deepfakes and AI generated content related to matters of public interest. Platforms and publishers may be required to label such material clearly to prevent misinformation and ensure that audiences can distinguish synthetic media from authentic sources. Public consultation on the draft will remain open until the end of March, with finalization expected by early June.

Cybersecurity moves to the centre of Europe’s digital strategy

While AI governance dominates headlines, cybersecurity regulation is evolving simultaneously. On March 3, 2026, the European Commission released draft guidance to help companies implement the Cyber Resilience Act, a sweeping law designed to strengthen the security of digital products across the European market.
The guidance addresses several areas that have created uncertainty since the legislation entered into force in December 2024. Among the issues clarified are the treatment of cloud connected products, the distinction between commercial and non commercial open source software, and the duration of manufacturers’ obligations to provide security updates.

The guidance also explains how the Cyber Resilience Act interacts with other EU laws, including the AI Act and the NIS2 cybersecurity directive. Special attention is given to small and medium sized enterprises, which may face disproportionate compliance costs due to the technical and administrative demands of cybersecurity certification.

These cybersecurity measures are part of a broader policy package proposed earlier in 2026. The European Commission has suggested reforms to the EU Cybersecurity Act that would transform certification from a voluntary quality label into a central compliance mechanism. Additional amendments to the NIS2 directive aim to reduce administrative burdens for certain mid sized companies while expanding coverage to new digital services such as European digital identity wallet providers.

The package also introduces requirements for organizations to report ransomware payments, including the amounts paid and the identities of recipients.
 

The Anthropic case and the security implications of advanced AI

The urgency underpinning regulatory frameworks like the European Cyber Resilience Act is brought into sharp focus by recent events demonstrating the increasingly porous boundary between technological innovation and critical cybersecurity threats. In mid-June 2026, the United States government compelled the AI company Anthropic to abruptly suspend global access to its most advanced models, Claude Fable 5 and Mythos 5, restricting their use exclusively to U.S. citizens.

This unprecedented intervention was driven by immediate national security imperatives. The Mythos model family possesses unparalleled, cutting-edge capabilities in parsing vast amounts of code and identifying critical vulnerabilities across software ecosystems. The tipping point occurred with the discovery of sophisticated jailbreak techniques (methods designed to bypass the safety filters of Fable 5), potentially coercing the system into revealing or actively exploiting these underlying flaws.

By resorting to drastic export control measures, Washington explicitly acknowledged that advanced artificial intelligence is no longer merely a commercial software product, but a highly sensitive dual-use infrastructure with profound military and defensive implications.

This episode vividly illustrates the tangible risks that European policymakers are attempting to mitigate through proactive vulnerability reporting and systemic resilience requirements.
 

Three competing visions of digital governance

The abrupt restriction of the Fable 5 and Mythos models also serves as a stark reminder of the profound cultural and strategic divergences that characterize global digital governance.
As the three major global powers navigate the technological frontier, their regulatory philosophies reflect fundamentally opposing worldviews.

The European Union remains steadfast in its precautionary, rights-based approach.
By designing a comprehensive and structurally sound legislative ecosystem (anchored by the AI Act, the GDPR, and the Cyber Resilience Act) the EU aims to ensure that technological advancement serves human-centric goals without compromising fundamental civil liberties, ultimately hoping to export these ethical standards globally.

In stark contrast, the United States continues to champion a market-driven, laissez-faire model that allows innovation to run largely unchecked to secure economic dominance.

Federal intervention in the U.S. remains predominantly reactive, triggered almost exclusively by concerns over national security and geopolitical supremacy, and relying heavily on executive orders and targeted export embargoes rather than holistic legislative frameworks. Meanwhile, China has subordinated its technological development to the strict imperatives of domestic stability and state security.

Beijing's regulatory architecture is inherently authoritarian, enforcing stringent mandates that require algorithms to adhere to political censorship and reflect the core values of the ruling party, thereby ensuring complete digital sovereignty and absolute control over citizen data.

This geopolitical tripartite clearly underscores the uniqueness of Europe’s quest to build an environment rooted in digital trust, positioning itself as a democratic counterbalance to both American techno-nationalism and Chinese digital authoritarianism.
 
22 June 2026

Read more news

News

MyHealth@EU: European Digital Healthcare Becomes a Reality

MyHealth@EU is the European digital infrastructure that enables the secure exchange of health data between Member States. Operational since 2019, it allows citizens to receive care in any EU country by making necessary clinical information available to authorized healthcare professionals, thereby fostering interoperability, continuity of care, and safe, integrated European mobility.
06 July 2026
News

Europe’s digital crossroads, how the EU is rewriting the rules for AI, Cybersecurity and digital trust

A new phase for Europe’s digital governance. Europe is entering a decisive phase in the governance of artificial intelligence, cybersecurity, and digital infrastructure.

22 June 2026
Press review

Collectives welcomes the Maggioli technology group into its shareholder structure.

Maggioli, with international operations in Italy, Spain, Brussels, and Latin America, is making a strategic investment in Greece and has chosen Collectives as its strategic partner.
11 June 2026
News

Digital Local Public Administration: after the NRRP, the real challenge is skills, governance and the citizen

The next phase for Local Public Administrations is to turn digital projects into sustainable services through stronger skills, clearer governance and a more citizen-centred approach.

08 June 2026