< Back to all clusters
[TECHNOLOGY] · Germany · 5 sources

started · updated

EU pushes new AI, cloud and cybersecurity regulations with emphasis on human risk management

The European Union is advancing three intertwined regulatory frameworks – the AI Act, the NIS2 directive and the Digital Operational Resilience Act (DORA). All three require firms to address human‑related risks, mandating transparent documentation of who develops and oversees high‑risk AI systems, integration of human‑risk management into security architectures, and thorough third‑party reviews. Validato AG, a German provider of background‑check and risk‑management services, proposes a platform that combines AI‑assisted screening with human‑in‑the‑loop verification to meet these obligations.

Separately, the European Commission has released a draft Cloud and AI Development Act (CADA) to strengthen Europe’s cloud and AI sectors. CADA outlines three pillars – investment in research and innovation, rapid expansion of data‑centre capacity, and a four‑level sovereignty and security framework. Reactions are mixed: industry groups warn the rules may be discriminatory toward non‑EU providers, while several EU parliamentarians argue for a risk‑based approach and faster permitting through “Data Centre Acceleration Zones” and “Strategic Projects”. The proposal seeks to triple EU data‑centre capacity within five to seven years, but critics cite practical challenges such as limited qualified construction firms and tight approval timelines.