Tag: Trends and Insights
-

The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere
Read more: The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhereKey takeaways Introduction: the AI compliance deadline GRC teams have been racing toward just moved For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…
-

When the US government switched off AI: what the Anthropic shutdown means for your GRC program
Read more: When the US government switched off AI: what the Anthropic shutdown means for your GRC programKey takeaways Introduction: for many businesses the lights went out when the US government enforced AI restrictions Picture this: it’s the morning of 13 June 2026 and the compliance team at a mid-sized, European financial services business opens their AI-assisted regulatory monitoring tool – the one they recently rolled out, that surfaces horizon risk items and flags policy changes across five jurisdictions. It is offline, with no warning email, no estimated time of restoration and, critically, no fallback. …
-

8 risk and compliance leaders to follow and learn from on LinkedIn
Read more: 8 risk and compliance leaders to follow and learn from on LinkedInWe’re shining a spotlight on the people shaping the future of governance, risk and compliance. LinkedIn is one of the best places to find real conversations about risk leadership, compliance culture, internal audit, AI governance, operational resilience and the future of GRC. In this blog, we’ve curated 8 GRC leaders worth following on LinkedIn. Their work spans: From established analysts and community…
-

The Novo Nordisk breach shows cyber extortion now targets far more than personal data – what risk and compliance leaders can learn from this
Read more: The Novo Nordisk breach shows cyber extortion now targets far more than personal data – what risk and compliance leaders can learn from thisKey takeaways What happened at Novo Nordisk? Reuters reported that cyber extortion group FulcrumSec claimed it spent more than 2 months inside Novo Nordisk’s network and stole more than 700,000 files, equal to roughly 1.3 terabytes of data. The group also claimed Novo Nordisk refused to pay a $25m extortion demand. Reuters said it could not immediately verify the authenticity of the data…
-

World Cup stadium strike was narrowly averted: how resilient are your critical suppliers?
Read more: World Cup stadium strike was narrowly averted: how resilient are your critical suppliers?Key takeaways Introduction: What happened at the 2026 World Cup? Days before the World Cup began, a supplier issue at one of the tournament’s highest-profile venues was narrowly avoided. Reuters reported that a union representing around 2,000 food and beverage workers at SoFi Stadium reached a tentative agreement with Legends Hospitality only days before the tournament. AP described the agreement as averting a…
-

Recent Bank of England warning and why AI-driven cyber threats are now a top concern for banking regulators globally
Read more: Recent Bank of England warning and why AI-driven cyber threats are now a top concern for banking regulators globallyKey takeaways Introduction: Is AI changing the cyber threat environment faster than organizations can respond? AI is not only a technology that organizations need to govern internally. It is also reshaping the external cyber threat environment. Used well, AI can help teams detect vulnerabilities, strengthen defenses and respond to incidents more quickly. However, the same capabilities can create new attack…
-

When employees become the attack surface: lessons from the Carnival breach
Read more: When employees become the attack surface: lessons from the Carnival breachKey Takeaways Introduction: what happened in the Carnival data breach? Carnival Corporation is one of the world’s largest cruise operators, with a portfolio of cruise brands serving customers across international markets. On 14 April 2026, Carnival Corporation said its IT security team identified unauthorized activity involving an employee account. According to the company, an unauthorized…
-

US & UAE GRC headlines: Regulators are widening the assurance perimeter.
Read more: US & UAE GRC headlines: Regulators are widening the assurance perimeter.Recent regulatory activity in the US and UAE points to a bigger GRC trend: regulators are looking beyond policies and asking whether organizations can prove control across more areas of the business. In the US, the Department of Justice announced a $549.5m False Claims Act settlement over alleged evasion of customs duties on Chinese aluminum extrusions. The…
-

Shein data transfer inquiry: cross-border data risk is back in focus with Ireland’s Data Protection Commission
Read more: Shein data transfer inquiry: cross-border data risk is back in focus with Ireland’s Data Protection CommissionKey takeaways Ireland’s Data Protection Commission has opened an inquiry into SHEIN Ireland over transfers of EU/EEA personal data to China. The DPC has said transfers to China are now an “important strategic priority,” and the inquiry will examine GDPR principles, transparency obligations, and Chapter V transfer requirements. This messaging makes this far more than…
-

Ultra Electronics, Balt SAS and Nazaha reporting: Global anti-bribery enforcement is testing compliance programs
Read more: Ultra Electronics, Balt SAS and Nazaha reporting: Global anti-bribery enforcement is testing compliance programsKey takeaways / abstract Anti-bribery enforcement is not standing still. In the space of a few weeks, cases and enforcement activity across the UK, US and Middle East have pointed to the same issue: regulators are not just looking for policies. They are looking for proof that compliance programs work in practice. The Ultra Electronics…