Posts tagged with "Compliance"

Found 15 posts

Security & Compliance
August 13, 2026

Claude's text watermark: what it means for Article 50

Anthropic will weave an invisible watermark into Claude's text output to meet the EU AI Act's Article 50 marking obligation, applying it globally across the API, apps and cloud platforms including Microsoft Foundry. What the mark can and cannot prove, which deployer duties remain yours, and when a DIY provenance layer still earns its keep on Azure.

EU AI Act
Article 50
Claude
Anthropic
Watermarking
C2PA
Microsoft Foundry
Compliance
AI Governance
Content Provenance
By Falak Mahmood
Security & Compliance
August 5, 2026

Who enforces the AI Act in Sweden? PTS and the new map

Sweden's AI Act enforcement map is now set: the SOU 2025:101 inquiry designates Post- och telestyrelsen (PTS) as coordinating market surveillance authority, with eleven surveillance bodies, two notifying authorities, and a PTS-run regulatory sandbox. The supplementary law was written to take effect on 2 August 2026 but awaits formal adoption, so PTS and its peers operate on interim government assignments while EU transparency rules already apply.

EU AI Act
PTS
Sweden
SOU 2025:101
Compliance
Market Surveillance
Regulatory Sandbox
IMY
Digital Omnibus
Azure
By Falak Mahmood
Security & Compliance
August 4, 2026

AI Act enforcement is now real: an Azure deployer checklist

On 2 August 2026 the European Commission's enforcement powers over general-purpose AI providers activated: the AI Office can now demand documentation, run model evaluations, restrict models from the EU market and fine up to 3% of global turnover or EUR 15 million. The same date brought Article 50 transparency into application, and this guide maps what Azure OpenAI and Foundry teams must demand from vendors versus handle themselves as deployers.

AI Act
EU AI Act
GPAI
Article 50
Azure OpenAI
Azure AI Foundry
AI Office
Compliance
Digital Omnibus
Transparency
By Falak Mahmood
Security & Compliance
July 28, 2026

The AI Act's high-risk deadline moved to December 2027

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moves the AI Act deadline for Annex III high-risk systems from August 2026 to 2 December 2027, with Annex I embedded systems following in August 2028. Article 50 transparency still applies from 2 August 2026, a new prohibition arrives with a December 2026 marking deadline, and a phased 16-month plan turns the reprieve into a workable compliance programme.

EU AI Act
Digital Omnibus
High-Risk AI
Compliance
Article 50
Azure
Sweden
AI Governance
GDPR
By Falak Mahmood
Security & Compliance
July 22, 2026

Article 50 compliance for Azure OpenAI apps: a guide

The European Commission adopted its final Article 50 transparency guidelines on 20 July 2026 and confirmed the Code of Practice on marking AI-generated content as adequate, less than two weeks before the obligations start to apply. Here is what Swedish and EU teams running chatbots, copilots and content generators on Azure OpenAI must implement: chatbot disclosure, machine-readable marking and deepfake labels, with concrete code patterns for each.

EU AI Act
Article 50
Azure OpenAI
Transparency
C2PA
Code of Practice
Compliance
GenAI
Chatbots
By Falak Mahmood
Security & Compliance
June 17, 2026

AI Act deadlines moved: what still lands August 2, 2026

On 16 June 2026 the European Parliament approved the Digital Omnibus amendments 423-57, moving Annex III high-risk AI Act obligations to 2 December 2027 and product-embedded obligations to 2 August 2028. Article 50 transparency duties and the Commission's GPAI enforcement powers were not delayed, which leaves Swedish enterprises six weeks to ship chatbot disclosure, content marking and a documented GPAI position before 2 August 2026.

EU AI Act
Digital Omnibus
Article 50
GPAI
Compliance
AI Governance
Azure OpenAI
Sweden
Transparency
By Falak Mahmood
Security & Compliance
June 15, 2026

Who will knock on your door about AI in Sweden? IMY, mostly

On 15 June 2026 IMY confirmed its role as market surveillance authority for the EU AI Act, with responsibility covering AI systems in areas such as law enforcement and credit assessment, alongside PTS and Finansinspektionen. For Swedish enterprises this puts GDPR and AI Act supervision under one regulator, and IMY's sandbox role offers a way to get data protection guidance before enforcement reaches full strength in 2027.

EU AI Act
IMY
Sweden
Market Surveillance
Regulatory Sandbox
GDPR
Compliance
High-Risk AI
Azure
By Falak Mahmood
Security & Compliance
June 1, 2026

Sweden's cloud policy: digital sovereignty for Azure teams

Sweden's first national cloud policy (Fi2026/01233) bans no provider but makes jurisdictional exposure, portability and exit capability the questions every public-sector cloud decision must now answer in writing. For Azure estates, a defensible position means classified workloads, enforced Swedish and EU residency, customer-managed keys for sensitive data and a tested export path.

Sweden
Cloud Policy
Digital Sovereignty
Public Sector
Azure
Data Residency
Procurement
Compliance
By Falak Mahmood
Security & Compliance
May 10, 2026

EU AI Act High-Risk Readiness: 11 Weeks to August 2026

High-risk obligations under the EU AI Act apply August 2, 2026. For teams shipping AI inside the Annex III categories, that is 11 weeks of runway. This is the readiness state most teams reach by skipping the strategy decks: what actually changes, what the four obligations that require code look like, and where compliance spending misfires before the deadline.

EU AI Act
Compliance
High-Risk AI
Regulation
GDPR
By Falak Mahmood
Security & Compliance
April 16, 2026

Demystifying the EU AI Act: The Engineering Reality

A working-engineer walk-through of the EU AI Act beyond the risk-tier summary. Covers legal structure, Annex III classification decisions, GPAI rules, the full timeline to 2027, Article 12 logging, Article 50 transparency, conformity assessment artifacts, CE marking, penalties, and the Swedish implementation.

EU AI Act
AI Regulation
Compliance
AI Governance
GDPR
Risk Management
Sweden
Policy
Annex III
Conformity Assessment
By Falak Mahmood
Security & Compliance
April 14, 2026

Azure Entra Agent ID: Identity and Permissions for Agentic AI

A deep dive into Microsoft Entra Agent ID, the control plane for AI agent identity in 2026. Covers identity blueprints, attended and unattended authentication, tool-level RBAC, conditional access, OBO flows across multi-agent systems, and the audit logging that satisfies DORA, NIS2, and AI Act obligations.

Entra
Azure AD
Identity
AI Agents
Agentic AI
RBAC
Zero Trust
Security
Microsoft Foundry
Compliance
By Falak Mahmood
Business & Strategy
March 24, 2026

EU AI Act High-Risk Deadline: Swedish Prep List for August 2026

A 4-month practical preparation checklist for the EU AI Act August 2026 high-risk deadline, tailored to Swedish B2B teams — classification, Annex IV documentation, Article 12 logging, human oversight, and CE marking.

EU AI Act
High-Risk AI
Compliance
Sweden
Strategy
By Falak Mahmood
Security & Compliance
March 10, 2026

NIS2 in Sweden: The Practical Engineer's Checklist

A practical engineering checklist for NIS2 compliance in Sweden — the ten risk-management measures, the 24-hour and 72-hour incident reporting timelines, supply-chain controls, and what board accountability looks like on the ground.

NIS2
Cybersecurity
Compliance
Sweden
Security
By Falak Mahmood
Security & Compliance
January 15, 2026

DORA One Year In: Swedish Fintech Engineering Lessons

One year after the Digital Operational Resilience Act entered into force for financial-sector firms on 17 January 2025, this is what Swedish fintech engineering teams actually learned about ICT risk, incident reporting, TLPT, and the third-party register.

DORA
Fintech
Compliance
Sweden
Resilience
By Falak Mahmood
Security & Compliance
January 6, 2026

EU AI Act One Year On: Lessons for Swedish B2B Teams

A practical review, one year after the EU AI Act Article 5 prohibitions entered into force on 2 February 2025 — where Swedish B2B teams over-reacted, where they under-reacted, and what must ship before the August 2026 high-risk deadline.

EU AI Act
AI Regulation
Compliance
Sweden
GDPR
By Falak Mahmood