Posts tagged with "Sweden"

Found 13 posts

Security & Compliance
August 5, 2026

Who enforces the AI Act in Sweden? PTS and the new map

Sweden's AI Act enforcement map is now set: the SOU 2025:101 inquiry designates Post- och telestyrelsen (PTS) as coordinating market surveillance authority, with eleven surveillance bodies, two notifying authorities, and a PTS-run regulatory sandbox. The supplementary law was written to take effect on 2 August 2026 but awaits formal adoption, so PTS and its peers operate on interim government assignments while EU transparency rules already apply.

EU AI Act
PTS
Sweden
SOU 2025:101
Compliance
Market Surveillance
Regulatory Sandbox
IMY
Digital Omnibus
Azure
By Falak Mahmood
Security & Compliance
July 28, 2026

The AI Act's high-risk deadline moved to December 2027

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moves the AI Act deadline for Annex III high-risk systems from August 2026 to 2 December 2027, with Annex I embedded systems following in August 2028. Article 50 transparency still applies from 2 August 2026, a new prohibition arrives with a December 2026 marking deadline, and a phased 16-month plan turns the reprieve into a workable compliance programme.

EU AI Act
Digital Omnibus
High-Risk AI
Compliance
Article 50
Azure
Sweden
AI Governance
GDPR
By Falak Mahmood
Security & Compliance
June 17, 2026

AI Act deadlines moved: what still lands August 2, 2026

On 16 June 2026 the European Parliament approved the Digital Omnibus amendments 423-57, moving Annex III high-risk AI Act obligations to 2 December 2027 and product-embedded obligations to 2 August 2028. Article 50 transparency duties and the Commission's GPAI enforcement powers were not delayed, which leaves Swedish enterprises six weeks to ship chatbot disclosure, content marking and a documented GPAI position before 2 August 2026.

EU AI Act
Digital Omnibus
Article 50
GPAI
Compliance
AI Governance
Azure OpenAI
Sweden
Transparency
By Falak Mahmood
Security & Compliance
June 15, 2026

Who will knock on your door about AI in Sweden? IMY, mostly

On 15 June 2026 IMY confirmed its role as market surveillance authority for the EU AI Act, with responsibility covering AI systems in areas such as law enforcement and credit assessment, alongside PTS and Finansinspektionen. For Swedish enterprises this puts GDPR and AI Act supervision under one regulator, and IMY's sandbox role offers a way to get data protection guidance before enforcement reaches full strength in 2027.

EU AI Act
IMY
Sweden
Market Surveillance
Regulatory Sandbox
GDPR
Compliance
High-Risk AI
Azure
By Falak Mahmood
Security & Compliance
June 10, 2026

CADA explained for Azure customers: EU cloud sovereignty

On 3 June 2026 the European Commission proposed the Cloud and AI Development Act, a regulation that introduces four Union assurance levels for cloud sovereignty and aims to at least triple EU data centre capacity within five to seven years. For Swedish public-sector and regulated teams on Azure, the framework will decide which workloads can stay on a US hyperscaler and which need an EU-controlled alternative, so the classification work should start now.

CADA
Cloud and AI Development Act
Cloud Sovereignty
Azure
EU Data Boundary
Sovereign Cloud
Public Procurement
Sweden
NIS2
Security & Compliance
By Falak Mahmood
Security & Compliance
June 1, 2026

Sweden's cloud policy: digital sovereignty for Azure teams

Sweden's first national cloud policy (Fi2026/01233) bans no provider but makes jurisdictional exposure, portability and exit capability the questions every public-sector cloud decision must now answer in writing. For Azure estates, a defensible position means classified workloads, enforced Swedish and EU residency, customer-managed keys for sensitive data and a tested export path.

Sweden
Cloud Policy
Digital Sovereignty
Public Sector
Azure
Data Residency
Procurement
Compliance
By Falak Mahmood
Security & Compliance
April 16, 2026

Demystifying the EU AI Act: The Engineering Reality

A working-engineer walk-through of the EU AI Act beyond the risk-tier summary. Covers legal structure, Annex III classification decisions, GPAI rules, the full timeline to 2027, Article 12 logging, Article 50 transparency, conformity assessment artifacts, CE marking, penalties, and the Swedish implementation.

EU AI Act
AI Regulation
Compliance
AI Governance
GDPR
Risk Management
Sweden
Policy
Annex III
Conformity Assessment
By Falak Mahmood
Business & Strategy
March 24, 2026

EU AI Act High-Risk Deadline: Swedish Prep List for August 2026

A 4-month practical preparation checklist for the EU AI Act August 2026 high-risk deadline, tailored to Swedish B2B teams — classification, Annex IV documentation, Article 12 logging, human oversight, and CE marking.

EU AI Act
High-Risk AI
Compliance
Sweden
Strategy
By Falak Mahmood
Security & Compliance
March 10, 2026

NIS2 in Sweden: The Practical Engineer's Checklist

A practical engineering checklist for NIS2 compliance in Sweden — the ten risk-management measures, the 24-hour and 72-hour incident reporting timelines, supply-chain controls, and what board accountability looks like on the ground.

NIS2
Cybersecurity
Compliance
Sweden
Security
By Falak Mahmood
Payment & E-Commerce
February 12, 2026

Swish Handel 2026: Integration Patterns for Node Applications

A practical integration guide for Swish Handel in modern Node and Next.js applications in 2026 — certificate management, callback handling, idempotency, reconciliation, and the failure modes every integrator should design for.

Swish
Payments
Sweden
Integration
Node.js
By Falak Mahmood
Security & Compliance
January 15, 2026

DORA One Year In: Swedish Fintech Engineering Lessons

One year after the Digital Operational Resilience Act entered into force for financial-sector firms on 17 January 2025, this is what Swedish fintech engineering teams actually learned about ICT risk, incident reporting, TLPT, and the third-party register.

DORA
Fintech
Compliance
Sweden
Resilience
By Falak Mahmood
Security & Compliance
January 6, 2026

EU AI Act One Year On: Lessons for Swedish B2B Teams

A practical review, one year after the EU AI Act Article 5 prohibitions entered into force on 2 February 2025 — where Swedish B2B teams over-reacted, where they under-reacted, and what must ship before the August 2026 high-risk deadline.

EU AI Act
AI Regulation
Compliance
Sweden
GDPR
By Falak Mahmood
Business & Strategy
December 23, 2025

IT Budget 2026: Where Swedish CTOs Should Invest First

A practical allocation framework for Swedish CTOs planning 2026 IT spend — from EU AI Act governance infrastructure and Entra Agent ID, to Azure Sweden Central residency work, NIS2 gap closure, and the investments worth deferring.

CTO
Budget
Strategy
Sweden
IT Leadership
By Falak Mahmood