Sharpen CISO Logo

The EU AI Act, Explained: What Businesses Actually Need to Know

The EU AI Act is no longer a future regulation to prepare for. As of August 2026, most of it is already in force. It also applies far beyond companies headquartered in Europe. If your AI system’s output reaches someone in the EU, the regulation likely reaches you too.

That surprises a lot of teams. Many still treat the EU AI Act as a distant compliance project, something to revisit “closer to the deadline.” In practice, though, the deadlines have already started passing. More are coming through 2027.

This post breaks down what the regulation actually says. It covers how the EU AI Act classifies risk, what it bans outright, what it demands from high-risk systems, and what your team should be doing right now.

What Is the EU AI Act, Exactly?

Formally, it’s Regulation (EU) 2024/1689. It defines an AI system broadly. A machine-based system that operates with some autonomy, may adapt after deployment, and infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions all counts.

That definition matters because it’s intentionally wide. It covers everything from a resume-screening tool to a large generative model. It isn’t limited to headline-grabbing systems like facial recognition or autonomous vehicles.

Just as importantly, the EU AI Act reaches outside the EU’s borders. Say you place an AI system on the EU market, or its output gets used within the EU. Either way, you fall under scope. Location alone doesn’t exempt anyone, and neither does routing your AI infrastructure through a non-EU subsidiary.

The EU AI Act’s Risk-Based Approach

Rather than regulating every AI system the same way, the EU AI Act sorts systems into risk tiers. Each tier carries a different level of obligation.

At the top sits unacceptable risk: practices banned outright, with no compliance path available. Below that comes high-risk, meaning systems that stay on the market but only under strict obligations around risk management, documentation, and oversight. Below that sits limited risk, which mainly triggers transparency duties, such as disclosing that content was AI-generated. Everything else falls into minimal risk, where the regulation imposes no binding requirements at all.

This structure explains why compliance work looks so different from one AI use case to the next. A chatbot on a retail website faces a light touch. A tool used to screen job applicants faces a heavy one, even though both are technically “just AI.”

What’s Banned Outright Under the EU AI Act

Article 5 lists AI practices the EU AI Act prohibits entirely, regardless of sector or safeguards. These prohibitions have applied since February 2025, well ahead of the rest of the regulation.

Banned practices include AI systems that use subliminal or manipulative techniques to distort someone’s behavior in ways that cause harm. They also include systems that exploit vulnerabilities tied to a person’s age, disability, or economic situation. Social scoring by public or private actors is banned too. So is untargeted scraping of facial images from the internet or CCTV footage to build recognition databases.

A few other practices sit in this banned category with narrow carve-outs. Emotion recognition in workplaces and schools is prohibited, except for medical or safety purposes. Real-time remote biometric identification in public spaces for law enforcement is banned by default as well. A narrow exception exists for cases like searching for abduction victims or preventing an imminent terrorist threat. Even then, courts and strict safeguards apply before any deployment.

High-Risk AI Systems Carry the Heaviest Obligations

Annex III of the EU AI Act lists the areas where AI systems are automatically classified as high-risk. They include biometric identification and critical infrastructure. They also cover education and vocational training, employment and worker management, and access to essential public and private services. Law enforcement and migration and border control round out the list.

Falling into one of these categories doesn’t ban the system outright. Instead, it triggers a substantial compliance package. Providers must run a risk management process across the system’s lifecycle. They must maintain detailed technical documentation, ensure meaningful human oversight, and build in logging and traceability. Registration in an EU database is required too, before the system ever reaches deployment.

There’s a narrow exception worth knowing. A system that performs only a narrow procedural task, or one that merely improves on already-completed human work without replacing human judgment, may fall outside the high-risk category. But that exception has limits. Any system that profiles natural persons is automatically treated as high-risk, no matter how narrow its stated task looks.

General-Purpose AI Models Get Their Own Rules

Large generative models don’t fit neatly into the high-risk framework built around specific use cases. So the EU AI Act creates a separate track for general-purpose AI (GPAI) models instead.

All GPAI providers must maintain technical documentation. They also need to give downstream developers the information required to use the model responsibly. On top of that, providers must put a policy in place to comply with EU copyright law, including a summary of the content used to train the model.

Models presumed to carry systemic risk face additional duties. These include model evaluation, adversarial testing, incident reporting, and cybersecurity protections for the model itself. Open-source models get some relief from the transparency rules above. That relief disappears, however, the moment a model is considered to present systemic risk.

Transparency Obligations: Chatbots and Deepfakes

Article 50 covers systems that don’t reach high-risk status but still need to be honest with users about what they’re looking at.

Providers must ensure people know when they’re interacting with an AI system rather than a human. The exception is when that fact is already obvious from context. Separately, deployers of systems that generate deepfakes must disclose it too. A deepfake here means AI-manipulated image, audio, or video content that resembles a real person, place, or event.

These aren’t heavy obligations compared to the high-risk tier. Still, they’re easy to miss. That’s especially true for marketing or content teams experimenting with generative tools without security or legal in the loop.

The EU AI Act Timeline: What Applies When

The EU AI Act didn’t arrive all at once. It phases in across several dates, and by August 2026, most of those dates have already passed.

Prohibited practices under Article 5 became enforceable on 2 February 2025. That date also brought the general provisions and AI literacy obligations in Chapters I and II. Governance structures, GPAI obligations, and the penalty framework followed on 2 August 2025. Then, on 2 August 2026, the bulk of the regulation became applicable, including most high-risk system obligations under Annex III.

One piece still remains on the horizon. High-risk AI systems that serve as safety components of products already regulated under other EU harmonization law, think machinery or medical devices, get extra time. Article 6(1) and its corresponding obligations won’t apply to them until 2 August 2027.

Penalties: How Much Non-Compliance Actually Costs

The EU AI Act backs its obligations with real financial exposure. The amounts scale with the type of violation, not a flat penalty across the board.

Violating the Article 5 prohibitions carries the steepest penalty: fines up to €35 million, or 7% of global annual turnover, whichever is higher. Non-compliance with high-risk system obligations, transparency duties, or requirements for importers and distributors caps lower, at €15 million or 3% of turnover. Supplying incorrect or misleading information to regulators tops out at €7.5 million or 1% of turnover.

For SMEs and startups, each of those caps applies at whichever figure is lower, not higher. That softens the blow somewhat. Even so, regulators weigh factors like intent, cooperation, and harm caused when setting the actual fine. In other words, the ceiling isn’t the only number that matters.

How to Start Preparing

Given how much of the EU AI Act is already active, the practical question isn’t whether to prepare. It’s where to start.

Begin with an inventory. Map every AI system your organization builds, buys, or deploys. Don’t forget tools embedded in third-party software that teams may not even think of as “AI.” From there, classify each system against the risk tiers above, since that classification determines everything else about your obligations, from documentation depth to whether you can deploy the system at all.

If you already run an ISO 27001 or NIS2 compliance program, resist the urge to treat AI governance as a separate track. The EU AI Act’s risk management, documentation, and audit requirements overlap heavily with controls you likely already have in place. Extending an existing information security management system to cover AI systems and their data pipelines is far more efficient than building a parallel compliance silo from scratch. It also keeps a lean compliance team from drowning under yet another standalone framework.

For related reading, see your Secure by Design and Default guide, your Cyber Resilience Act compliance guide, and your ISO 27001 documentation checklist.

The Takeaway

The EU AI Act is no longer a regulation on the horizon; it’s current, active law for most AI systems on the EU market. Its prohibitions have been enforceable since early 2025. Its core obligations took effect in August 2026. Only one narrow category, embedded high-risk systems inside already-regulated products, still has runway left, until August 2027.

The fastest path forward is classification. Once you know which risk tier each of your AI systems falls into, the rest of the compliance work follows a clear, documented path from there.


Sources: Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex

AI Cyber Risk Management: Why Your GRC Program Must Evolve

AI spending is about to explode, and most programs aren’t ready for what that means for AI cyber risk management. Your governance model may not survive the pace.

Gartner forecasts AI spending will grow 44% in 2026 alone. By 2029, total AI spending across infrastructure, products, and services will reach $4.7 trillion. Yet, only 15% of organizations report having comprehensive AI governance in place.

That gap is the real risk. Specifically, it’s a governance problem before it’s a technology problem. This article breaks down why, and what Gartner recommends CISOs and security leaders do about it.

The Fragmentation Trap in AI Risk Governance

Here’s the common mistake. As AI adoption accelerates, many security teams respond by building something new. Specifically, they create separate policies, workflows, and tools just for AI risk.

At first, it feels logical. In practice, though, it backfires.

Because these frameworks run in parallel, they fragment cyber-risk management before it even starts. As a result, they slow down risk-informed decisions. Worse, they make it harder for executives to compare AI risks against everything else on the risk register.

So, Gartner’s guidance is clear. Don’t build a second system for AI. Instead, evolve the one you already have.

This mirrors a governance gap boards are already facing elsewhere. The World Economic Forum’s Global Cybersecurity Outlook 2026 found a similar pattern in supply chain oversight: fragmented visibility, not a lack of tools, is usually the real problem.

Six Ways to Evolve AI Cyber Risk Management

Gartner outlines six specific actions across methodology, people, and technology. Together, they keep AI risk inside your existing governance structure, rather than bolted on beside it.

1. Drive AI cyber-risk accountability. Security teams often become the default owner of every AI-related risk. That’s a problem, since business units that deploy AI tools need to own the risks those tools introduce.

In practice, this means updating your cybersecurity charter. It also means requiring business sponsors to formally acknowledge and accept AI risk before deployment, not after.

2. Keep a unified cyber-risk register. Resist the urge to build a separate register for AI risks. Instead, evaluate AI threats with the same methodology you use for everything else.

Why does this matter? Because a single register forces consistent prioritization across the board. As a result, it stops AI from becoming its own isolated conversation, disconnected from broader risk decisions.

3. Adopt a threat-informed approach. Traditional risk registers often list compliance gaps and isolated vulnerabilities. That approach, however, doesn’t scale well against AI-specific threats like prompt injection or model data leakage.

Instead, ground your risk assessments in real adversary behavior. For example, draft AI-specific scenarios, but score them using the same criteria as every other cyber risk.

4. Normalize AI governance in existing policies. Avoid writing a brand-new “AI policy” for every situation. Instead, most AI risks fit naturally into policies you already maintain, like identity and access management.

Create new, AI-specific standards only when nothing existing applies. For instance, model integrity validation is a good example of a case that may need one.

5. Upskill for AI security. You likely don’t need new job titles. Instead, your current GRC professionals are already well-positioned to manage AI risk, with the right training.

So, invest in upskilling. First, partner with HR to fund AI security certifications. Then, add AI-generated attack scenarios to your existing tabletop exercises.

6. Use technology to strengthen, not fragment, your program. New tools supporting AI governance can add real value. However, adding more disconnected tools won’t automatically fix anything.

Before buying something new, therefore, understand what your existing platforms already do. In short, consolidation, not proliferation, is the goal.

Why AI Cyber Risk Management Matters Now

Some 302 cybersecurity leaders were surveyed for Gartner’s 2025 AI Risk Management research. The result was telling: most said their organizations need significant, if not comprehensive, changes to manage emerging AI cybersecurity risks.

Clearly, that’s not a distant problem for AI cyber risk management. Rather, it’s happening right now, as generative AI tools, custom AI applications, and embedded AI features move into production.

Still, technology alone won’t close this gap. That’s because cyber-risk management depends on expert human judgment. Instead, what AI does is help teams process more signals, faster, so people can focus on the decisions that matter most.

For a look at how this plays out for smaller organizations specifically, see how AI is reshaping cyber risk for growing businesses.

The Bottom Line on AI Cyber Risk Management

AI isn’t a side project anymore. Rather, it’s woven into how organizations already operate.

Because of that, your cyber GRC program can’t treat AI as an exception. Instead, it needs to absorb AI risk into the same structure, register, and accountability model you already trust.

So, organizations that evolve their existing governance, rather than duplicate it, will scale far more effectively. In an AI-driven environment, that’s not just good practice. In fact, it’s the only practice that keeps pace.

Source: Gartner, “Cyber GRC Practices Must Evolve to Manage AI Risk,” 27 April 2026 (ID G00846514).

Secure by Design: What ENISA’s New Playbook Means for Small Teams

Most small software and hardware teams agree that security matters. But agreeing isn’t the hard part. The hard part is knowing exactly what to build. Do it with almost no spare budget or dedicated security staff, and the gap between intention and execution grows fast.

That’s the gap ENISA just tried to close. In July 2026, the EU Agency for Cybersecurity published the Secure by Design and Default Playbook. It’s a practical guide built specifically for small and medium-sized enterprises. The document doesn’t just repeat the usual “shift security left” advice. Instead, it breaks secure by design into 22 concrete playbooks. Each one comes with a checklist, a minimum-evidence list, and a release gate your team can copy straight into a pull request template.

This post walks through what the playbook actually says. It covers why the guidance exists now, and how a lean team can start using it without hiring a security department first.

The guidance targets a specific audience: software developers, technical product managers, SME security leads, and system architects working with limited resources. If that sounds like your team, the playbook was written with you in mind, not with a Fortune 500 security org.

Why Secure by Design Needed Its Own Playbook

Secure by design sounds simple: build protection in from the start instead of bolting it on later. However, simple ideas don’t always translate into simple action.

ENISA points to a familiar pattern. SME manufacturers face budget constraints, limited security expertise, and constant time pressure from the business. As a result, principles that sound obvious in a conference talk often stay unimplemented in the actual codebase.

The Cyber Resilience Act (CRA) raises the stakes further. Products with digital elements sold in the EU must now demonstrate an appropriate level of cybersecurity. They must also ship with secure default configurations and support timely security updates. So secure by design isn’t just good practice anymore. For many manufacturers, it’s becoming a market-access requirement.

The playbook doesn’t offer legal advice. Instead, it gives engineering teams something more useful day to day: a repeatable way to translate CRA-relevant principles into ordinary sprint work.

Two Ideas, Four Categories

ENISA organizes its guidance around two related but distinct concepts.

Secure by design covers how a system is built. It means embedding threat modeling, secure architecture patterns, and vulnerability management into development from day one. That’s very different from retrofitting them after launch.

Secure by default covers what happens when a user first turns the product on. A secure-by-default product ships with the most protective configuration reasonably possible. Users shouldn’t need expert knowledge just to stay safe out of the box.

Within secure by design, ENISA groups principles into architectural foundations and operational integrity. Architectural foundations cover how the system is structured. Operational integrity, meanwhile, covers how it’s managed and maintained after launch. Within secure by default, principles split into default hardening and guided protection. Default hardening describes the factory-shipped state. Guided protection, in turn, describes how the system helps users stay secure over time.

Together, these four categories organize all 22 playbooks. They range from trust boundaries and least privilege through to secure recovery and ownership transfer.

Inside a Playbook: How the Checklists Actually Work

Each of the 22 playbooks follows the same five-part structure. That consistency is part of what makes the guide so usable for small teams.

First comes the principle itself, stated in one sentence. Next comes the objective: what failure mode this principle is meant to prevent. Then a checklist lists the highest-impact actions. These are written to be achievable by lean teams, not large dedicated security functions.

After that, a minimum evidence section names the smallest set of artifacts that prove the checklist was actually implemented. Finally, a release gate offers pass/fail criteria you can paste directly into a CI pipeline or release review.

For example, take attack surface minimization. The checklist asks teams to list every exposed interface and enforce default-deny network rules. It also asks them to strip development and diagnostic tooling from production builds, and to minimize the data they collect in the first place. The release gate then confirms, before each release, that no new port or admin endpoint slipped through unreviewed.

This format matters because it turns “be more secure” into something a developer can actually check off during a pull request review.

The Principles Cover the Whole Product Life Cycle

The 22 playbooks map onto every stage of a product’s life, not just the coding phase.

Trust boundaries and threat modeling come first. Teams need to know what they’re protecting before they can protect it. Least privilege, strong identity architecture, and defence in depth follow next. Together, these form the architectural backbone of the system.

Operational integrity principles then take over. This includes secure coding practices, logging and monitoring, incident response, and vulnerability and patch management. Supply-chain controls round out the design side. They cover everything from signed build artifacts to software bills of materials (SBOMs).

On the default side, the playbook addresses what ships in the box. That means minimized default services, no shared admin credentials, encrypted communication from the first connection, and unique per-device secrets. Guided protection principles then help users stay secure after setup. They do this through mandatory onboarding steps, automatic updates, and clear warnings whenever someone disables a protection.

Notably, ENISA treats these life-cycle stages as iterative rather than sequential. A vulnerability found in production should trigger a return to earlier threat-modeling and risk-assessment steps, not just a quick patch and a shrug.

Threat Modeling Without the Overhead

Many small teams avoid threat modeling because it sounds like a multi-week exercise reserved for enterprise security departments. In practice, ENISA pushes back on that assumption directly.

The playbook recommends Adam Shostack’s four-question framework as a lightweight starting point. What are we working on? What can go wrong? What are we going to do about it? Did we do a good enough job? Teams can answer these with a single diagram and a short list of top threats. A simple table mapping each threat to its mitigation rounds out the exercise.

The goal isn’t exhaustive documentation. It’s a minimum viable model that’s fast to produce and easy to refresh. Crucially, it should stay tightly coupled to real design decisions. A threat model nobody updates after the first release isn’t worth building in the first place.

Proving It, Not Just Claiming It

One of the more forward-looking sections of the playbook covers machine-processable attestation. Instead of relying on a static PDF report that nobody reads after the audit, ENISA describes how security claims can be expressed as structured, machine-readable data.

For instance, a signed attestation might state that a product enforces TLS 1.3 with AES-256 encryption. That claim then links to actual evidence, such as a configuration scan, a test result, or a build log. Automated systems can verify the claim without waiting on a human reviewer.

For an SME, this matters because it replaces expensive manual audits with automated checks that run on every release. Still, the playbook is careful to note the limits. An attestation alone doesn’t prove a product is secure. Verification and independent assessment remain separate, necessary steps. Structured evidence simply makes both of those steps faster and cheaper to carry out.

How to Start Without Boiling the Ocean

Twenty-two playbooks can feel overwhelming for a five-person engineering team. Fortunately, ENISA anticipated this reaction and suggests a progressive adoption path instead.

Start by establishing context. Define your product’s scope, users, and top risks using the lightweight threat-modeling approach described above. From there, build a foundational baseline covering secure coding practices, logging and monitoring, vulnerability management, and supply-chain controls. If your product handles user access, add restrictive initial access and secure-by-default communication to that baseline too.

Only after that foundation is in place should teams work through the remaining playbooks. Prioritize them by your specific risks and deployment context, not by the order they appear in the document. Progressive adoption isn’t an excuse to delay CRA obligations, though. It’s simply a realistic sequence for teams working with limited time and limited hands.

The Takeaway

Secure by design has always been easy to endorse and hard to operationalize. ENISA’s playbook doesn’t remove that difficulty entirely. But it does turn a vague principle into 22 checklists a small team can actually run through before shipping. Given the CRA’s incoming requirements, that shift from aspiration to action is exactly what most manufacturers need right now.

If your team hasn’t run a lightweight threat model yet, that’s the natural place to start. Everything else in the playbook builds outward from there, one release gate at a time.

For teams already navigating CRA compliance, the playbook is also worth reading alongside Annex C of the original document. It maps each of the 22 principles directly to specific CRA essential requirements, which can save real time when you’re building an internal compliance case. In other words, the checklist work you do for engineering reasons doubles as evidence for regulatory reasons too.

Source: ENISA, Secure by design and default playbook

 

Supply Chain Cyber Risk: What Boards Must Know in 2026

One weak vendor can now shut down an entire company. That’s not a warning anymore. It’s already happened, more than once.

The World Economic Forum’s Global Cybersecurity Outlook 2026 confirms it. Supply chain risk has become the single biggest cybersecurity challenge for large organizations. For boards, this is no longer a topic to delegate. It’s a governance issue.

This article explains why the risk has grown so fast. It also outlines what directors and executives should be asking their teams right now.

The Numbers Behind the Shift

According to the report, 65% of large companies now name supply chain vulnerabilities as their greatest barrier to cyber resilience. That’s up sharply from 54% just a year earlier.

Why the jump? Because today’s digital supply chains are deeply interconnected. A breach at one supplier can cascade through an entire ecosystem. It can hit production, operations, and even other customers, all at once.

Clearly, this isn’t a hypothetical risk. In fact, it’s already playing out in boardrooms around the world.

Real Incidents, Real Costs

Consider Jaguar Land Rover. In 2025, a single cyberattack halted production for five weeks. In fact, the attack disrupted more than 5,000 suppliers at once.

The direct financial impact was severe: £196 million in cyber-related costs, and a nearly 25% drop in quarterly revenue. The wider UK economy absorbed an estimated £1.9 billion in losses. The government even stepped in with a £1.5 billion loan guarantee to stabilize the supply chain.

Or take Asahi, the Japanese beverage maker. A cyberattack in late 2025 knocked out core IT systems. As a result, staff had to revert to pen and paper just to track inventory.

Similarly, in Europe, a relatively small breach at an airport check-in vendor caused widespread flight delays and cancellations. The technical fix was simple. Still, the business disruption was not.

Together, these cases send a clear message to leadership. A vendor’s weakness quickly becomes your company’s crisis.

Why Trust in Vendors Is Breaking Down

At the heart of this problem is a simple, uncomfortable truth. Most companies can’t fully verify the security of the vendors they depend on.

The WEF report calls this “inheritance risk.” In plain terms, it means inheriting a vendor’s vulnerabilities without knowing they exist. It now ranks as the top supply chain concern in the survey.

Close behind is a lack of visibility. Many organizations simply don’t have a clear map of their extended supply chain. As a result, they can’t manage risks they can’t see.

Finally, there’s concentration risk. Businesses increasingly depend on a small number of critical providers, like major cloud platforms. So, if one of those providers fails, the damage can spread across thousands of companies overnight.

What the Most Resilient Companies Do Differently

The report draws a clear line between resilient organizations and the rest. The difference comes down to specific, board-visible practices.

Highly resilient companies involve their security teams in procurement decisions 76% of the time. Less resilient companies do this only 53% of the time. In other words, security earns a seat at the table before you sign contracts, not after a breach.

Similarly, 74% of resilient companies formally assess their suppliers’ security maturity. Only 48% of less resilient companies do the same.

Resilient companies also rehearse for failure. As a result, 44% run joint incident simulations with their supply chain partners, compared to just 16% of less resilient peers. That preparation pays off: only 15% of highly resilient companies report weak incident response planning, versus 37% of the rest.

The Board’s Role Is No Longer Optional

Board engagement now separates resilient companies from vulnerable ones. The data on this point is striking.

Among highly resilient organizations, 99% report active board involvement in cybersecurity. Just over half receive regular updates on cyber risks. Nearly half say their board has a clearly defined oversight role.

By contrast, boards at less resilient companies disengage far more often. That gap in oversight directly tracks the gap in outcomes.

For directors, the takeaway is simple. Cybersecurity oversight isn’t a technical checkbox. Instead, it’s a core part of enterprise risk management, alongside financial and operational risk.

Questions Every Board Should Be Asking

Given all this, what should leadership actually do? A few focused questions can drive real change.

First, ask how security teams take part in vendor selection. If procurement moves forward without a security review, that’s a governance gap worth closing.

Second, ask for a map of critical dependencies. Specifically, leadership should know which vendors, if breached, would cause the most damage.

Third, ask whether the company has tested its response with key partners. Because a plan nobody has rehearsed often fails when it matters most.

Finally, ask how the company manages concentration risk. After all, relying on a single critical provider, without a backup plan, is a strategic vulnerability, not just a technical one.

The Bottom Line

Supply chain risk has moved from the server room to the boardroom. The WEF’s 2026 findings make that shift impossible to ignore.

However, the path forward is well defined. Companies that involve security early, map their dependencies, and rehearse their response are measurably more resilient.

For boards, the message is direct. Ask the hard questions now, before a vendor’s weakness becomes your headline.

Source: World Economic Forum, Global Cybersecurity Outlook 2026, January 2026.

Small Business Cybersecurity: The Warning Signs in WEF’s 2025 Report

Cybercrime is no longer a big-company problem. In fact, small and mid-sized businesses are now the weakest link in the chain.

That’s the clear message from the World Economic Forum’s Global Cybersecurity Outlook 2025. The report surveyed hundreds of business and security leaders worldwide. Its findings paint a worrying picture for smaller businesses.

This article breaks down what the report found. It also explains what small business owners and managers can do about it, starting today.

The Gap Between Small and Large Businesses Is Widening

According to the WEF report, 35% of small businesses now say their cyber defenses fall short. That figure has grown sevenfold since 2022, when it stood at just 5%.

Large companies, meanwhile, are moving the other way. By comparison, only 7% of large companies now report weak defenses, down from 13% a few years ago.

In other words, big companies are getting stronger. Small companies are falling further behind. And because supply chains link small vendors to large enterprises, this gap puts everyone at risk.

The report is blunt about it. At the WEF’s 2024 Annual Meeting on Cybersecurity, 71% of cyber leaders agreed on one point. Small businesses, they said, have already reached a tipping point. Many can no longer defend themselves against today’s threats.

Why Smaller Companies Struggle to Keep Up

Several factors explain this widening gap. Understanding them is the first step toward closing it.

A shortage of skilled people. The report identifies a global shortfall of 2.8 million to 4.8 million cybersecurity workers. Small businesses feel this shortage the hardest. That’s because they rarely compete with large firms on salary or perks.

Only 14% of businesses say they have the talent they need. For small businesses, the skills gap ranks second on their list of barriers. Only the sheer complexity of today’s threats ranks higher.

Limited budgets and resources. Larger companies can afford dedicated security teams, advanced tools, and outside consultants. Smaller businesses typically can’t. That means fewer defenses are in place when an attack happens.

Growing complexity everywhere. World tensions, new rules, and fast-moving tech are all adding pressure. Nearly 60% of businesses say world tensions have already reshaped their security plans. Small teams simply have less time to track every new development.

The Threats Small Businesses Should Watch Closely

In practice, not every cyberthreat affects every business equally. The WEF report highlights a few that matter most right now.

Ransomware still tops the list. Across all business sizes, 45% of respondents rank ransomware as their top cyber risk. Attackers increasingly rent out ransomware tools to less skilled criminals. As a result, there are more attackers, more often.

Fraud and phishing are close behind. Roughly one in five respondents named cyber-enabled fraud, including phishing and fake payment requests, as their top worry. These attacks often target smaller businesses. Why? Because staff may not get the same security training larger firms provide.

AI-made deepfakes are an emerging risk. Criminals now use generative AI to convincingly fake the voice and video of executives. In fact, research cited in the report found a 223% jump in deepfake tools traded on the dark web. That happened within a single year. More than half of surveyed security leaders now see deepfakes as a real threat.

Third-party and supply chain risk is real, even if it doesn’t feel that way. Large companies rank supply chain risk as their top concern. That’s largely because they depend on smaller vendors like you. If your systems get compromised, the damage can spread to every partner you work with.

What Small Businesses Can Do Right Now

Still, the report isn’t just a warning. It also points to practical steps that make a measurable difference, even without a large security budget.

First, invest in your people. The WEF report found that 76% of businesses are closing the skills gap by training current staff. Fewer rely only on hiring new specialists. So, basic security training for your whole team, not just IT staff, goes a long way toward preventing phishing and fraud.

Second, get leadership involved. The report found that 62% of highly resilient businesses give leaders regular updates on cyber risks. Only 29% of less resilient businesses do the same. In short, cybersecurity works best as a business priority, not just a technical one.

Third, prepare for ransomware directly. Because it remains the top risk, don’t leave it to chance. Keep offline backups. Test your response plan. And make sure everyone knows their role during an attack.

Fourth, verify unusual requests. AI-made deepfakes and impersonation scams are rising fast. So, train employees to double-check unusual payment requests or executive instructions. A quick phone call before acting can stop a scam cold.

Finally, ask questions of your vendors and partners. If you supply larger companies, for example, expect them to ask about your security practices. Getting ahead of those questions builds trust and protects your business relationships.

The Bottom Line

The WEF’s 2025 report makes one thing clear. Strong cyber defenses are no longer optional for small businesses. The gap between large and small companies is real, and it’s growing.

However, the report also shows that real progress doesn’t need a big budget. Training your team, involving leadership, and preparing for common threats can go a long way.

Cybersecurity may feel like a big-company problem. But as this year’s report shows, small businesses can no longer afford to think that way.

Source: World Economic Forum, Global Cybersecurity Outlook 2025, January 2025.

63% of boards say their cyber governance isn’t good enough

Cyber risk has become continuous. The governance that oversees it, however, is still periodic.

The result: 63% of boards consider their current practices insufficient to oversee this risk. Five structural causes explain why.

1. Periodic oversight for a continuous risk

Review cadence hasn’t caught up with how the risk actually behaves. In fact, 29% of French companies review cyber risk only once a year, at ExCo or board level.

Attackers don’t wait for the next quarterly meeting. Increasingly, neither can oversight. The World Economic Forum’s 2026 Global Cybersecurity Outlook confirms this shift: threat landscapes now move in near real time. AI drives that speed, on both the offensive and the defensive side.

2. Silos that don’t cover their own seams

Blind spots rarely form inside a single team. Instead, they form in the gap between teams.

Here’s an example: 79% of French companies already use AI internally, but only 42% do so with a formalized security strategy. That 37-point gap is exactly where risk hides.

This isn’t just a French pattern, either. Globally, 87% of organizations named AI-related vulnerabilities their fastest-growing cyber risk last year (WEF, 2026). Meanwhile, security teams are catching up: the share of organizations that assess AI tools before deployment jumped from 37% to 64% in just one year.

3. A skills gap that keeps widening

54% of organizations lack the skills to deploy AI securely. This gap doesn’t close on its own — it widens as AI adoption outpaces upskilling.

So which roles are missing? Globally, three stand out: threat intelligence analysts, DevSecOps engineers, and identity and access management specialists (WEF, 2026). These are exactly the profiles you need to secure AI at scale, not generalist security hires.

4. Regulatory fragmentation that redirects the effort

NIS2, DORA, ReCyF, ISO: each framework brings its own lens, its own evidence requirements, its own audit cadence. As a result, 76% of CISOs say this multiplicity hurts their ability to stay compliant.

So effort shifts from protection to regulatory paperwork. And the scope keeps expanding: 59% of French companies already consider themselves in scope for NIS2 alone, ahead of DORA (32%) and the Cyber Resilience Act (30%). Three overlapping regimes, three separate compliance tracks, one finite security budget.

5. Third-party risk managed by declaration, not by control

30% of French cyber incidents originate with a third party. Yet only 23% of companies monitor their attack surface continuously. The rest relies on a contract clause. In other words, it relies on trust, not on control.

A model built for a pace that no longer exists

The takeaway is simple: boards built cyber governance for a pace of risk that no longer exists.

Getting out of this impasse follows a four-step path:

Ad hoc GRC → Standardization → Centralization → Automation

Each step corrects one of these five causes, in order. Standardization closes the gaps between silos (#2). Centralization turns periodic reporting into continuous visibility (#1), and it also cuts through regulatory duplication (#4). Automation closes the skills gap (#3) last, and it’s what finally makes continuous third-party monitoring (#5) realistic instead of aspirational.

So, where does your organization sit on that path today — still running ad hoc GRC, or already automating?

Sources: WEF, CESIN, Gartner

#SharpenCISO #CISO #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement

Cyber compliance should no longer be a barrier to growth

Proving cyber maturity has become a hurdle to clear before a business can grow. For many organizations, compliance now sits on the critical path of every deployment, every tender, and every audit.

Three everyday situations show exactly how.

  • A project manager needs sign-off from the cyber team before deploying a new application — and that approval can take weeks if the right evidence isn’t already in place.
  • An IT vendor has to prove its security posture during a tender, typically through an ISO 27001 or SOC 2 certification — and one missing document can knock them out of the running.
  • An organization has to prove compliance to regulators, under frameworks like NIS2, DORA, or the CRA — each with its own evidence requirements and its own deadline.

A pace traditional methods can’t follow

Cyberattacks are accelerating. AI is rolling out everywhere. Regulatory requirements keep multiplying, often on the same team, at the same time.

As a result, security teams face more demands with the same limited resources. The frameworks themselves keep stacking, too: NIS2, DORA, and the CRA now overlap for many organizations, each with its own audit cadence and its own evidence trail.

Traditional approaches relied mainly on manual human review, and they simply can’t keep pace anymore. Spreadsheets, one-off audits, and point-in-time certifications suited a slower, more predictable risk environment — not continuous, AI-accelerated change.

Yet when companies innovate at the speed of AI, proving cyber compliance has to move at that same speed. Otherwise, compliance stops protecting the business and starts holding it back.

SharpenCISO: an augmented GRC platform

That’s exactly why we built SharpenCISO.

Our platform automates up to 80% of the manual work needed to demonstrate cyber compliance and manage risk in real time. This isn’t about removing people from the process. It’s about freeing your team from repetitive evidence-gathering, so their expertise goes where it creates the most value: judgment calls, risk decisions, and strategic conversations with the business.

Concretely, SharpenCISO automates the collection of cyber maturity evidence for four audiences at once:

  • Regulators, across frameworks like NIS2, DORA, and the CRA
  • Internal security (SSI) teams, who need continuous visibility instead of a once-a-year snapshot
  • Certification bodies, for standards like ISO 27001 or SOC 2
  • Client tenders and RFPs, where proof of security maturity now shapes business outcomes and risk decisions

One evidence base. Four audiences. No duplicated effort.

Turning cybersecurity into a competitive advantage

That’s our ambition. Proving cyber maturity should never slow an organization down.

Done right, it does the opposite. It builds trust with regulators and customers. It speeds up projects instead of gating them. And it opens doors — deals, partnerships, and markets — that used to stay closed until the paperwork caught up.

Compliance shouldn’t be the brake. It should be the accelerator.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement #SecureAI #AISecurity

Is cyber risk data reliable enough for executive committee decisions?

Cyber risk now sits on nearly every board agenda. But does the data behind those conversations actually reflect what’s happening inside the information system? That’s the question every CISO eventually has to answer in front of their ExCo or board.

Three figures from the latest OpinionWay barometer for CESIN caught our attention:

  • 92% of companies rank cyber risk among their top 5 business risks.
  • 29% review it only once a year, at ExCo or board level.
  • 61% review it several times a year, at the same level.

So cyber risk has clearly become a strategic business risk, not just a technical one. And that status comes with a consequence: CISOs are now expected to support real strategic decisions in the boardroom, not just report on past incidents.

Cyber risk earned its seat at the table — the data hasn’t caught up

Financial data reaching the board goes through audits, standardized formats, and controls built over decades. Cyber risk data, in most organizations, still doesn’t.

This gap isn’t just a reporting habit. It shows up in the decisions that follow, too. For the first time in three years, the share of French companies allocating 5% or more of their IT budget to security actually fell in 2025, down from 48% to 42% (CESIN, 2026). When the data behind that decision is a stale snapshot, the budget that follows gets calibrated on old information — not on the risk as it stands today.

A question that keeps coming up with CISOs

Here’s what we keep hearing in our conversations with CISOs: does data consolidated at a few key moments in the year actually reflect the operational reality of the information system? And is that data reliable enough to inform a CISO’s strategic decisions at ExCo or board level?

In many organizations, teams still pull that data together manually, from scattered tools, just before the meeting. By the time it reaches the board, it’s already a snapshot of where things stood weeks earlier — not where they stand today.

At SharpenCISO, we’re convinced the real issue isn’t measuring more often. It’s building on more reliable data in the first place. Reporting frequency without data quality just means reporting the wrong picture, more often.

What “reliable” actually means here

Reliable doesn’t just mean accurate at the moment of collection. It means current when it reaches the decision-maker.

Take third-party risk as an example. Only 23% of French companies monitor their attack surface continuously — most still rely on a contract clause, reviewed once and rarely revisited. That’s a governance choice as much as a technical one, and it’s exactly the kind of gap that a single point-in-time report can hide.

The same shift is already happening elsewhere in security. The share of organizations that assess their AI tools before deployment nearly doubled in a year, from 37% to 64% (WEF, 2026). Continuous verification is becoming the norm for AI risk. Cyber GRC reporting for the board needs to make the same move — from a periodic snapshot to a live picture.

So, what’s your confidence level?

We’re curious: how much confidence does your organization place in its cyber GRC data when it’s time to make a decision at ExCo or board level?

CISOs, does the data you present match what’s really happening on the ground? And board members, do you feel you’re deciding on today’s risk, or on last quarter’s? Tell us in the comments — we’d like to hear how this looks from where you sit.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

Cybersecurity is becoming a governance issue. It’s now a matter of resilience and risk control, not just technical defense. The latest OpinionWay barometer for CESIN confirms this shift: three regulatory frameworks now dominate corporate priorities in France.

Overall, 59% of French companies say they’re in scope for NIS2, 32% for DORA, and 30% for the CRA (CESIN, 2026). But those averages hide a sharp divide by company size. That divide is where the real story is.

1. NIS2: the new center of gravity

70% of large enterprises rank NIS2 as a top priority. Among small and mid-sized businesses (TPE/PME), that figure drops to just 44%.

The gap makes sense. Large groups already went through NIS1, so they know the drill: risk management, incident notification, board-level accountability. Smaller structures, on the other hand, are still discovering the real scope of the requirements — including obligations that reach into their supply chain, not just their own systems.

2. DORA: operational resilience at the heart of finance

DORA remains a strong priority for large enterprises, at 38%. That number reflects its scope: financial institutions and their critical ICT providers.

Resilience testing, third-party risk management, governance: DORA demands a rigorous discipline. And because it reaches ICT providers as well as financial firms directly, its impact spreads well beyond the finance sector itself.

3. The CRA: securing products by design

With the CRA, the logic shifts. Security has to be built in from the start, not bolted on later. That’s the core of Secure by Design and Secure by Default.

Large enterprises are ahead here too: 37% are already anticipating the CRA, compared to just 23% of mid-sized companies (ETI). That 14-point gap matters, because the CRA’s core requirements — software bills of materials (SBOM) and patch management — take real time to operationalize. Waiting until the deadline isn’t really an option.

What sets the top-performing organizations apart

We’re convinced the organizations that progress fastest will share three habits:

  • They pool controls and reference frameworks across regulations, instead of running separate compliance programs for NIS2, DORA, and the CRA side by side.
  • They prioritize action by actual risk level, not by how easy it is to produce evidence. The easiest compliance box to tick isn’t always the risk that matters most.
  • They give cyber GRC teams the tools to industrialize assessments, produce reliable evidence, and manage several regulations at once — without multiplying the effort every time.

This isn’t a small opportunity. As we discussed in an earlier post, 76% of CISOs already say that managing multiple frameworks in parallel hurts their ability to stay compliant. Convergence isn’t a nice-to-have; it’s how compliance stays sustainable.

Turning compliance into a lever, not an obligation

That’s precisely the approach we’re building with SharpenCISO, our AI-native GRC platform, automated in real time.

Our goal is simple: turn compliance into a genuine lever for managing cyber risk — one that durably strengthens security posture — instead of a string of regulatory obligations to tick off, one framework at a time.

So, what have you put in place?

We’re curious: what have you put in place to improve the performance and impact of your cyber GRC teams?

Are you still running NIS2, DORA, and the CRA as separate tracks, or have you already started pooling the effort? Let us know in the comments.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

 

 

AI Governance in Cybersecurity: The Gap Between Perceived Risk and Reality

One number sets the scene. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 87% of cybersecurity professionals now see AI-related risk as growing fast. That’s more than phishing. More than ransomware. More than classic software flaws. And it’s exposing a widening AI governance gap inside most organizations.

Yet another number tells a different story. Only 64% of organizations assess the security of an AI tool before deploying it. That share is improving. It stood at just 37% in 2025. But it still leaves more than a third of companies exposed to tools they’ve never truly vetted.

This gap isn’t a statistical footnote. It’s the new terrain CISOs must navigate in 2026, and it’s why AI governance is becoming a board-level topic.

The nature of the risk has shifted

A year ago, the dominant fear centered on AI’s offensive capabilities. Deepfakes, auto-generated malware, hyper-personalized phishing: it was the attacker who worried people most. In 2025, 47% of leaders named these adversarial capabilities as their top generative AI concern.

In 2026, that trend has flipped. The figure has dropped to 29%. Data leaks tied to generative AI now lead instead, cited by 34% of respondents, up from 22% the year before.

In other words, the fear no longer comes only from outside. It also comes from within. An employee pasting sensitive data into a public chatbot. An AI agent connected to a critical system, unsupervised. An internal model poorly segmented. The WEF confirms it: the “AI arms race” between attackers and defenders keeps intensifying. But attention is now shifting toward the unintended exposure of data.

A booming market, an AI governance lag

Gartner’s Hype Cycle for Cyber-Risk Management 2026 adds a complementary lens, this time from the market side. The AI-security tooling sector is expected to grow from $1.5 billion in 2025 to $16.5 billion by 2030. A staggering pace, and a clear sign of shared urgency.

But Gartner also flags a blind spot: shadow AI. Generative and agentic assistants are rolling out faster than the governance frameworks meant to contain them. The result is an attack surface expanding quietly, often off the CISO’s radar.

Another telling signal: data security governance is going through what Gartner calls a “trough of disillusionment.” Organizations struggle to deploy it. The culprits are fragmented data silos and underestimated operational complexity. Technology is outpacing the processes meant to keep it in check.

This shift shows up in the budgets too. By 2030, AI-enhanced security solutions are expected to account for more than half of the entire cybersecurity market, itself projected at $353 billion. Investment is following the threat. The question is whether governance can keep the same pace.

France adds its own layer of urgency: sovereignty

This global picture takes on a distinct tone in France. The CESIN cybersecurity barometer (wave 11, January 2026) is unambiguous on this point. 63% of French companies now say they’re concerned about digital sovereignty and trusted cloud. That’s up 11 points in a single year.

This shift matters. Securing AI isn’t just about picking the right tool. It also means knowing where data is hosted, under which jurisdiction, and with what real level of control. For French and European companies, sovereignty and AI governance are becoming inseparable — and a growing number are folding sovereignty checks directly into their ISO 27001 risk assessment process.

The same barometer points to confidence that remains fragile. 67% of respondents say they’re worried about their company’s ability to face cyber risk going forward, up from 63% in the previous wave. Vigilance is rising faster than reassurance.

Geopolitics is adding to the pressure

AI isn’t the only factor complicating the picture. The WEF finds that geopolitics remains, in 2026, the top factor shaping cyber risk strategies. 64% of organizations now factor in geopolitically motivated attacks: disruption of critical infrastructure, espionage.

This climate is also eroding executive confidence. Fewer than 45% of private-sector CEOs trust their country’s ability to respond to a major cyberattack. That uncertainty feeds, once again, the growing interest in digital sovereignty.

For French companies, geopolitics and cloud sovereignty are no longer separate topics. They reinforce each other. And together they fuel the same demand: regaining control over data, and over who handles it.

Why checklists aren’t enough for AI governance

Faced with this acceleration, the instinct is to respond with more controls. More policies, more committees, more manual sign-offs. The WEF warns against exactly this trap. Too many controls create friction. Teams end up working around the rules instead of following them.

The challenge, then, isn’t stacking up constraints. Effective AI governance keeps pace with the business instead of slowing it down. That calls for three things:

  • guardrails built in by design (security-by-design), rather than bolted on afterward;
  • continuous human oversight, especially for high-impact decisions;
  • near real-time monitoring, rather than periodic, backward-looking audits.

This is exactly the philosophy behind the “AI proposes, the CISO decides” approach. Artificial intelligence speeds up detection. It prioritizes risk. It automates repetitive compliance work. But the final call stays in human hands, especially when it touches a business risk or a regulatory obligation.

The link to the EU AI Act

This governance shift isn’t happening in a regulatory vacuum. The EU AI Act already imposes obligations on AI systems classified as high-risk: technical documentation, risk management, human oversight, decision traceability.

For a CISO, there’s good news here too. The AI Act’s requirements largely overlap with ISO 27001 and NIS2. They demand the same discipline: identify risks, document controls, prove compliance over time. Treating AI as an isolated compliance track means duplicating work already under way elsewhere.

The more effective approach is folding the AI Act into the same control mapping as other frameworks. One control plan, several regulations covered. That’s also what keeps a compliance team lean, even as regulatory requirements keep piling up.

AI governance that builds on what already exists

Good news for CISOs already running an ISO 27001 or NIS2 program: there’s no need to start from scratch. AI governance fits naturally into existing GRC processes.

An information security management system (ISMS) already covers most of the groundwork. Asset mapping, risk management, access control, vendor management: these building blocks already exist. It’s simply a matter of extending them to AI tools and their data pipelines, rather than building a parallel silo.

This continuity has a direct payoff. It avoids compliance fatigue. Teams work from a single map, where ISO 27001, NIS2, DORA, and the AI Act overlap and reinforce each other.

Where to start, concretely

A few priorities stand out from the 2026 data, for any CISO looking to structure a response now:

  • Map real AI usage, including tools not officially declared by business teams (shadow AI).
  • Extend vendor risk assessments to AI solution providers, with close attention to data location.
  • Document a pre-deployment validation process, even a lightweight one. The goal: close the gap between perceived risk (87%) and actual coverage (64%).
  • Prioritize human oversight on use cases with high business or regulatory impact.
  • Reassess the cloud supply chain in light of sovereignty concerns, now a priority for two-thirds of French companies.

None of these steps require an organizational big bang. They build on GRC fundamentals most companies already apply elsewhere — the same ones covered in our GRC practices checklist.

In summary: closing the AI governance gap

AI risk is no longer just a sophisticated external threat. It also lives in the everyday, often invisible uses of generative AI at work. The 2026 data leaves little doubt: perceived risk is rising faster than the AI governance meant to contain it.

Closing that gap doesn’t mean slowing AI adoption. It means applying the same rigor already used for information security. Mapping, risk assessment, continuous oversight. And a human decision that keeps the final word.

Want to assess how mature your organization’s AI governance really is? Talk to us about your specific context.


Sources cited: World Economic Forum; Gartner ; CESIN.