Sharpen CISO Logo

The EU AI Act, Explained: What Businesses Actually Need to Know

The EU AI Act is no longer a future regulation to prepare for. As of August 2026, most of it is already in force. It also applies far beyond companies headquartered in Europe. If your AI system’s output reaches someone in the EU, the regulation likely reaches you too.

That surprises a lot of teams. Many still treat the EU AI Act as a distant compliance project, something to revisit “closer to the deadline.” In practice, though, the deadlines have already started passing. More are coming through 2027.

This post breaks down what the regulation actually says. It covers how the EU AI Act classifies risk, what it bans outright, what it demands from high-risk systems, and what your team should be doing right now.

What Is the EU AI Act, Exactly?

Formally, it’s Regulation (EU) 2024/1689. It defines an AI system broadly. A machine-based system that operates with some autonomy, may adapt after deployment, and infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions all counts.

That definition matters because it’s intentionally wide. It covers everything from a resume-screening tool to a large generative model. It isn’t limited to headline-grabbing systems like facial recognition or autonomous vehicles.

Just as importantly, the EU AI Act reaches outside the EU’s borders. Say you place an AI system on the EU market, or its output gets used within the EU. Either way, you fall under scope. Location alone doesn’t exempt anyone, and neither does routing your AI infrastructure through a non-EU subsidiary.

The EU AI Act’s Risk-Based Approach

Rather than regulating every AI system the same way, the EU AI Act sorts systems into risk tiers. Each tier carries a different level of obligation.

At the top sits unacceptable risk: practices banned outright, with no compliance path available. Below that comes high-risk, meaning systems that stay on the market but only under strict obligations around risk management, documentation, and oversight. Below that sits limited risk, which mainly triggers transparency duties, such as disclosing that content was AI-generated. Everything else falls into minimal risk, where the regulation imposes no binding requirements at all.

This structure explains why compliance work looks so different from one AI use case to the next. A chatbot on a retail website faces a light touch. A tool used to screen job applicants faces a heavy one, even though both are technically “just AI.”

What’s Banned Outright Under the EU AI Act

Article 5 lists AI practices the EU AI Act prohibits entirely, regardless of sector or safeguards. These prohibitions have applied since February 2025, well ahead of the rest of the regulation.

Banned practices include AI systems that use subliminal or manipulative techniques to distort someone’s behavior in ways that cause harm. They also include systems that exploit vulnerabilities tied to a person’s age, disability, or economic situation. Social scoring by public or private actors is banned too. So is untargeted scraping of facial images from the internet or CCTV footage to build recognition databases.

A few other practices sit in this banned category with narrow carve-outs. Emotion recognition in workplaces and schools is prohibited, except for medical or safety purposes. Real-time remote biometric identification in public spaces for law enforcement is banned by default as well. A narrow exception exists for cases like searching for abduction victims or preventing an imminent terrorist threat. Even then, courts and strict safeguards apply before any deployment.

High-Risk AI Systems Carry the Heaviest Obligations

Annex III of the EU AI Act lists the areas where AI systems are automatically classified as high-risk. They include biometric identification and critical infrastructure. They also cover education and vocational training, employment and worker management, and access to essential public and private services. Law enforcement and migration and border control round out the list.

Falling into one of these categories doesn’t ban the system outright. Instead, it triggers a substantial compliance package. Providers must run a risk management process across the system’s lifecycle. They must maintain detailed technical documentation, ensure meaningful human oversight, and build in logging and traceability. Registration in an EU database is required too, before the system ever reaches deployment.

There’s a narrow exception worth knowing. A system that performs only a narrow procedural task, or one that merely improves on already-completed human work without replacing human judgment, may fall outside the high-risk category. But that exception has limits. Any system that profiles natural persons is automatically treated as high-risk, no matter how narrow its stated task looks.

General-Purpose AI Models Get Their Own Rules

Large generative models don’t fit neatly into the high-risk framework built around specific use cases. So the EU AI Act creates a separate track for general-purpose AI (GPAI) models instead.

All GPAI providers must maintain technical documentation. They also need to give downstream developers the information required to use the model responsibly. On top of that, providers must put a policy in place to comply with EU copyright law, including a summary of the content used to train the model.

Models presumed to carry systemic risk face additional duties. These include model evaluation, adversarial testing, incident reporting, and cybersecurity protections for the model itself. Open-source models get some relief from the transparency rules above. That relief disappears, however, the moment a model is considered to present systemic risk.

Transparency Obligations: Chatbots and Deepfakes

Article 50 covers systems that don’t reach high-risk status but still need to be honest with users about what they’re looking at.

Providers must ensure people know when they’re interacting with an AI system rather than a human. The exception is when that fact is already obvious from context. Separately, deployers of systems that generate deepfakes must disclose it too. A deepfake here means AI-manipulated image, audio, or video content that resembles a real person, place, or event.

These aren’t heavy obligations compared to the high-risk tier. Still, they’re easy to miss. That’s especially true for marketing or content teams experimenting with generative tools without security or legal in the loop.

The EU AI Act Timeline: What Applies When

The EU AI Act didn’t arrive all at once. It phases in across several dates, and by August 2026, most of those dates have already passed.

Prohibited practices under Article 5 became enforceable on 2 February 2025. That date also brought the general provisions and AI literacy obligations in Chapters I and II. Governance structures, GPAI obligations, and the penalty framework followed on 2 August 2025. Then, on 2 August 2026, the bulk of the regulation became applicable, including most high-risk system obligations under Annex III.

One piece still remains on the horizon. High-risk AI systems that serve as safety components of products already regulated under other EU harmonization law, think machinery or medical devices, get extra time. Article 6(1) and its corresponding obligations won’t apply to them until 2 August 2027.

Penalties: How Much Non-Compliance Actually Costs

The EU AI Act backs its obligations with real financial exposure. The amounts scale with the type of violation, not a flat penalty across the board.

Violating the Article 5 prohibitions carries the steepest penalty: fines up to €35 million, or 7% of global annual turnover, whichever is higher. Non-compliance with high-risk system obligations, transparency duties, or requirements for importers and distributors caps lower, at €15 million or 3% of turnover. Supplying incorrect or misleading information to regulators tops out at €7.5 million or 1% of turnover.

For SMEs and startups, each of those caps applies at whichever figure is lower, not higher. That softens the blow somewhat. Even so, regulators weigh factors like intent, cooperation, and harm caused when setting the actual fine. In other words, the ceiling isn’t the only number that matters.

How to Start Preparing

Given how much of the EU AI Act is already active, the practical question isn’t whether to prepare. It’s where to start.

Begin with an inventory. Map every AI system your organization builds, buys, or deploys. Don’t forget tools embedded in third-party software that teams may not even think of as “AI.” From there, classify each system against the risk tiers above, since that classification determines everything else about your obligations, from documentation depth to whether you can deploy the system at all.

If you already run an ISO 27001 or NIS2 compliance program, resist the urge to treat AI governance as a separate track. The EU AI Act’s risk management, documentation, and audit requirements overlap heavily with controls you likely already have in place. Extending an existing information security management system to cover AI systems and their data pipelines is far more efficient than building a parallel compliance silo from scratch. It also keeps a lean compliance team from drowning under yet another standalone framework.

For related reading, see your Secure by Design and Default guide, your Cyber Resilience Act compliance guide, and your ISO 27001 documentation checklist.

The Takeaway

The EU AI Act is no longer a regulation on the horizon; it’s current, active law for most AI systems on the EU market. Its prohibitions have been enforceable since early 2025. Its core obligations took effect in August 2026. Only one narrow category, embedded high-risk systems inside already-regulated products, still has runway left, until August 2027.

The fastest path forward is classification. Once you know which risk tier each of your AI systems falls into, the rest of the compliance work follows a clear, documented path from there.


Sources: Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex

AI Cyber Risk Management: Why Your GRC Program Must Evolve

AI spending is about to explode, and most programs aren’t ready for what that means for AI cyber risk management. Your governance model may not survive the pace.

Gartner forecasts AI spending will grow 44% in 2026 alone. By 2029, total AI spending across infrastructure, products, and services will reach $4.7 trillion. Yet, only 15% of organizations report having comprehensive AI governance in place.

That gap is the real risk. Specifically, it’s a governance problem before it’s a technology problem. This article breaks down why, and what Gartner recommends CISOs and security leaders do about it.

The Fragmentation Trap in AI Risk Governance

Here’s the common mistake. As AI adoption accelerates, many security teams respond by building something new. Specifically, they create separate policies, workflows, and tools just for AI risk.

At first, it feels logical. In practice, though, it backfires.

Because these frameworks run in parallel, they fragment cyber-risk management before it even starts. As a result, they slow down risk-informed decisions. Worse, they make it harder for executives to compare AI risks against everything else on the risk register.

So, Gartner’s guidance is clear. Don’t build a second system for AI. Instead, evolve the one you already have.

This mirrors a governance gap boards are already facing elsewhere. The World Economic Forum’s Global Cybersecurity Outlook 2026 found a similar pattern in supply chain oversight: fragmented visibility, not a lack of tools, is usually the real problem.

Six Ways to Evolve AI Cyber Risk Management

Gartner outlines six specific actions across methodology, people, and technology. Together, they keep AI risk inside your existing governance structure, rather than bolted on beside it.

1. Drive AI cyber-risk accountability. Security teams often become the default owner of every AI-related risk. That’s a problem, since business units that deploy AI tools need to own the risks those tools introduce.

In practice, this means updating your cybersecurity charter. It also means requiring business sponsors to formally acknowledge and accept AI risk before deployment, not after.

2. Keep a unified cyber-risk register. Resist the urge to build a separate register for AI risks. Instead, evaluate AI threats with the same methodology you use for everything else.

Why does this matter? Because a single register forces consistent prioritization across the board. As a result, it stops AI from becoming its own isolated conversation, disconnected from broader risk decisions.

3. Adopt a threat-informed approach. Traditional risk registers often list compliance gaps and isolated vulnerabilities. That approach, however, doesn’t scale well against AI-specific threats like prompt injection or model data leakage.

Instead, ground your risk assessments in real adversary behavior. For example, draft AI-specific scenarios, but score them using the same criteria as every other cyber risk.

4. Normalize AI governance in existing policies. Avoid writing a brand-new “AI policy” for every situation. Instead, most AI risks fit naturally into policies you already maintain, like identity and access management.

Create new, AI-specific standards only when nothing existing applies. For instance, model integrity validation is a good example of a case that may need one.

5. Upskill for AI security. You likely don’t need new job titles. Instead, your current GRC professionals are already well-positioned to manage AI risk, with the right training.

So, invest in upskilling. First, partner with HR to fund AI security certifications. Then, add AI-generated attack scenarios to your existing tabletop exercises.

6. Use technology to strengthen, not fragment, your program. New tools supporting AI governance can add real value. However, adding more disconnected tools won’t automatically fix anything.

Before buying something new, therefore, understand what your existing platforms already do. In short, consolidation, not proliferation, is the goal.

Why AI Cyber Risk Management Matters Now

Some 302 cybersecurity leaders were surveyed for Gartner’s 2025 AI Risk Management research. The result was telling: most said their organizations need significant, if not comprehensive, changes to manage emerging AI cybersecurity risks.

Clearly, that’s not a distant problem for AI cyber risk management. Rather, it’s happening right now, as generative AI tools, custom AI applications, and embedded AI features move into production.

Still, technology alone won’t close this gap. That’s because cyber-risk management depends on expert human judgment. Instead, what AI does is help teams process more signals, faster, so people can focus on the decisions that matter most.

For a look at how this plays out for smaller organizations specifically, see how AI is reshaping cyber risk for growing businesses.

The Bottom Line on AI Cyber Risk Management

AI isn’t a side project anymore. Rather, it’s woven into how organizations already operate.

Because of that, your cyber GRC program can’t treat AI as an exception. Instead, it needs to absorb AI risk into the same structure, register, and accountability model you already trust.

So, organizations that evolve their existing governance, rather than duplicate it, will scale far more effectively. In an AI-driven environment, that’s not just good practice. In fact, it’s the only practice that keeps pace.

Source: Gartner, “Cyber GRC Practices Must Evolve to Manage AI Risk,” 27 April 2026 (ID G00846514).

The DORA Register of Information: A Practical Guide

If your organization is a financial entity operating in the EU, the DORA register of information isn’t optional paperwork. It’s a legal requirement, and it’s already in force. The Digital Operational Resilience Act, or DORA, became applicable on 17 January 2025. From that date, in-scope firms need a complete, current register of every contractual arrangement they hold with ICT third-party service providers.

That sounds simple on paper. In practice, it’s turned out to be one of the more demanding reporting obligations financial entities have faced in years. The European Banking Authority, or EBA, ran a dry run exercise in 2024 specifically to catch problems before official reporting began. Even so, the issues it found were still showing up in testing well into 2025.

This post walks through what the DORA register of information actually requires. It covers why regulators built it this way, and what the EBA’s own data quality findings suggest your team should double-check before filing.

What Is the DORA Register of Information?

The DORA register of information is a structured inventory of a financial entity’s ICT third-party relationships. It has to be maintained at three levels: entity, sub-consolidated, and consolidated. A standalone firm reports differently than a banking group with multiple subsidiaries. Either way, both need the register ready and accurate.

This isn’t a one-time filing, either. Financial entities must keep the register current on an ongoing basis. From there, they submit it to their competent authority on request. That competent authority then passes the collected registers up to the European Supervisory Authorities, known as the ESAs, for further use.

Scope matters here too. DORA applies broadly across the EU financial sector. It covers banks, insurers, and investment firms. Payment institutions and a long list of other regulated entities fall under it as well. If your organization falls under DORA at all, the register of information obligation almost certainly applies to you.

Why the DORA Register of Information Exists

Regulators didn’t build this reporting requirement just to generate paperwork. Instead, the DORA register of information serves three distinct purposes. Each one shapes what the data actually needs to look like.

First, it lets financial entities monitor their own ICT third-party risk. A complete register makes concentration risk visible. Say five critical business functions all depend on the same cloud provider. That pattern shows up clearly in the data, instead of staying hidden across five separate contract files.

Second, it gives EU competent authorities a supervisory tool. Regulators can review how firms manage ICT and third-party risk without waiting for an incident to surface the gaps.

Third, and perhaps most consequentially, the ESAs use the aggregated registers to designate critical ICT third-party providers. These are often shortened to CTPPs. Once a provider earns that designation, it becomes subject to direct EU-level oversight. In other words, the register of information isn’t just about your firm’s own compliance. It’s also the mechanism that identifies which cloud and tech vendors are systemically important to the entire European financial sector.

What the 2024 Dry Run Revealed

Before official reporting began, the ESAs ran a dry run exercise throughout 2024. Financial entities across the EU submitted test registers as part of it. That gave regulators, and the firms themselves, a chance to find problems before the requirement carried real legal weight.

The dry run wasn’t a minor pilot, either. It included industry workshops, a dedicated reporting template, and a draft taxonomy. It also came with its own data quality checks. The EBA published a summary report afterward, along with a factsheet explaining what the exercise was meant to accomplish.

That preparation mattered, because it surfaced structural issues early. Following the 2024 exercise, the EBA published observations from testing official RoI submissions. The findings described key common issues identified across the industry. In practice, this means firms weren’t just getting individual data points wrong. They were running into recurring, systemic problems with how they structured and validated their registers in the first place.

The Technical Side of the DORA Register of Information

Filing the DORA register of information isn’t a matter of filling in a spreadsheet freely. Instead, the reporting format is tightly specified through a formal technical package.

At the center sits the Implementing Technical Standards, or ITS, on the register of information. These were adopted and published in the EU’s Official Journal. From there, the EBA maintains a full Data Model. That includes a Data Point Model dictionary and an annotated table layout defining every field a firm might need to populate.

Submissions ultimately need to conform to a taxonomy built on XBRL-CSV architecture. Sample files and a full taxonomy package are both available for firms to test against before filing for real. On top of that, the EBA publishes validation rules. It also provides a detailed overview of the technical and business checks it applies to every submission. There’s even a plain CSV reporting package for firms that want a simpler path than full XBRL tooling, along with a conversion tool to move between formats.

This level of technical specification exists for a reason. Registers arrive from hundreds of financial entities, spread across different countries and different internal systems. All of that still has to aggregate into one consistent dataset the ESAs can actually analyze.

Common Pitfalls in DORA Register of Information Reporting

Given how technical the format is, it’s no surprise that data quality has been a recurring theme. The EBA has published explanatory material on the data quality feedback firms receive from validation checks. It also shares sample data quality responses, so firms can see what an actual error report looks like before they get one of their own.

A few patterns stand out from that material. Firms sometimes struggle with correctly categorizing licensed activities, which draws on a dedicated annex listing possible values. Others run into trouble with how sub-consolidated and consolidated registers relate to each other. Group-level reporting introduces dependencies that a single-entity register simply doesn’t have to handle.

The EBA also maintains a running FAQ on register of information reporting, updated as new questions surface. That FAQ is worth treating as a living document rather than a one-time read. It reflects issues the EBA is actually seeing in submitted data, not hypothetical edge cases.

How to Prepare for DORA Register of Information Reporting

If your organization hasn’t yet built a repeatable process for this, a few priorities make the biggest difference.

Start by mapping every ICT third-party contract your organization holds, not just the obvious cloud vendors. DORA’s definition of ICT third-party services is broad. Gaps in your contract inventory become gaps in your register, and those gaps are exactly what supervisors are trained to look for. Next, assign clear ownership for keeping that inventory current. The register isn’t a point-in-time exercise. Contracts change and vendors get replaced, so the register needs to reflect that in near real time.

From there, test early against the EBA’s published validation rules. Don’t wait until a filing deadline to discover a formatting issue you could have caught months earlier. The dry run exercise and the subsequent common-issues report both exist specifically so firms can learn from other people’s mistakes instead of their own. Finally, if your organization already runs other EU compliance programs, look for overlap. The vendor risk assessment work behind ISO 27001 or NIS2 compliance often maps closely onto the third-party data DORA now requires, just in a more structured, reportable format.

The Takeaway

The DORA register of information has moved past the planning stage. It’s a live, binding obligation now, backed by a detailed technical reporting package and a body of real-world data quality findings from the EBA’s own testing. The firms handling it well aren’t the ones treating it as an annual scramble. They’re the ones maintaining an accurate, continuously updated inventory of ICT third-party relationships, validated against the EBA’s published rules well before any filing deadline arrives.

If you haven’t tested your register against the EBA’s validation rules yet, that’s the most useful next step. Everything else in this process builds outward from having that data structured correctly from the start.

For related reading, see your Cyber Resilience Act compliance guide, your NIS2 requirements overview, and your ISO 27001 documentation checklist.


Sources: European Banking Authority — Preparations for reporting of DORA registers of information

 

Supply Chain Cyber Risk: What Boards Must Know in 2026

One weak vendor can now shut down an entire company. That’s not a warning anymore. It’s already happened, more than once.

The World Economic Forum’s Global Cybersecurity Outlook 2026 confirms it. Supply chain risk has become the single biggest cybersecurity challenge for large organizations. For boards, this is no longer a topic to delegate. It’s a governance issue.

This article explains why the risk has grown so fast. It also outlines what directors and executives should be asking their teams right now.

The Numbers Behind the Shift

According to the report, 65% of large companies now name supply chain vulnerabilities as their greatest barrier to cyber resilience. That’s up sharply from 54% just a year earlier.

Why the jump? Because today’s digital supply chains are deeply interconnected. A breach at one supplier can cascade through an entire ecosystem. It can hit production, operations, and even other customers, all at once.

Clearly, this isn’t a hypothetical risk. In fact, it’s already playing out in boardrooms around the world.

Real Incidents, Real Costs

Consider Jaguar Land Rover. In 2025, a single cyberattack halted production for five weeks. In fact, the attack disrupted more than 5,000 suppliers at once.

The direct financial impact was severe: £196 million in cyber-related costs, and a nearly 25% drop in quarterly revenue. The wider UK economy absorbed an estimated £1.9 billion in losses. The government even stepped in with a £1.5 billion loan guarantee to stabilize the supply chain.

Or take Asahi, the Japanese beverage maker. A cyberattack in late 2025 knocked out core IT systems. As a result, staff had to revert to pen and paper just to track inventory.

Similarly, in Europe, a relatively small breach at an airport check-in vendor caused widespread flight delays and cancellations. The technical fix was simple. Still, the business disruption was not.

Together, these cases send a clear message to leadership. A vendor’s weakness quickly becomes your company’s crisis.

Why Trust in Vendors Is Breaking Down

At the heart of this problem is a simple, uncomfortable truth. Most companies can’t fully verify the security of the vendors they depend on.

The WEF report calls this “inheritance risk.” In plain terms, it means inheriting a vendor’s vulnerabilities without knowing they exist. It now ranks as the top supply chain concern in the survey.

Close behind is a lack of visibility. Many organizations simply don’t have a clear map of their extended supply chain. As a result, they can’t manage risks they can’t see.

Finally, there’s concentration risk. Businesses increasingly depend on a small number of critical providers, like major cloud platforms. So, if one of those providers fails, the damage can spread across thousands of companies overnight.

What the Most Resilient Companies Do Differently

The report draws a clear line between resilient organizations and the rest. The difference comes down to specific, board-visible practices.

Highly resilient companies involve their security teams in procurement decisions 76% of the time. Less resilient companies do this only 53% of the time. In other words, security earns a seat at the table before you sign contracts, not after a breach.

Similarly, 74% of resilient companies formally assess their suppliers’ security maturity. Only 48% of less resilient companies do the same.

Resilient companies also rehearse for failure. As a result, 44% run joint incident simulations with their supply chain partners, compared to just 16% of less resilient peers. That preparation pays off: only 15% of highly resilient companies report weak incident response planning, versus 37% of the rest.

The Board’s Role Is No Longer Optional

Board engagement now separates resilient companies from vulnerable ones. The data on this point is striking.

Among highly resilient organizations, 99% report active board involvement in cybersecurity. Just over half receive regular updates on cyber risks. Nearly half say their board has a clearly defined oversight role.

By contrast, boards at less resilient companies disengage far more often. That gap in oversight directly tracks the gap in outcomes.

For directors, the takeaway is simple. Cybersecurity oversight isn’t a technical checkbox. Instead, it’s a core part of enterprise risk management, alongside financial and operational risk.

Questions Every Board Should Be Asking

Given all this, what should leadership actually do? A few focused questions can drive real change.

First, ask how security teams take part in vendor selection. If procurement moves forward without a security review, that’s a governance gap worth closing.

Second, ask for a map of critical dependencies. Specifically, leadership should know which vendors, if breached, would cause the most damage.

Third, ask whether the company has tested its response with key partners. Because a plan nobody has rehearsed often fails when it matters most.

Finally, ask how the company manages concentration risk. After all, relying on a single critical provider, without a backup plan, is a strategic vulnerability, not just a technical one.

The Bottom Line

Supply chain risk has moved from the server room to the boardroom. The WEF’s 2026 findings make that shift impossible to ignore.

However, the path forward is well defined. Companies that involve security early, map their dependencies, and rehearse their response are measurably more resilient.

For boards, the message is direct. Ask the hard questions now, before a vendor’s weakness becomes your headline.

Source: World Economic Forum, Global Cybersecurity Outlook 2026, January 2026.

Small Business Cybersecurity: The Warning Signs in WEF’s 2025 Report

Cybercrime is no longer a big-company problem. In fact, small and mid-sized businesses are now the weakest link in the chain.

That’s the clear message from the World Economic Forum’s Global Cybersecurity Outlook 2025. The report surveyed hundreds of business and security leaders worldwide. Its findings paint a worrying picture for smaller businesses.

This article breaks down what the report found. It also explains what small business owners and managers can do about it, starting today.

The Gap Between Small and Large Businesses Is Widening

According to the WEF report, 35% of small businesses now say their cyber defenses fall short. That figure has grown sevenfold since 2022, when it stood at just 5%.

Large companies, meanwhile, are moving the other way. By comparison, only 7% of large companies now report weak defenses, down from 13% a few years ago.

In other words, big companies are getting stronger. Small companies are falling further behind. And because supply chains link small vendors to large enterprises, this gap puts everyone at risk.

The report is blunt about it. At the WEF’s 2024 Annual Meeting on Cybersecurity, 71% of cyber leaders agreed on one point. Small businesses, they said, have already reached a tipping point. Many can no longer defend themselves against today’s threats.

Why Smaller Companies Struggle to Keep Up

Several factors explain this widening gap. Understanding them is the first step toward closing it.

A shortage of skilled people. The report identifies a global shortfall of 2.8 million to 4.8 million cybersecurity workers. Small businesses feel this shortage the hardest. That’s because they rarely compete with large firms on salary or perks.

Only 14% of businesses say they have the talent they need. For small businesses, the skills gap ranks second on their list of barriers. Only the sheer complexity of today’s threats ranks higher.

Limited budgets and resources. Larger companies can afford dedicated security teams, advanced tools, and outside consultants. Smaller businesses typically can’t. That means fewer defenses are in place when an attack happens.

Growing complexity everywhere. World tensions, new rules, and fast-moving tech are all adding pressure. Nearly 60% of businesses say world tensions have already reshaped their security plans. Small teams simply have less time to track every new development.

The Threats Small Businesses Should Watch Closely

In practice, not every cyberthreat affects every business equally. The WEF report highlights a few that matter most right now.

Ransomware still tops the list. Across all business sizes, 45% of respondents rank ransomware as their top cyber risk. Attackers increasingly rent out ransomware tools to less skilled criminals. As a result, there are more attackers, more often.

Fraud and phishing are close behind. Roughly one in five respondents named cyber-enabled fraud, including phishing and fake payment requests, as their top worry. These attacks often target smaller businesses. Why? Because staff may not get the same security training larger firms provide.

AI-made deepfakes are an emerging risk. Criminals now use generative AI to convincingly fake the voice and video of executives. In fact, research cited in the report found a 223% jump in deepfake tools traded on the dark web. That happened within a single year. More than half of surveyed security leaders now see deepfakes as a real threat.

Third-party and supply chain risk is real, even if it doesn’t feel that way. Large companies rank supply chain risk as their top concern. That’s largely because they depend on smaller vendors like you. If your systems get compromised, the damage can spread to every partner you work with.

What Small Businesses Can Do Right Now

Still, the report isn’t just a warning. It also points to practical steps that make a measurable difference, even without a large security budget.

First, invest in your people. The WEF report found that 76% of businesses are closing the skills gap by training current staff. Fewer rely only on hiring new specialists. So, basic security training for your whole team, not just IT staff, goes a long way toward preventing phishing and fraud.

Second, get leadership involved. The report found that 62% of highly resilient businesses give leaders regular updates on cyber risks. Only 29% of less resilient businesses do the same. In short, cybersecurity works best as a business priority, not just a technical one.

Third, prepare for ransomware directly. Because it remains the top risk, don’t leave it to chance. Keep offline backups. Test your response plan. And make sure everyone knows their role during an attack.

Fourth, verify unusual requests. AI-made deepfakes and impersonation scams are rising fast. So, train employees to double-check unusual payment requests or executive instructions. A quick phone call before acting can stop a scam cold.

Finally, ask questions of your vendors and partners. If you supply larger companies, for example, expect them to ask about your security practices. Getting ahead of those questions builds trust and protects your business relationships.

The Bottom Line

The WEF’s 2025 report makes one thing clear. Strong cyber defenses are no longer optional for small businesses. The gap between large and small companies is real, and it’s growing.

However, the report also shows that real progress doesn’t need a big budget. Training your team, involving leadership, and preparing for common threats can go a long way.

Cybersecurity may feel like a big-company problem. But as this year’s report shows, small businesses can no longer afford to think that way.

Source: World Economic Forum, Global Cybersecurity Outlook 2025, January 2025.

63% of boards say their cyber governance isn’t good enough

Cyber risk has become continuous. The governance that oversees it, however, is still periodic.

The result: 63% of boards consider their current practices insufficient to oversee this risk. Five structural causes explain why.

1. Periodic oversight for a continuous risk

Review cadence hasn’t caught up with how the risk actually behaves. In fact, 29% of French companies review cyber risk only once a year, at ExCo or board level.

Attackers don’t wait for the next quarterly meeting. Increasingly, neither can oversight. The World Economic Forum’s 2026 Global Cybersecurity Outlook confirms this shift: threat landscapes now move in near real time. AI drives that speed, on both the offensive and the defensive side.

2. Silos that don’t cover their own seams

Blind spots rarely form inside a single team. Instead, they form in the gap between teams.

Here’s an example: 79% of French companies already use AI internally, but only 42% do so with a formalized security strategy. That 37-point gap is exactly where risk hides.

This isn’t just a French pattern, either. Globally, 87% of organizations named AI-related vulnerabilities their fastest-growing cyber risk last year (WEF, 2026). Meanwhile, security teams are catching up: the share of organizations that assess AI tools before deployment jumped from 37% to 64% in just one year.

3. A skills gap that keeps widening

54% of organizations lack the skills to deploy AI securely. This gap doesn’t close on its own — it widens as AI adoption outpaces upskilling.

So which roles are missing? Globally, three stand out: threat intelligence analysts, DevSecOps engineers, and identity and access management specialists (WEF, 2026). These are exactly the profiles you need to secure AI at scale, not generalist security hires.

4. Regulatory fragmentation that redirects the effort

NIS2, DORA, ReCyF, ISO: each framework brings its own lens, its own evidence requirements, its own audit cadence. As a result, 76% of CISOs say this multiplicity hurts their ability to stay compliant.

So effort shifts from protection to regulatory paperwork. And the scope keeps expanding: 59% of French companies already consider themselves in scope for NIS2 alone, ahead of DORA (32%) and the Cyber Resilience Act (30%). Three overlapping regimes, three separate compliance tracks, one finite security budget.

5. Third-party risk managed by declaration, not by control

30% of French cyber incidents originate with a third party. Yet only 23% of companies monitor their attack surface continuously. The rest relies on a contract clause. In other words, it relies on trust, not on control.

A model built for a pace that no longer exists

The takeaway is simple: boards built cyber governance for a pace of risk that no longer exists.

Getting out of this impasse follows a four-step path:

Ad hoc GRC → Standardization → Centralization → Automation

Each step corrects one of these five causes, in order. Standardization closes the gaps between silos (#2). Centralization turns periodic reporting into continuous visibility (#1), and it also cuts through regulatory duplication (#4). Automation closes the skills gap (#3) last, and it’s what finally makes continuous third-party monitoring (#5) realistic instead of aspirational.

So, where does your organization sit on that path today — still running ad hoc GRC, or already automating?

Sources: WEF, CESIN, Gartner

#SharpenCISO #CISO #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement

Cyber compliance should no longer be a barrier to growth

Proving cyber maturity has become a hurdle to clear before a business can grow. For many organizations, compliance now sits on the critical path of every deployment, every tender, and every audit.

Three everyday situations show exactly how.

  • A project manager needs sign-off from the cyber team before deploying a new application — and that approval can take weeks if the right evidence isn’t already in place.
  • An IT vendor has to prove its security posture during a tender, typically through an ISO 27001 or SOC 2 certification — and one missing document can knock them out of the running.
  • An organization has to prove compliance to regulators, under frameworks like NIS2, DORA, or the CRA — each with its own evidence requirements and its own deadline.

A pace traditional methods can’t follow

Cyberattacks are accelerating. AI is rolling out everywhere. Regulatory requirements keep multiplying, often on the same team, at the same time.

As a result, security teams face more demands with the same limited resources. The frameworks themselves keep stacking, too: NIS2, DORA, and the CRA now overlap for many organizations, each with its own audit cadence and its own evidence trail.

Traditional approaches relied mainly on manual human review, and they simply can’t keep pace anymore. Spreadsheets, one-off audits, and point-in-time certifications suited a slower, more predictable risk environment — not continuous, AI-accelerated change.

Yet when companies innovate at the speed of AI, proving cyber compliance has to move at that same speed. Otherwise, compliance stops protecting the business and starts holding it back.

SharpenCISO: an augmented GRC platform

That’s exactly why we built SharpenCISO.

Our platform automates up to 80% of the manual work needed to demonstrate cyber compliance and manage risk in real time. This isn’t about removing people from the process. It’s about freeing your team from repetitive evidence-gathering, so their expertise goes where it creates the most value: judgment calls, risk decisions, and strategic conversations with the business.

Concretely, SharpenCISO automates the collection of cyber maturity evidence for four audiences at once:

  • Regulators, across frameworks like NIS2, DORA, and the CRA
  • Internal security (SSI) teams, who need continuous visibility instead of a once-a-year snapshot
  • Certification bodies, for standards like ISO 27001 or SOC 2
  • Client tenders and RFPs, where proof of security maturity now shapes business outcomes and risk decisions

One evidence base. Four audiences. No duplicated effort.

Turning cybersecurity into a competitive advantage

That’s our ambition. Proving cyber maturity should never slow an organization down.

Done right, it does the opposite. It builds trust with regulators and customers. It speeds up projects instead of gating them. And it opens doors — deals, partnerships, and markets — that used to stay closed until the paperwork caught up.

Compliance shouldn’t be the brake. It should be the accelerator.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement #SecureAI #AISecurity

Is cyber risk data reliable enough for executive committee decisions?

Cyber risk now sits on nearly every board agenda. But does the data behind those conversations actually reflect what’s happening inside the information system? That’s the question every CISO eventually has to answer in front of their ExCo or board.

Three figures from the latest OpinionWay barometer for CESIN caught our attention:

  • 92% of companies rank cyber risk among their top 5 business risks.
  • 29% review it only once a year, at ExCo or board level.
  • 61% review it several times a year, at the same level.

So cyber risk has clearly become a strategic business risk, not just a technical one. And that status comes with a consequence: CISOs are now expected to support real strategic decisions in the boardroom, not just report on past incidents.

Cyber risk earned its seat at the table — the data hasn’t caught up

Financial data reaching the board goes through audits, standardized formats, and controls built over decades. Cyber risk data, in most organizations, still doesn’t.

This gap isn’t just a reporting habit. It shows up in the decisions that follow, too. For the first time in three years, the share of French companies allocating 5% or more of their IT budget to security actually fell in 2025, down from 48% to 42% (CESIN, 2026). When the data behind that decision is a stale snapshot, the budget that follows gets calibrated on old information — not on the risk as it stands today.

A question that keeps coming up with CISOs

Here’s what we keep hearing in our conversations with CISOs: does data consolidated at a few key moments in the year actually reflect the operational reality of the information system? And is that data reliable enough to inform a CISO’s strategic decisions at ExCo or board level?

In many organizations, teams still pull that data together manually, from scattered tools, just before the meeting. By the time it reaches the board, it’s already a snapshot of where things stood weeks earlier — not where they stand today.

At SharpenCISO, we’re convinced the real issue isn’t measuring more often. It’s building on more reliable data in the first place. Reporting frequency without data quality just means reporting the wrong picture, more often.

What “reliable” actually means here

Reliable doesn’t just mean accurate at the moment of collection. It means current when it reaches the decision-maker.

Take third-party risk as an example. Only 23% of French companies monitor their attack surface continuously — most still rely on a contract clause, reviewed once and rarely revisited. That’s a governance choice as much as a technical one, and it’s exactly the kind of gap that a single point-in-time report can hide.

The same shift is already happening elsewhere in security. The share of organizations that assess their AI tools before deployment nearly doubled in a year, from 37% to 64% (WEF, 2026). Continuous verification is becoming the norm for AI risk. Cyber GRC reporting for the board needs to make the same move — from a periodic snapshot to a live picture.

So, what’s your confidence level?

We’re curious: how much confidence does your organization place in its cyber GRC data when it’s time to make a decision at ExCo or board level?

CISOs, does the data you present match what’s really happening on the ground? And board members, do you feel you’re deciding on today’s risk, or on last quarter’s? Tell us in the comments — we’d like to hear how this looks from where you sit.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

Cybersecurity is becoming a governance issue. It’s now a matter of resilience and risk control, not just technical defense. The latest OpinionWay barometer for CESIN confirms this shift: three regulatory frameworks now dominate corporate priorities in France.

Overall, 59% of French companies say they’re in scope for NIS2, 32% for DORA, and 30% for the CRA (CESIN, 2026). But those averages hide a sharp divide by company size. That divide is where the real story is.

1. NIS2: the new center of gravity

70% of large enterprises rank NIS2 as a top priority. Among small and mid-sized businesses (TPE/PME), that figure drops to just 44%.

The gap makes sense. Large groups already went through NIS1, so they know the drill: risk management, incident notification, board-level accountability. Smaller structures, on the other hand, are still discovering the real scope of the requirements — including obligations that reach into their supply chain, not just their own systems.

2. DORA: operational resilience at the heart of finance

DORA remains a strong priority for large enterprises, at 38%. That number reflects its scope: financial institutions and their critical ICT providers.

Resilience testing, third-party risk management, governance: DORA demands a rigorous discipline. And because it reaches ICT providers as well as financial firms directly, its impact spreads well beyond the finance sector itself.

3. The CRA: securing products by design

With the CRA, the logic shifts. Security has to be built in from the start, not bolted on later. That’s the core of Secure by Design and Secure by Default.

Large enterprises are ahead here too: 37% are already anticipating the CRA, compared to just 23% of mid-sized companies (ETI). That 14-point gap matters, because the CRA’s core requirements — software bills of materials (SBOM) and patch management — take real time to operationalize. Waiting until the deadline isn’t really an option.

What sets the top-performing organizations apart

We’re convinced the organizations that progress fastest will share three habits:

  • They pool controls and reference frameworks across regulations, instead of running separate compliance programs for NIS2, DORA, and the CRA side by side.
  • They prioritize action by actual risk level, not by how easy it is to produce evidence. The easiest compliance box to tick isn’t always the risk that matters most.
  • They give cyber GRC teams the tools to industrialize assessments, produce reliable evidence, and manage several regulations at once — without multiplying the effort every time.

This isn’t a small opportunity. As we discussed in an earlier post, 76% of CISOs already say that managing multiple frameworks in parallel hurts their ability to stay compliant. Convergence isn’t a nice-to-have; it’s how compliance stays sustainable.

Turning compliance into a lever, not an obligation

That’s precisely the approach we’re building with SharpenCISO, our AI-native GRC platform, automated in real time.

Our goal is simple: turn compliance into a genuine lever for managing cyber risk — one that durably strengthens security posture — instead of a string of regulatory obligations to tick off, one framework at a time.

So, what have you put in place?

We’re curious: what have you put in place to improve the performance and impact of your cyber GRC teams?

Are you still running NIS2, DORA, and the CRA as separate tracks, or have you already started pooling the effort? Let us know in the comments.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

 

 

AI Governance in Cybersecurity: The Gap Between Perceived Risk and Reality

One number sets the scene. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 87% of cybersecurity professionals now see AI-related risk as growing fast. That’s more than phishing. More than ransomware. More than classic software flaws. And it’s exposing a widening AI governance gap inside most organizations.

Yet another number tells a different story. Only 64% of organizations assess the security of an AI tool before deploying it. That share is improving. It stood at just 37% in 2025. But it still leaves more than a third of companies exposed to tools they’ve never truly vetted.

This gap isn’t a statistical footnote. It’s the new terrain CISOs must navigate in 2026, and it’s why AI governance is becoming a board-level topic.

The nature of the risk has shifted

A year ago, the dominant fear centered on AI’s offensive capabilities. Deepfakes, auto-generated malware, hyper-personalized phishing: it was the attacker who worried people most. In 2025, 47% of leaders named these adversarial capabilities as their top generative AI concern.

In 2026, that trend has flipped. The figure has dropped to 29%. Data leaks tied to generative AI now lead instead, cited by 34% of respondents, up from 22% the year before.

In other words, the fear no longer comes only from outside. It also comes from within. An employee pasting sensitive data into a public chatbot. An AI agent connected to a critical system, unsupervised. An internal model poorly segmented. The WEF confirms it: the “AI arms race” between attackers and defenders keeps intensifying. But attention is now shifting toward the unintended exposure of data.

A booming market, an AI governance lag

Gartner’s Hype Cycle for Cyber-Risk Management 2026 adds a complementary lens, this time from the market side. The AI-security tooling sector is expected to grow from $1.5 billion in 2025 to $16.5 billion by 2030. A staggering pace, and a clear sign of shared urgency.

But Gartner also flags a blind spot: shadow AI. Generative and agentic assistants are rolling out faster than the governance frameworks meant to contain them. The result is an attack surface expanding quietly, often off the CISO’s radar.

Another telling signal: data security governance is going through what Gartner calls a “trough of disillusionment.” Organizations struggle to deploy it. The culprits are fragmented data silos and underestimated operational complexity. Technology is outpacing the processes meant to keep it in check.

This shift shows up in the budgets too. By 2030, AI-enhanced security solutions are expected to account for more than half of the entire cybersecurity market, itself projected at $353 billion. Investment is following the threat. The question is whether governance can keep the same pace.

France adds its own layer of urgency: sovereignty

This global picture takes on a distinct tone in France. The CESIN cybersecurity barometer (wave 11, January 2026) is unambiguous on this point. 63% of French companies now say they’re concerned about digital sovereignty and trusted cloud. That’s up 11 points in a single year.

This shift matters. Securing AI isn’t just about picking the right tool. It also means knowing where data is hosted, under which jurisdiction, and with what real level of control. For French and European companies, sovereignty and AI governance are becoming inseparable — and a growing number are folding sovereignty checks directly into their ISO 27001 risk assessment process.

The same barometer points to confidence that remains fragile. 67% of respondents say they’re worried about their company’s ability to face cyber risk going forward, up from 63% in the previous wave. Vigilance is rising faster than reassurance.

Geopolitics is adding to the pressure

AI isn’t the only factor complicating the picture. The WEF finds that geopolitics remains, in 2026, the top factor shaping cyber risk strategies. 64% of organizations now factor in geopolitically motivated attacks: disruption of critical infrastructure, espionage.

This climate is also eroding executive confidence. Fewer than 45% of private-sector CEOs trust their country’s ability to respond to a major cyberattack. That uncertainty feeds, once again, the growing interest in digital sovereignty.

For French companies, geopolitics and cloud sovereignty are no longer separate topics. They reinforce each other. And together they fuel the same demand: regaining control over data, and over who handles it.

Why checklists aren’t enough for AI governance

Faced with this acceleration, the instinct is to respond with more controls. More policies, more committees, more manual sign-offs. The WEF warns against exactly this trap. Too many controls create friction. Teams end up working around the rules instead of following them.

The challenge, then, isn’t stacking up constraints. Effective AI governance keeps pace with the business instead of slowing it down. That calls for three things:

  • guardrails built in by design (security-by-design), rather than bolted on afterward;
  • continuous human oversight, especially for high-impact decisions;
  • near real-time monitoring, rather than periodic, backward-looking audits.

This is exactly the philosophy behind the “AI proposes, the CISO decides” approach. Artificial intelligence speeds up detection. It prioritizes risk. It automates repetitive compliance work. But the final call stays in human hands, especially when it touches a business risk or a regulatory obligation.

The link to the EU AI Act

This governance shift isn’t happening in a regulatory vacuum. The EU AI Act already imposes obligations on AI systems classified as high-risk: technical documentation, risk management, human oversight, decision traceability.

For a CISO, there’s good news here too. The AI Act’s requirements largely overlap with ISO 27001 and NIS2. They demand the same discipline: identify risks, document controls, prove compliance over time. Treating AI as an isolated compliance track means duplicating work already under way elsewhere.

The more effective approach is folding the AI Act into the same control mapping as other frameworks. One control plan, several regulations covered. That’s also what keeps a compliance team lean, even as regulatory requirements keep piling up.

AI governance that builds on what already exists

Good news for CISOs already running an ISO 27001 or NIS2 program: there’s no need to start from scratch. AI governance fits naturally into existing GRC processes.

An information security management system (ISMS) already covers most of the groundwork. Asset mapping, risk management, access control, vendor management: these building blocks already exist. It’s simply a matter of extending them to AI tools and their data pipelines, rather than building a parallel silo.

This continuity has a direct payoff. It avoids compliance fatigue. Teams work from a single map, where ISO 27001, NIS2, DORA, and the AI Act overlap and reinforce each other.

Where to start, concretely

A few priorities stand out from the 2026 data, for any CISO looking to structure a response now:

  • Map real AI usage, including tools not officially declared by business teams (shadow AI).
  • Extend vendor risk assessments to AI solution providers, with close attention to data location.
  • Document a pre-deployment validation process, even a lightweight one. The goal: close the gap between perceived risk (87%) and actual coverage (64%).
  • Prioritize human oversight on use cases with high business or regulatory impact.
  • Reassess the cloud supply chain in light of sovereignty concerns, now a priority for two-thirds of French companies.

None of these steps require an organizational big bang. They build on GRC fundamentals most companies already apply elsewhere — the same ones covered in our GRC practices checklist.

In summary: closing the AI governance gap

AI risk is no longer just a sophisticated external threat. It also lives in the everyday, often invisible uses of generative AI at work. The 2026 data leaves little doubt: perceived risk is rising faster than the AI governance meant to contain it.

Closing that gap doesn’t mean slowing AI adoption. It means applying the same rigor already used for information security. Mapping, risk assessment, continuous oversight. And a human decision that keeps the final word.

Want to assess how mature your organization’s AI governance really is? Talk to us about your specific context.


Sources cited: World Economic Forum; Gartner ; CESIN.