Compliance & IT, clearly explained.
Regulation changes faster than most companies can keep up. Here we put new obligations, deadlines and security topics into context - without legalese and with concrete action steps for SMEs.
How to label AI content correctly: A practical guide for websites and social media
Since 2 August 2026, the transparency obligations under Article 50 of the EU AI Act have applied. Anyone using chatbots, AI images, AI voices or AI-generated text has since been asking: Do I now have to label all of it? The short answer is no. The AI Act does not require companies to label every piece of AI-generated content—the obligations apply to clearly defined situations, not every use of an AI tool. This is precisely where the practical problem arises: some companies label everything out of uncertainty and therefore appear unprofessional. Others label too little and risk a violation. This article explains the four cases governed by Article 50, the applicable exceptions and exactly how to label content on websites and social media.
NIS2 from 2026: These obligations are coming for SMEs.
The NIS2 Directive (EU 2022/2555) is the European Union's most far-reaching cybersecurity regulation to date - and it affects significantly more companies than its predecessor. Many SMEs still assume that ‘cybersecurity obligations’ apply only to large corporations or critical infrastructure. That misconception can be costly. As transposition into national law is taking effect gradually in several Member States, 2026 will be the year of practical application for many companies. Those who do not start now will come under time pressure. This article summarises who is affected, which obligations apply and where management bears personal responsibility.
ISO 42001 & AI policy template: Your guide through the EU AI Act—pragmatic and efficient
The EU AI Act requires companies to establish systematic governance structures for the legally compliant use of artificial intelligence. But where do you start? How can these complex requirements be implemented in practice without bringing business operations to a standstill? ISO 42001 is the first international standard for AI management systems and translates many abstract AI Act requirements into 38 concrete controls—a field-tested blueprint that helps you: In this article, we show you how to use the structure of ISO 42001 to comply with the AI Act pragmatically—and implement it efficiently with our policy template. This integrated approach not only saves time but also significantly reduces your AI compliance costs.

The new Whistleblower Directive – what companies should do now
With the new EU Whistleblower Directive, Brussels aims to regulate and harmonize whistleblowing across the EU for the first time. Its stated objective is better protection for whistleblowers. Anyone who reports breaches of Union law or unethical conduct in or by a company should not have to fear sanctions. To achieve this, companies must create appropriate structures and preserve whistleblowers’ anonymity. We explain what this means for companies and how they can overcome the challenges.

How data protection and compliance are connected
Data protection is often neglected in many companies and ends up low on the list of priorities. Yet data protection plays a central role and occupies a special position within a company’s compliance framework.
Never miss a new obligation again
Once a month: the most important regulatory changes and security topics, summarised concisely for decision-makers. No marketing, only what matters.