ZeroGravity Weekly Brief | January 19, 2026

This week reinforces a clear direction of travel, focusing on concrete regulatory outputs and implementation steps at EU and national level, spanning AI security standards, cybersecurity enforcement, supervisory cooperation, and digital platform obligations.

EU Level

AI security gets a baseline: ETSI EN 304223 sets baseline cybersecurity requirements for AI models and systems acrossthe full lifecycle. It addresses risks such as data poisoning and promptinjection and is likely to become a reference point for procurement, audits,and security-by-design expectations.

Read More

GDPR enforcement reminder: €42m fine forsecurity failings CNIL fined FREE MOBILE (€27m) and FREE (€15m) forcybersecurity shortcomings impacting customer data. Message is simple:regulators are still punishing fundamentals, not just cutting-edge AI edgecases.

Read More

DORA oversight goes cross-border: EUsupervisors and UK regulators signed an MoU on oversight of critical ICTthird-party providers, increasing scrutiny on concentration risk, incidentcoordination, and supplier control.

ReadMore

Council paves the way for AI gigafactories:The Council approved reforms to the EuroHPC Joint Undertaking, enabling AIgigafactories and a quantum pillar, unlocking public-private funding forlarge-scale AI compute across Europe.

ReadMore

 

Sweden Level

Digital Services Act strengthens userrights online: Sweden’s Digital Services Coordinator is PTS, working withKonsumentverket and Mediemyndigheten. Platforms must enable illegal contentreporting, explain moderation decisions, label ads, and meet stricterobligations if designated as very large.

ReadMore

NIS2 is now active in Sweden : Sweden’sCybersecurity Act and Ordinance entered into force, replacing the prior NISframework. This is the start of stricter requirements on governance, riskcontrols, and incident reporting for many operators across critical sectors.

ReadMore

Continue reading
Need help?
Contact Us