Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform
CyberGrant protects every aspect of your digital security
Discover the modular solutions designed to protect your company from external and internal threats, as well as new challenges like AI.
Digital asset protection
Automatic classification
Cloud encryption
Email protection
Anti-phishing
Malware blocking
Insider threat
Remote access
Application control
Zero trust
Zero-day defense
Surface scan
Vulnerability check
Pen Test
Ransomware simulation
Phishing test
DDoS simulation
Tailored cybersecurity for every business.
Scalable solutions compatible with legacy systems, designed for both SMEs and large enterprises requiring full control over data, access, and sharing.
Discover security features to protect your data, files, and endpoints
Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform
Control every credential like a file. Share, track, and revoke access instantly.
RemoteGrant protects your business from attacks and data loss by enabling employees to securely access workstations and files from anywhere.
Encrypt every email and keep control of attachments, even after sending.
AIGrant is your personal assistant - it understands your data, keeps it secure, and delivers exactly what you need.
With the AI Act's transparency obligations live from August 2, 2026, Europe adds the last piece to a regulatory mosaic that ties together NIS2, DORA, the Cyber Resilience Act, and the Cyber Solidarity Act. For anyone running an Italian company, the practical question narrows to one: does the data stay protected and provable even when it leaves the systems that hold it? A practical guide for CEOs, CISOs, and CIOs.
August 2, 2026 is not just another date for anyone in Italy who uses artificial intelligence to work. From that day, the transparency obligations set out in Article 50 of Regulation (EU) 2024/1689, the AI Act, come into force. The European Commission spelled them out in its guidelines on the implementation of Article 50, a text that specialized portals such as artificialintelligenceact.eu (Future of Life Institute) have helped make readable for businesses. The document clarifies that the obligations fall on both providers and deployers in four situations: when AI interacts directly with people, when it generates or manipulates synthetic content in text, images, audio, or video, when it recognizes emotions or categorizes people on a biometric basis, and when it produces deepfakes or published text meant to inform on matters of public interest. They apply to any system used in those contexts and can stack on the same system, drawing in different players along the chain.
The Commission itself notes that the guidelines are not binding, and that authoritative interpretation rests with the Court of Justice of the European Union. What remains is the operational text through which Brussels tells businesses, media, and public bodies how to move. The practical message is blunt: whoever fails to comply risks penalties up to 15 million euros or 3% of total annual worldwide turnover, whichever is higher.
Read as an isolated requirement, the deadline shows only half the picture. In the preceding weeks the Commission framed five instruments as parts of a single European model of digital resilience. The Cyber Resilience Act introduces security and vulnerability-management requirements across the life cycle of digital products. The AI Act governs the risks of artificial intelligence systems and models. The NIS2 Directive imposes technical and organizational risk-management measures on essential and important entities. DORA does the same for the financial sector. The Cyber Solidarity Act strengthens Europe's capacity to detect and respond to large-scale incidents.
Taken one at a time, they look like five separate requirements, each with its own scope and calendar. Read together, they point in a single direction. And artificial intelligence, which makes attacks more automated and scalable, is the reason the emphasis falls on the resilience of the whole system.
Search these texts for the word "product" and you will not find it. What you find, repeated in different formulas, is the same need. GDPR, in Article 32, calls for adequate technical measures and names encryption among the first examples. NIS2, among its risk-management measures, lists access control and cryptography, and it requires incident notification within tight windows: an early warning within 24 hours, an update within 72, a final report within one month. DORA, for financial entities, prescribes encryption policies for data at rest and in transit, access management based on least privilege, and strict control over ICT suppliers and subcontractors.
There is a detail in the AI Act guidelines that confirms the direction. Among the techniques indicated for marking generated content, the Commission cites cryptographic methods to prove origin and authenticity. Even when the subject is artificial intelligence, trust is built on the proof of the data's origin. Three regulations born in different contexts, one denominator that keeps returning: protect the data as such and know who accesses it, with the ability to demonstrate it after the fact.
The Data Loss Prevention solutions most companies adopted over the years rest on one assumption: data lives inside the corporate perimeter and must be intercepted when it tries to leave. That was reasonable when files lived on internal servers and the escape routes were few and watchable. That world has dissolved. Today a document is born in the cloud, passes through a personal device, gets shared with a supplier, pasted into an AI tool, synced to services that IT does not even track. The controls at the boundary still work. The problem lies in the premise beneath them. Once content crosses the barrier and travels in the clear, nothing is left to protect it. And an incident that exposes readable data has no closing date: that information stays usable for years. The opposite direction has existed for a while and has a name, file-centric protection: security travels with the document, not with the network that hosts it.
Recent data helps us look at the right spot. According to the Clusit 2026 Report, in 2025 known serious incidents worldwide reached 5,265, up 48.7% on the prior year, the sharpest rise ever recorded; in Italy serious incidents rose 42%, and roughly one in three was classified as critical or extreme in severity. The same source notes that generative AI is now used by attackers as a force multiplier.
The IBM Cost of a Data Breach Report 2025 adds the economic measure. The global average cost of a breach fell to 4.44 million dollars, while in the United States it climbed to 10.22 million, an all-time high driven partly by rising regulatory fines. The costliest vector, for the second year running, is the malicious insider: 4.92 million dollars per breach, just above the compromise of suppliers and the supply chain. This is exactly the point security plans tend to overlook. The hardest threat to stop is someone who holds legitimate access and uses it beyond their remit, and against the insider the boundary barrier by definition never triggers.
There is a second front, more recent, that the AI Act frames from the transparency side and the data frame from the cost side. Call it shadow AI: the ungoverned use of artificial intelligence tools by employees. An employee pastes a confidential contract into a public assistant to summarize its clauses, and in that instant the data leaves the company's control. According to IBM, in 2025 one breach in five involved shadow AI, and where it was widespread the average incident cost rose by 670,000 dollars. Sharper still is another finding: among organizations that reported breaches of their own AI systems, 97% had no adequate controls over AI access.
Banning the tools is impractical and does little. The real work sits upstream: govern the data before it enters the model, know which information can be processed and by whom, and keep a private alternative inside the perimeter when the content is sensitive. This is the logic of on-premise private AI: an engine like AIGrant classifies and processes documents while staying inside the company's infrastructure, without exposing them to a public model. If you want, you can add it alongside the assistants already in use, keeping only the content that must not leave in a controlled environment.
Here returns the lever every rule cites and few companies use to the full. If the data exfiltrated in a breach stays encrypted and unintelligible, Article 34 of GDPR can remove the obligation to notify the individuals affected: in that case encryption contains the impact once prevention has already failed. IBM's economic analysis confirms it, ranking encryption among the most effective factors in lowering the cost of a breach, with average savings above 200,000 dollars per incident. On the other side, non-compliance with regulation is among the factors that push that cost up.
Then there is a silent deadline that leadership rarely puts on the books. Data encrypted today with traditional algorithms is being collected by attackers who count on decrypting it tomorrow, once computing power allows. For information meant to stay confidential for a decade, the shift to post-quantum cryptography, with the standards NIST selected such as CRYSTALS-Kyber (FIPS 203), stops being a lab topic and becomes a governance decision. This is the terrain of FileGrant's Lock&Go encryption, quantum-safe and built on CRYSTALS-Kyber, designed so that protection stays attached to the file even after it is shared. It reflects one of the three trends reshaping the CISO agenda for 2026. See how FileGrant applies it in practice.
What the most recent rules share is the question of who answers. NIS2, transposed in Italy through Legislative Decree 138/2024, assigns direct responsibility to the management bodies, with personal sanctions reaching up to suspension from management duties. DORA places ultimate responsibility for ICT risk on the management body. And the ACN Determination of April 13, 2026 made NIS2 operational in Italy by moving the bar from declaration to proof: what counts is demonstrable resilience, with real processes and verifiable data, and the supply chain moves to the center of the obligation. From January 1, 2026 entities in scope notify incidents; by October 2026 they must complete baseline security measures and oversee their supply chain.
For CEOs, CISOs, and CIOs this translates into a few operational questions, worth asking before the next audit:
These are questions of corporate governance before they are questions of technology, and the answers end up in the file an authority can ask to see.
For years security was treated as a property of the network: higher walls, tighter controls at the boundary. That boundary now shifts every time a file is shared, synced, or fed to a model. As long as protection stays attached to the environment and not to the content, every new European obligation will find Italian companies chasing the same moving perimeter, requirement after requirement. The resilience Europe asks for, from August 2 and in the deadlines that follow, is built on the data. It is the bet on which CyberGrant builds its file-centric platform, and it pays to get there before a penalty is the thing that reminds you.
From August 2, 2026, the transparency obligations of Article 50 of Regulation (EU) 2024/1689 apply. Providers and deployers of AI systems must make it recognizable when content is generated or manipulated by AI, when a chatbot interacts with a person, and when deepfakes are produced. The obligations cover both providers and deployers and can stack on the same system.
Breaching the transparency obligations can cost up to 15 million euros or 3% of total annual worldwide turnover, whichever is higher. The European Commission's May 2026 guidelines clarify the scope but are not binding: authoritative interpretation rests with the Court of Justice of the European Union.
Three recurring technical requirements: encrypt the data, control who accesses it, and be able to prove it in an audit. GDPR names encryption in Article 32, NIS2 lists access control and cryptography among its risk-management measures, and DORA requires encryption policies for data at rest and in transit in the financial sector.
Shadow AI is the ungoverned use of artificial intelligence tools by employees, for example pasting a confidential contract into a public assistant. According to IBM, in 2025 one breach in five involved shadow AI, at an average cost 670,000 dollars higher; 97% of the affected organizations had no adequate AI access controls.
Yes. If exfiltrated data stays encrypted and unintelligible, Article 34 of GDPR can remove the obligation to notify the individuals affected. Encryption contains the impact once prevention has already failed, and per IBM 2025 it lowers the average cost of a breach by more than 200,000 dollars.
It is a family of algorithms designed to resist quantum computers. The risk is already concrete under the "harvest now, decrypt later" logic: data encrypted today is collected to be decrypted later. In August 2024 NIST standardized the first post-quantum algorithms, including CRYSTALS-Kyber (FIPS 203). For information that must stay confidential for a decade, the shift is a governance decision.
The management bodies. NIS2, transposed in Italy through Legislative Decree 138/2024, assigns direct responsibility to top management, with personal sanctions up to suspension from management duties. DORA places ultimate responsibility for ICT risk on the management body. The ACN Determination of April 13, 2026 moved the bar from declaration to proof, putting the supply chain at the center of the obligation.