Cyber Grant Blog

Cyber compliance after August 2, 2026 : why it comes down to the data

Written by CyberGrant Team | Jul 23, 2026 3:19:52 PM

Cyber compliance after August 2: why it comes down to the data

With the AI Act's transparency obligations live from August 2, 2026, Europe adds the last piece to a regulatory mosaic that ties together NIS2, DORA, the Cyber Resilience Act, and the Cyber Solidarity Act. For anyone running an Italian company, the practical question narrows to one: does the data stay protected and provable even when it leaves the systems that hold it? A practical guide for CEOs, CISOs, and CIOs.

In short

  • From August 2, 2026, the transparency obligations of Article 50 of the AI Act apply to chatbots, synthetic content, and deepfakes, with penalties up to 15 million euros or 3% of worldwide turnover.
  • Beneath different legal wording, GDPR, NIS2, and DORA converge on one technical demand: encrypt the data, control who accesses it, and be able to prove it in an audit.
  • The numbers show where the risk falls: in Italy serious incidents rose 42% in 2025 (Clusit 2026); insiders and shadow AI remain among the costliest vectors (IBM 2025).
  • The lever that holds when perimeter defenses give way is protection applied to the data itself: encryption at the source, persistent, verifiable.

 

August 2, 2026 is not just another date for anyone in Italy who uses artificial intelligence to work. From that day, the transparency obligations set out in Article 50 of Regulation (EU) 2024/1689, the AI Act, come into force. The European Commission spelled them out in its guidelines on the implementation of Article 50, a text that specialized portals such as artificialintelligenceact.eu (Future of Life Institute) have helped make readable for businesses. The document clarifies that the obligations fall on both providers and deployers in four situations: when AI interacts directly with people, when it generates or manipulates synthetic content in text, images, audio, or video, when it recognizes emotions or categorizes people on a biometric basis, and when it produces deepfakes or published text meant to inform on matters of public interest. They apply to any system used in those contexts and can stack on the same system, drawing in different players along the chain.

The Commission itself notes that the guidelines are not binding, and that authoritative interpretation rests with the Court of Justice of the European Union. What remains is the operational text through which Brussels tells businesses, media, and public bodies how to move. The practical message is blunt: whoever fails to comply risks penalties up to 15 million euros or 3% of total annual worldwide turnover, whichever is higher.

 

Why August 2 is the last piece of a bigger design

Read as an isolated requirement, the deadline shows only half the picture. In the preceding weeks the Commission framed five instruments as parts of a single European model of digital resilience. The Cyber Resilience Act introduces security and vulnerability-management requirements across the life cycle of digital products. The AI Act governs the risks of artificial intelligence systems and models. The NIS2 Directive imposes technical and organizational risk-management measures on essential and important entities. DORA does the same for the financial sector. The Cyber Solidarity Act strengthens Europe's capacity to detect and respond to large-scale incidents.

Taken one at a time, they look like five separate requirements, each with its own scope and calendar. Read together, they point in a single direction. And artificial intelligence, which makes attacks more automated and scalable, is the reason the emphasis falls on the resilience of the whole system.

 

What the rules actually ask, beneath the legal language

Search these texts for the word "product" and you will not find it. What you find, repeated in different formulas, is the same need. GDPR, in Article 32, calls for adequate technical measures and names encryption among the first examples. NIS2, among its risk-management measures, lists access control and cryptography, and it requires incident notification within tight windows: an early warning within 24 hours, an update within 72, a final report within one month. DORA, for financial entities, prescribes encryption policies for data at rest and in transit, access management based on least privilege, and strict control over ICT suppliers and subcontractors.

There is a detail in the AI Act guidelines that confirms the direction. Among the techniques indicated for marking generated content, the Commission cites cryptographic methods to prove origin and authenticity. Even when the subject is artificial intelligence, trust is built on the proof of the data's origin. Three regulations born in different contexts, one denominator that keeps returning: protect the data as such and know who accesses it, with the ability to demonstrate it after the fact.

 

Why the perimeter model no longer holds

The Data Loss Prevention solutions most companies adopted over the years rest on one assumption: data lives inside the corporate perimeter and must be intercepted when it tries to leave. That was reasonable when files lived on internal servers and the escape routes were few and watchable. That world has dissolved. Today a document is born in the cloud, passes through a personal device, gets shared with a supplier, pasted into an AI tool, synced to services that IT does not even track. The controls at the boundary still work. The problem lies in the premise beneath them. Once content crosses the barrier and travels in the clear, nothing is left to protect it. And an incident that exposes readable data has no closing date: that information stays usable for years. The opposite direction has existed for a while and has a name, file-centric protection: security travels with the document, not with the network that hosts it.

 

What the numbers say about where the risk falls

Recent data helps us look at the right spot. According to the Clusit 2026 Report, in 2025 known serious incidents worldwide reached 5,265, up 48.7% on the prior year, the sharpest rise ever recorded; in Italy serious incidents rose 42%, and roughly one in three was classified as critical or extreme in severity. The same source notes that generative AI is now used by attackers as a force multiplier.

The IBM Cost of a Data Breach Report 2025 adds the economic measure. The global average cost of a breach fell to 4.44 million dollars, while in the United States it climbed to 10.22 million, an all-time high driven partly by rising regulatory fines. The costliest vector, for the second year running, is the malicious insider: 4.92 million dollars per breach, just above the compromise of suppliers and the supply chain. This is exactly the point security plans tend to overlook. The hardest threat to stop is someone who holds legitimate access and uses it beyond their remit, and against the insider the boundary barrier by definition never triggers.

 

How shadow AI brought the risk inside the organization

There is a second front, more recent, that the AI Act frames from the transparency side and the data frame from the cost side. Call it shadow AI: the ungoverned use of artificial intelligence tools by employees. An employee pastes a confidential contract into a public assistant to summarize its clauses, and in that instant the data leaves the company's control. According to IBM, in 2025 one breach in five involved shadow AI, and where it was widespread the average incident cost rose by 670,000 dollars. Sharper still is another finding: among organizations that reported breaches of their own AI systems, 97% had no adequate controls over AI access.

Banning the tools is impractical and does little. The real work sits upstream: govern the data before it enters the model, know which information can be processed and by whom, and keep a private alternative inside the perimeter when the content is sensitive. This is the logic of on-premise private AI: an engine like AIGrant classifies and processes documents while staying inside the company's infrastructure, without exposing them to a public model. If you want, you can add it alongside the assistants already in use, keeping only the content that must not leave in a controlled environment.

 

Why encryption is what holds when everything else gives way

Here returns the lever every rule cites and few companies use to the full. If the data exfiltrated in a breach stays encrypted and unintelligible, Article 34 of GDPR can remove the obligation to notify the individuals affected: in that case encryption contains the impact once prevention has already failed. IBM's economic analysis confirms it, ranking encryption among the most effective factors in lowering the cost of a breach, with average savings above 200,000 dollars per incident. On the other side, non-compliance with regulation is among the factors that push that cost up.

Then there is a silent deadline that leadership rarely puts on the books. Data encrypted today with traditional algorithms is being collected by attackers who count on decrypting it tomorrow, once computing power allows. For information meant to stay confidential for a decade, the shift to post-quantum cryptography, with the standards NIST selected such as CRYSTALS-Kyber (FIPS 203), stops being a lab topic and becomes a governance decision. This is the terrain of FileGrant's Lock&Go encryption, quantum-safe and built on CRYSTALS-Kyber, designed so that protection stays attached to the file even after it is shared. It reflects one of the three trends reshaping the CISO agenda for 2026. See how FileGrant applies it in practice.

 

Who is accountable for data security today

What the most recent rules share is the question of who answers. NIS2, transposed in Italy through Legislative Decree 138/2024, assigns direct responsibility to the management bodies, with personal sanctions reaching up to suspension from management duties. DORA places ultimate responsibility for ICT risk on the management body. And the ACN Determination of April 13, 2026 made NIS2 operational in Italy by moving the bar from declaration to proof: what counts is demonstrable resilience, with real processes and verifiable data, and the supply chain moves to the center of the obligation. From January 1, 2026 entities in scope notify incidents; by October 2026 they must complete baseline security measures and oversee their supply chain.

For CEOs, CISOs, and CIOs this translates into a few operational questions, worth asking before the next audit:

  • Do we know where the critical data is, even when it leaves for suppliers, consultants, and unmonitored cloud tools?
  • Are the most sensitive files encrypted at the source, so they stay protected even outside our systems?
  • Can we revoke access to a document after sharing, and prove in a log who accessed it, when, and from which device?
  • Is there a governed alternative to public AI tools for confidential content?
  • Is accountability for the data explicitly assigned to the levels the rules name?

These are questions of corporate governance before they are questions of technology, and the answers end up in the file an authority can ask to see.

 

Where it pays to arrive first

For years security was treated as a property of the network: higher walls, tighter controls at the boundary. That boundary now shifts every time a file is shared, synced, or fed to a model. As long as protection stays attached to the environment and not to the content, every new European obligation will find Italian companies chasing the same moving perimeter, requirement after requirement. The resilience Europe asks for, from August 2 and in the deadlines that follow, is built on the data. It is the bet on which CyberGrant builds its file-centric platform, and it pays to get there before a penalty is the thing that reminds you.

 

 

Frequently asked questions

 

What changes from August 2, 2026 under the AI Act?

From August 2, 2026, the transparency obligations of Article 50 of Regulation (EU) 2024/1689 apply. Providers and deployers of AI systems must make it recognizable when content is generated or manipulated by AI, when a chatbot interacts with a person, and when deepfakes are produced. The obligations cover both providers and deployers and can stack on the same system.

What penalties does Article 50 of the AI Act carry?

Breaching the transparency obligations can cost up to 15 million euros or 3% of total annual worldwide turnover, whichever is higher. The European Commission's May 2026 guidelines clarify the scope but are not binding: authoritative interpretation rests with the Court of Justice of the European Union.

What do GDPR, NIS2, and DORA ask in common about data?

Three recurring technical requirements: encrypt the data, control who accesses it, and be able to prove it in an audit. GDPR names encryption in Article 32, NIS2 lists access control and cryptography among its risk-management measures, and DORA requires encryption policies for data at rest and in transit in the financial sector.

What is shadow AI and why is it a risk for companies?

Shadow AI is the ungoverned use of artificial intelligence tools by employees, for example pasting a confidential contract into a public assistant. According to IBM, in 2025 one breach in five involved shadow AI, at an average cost 670,000 dollars higher; 97% of the affected organizations had no adequate AI access controls.

Can encryption reduce the obligation to notify a breach?

Yes. If exfiltrated data stays encrypted and unintelligible, Article 34 of GDPR can remove the obligation to notify the individuals affected. Encryption contains the impact once prevention has already failed, and per IBM 2025 it lowers the average cost of a breach by more than 200,000 dollars.

What is post-quantum cryptography and why does it matter now?

It is a family of algorithms designed to resist quantum computers. The risk is already concrete under the "harvest now, decrypt later" logic: data encrypted today is collected to be decrypted later. In August 2024 NIST standardized the first post-quantum algorithms, including CRYSTALS-Kyber (FIPS 203). For information that must stay confidential for a decade, the shift is a governance decision.

Who is accountable for data security under NIS2 and DORA?

The management bodies. NIS2, transposed in Italy through Legislative Decree 138/2024, assigns direct responsibility to top management, with personal sanctions up to suspension from management duties. DORA places ultimate responsibility for ICT risk on the management body. The ACN Determination of April 13, 2026 moved the bar from declaration to proof, putting the supply chain at the center of the obligation.