Insights and updates

From emerging regulation to deal mechanics, we write about the questions founders and investors actually ask — practical analysis you can put to work.

Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment (DPIA) is a structured process to identify and minimise data protection risks of a project, system or processing activity — mandated by GDPR Article 35 when processing is “likely to result in a high risk to the rights and freedoms of natural persons”.

eIDAS 2.0 (European Digital Identity)

eIDAS 2.0 (Regulation (EU) 2024/1183) is the EU’s update to the original eIDAS framework, introducing the European Digital Identity Wallet (EUDI Wallet) — a sovereign, interoperable digital identity that EU citizens can use to identify themselves, share verified credentials and sign documents acr…

EU Data Act

The EU Data Act (Regulation (EU) 2023/2854) is the EU’s regulation establishing harmonised rules on fair access to and use of industrial and IoT data.

IFRS S1 / S2 Sustainability Disclosures

IFRS S1 (General Requirements for Disclosure of Sustainability-related Financial Information) and IFRS S2 (Climate-related Disclosures) are the first two standards issued by the ISSB in June 2023. They establish the baseline for sustainability disclosures aligned with capital-markets needs.

International Sustainability Standards Board (ISSB)

The International Sustainability Standards Board (ISSB) is the standards-setting body established by the IFRS Foundation in November 2021 to develop a global baseline of sustainability disclosure standards for capital markets.

Corporate Sustainability Reporting Directive (CSRD)

The Corporate Sustainability Reporting Directive (CSRD — Directive (EU) 2022/2464) is the EU’s framework for mandatory sustainability reporting by companies, replacing and dramatically expanding the 2014 Non-Financial Reporting Directive (NFRD).

Cyber Resilience Act (CRA)

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU’s horizontal regulation on cybersecurity requirements for “products with digital elements” — covering hardware, software, IoT, and connected services placed on the EU market.

AI Red-Teaming

AI red-teaming is structured adversarial testing of AI systems — typically LLMs and multimodal models — to discover vulnerabilities, harmful outputs, jailbreaks, prompt injection vectors, biased behavior and safety failures before deployment.

System Card

A system card is a structured public document that describes an AI system’s purpose, capabilities, limitations, training data summary, evaluation results, safety measures and known risks.