Kortave
Back to Kortave

[ The Kortave Brief ]

EU Compliance Intelligence

Analysis, guides, and regulatory updates from the Kortave compliance team.

FeaturedAI Act

Eight Weeks to the EU AI Act High-Risk Deadline: What Is Still Missing in Most Compliance Files

The full obligations for high-risk AI systems apply from 2 August 2026. With eight weeks remaining, most compliance files are incomplete in the same three places. Here is what to fix first.

4 June 202610 min readRead article →
GDPR

Every AI Tool Your Company Uses Is a GDPR Liability — Most Legal Teams Have Not Noticed Yet

Microsoft Copilot, ChatGPT Enterprise, and their equivalents process employee and client data at scale. Without DPAs, ROPAs entries, and transfer impact assessments in place, you are already non-compliant.

2 June 20269 min read
NIS2

NIS2 in Practice: What a Compliant Incident Response Actually Looks Like

NIS2 has a 24-hour early warning requirement, a 72-hour notification, and a 1-month final report. Most companies discover their incident response process does not trigger fast enough. Here is what it needs to look like.

28 May 20269 min read
CRA

The Cyber Resilience Act: What Product Companies Must Do Before December 2027

The CRA makes cybersecurity a legal obligation for any hardware or software product sold in the EU. Here is what manufacturers and developers need to know — and do.

10 May 20258 min read
Data Act

EU Data Act: What Changes for IoT Manufacturers and Cloud Providers in 2025

The EU Data Act applies from September 2025. It gives users the right to access device-generated data, requires fair B2B data-sharing terms, and reshapes cloud switching rules.

8 May 20257 min read
ePrivacy

Cookie Consent in 2025: What ePrivacy Requires and Where Companies Are Still Getting It Wrong

Cookie consent fines exceeded €500M across the EU in the past two years. Most violations share the same root cause: ignoring what "freely given" consent actually means.

6 May 20256 min read
DORA

DORA Is Already in Force. Your ICT Contracts Probably Are Not Ready.

DORA's contractual requirements for ICT third-party arrangements are specific, mandatory, and not optional by agreement. Most financial firms are behind.

5 May 20258 min read
DSA

DGA and DSA: Two EU Laws That Are Already in Force and Still Widely Misunderstood

The Data Governance Act and Digital Services Act are both fully applicable. Here is what each law requires, who is in scope, and the enforcement actions you need to know about.

4 May 20258 min read
NIS2

NIS2 Is Being Enforced. Here Is Who Is Actually Liable.

NIS2's management liability provision is the provision most companies have not read. Directors can be personally fined and temporarily banned from management roles.

28 April 20257 min read
GDPR

GDPR in 2025: The Five Things SaaS Companies Keep Getting Wrong

Fines are up 143% year-on-year. Most of them trace back to the same five operational failures — none of which require a lawyer to fix.

14 April 20257 min read
AI Act

EU AI Act Compliance: Your Checklist Before the August 2026 Deadline

High-risk AI obligations land in full on 2 August 2026. Most companies affected haven't started. Here's exactly what you need to have in place.

28 March 20259 min read
GDPR

GDPR Data Transfers in 2025: What SCCs Actually Require You to Do

Standard Contractual Clauses are not a checkbox. They require a Transfer Impact Assessment before you sign them. Most companies skip this step entirely.

10 March 20256 min read
AI Act

The EU AI Act and Foundation Models: What GPAI Compliance Actually Looks Like

General Purpose AI obligations under the AI Act apply to any model that can be used across multiple purposes. Most companies using LLM APIs are deployers, not providers — but the distinction matters.

18 February 20259 min read
NIS2

NIS2 Is Being Enforced. Here's What Most Companies Haven't Done Yet.

The NIS2 Directive has been national law across most EU member states since late 2024. Supervisory authorities are already investigating. The gaps they're finding are predictable.

17 February 20258 min read
AI Act

The EU AI Act: A Complete Guide to the World's First AI Regulation

History, risk tiers, high-risk AI obligations, GPAI model requirements, and key enforcement dates. Everything a business needs to know about the EU AI Act.

5 February 202512 min read
GDPR

The General Data Protection Regulation: A Complete Guide for Businesses

Where GDPR came from, who it applies to, what the core principles mean in practice, and what it actually requires your organisation to do.

20 January 202511 min read
GDPR

Your GDPR Deletion Backlog Is Your Biggest Legal Risk Right Now

Most companies know they have unprocessed erasure requests. Very few understand how their exposure compounds with each passing day — or how quickly it becomes a material fine.

9 January 20256 min read
NIS2

NIS2 and DORA: The EU's Cybersecurity and Resilience Regulations Explained

NIS2 is enforced and management liability is real. DORA has been in force since January 2025. A comprehensive guide to both regulations — scope, obligations, and what to do.

8 January 202513 min read

Stay ahead of enforcement

Get our latest compliance analysis delivered to your inbox. No noise, just signal.