CSA2: analysis of EU countries’ positions on proposed framework restricting high-risk suppliers
01 September 26
Visiola Pula
According to a document prepared by the Council’s general secretariat and seen by Cullen International, several member states raised concerns over the proposed mechanism to designate high-risk suppliers (HRS) under the Cybersecurity Act 2 (CSA2). They called for an assessment in which suppliers’ links to countries posing cybersecurity concerns are treated as a risk indicator rather than a determining factor. Regarding telecoms networks, several member states questioned the proposed EU-wide three-year timeline for phasing out HRS components from 5G networks, favouring greater flexibility to account for national circumstances and the equipment lifecycles.
European Commission publishes guidance on how new cybersecurity rules for products with digital elements apply to free and open-source software
11 August 26
Alessandra Vaes
This Flash highlights the main aspects addressed in the guidance on the Cyber Resilience Act (CRA) related to free and open-source software (FOSS). It provides examples where FOSS is considered to be supplied during a commercial activity and hence placed on the market, triggering the obligations for manufacturers. The guidance also clarifies the concept of stewards and when they would be subject to the CRA reporting obligations. A steward sustains and supports FOSS intended for commercial use but does not place the software on the market.
European Commission’s guidance clarifies key provisions of new cybersecurity rules for products with digital elements
09 August 26
Alessandra Vaes
The guidance sets out the Commission’s interpretation of certain provisions of the Cyber Resilience Act (CRA) and provides practical examples on their implementation. This Flash highlights some of the main aspects addressed in the guidance, including products designed before the CRA becomes applicable on 11 December 2027, remote data processing solutions, and conformity assessment for products posing a higher risk.
Panama unveils National Advanced Technologies Agenda, deepens industrial ties with US
08 August 26
Jose Jehuda Garcia
The government of Panama formally launched its National Advanced Technologies Agenda, which consists of two core state strategies: the new National Artificial Intelligence Strategy and the 2025 National Strategy for Semiconductors and Microelectronics. The aim is to position the country as a regional technology hub, particularly as a secure transit node for the technology supply chain. US involvement plays an important role in the background.
AI Omnibus enters into force, application of rules for high-risk AI systems delayed
27 July 26
Javier Huerta Bravo
The AI Omnibus, amending key provisions of the AI Act, entered into force on 27 July 2026, following its publication in the Official Journal of the EU.
AI Omnibus: analysis of core amendments to EU AI Act
22 July 26
Elisar Bashir
The AI Omnibus introduces a fixed timeline for the delayed application of the rules for high-risk AI systems, clarifies the definition of a safety component, streamlines the conformity assessment procedure for products under EU harmonisation legislation, and adds a new ban on “nudification” applications.