Insights

The regulatory horizon, and the risk of autonomous intelligence.

We track the European regulatory horizon and the emerging risk of agentic AI so boards can govern rather than merely comply. Below is the framework set we advise on.

Frameworks & Standards

NIS2
Directive 2022/2555 — governance and risk-management obligations for essential and important entities.
DORA
Regulation 2022/2554 — digital operational resilience for the financial sector.
EU AI Act
Regulation 2024/1689 — risk-based governance of artificial intelligence, including agentic systems.
GDPR
Regulation 2016/679 — data protection and privacy.
ISO/IEC 27001
Information security management systems (ISMS).
ISO/IEC 42001
AI management systems (AI-SMS).
NIST AI RMF
AI risk management framework.

Agentic AI security & risk

As AI agents gain autonomy, the attack surface becomes behavioural. Our advisory focuses on guardrails, kill-switches and accountability chains that keep agentic systems answerable to human intent — and on threat simulation that tests the decisions, not just the defenses.

Board advisory & liability

Personal liability exposure under the EU AI Act and GDPR, followed by NIS2 and DORA, translated into governance decisions the board can actually take and defend.