European security and compliance teams are facing significant challenges in operationalizing regulatory requirements, particularly in areas such as AI incident response and software supply chain visibility. Reports indicate that while regulatory frameworks like GDPR and upcoming AI regulations are well established on paper, many organizations in France, Germany, and the UK lag behind global averages in adopting AI anomaly detection and training data recovery capabilities. Additionally, the adoption of software bill of materials (SBOM) management and secure software development lifecycle (SDLC) practices remains limited, exposing persistent gaps in supply chain security.
The increasing use of generative AI tools, personal cloud services, and unsanctioned applications is compounding these operational challenges, leading to a rise in data policy violations and cloud-based risks. Security teams are advised to enhance monitoring and control over data movement across both managed and unmanaged cloud services, as well as to address persistent threats such as phishing. The evolving landscape underscores the need for European organizations to bridge the gap between regulatory compliance and practical, day-to-day security operations to effectively manage emerging risks.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Netskope's Cloud and Threat Report 2026 reported a sharp increase in generative AI-related data violations in enterprise environments. The report also highlighted risks from unsanctioned cloud apps, phishing for cloud credentials, and emerging agentic AI systems, urging stronger visibility and AI-aware security controls.
A Kiteworks report found that European organizations have strong regulatory frameworks such as GDPR and the upcoming AI Act, but lag in operationalizing security and compliance controls. It highlighted below-average adoption of AI-specific incident response, SBOM management, third-party risk coordination, compliance automation, and cross-border AI governance measures.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.