<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Kilde — compliance radar &amp; updates</title><link>https://trykilde.com/updates/</link><description>Dated, verified updates on EU and HK regulatory deadlines: CRA, EmpCo, AI Act Article 50, PLD, SWIFT CSP, HK banking.</description><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><item><title>The CRA reporting duty is in force</title><link>https://trykilde.com/updates/#2026-09-11-cra-duty-in-force</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-09-11-cra-duty-in-force</guid><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><description>As of 11 September 2026 the Cyber Resilience Act&#x27;s Article 14 duty applies: an actively exploited vulnerability or a severe incident in an in-scope product must reach ENISA and the designated CSIRT as an early warning within 24 hours of awareness, with a notification at 72 hours and a final report after that — and by Article 69(3) that covers every in-scope product already on the EU market. We have not re-verified the reporting platform&#x27;s go-live status against ENISA&#x27;s page today; the obligation to notify does not depend on it. The CRA guides and radar now read in the present tense.</description></item><item><title>New Product Liability Directive verified: 9 December 2026, software expressly in scope</title><link>https://trykilde.com/updates/#2026-08-26-pld-on-the-radar</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-08-26-pld-on-the-radar</guid><pubDate>Wed, 26 Aug 2026 00:00:00 +0000</pubDate><description>We read Directive (EU) 2024/2853 verbatim at EUR-Lex today. Three anchors: it applies to products placed on the market or put into service &lt;b&gt;after 9 December 2026&lt;/b&gt;; Member States must transpose &lt;b&gt;by 9 December 2026&lt;/b&gt;; and the 1985 directive is repealed with effect from the same date. The definition settles the software question in five words — &#x27;product&#x27; means all movables and &lt;i&gt;includes electricity, digital manufacturing files, raw materials and software&lt;/i&gt; — with free and open-source software outside a commercial activity carved out. For software and device makers this is the next fuse after the CRA&#x27;s reporting duty; a guides cluster is in preparation.</description></item><item><title>CRA Annex III/IV category lists verified verbatim — 26 category guides live</title><link>https://trykilde.com/updates/#2026-08-26-cra-annexes-verified</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-08-26-cra-annexes-verified</guid><pubDate>Wed, 26 Aug 2026 00:00:00 +0000</pubDate><description>We verified the Cyber Resilience Act&#x27;s important and critical product lists word for word against the Official Journal text at EUR-Lex: 19 Class I categories, 4 Class II, 3 critical. One guide per category is now live, each carrying the verbatim listing plus what the tier changes — and what it doesn&#x27;t (the 11 September reporting duty is class-blind).</description></item><item><title>CRA harmonised standards slip to ~30 October — Class I still has no self-assessment path</title><link>https://trykilde.com/updates/#2026-08-20-standards-slip</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-08-20-standards-slip</guid><pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate><description>The first-citation timeline for CRA harmonised standards moved to around 30 October 2026 (it has slipped before — treat as an estimate). Until a citation lands, Class I products cannot use the self-assessment route: conformity budgeting should assume a notified body, with the citation treated as good news if it arrives.</description></item><item><title>ENISA revises the reporting-platform submission guide</title><link>https://trykilde.com/updates/#2026-08-14-enisa-ar-guide</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-08-14-enisa-ar-guide</guid><pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><description>The Assigned Representative notification guide was revised again (summarized from the revision notes; ENISA marks all platform documentation subject to change). Notable mechanics: a notification cap for unverified ARs, drafts private per representative, and CSIRT-side handling details. The platform itself remains pre-launch, targeted operational by 11 September.</description></item><item><title>Anthropic announces text watermarking — announced is not live</title><link>https://trykilde.com/updates/#2026-08-11-anthropic-watermark-announced</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-08-11-anthropic-watermark-announced</guid><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><description>Anthropic announced model-level text watermarking plus C2PA on file outputs under its Code of Practice commitment. Read the announcement&#x27;s tense: &lt;i&gt;future&lt;/i&gt; models will generate watermarked text, with detection tooling &#x27;soon&#x27;. Until a go-live is verified, treat current outputs as unmarked — compliance evidence is what your pipeline actually emits, not what a vendor intends.</description></item><item><title>Official EU AI icons published — voluntary, and visible-layer only</title><link>https://trykilde.com/updates/#2026-08-10-eu-ai-icons</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-08-10-eu-ai-icons</guid><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><description>The Commission&#x27;s icon set went live: three icons (AI interaction, fully AI-generated, partially AI-modified) in four variants, free to use without attribution. Two framing facts from the Commission itself: the icons are voluntary while the labelling requirements are not, and icon-plus-text outperforms either alone. They serve the visible disclosure duties — they do nothing for machine-readable marking.</description></item><item><title>Commission publishes CRA application guidance</title><link>https://trykilde.com/updates/#2026-07-27-cra-guidance</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-07-27-cra-guidance</guid><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><description>The Commission&#x27;s application guidance for the Cyber Resilience Act landed, covering scope boundaries (remote data processing, open source) and interplay questions. Still outstanding at our verification date: the SME technical-documentation form and the first harmonised-standard citation.</description></item><item><title>Digital Omnibus in the Official Journal: the 2 December marking grace becomes law</title><link>https://trykilde.com/updates/#2026-07-24-omnibus-oj</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-07-24-omnibus-oj</guid><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><description>Regulation (EU) 2026/1744 published (in force 27 July). Its entire effect on AI transparency: generative systems placed on the market before 2 August 2026 get until 2 December 2026 for machine-readable marking. New systems get no runway, and the disclosure duties get no grace at all. The high-risk delays (Annex III to December 2027, Annex I to August 2028) are separate provisions.</description></item><item><title>Final Article 50 guidelines adopted: agents, editorial review, exclusions settled</title><link>https://trykilde.com/updates/#2026-07-20-final-guidelines</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-07-20-final-guidelines</guid><pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate><description>The Commission adopted the final Article 50 guidelines (51pp, non-binding, 24 languages). The load-bearing deltas: AI agents must disclose their artificial nature and whose behalf they act on; the text exemption requires deliberate substance review with editorial responsibility (cursory sign-off insufficient, post-review AI edits void it); wholly fantastical content is excluded from deepfake scope but the boundary reads broadly; assistive exclusions now expressly include AI translations, source code and short outputs; and Article 50 attaches to systems, not models — the wrapper provider carries the marking duty.</description></item><item><title>Transparency Code of Practice adequacy endorsed</title><link>https://trykilde.com/updates/#2026-07-09-cop-adequacy</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-07-09-cop-adequacy</guid><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><description>The Commission (8 July) and AI Board (9 July) endorsed the transparency Code of Practice: signatories can rely on its measures to demonstrate compliance for Articles 50(2), (4) and (5). Not conclusive proof, but the cleanest demonstration route available — and late accession remains open.</description></item><item><title>SWIFT CSP 2026 attestation window opens</title><link>https://trykilde.com/updates/#2026-07-01-swift-window</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-07-01-swift-window</guid><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><description>KYC-SA opened for attestations against CSCF v2026: 26 mandatory + 6 advisory controls, control 2.4 (Back Office Data Flow Security) newly mandatory, and customer connectors now in-scope components of 14 controls — the redefinition that moves some browser-only institutions to Architecture A4.</description></item><item><title>Green Claims Directive negotiations reported abandoned — EmpCo unaffected</title><link>https://trykilde.com/updates/#2026-06-11-gcd-abandoned</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-06-11-gcd-abandoned</guid><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate><description>The Council Presidency was reported to have abandoned negotiations on the Green Claims Directive proposal — stalled, not withdrawn, not law. The rules actually rewiring EU green marketing remain EmpCo&#x27;s twelve banned practices, applying 27 September 2026 on a date that does not move.</description></item><item><title>SFC circular 26EC29: zero tolerance on questionable documents</title><link>https://trykilde.com/updates/#2026-05-22-sfc-circular</link><guid isPermaLink="true">https://trykilde.com/updates/#2026-05-22-sfc-circular</guid><pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate><description>The SFC&#x27;s circular set zero tolerance for questionable or forged documents in onboarding and ongoing relationships, with risk-based, on-request dormant-account measures (not a blanket closure mandate). The practical read for legitimate customers under review: honest gaps explained survive; papered gaps don&#x27;t.</description></item></channel></rss>