Cerca per


Consob - Sperimentazione dell’IA nell’azione di contrasto agli abusivismi finanziari

Pubblicato il Quaderno Fintech “Sperimentazione dell’IA nell’azione di contrasto della Consob agli abusivismi finanziari”. Lo studio presenta un prototipo messo a punto dalla Consob in collaborazione con il Politecnico di Torino e l’Università Politecnica delle Marche. Lo sviluppo sperimentale di strumenti di intelligenza artificiale nelle attività di contrasto dell’abusivismo finanziario consentirà alla Consob di disporre di un sistema basato su una combinazione di algoritmi utile ad efficientare i processi di vigilanza. La supervisione e il coordinamento umano restano presupposti imprescindibili per garantire affidabilità dei risultati, trasparenza e spiegabilità delle fasi valutative e decisionali nonché la coerenza con il quadro normativo europeo e nazionale

Leggi dettaglio

Guidelines on transparency obligations for providers and deployers of certain AI systems

The European Commission published guidelines to assist providers and deployers of artificial intelligence (AI) systems in meeting the AI Act's transparency obligations, which start to apply on 2 August 2026. A person interacts with an AI interface, data charts, and code, symbolizing AI-driven development. Transparency obligations will help people recognise when they are interacting with AI or when content has been generated or altered by AI, reducing the risk of deception and manipulation. The guidelines clarify which providers and deployers must comply with the transparency obligations for interactive AI systems and the marking and labelling of AI-generated content. Under the AI Act, AI providers will have to design AI systems to inform users when they are directly interacting with an AI and they will have to add machine-readable marks to enable the detection of AI-generated or manipulated content. Deployers will also have to inform people when they are exposed to deep fakes, to AI-generated content on matters of public interests without human review or editorial control, and to emotion recognition or biometric categorisation systems

Leggi dettaglio

Banca d'Italia: Comunicazione al mercato in materia di resilienza operativa digitale e modelli avanzati di Intelligenza Artificiale

La Banca d'Italia invita gli intermediari direttamente vigilati ad adottare le misure necessarie per rafforzare i processi di gestione dei rischi e i presidi di sicurezza a tutela dei propri sistemi informatici. L'iniziativa rientra tra quelle della Banca d'Italia, volte a rafforzare la resilienza operativa degli intermediari ed è in linea con quella delle altre Autorità Europee.

Leggi dettaglio

AMLA - Annual Report 2025

The report provides an overview of AMLA’s institutional development and the progress made in 2025 across its core tasks: developing the EU Single Rulebook, strengthening AML/CFT supervision and supporting cooperation between Financial Intelligence Units

Leggi dettaglio

ACN - Aggiornate le FAQ sugli obblighi degli organi di amministrazione e direttivi dei soggetti NIS

L'Agenzia per la Cybersicurezza Nazionale ha aggiornato le FAQ relative agli obblighi degli organi di amministrazione e direttivi dei soggetti NIS, integrando le FAQ ODA.8 e ODA.9 e introducendo le nuove FAQ ODA.10, ODA.11 e ODA.12. L'aggiornamento fornisce indicazioni interpretative su alcuni aspetti applicativi della disciplina NIS 2, contribuendo a chiarire il ruolo degli organi di amministrazione e direttivi nell'ambito del sistema di governance della cybersicurezza

Leggi dettaglio

UIF - Segnalazioni di operazioni sospette 1° semestre 2026

Nell'ambito della collana "Quaderni dell’antiriciclaggio-Statistiche" l'UIF ha pubblicato  "Segnalazioni di operazioni sospette 1° semestre 2026". Nel primo semestre del 2026 l’Unità di Informazione Finanziaria ha ricevuto 90.200 segnalazioni di operazioni sospette (SOS), il valore semestrale più elevato finora registrato. Rispetto al corrispondente periodo del 2025 le segnalazioni sono aumentate dell’11,6 per cento (+9.373 unità). Nello stesso periodo la UIF ha analizzato 90.049 segnalazioni, con una crescita del 10,7 per cento rispetto al primo semestre dell’anno precedente

Leggi dettaglio

Consob - Al via la prima fase di Esap, il punto di accesso unico europeo ai dati su imprese, Pmi, mercati finanziari e sostenibilità

Dal 10 luglio 2026 ha preso avvio la prima fase dell’Esap, l’European Single Access Point, il punto di accesso unico europeo alle informazioni pubbliche relative a imprese, Pmi, servizi finanziari, mercati dei capitali e sostenibilità. L’iniziativa, prevista dalla normativa europea, punta a rendere più semplice e centralizzata la consultazione dei dati pubblici su società e operatori del mercato. L’Esap, che verrà gestito dall’Esma, sarà pienamente operativo e aperto alla consultazione da parte del pubblico entro il 10 luglio 2027. L’attuazione dell’Esap avverrà progressivamente, in tre fasi. La prima riguarda i flussi informativi previsti dalla Direttiva Transparency, dal Regolamento Prospetto e dal Regolamento sulle vendite allo scoperto, noto anche come Regolamento Short Selling. Nella fase iniziale le informazioni saranno raccolte dai collection bodies e dall’Esma e saranno poi rese pubbliche sulla piattaforma Esap non appena questa sarà operativa e accessibile al pubblico

Leggi dettaglio

Decreto legislativo 10 giugno 2026, n. 122

Pubblicato in GU n. 156 dell'8 luglio 2026 il D.Lgs. 10 giugno 2026, n. 122 recante il recepimento degli articoli 11, 12, 13 e 15 della direttiva (UE) 2024/1640 del Parlamento europeo e del Consiglio, del 31 maggio 2024, relativa ai meccanismi che gli Stati membri devono istituire per prevenire l'uso del sistema finanziario a fini di riciclaggio o finanziamento del terrorismo, che modifica la direttiva (UE) 2019/1937, e modifica e abroga la direttiva (UE) 2015/849. Il Decreto entrerà in vigore il prossimo 23 luglio

Leggi dettaglio

EDPB - Consultations: Guidelines on anonymisation and Guidelines on web scraping in the context of generative AI

The new EDPB guidelines on anonymisation bring clarity to the notion of anonymous data. The guidelines also provide a practical framework for organisations to determine if anonymisation is successful. The framework can be applied in two ways: either by assessing differences in capabilities between those who might identify the individual (‘contextual approach’) or for simplicity’s sake by not taking such differences into account (‘simplified approach’), if a controller chooses to do so. The simplified approach can go beyond the legal standard and may lead an anonymising controller to treat data as though it is not anonymous even if it would actually be so for some relevant entities, but this approach can be more convenient, and provide greater confidence that data is actually anonymous. The framework uses 3 criteria to test if data is anonymous: 1) no record isolation, 2) no linkage, and 3) no inference. If all 3 criteria are met, the data can be safely considered anonymous. If any of these criteria are not satisfied, further analysis should be done to determine if the data may be considered anonymous. Web scraping is a large-scale automated data extraction process that often operates without individuals being aware, and which may pose significant risks to the protection of their personal data. In its guidelines on web scraping in the context of generative AI, the Board clarifies various aspects of the GDPR compliance of web scraping, including the legal basis for such activities and the conditions under which special categories of data can be processed in this context. The GDPR applies to web scraping when it includes personal data processing operations, such as collection, storage, organisation and retrieval. The guidelines provide further clarifications and examples on the use of the legitimate interest legal basis in the specific context of web scraping for AI training. Both guidelines will be subject to public consultation until 30 October 2026

Leggi dettaglio

Banca d'Italia - Quadro segnaletico di Vigilanza dei gravi incidenti ICT: Analisi orizzontale 2025

Il rapporto sintetizza le evidenze raccolte a livello nazionale tramite lo schema di segnalazione istituito dal Dipartimento di Vigilanza, in linea con le previsioni del regolamento DORA. In particolare, il rapporto evidenzia che: (i) nel corso del 2025, 101 singoli eventi hanno dato luogo a 137 segnalazioni, inviate perlopiù da banche e gruppi bancari; (ii) la maggior parte degli incidenti è di natura operativa ed è prevalentemente associata a malfunzionamenti dei sistemi, in particolare di tipo software, seguiti da problemi di rete; (iii) gli eventi relativi alla cybersicurezza rappresentano il 23% del totale e riguardano soprattutto casi di esfiltrazione di dati, seguiti da attacchi alla catena di fornitura e da attacchi ransomware; (iv) in oltre la metà delle segnalazioni è coinvolto un fornitore o subfornitore di servizi; (v) sotto il profilo degli impatti, l’interruzione dei servizi continua a costituire la conseguenza più frequente (70% del totale), mentre le perdite economiche risultano nel complesso concentrate in un numero limitato di casi di maggiore severità

Leggi dettaglio

AMLA - Final Report: Draft RTS on pecuniary sanctions, administrative measures and periodic penalty payments under Art. 53(10) AMLD

The new standards advance one of AMLA's core goals: harmonised, risk-based supervision across the EU. Until now, the same breach in the same situation could draw very different enforcement outcomes from one supervisor or country to the next. The new set of rules provides every supervisor with a common approach to assessing the gravity of breaches, leading to consistent enforcement outcomes across the EU while preserving proportionality, effectiveness and dissuasiveness. Supervisors in the EU will follow a common, step-by-step method. They first weigh the level of gravity of a breach against a shared set of indicators, including how long it lasted, whether it was repeated, and what impact it had. The breach is then classified into one of four levels of gravity, and common criteria guide supervisors to determine the appropriate enforcement outcome. The standards apply to all sectors covered by AML rules, financial and non-financial alike. Once adopted by the European Commission, they will apply directly and become legally binding in all EU Member States

Leggi dettaglio

ESMA - Common Supervisory Action on CASPs’ digital operational resilience for custody

ESMA is launching a Common Supervisory Action (CSA) focusing on the digital operational resilience of Crypto-Asset Service Providers (CASPs), with a specific emphasis on custody services. The CSA will assess the maturity of CASPs’ digital operational resilience frameworks in relation to custody activities. It will focus on risks inherent to distributed ledger technology (DLT), including governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and dependencies on third-party providers. National Competent Authorities (NCAs) will carry out the exercise on a risk-based sample of authorised CASPs. The exercise will run from the second half of 2026 to the first half of 2027   The findings collected from NCAs will be consolidated into a final report, which will be submitted to ESMA’s Board of Supervisors following the conclusion of the exercise in the second half of 2027

Leggi dettaglio

ESMA - Deprioritisation of supervisory actions in relation to the mechanical issuance of invoices under the RTS on Reasonable Commercial Basis

ESMA recalls that the RTS on RCB applies in full to market data providers within its scope  from 23 August 2026. ESMA recognises that certain requirements under the RTS on RCB, in particular those relating to fee schedules and units of count, are operationally reflected through invoicing systems that  follow predefined billing cycles. In limited circumstances, this may give rise to practical challenges in aligning the mechanical issuance of invoices exactly with the application date.  Against this background, from 23 August 2026 until 30 September 2026, as part of a coordinated approach, ESMA expects NCAs not to prioritise supervisory actions in relation to the application of fees and the corresponding issuance of invoices reflecting revised fee schedules. This statement is limited to that operational issue.      

Leggi dettaglio