On 24 July 2025, Teiss Talk host Thom Langford, was joined by Satyam Rastogi, Director of Information Security & DevOps, BAMKO; Mike Johnson, Global Cyber Threat & Incident Response Manager, Verifone; and Madison Dreshner, Principal of IT Risk and Compliance solutions, AuditBoard.
Meta says it won’t sign the European Union’s artificial intelligence code of practice agreement, warning that “Europe is heading down the wrong path on AI.” The code published by the EU on July 10th is a voluntary set of guidelines to help companies follow the AI Act’s rules around general-purpose AI before they come into effect in a few weeks. This comes ahead of AI Act rules coming into force on August 2nd that require general-purpose AI providers to be transparent about training and security risks for their models, and abide by EU and national copyright laws. The EU can fine companies that violate the AI Act up to seven percent of their annual sales. While META wants to join the genAI race, they still may not see clearly the use cases where they could leverage the technology. Another way of looking at this news is that while META is taking a stand here against the EU regulation, they may still comply with it eventually.
Even companies that don’t have a presence in the markets under DORA’s and NIS2’s scope may be affected by them as suppliers of businesses operating in the area. One of the main compliance challenges is to align NIS2 and DORA as pieces of legislation radically different from the ones previously mandated by the EU. Other obligations include red teaming and reporting an incident within 24 hours. DORA doesn’t distinguish between a traditional IT (e.g., a server running out of memory) and a cyber incident. In case of a serious cyber incident, you still might not know in the first 24 hours what exactly has happened. The legislation paints all financial institutions with the same brush.
Being less prescriptive, SEC cybersecurity reporting in the US has a slightly different approach from DORA, offering broad and generic statements without going into specifics regarding how to achieve compliance. DORA overlaps with general data legislation such as GDPR to a large extent, while the payment industry already has PCI to comply with. DORA mandates businesses to report an incident in the country where the most clients are impacted, which means that in countries that come second or third in terms of impact may not be notified about the incident. Detailed notification about an incident is expected to get a bit of a leeway later from 24 to 72 hours or so. New regulation also puts too much pressure on CISOs, which might in the long term result in less professionals choosing this career path.
The EU could have taken a different approach by amending existing regulation rather than creating a completely new piece that overlaps with others up to 80-90% and thus adding new ingredients to the alphabet soup of frameworks. What makes a risk-based approach trickier is that it’s harder to justify a security investment until an incident actually has happened. CISOs can transfer risk by explaining to the board what controls need to be in place to minimise risk and refrain from taking the blame if management refuses to invest in some of them. AI can be leveraged for 3P compliance to meet the requirements of the EU AI Act, DORA and NIS2.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543