Artificial intelligence is advancing at a pace that outpaces the adaptive capacity of many organizations and their governance frameworks. Both the public and private sectors face the challenge of incorporating this technology securely, responsibly, and in accordance with an increasingly demanding regulatory environment. Against this backdrop, the The ISACA European Conference 2026 will meet in Munich from October 7-9, to more than 50 international speakers to analyze how to strengthen supervision, manage risk and develop resilience in the face of new technological challenges.
The meeting coincides with the organizations' preparations for the implementation of the European Union Artificial Intelligence Actalong with other standards such as NIS2, DORA, and the Cyber Resilience Act. Together, these frameworks are redefining the requirements for governance, operational resilience, and digital trust as artificial intelligence becomes increasingly integrated into the activities of businesses and institutions.
The AI Act marks a turning point in regulation
As of August 2, 2026, most of the obligations under the European Artificial Intelligence Regulation (AI Act) are now enforceable. This legislation, the first of its kind globally, establishes a phased implementation regime until 2028 and aims to ensure that AI is used safely, transparently, and in accordance with fundamental rights. Companies must inform users when they interact with an AI systemsuch as chatbots or virtual assistants, although mandatory labeling of AI-generated content has been postponed until December 2026 for certain generative models.
The sanctions regime is especially severe: The most serious infringements can result in fines of up to 35 million eurosespecially when using prohibited AI systems. Violations related to high-risk systems can result in fines of up to €15 million. Uses already prohibited from 2025 include social scoring systems, real-time remote biometric identification in public spaces for policing purposes (with very limited exceptions), and tools that exploit the vulnerability of minors or people with disabilities.
However, some obligations have been delayed. Requirements for high-risk systems, such as those used in personnel selection, credit granting, or setting insurance premiumsThese will be applied from December 2027. A year later, in August 2028, it will be the turn of systems integrated into already regulated products, such as medical devices or driving assistants.
Spain is moving forward with its own AI governance law
In parallel with the European regulation, the Spanish Government is promoting the project of Law for the Proper Use and Governance of Artificial IntelligenceCurrently under parliamentary review, this legislation does not create a separate regime but rather adapts the application of the AI Act to the Spanish legal system, defining the competent authorities, the supervisory system, and the sanctioning procedure. It also establishes specific obligations for the public sector, reinforcing the need for public administrations to prepare to comply with the new standards.
Experts like Giovanni Alessandrello, CEO of BIP Iberia, warn that The biggest risk is that companies will interpret the extensions as a reason to delay their adaptationIn his opinion, the new framework represents an opportunity to promote a Explainable, audited, and governed AIGuillermo Hidalgo, a technology lawyer at Maio Legal, adds that the regulations provide legal certainty by differentiating between low-impact applications and those that affect decisions about loans, employment, or education.
Autonomous AI agents open up a new risk surface
While regulation is progressing, technological reality is accelerating. AI agents, capable of interpreting instructions and acting autonomously within corporate networks, are being deployed at a rapid pace. According to a global survey by the Cloud Security Alliance (CSA) from April 2026, 82% of organizations have unknown AI agents operating on their infrastructure And 65% have already experienced security incidents related to these agents in the last 12 months. Of that group, 61% reported data exposure, 43% operational disruptions, and 35% financial losses.
The phenomenon of Shadow AI, or the use of artificial intelligence tools without authorization from technology teams, exacerbates the problem. The Cost of a Data Breach Report 2025, prepared by the Ponemon Institute, revealed that 97% of organizations that suffered an AI-related security incident lacked adequate access controlsAnd that 63% lack governance policies to manage AI. Shadow AI incidents already account for 20% of all breaches and add, on average, $670.000 to the cost of an incident.
Furthermore, in May 2026, Google researchers detected the first real-world attack using artificial intelligence to exploit a zero-day vulnerability, confirming that offensive AI is already a reality. Sectors such as mining, energy, and manufacturing are particularly vulnerable, as an actor with access to operational systems can escalate an incident from the digital to the physical realm.
The ISACA European Conference 2026 as a response to the challenge
Given this scenario, the ISACA European Conference 2026, to be held in Munich from October 7 to 9, is presented as a key forum to address AI governance. More than 50 international speakers will participate in more than 40 sessions These sessions will cover topics ranging from agentic AI governance to cyber resilience, cloud security, and privacy. Highlights include "AI Governance Reaches Maturity: Regulation, Risk, and Agentic AI" and "How to Build a People-Centric Defense Against AI-Driven Attacks."
The conference will begin with a keynote address by Henry Ajder, a specialist in generative AI and deepfakes, and an advisor to the World Economic Forum and the European Commission. Also participating will be Mónica Verma, former Chief Information Security Officer and founder of Cyber Foyer, who will share strategies for strengthening cyber resilience and leadership. ISACA will also present new advanced AI credentialsAdvanced in AI Audit (AAIA), Advanced in AI Risk (AAIR) and Advanced in AI Security Management (AAISM), designed to equip professionals with specific skills in auditing, risk and cybersecurity.
Two specialized workshops will be held prior to the congress: one on preparing for the Advanced in AI Risk certification and another on designing and implementing privacy programs. Attendees can earn up to 32 Continuing Professional Development (CPE) credits and network with professionals from across Europe. The conference can be attended in person or virtually, and registration is now open at a reduced rate until August 28, 2026.
The combination of the entry into force of the AI Act, the processing of the Spanish law and the proliferation of autonomous AI agents underlines the urgency of establishing robust governance frameworks. Organizations that fail to prepare now risk multimillion-dollar fines, security incidents, and loss of trust.AI governance is no longer an option, but a strategic necessity to compete in an increasingly regulated and technologically complex environment.
