Navigating Regulatory Challenges

Explore top LinkedIn content from expert professionals.

  • View profile for Sarah Fluchs

    Cybersecurity risk assessments that keep you compliant without over-engineering security requirements. | CTO @admeritia | CRA Expert Group @EU Commission | Co-Convenor @ISA/IEC 62443-3-2

    21,158 followers

    🥳 ....aaand it's official: The Cyber Resilience Act (CRA) has been adopted by the EU Council today! (Here's your reading list.) 🥳 The CRA will enter into force this year (once it's published in the EU's official journal), and apply 36 months after that date. This is a milestone: the CRA is the first regulation of its kind in the world, making product cybersecurity mandatory. Up to now, cybersecurity regulation focused primarily on critical infrastructures USING these products. Unlike the NIS-2 directive, which needs to be translated into national law at the member states (a lengthy process that is currently delayed in most states), the CRA is EU legislation, and directly applicable in all member states. So if you're selling a "product with digital elements" (yes, the scope is actually as wide as it sounds) in the EU and want to continue selling it in 2027, you will have to affix a CE marking to your product (similar to the one you may know from sunglasses, pressure vessels, or children's toys) and make sure it complies with the essential cybersecurity requirements in the CRA. I've been closely following the process since the first draft was published in 2022. Here's a list of my blog posts to get your CRA knowledge up to speed: 1️⃣ Introduction to the CRA, the CE marking, and the regulatory ecosystem around it (2022, in fact one of the most-read articles on my blog): https://lnkd.in/enBpvEDN 2️⃣ Explanation how the standards ("harmonised European norms, hEN") are defined that will detail the actual cybersecurity requirements in the CRA (2023): https://lnkd.in/evenyNgW 3️⃣ Overview of the essential requirements outlined in the CRA (2024): https://lnkd.in/e872mabW 4️⃣ Overview of the global product security regulation landscape and how the CRA fits into it (2024): https://lnkd.in/ej9BTMVU 5️⃣ Good-practice example for the "information and instructions to the user," one of the central documentations that need to be written for CRA compliance and the only one that must be provided to the product's users (2024): https://lnkd.in/eXaVpTHT Official links: ⭐ Today's EU press release announcing the adoption: https://lnkd.in/e5Teuzzm ⭐ Adopted CRA text: https://lnkd.in/en73cHDE

  • View profile for Tibor Zechmeister

    Founding Member & Head of Regulatory and Quality @ Flinn.ai | Notified Body Lead Auditor | Chair, RAPS Austria LNG | MedTech Entrepreneur | AI in MedTech • Regulatory Automation | MDR/IVDR • QMS • Risk Management

    29,051 followers

    Every quality manager knows the truth: ISO 13485 looks simple on paper. But implementing it? That's where reality hits hard. I've audited dozens of medical device manufacturers, and one pattern keeps emerging: Companies often miss the forest for the trees. They focus on individual requirements without seeing how everything connects. Here's what 15 years of working with quality management systems have taught me: 1.⁠ ⁠Core QMS Foundation ↳ Your quality system isn't just documentation—it's your operational backbone ↳ Start with clear processes before diving into procedures ↳ Remember: A good QMS should make work easier, not harder 2.⁠ ⁠Design Control Integration ↳ This isn't a checkbox exercise—it's your product development roadmap ↳ Link user needs directly to verification steps ↳ Make design reviews meaningful, not just meetings 3.⁠ ⁠Risk Management Evolution ↳ Stop treating risk management as a one-time exercise ↳ Build it into every process decision ↳ Use real-world data to challenge your initial assumptions 4.⁠ ⁠CAPA That Actually Works ↳ Most CAPAs fail because they solve symptoms, not causes ↳ Invest time in proper root cause analysis ↳ Track effectiveness checks like they matter—because they do 5.⁠ ⁠Post-Market Intelligence ↳ Your QMS should be learning and evolving ↳ Turn complaint trends into design improvements ↳ Use post-market data to validate your risk assumptions The secret to ISO 13485 success isn't in the standard's text. It's in how you make these elements work together seamlessly. Think of your QMS as a living system, not a stack of documents. P.S. What's your biggest challenge in making these elements work together? ⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡ MedTech regulatory challenges can be complex, but smart strategies, cutting-edge tools, and expert insights can make all the difference. I'm Tibor, passionate about leveraging AI to transform how regulatory processes are automated and managed. Let's connect and collaborate to streamline regulatory work for everyone! #automation #regulatoryaffairs #medicaldevices

  • View profile for Stacey Hronowski

    Canix Co-Founder | SVP of Pioneer Fund | Forbes 30U30 | Winner of TechCrunch Disrupt 2020

    7,044 followers

    I am shocked by something we keep hearing from New York Cannabis operators. Even with a looming OCM deadline, the industry still is not clear on the regulations for New York, particularly regarding BioTrack. We were at MJBiz last week. There, we had a conversation with Adrian Adams, EdD, a New York cannabis Processing Licensee* who thought commercial BioTrack (BioTrackTHC) was required in New York. On Monday, I spoke to Derek Frank, another operator with the same impression. These are not isolated incidents; we’ve been hearing this for quite a while now. So - here's the clarity. 1. BioTrack has several products, which include the (1) Government Traceability Product and the (2) Commercial Softwares (This includes Cannabis Cultivation software, Manufacturing, Dispensary POS, etc.) 2. The New York State Office of Cannabis Management has a contract with BioTrack for ONLY the Government product 3. Operators are required to have a system that can INTEGRATE with the Government product. 4. Operators are NOT required to use any BioTrack Commercial products (“BioTrackTHC”). 5. The Government API is provided FOR FREE to New York operators. They do not need to pay for this software. (They may need to pay for tag costs). 6. The New York BioTrack API is based on the Florida BioTrack API. 7. The companies that are Approved Integrators with BioTrack for the Florida API are Alleaves, BioTrack, Canix, Sweed POS, Dutchie, Silverleaf by Velosio, Flourish Software, and Salve 8. By January 17, 2025, all licensees must notify the OCM of their chosen inventory tracking system vendor that is capable of integrating with the BioTrack New York API. 9. Here is the link where you submit your system of choice to the OCM: https://lnkd.in/gYpwUecV For something as critical as Seed-to-Sale and POS, in a burgeoning, fast-growing cannabis market, there should not be so much confusion about what is and isn’t required. We need more transparency to support a thriving cannabis industry. #newyorkcannabis - what are you hearing? Tag someone who might need clarity on New York cannabis regulations. References: a. https://lnkd.in/gVVJRcgg b. https://lnkd.in/gAfhVKWx c. https://lnkd.in/gPF6WKTE d. https://lnkd.in/gWcUZVqJ e. https://lnkd.in/gTg7bdVm f. https://lnkd.in/gTP_GZgU g. https://lnkd.in/g_E-4JGE * The previous version of this post improperly referred to Adrian Adams, EdD as a Cannabis consultant, rather than a New York cannabis processing licensee.

  • View profile for Carl Haffner

    Founder, Operations Mentor, Entrepreneur, C-Suite and Board experienced Executive, Board Advisor in Security, Cannabis, Logistics, AI, Tech, & Regulated Markets

    13,076 followers

    𝗛𝗼𝘄 𝘁𝗼 𝗯𝘂𝗶𝗹𝗱 𝗦𝘂𝗰𝗰𝗲𝘀𝘀 𝗶𝗻 𝗠𝗲𝗱𝗶𝗰𝗮𝗹 𝗖𝗮𝗻𝗻𝗮𝗯𝗶𝘀. 𝗪𝗶𝘁𝗵𝗼𝘂𝘁 𝗕𝘂𝗿𝗻𝗶𝗻𝗴 𝗖𝗮𝘀𝗵 𝗼𝗿 𝗖𝗿𝗲𝗱𝗶𝗯𝗶𝗹𝗶𝘁𝘆 Start with the Patient, Not the Plant Medical cannabis is medicine, not wellness or lifestyle. Your product must serve a real need consistently & safely, backed by data. Understand patient journeys, work with clinics & doctors, & embed yourself in the healthcare system, not outside it. Build GACP First, Then EU GMP or Equivalent Too many try to chase EU GMP without mastering GACP. Good Agricultural & Collection Practices are about how you grow. EU GMP is for post-harvest processing & pharma-grade quality control. Get the basics right, document everything, & then scale. Make Regulation One of Your Strengths If you don’t understand the regulatory landscape, you don’t have a business. Know your country’s cannabis laws, narcotics classifications, export rules, & patient access pathways. Compliance is not a department, it’s part of your product. Never Outsource Your Integrity There will be pressure to cut corners, overpromise, or take shortcuts. Don’t. One contamination, one false claim, one deal with a bad distributor and your business collapses. In cannabis, reputation takes years to build and seconds to lose. Trust the Local Team If you operate in another country, listen to the people on the ground. Local growers, engineers, regulators, and logistics teams know more than a remote HQ ever will. Many failed projects stem from ignoring local intelligence. Control the Supply Chain Medical cannabis isn’t just about growing. It’s about controlling drying, processing, lab testing, packaging, export clearance, & more. Own your chain or verify every part of it. You cannot afford surprises with patient-use products. Avoid Chasing the “Next Big Thing” There’s always a new hype, CBD for pets, infused snacks, luxury creams. These trends rarely survive strict medical regulation. Stick to your core business. Deliver clean, consistent, compliant flower or extract. Then grow. Document Everything This industry runs on traceability. You need clean SOPs, batch logs, validated results, cultivation records, & patient outcomes. If it’s not documented, it didn’t happen. If it’s not auditable, it’s not exportable. Raise the Right Money Work with investors who understand the timelines and risks. You need partners who can handle a 3 to 5-year return horizon and still back compliance over short-term revenue. Misaligned finance will kill your project faster than pests. Know When to Say No Sometimes the smartest move is to walk away. If the laws are too grey, your partners untrustworthy, or the facility isn’t ready, pause. Medical cannabis must be built with discipline and maturity. Forced projects fail. Focused ones succeed. Please ask me how to build or fix your cannabis business if you are unsure, stuck, or scaling. I’ve worked in this space for 9+ years, and I have seen what works and what wrecks good ideas.

  • View profile for Luiza Jarovsky, PhD
    Luiza Jarovsky, PhD Luiza Jarovsky, PhD is an Influencer

    Co-founder of the AI, Tech & Privacy Academy, Author of Luiza’s Newsletter, Mother of 3

    139,492 followers

    🚨 The changes to the EU AI Act were APPROVED by the Council of the EU, including the postponement of high-risk deadlines. Key changes: 1. New application dates: - 2 December 2027 for high-risk AI systems listed on Annex III; - 2 August 2028 for high-risk AI systems listed on Annex I; - 2 August 2027 is the new deadline for the establishment of AI regulatory sandboxes by competent authorities at the national level; - 2 December 2026 is when the grace period ends for providers to implement transparency solutions for AI-generated content. 2. New prohibited AI practice: - The generation of non-consensual sexual and intimate content or child sexual abuse material (CSAM) will be prohibited. - AI systems that generate nude images of real people or edit clothes out in existing photos to reveal intimate parts are banned starting in December 2026. 3. Clarification of the competences of the AI Office: - The new text clarifies the competences of the AI Office for the supervision of AI systems based on general-purpose AI models where the model and that system are developed by the same provider. - It lists the exceptions where national authorities remain competent, including law enforcement, border management, judicial authorities, and financial institutions. 4. Interplay between sectoral rules and the AI Act: - For high-risk AI systems covered in Annex I (those already regulated by sectoral laws, such as medical devices, toys, lifts, watercraft, and many others), the new text limits the AI Act’s application in situations where sectoral laws already impose AI-specific requirements similar to those of the AI Act. 5. Machinery exemption: - Products covered by machinery regulation (and previously classified as high-risk under Annex I) were exempted from direct applicability of the AI Act; The EU Commission is empowered to adopt secondary legislation under the machinery regulation to add health and safety requirements to the machinery systems that are also covered by the AI Act. 6. Minimizing compliance burden: - The new text also adds an obligation for the EU Commission to provide guidance to assist economic operators of high-risk AI systems covered by Annex I (those already covered by sectoral law) in complying with the high-risk requirements of the AI Act in a manner that minimizes the compliance burden. A reminder that the legislative act making these changes official still has to be published in the Official Journal of the European Union. It will enter into force three days after it is published there. - 👉 To stay up to date with AI policy and regulatory developments, join my newsletter's 97,600+ subscribers below.

  • View profile for Montgomery Singman
    Montgomery Singman Montgomery Singman is an Influencer

    Managing Partner @ Radiance Strategic Solutions | xSony, xElectronic Arts, xCapcom, xAtari

    27,978 followers

    On August 1, 2024, the European Union's AI Act came into force, bringing in new regulations that will impact how AI technologies are developed and used within the E.U., with far-reaching implications for U.S. businesses. The AI Act represents a significant shift in how artificial intelligence is regulated within the European Union, setting standards to ensure that AI systems are ethical, transparent, and aligned with fundamental rights. This new regulatory landscape demands careful attention for U.S. companies that operate in the E.U. or work with E.U. partners. Compliance is not just about avoiding penalties; it's an opportunity to strengthen your business by building trust and demonstrating a commitment to ethical AI practices. This guide provides a detailed look at the key steps to navigate the AI Act and how your business can turn compliance into a competitive advantage. 🔍 Comprehensive AI Audit: Begin with thoroughly auditing your AI systems to identify those under the AI Act’s jurisdiction. This involves documenting how each AI application functions and its data flow and ensuring you understand the regulatory requirements that apply. 🛡️ Understanding Risk Levels: The AI Act categorizes AI systems into four risk levels: minimal, limited, high, and unacceptable. Your business needs to accurately classify each AI application to determine the necessary compliance measures, particularly those deemed high-risk, requiring more stringent controls. 📋 Implementing Robust Compliance Measures: For high-risk AI applications, detailed compliance protocols are crucial. These include regular testing for fairness and accuracy, ensuring transparency in AI-driven decisions, and providing clear information to users about how their data is used. 👥 Establishing a Dedicated Compliance Team: Create a specialized team to manage AI compliance efforts. This team should regularly review AI systems, update protocols in line with evolving regulations, and ensure that all staff are trained on the AI Act's requirements. 🌍 Leveraging Compliance as a Competitive Advantage: Compliance with the AI Act can enhance your business's reputation by building trust with customers and partners. By prioritizing transparency, security, and ethical AI practices, your company can stand out as a leader in responsible AI use, fostering stronger relationships and driving long-term success. #AI #AIACT #Compliance #EthicalAI #EURegulations #AIRegulation #TechCompliance #ArtificialIntelligence #BusinessStrategy #Innovation 

  • View profile for Antonio Vizcaya Abdo

    Turning Sustainability from Compliance into Business Value | ESG Strategy & Governance Advisor | TEDx Speaker | LinkedIn Creator | UNAM Professor | +129K Followers

    129,034 followers

    Aligning key sustainability regulations 🌎 Sustainability regulations in the EU are evolving rapidly, with the CSRD, CSDDD, and EU Taxonomy shaping corporate reporting and due diligence requirements. While each framework has a distinct purpose, they share significant overlaps that businesses must navigate efficiently. A structured approach to compliance can help companies reduce reporting burdens while ensuring alignment with regulatory expectations. Understanding how these regulations interact provides opportunities to streamline processes and enhance ESG risk management. Key areas of overlap include impact, risk, and opportunity management, double materiality assessment, due diligence requirements, and minimum safeguard alignment with international standards such as the UNGPs and OECD Guidelines. These common elements form the foundation of an integrated sustainability due diligence system. The EU Omnibus package, expected later this month, seeks to harmonize these regulations further. Its success will depend on maintaining the depth of due diligence requirements while providing companies with greater clarity and efficiency in reporting. For companies already implementing an integrated approach, the Omnibus package may not introduce significant changes. However, for those still working in silos, it could offer a clearer framework for compliance and strategic alignment. Identifying and leveraging regulatory synergies is not just a compliance exercise—it is a way to gain deeper ESG insights, improve sustainability performance, and align with global standards. Organizations that integrate these frameworks effectively will be better positioned to manage risks and create long-term value. As sustainability expectations continue to rise, businesses that proactively align their reporting and due diligence processes will be ahead of the curve. The focus should be on efficiency, transparency, and ensuring that compliance efforts translate into measurable impact. Source: Ramboll #sustainability #sustainable #business #esg #climatechange

  • View profile for Martyn Redstone

    Head of Responsible AI & Industry Engagement @ Warden AI | AI Governance for HR, Recruitment, Staffing & HR Technology

    22,225 followers

    Yesterday, the European Commission released two proposals that will materially affect how HR and TA teams use AI and manage people data: The Digital Omnibus Regulation and the AI Act Simplification Amendment. 1. High-Risk AI Timeline Adjustments The fixed August 2026 enforcement date for high-risk AI no longer applies. Obligations will now begin once the Commission confirms supporting tools (standards, guidance) are available, followed by a six-month transition for HR-related high-risk systems. A new final deadline requires compliance no later than December 2027. This creates a more realistic adoption window for HR technology and recruitment AI. 2. Key GDPR Changes for HR The Digital Omnibus updates GDPR to support modern people analytics and AI use: • Clearer definition of personal data, reducing uncertainty when using aggregated or pseudonymised data. • Permission for residual special-category data in AI training under strict safeguards. • Confirmed allowance for biometric verification when controlled by the employee. • Harmonised DPIA requirements across the EU. • Data breach reporting extended to 96 hours, with a unified EU reporting portal. 3. Streamlined Data and AI Governance Several data laws are consolidated into a clearer Data Act, simplifying vendor oversight and data portability. The AI Act amendment also introduces more practical obligations, expanded simplifications for SMEs and small mid-caps, stronger EU-level oversight, and support for using sensitive data to detect or correct bias in hiring and workforce systems. What This Means for HR and TA: The proposals provide clearer rules, reduced administrative burden, a more achievable timeline for high-risk AI, and better support for fair and compliant AI in recruitment and workforce management. Both the Digital Omnibus and the AI Act amendment are Commission proposals and are not yet law. They now enter the EU’s Ordinary Legislative Procedure, where the European Parliament and the Council will review, amend and negotiate the texts before jointly adopting them. Once approved and published in the Official Journal, each Regulation will enter into force and begin applying on the dates specified in the final legislation. If you’d like a tailored breakdown for your organisation or HR tech stack, feel free to get in touch.

  • View profile for Jigar Shah
    Jigar Shah Jigar Shah is an Influencer

    Host of the Energy Empire and Open Circuit podcasts

    756,509 followers

    The fastest fix for the U.S. interconnection backlog is battery storage technology that's already cheap and quick to build, paired with a small tweak to how "capacity" gets defined. The core problem: connecting new generation to the grid now takes up to eight years in most U.S. markets, because interconnection studies model worst-case, full-output conditions years into the future and bill developers for every upgrade needed to survive them. More than 2,000 GW of proposed projects are stuck in queues nationally, enough to double the size of our grid. A generator or battery storage system sited right next to a data center, industrial load, or Wal-mart store can supply real capacity to that specific load even if it looks like a plain "energy-only" resource to the wider grid operator. The system operator's capacity-accreditation process wasn't built for this arrangement, so today's interconnection rules treat it as more red tape than it needs to be, even though the physical reliability benefit is real and local. Batteries are uniquely suited to unlock this fast. A BESS project can be permitted and built in 12–18 months, versus years to even procure a gas turbines or build new transmission. It's dispatchable to the minute, which is exactly the property that lets it opt into the "connect and manage" style of access Texas already uses. This means a lighter safety study and accept curtailment if the transmission grid is "full". For a battery, curtailment isn't even much of a compromise; it's how it operates today. In PJM alone, standalone battery storage totals about 67.5 GW of proposed capacity across 349 projects, the second-largest category behind natural gas. Yet PJM's own pilot cycle shows the bottleneck in action: only about 1.9 GW of that battery capacity actually reached a signed interconnection agreement, taking nearly two years even under the "fast" reformed process. The projects should all be greenlighted this year to respond to this crisis. Two federal proposals are converging on the fix. Sen. Martin Heinrich's new bill would create "BASED" service (Basic Access Service for Energy-Only Delivery) nationally — any new plant, including batteries, could connect fast on an energy-only basis and upgrade to full capacity status later. The Energy Cost Fairness and Reliability Act (S.4559) targets the colocated case directly: fast, non-firm energy access for a battery or generator serving a nearby large load, while requiring that any capacity pulled off the public grid be backed by real replacement generation, so other customers aren't left exposed. At the FERC/PJM conference next week, they need to unlock these batteries to provide the capacity required to get through the new few years while everyone waits for other technologies to come online after 2031.

  • View profile for Kyle Sherman

    Founder, Chairman & CEO at Flowhub

    8,920 followers

    With the new federal spending package now signed into law, there’s understandable confusion about the hemp provisions it contains. Some people call it a “hemp ban.” Others say it will wipe out the industry. Neither is true. This law doesn’t ban hemp. It closes a loophole that allowed an entirely separate market of intoxicating products to operate with no testing, no age controls, and no regulatory structure. That market grew far beyond the intent of the 2018 Farm Bill. In recent years, you could walk into a store in states like North Carolina and purchase products labeled as “hemp” that were every bit as intoxicating as regulated cannabis sold in California. In many cases, the products were California cannabis rebranded as hemp. In other cases, they were low-potency flower sprayed with chemically converted THC or synthetic cannabinoids. None of it required testing or safety standards. Consumers had no way of knowing whether the grower used pesticides banned in regulated cannabis markets, including chemicals such as Eagle 20. This wasn’t the industry Congress legalized. The 2018 Farm Bill was meant to support non-intoxicating hemp used for fiber, grain, seed, nutrition, and wellness. The rise of intoxicating hemp was a direct result of a technical reading of the law that ignored its purpose. Businesses built around this loophole were operating in legally unstable territory from the start. The new law restores the boundary between hemp and intoxicating products. It keeps hemp fully legal for the uses Congress intended. Industrial hemp is untouched. Hemp foods, supplements, topicals, grain, fiber, and non-intoxicating cannabinoids all remain protected. The only change is that intoxicating cannabinoids are no longer allowed to circulate nationally without oversight. Those products will now fall under the types of state-regulated systems that already exist for cannabis. These systems are designed to ensure testing, labeling, age verification, and consumer safety. The law also gives the Department of Health and Human Services the responsibility to identify which cannabinoids have intoxicating effects. This closes the door on future chemical workarounds where new forms of THC are created simply to evade regulation. All of this prepares the federal landscape for what comes next. If cannabis is moved to Schedule III or otherwise rescheduled, regulators will need stable definitions for THC, intoxicating cannabinoids, and the dividing line between hemp and cannabis products. This new law provides those definitions. So, clearly this is not a hemp ban. It is a modernization of federal hemp law that brings clarity and safety back to the marketplace. It protects the legitimate hemp industry while ensuring intoxicating products are handled through regulated channels built for consumer protection. With the loophole closed hemp can operate on stable ground and the country now has the regulatory footing needed for the next steps in federal cannabis reform.

Explore categories