Heather Hinton, Chief Information Security Officer at the platform Sitecore, says that AI urgently requires effective guardrails and regulations, but progress is too slow among practitioners, regulators and users. She says:
“Unlike with GDPR, we now have the expertise in technology, data security and privacy to establish strong, future-proofed policies that protect individuals in this rapidly evolving field. We need clear, decisive regulation that reflects public concerns and keeps pace with the speed of AI development. Businesses will find ways to innovate responsibly, but only if they are given firm accountability structures from the outset. I have every confidence that businesses can do this if held accountable from the beginning.
“Delayed or inconsistent regulation will not deliver the safe or trustworthy AI adoption the public expects. Policymakers should work closely with experts in data security, privacy and those safeguarding vulnerable groups, rather than relying solely on commercial interests. By doing so, we can produce regulations that are both practical and proportionate – enabling responsible AI use while protecting individuals and strengthening trust in the organisation deploying it.”
While privacy concerns have kept mandatory digital IDs largely at bay, digital identities tied to their real human identities will become far more popular with the rollout of large regional programs such as the EU Digital Identity Wallet, which will be available to all EU citizens in 2026. While these programs are unlikely to be compulsory, they are expected to become increasingly necessary for accessing digital services, KnowBe4 says.
Q-Day, the day when quantum computers become sufficiently capable of cracking most of today’s traditional asymmetric encryption, will likely happen in 2026. The security of these systems has never been more important. Organisations must strengthen human authentication through passkeys and device-bound credentials while applying the same governance rigor to non-human identities like service accounts, API keys and AI agent credentials, KnowBe4 predicts.




