Citizen Card v2

Citizen Card v1 to v2: What Changed for Developers

Five things changed. Keys moved from RSA to ECDSA. Contactless reading arrived over ISO/IEC 14443, protected by the PACE protocol. A six-digit CAN code was introduced for contactless access. The chip contacts moved to the back of the card. And there is no API that tells you which version is in front of you.

EUDI Wallet

Who Must Accept the EUDI Wallet by December 2027?

Eleven sectors are named in Article 5f(2) of the eIDAS Regulation as amended: transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education and telecommunications. The deadline is 24 December 2027.

document AI extraction

Document AI: Why Does It Fail in Production?

Because extraction is the easy part. What separates a demonstration from a production system is disambiguation, meaning knowing that three different spellings are the same entity and that two identical spellings are not, and knowing when the model should refuse to answer rather than risk it.

Software Quality Evidence:

Software Quality Evidence: The Gap That Costs

Software quality evidence is not the same thing as a testing programme, and the difference is what the first serious supervisory review tends to expose. Most regulated financial institutions have QA engineers, test suites, CI/CD pipelines and dashboards that show green. Far fewer have evidence.

Nearshore Portugal

Nearshore Portugal: The Compliance Case

Choosing a nearshore Portugal partner used to be a conversation about rates, time zones and English proficiency. In 2026 a fifth criterion appears in RFPs from regulated sectors with growing regularity: whether the development partner operates under the same regulatory framework as the client.

EUDI Wallet relying party

EUDI Wallet Relying Party: Integration Guide

Becoming a EUDI Wallet relying party is the part of eIDAS 2.0 that lands on engineering teams, and it is the part that has had the least attention. By 24 December 2026, every member state must make a compliant European Digital Identity Wallet available to its citizens and residents.

EU AI Act August 2026: What Actually Changed

EU AI Act August 2026: What Actually Changed

The EU AI Act’s enforcement date was August 2, 2026. Most of the coverage this week focused on what was delayed: the postponement of the high-risk obligations for employment decisions, credit scoring, and access to public services to December 2027.

CRA vulnerability reporting

CRA September 2026: 24-Hour Vulnerability Reporting

From 11 September 2026, every software manufacturer selling into the EU has to report an actively exploited vulnerability within 24 hours of becoming aware of it. Not 24 business hours. Twenty-four hours.

AI QA Testing for Regulated Industries: Qualigentic vs. Generic AI Tools

When a QA team at a bank evaluates AI testing tools, the conversation tends to start with the same set of questions that any engineering team would ask: how many test cases does it generate, how accurate is the generation, how well does it handle test maintenance, what frameworks does it support. These are legitimate questions. They’re also the wrong starting point, because they treat the problem of AI-assisted QA at a regulated financial institution as though it were the same problem as AI-assisted QA at a SaaS startup. It isn’t.