Skip to content
Search our site  
    October 1, 2026

    Businesses’ digital trust awareness

      Back                                                                                                                                                                            

    Until only a few years ago, digital trust, including cybersecurity and AI governance, was largely a compliance dis-cussion. Today, it is increasingly influencing  procurement decisions, customer confidence, partnership agreements, access to markets, and board-level invest-ment priorities.

     

    China certCCC

    Still, many organisations continue to approach digital trust as a regulatory exercise rather than a strategic capability. The biggest risk then, however, is not non-compliance but rather investing significant time and money in digital trust  programs that fail to address their most material business risks.


    Surveys amongst certain business leaders in Europe have shown (amongst other things) that:

    • Although the EU AI Act and the Cyber Resilience Act contain obligations that depend on organisational role, product type, use case, and risk classification, many organisations begin building policies, controls, and governance structures before establishing a clear understanding of where their actual exposure lies. Thereby resources may be directed toward low-priority activities while more significant risks remain unaddressed.

    • Many leaders assume AI governance and cybersecurity readiness are primarily technical challenges, while technology is rarely the biggest obstacle.

    • Organisations underestimate how quickly governance gaps emerge when adoption outpaces organisational readiness.

    • As AI moves into critical business functions, the leaders navigating this most effectively understand that while technology can be outsourced, accountability cannot. Digital trust ultimately remains a leadership responsibility.

    • Few developments are moving faster than enterprise AI adoption. What organisations may underestimate is how quickly governance gaps emerge when adoption outpaces organisational readiness.

    • Regulations such as the Cyber Resilience Act and the New Information Security Directive (NIS2), require organisations to strengthen capabilities around vulnerability management, software transparency, incident response, and product security. But the most forward-looking organisations are doing it because business resilience requires it.

    • Digital trust is becoming a competitive advantage. Customers’ faith in data security and responsible AI can directly lead to business growth, with trusted organizations more likely to see significant annual growth rates. Procurement teams and enterprise customers ask suppliers to demonstrate AI governance practices, cybersecurity maturity, and structured risk-management processes.

    A more comprehensive article on this topic can be seen at this link.

     

    For further information or/and assistance concerning cyber- and AI security matters, please contact
    Gustavo.Sánchez@nemko.com or Alicja.Halbryt@nemko.com

     

    (This article is based on information provided by Alicja Halbryt; edited by T.Sollie) 

     

    Click Here To Subscribe To Our News In Brief

    Nemko

    Since 1933, we have ensured that our customers comply with requirements anywhere in the world. Our services include pre-compliance, product testing, product certification, global market access, cyber assurance, field evaluation, management system certification and functional safety.

    Some of the other articles in this newsletter