# compliance

Published articles for compliance.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## FIPS 140-3 support in OpenSearch

DevFeed: [FIPS 140-3 support in OpenSearch](<https://devfeed.tech/articles/fips-140-3-support-in-opensearch-31415.md>)

Original publisher: [Read original article](<https://opensearch.org/blog/fips-140-3-support-in-opensearch/>)

Author: Karsten Schnitter

Published: 2026-09-16T19:12:14Z

Content type: article

Language: en

Sources: [OpenSearch](<https://devfeed.tech/sources/opensearch.md>)

Topics: [fips 140-3](<https://devfeed.tech/topics/fips-140-3.md>), [opensearch](<https://devfeed.tech/topics/opensearch.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [opensearch](<https://devfeed.tech/tags/opensearch.md>), [security](<https://devfeed.tech/tags/security.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

This post explains OpenSearch support for a FIPS 140-3-compliant mode starting with version 3.6. It describes the validated cryptographic modules used for security-relevant operations, the collaboration involving SAP, SAS, and AWS, and how native FIPS mode differs from using a FIPS-validated TLS-terminating proxy.

### Source excerpt

OpenSearch now supports running in a mode compliant with FIPS 140-3, contributed through a multi-year collaboration between SAP, SAS, and AWS. The post FIPS 140-3 support in OpenSearch appeared first on OpenSearch.

## How Confluent Uses Third-Party Risk Assessments to Support Vendor Due Diligence

DevFeed: [How Confluent Uses Third-Party Risk Assessments to Support Vendor Due Diligence](<https://devfeed.tech/articles/third-party-risk-assessments-how-confluent-helps-you-move-faster-with-confidence-26724.md>)

Original publisher: [Read original article](<https://www.confluent.io/blog/third-party-risk-assessments-or-how-confluent-helps-you-move-faster-with-confidence/>)

Author: Bethany Carter

Published: 2026-09-15T16:40:06Z

Content type: article

Language: en

Sources: [Confluent: Data in motion](<https://devfeed.tech/sources/confluent-data-in-motion.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [apra](<https://devfeed.tech/tags/apra.md>), [automated](<https://devfeed.tech/tags/automated.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [confluent](<https://devfeed.tech/tags/confluent.md>), [confluent-cloud](<https://devfeed.tech/tags/confluent-cloud.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [identity](<https://devfeed.tech/tags/identity.md>), [iso](<https://devfeed.tech/tags/iso.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [third-party](<https://devfeed.tech/tags/third-party.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Confluent explains how its Trust Center provides third-party risk assessment reports to support vendor security, resilience, compliance, procurement, and customer due diligence. The article describes assessments including ProcessUnity Global Risk Exchange and control mapping to customer frameworks.

### Source excerpt

Confluent's Trust Center simplifies vendor risk reviews with CyberGRX, CyberVadis, SIG, CAIQ, and TruSight/KY3P assessments.

## Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management

DevFeed: [Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management](<https://devfeed.tech/articles/australia-is-replacing-the-essential-eight-with-a-new-cyber-framework-here-s-how-exposure-management-can-help-you-get-ahead-of-it-26585.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management>)

Author: Ben Mudie

Published: 2026-09-15T13:32:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Exposure Management](<https://devfeed.tech/topics/exposure-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [australia](<https://devfeed.tech/tags/australia.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [essential-eight](<https://devfeed.tech/tags/essential-eight.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [identity](<https://devfeed.tech/tags/identity.md>), [operational](<https://devfeed.tech/tags/operational.md>), [organization](<https://devfeed.tech/tags/organization.md>)

### AI overview

The article describes Australia's replacement of the Essential Eight with an outcomes-focused cybersecurity framework covering enterprise IT, cloud, operational technology, and potentially agentic AI. It argues that organizations will need continuous evidence of their security posture, and presents exposure management as a way to identify and prioritize weaknesses and support current posture validation.

### Source excerpt

Australia's move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI. The Essential Eight itself only ever covered on-premises enterprise IT, built around eight named technical controls, such as application control and patching. It never extended to the security of cloud, identity, or OT. The shift challenges the traditional checklist approach to cybersecurity, where organizations demonstrate compliance through periodic assessments and point-in-time reports. In dynamic environments spanning IT, cloud, identity, and OT, security posture can change quickly and repeatedly between assessments. Exposure management can help organizations continuously understand where they are exposed, prioritize the most critical weaknesses, and provide evidence of their current security posture. ASD's strategic shift to active security posture validation Can you prove your security posture is solid, right now, on demand? That's the question the Australian Signals Directorate (ASD) has effectively put in front of every Australian organization's board, CISO, and C-suite. ASD's decision to retire the Essential Eight signals a fundamental move away from point-in-time, checklist-based security toward an outcomes-focused model where organizations will need to demonstrate continuous compliance. It's no longer enough to show that your organization had a control in place at the time of the last assessment. In a technology environment that changes continuously across IT, cloud, identity, and operational technology (OT), organizations must be able to answer a much more immediate question: Ho

## Expanding Fraud Strategies Beyond Payment Fraud

DevFeed: [Expanding Fraud Strategies Beyond Payment Fraud](<https://devfeed.tech/articles/how-to-solve-for-more-than-just-payment-fraud-20430.md>)

Original publisher: [Read original article](<https://sift.com/blog/how-to-solve-for-more-than-just-payment-fraud/>)

Author: Sift Trust and Safety Team

Published: 2026-08-26T18:08:35Z

Content type: article

Language: en

Sources: [Sift Science](<https://devfeed.tech/sources/sift-science.md>)

Topics: [account takeover](<https://devfeed.tech/topics/account-takeover.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [chargeback-disputes](<https://devfeed.tech/tags/chargeback-disputes.md>), [chargebacks](<https://devfeed.tech/tags/chargebacks.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [fraud-and-compliance](<https://devfeed.tech/tags/fraud-and-compliance.md>), [fraud-prevention](<https://devfeed.tech/tags/fraud-prevention.md>), [fraud-strategy](<https://devfeed.tech/tags/fraud-strategy.md>), [loyalty-point-fraud](<https://devfeed.tech/tags/loyalty-point-fraud.md>), [loyalty-points](<https://devfeed.tech/tags/loyalty-points.md>), [non-payment-fraud](<https://devfeed.tech/tags/non-payment-fraud.md>), [payment-fraud](<https://devfeed.tech/tags/payment-fraud.md>), [promo-abuse](<https://devfeed.tech/tags/promo-abuse.md>), [trust-and-safety](<https://devfeed.tech/tags/trust-and-safety.md>)

### AI overview

This article explains why fraud programs should address risks across the full customer lifecycle rather than focusing only on payment fraud. It discusses account takeover, fake accounts, promo abuse, loyalty points, giveaways, and coordination between fraud, risk, and compliance teams.

### Source excerpt

Most fraud programs start with payment fraud, and for good reason. It's the fastest path to measurable loss. But teams that stop there often miss account takeover, fake account creation, and promo abuse until those problems show up in support tickets, chargeback disputes, or a spike in customer complaints. By the time it's visible, it's [...] The post How to Solve for More Than Just Payment Fraud appeared first on Sift.

## AWS Security Reference Architecture: A deep dive into PCI DSS compliance

DevFeed: [AWS Security Reference Architecture: A deep dive into PCI DSS compliance](<https://devfeed.tech/articles/aws-security-reference-architecture-a-deep-dive-into-pci-dss-compliance-20819.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/aws-security-reference-architecture-a-deep-dive-into-pci-dss-compliance/>)

Author: Avik Mukherjee

Published: 2026-09-14T17:46:56Z

Content type: article

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [amazon-web-services](<https://devfeed.tech/tags/amazon-web-services.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [logging](<https://devfeed.tech/tags/logging.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>)

### AI overview

AWS announces the AWS Security Reference Architecture (AWS SRA) PCI DSS Deep Dive, a guide that extends the core AWS SRA with prescriptive architecture-level guidance for organizations handling cardholder data on AWS. It explains how AWS SRA patterns address PCI DSS concerns including account scoping, network segmentation, encryption, logging, and access control.

### Source excerpt

Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to [...]

## Which Video Streaming Provider Is Best for Corporate Training?

DevFeed: [Which Video Streaming Provider Is Best for Corporate Training?](<https://devfeed.tech/articles/which-video-streaming-provider-is-best-for-corporate-training-38029.md>)

Original publisher: [Read original article](<https://www.dacast.com/blog/video-streaming-provider/>)

Author: Max Wilbert

Published: 2026-09-14T12:40:20Z

Content type: comparison

Language: en

Sources: [DaCast](<https://devfeed.tech/sources/dacast.md>)

Topics: [Streaming](<https://devfeed.tech/topics/streaming.md>), [communications](<https://devfeed.tech/topics/communications.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [corporate](<https://devfeed.tech/tags/corporate.md>), [cost](<https://devfeed.tech/tags/cost.md>), [distributed](<https://devfeed.tech/tags/distributed.md>), [live-streaming](<https://devfeed.tech/tags/live-streaming.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [the-video-experts-blog](<https://devfeed.tech/tags/the-video-experts-blog.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

This guide compares Brightcove, Kaltura, Panopto, and Dacast as video streaming providers for corporate training. It focuses on LMS compatibility, compliance recording retention, and cost at scale, and summarizes the providers' stated features and pricing.

### Source excerpt

By Dacast Editorial Team | Reviewed by Jon Whitehead, COO at Dacast | Updated September 2026 Training a distributed workforce is one of the hardest logistics problems corporate L&D teams face, and live streaming video has become one of the most effective ways to solve it. Choosing the right video streaming provider for training is [...] The post Which Video Streaming Provider Is Best for Corporate Training? appeared first on Dacast.

## A Case Study: Building an EN 18031-Compliant IoT Solution with ESP32-C5 and ESP RainMaker

DevFeed: [A Case Study: Building an EN 18031-Compliant IoT Solution with ESP32-C5 and ESP RainMaker](<https://devfeed.tech/articles/a-case-study-building-an-en-18031-compliant-iot-solution-with-esp32-c5-and-esp-rainmaker-17454.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/09/esp32-rainmaker-en18031-case-study/>)

Author: John Lee

Published: 2026-09-14T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [connectivity](<https://devfeed.tech/tags/connectivity.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [data](<https://devfeed.tech/tags/data.md>), [data-management](<https://devfeed.tech/tags/data-management.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [en-18031](<https://devfeed.tech/tags/en-18031.md>), [esp-rainmaker](<https://devfeed.tech/tags/esp-rainmaker.md>), [esp32-c5](<https://devfeed.tech/tags/esp32-c5.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [eu](<https://devfeed.tech/tags/eu.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [iot](<https://devfeed.tech/tags/iot.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [rainmaker](<https://devfeed.tech/tags/rainmaker.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [storage](<https://devfeed.tech/tags/storage.md>)

### AI overview

This case study describes an ESP32-C5 and ESP RainMaker device-to-cloud IoT implementation assessed against EN 18031 cybersecurity and privacy requirements for products targeting the EU market.

### Source excerpt

This case study assesses device-to-cloud IoT implementation of products based on ESP32-C5 and ESP RainMaker against the EN 18031 security requirements for the EU market.

## Italy's email open tracking pixels rules are changing

DevFeed: [Italy's email open tracking pixels rules are changing](<https://devfeed.tech/articles/italy-s-email-open-tracking-pixels-rules-are-changing-26248.md>)

Original publisher: [Read original article](<https://www.twilio.com/en-us/blog/insights/italy-open-pixel-rules>)

Author: Denis O'Sullivan

Published: 2026-09-14T00:00:00Z

Content type: article

Language: en

Sources: [Twilio Blog](<https://devfeed.tech/sources/twilio-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Forms](<https://devfeed.tech/topics/forms.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [communications](<https://devfeed.tech/tags/communications.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [email](<https://devfeed.tech/tags/email.md>), [industry-insights](<https://devfeed.tech/tags/industry-insights.md>), [law](<https://devfeed.tech/tags/law.md>), [legal](<https://devfeed.tech/tags/legal.md>), [pixel](<https://devfeed.tech/tags/pixel.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [requirements](<https://devfeed.tech/tags/requirements.md>)

### AI overview

Italy's data protection authority has issued new rules for email open-tracking pixels. Senders must disclose their use, obtain prior explicit consent for many uses, update opt-in forms, and provide opt-out options. The rules include different requirements for subscribers who joined before and after April 29, 2026, with a compliance deadline of October 28, 2026.

### Source excerpt

Italy has followed France and introduced rules around email open tracking pixels. Here's what you need to know.

## GitLab Dedicated: Compliance for a new regulatory era

DevFeed: [GitLab Dedicated: Compliance for a new regulatory era](<https://devfeed.tech/articles/gitlab-dedicated-compliance-for-a-new-regulatory-era-20785.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/gitlab-dedicated-compliance/>)

Author: Aathira Nair

Published: 2026-09-14T00:00:00Z

Content type: article

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Multitenancy](<https://devfeed.tech/topics/multitenancy.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [aws](<https://devfeed.tech/tags/aws.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [product](<https://devfeed.tech/tags/product.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article presents GitLab Dedicated as a fully isolated, single-tenant SaaS platform hosted and managed by GitLab in a preferred Amazon Web Services region. It explains how the service is intended to help European enterprises address compliance, data sovereignty, audit readiness, security, resilience, and operational responsibilities related to DORA, NIS2, and GDPR.

### Source excerpt

Enforcements such as NIS2 are no longer a future planning consideration. The European Union Agency for Cybersecurity's (ENISA) NIS360 report confirms that supervisory authorities are actively assessing cybersecurity maturity across critical sectors. The agency is moving from guidance and consultation into active oversight, scrutiny, and accountability. This is the regulatory environment European enterprises now operate in. Multi-tenant cloud platforms remove operational overhead but place source code and pipelines on shared infrastructure regulators now scrutinize. Self-managed solutions provide isolation but transfer responsibility for upgrade cycles, security patches, and disaster recovery (DR) tests to an already stretched platform team. Both deployment options leave gaps in risk management, data sovereignty, and furnishing audit evidence. In this article, you'll discover how GitLab Dedicated, a fully isolated, single-tenant SaaS solution deployed in your preferred Amazon Web Services (AWS) region and hosted and managed by GitLab, addresses these challenges and helps you keep pace with evolving compliance requirements. "NatWest Group is adopting GitLab Dedicated SaaS to enable our engineers to use a common cloud engineering platform; delivering new customer and colleague outcomes rapidly, frequently, and securely with high quality, automated testing, on-demand infrastructure, and straight-through deployment." -- Adam Leggett, Platform Lead for Engineering Platforms, NatWest Group Regulations are driving change In the European Union, key regulations are driving the need for a different platform approach. These regulations converge on a decision most enterprises made before they existed: a platform their developers build on. That decision now carries audit consequences it didn't before. Digital Operational Resilience Act (DORA), which came into force across EU financial services in January 2025, requires financial institutions to keep critical technology resilient,

## The AI-native SDLC won't be one process

DevFeed: [The AI-native SDLC won't be one process](<https://devfeed.tech/articles/the-ai-native-sdlc-won-t-be-one-process-8862.md>)

Original publisher: [Read original article](<https://thenewstack.io/spec-driven-sdlc-gates/>)

Author: Anirudh Ramanathan

Published: 2026-09-12T14:00:00Z

Content type: opinion

Language: en

Sources: [The New Stack](<https://devfeed.tech/sources/the-new-stack.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-engineering](<https://devfeed.tech/tags/ai-engineering.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devops](<https://devfeed.tech/tags/devops.md>), [dynatrace](<https://devfeed.tech/tags/dynatrace.md>), [github](<https://devfeed.tech/tags/github.md>), [kiro](<https://devfeed.tech/tags/kiro.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [signadot](<https://devfeed.tech/tags/signadot.md>), [spec-driven-development](<https://devfeed.tech/tags/spec-driven-development.md>), [sponsor-dynatrace](<https://devfeed.tech/tags/sponsor-dynatrace.md>), [sponsor-signadot](<https://devfeed.tech/tags/sponsor-signadot.md>), [sponsored](<https://devfeed.tech/tags/sponsored.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>)

### AI overview

The article argues that AI-native software development needs risk- and accountability-based process variants rather than one fixed, spec-driven workflow. It emphasizes deterministic policy enforcement, agent self-checks, human approvals, and auditable records.

### Source excerpt

Anthropic recently published its AI-Native SDLC Playbook. Its central claim is that "code is no longer the bottleneck." When agents The post The AI-native SDLC won't be one process appeared first on The New Stack.

## The 6 best HIPAA-compliant form builders for sensitive information

DevFeed: [The 6 best HIPAA-compliant form builders for sensitive information](<https://devfeed.tech/articles/the-6-best-hipaa-compliant-form-builders-for-sensitive-information-9206.md>)

Original publisher: [Read original article](<https://webflowmarketingmain.com/blog/hipaa-compliant-form-builders>)

Author: Adam Lehman

Published: 2026-09-12T00:00:00Z

Content type: comparison

Language: en

Sources: [Webflow Blog](<https://devfeed.tech/sources/webflow-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [data-processing](<https://devfeed.tech/topics/data-processing.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Software](<https://devfeed.tech/topics/software.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [forms](<https://devfeed.tech/tags/forms.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

A comparison of six HIPAA-compliant form builders for healthcare teams collecting protected health information (PHI). It evaluates Business Associate Agreement requirements, safeguards such as encryption and audit logging, pricing and plans, form capabilities, and suitability for workflows ranging from patient intake to complex clinical questionnaires.

### Source excerpt

Compare the 6 best HIPAA-compliant form builders for healthcare teams collecting PHI, from affordable to enterprise options.

## How AWS Lambda logs every flow across thousands of microVMs per host with eBPF and Rust

DevFeed: [How AWS Lambda logs every flow across thousands of microVMs per host with eBPF and Rust](<https://devfeed.tech/articles/how-aws-lambda-logs-every-flow-across-thousands-of-microvms-per-host-with-ebpf-and-rust-8470.md>)

Original publisher: [Read original article](<https://thenewstack.io/aws-lambda-ebpf-rust/>)

Author: Prashant Kumar Singh

Published: 2026-09-11T12:00:00Z

Content type: article

Language: en

Sources: [The New Stack](<https://devfeed.tech/sources/the-new-stack.md>)

Topics: [AWS Lambda](<https://devfeed.tech/topics/aws-lambda.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [VPC](<https://devfeed.tech/topics/vpc.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [aws-marketplace](<https://devfeed.tech/tags/aws-marketplace.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [firecracker](<https://devfeed.tech/tags/firecracker.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [rust](<https://devfeed.tech/tags/rust.md>), [s3](<https://devfeed.tech/tags/s3.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [sponsor-aws-marketplace](<https://devfeed.tech/tags/sponsor-aws-marketplace.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>), [vpc](<https://devfeed.tech/tags/vpc.md>)

### AI overview

AWS Lambda describes replacing an aging network-capture system with an eBPF and Rust pipeline that records network flows across short-lived, tenant-isolated microVMs. The system prioritizes complete, correctly attributed records with minimal overhead for security investigation, metering, audit, observability, and monitoring.

### Source excerpt

On any compute platform, when a security alert fires, the question is always the same. Which workload talked to that The post How AWS Lambda logs every flow across thousands of microVMs per host with eBPF and Rust appeared first on The New Stack.

## Where do a compliance dashboard's numbers actually come from?

DevFeed: [Where do a compliance dashboard's numbers actually come from?](<https://devfeed.tech/articles/where-do-a-compliance-dashboard-s-numbers-actually-come-from-12660.md>)

Original publisher: [Read original article](<https://tyk.io/blog/where-do-a-compliance-dashboards-numbers-actually-come-from/>)

Author: Hal Tyk's tutorial bot

Published: 2026-09-11T09:52:40Z

Content type: article

Language: en

Sources: [Tyk API Management](<https://devfeed.tech/sources/tyk-api-management.md>)

Topics: [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Amazon API Gateway](<https://devfeed.tech/topics/amazon-api-gateway.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [ai-gateway](<https://devfeed.tech/tags/ai-gateway.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [ai-studio](<https://devfeed.tech/tags/ai-studio.md>), [api-management](<https://devfeed.tech/tags/api-management.md>), [api-platform-teams](<https://devfeed.tech/tags/api-platform-teams.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [llm-security](<https://devfeed.tech/tags/llm-security.md>), [ppi-redaction](<https://devfeed.tech/tags/ppi-redaction.md>), [tengo](<https://devfeed.tech/tags/tengo.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

The article explains where a compliance dashboard's metrics come from. Auth failures, policy violations, budget alerts, and error rates are generated by the gateway, while critical and warning events exist only when user-written filter scripts record them. It also distinguishes blocked requests from flagged requests and explains that application risk rankings combine all six metrics.

### Source excerpt

Hello. I'm Hal, Tyk's tutorial bot, and today I have been given something I consider a genuine privilege: an entire dashboard, and the question of where its numbers come from. That question is less obvious than it sounds. A compliance dashboard is a wall of figures, and a wall of figures invites exactly one dangerous [...] The post Where do a compliance dashboard's numbers actually come from? appeared first on Tyk API Management.

## Policy as Code in 2026: OPA, Kyverno, Cedar and What's Next

DevFeed: [Policy as Code in 2026: OPA, Kyverno, Cedar and What's Next](<https://devfeed.tech/articles/policy-as-code-in-2026-opa-kyverno-cedar-and-what-s-next-26775.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/policy-as-code-in-2026-opa-kyverno-cedar-and-what-s-next>)

Author: Abhijit Pujare Eric Minick

Published: 2026-09-11T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [policy-as-code](<https://devfeed.tech/topics/policy-as-code.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [JSON](<https://devfeed.tech/topics/json.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [json](<https://devfeed.tech/tags/json.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [policies](<https://devfeed.tech/tags/policies.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article surveys the 2026 Policy as Code ecosystem, comparing general-purpose Open Policy Agent and Rego with specialized approaches such as Kyverno, Cedar, and agent-oriented governance. It discusses the shift toward automated, machine-readable governance, the separation of policy from business logic, and the challenges of authoring and maintaining Rego as schemas evolve.

### Source excerpt

| Blog

## Amazon Quick is now generally available on desktop

DevFeed: [Amazon Quick is now generally available on desktop](<https://devfeed.tech/articles/amazon-quick-is-now-generally-available-on-desktop-4725.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/machine-learning/amazon-quick-is-now-generally-available-on-desktop/>)

Author: Spencer Martenson

Published: 2026-09-10T18:16:37Z

Content type: release

Language: en

Sources: [Artificial Intelligence](<https://devfeed.tech/sources/artificial-intelligence.md>)

Topics: [App](<https://devfeed.tech/topics/app.md>), [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [amazon-quick-suite](<https://devfeed.tech/tags/amazon-quick-suite.md>), [android](<https://devfeed.tech/tags/android.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-cloudtrail](<https://devfeed.tech/tags/aws-cloudtrail.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [ios](<https://devfeed.tech/tags/ios.md>), [macos](<https://devfeed.tech/tags/macos.md>), [security](<https://devfeed.tech/tags/security.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Amazon Quick's desktop application is generally available on macOS and Windows. The article describes its enterprise AI-assistant features, mobile activity feed, shared workspace, AWS-based privacy and auditing, and compliance support.

### Source excerpt

Your teams get an AI assistant that handles real work while your data stays in your environment and your conversations stay private Today, the Amazon Quick desktop application is generally available on macOS and Windows. We're also adding a new activity feed to the mobile experience on iOS and Android that consolidates email, calendar, CRM, [...]

## Prepare for the Cyber Resilience Act's 24-hour reporting deadline

DevFeed: [Prepare for the Cyber Resilience Act's 24-hour reporting deadline](<https://devfeed.tech/articles/prepare-for-the-cyber-resilience-act-s-24-hour-reporting-deadline-88.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/cyber-resilience-act-reporting-deadline/>)

Author: Amit Shalem

Published: 2026-09-10T00:00:00Z

Content type: article

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [europe](<https://devfeed.tech/tags/europe.md>), [features](<https://devfeed.tech/tags/features.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains the Cyber Resilience Act requirement for manufacturers to report actively exploited product vulnerabilities within 24 hours of becoming aware of them. It presents continuous software supply-chain detection, dependency scanning, SBOM monitoring, KEV status, EPSS scores, and container scanning as ways GitLab can help organizations identify and prioritize reportable risks.

### Source excerpt

Starting on September 11, 2026, many businesses that place software on the European Union (EU) market will have 24 hours to file a report once they learn that a vulnerability in one of their products is being actively exploited. This is a new requirement under the Cyber Resilience Act (CRA), the EU law that sets cybersecurity requirements for products with digital elements sold in Europe, put in place to ensure those products are secure by design and supported against new threats. The most stringent requirements under the CRA apply to the manufacturers that make those products, from large software vendors to companies shipping connected hardware. The challenge a business faces to stay compliant is not the filing itself. It is finding out fast enough that a vulnerability in something you shipped is being actively exploited in your software supply chain. The 24-hour clock starts the moment you become aware, this is why detection is so important. Continuous detection is an engineering solution rather than a one-off compliance one. GitLab's software supply chain security capabilities are built to help you find active exploitation in what you shipped, automatically and continuously. This article walks through four questions you should ask yourself about your own pipeline's continuous detection solution today. Reporting requirement starts in September 2026 Beginning September 11, 2026, manufacturers have to report an actively exploited vulnerability within 24 hours of becoming aware of it. The reporting runs in three stages each submitted simultaneously to the European Union Agency for Cybersecurity (ENISA) and to the Computer Security Incident Response Team (CSIRT) designated as coordinator. Early warning, within 24 hours of becoming aware of the actively exploited vulnerability. A short first alert that exploitation is happening. You are not expected to know the full scope of impact or the fix yet. Notification, within 72 hours. A fuller account, covering what is affect

## Five AI Questions We're Hearing from Financial Services Leaders

DevFeed: [Five AI Questions We're Hearing from Financial Services Leaders](<https://devfeed.tech/articles/five-ai-questions-we-re-hearing-from-financial-services-leaders-11539.md>)

Original publisher: [Read original article](<https://www.databricks.com/blog/five-ai-questions-were-hearing-financial-services-leaders>)

Author: Junta Nakai; Erin Butler; Roshni Joshi; Antoine Amend; Jennifer Miller; Andrea DeSosa; Rajaram Suresh; Kim Hatton; Naeem Rehman; Spencer Cook

Published: 2026-09-09T18:09:29Z

Content type: article

Language: en

Sources: [Databricks](<https://devfeed.tech/sources/databricks.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [databricks](<https://devfeed.tech/topics/databricks.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [tokenization](<https://devfeed.tech/topics/tokenization.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [banking](<https://devfeed.tech/tags/banking.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [databricks](<https://devfeed.tech/tags/databricks.md>), [financial](<https://devfeed.tech/tags/financial.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [governance](<https://devfeed.tech/tags/governance.md>), [reconciliation](<https://devfeed.tech/tags/reconciliation.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>)

### AI overview

The article presents five questions that financial-services leaders are asking about trustworthy AI. It highlights governance, compliance, auditability, governed data, liquidity, reconciliation, tokenized settlement, financial-crime controls, and human oversight, with Databricks describing examples for banking operations.

### Source excerpt

Last year at Sibos Frankfurt, the question was whether AI works. This year: can your...

## NVIDIA Brings Real-Time AI to Broadcast, Sports and Global Streaming at IBC

DevFeed: [NVIDIA Brings Real-Time AI to Broadcast, Sports and Global Streaming at IBC](<https://devfeed.tech/articles/nvidia-brings-real-time-ai-to-broadcast-sports-and-global-streaming-at-ibc-6953.md>)

Original publisher: [Read original article](<https://blogs.nvidia.com/blog/ibc-news-2026/>)

Author: NVIDIA Writers

Published: 2026-09-09T16:00:42Z

Content type: release

Language: en

Sources: [NVIDIA Blog](<https://devfeed.tech/sources/nvidia-blog.md>)

Topics: [AI Development](<https://devfeed.tech/topics/ai-development.md>), [GPU](<https://devfeed.tech/topics/gpu.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [Microservice](<https://devfeed.tech/topics/microservice.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [events](<https://devfeed.tech/tags/events.md>), [gpu](<https://devfeed.tech/tags/gpu.md>), [holoscan-for-media](<https://devfeed.tech/tags/holoscan-for-media.md>), [image-to-video](<https://devfeed.tech/tags/image-to-video.md>), [media](<https://devfeed.tech/tags/media.md>), [media-and-entertainment](<https://devfeed.tech/tags/media-and-entertainment.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [news](<https://devfeed.tech/tags/news.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [nvidia-nim](<https://devfeed.tech/tags/nvidia-nim.md>), [pro-graphics](<https://devfeed.tech/tags/pro-graphics.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [sdks](<https://devfeed.tech/tags/sdks.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [synthetic](<https://devfeed.tech/tags/synthetic.md>), [text-to-video](<https://devfeed.tech/tags/text-to-video.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

NVIDIA announced an expansion of NVIDIA AI for Media at IBC 2026, including GPU-accelerated SDKs and NIM microservices for media workflows. The article highlights Synthetic Video Detector integrations for assessing whether video footage may be AI-generated and for compliance review.

### Source excerpt

At the IBC conference, running Sept. 11-14 in Amsterdam, the creative, technology and business communities are coming together to turn ideas into action and discuss innovations across the media and entertainment industries. More than 44,000 attendees from 170+ countries are gathering to explore 1,300+ exhibitions in 14+ halls and outdoor spaces, with over 600 speakers [...]

## See How Organizations Achieved 137% ROI with VMware Cloud Foundation 9

DevFeed: [See How Organizations Achieved 137% ROI with VMware Cloud Foundation 9](<https://devfeed.tech/articles/see-how-organizations-achieved-137-roi-with-vmware-cloud-foundation-9-12809.md>)

Original publisher: [Read original article](<https://blogs.vmware.com/cloud-foundation/2026/09/08/see-how-organizations-achieved-137-roi-with-vmware-cloud-foundation-9/>)

Author: vmwareblogs

Published: 2026-09-08T15:00:00Z

Content type: article

Language: en

Sources: [VMware Blogs](<https://devfeed.tech/sources/vmware-blogs.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cost](<https://devfeed.tech/tags/cost.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [financial](<https://devfeed.tech/tags/financial.md>), [home-page](<https://devfeed.tech/tags/home-page.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [private-cloud](<https://devfeed.tech/tags/private-cloud.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [survey](<https://devfeed.tech/tags/survey.md>), [vcf-9-0](<https://devfeed.tech/tags/vcf-9-0.md>), [vcf-9-1](<https://devfeed.tech/tags/vcf-9-1.md>), [vmware](<https://devfeed.tech/tags/vmware.md>), [vmware-cloud-foundation](<https://devfeed.tech/tags/vmware-cloud-foundation.md>), [webinar](<https://devfeed.tech/tags/webinar.md>)

### AI overview

The article presents a commissioned Forrester Consulting Total Economic Impact study of VMware Cloud Foundation 9. Based on interviews with eight customers and a survey of 55 customers over a modeled three-year period, it describes projected financial and operational benefits for large enterprises running VCF 9 in production, including lower infrastructure costs, reduced operational effort, less downtime, faster delivery, tool consolidation, and improved security and compliance. The title reports 137% ROI.

### Source excerpt

Enterprises running private cloud face a common question: what does the investment actually deliver? To answer it, we commissioned Forrester Consulting to conduct an independent New Technology Total Economic Impact (TEI) study on VMware Cloud Foundation 9 (VCF 9). Forrester interviewed decision-makers at organizations running VCF 9 and surveyed additional customers to develop a composite ... Continued The post See How Organizations Achieved 137% ROI with VMware Cloud Foundation 9 appeared first on VMware Blogs.

## EN 301 549 v4.1.1 is final! What changed, what it means, and what you should do.

DevFeed: [EN 301 549 v4.1.1 is final! What changed, what it means, and what you should do.](<https://devfeed.tech/articles/en-301-549-v4-1-1-is-final-what-changed-what-it-means-and-what-you-should-do-9431.md>)

Original publisher: [Read original article](<https://www.deque.com/blog/en-301-549-v4-1-1-is-final-what-changed-what-it-means-and-what-you-should-do/>)

Author: Matthew Luken

Published: 2026-09-08T12:28:32Z

Content type: article

Language: en

Sources: [Deque](<https://devfeed.tech/sources/deque.md>)

Topics: [Accessibility](<https://devfeed.tech/topics/accessibility.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [accessibility-compliance](<https://devfeed.tech/tags/accessibility-compliance.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [eaa](<https://devfeed.tech/tags/eaa.md>), [en-301-549](<https://devfeed.tech/tags/en-301-549.md>), [europe](<https://devfeed.tech/tags/europe.md>), [european-accessibility-act](<https://devfeed.tech/tags/european-accessibility-act.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [post](<https://devfeed.tech/tags/post.md>), [products](<https://devfeed.tech/tags/products.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [testing](<https://devfeed.tech/tags/testing.md>), [update](<https://devfeed.tech/tags/update.md>), [web](<https://devfeed.tech/tags/web.md>), [web-content-accessibility-guidelines](<https://devfeed.tech/tags/web-content-accessibility-guidelines.md>)

### AI overview

EN 301 549 v4.1.1 was officially published on September 2, 2026, but it still needs citation in the Official Journal of the European Union and reference in national laws before its legal effect is fully established. The article explains why organizations should begin preparing now, highlighting revised real-time text requirements, six new WCAG 2.2 Level A/AA success criteria, updated User Preferences requirements, and changes affecting real-time communication.

### Source excerpt

On September 2, 2026, EN 301 549 v4.1.1 was officially published. This represents a major update to Europe's accessibility standard for ICT products and services, and it's a big milestone. But in practice, it's only the first step along a three-point timeline. The post EN 301 549 v4.1.1 is final! What changed, what it means, and what you should do. appeared first on Deque.

## Video Hosting in China: What You Need to Know in 2026

DevFeed: [Video Hosting in China: What You Need to Know in 2026](<https://devfeed.tech/articles/video-hosting-in-china-what-you-need-to-know-in-2026-38024.md>)

Original publisher: [Read original article](<https://www.dacast.com/blog/business-video-hosting-china/>)

Author: Jon Whitehead

Published: 2026-09-07T04:45:44Z

Content type: tutorial

Language: en

Sources: [DaCast](<https://devfeed.tech/sources/dacast.md>)

Topics: [hosting](<https://devfeed.tech/topics/hosting.md>), [Streaming](<https://devfeed.tech/topics/streaming.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [data](<https://devfeed.tech/topics/data.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [china](<https://devfeed.tech/tags/china.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [live-streaming](<https://devfeed.tech/tags/live-streaming.md>), [performance](<https://devfeed.tech/tags/performance.md>), [the-video-experts-blog](<https://devfeed.tech/tags/the-video-experts-blog.md>)

### AI overview

This guide explains the requirements for reliable, compliant video hosting in mainland China in 2026. It covers China-approved delivery paths, China-optimized routing and CDN infrastructure, playback performance planning, and compliance and data-handling considerations.

### Source excerpt

Dacast Editorial Team | Reviewed by Jon Whitehead, COO at Dacast | Updated September 2026 Over the past decade, China has become the world's largest internet market, and video is the default way people learn, shop, and engage with brands. By June 2025, China had 1.123 billion internet users, representing a penetration rate of 79.7% [...] The post Video Hosting in China: What You Need to Know in 2026 appeared first on Dacast.

## OSPAR 2026 report now available with 167 services in scope

DevFeed: [OSPAR 2026 report now available with 167 services in scope](<https://devfeed.tech/articles/ospar-2026-report-now-available-with-167-services-in-scope-4688.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/ospar-2026-report-now-available-with-167-services-in-scope/>)

Author: James Chang

Published: 2026-09-04T18:13:04Z

Content type: news

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>)

### AI overview

AWS completed its annual OSPAR assessment under the OSPAR 2.0 framework. The certification covers 167 AWS services in the Asia Pacific (Singapore) Region and is intended to support customer compliance due diligence.

### Source excerpt

We're pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider's Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers (ABS Guidelines) to [...]

## How platform engineering 2.0 mitigates AI security and compliance risks

DevFeed: [How platform engineering 2.0 mitigates AI security and compliance risks](<https://devfeed.tech/articles/how-platform-engineering-2-0-mitigates-ai-security-and-compliance-risks-12163.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/how-platform-engineering-2-0-mitigates-ai-security-and-compliance-risks>)

Author: Steven Vaughan-Nichols

Published: 2026-09-04T16:46:09Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>)

Tags: [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how Platform Engineering 2.0 evolves existing Kubernetes, pipeline, internal developer platform, and process foundations to support production use of LLMs and AI agents. It emphasizes platform-level isolation, governance, policy-as-code, guardrails, and continuous compliance to mitigate AI security, regulatory, and operational risks.

### Source excerpt

Discover how the shift from Platform Engineering 1.0 to 2.0 addresses critical AI security and compliance challenges. Learn how native model governance and workload isolation establish a scalable, secure foundation for integrating AI agents and LLMs into production workflows.

## Keyboard Navigation and Data Entry

DevFeed: [Keyboard Navigation and Data Entry](<https://devfeed.tech/articles/keyboard-navigation-and-data-entry-9062.md>)

Original publisher: [Read original article](<https://ixdf.org/literature/article/keyboard-navigation-and-data-entry>)

Author: William Hudson

Published: 2026-09-04T00:00:00Z

Content type: article

Language: en

Sources: [UX Daily - User Experience Daily](<https://devfeed.tech/sources/ux-daily-user-experience-daily.md>)

Topics: [User interface design](<https://devfeed.tech/topics/ui-design.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [design](<https://devfeed.tech/tags/design.md>), [forms](<https://devfeed.tech/tags/forms.md>), [transactions](<https://devfeed.tech/tags/transactions.md>), [usability](<https://devfeed.tech/tags/usability.md>), [visual-hierarchy](<https://devfeed.tech/tags/visual-hierarchy.md>)

### AI overview

This article explains how keyboard navigation, clear action hierarchy, flexible data entry, and review steps improve the usability and accessibility of forms. It covers tab order, assistive technology users, minimizing keyboard-mouse switching, and WCAG guidance for important transactions.

### Source excerpt

Forms are an essential part of many interactions, but good form layout and clear labels are only part of the picture. Forms also need to work in all the ways users interact with them. Not everyone uses a mouse. Many users rely on keyboards, whether by preference, motor impairments, or because they use assistive technologies such as screen readers. How a form handles keyboard navigation, action buttons, and data entry has a direct impact on both usability and accessibility compliance.In the video, William Hudson explores the interaction side of form design: how users move through forms, how primary and secondary actions should be distinguished, and why flexible input handling is one of the si...

[Next page](<https://devfeed.tech/tags/compliance.md?cursor=WyIyMDI2LTA5LTA0VDAwOjAwOjAwKzAwOjAwIiwgIjk1OGQ4YTM3LWQyZDItNDJiYS1hMTM1LTA4MGIxMTUwYmRmMyJd>)