SCCS Summit Network
Your global hub for resilience in third party and supply chain cyber risk.
A year-round community for Information Security, Cyber TPRM, and GRC professionals to connect, exchange ideas, and tackle the most pressing challenges in supply chain cyber security and resilience.
Join our monthly virtual discussions to:
- Learn from leading experts and peers
- Share insights and best practices
- Shape stronger, more resilient supply chains worldwide
Be part of a trusted network driving collaboration and innovation in supply chain cyber security.
Next Session
| Date: | September 30, 2026 |
| Time: | 16:00 – 17:00 CEST (Prague) | 15:00 – 16:00 GMT (London) | 18:00 – 19:00 UTC (Dubai) |
| Lead Speaker: | George Necola, Chief Information Security Officer at Alpiq |
| Moderator: | Jackson Jos Kunnankada, Senior Manager, Cybersecurity & Privacy at PwC Switzerland |
| Topic: | You Approved the Supplier. Did You Approve Its AI? EU AI Act in Practice: Securing AI Across the Supply Chain |
AI is now embedded across SaaS platforms, outsourced services and critical business processes, usually without triggering a new supplier assessment, contract review or governance decision. The supplier you approved two years ago is not the supplier you have today.
For cyber, third party risk, privacy, legal and procurement leaders, the practical question is not what the regulation says, it is how to translate it into supplier assurance that works: how due diligence, security requirements, contracting and reassessment need to change for AI-enabled services, and who owns the risk when it spans six functions without creating another disconnected layer of compliance.
The timing shifted this summer, and most people heard the wrong half of the story. The EU did delay part of the AI Act in July but only the heavy compliance regime for high-risk systems, which now lands in late 2027 and 2028. The obligations that shape what you have to ask suppliers today did not move at all. Transparency and staff AI literacy duties already apply, and a further set takes effect on 2 December 2026, two months after this session.
In short: the delay buys time on classification paperwork. It buys no time at all on knowing where AI sits in your supply chain, what it does with your data and who is accountable for it.
This roundtable brings together legal, security, and governance practitioners to explore:
- Where AI is entering the supply chain – SaaS, outsourced services and underlying model dependencies you never contracted for directly;
- What actually changed in July – which obligations were deferred, which were not, and what the 2 December 2026 date means for your programme;
- How supplier cyber assurance needs to evolve – due diligence, security requirements, contracting, reassessment triggers and change notification for AI-enabled services;
- Who owns AI risk – a workable accountability split across cyber, TPRM, privacy, legal, procurement and AI governance;
- What AI resilience looks like – model concentration risk, substantial modification and grandfathering, ongoing monitoring and incident response.
If your board asked tomorrow which suppliers are using AI with your organisation’s data, could you answer? Be part of the conversation and contribute your perspective to building more resilient supply chains worldwide.