Skip to content

Ops Log tag

#EU

Reviewed Ops Log notes tagged EU, written by Michal Jatczak with source links, test context and operational checks.

5 reviewed notes

Decision MemoSecurity & Infrastructure

The MFSA closes the DORA register window on 21 March, and only a submission that reaches Accepted counts

The MFSA sets the DORA Register of Information window at 1 January to 21 March each year, with 31 December of the preceding year as the reference date, and counts only a submission that reaches Accepted on the LH Portal. Here are the dates, the provider level fields, and the December work behind them.

By Michal Jatczak
Change NoteAI & Automation

Anthropic in Excel and PowerPoint is a separate setting, on by default for EU tenants created after 25 March 2026

Copilot in Word, Excel and PowerPoint has its own Anthropic setting, a different object from the global Anthropic subprocessor control, and it defaults to on for EU, EFTA and UK tenants created after 25 March 2026. Whether anything actually leaves the EU Data Boundary turns on the second control, so read the tenant creation date and then read both.

By Michal Jatczak
Operator RunbookAI & Automation

Self-hosted LLM serving in the EU: runtime choice, GPU sizing, and the sovereignty argument

A runbook for deciding whether to self-host an open-weights model in the EU: the runtime field after TGI entered maintenance mode, GPU sizing computed from the model config instead of copied from a table, a corrected token-throughput cost model, and the DORA, NIS2 and AI Act record you will be asked for.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

DORA in practice: the three report clocks, the major-incident gate, and the evidence pack

DORA has been enforceable since 17 January 2025, and under Article 5 of Commission Delegated Regulation (EU) 2025/301 each of the three reports on a major incident runs from a different event. This memo rebuilds the deadlines against that article, ships a PowerShell function that computes them, separates the Article 35 penalty on critical third-party providers from the Article 50 regime that applies to financial entities, and lists the evidence the regulation requires you to hold.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

NIS2 for managed service providers: who is actually in scope, and what Article 21 requires

A clause-by-clause scoping runbook for managed service providers under Directive (EU) 2022/2555: the size test that lives in the SME Recommendation, the closed Article 2(2) list that does not name MSPs, the Article 21(2) control set as expanded by Implementing Regulation (EU) 2024/2690, and the Article 23 reporting clock with the MSP-specific significance thresholds.

By Michal Jatczak

Adjacent tags

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.