Background image of the Lantero team

Compliance - Digital tools and personal support

Lantero simplifies work regarding regulations and laws. Through clear and efficient digital tools, it becomes easy to work professionally with complex issues. Additionally, you gain access to personal support or advice from specialist when it is truly needed.

Lantero has been operating since 2014 and today offers leading solutions for, among other things, AI-driven document redaction, whistleblowing services, and the management of cybersecurity.

Read more

Customer references

Attendo logo
Barncancerfonden logo
Cabonline logo
Cancerfonden logo
Eletrikerna logo
Finansinspektionen logo
Gävle Kommun logo
Kjell & Company logo
Kommunal logo
Ljung & Sjöberg logo
Luleå Energi logo
Luleå Kommun logo
Nordic Wellness logo
Region Norrbotten logo
Sigtuna Kommun logo
Soltech logo
Trafikverket logo
Vesper Group logo
Attendo logo
Barncancerfonden logo
Cabonline logo
Cancerfonden logo
Eletrikerna logo
Finansinspektionen logo
Gävle Kommun logo
Kjell & Company logo
Kommunal logo
Ljung & Sjöberg logo
Luleå Energi logo
Luleå Kommun logo
Nordic Wellness logo
Region Norrbotten logo
Sigtuna Kommun logo
Soltech logo
Trafikverket logo
Vesper Group logo

Blog

blog image

September 7, 2026

Labeling and Traceability of AI-Generated Material: What Do the New Requirements Entail?

In an interview with Joakim Karlén, we discuss new requirements for AI-generated material, primarily various types of labeling. The discussion stems from the new regulations that recently came into force as a result of the AI Act. ## New Requirements The EU AI Act and its new transparency requirements place higher demands on how AI-generated material must be handled and labeled. For many organizations, the new rules raise questions regarding what responsibility actually lies with them—whether as a developer, employer, or individual publisher. The transparency rules in the EU AI Act have now entered into force, two years after the legislation's original adoption. This means that all organizations that develop or deploy AI systems need to comply with clear requirements for labeling and traceability. ## Types of Labeling Labeling of AI-generated content can broadly be divided into two categories: Overt labeling: Clearly visible information for the viewer, such as a watermark on an image stating "AI-generated" or plain text in a document's metadata. Technical (invisible) labeling: Mathematical or statistical shifts in the material, such as SynthID. It is not visible to the human eye at first glance, but can be identified by digital detection tools. ## Who Bears the Responsibility? It is important to distinguish where the responsibility lies in the chain. Creators of AI models (such as OpenAI, Anthropic, and Google) are required to build traceability and labeling directly into the technology. For companies that purchase or deploy these tools for their employees, the same general requirements for automatic labeling do not apply—with important exceptions. When publishing deceptive material, such as deepfakes or completely unmoderated texts, an obligation arises to inform the recipient. If, on the other hand, text or images have been reviewed, edited, or processed by a human prior to publication, an explicit warning is generally not required. As AI tools become a natural part of daily work—much like earlier technologies such as spell check—the need for major adjustments diminishes. The key for companies is to establish clear internal principles for communication and transparency. By proactively clarifying how AI is used in the organization, ambiguities are avoided and trust among customers and the public is maintained.
blog image

July 13, 2026

The Cybersecurity Act: What Smaller Companies Need to Know About Supply Chains and Cyber Hygiene

The new Cybersecurity Act (based on EU legislation) has become a hot topic of conversation in the business world. The main purpose of the law is clear: to raise cybersecurity and incident readiness across society, while giving corporate management clearer ownership of security issues. The focus lies on socially critical operations, such as government agencies, municipalities, energy companies, and food supply. So why is a law specifically targeting critical societal functions being discussed so broadly? The answer is the supply chain. ### Requirements Inherited Down the Line The legislation includes a strict requirement for covered organizations to ensure that their entire supply chain is secure. When a government agency or an energy company procures goods and services, they must vet their suppliers. In practice, this means that regardless of whether you run a large or small company, you will face tough security questions in future procurements. The requirements are simply inherited down the line. A vulnerability in a sub-contractor several tiers down ultimately becomes a vulnerability for the socially critical organization. ### Compliance Burden or Real Benefit? It is easy to view new laws as mostly unnecessary administration. However, much of the work provides a tangible benefit, and if approached wisely, it does not have to be overly burdensome. Information security is fundamentally about structure, and once you have those structures in place, it translates into security improvements that protect your business every single day. In an era of frequent cyberattacks and phishing attempts, good "cyber hygiene" is absolutely vital for any company. ### Three Steps to Tackle the Project For smaller organizations lacking a large IT budget or a dedicated compliance department, it is all about being concrete and narrowing the scope. The work can be boiled down to three central steps: 1. Get the technology right: Start with the low-hanging fruit. Implement two-factor authentication on all systems, ensure firewalls are enabled, and perform continuous security updates. Also, train your staff regularly so they recognize threats such as phishing (fraudulent emails) and vishing (phone scams). 2. Document: Conduct a simple inventory of your assets—what software, hardware, and networks do you use? Identify the risks associated with these and establish clear policies. For example, how do you manage "Shadow IT" (when employees use private phones or computers for work)? By documenting your processes, you will have ready-made answers when clients ask questions during a procurement. 3. Follow up: Cybersecurity is a moving target. At regular intervals, you must evaluate whether your routines align with reality, perform new risk assessments when purchasing new technology, and stay updated on emerging threats. ### Do You Need ISO 27001 Certification? Larger organizations often run heavy projects to get certified according to ISO 27001. For a smaller company—perhaps around 50 employees with a less complex operation—a formal certification is rarely necessary, unless explicitly required by your clients. It is far more important that you actually do the right things and have them documented in a well-functioning information security management system that mirrors the structure of ISO 27001, rather than having the actual certificate on the wall. Here at Lantero, we have developed ready-made, easy-to-understand templates and pre-filled examples to help you inventory your resources, conduct risk assessments, and establish the right structure from the start—without making the process heavier than it needs to be.
blog image

July 6, 2026

Whistleblowing in municipalities – trends and challenges

Lantero currently partners with around 80 of Sweden’s municipalities. Through this unique insight, we see a clear development: activity within municipal whistleblowing channels is increasing. But what is actually driving this development, how are the incoming cases best managed, and what new administrative challenges are waiting around the corner? We summarize some of the key insights based on a conversation with whistleblowing expert Andreas Wahlström. ### Increased Awareness and Turbulent Periods The fact that more reports are being submitted is primarily due to two things: increased trust and better information. Employees are becoming increasingly aware that these channels exist and trust that they are secure. However, this is not an entirely universal trend; activity varies greatly from one municipality to another. We see a clear link to two specific factors: 1. Focus on Welfare Crime: In municipalities that actively combat corruption and welfare crime, the propensity to report increases. 2. Turbulence and Change: Organizations undergoing a phase of restructuring or turbulence often experience higher pressure in their channels. Experience also shows that municipalities that are engaged and skilled at continuously training their staff receive more—and more relevant—reports. ### Screening and the Need for Investigative Expertise One of the greatest challenges for a municipality is managing the breadth of what is reported. Less than half of the incoming cases actually fall under the strict definition of the Whistleblowing Act. Much of it instead concerns general complaints or personnel matters. Despite this, a large portion of the reports carry significant value for the employer to be made aware of and to follow up on. Once a complex case has been identified, the next challenge arises: the investigation. Conducting an investigation internally can be legally and operationally complicated. A clear trend is therefore that more and more municipalities choose to bring in external expertise to quality-assure the investigative work and guarantee an independent review. ### The New Administrative Challenge: "War of the AI:s” Once a case has been handled, it does not always end there. Awareness among journalists and the public regarding the existence of these channels has increased, which has led to a significant spike in requests to extract documents from the systems. This is largely driven by AI technology. Since reviewers can now use AI to read and summarize vast amounts of text, they do not hesitate to request extensive logs and all available cases. For the already heavily burdened municipal case officers, this creates immense administrative pressure, as confidentiality and harm assessments (skadeprövning) must be carried out promptly and meticulously, since accidental disclosure of sensitive information can have severe consequences. To meet this AI-driven wave of requests, the municipalities themselves have begun implementing AI support in their processes. By allowing an AI to handle the groundwork and flag potential confidentiality risks, administrative time can often be cut by around 80%. This frees up time so that case officers can focus on what only a human can do: the final, qualified harm assessment.
Image describing Simplicity

Simplicity

Simplicity is the guiding principle in all of Lantero's solutions. The regulations and requirements we work with are often complex, which makes it especially important that processes, forms and templates are clear and understandable.

The functionality is tailored to the customer's needs, to create a purposeful solution without unnecessary complexity.

Image describing Personal commitment

Personal commitment

Lantero's philosophy is that complex regulations should be managed with a combination of simple digital tools and personal support when needed.

We are here to support everything from questions about the specific regulation to questions about the process or practices in a certain area.

Image describing Network of experts

Network of experts

We know from experience that expertise from specialist often is necessary. Therefore, to provide comprehensive support, Lantero offers a network of lawyers and other experts.

We ensure that the customer receives the right advisors based on current needs and that the assignment is clearly defined to create predictability in delivery and cost.

What do our customer think?

Lantero is always easy to get hold of when you have questions about a case and I like that we can always get support.

Gabriella Demirci

Coordinator of the whistleblower function, Botkyrka municipality
We are very happy with the service that Lantero has given us from the very beginning, all the way from support regarding the whistleblowing process to detailed questions regarding individual cases. Lantero is always available and respond quickly, relevantly, and educationally, even at non-working hours, with great customer-focused commitment. It makes it both safe and convenient for us to have this support from Lantero.

Jakob Söderbaum

Data Protection Officer, Huddinge municipality
Lantero's whole approach feels serious and well thought out, it suits us.

Monika Sundesson

Head of HR, Barncancerfonden
Even before the new law, we were looking for different possibilities of integrating whistleblowing into our code of conduct. We found Lantero to be simple, clear and it was especially good with an independent party that was not connected to other governance functions or collaborators within the company. Everything has worked smoothly, and the tool is simple to handle if cases come.

Josefin Sollander

Chief Communications Officer, Soltech Energy Sweden AB
I appreciate Lantero's care and pragmatism.

Niklas Nordh

General Counsel, Cabonline
Lantero's service is the most thorough in the industry with consistently high quality at all levels. It was also very easy to implement the process. We work with recruitment and consultants in finance, such as CFOs, controllers, and accounting economists, and the trust that an independent whistleblowing channel creates becomes an advantage in the relationship with customers as well as candidates.

Peter Bergmark

VD, Vindex AB

Read more about our services

Book a demo for a service!

Questions? Contact us