Alessandro AleddaInsider Threat and Risk

INTRA/MD/MD012User and entity behavior analytics

The automated derivation of a baseline of activity and the treatment of departures from it as signals.

Pillar
MD  |  Monitoring and detection
Sources cited
13
Added
30 AUGUST 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
MD012/EUMandatoryEuropean UnionRegulation (EU) 2024/1689, articles 5(1)(f), 10, and 26(7), and Annex III(4)European Parliament and Council · read 11 Aug 2026Regulation (EU) 2026/1744, amending the Artificial Intelligence ActEuropean Parliament and Council · read 16 Aug 2026That inferring emotions at work is prohibited, that employment and worker management are a high-risk category, what the data a high-risk system is trained and tested on have to answer for, and that representatives are told before deployment.Whether the engine falls in the high-risk category turns on whether it is intended to monitor and evaluate the performance and behavior of the people it watches. Where it does, the full set of obligations follows, and none of that settles whether the detection method is lawful under data protection or employment law.
MD012/CoEMandatoryCouncil of EuropeBărbulescu v. RomaniaEuropean Court of Human Rights, Grand Chamber · read 11 Aug 2026That private life and correspondence reach into the workplace, and the six criteria against which any monitoring measure is weighed.Private life and correspondence extend into the workplace, including where a worker’s private use of a work device breaks the employer’s rules, and a monitoring measure is to be assessed against six criteria, prior notification and the availability of a less intrusive method among them. The case concerned the reading of a worker’s messages, and whether the criteria reach an engine deriving a baseline from activity is not decided in it.
MD012/ATMandatoryAustriaArbeitsverfassungsgesetz, sections 96 and 96aNationalrat · read 29 Aug 2026That a control measure touching human dignity has no legal effect without the works council’s consent, and that consent for automated processing and for assessment systems can be replaced by a conciliation board while consent under section 96 cannot.The works council’s consent is the condition of the analytics engine having legal effect, and the threshold is whether it touches human dignity.
MD012/FRMandatoryFranceCode du travail, articles L1121-1, L1222-4, and L2312-38République française · read 16 Aug 2026Consultation of the social and economic committee before the decision, prior knowledge for the worker, and proportionality to the task.The social and economic committee has to be informed and consulted before the decision to put the analytics engine in place, and the worker informed before it reaches them.
MD012/DEMandatoryGermanyBetriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance.The works council has to agree before introducing the analytics engine, and again on the manner in which it is used.
MD012/ITMandatoryItalyLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the analytics engine.
MD012/NLMandatoryNetherlandsWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the analytics engine is adopted, amended, or withdrawn.
MD012/ESMandatorySpainLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the analytics engine into operation.
RecommendedBelgiumwhere writtenCyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch.Behavior analytics that learn what is normal and flag departures from it are named among the tools, and so is a class aimed at the misuse of user accounts, stolen credentials and insider threats among what it is said to be for.
RecommendedNorwaywhere writtenNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.Knowledge of the normal state of the systems is established and maintained so that a change or an abnormality pointing to unauthorized action can be seen. The maintenance is the requirement: the normal state has to answer to reorganizations, acquisitions, mergers, downsizing, and a change of operating concept. What it is meant to expose is named as data flowing against the flow that was decided, data flowing at abnormal times, and abnormally large volumes.
ReportedCzechiawhere writtenRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.The pattern is built by watching behavior over a long period, and what is looked for against it is named: a person taking an interest in documents from projects they do not ordinarily work on, and a rise in documents pulled down from central repositories onto a workstation.
ReportedUnited Kingdomwhere writtenIntegrating Human Factors into Insider Threat Detection: A Systematic ReviewPathirana, Roberts, Kalutarage, and McDermott · read 16 Aug 2026The models, data sources, and evaluation methods used where detection research has taken up human factors.The models and data sources the research has used are catalogued and untested, so an engine built on them inherits an evidence base nobody has validated.