Latest Publications

Share:

California Legislature Sends Bills Regulating AI to the Governor

Last week, the California Legislature passed several bills that, if signed by the governor, will regulate how organizations develop, train, and use artificial intelligence (AI) models, systems, and applications. Of these...more

Latest NIST Guidance Identifies Generative AI Risks and Corresponding Mitigation Strategies

On July 26, NIST released a final version of its Generative Artificial Intelligence Profile (GenAI Profile), a cross-sectoral profile of and companion to the AI Risk Management Framework (AI RMF) (for further detail on the AI...more

CPPA Releases Data Broker Regulations for Public Comment

California agency's proposed regulations for data brokers include clarifications and new definitions - On July 5, 2024, the California Privacy Protection Agency (CPPA) released a notice of proposed rulemaking and proposed...more

SEC Clarifies Reporting of Material vs. Immaterial Cybersecurity Incidents

The U.S. Securities and Exchange Commission's (SEC) Division of Corporate Finance (Division) published a statement on May 21, 2024, regarding how public companies may disclose cyber incidents they determined to be immaterial....more

All-In on AI: Bipartisan Senate AI Policy Roadmap Identifies Areas of Consensus

On March 15, 2024, the Bipartisan Senate Artificial Intelligence Working Group (the "AI Working Group")—led by Senate Majority Leader Chuck Schumer (D-N.Y.) and Sens. Mike Rounds (R-S.D.), Martin Heinrich (D-N.M.), and Todd...more

Utah Enacts Consumer Disclosure Requirements for Businesses Using Bots and Generative AI

On March 13, 2024, Utah enacted the Artificial Intelligence Policy Act ("AIPA"), which creates two types of disclosure requirements for a business or person that "uses, prompts, or otherwise causes" generative AI applications...more

California Privacy Regulator Issues First Enforcement Alert

On April 1, 2024, the California Privacy Protection Agency (CPPA) issued its first enforcement advisory directing businesses to implement the data minimization principle when responding to consumer requests. The advisory was...more

CISA, UK NCSC, and 17 Other Countries Issue Landmark Joint Guidelines for Secure AI System Development

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (UK NCSC), along with partner agencies from 17 nations, have released Guidelines for Secure AI System Development (the...more

California Regulator Previews Intentions for Cybersecurity, Privacy, and Automated Decisionmaking Regulations

The CPPA kicked off a first round of rulemaking in May 2022 and finalized that set of rules in March of this year. At the latest California Privacy Protection Agency (CPPA) meeting, the CPRA Rules Subcommittee (Rules...more

SEC Adopts Cybersecurity Rule for Public Companies

On July 26, 2023, the U.S. Securities and Exchange Commission (SEC or Commission) finalized its Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule for public companies (the "Final Rule") by a...more

White House Announces Voluntary AI Governance Commitments from Seven Leading Companies

On July 21, the White House announced that seven leading AI companies (Amazon, Anthropic, Google, Inflection, Meta, Microsoft, and OpenAI) have agreed to make voluntary commitments around three key areas of their AI systems:...more

U.S. Fulfills Commitments for Implementing EU-U.S. Data Privacy Framework

The U.S. Secretary of Commerce, Gina Raimondo, issued a statement on July 3, 2023, announcing completion of commitments by the U.S. for implementing the Trans-Atlantic Data Privacy Framework (the "Framework"). The Framework...more

SEC Delays Proposed Cybersecurity Rules

According to its Spring 2023 rulemaking agenda, the U.S. Securities and Exchange Commission (SEC) has delayed issuance of two sets of cybersecurity requirements that previously were expected to be finalized in April 2023. The...more

White House Announcement Explores Measures to Regulate AI as Component of a National AI Strategy

On May 23, the Biden Administration announced several new initiatives to support the development of a National Artificial Intelligence (AI) Strategy. The initiatives focus on: (1) outlining a plan to increase federal...more

Department of Commerce’s NTIA Sets Sights on Developing Federal AI Accountability Policies

On April 11, 2023, the Department of Commerce, through the National Telecommunications and Information Administration (NTIA), issued a request for comments (RFC) on AI system accountability measures and policies. The “AI...more

Final Rules Implementing Colorado Privacy Act Have Arrived

The Colorado Attorney General's Office released the final version of its rules implementing the Colorado Privacy Act (CPA) on March 15. The CPA was enacted on July 7, 2021 and the first draft of the implementing rules were...more

SEC Settles Ransomware Disclosure Charges for $3 Million

The U.S. Securities and Exchange Commission ("SEC" or the "Commission") has ordered Blackbaud, Inc. ("Blackbaud") to pay $3 million to resolve claims that it made materially misleading statements about a 2020 ransomware...more

NIST Releases Final Risk Management Framework for Developing Trustworthy AI

On January 26, 2023, the National Institute of Standards and Technology (NIST) released the final version of its AI Risk Management Framework (RMF). ...more

SEC Looks to Finalize Proposed Cyber Rules, Issue New NPRM

The U.S. Securities and Exchange Commission (SEC) appears to have big plans for cybersecurity regulation in 2023....more

Colorado AG Releases Second Draft of Proposed Colorado Privacy Act Rules

On December 21, 2023, the Colorado Attorney General released a second draft of the Colorado Privacy Act Rules, revising the previous draft of the proposed rules. Our analysis of the first draft of the rules can be found here....more

European Commission Takes Major Step Towards Approving Streamlined International Data Transfer Mechanism

In a significant move toward replacing the invalidated Privacy Shield, the European Commission (EC) released a draft Adequacy Decision on December 13, 2022, concluding that the U.S. legal framework provides an adequate level...more

New York Department of Financial Services Proposes Significant Amendments to its Cybersecurity Regulation

The New York Department of Financial Services (NYDFS) has proposed significant amendments (Proposed Amendments) to its Cybersecurity Requirements for Financial Services Companies (Cybersecurity Regulation)....more

New York Department of Financial Services' EyeMed Settlement Emphasizes Risk Assessments, Email Controls (UPDATED)

The New York Department of Financial Services (NYDFS) continues to be a major player in data security enforcement. On Oct. 18, 2022, NYDFS announced that it had entered into a consent order with EyeMed Vision Care LLC...more

42 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide