Latest Publications

Share:

NY Department of Financial Services Signals Increased Scrutiny of Third-Party Technology Risk Management

On October 21, 2025, the New York Department of Financial Services ("NYDFS") sent a letter to the executives and information security personnel at covered entities with new guidance for managing technology and data risks...more

California Enacts SB 53, Setting New Standards for Frontier AI Safety Disclosures

California's new Transparency in Frontier Artificial Intelligence Act creates the nation's first standardized safety disclosure framework for frontier AI models. On September 29, 2025, Governor Newsom signed the Transparency...more

Raising the Stakes: California Enacts Trio of New Consumer Privacy Obligations

Three new California privacy bills signed into law expand consumer privacy protections and could have broad compliance implications for any company doing business in the state....more

California Bill Will Require Disclosures About Data Used in Training AI Models

On January 1, 2026, California Assembly Bill 2013, the "Generative Artificial Intelligence Training Data Transparency Act" ("AB 2013"), will come into effect, requiring generative artificial intelligence ("GenAI") developers...more

CJEU Clarifies Scope of Personal Data in EDPS v SRB Decision

The Single Resolution Board ("SRB") transferred pseudonymized comments from data subjects to Deloitte without informing them. The European Data Protection Supervisor ("EDPS") found a violation of information duties applicable...more

EU General Court Upholds EU-U.S. Data Privacy Framework

On September 3, 2025, the General Court of the European Union dismissed an action for annulment brought by a French member of Parliament against the European Commission's decision recognizing the adequacy of the level of...more

EU AI Act: European Commission Publishes General-Purpose AI Code of Practice

The European Union's Artificial Intelligence Act ("AI Act") establishes a comprehensive, risk-based regulatory framework including provisions relating to general-purpose AI ("GPAI") models that apply as from 2 August 2025. In...more

White House Issues Executive Orders on AI Action Plan

The White House recently announced America's AI Action Plan (the "Plan")—sweeping federal AI policy reforms prioritizing innovation and deregulation of the artificial intelligence ("AI") industry....more

NIST Updates Its Privacy Framework to Address AI

The National Institute of Standards and Technology ("NIST") recently updated its 2020 Privacy Framework 1.0 to include artificial intelligence ("AI") risk management....more

FTC Finalizes Amendments to the Children's Online Privacy Protection Act Rule

On April 22, 2025, the Federal Trade Commission ("FTC") published the finalized amendments to the Children's Online Privacy Protection Act ("COPPA") Rule (the "Rule"), marking the first major update since 2013....more

OMB Directs Agencies to Accelerate AI Adoption and Devise Governance Strategy

The Office of Management and Budget releases highly anticipated guidance to federal agencies on the use and deployment of artificial intelligence and how to manage its risks....more

EU AI Act: First Rules Take Effect on Prohibited AI Systems and AI Literacy

The European Union's Artificial Intelligence Act ("AI Act"), the world's first comprehensive legal framework on AI, entered into force on August 1, 2024. The AI Act sets out staggered compliance deadlines for the various...more

Understanding DORA: Digital Operational Resilience Act Now in Effect for Financial Entities and ICT Service Providers

DORA, the first EU regulation designed to establish a unified and robust digital resilience standard for the financial sector, becomes directly applicable on January 17, 2025, introducing significant penalties and...more

Justice Department Issues Final Rule on Bulk Transfers of Sensitive Personal Data to Certain Countries

The final rule establishes prohibitions and restrictions on the transfer of certain data due to national security risks from specified countries of concern....more

The Impact of a Second Trump Presidency on SEC Enforcement Priorities

A new presidential administration is likely to bring change across the federal government, perhaps nowhere more starkly than at the Securities and Exchange Commission ("SEC"), which has greatly expanded its enforcement reach...more

TSA Releases Proposed Rule to Enhance Pipeline and Railroad Cyber Risk Management

The Transportation Security Administration's ("TSA") proposed rule would require owners and operators of certain pipeline, freight railroad, passenger railroad, rail transit, and over-the-road bus ("OTRB") systems to...more

NIS 2 Directive: Transposition Period is Up for EU Member States

As the national implementation deadline for the NIS 2 EU Directive is over, businesses in scope should ensure they will soon be ready to comply with the strengthened cybersecurity requirements....more

First Tranche of Australia's Much Anticipated Privacy Law Reforms Revealed

The first wave of Australia's expansive privacy law reforms has been introduced into Federal Parliament in the Privacy and Other Legislation Amendment Bill 2024 (Cth) ("Bill")....more

SEC's and Private Litigants' Continued Focus on "AI Washing"

On September 4, 2024, U.S. Securities and Exchange Commission ("SEC") Chair Gary Gensler reiterated concerns about artificial intelligence-related ("AI") disclosures and the need for companies to communicate accurately about...more

California Enacts AI Transparency Law Requiring Disclosures for AI Content

On September 19, 2024, California adopted the California AI Transparency Act ("SB 942") to create transparency mechanisms that allow consumers to determine whether an "image, video, or audio content, or content that is any...more

New FAA Regulations Target Cybersecurity Vulnerabilities in Aircraft Design

The Federal Aviation Administration ("FAA") has proposed new rules to standardize its criteria for addressing cybersecurity threats for transport category airplanes, engines, and propellers....more

U.S. District Court Invalidates HHS Guidance Overreading HIPAA's Application to Online Technologies

On June 20, 2024, a U.S. federal district court held, in a suit brought by Jones Day, that the Department of Health and Human Services ("HHS") had misapplied the Health Insurance Portability and Accountability Act ("HIPAA")...more

SEC v. SolarWinds: Court Rejects SEC Authority Over Cybersecurity Controls and Most Alleged Disclosure Violations

The U.S. District Court for the Southern District of New York dismissed the majority of claims that the Security and Exchange Commission ("SEC") asserted against SolarWinds, including claims that the company's alleged...more

Rhode Island Continues State-Level Adoption of Comprehensive Data Privacy Laws

Rhode Island is the latest state to adopt a comprehensive data privacy law, titled the Data Transparency and Privacy Protection Act....more

128 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide