News & Analysis as of

Risk Management Risk Assessment European Union

Mayer Brown

Country Classification, Updated FAQ and Guidance, Draft Delegated Regulation: EUDR Compliance Made Easier?

Mayer Brown on

On 22 May 2025, the European Commission (“Commission”) made public risk classification of countries under the EU Deforestation Regulation (“EUDR”)1 which assigned a low level of risk to 140 countries and high level of risk to...more

Ropes & Gray LLP

European Commission Sets Country Risk Classifications for EU Deforestation Regulation Compliance

Ropes & Gray LLP on

The EU Deforestation Regulation requires the European Commission to classify countries according to their risk of producing EUDR covered commodities that are not deforestation-free. The Commission adopted its country...more

A&O Shearman

Zooming in on AI #18: Cybersecurity requirements for AI systems

A&O Shearman on

The Artificial Intelligence Act (AI Act) is the world's first comprehensive legal framework for AI regulation, which entered into force on August 1, 2024. The AI Act aims to ensure that AI systems are trustworthy, safe and...more

NAVEX

Five Questions to Ask About Navigating ‘Deregulatory Compliance’

NAVEX on

For many years, corporate compliance officers have followed a certain natural process. First, regulators adopt a new rule, then you decipher how the arrival of that new rule might require changes to your policies, procedures...more

Latham & Watkins LLP

Kingdom of Saudi Arabia Issues New Data Transfer Risk Assessment Guidelines

Latham & Watkins LLP on

The guidelines specify the requirements for data controllers to conduct risk assessments related to the transfer or disclosure of personal data outside the Kingdom. ...more

J.S. Held

2025 J.S. Held Global Risk Report: Artificial Intelligence, Data & Digital Regulations

J.S. Held on

Artificial Intelligence (AI) has been touted as the answer to a multitude of business challenges. However, AI – along with machine learning and large language models (LLMs) – is still fraught with technical and regulatory...more

A&O Shearman

EBA consultation on amending data collection for 2026 benchmarking under CRD IV

A&O Shearman on

The European Banking Authority (EBA) has published a consultation paper containing draft implementing technical standards (ITS) on amending Commission Implementing Regulation (EU) 2016/2070 with regard to the benchmarking of...more

A&O Shearman

Regulatory monitoring: EU version Newsletter - February 2025

A&O Shearman on

1. Bank regulation - 1.1 PRUDENTIAL REGULATION - a) General - (i) International - BCBS: Work programme and strategic priorities for 2025/26 Status: Final - The BCBS has published its work programme and strategic...more

A&O Shearman

European Commission adopts Delegated Regulation on RTS on threat-led penetration testing under DORA

A&O Shearman on

The European Commission (EC) has adopted a Commission Delegated Regulation supplementing the Digital Operational Resilience Act (DORA) with regard to RTS specifying the criteria used for identifying financial entities...more

K&L Gates LLP

New EDPB Statement on Age Assurance: What You Need to Know

K&L Gates LLP on

On 11 February 2024, the European Data Protection Board (EDPB) adopted a new statement on age assurance. This statement, while not legally binding, will guide the enforcement of age-gating methods across the EU. Age assurance...more

A&O Shearman

European Commission rejects draft technical standards on sub-contracting ICT services under Digital Operational Resilience Act

A&O Shearman on

The European Commission has published a letter (dated 21 January 2025) addressed to the Joint Committee of the European Supervisory Authorities (ESAs) rejecting certain draft regulatory technical standards (RTS) the ESAs...more

A&O Shearman

European Supervisory Authorities approve terms of reference for new EU systemic cyber incidence co-ordination framework forum...

A&O Shearman on

The European Supervisory Authorities have published the terms of reference for the EU systemic cyber incident co-ordination framework Forum established under the EU Digital Operational Resilience Act. The Forum will be...more

A&O Shearman

Financial Stability Institute insights paper on regulating AI in financial services sector

A&O Shearman on

The Financial Stability Institute of the Bank for International Settlements has published a policy implementation insights paper on developments and challenges relating to regulating AI in the financial services sector. The...more

Littler

The First Requirements of the EU AI Act Come into Force in February 2025

Littler on

Earlier this year, the European Parliament approved the EU Artificial Intelligence Act (the “AI Act”) by a sweeping majority, becoming the world’s first comprehensive set of rules for artificial intelligence....more

Alston & Bird

D-Day for the EU Cyber Resilience Act

Alston & Bird on

Our Privacy, Cyber & Data Strategy Team discusses the new Cyber Resilience Act (CRA) that affects manufacturers and distributors of connected devices that are in use anywhere in the European Union....more

Foley Hoag LLP

Actualités en matière de lutte contre la corruption en France et en Europe

Foley Hoag LLP on

Deux études particulièrement intéressantes ont récemment été publiées par l’Agence Française Anticorruption (l’AFA) et la Commission européenne dans le domaine de la lutte contre la corruption. La première étude publié...more

Society of Corporate Compliance and Ethics...

Corporate compliance with human rights: An overview

Creating value for shareholders has long been considered the primary purpose of corporations, especially within the framework of traditional economic theories. However, this view has evolved significantly over the past few...more

American Conference Institute (ACI)

How Can Companies Tackle Europe’s AI and Data Protection Rules?

Life science companies will have to grapple with unique questions in complying with the European Artificial Intelligence Act, including the scope of the law’s research exemption and the use of AI in personalized medicine and...more

American Conference Institute (ACI)

Operationalizing the EU AI Act: Five Compliance Steps to Take Now

Now that the European Union’s Artificial Intelligence (AI) Act has entered into force, the real work begins putting its obligations into practice. This article explores five compliance steps to take now to operationalize the...more

Paul Hastings LLP

DOJ to Evaluate AI Compliance Programs

Paul Hastings LLP on

The Department of Justice (DOJ) recently raised the stakes for businesses under investigation who use artificial intelligence (AI). The Evaluation of Corporate Compliance Program (ECCP) outlines the criteria to be considered...more

Arnall Golden Gregory LLP

Preparing for the Digital Operational Resilience Act (“DORA”): Key Steps for Payments and Fintech Clients

The Digital Operational Resilience Act (“DORA”), an EU regulation designed to bolster the resilience of financial entities against Information and Communications Technology (“ICT”) risks, entered into force on January 16,...more

DLA Piper

The UK Cybersecurity and Resilience Bill – A Different Approach to NIS2 or a British Sister Act?

DLA Piper on

Introduction It wouldn't be much of an exaggeration to say that NIS2 is the acronym on everyone's lips. When coupled with its European sister legislation DORA, we encounter a regulatory twosome that make GDPR feel like...more

Fenwick & West LLP

Notable Trends in 2024 ESG/Sustainability Reports

Fenwick & West LLP on

Teneo Insights recently published its fourth annual “State of U.S. Sustainability Reports,” which analyzes 250 sustainability reports from S&P 500 companies published this year through July 30, seeking to understand how...more

Akin Gump Strauss Hauer & Feld LLP

EU Takes Steps to Develop General Purpose AI Code of Practice

Following the publication of the European Union’s Artificial Intelligence Act (AI Act or Act) on 12 July 2024, there are now a series of steps that various EU bodies need to take towards implementation. One of the first key...more

A&O Shearman

Zooming in on AI – #4: What is the interplay between “Deployers” and “Providers” in the EU AI Act?

A&O Shearman on

One of the key aspects of the EU AI Act (“AI Act”)[1] is linked to the qualification of providers and deployers and the nuances which help distinguish between the two categories of stakeholders. What would this mean in...more

83 Results
 / 
View per page
Page: of 4

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide