Latest Publications

Share:

Navigating the New Cybersecurity Landscape: Key Implications of the EU’s NIS 2 Directive

The deadline for EU countries to transpose the expanded cybersecurity directive, NIS 2, into national law is 17 October 2024, but the implementation status varies significantly from country to country. Some of the member...more

EU Standardization Supporting the Artificial Intelligence Act

With the EU’s AI Act having entered into force on August 1, 2024, companies now need to focus on its implementation. Although the AI Act will not be fully enforceable until August 2, 2027, some obligations will become binding...more

New FTC Initiative Targets Deceptive AI Claims and a Generative AI Service

The Federal Trade Commission (FTC) recently initiated an enforcement sweep called Operation AI Comply against several companies that allegedly “relied on artificial intelligence as a way to supercharge deceptive or unfair...more

Developing and Using AI Require Close Monitoring of Risks and Regulations

As AI systems become more complex, companies are increasingly exposed to reputational, financial and legal risks from developing and deploying AI systems that do not function as intended or that yield problematic outcomes....more

Key Updates to the DOJs Evaluation of Corporate Compliance Programs

On September 23, 2024, the U.S. Department of Justice (DOJ) updated its Evaluation of Corporate Compliance Programs (ECCP) guidance. First published in 2017, the ECCP sets out factors that DOJ Criminal Division prosecutors...more

How and When SEC Recordkeeping Rules May Apply to AI-Generated Content

AI has revolutionized the way many businesses operate. Firms in the financial sector are eager to take advantage of rapidly developing technologies but do not want to risk running afoul of relevant Securities and Exchange...more

The Informed Board - Summer 2024

Across industries, companies are facing new and uncertain regulatory pressures and demands in areas including artificial intelligence, sustainability, algorithmic pricing and fintech-bank relations. In this issue of The...more

DOJ Enters First Intervention in Cybersecurity Qui Tam

The U.S. government’s recent complaint in a relator-filed case under the False Claims Act (FCA): - Marks the first FCA suit in which the Department of Justice (DOJ) has intervened since launching its ongoing Civil...more

AI Safety: The Role of the Board in Assessing and Managing AI Risk

As AI systems become more complex, companies are increasingly exposed to reputational, financial and legal risk from developing and deploying AI systems that do not function as intended or that yield problematic outcomes. The...more

How Defense Contractors Can Prepare Now for CMMC Implementation

The Department of Defense (DoD) is currently reviewing and adjudicating the public comments received in response to its proposed regulations implementing its Cybersecurity Maturity Model Certification 2.0 program (CMMC)....more

Takeaways From the Dismissal of SEC Claims Against SolarWinds and Its CISO

The U.S. District Court for the Southern District of New York has dismissed many of the Securities and Exchange Commission’s (SEC’s) claims against software development company SolarWinds and its chief information security...more

ECB Mandates Board Expertise in Addressing ICT and Security Risks

Earlier this year, a dedicated policy prepared by the European Central Bank (ECB) came into effect requiring bank management bodies to broaden their collective understanding of and proficiency in identifying and dealing with...more

Contractors Settle Cyber Fraud Claims Alleging Ignored Security Measures

Two recent settlements under the False Claims Act (FCA): - Signal enhanced risk around cybersecurity for recipients of federal funds. - Underscore the need to assess compliance with cybersecurity requirements and...more

Colorado’s Landmark AI Act: What Companies Need To Know

Colorado has become the first state to enact a comprehensive law relating to the development and deployment of certain artificial intelligence (AI) systems. The Colorado Artificial Intelligence Act (CAIA), which will go into...more

SEC Amends Reg S-P To Strengthen Data Breach Response Requirements and Protect Investor Information

On May 16, 2024, the Securities and Exchange Commission (SEC) announced the adoption of amendments to Regulation S-P (Reg S-P), which broadly track the changes originally proposed in March 2023. The revised Reg S-P requires...more

CPPA’s First Enforcement Advisory Focuses on Applying Data Minimization Principles to Consumer Requests

On April 2, 2024, the Enforcement Division of the California Privacy Protection Agency (CPPA) issued Enforcement Advisory No. 2024-01. This first-ever enforcement advisory focuses on promoting compliance with California...more

Data Protection Rulings by European Regulators Offer Insights Into Their Security Expectations

Valuable insights into the measures European regulators expect businesses to take to protect data privacy can be found in a report from the European Data Protection Board (EDPB) summarizing decisions under the EU’s General...more

Utah Becomes First State To Enact AI-Centric Consumer Protection Law

On March 13, 2024, Utah enacted the Utah Artificial Intelligence Policy Act (UAIP), which imposes certain disclosure requirements on entities using generative AI tools with their customers, and limits an entity’s ability to...more

HHS Office for Civil Rights Reaches Second Health Care Ransomware Settlement

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently announced its second settlement in four months growing out of a ransomware attack on a health care business. Maryland-based Green Ridge...more

EU and Germany Lay Groundwork for the Use of Medical Data for Research and AI Training

Both the EU and Germany are taking significant steps to accelerate digitalization in the health sector and facilitate the exchange and use of health data for research and innovation purposes. They aim to improve...more

Tennessee Law Addresses Proliferation of Deepfakes

Tennessee has enacted the Ensuring Likeness, Voice and Image Security (ELVIS) Act, which aims to protect individuals from the use of their persona in connection with “deepfakes” (i.e., fake content generated by artificial...more

FCC Approves Voluntary Internet-of-Things Cybersecurity Labeling Program

The Federal Communications Commission (FCC) recently approved a voluntary Internet of Things (IoT) Labeling Program, which allows manufacturers of IoT products to earn the FCC’s approval to display a “U.S. Cyber Trust Mark”...more

Emerging Expectations: The Board’s Role in Oversight of Cybersecurity Risks

Key Points - - New SEC rules from 2023 require public companies to report material cybersecurity incidents promptly and detail their cybersecurity risk management strategies in annual reports — requirements that increase...more

121 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide