News & Analysis as of

Regulatory Requirements Cybersecurity Regulatory Oversight

BakerHostetler

[Podcast] 2025 DSIR Deeper Dive: Artificial Intelligence

BakerHostetler on

We’re back with a deeper dive into the 2025 Data Security Incident Response Report, which features insights and metrics from more than 1,250 incidents in 2024. This episode dives into AI law, regulation, and guidance from...more

DLA Piper

Thailand: PDPA Crackdown 2025: Are You Next? – Major Fines and Lessons from Thailand’s Latest Enforcement

DLA Piper on

Since the full enforcement of Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) in June 2022, the Personal Data Protection Committee (“PDPC”) has moved decisively from awareness-building to active enforcement....more

Hogan Lovells

2025 Horizons Life Sciences and Health Care

Hogan Lovells on

In 2025, Life Sciences and Health Care (LS&HC) companies face rapidly evolving regulatory paradigms that create transactional risks and require daily monitoring. After more than 70 national elections in 2024, the dust hasn’t...more

Ballard Spahr LLP

FDA Issues Guidance on AI for Medical Devices

Ballard Spahr LLP on

The Food and Drug Administration (FDA) issued final guidance Monday that explains how medical device manufacturers can use a Predetermined Change Control Plan (PCCP) to update AI-enabled device software functions (AI-DSFs)...more

Coblentz Patch Duffy & Bass

Navigating the Shifting AI Landscape: What U.S. Businesses Need to Know in 2025

Artificial intelligence is no longer a wild west frontier technology—it’s a regulated one. As AI systems become central to how companies operate, communicate, and compete, legal oversight is catching up. In 2025, AI...more

Katten Muchin Rosenman LLP

ESAs Publish Guide on Oversight of Critical ICT Third-Party Service Providers under DORA

The European Supervisory Authorities (ESAs) recently published a comprehensive guide (Guide) on the oversight of critical information and communications technology (ICT) third-party service providers (CTPPs) under the EU...more

HaystackID

HSR Filings Rise in July 2025 as Compliance and Cybersecurity Move to the Forefront of M&A

HaystackID on

Through July 2025, corporate M&A activity in the United States continues to reflect disciplined execution amid evolving economic signals. Hart-Scott-Rodino (HSR) premerger notification filings reached 1,699 transactions for...more

Skadden, Arps, Slate, Meagher & Flom LLP

NIS2 Update: EU Cyber Authority Sets Out Compliance Expectations, but Implementation Is a Work in Progress

- What is new: On 26 June 2025, the EU Agency for Cybersecurity (ENISA) published guidance documents setting out security measures that regulated organisations should have in place to comply with the EU’s critical...more

Fisher Phillips

“Regulate AI Outcomes, Not AI Tools.” Congressman Shares Vision for AI Regulation + 5 Tips for Employers

Fisher Phillips on

Speaking at last week’s FP AI Conference, Congressman Jay Obernolte set out to debunk two misconceptions about artificial intelligence. The first is that AI is largely unregulated. The second is that we need to pass myriad...more

Barnea Jaffa Lande & Co.

DORA for Tech Vendors - What You Should Know (But Haven’t Asked)

DORA (Digital Operational Resilience Act) is an EU regulation that sets rules for how financial entities manage ICT (Information and Communication Technology) risks. It covers areas like cyber resilience, incident reporting,...more

Orrick, Herrington & Sutcliffe LLP

GAO report focuses on AI use in financial services

On May 19, the GAO published a report discussing the use and oversight of AI in financial services. The report highlighted the benefits of AI, such as improved efficiency, reduced costs, and enhanced customer experience,...more

Hogan Lovells

The Cyber Security and Resilience Bill

Hogan Lovells on

On 1 April 2025, the UK Department for Science, Innovation and Technology issued a policy statement setting out its key proposals for the new Cyber Security and Resilience Bill. The Bill is intended to respond to an...more

A&O Shearman

FSB publishes finalised format for FIRE framework

A&O Shearman on

The Financial Stability Board (FSB) has published its finalised Format for Incident Reporting Exchange (FIRE), together with a press release and updated webpage. FIRE provides a standardised format for financial institutions...more

A&O Shearman

UK Financial Stability in Focus report: AI in the financial system

A&O Shearman on

The Financial Policy Committee (FPC) of the Bank of England (BoE) has published the Financial Stability in Focus report on AI in the UK financial system. The FPC considers the potential benefits of AI with its growing...more

Mayer Brown

US NAIC Spring 2025 National Meeting Highlights: Innovation, Cybersecurity, and Technology (H) Committee

Mayer Brown on

On March 26, 2025, the Innovation, Cybersecurity, and Technology (H) Committee (“H Committee”) met at the Spring 2025 US National Meeting of the National Association of Insurance Commissioners (“NAIC”). The meeting covered...more

Bradley Arant Boult Cummings LLP

Top 10 takeaways from the new HIPAA security rule NPRM

On Jan. 6, 2025, the U.S. Department of Health and Human Services (HHS) proposed new regulations to enhance cybersecurity protections for electronic protected health information (ePHI) under the Health Insurance Portability...more

Katten Muchin Rosenman LLP

Navigating DORA Compliance: Recent Developments

The EU Digital Operational Resilience Act (DORA) took effect on 17 January 2025 after a two-year implementation period. DORA sets out new requirements for financial entities (FEs) and their information technology and...more

Husch Blackwell LLP

Deadline Ahead: NYDFS Compliance Notifications are due by April 15

Husch Blackwell LLP on

Businesses that are subject to the NYDFS Cybersecurity Regulations have four weeks left to submit their annual notices of compliance or acknowledge their noncompliance. When the regulations were amended in 2023, several of...more

A&O Shearman

ESAs roadmap for designation of critical ICT third-party service providers under DORA

A&O Shearman on

The European Supervisory Authorities (ESAs) have published a roadmap for the designation of critical ICT third-party service providers (CTPPs) under the EU Digital Operational Resilience Act (DORA). The roadmap of key dates...more

Shumaker, Loop & Kendrick, LLP

Client Alert: Navigating FINRA’s 2025 Third-Party Risk Updates: Compliance Strategies for Financial Institutions

Every year, the Financial Industry Regulatory Authority (FINRA) issues an Annual Regulatory Report in an effort to provide FINRA Member Firms with insight into findings from FINRA’s regulatory operations programs. The Annual...more

Wiley Rein LLP

[Podcast] The Impact of IoT Supply Chain Risks on Government Contracts

Wiley Rein LLP on

In this episode of Wiley’s Government Contracts podcast, partners Tracye Howard and Sara Baxenberg discuss the evolving national security concerns surrounding Internet of Things (IoT) modules produced by Chinese companies...more

DLA Piper

EU: Cyber Resilience Act published in EU Official Journal

DLA Piper on

On 20 November 2024, the EU Cyber Resilience Act (CRA) was published in the Official Journal of the EU, kicking off the phased implementation of the CRA obligations....more

Royer Cooper Cohen Braunfeld LLC

How the Election Shapes Your Compliance Program

Staying the course in compliance is crucial, especially during uncertain political times. Regulatory updates like the new AML rule and Cybersecurity can have a significant impact on your program, and it's important for...more

Skadden, Arps, Slate, Meagher & Flom LLP

What Companies Can Do To Protect Against Cyberattacks … and the Litigation That Often Follows

Cyber threats continue to grow as a result of increased digitization, widespread use of cloud computing, advanced connectivity and artificial intelligence (AI), requiring boards of directors across all sectors to focus more...more

Benesch

Staying Ahead of the Curve: Adapting to Evolving Cyber Regulatory Enforcement

Benesch on

As calls for executive accountability for cybersecurity intensify, it is essential for companies to scrutinize the adequacy of ephemeral messengers, such as Signal, WhatsApp, WeChat, and Snapchat, in light of both present and...more

61 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide