NIS2: a Game-Changer for Senior Management and Boards
NIS2 transforms senior management and boards' approach to cybersecurity.
https://www.williamfry.com/knowledge/nis2-a-game-changer-for-senior-management-and-boards/
NIS2 transforms senior management and boards' approach to cybersecurity.
https://www.williamfry.com/knowledge/nis2-a-game-changer-for-senior-management-and-boards/
CIOs must consider five key questions before deploying agentic AI:
These considerations are crucial for successful AI integration, particularly regarding security and relevance.
https://www.ciodive.com/news/5-questions-agentic-AI-CIO/742296/
EU's new GPAI Code, delayed but published on March 11, aims to aid compliance under the AI Act for General Purpose AI providers. While it includes streamlined commitments and user-friendly documentation, concerns remain from tech bodies about copyright and risk evaluation requirements. Further guidance on GPAI models is forthcoming. Finalization is due by May; if not completed by August 2025, common rules may be established by the Commission. The success of this voluntary Code is crucial for practical implementation of the AI Act.
https://thelens.slaughterandmay.com/post/102k49e/ai-acts-new-gpai-code-out-finally
The NCSC report details publicly available hacking tools used by cybercriminals and nation-state actors, highlighting their accessibility and impact. It examines tools for credential theft, network exploitation, and persistence and urges organizations to strengthen defenses against these threats.
https://www.ncsc.gov.uk/report/joint-report-on-publicly-available-hacking-tools
CJEU's Feb 27, 2025 judgment in CK v Dun & Bradstreet clarifies GDPR provisions on access to personal data and automated decision-making. It mandates that data subjects must receive meaningful, concise explanations without full algorithm disclosure. Controllers must balance transparency with trade secret protection, sharing relevant information with supervisory authorities for cases involving trade secrets. The ruling rejects blanket legal exclusions for access rights based on trade secrets, requiring case-by-case assessments.
CISOs must adapt to rising regulatory pressures and evolving cyber threats, leading the way in resilience strategies while managing compliance. Their roles may evolve from purely cybersecurity to overseeing overall business resilience, integrating AI, and collaborating closely with IT and senior management. The CISO's focus will shift towards designing security architectures that support growth and adaptability, making them essential in the boardroom.
https://www.darkreading.com/vulnerabilities-threats/ciso-business-resilience-architect
EU's AI Act now mandates first obligations.
https://www.jdsupra.com/legalnews/the-eu-s-ai-act-the-first-obligations-3018655/
EU AI Act requires organizations to implement a governance system for AI systems, classify them by risk, and prepare for compliance within two years. Violations can incur hefty penalties. Companies should establish clear responsibility lines among IT, legal, and compliance teams, conduct risk assessments, and create an inventory of AI solutions. A proactive approach is needed to meet the law's requirements and mitigate risks involved with AI usage.
Industry expresses major concerns over the draft EU AI Code of Practice, highlighting unresolved copyright issues and burdensome obligations that could hinder AI innovation. Critics from various sectors say the code lacks legal clarity and fails to address key risks effectively. Feedback on this draft is open until March 30, with a final version expected by May.
EU AI Act's new draft Code for AI model makers offers gentler guidance for compliance, aiming to clarify obligations around transparency and copyright for general purpose AI providers. Feedback for finalizing the Code is being collected until March 30, 2025, amidst concerns about potential overregulation as the EU responds to pressures from the U.S. administration. Key aspects include streamlined commitments and nuanced language that may benefit larger AI companies' data practices. The final version will clarify roles and responsibilities of AI model makers.