AI, Friend or Foe?

AI: Friend or Foe?
Experts discuss AI legislation's future, moving focus from capabilities to regulation. Bunnings’ facial recognition case highlights privacy concerns and the need for risk-based regulatory frameworks, as seen in the EU's 2024 AI Act. A global consensus on AI's societal benefits is needed, emphasizing ethical principles over tech-specific laws. Trust in AI is crucial, particularly regarding open-source models. The call for regulations promotes safe AI deployment while balancing innovation, with Australian laws lagging behind global standards.

https://www.monash.edu/alumni/monash-life/articles-2025/ai-friend-or-foe

CJEU: Trade Secrets Protection Does Not Automatically Trump GDPR Disclosure

CJEU ruling clarifies that trade secrets protection does not override GDPR disclosure obligations. Businesses may have to share algorithms used in automated decision-making if deemed necessary by courts or regulators to meet data subject access rights under GDPR. This ruling emphasizes the need for information provided to be clear and understandable, rather than merely technical.

https://www.pinsentmasons.com/out-law/news/cjeu-trade-secrets-gdpr-disclosure

A Quarter of Startups in YC’s Current Cohort Have Codebases That Are Almost Entirely AI-generated

A quarter of Y Combinator's current startups have primarily AI-generated code, with 95% of their codebases created by AI. Founders are technical and capable but now rely on AI for coding. Concerns exist about AI-generated code introducing bugs and security flaws, emphasizing the need for developers to retain coding skills for debugging. The trend, considered by investors to be lasting, is termed “vibe coding,” where intuition is key in coding with AI assistance.

https://techcrunch.com/2025/03/06/a-quarter-of-startups-in-ycs-current-cohort-have-codebases-that-are-almost-entirely-ai-generated/

18 Cybersecurity Tools That May Cause a False Sense Of Security

18 cybersecurity tools create a false sense of security; adding more doesn't always enhance protection and can introduce complexities or vulnerabilities. Reliance on standard measures like traditional antivirus, SMS-based 2FA, and certifications can obscure real threats. Proper security requires holistic approaches, employee education, and continuous monitoring, not just tool accumulation.

https://www.forbes.com/councils/forbestechcouncil/2025/03/07/18-cybersecurity-tools-that-may-cause-a-false-sense-of-security/

NIST Releases Draft Cybersecurity White Paper on Crypto Agility, Aims to Shape Future Cybersecurity Strategies

NIST released a draft cybersecurity white paper on crypto agility, analyzing strategies and challenges for adapting cryptographic algorithms. The paper highlights the need for operational mechanisms to ensure security and interoperability during algorithm transitions, especially in light of threats from future quantum computing. NIST seeks stakeholder input to develop sector-specific strategies and emphasizes collaboration among experts to enhance cryptographic resilience.

https://industrialcyber.co/nist/nist-releases-draft-cybersecurity-white-paper-on-crypto-agility-aims-to-shape-future-cybersecurity-strategies/

What PCI DSS V4 Really Means

PCI DSS v4 mandates stricter payment security standards impacting third-party scripts and continuous monitoring. Businesses risk $100,000/month fines for non-compliance, highlighted by Abercrombie & Fitch's experience with audits, script security, and tamper detection. Key challenges include managing third-party dependencies and ongoing compliance. A&F’s journey stresses the importance of proactive risk assessment and continuous monitoring to mitigate potential attacks and fines. Compliance isn't a one-time effort; regular audits and vendor reviews are essential. The deadline looms on March 31, 2025, emphasizing immediate action for security and compliance.

https://thehackernews.com/2025/03/what-pci-dss-v4-really-means-lessons.html

EU’s Ai Dilemma: Balancing Regulation, Competitiveness, and Global Pressures  –

EU aims to balance AI regulation with global competitiveness amid pressures from the U.S. and China. The EU's regulatory-first approach prioritizes ethical values but risks economic growth. Recent initiatives, such as the AI Act and substantial investments in AI, aim to enhance competitiveness while facing challenges like resource dependency and complex legislation. The EU must simplify regulations without compromising human rights to become a leader in ethical AI, attract investment, and sustain its geopolitical influence. However, achieving consensus among member states and securing funding remains critical for successful implementation.

https://iari.site/2025/03/07/eus-ai-dilemma-balancing-regulation-competitiveness-and-global-pressures/

Measured Approach’ or Light-handed GPDR? Noyb Reports Only 1.3 Percent of EU Cases Result in Fine

1.3% of EU GDPR cases result in fines, contrary to initial fears of severe penalties for noncompliance. Noyb's report indicates low enforcement, allowing large companies to neglect access requests without consequences. Countries like Spain and France are strict enforcers, while others like the UK favor guidance over penalties.

https://www.complianceweek.com/regulatory-enforcement/measured-approach-or-light-handed-gpdr-noyb-reports-only-13-percent-of-eu-cases-result-in-fine/35860.article

CJEU Clarifies GDPR Rights on Automated Decision-Making and Trade Secrets

CJEU clarifies GDPR rights regarding automated decision-making and trade secrets. On February 27, 2025, the court ruled that data controllers must give clear, accessible information about automated decisions impacting individuals, without sacrificing trade secrets. It emphasized the balance between data subject rights and commercial interests and stated national laws cannot broadly exclude access to data based on trade secrets. Companies must ensure transparency while still protecting proprietary information, aligning with the explainability requirements in the AI Act.

https://www.insideprivacy.com/gdpr/cjeu-clarifies-gdpr-rights-on-automated-decision-making-and-trade-secrets/

How AI Tools Are Reshaping the Coding Workforce

AI tools are transforming the coding workforce by automating code development, resulting in greater efficiency but also altering hiring practices. Companies are using generative AI tools like GitHub Copilot to enable leaner development teams, shifting the focus from repetitive tasks to complex problem-solving and AI tool utilization. As hiring becomes more selective, there's a growing demand for candidates with critical thinking and communication skills rather than just coding ability. Despite potential job displacement, top talent remains essential. The coding tools are still in early stages, with a significant gap between current capabilities and future potential.

https://www.wsj.com/articles/how-ai-tools-are-reshaping-the-coding-workforce-6ad24c86

Scroll to Top