regulation

In a Landmark Decision, EU Court Clarifies When Pseudonymised Data Is Not Personal Data Under the GDPR

The ECJ clarified that pseudonymized data does not always constitute personal data under the GDPR; its classification depends on whether the recipient can reasonably reidentify individuals by considering technical, organizational, and legal factors. The perspective of the data recipient is critical; if they cannot realistically identify individuals, GDPR does not apply to that data. However, this is not an unlimited exemption—if reidentification is possible through access or contractual means, the GDPR requirements still apply. Data controllers must still be transparent, document their processes carefully, and regularly update their assessments and contracts. This decision may reduce GDPR compliance burdens and encourage broader data use for analytics and AI, provided that the risks of reidentification are effectively managed.

https://www.jdsupra.com/legalnews/in-a-landmark-decision-eu-court-7439040/

The EU Can’t Figure Out What to Do About ChatGPT

EU regulators are slow to define rules for regulating ChatGPT, despite its rapid user growth. OpenAI's chatbot must comply with the EU's Digital Services Act (DSA) and AI Act, but clarity on its categorization and requirements is lacking until mid-2026. The discrepancy between these laws and their alignment with ChatGPT's functionalities pose challenges in assessing risks, particularly regarding public health and elections. Potential penalties for non-compliance could be substantial.

https://www.politico.eu/article/eu-chatgpt-ai-digital-law-tech-openai-regulations-legal/

Biological AI Is Slipping Through Europe’s AI Law — For Now

EU's AI Act lacks regulation for biological AI models (BAIMs) which could pose significant biosecurity risks. Despite recognizing biological threats, existing guidance primarily applies to general-purpose AI like language models, leaving BAIMs potentially unregulated. Clarifying that BAIMs can be classified under the Act is crucial to prevent misuse and enhance safety, as these models can facilitate dangerous biological actions while the current laws create a regulatory blind spot. Timely intervention is essential as BAIM capabilities develop, ensuring oversight aligns with emerging biological risks.

https://www.techpolicy.press/biological-ai-is-slipping-through-europes-ai-law-for-now/

Navigating Geopolitical, Regulatory Issues in the Cloud

Modern cloud environments face challenges due to geopolitical issues, diverse regulations, and data localization demands. CIOs are now advised to use sovereign and federated cloud strategies to manage these complexities effectively while maintaining compliance and operational efficiency.

https://www.informationweek.com/cloud-computing/the-fractured-cloud-how-cios-can-navigate-geopolitical-and-regulatory-complexity

Top 10 Cybersecurity Frameworks Every CISO Should Know

CISOs should focus on top cybersecurity frameworks: NIST CSF 2.0 for strategy, ISO 27001 for ISMS, CIS Controls v8.1 for safeguards, NIST 800-53 for controls, SOC 2 for assurance, PCI DSS v4.0.1 for cardholder data, MITRE ATT&CK for threat defense, CSA CCM v4 for cloud, IEC 62443 for OT, and NERC CIP for the power grid. Current frameworks ensure compliance and preparedness against regulations, improving overall security postures.

https://programminginsider.com/top-10-cybersecurity-frameworks-every-ciso-should-know/

Around 70 Countries Sign New UN Cybercrime Convention—but Not Everyone’s on Board

Around 70 countries signed a UN Cybercrime Convention aiming to combat cybercrime through global cooperation. The treaty requires 40 states to ratify it to become law, yet the US is not among signatories, citing ongoing review. There are concerns about privacy erosion, expanded surveillance powers, and potential misuse by authoritarian governments. Critics argue the treaty's vague provisions could hamper legitimate cybersecurity efforts and lack adequate protections for human rights and due process.

https://www.malwarebytes.com/blog/news/2025/10/around-70-countries-sign-new-un-cybercrime-convention-but-not-everyones-on-board

How Evolving Regulations Are Redefining CISO Responsibility

CISOs face growing personal and criminal liability as cyberattacks targeting vulnerabilities in IoT and OT devices increase. Global regulations now require stricter cyber risk management, transparency, and compliance, with 20% of breaches in 2025 linked to device vulnerabilities. CISOs are expected to provide accurate asset inventories, honest reporting, prompt breach disclosure, and the management of third-party risks. Organizations are updating policies, boosting legal support, and enhancing security oversight to adapt.

https://www.csoonline.com/article/4079450/how-evolving-regulations-are-redefining-ciso-responsibility.html

Europe Wrote the AI Rulebook. Can It Deliver on Its Ambitions?

Europe's AI Act and Apply AI Strategy aim for values-based AI regulation and innovation, despite pressure from US tech companies to delay enforcement. Effective regulation is crucial for trust, investment security, and consumer protection. Europe’s technological and democratic sovereignty hinges on prioritizing public values over mere market convenience. The goal is a complementary AI Democracy Action plan to enhance governance and reduce dependency on US tech, affirming Europe's commitment to democratic digital sovereignty and fundamental rights.

https://www.techpolicy.press/europe-wrote-the-ai-rulebook-can-it-deliver-on-its-ambitions/

Why Companies Need a Chief Trust Officer Today

CTrO Essential: Centralizes trust across security, IT, and governance. Establishes accountability, reduces friction in deals, and addresses regulatory scrutiny. With increasing AI adoption, CTrOs ensure standards and policies align with accountability measures, enhancing innovation while safeguarding against risks. Trust must be observable and manageable for effective organizational response and stakeholder confidence.

https://www.scworld.com/perspective/why-companies-need-a-chief-trust-officer-today

Scroll to Top