As cyber incidents become more costly and complex, organisations are facing increasing exposure to personal data claims, mass actions and contractual disputes. We explore the key litigation trends, emerging risks and practical considerations shaping the UK data breach claims landscape.
NYDFS levies $250,000 fine on licensee for inadequate cyber risk assessment
On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation…
The EU AI Act – when does it become enforceable now?

The Digital Omnibus on AI (AI Omnibus) has now been published in the EU’s statute book. This pushes back some of the application dates for the AI Act. So, what’s applicable now and when will the rest become applicable? This post gives an overview of key dates to be aware of and a timeline of when the obligations now become enforceable.…
Quantum computing and cyber risk


Most security commentators believe that quantum computing will put the “cracking” of public-key cryptography in reach. This underscores the importance of preparing for the quantum revolution from a legal and security perspective. Here we consider where to start in that…
Rhode Island’s new AI and healthcare privacy law

We recently published an article to commemorate AI Appreciation Day, but readers may also appreciate a law that recently passed In Rhode Island, known as the “Use of Artificial Intelligence by Healthcare Providers Notification Act.” The bill…
AI Appreciation Day 2026 and key developments in governance and compliance
As artificial intelligence (AI) becomes embedded in business operations, data protection frameworks are increasingly shaping how organizations manage AI use. This update highlights key regulatory developments, including risk-based approaches and sector-specific rules, and outlines practical considerations for compliance…
Record €18m fine for an IT service provider to the aviation sector – reuse of customer data

Spain’s data protection agency, the Agencia Española de Protección de Datos (AEPD), has fined Amadeus IT Group, S.A. (Amadeus) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026…
NYDFS issues guidance “in a heightened cybersecurity environment”
On May 21, 2026, the New York Department of Financial Services (NYDFS) issued industry guidance to licensees regarding security measures they should consider taking “in a heightened cybersecurity threat environment.” Even organizations not subject to NYDFS regulation may want to …
Is my use case a high-risk AI system? Applying the Commission’s guidelines and next steps

The EU Commission’s long-awaited guidelines on high-risk AI systems were published on 19 May 2026. This is the promised explainer on what is – and is not – a high-risk AI system under the EU AI Act.
The guidelines
The…
When AI becomes the cyber attacker: Mythos and what comes next
Anthropic’s April 7, 2026 announcement that it built a model too powerful for public consumption, Claude Mythos Preview (Mythos), marks a notable moment for the legal, compliance, and cybersecurity communities. It is no surprise that the US Department of the…








