Skip to content

menu

Data Protection Report logo
Current Page:HomeAboutContact
Search
Close
Compliance and risk managementRegulatory responseData breachCybersecurity
View topics Archives
Subscribe

Data Protection Report

Data protection legal insight at the speed of technology

Is my use case a high-risk AI system? Applying the Commission’s guidelines and next steps

Photo of Rosie NancePhoto of Marcus Evans (UK)
By Rosie Nance & Marcus Evans (UK) on May 22, 2026

The EU Commission’s long-awaited guidelines on high-risk AI systems were published on 19 May 2026.  This is the promised explainer on what is – and is not – a high-risk AI system under the EU AI Act.

The guidelines

The…

Subscribe to Data Protection Report

Subscribe to this publication

When AI becomes the cyber attacker: Mythos and what comes next

Photo of Will Daugherty (US)Photo of Ji Won Kim (US)Photo of Remi Gambino (US)Photo of Phillip Pang (US)
By Will Daugherty (US), Ji Won Kim (US), Remi Gambino (US) & Phillip Pang (US) on May 21, 2026

Anthropic’s April 7, 2026 announcement that it built a model too powerful for public consumption, Claude Mythos Preview (Mythos), marks a notable moment for the legal, compliance, and cybersecurity communities. It is no surprise that the US Department of the…

Colorado’s new AI governance law

Photo of Marc Collier (US)Photo of Helen Christakos (US)Photo of Susana Medeiros (US)Photo of Ethan Glenn (US)Photo of Remi Gambino (US)Photo of Shushan Gabrielyan (US)
By Marc Collier (US), Helen Christakos (US), Susana Medeiros (US), Ethan Glenn (US), Remi Gambino (US) & Shushan Gabrielyan (US) on May 20, 2026

We recently published an alert that highlights Colorado’s new artificial intelligence (AI) governance law. After X.AI sued to enjoin enforcement of Colorado’s first AI governance law and the federal government moved to intervene, the Colorado Attorney General agreed to temporarily…

Colorado AI Act: DOJ Steps In As X.AI Suit Pauses

Photo of Marc Collier (US)Photo of Helen Christakos (US)Photo of Ethan Glenn (US)Photo of Remi Gambino (US)Photo of Shushan Gabrielyan (US)
By Marc Collier (US), Helen Christakos (US), Ethan Glenn (US), Remi Gambino (US) & Shushan Gabrielyan (US) on May 12, 2026

We recently published an alert that highlights recent developments in the case filed by X.AI LLC seeking to enjoin enforcement of Colorado’s Senate Bill 24-205 (SB-24-205), often referred to as the Colorado AI Act (the AI Act). The AI Act…

NYDFS Cybersecurity Enforcement: US$2.25m Fine Against Delta Dental

Photo of Susana Medeiros (US)Photo of Susan Ross (US)
By Susana Medeiros (US) & Susan Ross (US) on May 8, 2026

On April 30, 2026, the New York Department of Financial Services (NYDFS) announced a consent order with Delta Dental Insurance Company and Delta Dental of New York, Inc. for alleged violations of the NYDFS Cybersecurity Regulation relating to the 2023…

UK data protection complaints – new complaints handling obligations for controllers from 19 June

Photo of Elaine HilesPhoto of Rosie Nance
By Elaine Hiles & Rosie Nance on April 27, 2026

The changes to data controllers’ complaints handling obligations, made via the Data (Use and Access) Act, will come into force on 19 June 2026.  These include a new obligation to acknowledge complaints within 30 days, respond without undue delay, and…

How to approach governance of AI agents

Photo of Susana Medeiros (US)Photo of Steve Roosa (US)Photo of Wenda Tang (US)
By Susana Medeiros (US), Steve Roosa (US) & Wenda Tang (US) on April 13, 2026

Current approaches to agentic AI governance seem more focused on trying to apply governance after a system is developed, like a Band-Aid, instead of baking in reasonable governance and controls into the guts of the system. In the same way…

Navigating AI compliance with HIPAA essentials

Photo of Susan Ross (US)
By Susan Ross (US) on April 7, 2026

Healthcare providers are increasingly deploying artificial intelligence (AI) tools for diagnostics, documentation and operational efficiency. In fact, over the last few months, large AI platforms are now marketing AI-enabled tools directly to healthcare providers. Providers must navigate a…

Complaint accuses OpenAI of practicing law without a license

Photo of Susan Ross (US)
By Susan Ross (US) on April 6, 2026

A popular public AI tool has been accused in federal court of practicing law without a license.  Please see the post on the Artificial Intelligence page of Inside Tech Law: AI in litigation series: Complaint accuses OpenAI of practicing law…

NY DFS’s new MFA guidance: closing common gaps before the next exam

Photo of Ji Won Kim (US)Photo of Susan Ross (US)
By Ji Won Kim (US) & Susan Ross (US) on March 23, 2026

Multi‑factor authentication (MFA) is now a well-established baseline cybersecurity control. The amended New York Department of Financial Services (NY DFS) solidified that understanding and expanded MFA requirements under 23 NYCRR Part 500 (the NY DFS…

Post navigation

Older Posts 
The latest from our blog network
Norton Rose Blog Network
Global Regulation Tomorrow

HMT letter on transition and implementation of the UK Cryptoasset Regulatory Regime

May 29, 2026
Global Regulation Tomorrow

FCA PS26/8: Retail banking business models data

May 29, 2026
Global Regulation Tomorrow

ESMA annual report on the quality and use of regulatory data

May 29, 2026
Global Regulation Tomorrow

Commission Delegated Regulation supplementing the CRR with regard to RTS specifying operational risk requirements

May 29, 2026
Global Regulation Tomorrow

Handbook Notice 141

May 29, 2026
Global Regulation Tomorrow

Ultra Electronics Deferred Prosecution Agreement: Five Key Points

May 28, 2026
Global Regulation Tomorrow

FCA’s benchmark calculations review

May 28, 2026
Global Regulation Tomorrow

FCA publishes findings from a review of sanctions systems and controls in firms

May 28, 2026
Global Regulation Tomorrow

PRA PS15/26 (Pillar 2A review) Phase 1

May 28, 2026
View the Norton Rose blog network

Data Protection Report

Facebook Twitter RSS LinkedIn YouTube
Published by
Norton Rose Fulbright LLP logo
DisclaimerPrivacy policy

About

More than a news source, the Data Protection Report provides thought leadership on emerging privacy, data protection and cybersecurity issues, and helps its readers proactively address risks and anticipate next steps in this crucial emerging field.

Read more

Topics

Archives

Copyright © 2026, Norton Rose Fulbright LLP. All rights reserved.