Most security commentators believe that quantum computing will put the “cracking” of public-key cryptography in reach. This underscores the importance of preparing for the quantum revolution from a legal and security perspective. Here we consider where to start in that
Rhode Island’s new AI and healthcare privacy law

We recently published an article to commemorate AI Appreciation Day, but readers may also appreciate a law that recently passed In Rhode Island, known as the “Use of Artificial Intelligence by Healthcare Providers Notification Act.” The bill…
AI Appreciation Day 2026 and key developments in governance and compliance
As artificial intelligence (AI) becomes embedded in business operations, data protection frameworks are increasingly shaping how organizations manage AI use. This update highlights key regulatory developments, including risk-based approaches and sector-specific rules, and outlines practical considerations for compliance…
Record €18m fine for an IT service provider to the aviation sector – reuse of customer data

Spain’s data protection agency, the Agencia Española de Protección de Datos (AEPD), has fined Amadeus IT Group, S.A. (Amadeus) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026…
NYDFS issues guidance “in a heightened cybersecurity environment”
On May 21, 2026, the New York Department of Financial Services (NYDFS) issued industry guidance to licensees regarding security measures they should consider taking “in a heightened cybersecurity threat environment.” Even organizations not subject to NYDFS regulation may want to …
Is my use case a high-risk AI system? Applying the Commission’s guidelines and next steps

The EU Commission’s long-awaited guidelines on high-risk AI systems were published on 19 May 2026. This is the promised explainer on what is – and is not – a high-risk AI system under the EU AI Act.
The guidelines
The…
When AI becomes the cyber attacker: Mythos and what comes next
Anthropic’s April 7, 2026 announcement that it built a model too powerful for public consumption, Claude Mythos Preview (Mythos), marks a notable moment for the legal, compliance, and cybersecurity communities. It is no surprise that the US Department of the…
Colorado’s new AI governance law
We recently published an alert that highlights Colorado’s new artificial intelligence (AI) governance law. After X.AI sued to enjoin enforcement of Colorado’s first AI governance law and the federal government moved to intervene, the Colorado Attorney General agreed to temporarily…
Colorado AI Act: DOJ Steps In As X.AI Suit Pauses
We recently published an alert that highlights recent developments in the case filed by X.AI LLC seeking to enjoin enforcement of Colorado’s Senate Bill 24-205 (SB-24-205), often referred to as the Colorado AI Act (the AI Act). The AI Act…
NYDFS Cybersecurity Enforcement: US$2.25m Fine Against Delta Dental

On April 30, 2026, the New York Department of Financial Services (NYDFS) announced a consent order with Delta Dental Insurance Company and Delta Dental of New York, Inc. for alleged violations of the NYDFS Cybersecurity Regulation relating to the 2023…















