APAC
- Insurance Regulatory and Development Authority of India directed insurers to assess their exposure to AI cyber threats and submit report on action taken.
- The Advertising Standards Council of India published draft guidelines for responsible labelling of AI-generated content in advertising.
- Australia’s OAIC released an issues paper on transparency obligations for automated decision-making.
- South Korea’s PIPC sanctioned five agencies and companies for data protection and oversight violations.
- Singapore’s Cyber Security Agency published advisory on cybersecurity risks associated with a personal AI assistant.
EMEA
- The European Commission launched a consultation on draft guidelines for classification of high-risk AI systems under the EU AI Act.
- UK’s ICO published a guidance to protect organizations from AI-powered cyber threats.
- France’s CNIL imposed EUR 5 million fine on a health technology company for non-compliance in management of health data warehouse.
- Belgium’s DPA fined a public water utility company EUR 86,000 for GDPR violations linked to call recording and monitoring practices.
- Spanish AEPD closed EUR 18 million fine against a travel company for profiling-related violations.
- UK’s Office of Communications imposed GBP 600,000 fine on an entertainment company for failing to implement adequate age verification measures.
- European Cybersecurity Agency published NIS360 report to assess cybersecurity maturity across critical sectors covered by the NIS2 Directive.
- Finland’s legislation supplementing the EU Cyber Resilience Act came into force.
- Monaco’s APDP urged government to revise draft adequacy list for international data transfers.
- Data Protection Authorities of Nordic countries signed the Stockholm Declaration to strengthen regional cooperation.
Americas
- The US Federal Trade Commission reached USD 930,000 settlement with media and marketing companies over deceptive AI advertising claims.
- Texas’ AG filed a lawsuit against a technology company and its messaging platform alleging misrepresentations regarding privacy and encryption.
- Colorado enacted legislation regulating the use of automated decision-making technology.
- Oklahoma’s AG sued an online gaming platform over alleged child safety failures and deceptive practices.
- Brazil’s ANPD announced signing of presidential decrees expanding oversight under the Internet Bill of Rights framework.
- Michigan House lawmakers introduced legislation establishing cybersecurity requirements for large-scale solar energy facilities.
- Colombia’s SIC published adequacy decision recognizing Brazil, Ecuador, Kenya, Panama and South Africa as providing adequate level of data protection.
- California’s AG filed a lawsuit against a biotechnology company for failing to protect customer’s sensitive personal and genetic data.
- Vermont bill on neurological rights regulating AI use in health and human services signed by Governor.
- Florida’s AG initiated legal action against an AI company over alleged deceptive practices and failures to protect children from AI-related risks.
