Issue 318

  • Insurance Regulatory and Development Authority of India directed insurers to assess their exposure to AI cyber threats and submit report on action taken.
  • The Advertising Standards Council of India published draft guidelines for responsible labelling of AI-generated content in advertising.
  • Australia’s OAIC released an issues paper on transparency obligations for automated decision-making.
  • South Korea’s PIPC sanctioned five agencies and companies for data protection and oversight violations.
  • Singapore’s Cyber Security Agency published advisory on cybersecurity risks associated with a personal AI assistant.
  • The European Commission launched a consultation on draft guidelines for classification of high-risk AI systems under the EU AI Act.
  • UK’s ICO published a guidance to protect organizations from AI-powered cyber threats.
  • France’s CNIL imposed EUR 5 million fine on a health technology company for non-compliance in management of health data warehouse.
  • Belgium’s DPA fined a public water utility company EUR 86,000 for GDPR violations linked to call recording and monitoring practices.
  • Spanish AEPD closed EUR 18 million fine against a travel company for profiling-related violations.
  • UK’s Office of Communications imposed GBP 600,000 fine on an entertainment company for failing to implement adequate age verification measures.
  • European Cybersecurity Agency published NIS360 report to assess cybersecurity maturity across critical sectors covered by the NIS2 Directive.
  • Finland’s legislation supplementing the EU Cyber Resilience Act came into force.
  • Monaco’s APDP urged government to revise draft adequacy list for international data transfers.
  • Data Protection Authorities of Nordic countries signed the Stockholm Declaration to strengthen regional cooperation.
  • The US Federal Trade Commission reached USD 930,000 settlement with media and marketing companies over deceptive AI advertising claims.
  • Texas’ AG filed a lawsuit against a technology company and its messaging platform alleging misrepresentations regarding privacy and encryption.
  • Colorado enacted legislation regulating the use of automated decision-making technology.
  • Oklahoma’s AG sued an online gaming platform over alleged child safety failures and deceptive practices.
  • Brazil’s ANPD announced signing of presidential decrees expanding oversight under the Internet Bill of Rights framework.
  • Michigan House lawmakers introduced legislation establishing cybersecurity requirements for large-scale solar energy facilities.
  • Colombia’s SIC published adequacy decision recognizing Brazil, Ecuador, Kenya, Panama and South Africa as providing adequate level of data protection.
  • California’s AG filed a lawsuit against a biotechnology company for failing to protect customer’s sensitive personal and genetic data.
  • Vermont bill on neurological rights regulating AI use in health and human services signed by Governor.
  • Florida’s AG initiated legal action against an AI company over alleged deceptive practices and failures to protect children from AI-related risks.