Human-centric cybersecurity approach comes to the fore under Chile's new cybersecurity law.
Enacted in Chile, Cybersecurity Framework Law No. 21.663 introduces mandatory risk management and incident reporting for critical infrastructure and essential service providers while shifting the focus of cybersecurity from technical systems alone to the human element. Also aligned with US NIST standards, this approach requires organizations to design their security policies, training programs, and automated systems around the capabilities, limitations, and needs of employees. Experts recommend adopting user-centered and workable security governance rather than overly bureaucratic rules.
Click on the link for the full story.
Brazilian Data Protection Authority releases report recommending comprehensive governance against deepfake risks.
The Brazilian Data Protection Authority published its Technology Radar report, examining the data protection, cybersecurity, and digital fraud risks associated with AI-generated synthetic content (deepfakes). The report emphasizes that combating deepfakes cannot be limited to detection after content is generated; data collection, model training, and dissemination processes must be managed holistically. Companies are advised to act with diligence regarding biometric data usage, product design, and third-party vendor oversight to mitigate risks at the source.
Click on the link for the full story.
Brazilian Data Protection Authority fines TikTok 153.7 million reais over children's data violations.
The Brazilian Data Protection Authority imposed a landmark administrative fine exceeding 153.7 million reais on TikTok for processing personal data of children and adolescents without an appropriate legal basis. In addition to the fine, the Authority mandated the platform to implement more restrictive default settings for users under 16, proving its transition from an advisory role to an active enforcement authority. The nationwide suspension of Discord livestreams and facial recognition systems also marks this new era.
Click on the link for the full story.
Global healthcare AI deployments face complex regulations and cybersecurity risks.
Healthcare organizations face severe compliance challenges in clinical trials and drug development due to diverging data protection and AI regulations across China, the US, and the European Union. Experts highlight that conflicting regulations like the GDPR and the EU AI Act slow innovation, while inadequate security safeguards could put patient data at risk. To address the risk of autonomous AI agents going rogue, organizations are advised to build flexible governance models and establish consensus data management standards.
Click on the link for the full story.
Differential privacy technology emerging in the AI era sparks debate on privacy versus data utility.
Increasingly adopted to prevent large language models from memorizing sensitive data and to enable secure data sharing, differential privacy stands out for its mathematical rigor. However, because its noise-infusion mechanism can reduce data accuracy and mask details of small groups, policy discussions around restricting its use are growing. Experts advocate for standardizing noise levels, open-sourcing algorithms, and advancing this technology rather than reverting to less protective traditional methods.
Click on the link for the full story.
India accelerates digital transformation through Data Protection Act and strict AI regulation steps.
The Indian Government explicitly stated that compliance timelines for the Digital Personal Data Protection Act will not be extended, urging companies to comply immediately with data protection standards. Following Prime Minister Narendra Modi's announcement of a national technology vision covering AI, semiconductors, and data centers for 2047, financial regulators have introduced IT resilience indices and board-level accountability principles for AI deployments. Experts emphasize that data governance has become critical alongside expanding infrastructure investments.
Click on the link for the full story.
European Union's digital governance and AI policies keep human-centric values at the core.
The European Union faces criticism over its complex bureaucratic structure while advancing comprehensive regulatory frameworks such as the Cybersecurity Act, the Cloud and AI Development Act, and the Digital Omnibus. Despite rapid technological transformation, smart glasses, and warnings that AI could pose existential risks to humanity, the EU maintains its trajectory of safeguarding fundamental rights and human-centric values globally. Experts emphasize that this resolute stance ensures long-term trust in global digital governance.
Click on the link for the full story.
US state of Delaware tightens personal data privacy law through comprehensive reforms.
The Governor of Delaware signed into law HB 380, updating the Delaware Personal Data Privacy Act. Effective 1 January 2027, the regulation lowers applicability thresholds to bring more small and midsize businesses within scope. Introducing a "strictly necessary" standard for selling sensitive data, the new law significantly elevates data protection standards through data minimization requirements, third-party vendor oversight, validated due diligence, and mandatory data contracts.
Click on the link for the full story.
AI safety regulations and legal oversight gain momentum ahead of US midterm elections.
Ahead of the upcoming US midterm elections, legislative actions at both state and federal levels are accelerating to address AI system control loss and cybersecurity risks. As bipartisan AI safety bill negotiations continue in Congress, major companies like OpenAI are calling for national and global safety standards. While California enacted laws establishing independent verification and audit registries, transparency demands regarding the White House voluntary framework and congressional investigations remain top of mind.
Click on the link for the full story.
Supreme People's Court of China releases national judicial guidance on AI disputes.
The Supreme People's Court of China announced a new 24-provision judicial policy to guide courts in cases involving AI-driven rights violations, copyright disputes, and data breaches. Rejecting the notion of AI itself as a legal actor and establishing ordinary fault liability as the general rule for torts, the guidance clarifies the responsibilities of developers, providers, and users. The regulation directly impacts companies' model training and data documentation processes, aiming to achieve national judicial consistency.
Click on the link for the full story.