Multi-layered notification era begins in the healthcare and medtech sectors with the EU Cyber Resilience Act.
Entering into force in the European Union on September 11, 2026, the Cyber Resilience Act combines with NIS2, GDPR, and the Medical Device Regulation to trigger four distinct legal reporting timelines simultaneously during cyber incidents in the healthcare and medtech sectors. Establishing official records in incidents initially detected and reported by data centers will directly impact the legal liabilities of device manufacturers and hospitals. Experts advise properly managing the initial official notification, incorporating notification addendums into contracts, and updating incident response policies according to this four-layered structure.
Click on the link for the full story.
Focusing solely on legal compliance in AI governance risks human autonomy.
While organizations in AI governance generally focus on regulatory compliance and procedural requirements, the gradual negative impacts of automation on human agency, cognitive independence, and decision-making capacity are being overlooked. Noting that algorithmic systems can render employees passive while increasing societal dependence despite providing operational efficiency, experts recommend moving beyond transparency checklists to adopt an interdisciplinary governance approach centered on preserving human autonomy and active participation.
Click on the link for the full story.
Provider security breaches introduce new evidence obligations for user companies under the EU AI Act.
In cybersecurity breaches experienced by AI tool providers, public statements made by the provider alone do not eliminate the legal liability of deployer organizations. Under the EU AI Act, institutions operating high-risk AI systems are required to document the impact of provider-originated incidents on their own systems and data logs. Experts recommend that companies do not rely solely on provider statements, but instead create internal evidence files that analyze the impact on the system, preserve log records, and document decision-making processes.
Click on the link for the full story.
US state privacy laws draw new boundaries for AI model training and data usage.
Comprehensive state-level privacy laws becoming increasingly prevalent in the US expand consumer rights over personal data, creating new obligations for AI developers. Although existing laws do not yet offer a general "opt-out" right for AI training, they restrict companies in areas such as sensitive data usage, deletion requests, and automated profiling. Experts recommend that companies go beyond legal obligations to transparently offer data usage rights in AI training to gain consumer trust and remain prepared for potential legislative changes.
Click on the link for the full story.
Meta reaches a massive $17.1 billion settlement with US states over child safety violation claims.
Meta signed a landmark settlement of up to $17.1 billion with US state attorneys general over allegations of deploying addictive designs on social media platforms that endanger children's mental and physical health. Subject to court approval, Meta will implement radical security measures including default daily time limits for users under 18, nighttime notification blocks, and a ban on cosmetic image filters. The company also called on TikTok and YouTube to adopt similar restrictions.
Click on the link for the full story.
Data sharing and governance hold critical importance in healthcare AI projects.
As the use of AI tools spreads across healthcare institutions, the focus of privacy reviews shifts from the algorithms themselves to the journey of the data. Emphasizing that AI systems do not merely consume data but also generate new outputs, experts state that standard Business Associate Agreements (BAAs) alone are insufficient. Institutions are advised to adopt data minimization principles prior to implementation, define access limits for sensitive data, and maintain active governance against evolving model capabilities after contracts are signed.
Click on the link for the full story.
The US and the EU aim to ensure online child safety through age assurance systems.
Lawmakers and technology companies worldwide are focusing on age assurance systems to restrict children's access to harmful content on online platforms. While US states adopt various models such as ID verification, digital declarations, and app store accountability laws, the European Union is developing a standardized, privacy-preserving, anonymized model compatible with the EU Digital Identity Wallet under the Digital Services Act. Meanwhile, companies are attempting to comply with these regulations through application developer interfaces (APIs) and AI tools.
Click on the link for the full story.
The Italian Data Protection Authority fines newspaper for unlawfully publishing personal health data.
The Italian Data Protection Authority imposed an administrative fine of €23,750 on the newspaper "Il Fatto Quotidiano" for publishing the name, workplace, and health status of a victim in a cable car accident in a detailed and sensationalist manner. Determining that the details in the news text were neither necessary, proportionate, nor indispensable for the purpose of informing the public, the Authority ruled that the newspaper violated the GDPR principles of lawfulness, fairness, and data minimization.
Click on the link for the full story.
The Austrian Data Protection Authority rejects complaint regarding personal data transfer to China.
The Austrian Data Protection Authority decided on a complaint regarding a data transfer by a user who placed an order from a seller in China via an Ireland-based e-commerce platform. Although the DPA noted that the company failed to demonstrate an adequate level of protection against public authority access under standard contractual clauses, it emphasized that the transfer was necessary to perform pre-contractual measures initiated at the user's own request. Accordingly, the DPA found the transfer lawful under the derogations of GDPR Article 49 and rejected the complaint.
Click on the link for the full story.
The Dutch Data Protection Authority fines Uber €824.99 million over automated account deactivation practices.
The Dutch Data Protection Authority determined that Uber used software between 2018 and 2022 to monitor drivers’ behavior and customer ratings, automatically suspending accounts without human intervention. Ruling that these decisions—which prevented drivers from generating income—violated the rules on automated decision-making under Article 22 of the GDPR as well as transparency principles, the DPA imposed an administrative fine of €824.99 million on the company. Uber, which has since terminated these practices, announced that it will challenge the decision.
Click on the link for the full story.