EU KIDS Act
By: Sarah Pearce and Veronica Muratori
On 17 September 2026, the European Commission presented the EU KIDS Act, aimed at strengthening the protection of minors online and reducing fragmentation across Member States.
Read MoreInsight on how cyber risk is being mitigated and managed across the globe.
By: Sarah Pearce and Veronica Muratori
On 17 September 2026, the European Commission presented the EU KIDS Act, aimed at strengthening the protection of minors online and reducing fragmentation across Member States.
Read MoreBy: Cameron Abbott, Daniel Knight, Rob Pulham and Emre Cakmakcioglu
Western intelligence alliance Five Eyes has issued a strong warning to business leaders: AI-driven transformation of cyber risk is already here, and the time to act is now.
Read MoreBy: Cameron Abbott, Rob Pulham and Emre Cakmakcioglu
The Australian Privacy Commissioner has determined that Monash IVF and a telehealth company have interfered with the privacy of website visitors via tracking pixels, without obtaining end-user consent.
Read MoreBy: Cameron Abbott, Daniel Knight, Rob Pulham and Emre Cakmakcioglu
Mere days after an AI firm’s model hacked into Hugging Face, a separate AI company has now revealed that three of its models have hacked into three external companies during testing.
Read MoreBy: Cameron Abbott, Rob Pulham, and Emre Cakmakcioglu
The Office of the Australian Information Commissioner (OAIC) has published updated guidance for entities considering using facial recognition technology (FRT) in high-volume, publicly accessible physical spaces, like retail shopfronts.
Read MoreBy: Sarah Pearce and Sophie Verstraeten
The European Data Protection Board (EDPB) has called on the European Commission to assess the implications of the recent US Supreme Court decision in Trump v. Slaughter for the EU-US Data Privacy Framework (DPF), the mechanism that facilitates transfers of personal data between the EU and participating US organisations.
Read MoreBy: Sarah Pearce and Thomas Nietsch
The EU has adopted its first substantive amendment to the AI Act. Regulation (EU) 2026/1744, commonly referred to as the AI Omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. While the legislation postpones certain aspects of the AI Act’s compliance timetable, it would be a mistake for organisations to view the Omnibus as a broad pause on AI regulation in Europe.
Read MoreBy: Sarah Pearce and Veronica Muratori
On 20 July 2026, the European Commission published its final Guidelines on the transparency obligations under Article 50 of the EU AI Act. Although non-binding, the Guidelines provide important practical clarification ahead of the application of these obligations. Article 50 is not limited to high-risk AI systems and may apply to a broad range of AI solutions, including chatbots, generative AI tools, emotion recognition systems, biometric categorization tools, and deepfake technologies.
Read MoreBy: Cameron Abbott and Emre Cakmakcioglu
An artificial intelligence research organisation has released a statement detailing how two of its cybersecurity models escaped from an internal testing sandbox to hack AI research platform Hugging Face.
Read MoreBy: Sarah Pearce and Veronica Muratori
One of the more practically significant outcomes of the European Data Protection Board (EDPB)’s June 2026 plenary session, was the adoption of a common template for personal data breach notifications under the GDPR.
Read MoreCopyright © 2026, K&L Gates LLP. All Rights Reserved.