Cyber Law Watch

Insight on how cyber risk is being mitigated and managed across the globe.

1
EU Digital Omnibus on AI Enters Into Force
2
EU AI Act: Final Guidelines on Transparency Obligations Under Article 50
3
AI Models Were Asked To Solve The Test But Instead Hacked The Examiner
4
EDPB Adopts Common Data Breach Notification Template
5
An AFS Licensee First: Receiving an Order to Pay AU$2.5 Million for Cybersecurity Failures
6
ICO Publishes Soft Opt-in Electronic Marketing Guidance for United Kingdom Charities
7
Washington State Enacts First-of-Its-Kind Chatbot Disclosure Law
8
Mixed Blessings: Decision on Appeal by Bunnings Against Privacy Commissioner’s Determination Re the Use of Facial Recognition Technology
9
NSW Expands Surveillance Powers and Introduces Public Interest Protections
10
Australia’s Privacy Regulator Beginning 2026 With Its First Compliance Sweep

EU Digital Omnibus on AI Enters Into Force

By: Sarah Pearce and Thomas Nietsch

The EU has adopted its first substantive amendment to the AI Act. Regulation (EU) 2026/1744, commonly referred to as the AI Omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. While the legislation postpones certain aspects of the AI Act’s compliance timetable, it would be a mistake for organisations to view the Omnibus as a broad pause on AI regulation in Europe.

Read More

EU AI Act: Final Guidelines on Transparency Obligations Under Article 50

By: Sarah Pearce and Veronica Muratori

On 20 July 2026, the European Commission published its final Guidelines on the transparency obligations under Article 50 of the EU AI Act. Although non-binding, the Guidelines provide important practical clarification ahead of the application of these obligations. Article 50 is not limited to high-risk AI systems and may apply to a broad range of AI solutions, including chatbots, generative AI tools, emotion recognition systems, biometric categorization tools, and deepfake technologies.

Read More

AI Models Were Asked To Solve The Test But Instead Hacked The Examiner

By: Cameron Abbott and Emre Cakmakcioglu

An artificial intelligence research organisation has released a statement detailing how two of its cybersecurity models escaped from an internal testing sandbox to hack AI research platform Hugging Face.

Read More

An AFS Licensee First: Receiving an Order to Pay AU$2.5 Million for Cybersecurity Failures

By: Cameron Abbott, Daniel Knight, Rob Pulham, Alex Parker, Madison Jeffreys, Emre Cakmakcioglu and Annaliese Filippis

In a key decision against an Australian financial services licence (AFSL) holder, the Federal Court of Australia has ordered the AFSL holder to pay AU$2.5 million in penalties for inadequate cybersecurity measures. The Australian Securities and Investments Commission (ASIC) took action following a cyberattack on the AFSL holder’s IT systems, resulting in approximately 385GB of data being downloaded from its servers. 

Read More

ICO Publishes Soft Opt-in Electronic Marketing Guidance for United Kingdom Charities

By: Dr. Thomas Nietsch and Noirin M. McFadden

The UK’s data protection regulator, the Information Commissioner’s Office (ICO) has published guidance for charities to use the new charitable purposes soft opt-in for electronic marketing.

Read More

Washington State Enacts First-of-Its-Kind Chatbot Disclosure Law

By: Nicole H. Buckley and Whitney E. McCollum

Washington State Governor Bob Ferguson recently signed House Bill 2225 (the Chatbot Disclosure Act) into law, effective 1 January 2027. The Chatbot Disclosure Act requires people and entities who operate AI “companion” chatbots to provide clear and ongoing disclosure to Washington consumers that they are interacting with an automated system and not a human being.

Read More

Mixed Blessings: Decision on Appeal by Bunnings Against Privacy Commissioner’s Determination Re the Use of Facial Recognition Technology

By: Cameron Abbott and Rob Pulham

The Administrative Review Tribunal of Australia (Tribunal) has partially overturned the findings of the Privacy Commissioner on Bunnings’ use of facial recognition technology (FRT) in its stores.

Read More

NSW Expands Surveillance Powers and Introduces Public Interest Protections

By Cameron Abbott, Damien Timms and Maryam Ahmed (Graduate, Melbourne)

The NSW Government has announced legislative reforms that will enhance the surveillance powers of investigative agencies including NSW’s Independent Commission Against Corruption (ICAC).

Read More

Australia’s Privacy Regulator Beginning 2026 With Its First Compliance Sweep

By: Rob Pulham, Cameron Abbott, and Annaliese Filippis (Graduate, Melbourne)

The Office of the Australian Information Commissioner (OAIC), Australia’s privacy regulator, is conducting its first ever privacy compliance sweep, as of this January. The compliance sweep will include a review of the privacy policies of businesses that collect information in person.

Read More

Copyright © 2026, K&L Gates LLP. All Rights Reserved.