news
Colorado Rewrites Major AI Law Ahead of January 2027 Rollout
Colorado’s Automated Decision-Making Technology Act has replaced the state’s 2024 artificial intelligence law with a transparency regime built on disclosure, notice and human review instead of algorithmic discrimination duties. Signed on May 14, 2026, SB 26-189 requires developers and deployers of covered automated decision-making technology to document intended uses, notify consumers before consequential decisions and…
Read MoreConfidence in Automated Pen Testing Drops to 9%
Support for fully automated penetration testing fell sharply in 2026 as security teams reported missed critical vulnerabilities and moved toward testing models that combine automation with human expertise. Cobalt’s AI and Pentesting Pulse Report 2026 found that only 9% of surveyed security professionals support relying entirely on automation for security testing, down from 29% in…
Read MoreEU Unveils Cybersecurity and AI Action Plan
The European Commission launched the EU Action Plan on Cybersecurity and Artificial Intelligence on July 7, 2026, outlining measures for advanced AI model evaluation, controlled cybersecurity testing, faster vulnerability remediation, and European investment in AI security. The plan arrives before the Commission begins exercising AI Act enforcement powers for covered general-purpose AI providers on August…
Read MoreApple Sues OpenAI Over Alleged Trade Secret Theft
Apple sued OpenAI on July 10, 2026, accusing the company and two former Apple employees of misappropriating confidential hardware designs, manufacturing methods, supplier information, and other trade secrets related to future consumer devices. OpenAI denied any interest in competitors’ trade secrets, and no court has ruled that any defendant engaged in wrongdoing. The lawsuit places…
Read MoreClaude Fable 5 Restored After U.S. Lifts Export Controls
Anthropic restored global access to Claude Fable 5 on July 1, 2026, ending an 18-day suspension triggered by U.S. export controls over a reported jailbreak discovered during Amazon security testing. Although the restrictions were lifted, the incident exposed unresolved questions about government oversight of frontier AI models, export-control authority, enterprise AI governance, and the responsibilities…
Read MoreCMMC Phase 2 Certification Rollout Suspended
The Pentagon suspended the CMMC Phase 2 certification rollout on July 13, 2026, delaying mandatory third-party assessments for defense contractors. The decision paused planned Level 2 C3PAO assessments, Level 3 government assessments, and later implementation milestones while a CMMC Reform Task Force reviews program costs, assessment capacity, and possible structural changes.CMMC Phase 1 remains active.…
Read MoreDORA Reshapes Cyber Duties For EU Financial Firms
DORA has changed cybersecurity and technology-risk duties for EU financial firms from fragmented national obligations into a binding EU-wide operational resilience regime, with banks, insurers, payment firms, investment firms, and major ICT suppliers now facing stricter governance, incident reporting, testing, and third-party risk rules. The latest confirmed update came on June 3, 2026, when the…
Read MoreEU AI Act Enforcement: August 2026 Rules and Deadlines
The EU AI Act became broadly applicable on August 2, 2026, bringing Article 50 transparency requirements and stronger regulatory enforcement into effect. The European Commission’s AI Office and national authorities can now enforce applicable provisions, while general-purpose AI model requirements that started in 2025 have entered their full Commission enforcement phase.The regulatory timetable changed shortly…
Read MoreEU AI Act Pushes ISO/IEC 42001 Into AI Compliance Planning
The EU AI Act is driving interest in ISO/IEC 42001 certification as companies search for a practical way to document AI governance before enforcement and customer reviews intensify. The standard does not replace the AI Act, but it gives providers, deployers and vendors an auditable management system for AI risk, oversight, documentation, monitoring and accountability.Why…
Read MoreHITRUST CSF v11.8.0 Adds AI And Compliance Mappings
HITRUST CSF v11.8.0 has added new compliance and AI risk mappings to a widely used security assurance framework, giving healthcare, technology, financial services, and vendor-risk teams a newer reference point for continuous monitoring, privacy, PCI, SOC 2, state law, and large language model risks. The latest confirmed action came on May 8, 2026, when HITRUST…
Read More