Colorado Rewrites Major AI Law Ahead of January 2027 Rollout

Bright Defense compliance briefing banner about Colorado rewriting its AI law before the January 2027 rollout, beside the Colorado flag symbol.

Colorado’s Automated Decision-Making Technology Act has replaced the state’s 2024 artificial intelligence law with a transparency regime built on disclosure, notice and human review instead of algorithmic discrimination duties. Signed on May 14, 2026, SB 26-189 requires developers and deployers of covered automated decision-making technology to document intended uses, notify consumers before consequential decisions and…

Read More

Confidence in Automated Pen Testing Drops to 9%

Bright Defense briefing graphic showing confidence in automated penetration testing falling to 9%, with a descending chart.

Support for fully automated penetration testing fell sharply in 2026 as security teams reported missed critical vulnerabilities and moved toward testing models that combine automation with human expertise. Cobalt’s AI and Pentesting Pulse Report 2026 found that only 9% of surveyed security professionals support relying entirely on automation for security testing, down from 29% in…

Read More

EU Unveils Cybersecurity and AI Action Plan

Bright Defense compliance briefing graphic announcing the EU cybersecurity and AI action plan, with a European Union flag and digital globe.

The European Commission launched the EU Action Plan on Cybersecurity and Artificial Intelligence on July 7, 2026, outlining measures for advanced AI model evaluation, controlled cybersecurity testing, faster vulnerability remediation, and European investment in AI security. The plan arrives before the Commission begins exercising AI Act enforcement powers for covered general-purpose AI providers on August…

Read More

Apple Sues OpenAI Over Alleged Trade Secret Theft

Bright Defense compliance briefing graphic about Apple suing OpenAI over alleged trade secret theft, with Apple and OpenAI logos.

Apple sued OpenAI on July 10, 2026, accusing the company and two former Apple employees of misappropriating confidential hardware designs, manufacturing methods, supplier information, and other trade secrets related to future consumer devices. OpenAI denied any interest in competitors’ trade secrets, and no court has ruled that any defendant engaged in wrongdoing. The lawsuit places…

Read More

Claude Fable 5 Restored After U.S. Lifts Export Controls

Bright Defense compliance briefing graphic about Claude Fable 5 being restored after U.S. export controls were lifted.

Anthropic restored global access to Claude Fable 5 on July 1, 2026, ending an 18-day suspension triggered by U.S. export controls over a reported jailbreak discovered during Amazon security testing. Although the restrictions were lifted, the incident exposed unresolved questions about government oversight of frontier AI models, export-control authority, enterprise AI governance, and the responsibilities…

Read More

CMMC Phase 2 Certification Rollout Suspended

Bright Defense compliance briefing graphic announcing the suspension of the CMMC Phase 2 certification rollout.

The Pentagon suspended the CMMC Phase 2 certification rollout on July 13, 2026, delaying mandatory third-party assessments for defense contractors. The decision paused planned Level 2 C3PAO assessments, Level 3 government assessments, and later implementation milestones while a CMMC Reform Task Force reviews program costs, assessment capacity, and possible structural changes.CMMC Phase 1 remains active.…

Read More

DORA Reshapes Cyber Duties For EU Financial Firms

Bright Defense graphic on DORA changing cyber-resilience duties for EU financial firms.

DORA has changed cybersecurity and technology-risk duties for EU financial firms from fragmented national obligations into a binding EU-wide operational resilience regime, with banks, insurers, payment firms, investment firms, and major ICT suppliers now facing stricter governance, incident reporting, testing, and third-party risk rules. The latest confirmed update came on June 3, 2026, when the…

Read More

EU AI Act Enforcement: August 2026 Rules and Deadlines

Bright Defense compliance briefing graphic stating that the EU AI Act takes full effect on August 2, with a European Union flag.

The EU AI Act became broadly applicable on August 2, 2026, bringing Article 50 transparency requirements and stronger regulatory enforcement into effect. The European Commission’s AI Office and national authorities can now enforce applicable provisions, while general-purpose AI model requirements that started in 2025 have entered their full Commission enforcement phase.The regulatory timetable changed shortly…

Read More

HITRUST CSF v11.8.0 Adds AI And Compliance Mappings

Bright Defense graphic on HITRUST CSF v11.8.0 adding AI and compliance mappings.

HITRUST CSF v11.8.0 has added new compliance and AI risk mappings to a widely used security assurance framework, giving healthcare, technology, financial services, and vendor-risk teams a newer reference point for continuous monitoring, privacy, PCI, SOC 2, state law, and large language model risks. The latest confirmed action came on May 8, 2026, when HITRUST…

Read More