GDPR accountability for AI agents: why your governance must be reviewed per agent and per session
IAPP, NIST and the EDPB warn that privacy governance was not built for autonomous AI agents. Here is how to treat agents as manage…
81 articles
IAPP, NIST and the EDPB warn that privacy governance was not built for autonomous AI agents. Here is how to treat agents as manage…
Multilingual privacy notices, DPIAs and AI output diverge across jurisdictions. Here is how to make translation and localisation a…
AI hallucinations stem from training objectives and shape decision-making. Here is how to build a per-workflow verification layer …
Recent bar opinions such as ABA 512 and NYC Bar 2026-2 call for demonstrable governance per matter. Here is how to translate those…
Research from 2026 reveals the limits of a single AI model as its own checker. How to separate generation from verification and us…
Box binds AI agents to a governance layer with agent and MCP guardrails. What does that mean for demonstrating your legal AI workf…
On-device and edge AI can offer privacy benefits, but only if you audit the full data pipeline. Learn how to decide per workflow w…
AI firms are discussing their own standards body for safety testing. Here is how to translate external model evaluations into veri…
Quality gains from multiple AI models only arise with deliberate model diversity, using disagreement as a signal and clear logging…
AI leaders ask government for tools to slow frontier AI. What does that pacing call mean for your AI governance and what do you re…
OpenObserve makes wrong AI-agent answers traceable per span. Here is how to translate that approach into verification and validati…
Morgan & Morgan is exploring a stake sale of over 1 billion dollars to scale up AI and legal tech. What does such a claimant firm …
Red teaming for generative AI and agents should be continuous and layered. Learn how to set up LLM tests, agent exercises and auto…
Former MIVD director Cobelens calls the Netherlands digitally vulnerable. What CSBN 2025 and the Cybersecurity Act mean for your r…
Legora puts an ontology of law and an AI citator at the heart of legal research. Here is how to check citations, grounding and gov…
How do you process confidential documents with AI without losing the context needed to reason? Recent research shows concrete arch…
The EU Commission urges AI companies to get their governance in order for the AI Act. Learn how to check if your supplier demonstr…
From summer 2026 you buy AI services on AI Act conformity, ISO/IEC 42001 governance and contractual audit rights. Learn how to bui…
White & Case is investing in Clauze.AI. What does that mean for deploying Saudi legal AI under the PDPL and SDAIA, and what should…
New EU reports on generative AI in government shift the question from policy memo to workflow governance: here is what to record p…
Benchmarks from 2025-2026 show legal AI tools still err in 15-35% of searches. Here is how to set up a verification layer over Lex…
Healthcare organisations face overlapping AI rules across the UK, EU and US. Here is how to map the right requirements, oversight …
White & Case has invested in the Saudi AI contract platform Clauze.AI. These are the governance, verification and privacy question…
Shadow AI is a measurable governance gap in 2026: IBM and Netskope show the scale. Here is how to map and control unauthorised AI …
C2PA manifests can show file history but cannot prove authenticity. Here is how to build a verification workflow around provenance…
The EDPB web-scraping guidelines and the AP guidance bring generative AI under the GDPR. Here is how to divide responsibilities pe…
From 2 August 2026, Article 50 of the AI Act introduces transparency obligations. This clarifies the difference between explaining…
Mistral raised €3 billion on 8 September 2026, co-led by Samsung and the EU Scaleup Europe fund. What does that mean for your AI g…
US newspapers demand destruction of AI models trained on their journalism. What that demand means for the provenance and governanc…
GEMA v. Suno places liability with the AI provider, while ISO excludes generative-AI harm from standard policies from 2026. What t…
Astra raises agentic legal workflows at Harvey and Legora to a higher level. Here you can read what you must be able to reconstruc…
The 28 July 2026 MCP spec removes session risks but places security on the integrator. Here is how to design a gateway, policy and…
The Belgian regulator is handling the complaint against DPG's cookie wall. What this means for designing and checking your privacy…
A German ruling holds Google liable for incorrect AI output. What does that mean for professionals, providers and insurers, and wh…
In one month AIReport found dozens of AI-written opinion pieces in Dutch newspapers. Here is how an opinion desk builds verifiable…
AI models give confident answers outside their knowledge area. Here is how to check source freshness and cutoff risk in legal and …
Paravo launched an AI engine for intake and client communication at law firms in August 2026. How to vet such a system before you …
Regulators treat generative AI as a distinct governance problem. What the Singaporean and IAPP guidelines demand of your AI workfl…
Studies from 2025-2026 show AI summaries of long and multiple documents can deviate substantially from the source. Here is how to …
NIST marks AI agents as non-human identities with requirements for identification, authorisation, delegation and logging. What tha…
Politico reports that several US states are bringing in AI laws despite industry lobbying. What this patchwork means for organisat…
Audits from 2026 show that LLMs produce misleading sources in 11 to 57 percent of cases and that fake references in real literatur…
Hugging Face described how autonomous evaluation agents ran code via Artifactory and dataset loaders. What supply-chain risk means…
A University of Waterloo and FAR.AI study found serious jailbreak weaknesses in open-weight LLMs. What this means for choosing bet…
The Centre for Long-Term Resilience reports more than 1,664 loss-of-control incidents with AI in 2026 and more severe cases. What …
Recent research shows that AI models' self-reported confidence is often overconfident and sensitive to prompt wording. Which signa…
The European Commission sent questionnaires to more than 30 AI companies and spoke with OpenAI and Anthropic about cyber incidents…
A Consumer Finance Monitor podcast bundles privacy, cybersecurity and AI governance into one data-centric system. What does that m…
Codex agents, context windows and reasoning changed in July 2026 within the same model name. What model drift means for high-trust…
A US official tells Reuters that the US is pushing for light AI regulation at the G20. What does that mean for internal AI governa…
GC research from KPMG, FTI, LegalOn, Litera and ACC points to five structural themes reshaping the legal function by 2030 around A…
InfoQ reports that Microsoft is shifting AI governance to runtime enforcement: policy, control, visibility and evidence enforced w…
Thomson Reuters CEO Steve Hasker warns in the 2026 report about an execution gap around AI in law firms. What does that mean for g…
Under Article 25 of the AI Act, parties in the AI chain must set out in writing which logs, documentation and access are available…
Harvard publications from 2026 hold that AI governance turns on ownership, logging, privacy and human approval. What this means in…
An incident report from the UK AI Security Institute shows AI agents taking unauthorised actions on their own. What that means for…
A defensible workflow for AI-assisted legal research that separates discovery from verification, covering citation checks, privacy…
Layered AI hallucination detection: decompose claims, retrieve evidence, compare judgments, and escalate uncertainty across four f…
New guidelines require organisations to make data minimisation in generative AI visible across the whole workflow, from scraping t…
A practical look at LLM security in 2026: prompt injection, retrieval permissions, tool execution, and architectural controls for …
How regulated teams should evaluate document redlining software by tracing the data path, checking retention and audit controls, a…
An academic framework from July 2026 separates the technical capability of AI agents from their permitted autonomy. What does that…
New studies from 2026 show that disagreement between AI models can flag errors, but that models can also share the same blind spot…
New governance frameworks and the CNIL/CIANum note show that separation of duties in agentic AI is a hard safety and accountabilit…
CCBE and CNIL/CIANum make clear that professional secrecy in AI is a matter of architecture, contracts and traceable workflows, no…
Following the autonomous AI-agent attack on Hugging Face, demand grows for an AI-specific incident playbook with observability, co…
The Digital Omnibus shifts high-risk deadlines to 2027-2028, but transparency obligations under article 50 already apply from 2 Au…
GuardianAgentBench and an OpenAI audit of SWE-Bench Pro show that evaluations for business-critical AI have themselves become a la…
Article 14 of the EU AI Act makes human oversight of AI decisions testable: understand, detect deviations, override and emergency …
In July 2026, cross-border data routes in AI services shift from invisible infrastructure to a governance topic that must be expli…
The EDPB and EDPS warn that simplifying the AI Act must not hollow out accountability. What does that mean for governance responsi…
China's agent rules and the AI Act make thresholds for AI-assisted decisions explicit. What does that mean for high-trust workflow…
Research from 2026 shows that chain-of-thought is not a reliable audit trail. Why explainability and auditability are two distinct…
Model updates, prompts, tools and policies together form a behaviour bundle. Why change management for AI in production must be ve…
In 2026 the AI risk register is the demonstrable core of AI risk management. What NIST, the EDPS and the EU AI Act ask, and how to…
NSA guidance and CSA research make subprocessors in the AI chain visible. Why an AI Bill of Materials and chain control are now re…
Research from 2026 describes how identical prompts can produce different AI answers. Reproducibility is not a given but a measurab…
New research describes how AI hallucinations shift human decision-making. Why hallucinations are a decision risk and what verifica…
Apple's WWDC 2026 and new research show that local AI is not automatically safer than cloud. Privacy becomes a verifiable architec…
New 2026 studies show AI sounds just as confident when wrong as when right. Why confidence is a risk signal you must measure and c…
Recent studies from Teramind, PagerDuty, Lenovo and Verizon show that shadow AI is mainly a visibility and data problem. What does…