PrivacySignal
Enforcement

CISA Issues Updated Guidance on Minimum Elements of an SBOM

HIPAA Journal · · US Federal · Enforcement

CISA, the FBI, the NSA, and 15 international partners have released updated guidance defining the minimum required elements of a Software Bill of Materials (SBOM), a structured record of the components that make up a software product. The joint guidance builds on earlier frameworks and reflects growing international coordination around software supply chain transparency.

Why this matters: An SBOM is basically an ingredient list for software. When a vulnerability gets discovered in a common software component, organizations need to know fast whether they are running it. Without that list, they are guessing. This guidance matters because it sets a baseline that vendors and buyers can point to. It also signals that regulators across multiple countries are moving toward making SBOMs a real expectation, not a nice-to-have. If your organization uses third-party software and cannot quickly answer what is inside it, that gap is getting harder to defend.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Enforcement
The Guardian — Privacy · · International

Apple launches legal challenge against UK government demand to access data

The Home Office has made a fresh request for ‘back door’ access to encrypted iCloud data belonging to British users Apple has launched a new legal challenge against a UK government demand to access its customers’ highly encrypted data, a year after the Home Office agreed to abandon its previous request. The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully. Continue reading...

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →
Enforcement
HIPAA Journal · · US Federal

FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices

The Federal Trade Commission, along with Utah and California, has filed suit against telehealth company Hims & Hers, alleging unlawful business and data sharing practices. The action marks a coordinated federal-state enforcement effort targeting the San Francisco-based company.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

#enforcement#healthcare Read original →
Enforcement
C CNBC · · International

Anthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement powers

European regulators are moving to apply enforcement powers under the EU AI Act to major AI developers including Anthropic and OpenAI. The scrutiny marks an early test of how the law's oversight mechanisms will work against some of the most prominent players in the industry.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
WIRED — AI · · International

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Cyberattacks attributed to Iranian-linked actors have compromised water systems across seven U.S. states, raising concerns about critical infrastructure security. The incidents are part of a broader week in cybersecurity and digital policy that includes FBI interest in AI-based crime prediction tools and legal action by Elon Musk's xAI against a state law banning AI-generated sexual imagery.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
Ars Technica — Policy · · International

Reddit keeps its strange DMCA fight over Google search results alive

Reddit is pursuing a lawsuit accusing Perplexity AI of working with a web scraper to copy its content without permission, keeping the case alive after early legal challenges. The dispute centers on whether Perplexity unlawfully harvested Reddit posts and user-generated content to power its AI search product.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →