PrivacySignal
Enforcement

Microsoft Moves AI Governance From Policy to Runtime Enforcement

infoq.com · · International · Enforcement

Microsoft is shifting AI governance from written policy commitments to controls enforced at the system level, meaning rules about how its AI behaves would be built into runtime operations rather than left to voluntary guidelines.

Why this matters: Policy documents do not stop bad outcomes. They describe intentions. Runtime enforcement is different — it means the system is supposed to refuse or flag certain actions automatically, not because someone wrote a rule in a PDF but because the code itself won't allow it. That matters for anyone whose data or decisions touch Microsoft's AI tools. The real test is what exactly gets enforced, who defines the rules, and whether there is any outside way to verify the system actually does what Microsoft says it does.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Enforcement
EDPB · · EU

Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling

The Dutch Data Protection Authority has fined Uber approximately 825 million euros for violating GDPR rules on automated decision-making and failing to properly inform drivers about how profiling data was used against them.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · Cybersecurity · General readers · Policy

#enforcement#gdpr#ai-governance#surveillance#privacy Read original →
Enforcement
Y Yahoo · · International

Lawsuit claims facial recognition program led to wrongful arrest

A lawsuit alleges that a facial recognition program identified the wrong person, leading to a wrongful arrest. The case adds to a growing record of people facing serious legal consequences because of misidentification by automated systems.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →
Enforcement
The Guardian — Tech · · International

Police routinely failing to investigate ‘revenge porn’, research reveals

Research drawing on accounts from 100 people in England and Wales found that police frequently dismiss or fail to act on reports of intimate images shared without consent. Lawyers have filed a super-complaint to push authorities to treat image-based abuse as the serious criminal offense it legally is.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
The Guardian — Tech · · International

Privacy watchdog launches investigation into China-based company behind Kmart ‘pervert glasses’ app

Australia's privacy regulator has opened a formal investigation into Shenzhen Qingcheng, the China-based company behind the HeyCyan app embedded in Kmart's low-cost smartglasses, after the company failed to respond to the commissioner's inquiries. The probe follows public concern about the glasses being used to covertly capture images and video.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#regulation#privacy Read original →
Enforcement
A ANews · · International

US closes review of US airlines' data privacy without seeking penalties

U.S. regulators have closed a review of domestic airlines' data privacy practices without pursuing any penalties against the carriers. The outcome means airlines faced scrutiny but no formal consequences for how they handle passenger data.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
S SC Media · · International

Italy fines IQVIA $7.8 million for patient data privacy violations

Italy's data protection authority has fined IQVIA, a global health data and analytics company, approximately $7.8 million for violating patient privacy rules. The fine relates to how the company handled personal health data.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · General readers · Policy

#enforcement#healthcare#privacy Read original →