Covering Bidding, Artificial Intelligence, Cybersecurity, AI Standards, Mortgage Subrogation. Explore key regulatory updates in Bidding, AI, Cybersecurity, AI Standards, and Mortgage Subrogation sectors, including EU systemic cyber risk warnings, AI interoperability mandates, and Australia’s new AI standards for data centers.
Weekly news, analysis, and insights from AI regulation updates the world over
Welcome to This Week in AI Regulations.
Starting in the European Union, the European Systemic Risk Board issued a warning about systemic cyber risks stemming from frontier AI models. The ESRB highlighted that the increased speed, scale, and sophistication of cyberattacks enabled by these AI models significantly raise the likelihood and severity of systemic cyber incidents in the financial sector. Financial institutions within the European Union are required to assess and update their cybersecurity frameworks to address vulnerabilities exposed by frontier AI models. Furthermore, significant institutions must prepare detailed action plans to mitigate these risks.
Also in the European Union, there was a presentation and discussion on the EU cybersecurity and AI action plan, including AI cybersecurity risk assessment guidelines and a proposal to update the Cybersecurity Act with an emphasis on information and communications technology supply chain security. Public sector entities are expected to adopt and implement AI cybersecurity risk assessment guidelines and comply with the proposed regulatory framework for cybersecurity certification and ICT supply chain security under the updated Cybersecurity Act.
The European Data Protection Board published three new guidelines covering web scraping for AI training, data anonymisation, and blockchain processing of personal data. These guidelines emphasize compliance with the General Data Protection Regulation, especially given the privacy risks associated with large-scale personal data processing for AI training. Organizations must understand and apply GDPR principles to web scraping activities, including establishing lawful bases, ensuring transparency, data minimisation, and accuracy. They are also required to implement technical and organizational measures to mitigate risks, particularly when processing special categories of personal data. Additionally, anonymisation techniques must effectively prevent re-identification, with documentation of these processes maintained.
In another European Union update, the European Commission issued binding specification measures to Google concerning AI interoperability on Android and the sharing of Google Search data under the Digital Markets Act. Google must provide equal access to Android features for third-party AI assistants, including voice activation and app task delegation. Google is also required to share anonymised search data with eligible third-party search engines, including AI chatbots, using a multi-layered anonymisation method. The measures include safeguards to protect user privacy, device security, and data integrity.
Turning to Australia, the government has introduced Australian Standards for AI, as announced by Assistant Minister Charlton and Minister Ayres. These standards establish legal obligations for large data centres regarding power supply, connection costs, energy and water efficiency, and community engagement. Large data centres must underwrite their own new power supply and pay full connection costs. They are also required to reduce power usage when needed to support grid stability and maximize water efficiency. Additionally, the Office of AI has been established within the Department of Prime Minister and Cabinet.
That wraps up today's regulatory updates. Visit carveragents.ai for more information.