Regulatory Updates

Gain insights on the latest regulatory updates related to digital, data and tech and what action they require of you by reading the latest updates (including alerts).

Only some are linked below. To read all previous insights and be alerted to future insights, join the relevant Michalsons programme. You can view the public and the “Members only” ones if you are a member and logged in.

Gramm–Leach–Bliley Act: A practical guide for financial institutions

In a world where financial information is invaluable, understanding and complying with the Gramm–Leach–Bliley Act (GLBA) is crucial for financial institutions. This guide will walk you through the essential aspects of the GLBA, helping you ensure your institution is both [...]

By |2024-08-26T21:43:20+02:00December 11th, 2023|Categories: POPI and Data Protection|Tags: , |

Biden executive order on artificial intelligence

On 30 October, President Joe Biden issued a comprehensive executive order on artificial intelligence (AI). The executive order marks a significant step towards addressing the challenges and leveraging the benefits of this rapidly evolving technology. The executive order prioritises standards [...]

By |2024-03-01T14:31:23+02:00November 8th, 2023|Categories: AI Governance|Tags: , , |

AI Bill of Rights | Overview and summary

The White House Office of Science and Technology Policy released a Blueprint for an AI Bill of Rights. It is the first of it's kind. They also provide a handbook to accompany the principles in the AI Bill of [...]

By |2024-02-28T22:18:23+02:00August 14th, 2023|Categories: AI Governance|Tags: , , |

ISO publishes guidance on AI risk management

ISO's guidance on AI risk management introduces a common framework relating to the implementation and use of AI systems. Risk management allows organisations to identify and evaluate risks using resources. The guidance applies to organisations that produce, develop, use, or [...]

By |2024-02-28T22:41:22+02:00March 27th, 2023|Categories: AI Governance|Tags: , , |

ISO/IEC TR 24368:2022 AI’s ethical & societal concerns

Have you ever wondered whether AI might have ethical and societal consequences? Well, you’re not alone. Many people have. In fact, ISO and IEC recently released a technical report on AI’s ethical and societal concerns. It’s called ISO/IEC TR 24368:2022. [...]

By |2024-08-14T13:16:02+02:00August 23rd, 2022|Categories: AI Governance|Tags: , , |

The global standard for AI: the EU wants to take lead

Members of the European Parliament (MEPs) want the EU to set the global standard for AI. While the MEPs recognise that the EU has lagged in the global race for AI leadership, they still believe the Union must set the standard. [...]

By |2024-08-14T13:17:39+02:00May 5th, 2022|Categories: AI Governance|Tags: , , |

ISO/IEC 38507:2022 Guidance on AI Governance

ISO/IEC 38507:2022 has arrived! [Cue dramatic music]. Let’s see how it will support your organisation’s artificial intelligence (AI) governance. Who’s the audience? In short, it’s a document that guides an organisation’s governing body on how to enable and govern AI. [...]

By |2024-08-14T13:18:01+02:00April 9th, 2022|Categories: AI Governance|Tags: , , , |

ISO/IEC 27002:2022 Infosec, cybersecurity, & privacy

Recently, the International Organization for Standardization (ISO) published the ISO/IEC 27002:2022 standard. This document replaces a version of the same name from 2013. What is interesting is that for the first time the controls include privacy controls and ISO [...]

By |2024-08-14T13:20:14+02:00February 16th, 2022|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , |

Comment on the draft POPIA Amendment Regulations 2021

On 13 October 2021, the information regulator invited comments on draft regulations that will amend the POPIA regulations, 2018. The draft regulations mainly cover new proposed rules of procedure, administrative fines, and other proposed amendments to the POPIA regulations. [...]

Alert | The Cybercrimes Act is here – now what?

The President of South Africa has signed the Cybercrimes Act into law. This means that South Africa now has a comprehensive law to regulate cybercrime. The wait is finally over, and it is now time for you to take action. [...]

POPI Update: Parliament wants POPIA to commence urgently

Parliament has stressed that it wants South Africa's data protection law called the Protection of Personal Information Act (POPIA) to commence urgently. We still don't have any specific commencement date or deadline but Parliament said "we need specific timeframes". We [...]

By |2024-02-22T15:56:38+02:00May 13th, 2020|Categories: POPI and Data Protection|Tags: , , , , |