Regulation

Regulatory landscape and business impact

44 analyses

Regulation6 min

Biometric Data in the Age of AI: The Next Regulatory Minefield Executives Cannot Ignore

The Illinois Biometric Information Privacy Act (BIPA) has generated over $2.5 billion in settlements since 2008 and continues to produce record litigation. In 2025, Texas and Washington expanded similar legislation. In Europe, the AI Act classifies remote identification biometric systems as high risk. The proliferation of facial recognition cameras and voice authentication in the corporate environment exposes companies to increasing legal risks.

Read analysis →
Regulation7 min

China and AI Regulation: The Most Comprehensive Framework in the World and its Impact on Global Companies

China has built the world's most detailed and layered AI regulatory framework. With three main regulations already in effect and at least two more in preparation, the country requires registration of foundational models, pre-launch security assessments, and control of AI-generated content. Companies with operations or users in China need to map compliance across multiple fronts simultaneously.

Read analysis →
Regulation6 min

SEC and Cybersecurity: The New Disclosure Obligations that have Transformed the Role of the CISO

The SEC's rules on the disclosure of cyber incidents, effective from December 2023, require reporting of material incidents within four business days via Form 8-K. In May 2025, American banking associations petitioned the SEC to revoke the rule. The practical outcome: the CISO has become a direct interlocutor for the board and legal department in materiality decisions.

Read analysis →
Regulation7 min

PL 2338: Brazil Advances in AI Regulation and What Changes for Technology Companies

In December 2024, the Brazilian Senate approved PL 2338/2023, which establishes the regulatory framework for AI in the country. In March 2025, the text was forwarded to the Chamber of Deputies. The law adopts a risk-based approach, with three categories: excessive risk (prohibited), high risk (with stringent requirements), and other systems (general obligations). For developers and operators, the impacts are immediate and structural.

Read analysis →