Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 380 results

Client Alert | 3 min read | 08.14.25

DSIT's latest findings on AI, other emerging technologies and cyber security

On 8 August, the UK Department for Science, Innovation & Technology (“DSIT”) published a report titled “Emerging technologies and their effect on cyber security” (the “Report”). It examines how the convergence of AI, IoT, Quantum, Edge Computing, Blockchain and other emerging technologies is transforming the cyber threat landscape. We’ve summarised below some of their key findings and takeaways. In the pursuit of growth and efficiencies many companies are considering how to adopt emerging technology into their operational processes, and the Report provides a useful guide as to emerging cyber risks and where the UK Government’s attention is focused as it launches the Cyber Resilience Bill later this year.
...

Client Alert | 5 min read | 08.12.25

Cloud GDPR risks highlighted by European Commission ruling over Microsoft 365 use

On 11 July 2025, the European Data Protection Supervisor, (“EDPS”), the independent supervisory authority, which oversees the processing of personal data by EU institutions, bodies, offices and agencies, (“EUIs”) confirmed that the European Commission, (“Commission”) has succeeded in bringing its use of Microsoft 365 within the requirements of applicable European data protection rules thanks to additional measures adopted by both the Commission and Microsoft.
...

Client Alert | 4 min read | 08.06.25

Series of Major Data Breaches Targeting the Insurance Industry

Threat actors have targeted insurance companies in a recent string of cyber-attacks, exposing patients’ personal information, including Social Security numbers, claims information, and health reports.
...

Client Alert | 4 min read | 07.29.25

Children first: How Ofcom’s Children’s code and age checks change the digital game

Ofcom, the UK’s communications and appointed online safety regulator, is following through on its commitment to protect children online. From 25 July 2025, Ofcom will enforce its Protection of Children Codes of Practice (the “Code”) under the Online Safety Act 2023 - a significant milestone for digital safety in the UK.
...

Client Alert | 5 min read | 07.25.25

The Changing Face of UK Defence and Security

On 2 June 2025, the UK Government unveiled its 2025 Strategic Defence Review titled the “Plan for Change for Defence” (the “2025 SDR”), heralding it as the dawn of a new era in British defence and security. Hailed as a landmark by the Prime Minister, the 2025 SDR underscores the urgent need to address daily cyber threats and embrace the rapid evolution of technology that is reshaping the battlefield. It also emphasises both the necessity of and the opportunities that this approach affords to create a new partnership with industry and radically reform procurement, leading to the creation of a “defence dividend” of jobs, wealth and opportunity throughout the UK.
...

Client Alert | 3 min read | 07.24.25

UK Government's take on ransomware: Insights from the recent consultation

Ransomware attacks have escalated in frequency and sophistication, posing a significant threat to national security and critical national infrastructure (“CNI”). Cybersecurity has emerged as a core pillar of the UK’s national defence strategy, as set out in the recent Strategic Defence Review. The Government has recognised cyber as a crucial area for modern conflict. Ransomware attacks are a significant method of attack, as a form of cybercrime which involves malicious software encrypting data and a ransom demand for its restoration or to prevent its publication. The UK has experienced a notable rise in such incidents, including attacks on Synnovis (an NHS diagnostics service provider) and Southern Water (a water company providing water to a region of the UK), both in 2024.
...

Client Alert | 8 min read | 07.23.25

Artificial Intelligence and Open Source Data and Software: Contrasting Perspectives, Legal Risks, and Observations

Open source data and software play a foundational role in software development, artificial intelligence (AI), education, and research. Open source AI refers to systems where the source code, model parameters, and related components are freely available for anyone to use, study, modify, and distribute.
...

Client Alert | 2 min read | 07.09.25

New York Department of Health Issues “Urgent” Cybersecurity Warning to New York Health Care Providers Following U.S. Military Action in Iran

In response to the recent U.S. strikes on Iranian nuclear facilities, the New York State Department of Health (“NYS DOH”) issued a cybersecurity advisory (the “Advisory”) that cautions healthcare providers, such as hospitals, treatment centers, and healthcare practitioners, of a high likelihood of increased cyberattacks and heightened cybersecurity threat activity.  The Advisory follows similar announcements and warnings from U.S. Department of Homeland Security (“DHS”), NYS Intelligence Center (NYSIC) and the Health-ISAC (Information Sharing and Analysis Center).
...

Client Alert | 4 min read | 07.07.25

DOJ Data Security Program Update: Active Enforcement Begins This Week

The U.S. Department of Justice’s (DOJ) reprieve on civil enforcement of its Data Security Program (DSP), which imposes sweeping restrictions on bulk data transfers by U.S. entities to certain “countries of concern” and “covered persons,” is set to expire on July 8, 2025.
...

Client Alert | 8 min read | 06.30.25

AI Companies Prevail in Path-Breaking Decisions on Fair Use

Last week, artificial intelligence companies won two significant copyright infringement lawsuits brought by copyright holders, marking an important milestone in the development of the law around AI. These decisions – Bartz v. Anthropic and Kadrey v. Meta (decided on June 23 and 25, 2025, respectively), along with a February 2025 decision in Thomson Reuters v. ROSS Intelligence – suggest that AI companies have plausible defenses to the intellectual property claims that have dogged them since generative AI technologies became widely available several years ago. Whether AI companies can, in all cases, successfully assert that their use of copyrighted content is “fair” will depend on their circumstances and further development of the law by the courts and Congress.
...

Client Alert | 4 min read | 06.26.25

Ninth Circuit Affirms that CIPA Only Applies to Third-Party Eavesdropping

Crowell attorneys have closely monitored developments related to the California Invasion of Privacy Act (“CIPA”). In particular, we have watched plaintiffs attempt to extend this wiretapping law to encompass website chatbot communications that are managed by third parties.
...

Client Alert | 6 min read | 06.16.25

Cross-Border Data, Rising Risks: How International Arbitration Can Help

The flow of data across borders is essential to our global economy. As companies grow more and more dependent on cross-border data transfers to conduct business, two parallel legal trends have emerged:
...

Client Alert | 8 min read | 05.19.25

AI and Cybersecurity Under the Spotlight: UK Publishes New Codes for Software Security and Warns on AI Cybersecurity Divide

Earlier this month the National Cyber Security Centre (“NCSC”) hosted CYBERUK, the UK government’s flagship cybersecurity event. On 7 May the NCSC launched their report “Impact of AI on cyber threat from now to 2027” (“Report”), whilst the Department for Science, Innovation and Technology (“DSIT”) published a new voluntary Software Security Code of Practice, (“Code”). Cybersecurity and AI are under the spotlight in the UK. Eyes are also on the recently unveiled US/UK trade agreement and the possibility of a further transatlantic tech-focused agreement to cement prior Technology and Data Partnership discussions to create a US/UK “digital bridge.”
...

Client Alert | 9 min read | 05.19.25

U.S. Department of Commerce Rescinds Biden Administration’s AI Diffusion Export Control Rule and Issues New Guidance on Huawei, Chips for AI Purposes, and Diligence Expectations

On May 13, 2025, the Department of Commerce’s Bureau of Industry and Security (BIS) formally rescinded the Framework for Artificial Intelligence Diffusion interim final rule published by the Biden Administration, on the basis that it stifled innovation, was overly complex, and undermined U.S. diplomatic relations.
...

Client Alert | 2 min read | 05.15.25

DoD Specifies Implementation Requirements for NIST 800-171 Cyber Standard

The Department of Defense (DoD) has released a memorandum establishing the DoD Organization-Defined Parameters (ODPs) for use in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision (Rev) 3. Currently, DoD’s cybersecurity regimes require government contractors to comply with NIST SP 800-171 Rev. 2. However, the release of this memorandum may indicate DoD’s intention to soon incorporate Rev. 3 into DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012) as well as the forthcoming Cybersecurity Maturity Model Certification (CMMC).
...

Client Alert | 6 min read | 04.18.25

Ready To Know Your Data? DOJ Issues Implementation and Enforcement Guidance for Data Security Program Protecting Bulk Sensitive Data

On April 11, 2025, the U.S. Department of Justice (DOJ) issued guidance regarding the implementation and enforcement of the newly enacted final rule, “Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons,” now referred to as the Data Security Program (DSP). The release included an Implementation and Enforcement Policy, a Compliance Guide, and Frequently Asked Questions (FAQs). Collectively, these documents are designed to help entities subject to the DSP understand and comply with the obligations set out under the Final Rule.
...

Client Alert | 5 min read | 04.15.25

Is Section 230 Going to Change? The FTC, DOJ and FCC Signal Significant Change for Online Businesses

On April 3, 2025, the United States Department of Justice’ Antitrust Division hosted a forum on “Big-Tech Censorship” in which key Trump Administration Officials announced their desire to reform, or entirely overhaul, Section 230 of the Communications Decency Act. In March 2025, we wrote about the Federal Trade Commission’s (FTC) inquiry into “tech censorship” and its associated request for public comments from those who “may have been harmed by technology platforms that limited their ability to share ideas or affiliations freely and openly.” That RFI remains open, and its deadline is May 21, 2025.
...

Client Alert | 4 min read | 04.01.25

For Better or MORSE: Another Settlement Under DOJ’s Civil Cyber-Fraud Initiative

On March 26, 2025, the Department of Justice (DOJ) announced that defense contractor MORSECORP Inc. (MORSE) will pay $4.6 million to settle allegations that MORSE violated the False Claims Act (FCA) by failing to comply with cybersecurity requirements and subsequently submitting false or fraudulent claims for payment in its contracts with the Departments of the Army and Air Force. This is the first FCA settlement that is based on a defense contractor’s failure to reevaluate and promptly update its self-assessment score in the Supplier Performance Risk System (SPRS) after a third-party assessment resulted in a lower score.
...

Client Alert | 2 min read | 03.31.25

Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers

On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.
...

Client Alert | 3 min read | 03.26.25

FedRAMP 20x: Proposed Framework Aims To Increase Automation and Efficiency

On March 24, 2025, the Federal Risk and Authorization Management Program (FedRAMP) unveiled “FedRAMP 20x,” a proposal to make FedRAMP more efficient by automating FedRAMP security assessments and continuous monitoring, simplifying required technical controls, and leaning on industry to provide tooling and solutions to support automation. 
...