California Subpoenas OpenAI Over AI Model Cyber Risks

California's subpoena is an investigative step, not a finding.

California's subpoena is an investigative step, not a finding.

Keep the recruitment decision and its evidence together.

Australia’s privacy regulator has explained a 10 December disclosure duty for software-assisted decisions that significantly affect people. Human review and third-party tools do not automatically remove a decision from scope.

The FCC's EAS cybersecurity rule reaches beyond alert encoders to studio transmitter links and remotely managed equipment in the programming path. Three targeted controls apply from 29 September.

The EU plans public energy and water grades for individual data centres from 2027. The labels should aid comparisons, but will not show each site’s exact annual electricity total.

Australia's 2025-26 critical-infrastructure risk report is due on 28 September. The regulator says its next compliance cycle will look harder at serious or persistent gaps behind the board's statement.

Election software can need an urgent security fix while certification rules make vendors and operators afraid to apply it.

ENISA's CRA Single Reporting Platform is now live, and the first 24-hour reporting clock is running. Manufacturers need more than a portal login to meet it.

A US national-emergency order treats power-grid security as a hardware, firmware, maintenance and remote-access supply-chain problem.

Alabama has subpoenaed OpenAI over the Hugging Face agent intrusion, testing whether weak AI evaluation controls can also violate consumer-protection law.