Policy & Regulation — Page 6

Google loses final EU appeal, must pay €4.1 billion Android fine
The bloc's top court has ended a seven-year fight over how Google used Android to push its search engine and Chrome browser onto phones.

Chris Inglis on the Snowden Era: What NSA Got Wrong, and What CISOs Should Still Be Asking
The former NSA Deputy Director reflects on institutional failures, insider threat detection, and why 'enculturation' may matter more than access controls.

Microsoft Tightens Teams Meeting Controls for External AI Bots
A new admin policy requires organizer approval before automated external participants can join Teams meetings — a quiet but consequential shift in how enterprises govern AI access to sensitive calls.

Behavioral AI Pitched as Answer to Identity-Abuse Phishing, But Regulators Still Set the Bar
A vendor webinar makes the case for behavioral detection against BEC and account takeover. The compliance questions sit underneath.

Claude Fable 5 Comes Back Online as Commerce Drops Export Curbs
Anthropic restores Fable 5 across Claude.ai, Claude Code, and Cowork on July 1 after a roughly two-and-a-half-week U.S. export restriction gets lifted.

Supreme Court Extends Fourth Amendment Shield to Cell-Site Location Data
A geofence warrant case gives the Court a vehicle to rule that historical location records tied to a phone are constitutionally protected — full stop.

Zero Trust in OT: A Pragmatic 90-Day Action Plan
Aligning zero trust architecture with operational technology environments through a strategic, actionable 90-day plan.

Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt
Forensic traces and a Russian court filing place a UFED extraction on the activist's device in June 2021, raising hard questions about post-sale controls on dual-use forensic kit.

GDPR Turns Ten: A Decade of Fines, Frustration, and Unfinished Business
Six billion euros in penalties later, Europe's data regulation has reshaped corporate behavior — and created a compliance burden that companies say is quietly strangling AI development on the continent.

ICS Security's 25-Year Reunion Is Headed to Nashville
The Industrial Control Systems Cybersecurity Conference marks a quarter-century in October 2026, touching down at the W Nashville for three days of OT threat intelligence.

Compliance Theatre Has a Reckoning Coming. FedRAMP 20x Is the Opening Act.
Most SOC 2 and ISO 27001 reports audit a curated version of history, not operational reality. A federal cloud-security overhaul is forcing the question nobody wanted to answer: does passing audits actually mean anything?

DOJ Seizes HuiOne Cloud Account, Treasury Sanctions Prince Group Network
Cambodia-based conglomerates accused of laundering proceeds from pig-butchering and cyber-enabled fraud face coordinated U.S. action.

White House Orders Federal Agencies to Migrate Cryptography by 2030, Signals Contractor Reckoning
Two executive orders set hard federal deadlines for post-quantum cryptography adoption and launch a government-wide quantum R&D program — with ripple effects for every contractor touching federal networks.

Executive Order 14409 Locks In Federal PQC Deadlines: 2030 for Key Establishment, 2031 for Signatures
The June 22 order sets binding migration dates for high-value assets and high-impact systems, while leaving national security systems on a parallel track.

White House Sets Hard Clock on Post-Quantum Migration for Federal Systems
An executive order mandates that high-value federal assets shift to post-quantum cryptography by 2030–2031. For identity infrastructure, that deadline is closer than it looks.