GT Insight

Drawing on lessons learned from thousands of incident responses, this GT Advisory examines the most common and consequential mistakes organizations make when responding to a data breach. From lack of preparation to missteps in customer notification, understanding these pitfalls is the first step toward a more effective response.
Continue Reading Cyber Incident Response: 10 Lessons Learned from Thousands of Breaches

The European Commission’s draft guidelines on Article 50 of the EU AI Act clarify how transparency and disclosure obligations apply to interactive AI systems, synthetic content, deepfakes, and AI-generated text on matters of public interest. With the rules taking effect 2 August 2026, organizations should act now to assess their AI governance frameworks, labeling practices, and editorial workflows.

Continue Reading Deepfakes, Chatbots, AI-Generated Text: European Commission Details Transparency Obligations Under the AI Act

On June 2, 2026, the White House issued an Executive Order designed to bolster U.S. cybersecurity through AI-enabled defenses and a voluntary collaboration framework between federal agencies and private AI developers. The Order also directs the Attorney General to prioritize prosecution of AI-assisted cyber offenses under existing federal law.

Continue Reading White House Issues Executive Order Targeting Frontier AI Models

Colorado’s newly signed AI Act replaces the state’s 2024 comprehensive AI regulation with a more targeted framework governing automated decision-making technologies used in high-stakes decisions involving employment, healthcare, and financial services, with a compliance deadline of January 1, 2027.

Continue Reading Colorado Repeals and Replaces the Colorado AI Act

The CJEU’s March 19, 2026, judgment in Case C-526/24 marks a significant development in GDPR enforcement, holding for the first time that even a single data access request may be refused as “excessive” under Article 12(5) GDPR if made in bad faith, while also confirming that an unjustified refusal to comply with such a request can itself give rise to damages liability under Article 82(1) GDPR.

Continue Reading CJEU: First Request for Access May Be Rejected as Abusive Under GDPR

With its Russmedia judgment (C-492/23, Grand Chamber, 2 December 2025), the Court of Justice of the European Union (CJEU or Court) fundamentally reshapes how online marketplaces and other platforms hosting user-generated content must approach data protection compliance.
Continue Reading CJEU’s Russmedia Decision Expands Platform Controller Duties Under GDPR