Jul. 22, 2026

A New Name. A New Look. The Same Trusted Resource.

We are excited to unveil our refreshed brand and redesigned website. Our new name, Cybersecurity and AI Law Report, reflects the growing convergence of cybersecurity, data privacy and AI governance, and better captures the breadth of legal, regulatory and digital risk developments that we cover. The updated look also highlights our place within the distinguished ION Analytics family of products that deliver business intelligence, market data, news and analysis. While our brand has evolved, subscribers can continue to rely on the same authoritative analysis, practical guidance and industry-leading coverage of critical cybersecurity, data privacy and AI issues. Exemplifying that ongoing commitment, highlights from this week’s content include insights on the first Form 8‑K filing to disclose a shadow AI incident, a look at emerging advertising technology regulatory risks, and our inaugural collaboration with IAPP on state cybersecurity laws.

State Cybersecurity Laws: Enforcers’ Growing Toolkit

State AGs are expanding their role in cybersecurity enforcement, drawing on a robust toolkit that includes a growing mix of consumer protection laws, sector-specific statutes and emerging legislation to scrutinize how companies secure personal data. For privacy and cybersecurity professionals, this creates both heightened risk and a more complex compliance landscape that they need to understand and address. In this guest article, the first in a three-part collaborative series with IAPP, Jim Dempsey, managing director of the IAPP Cybersecurity Law Center, examines the key authorities that states are using, highlights recent enforcement trends across industries and explains how the relevant laws are reshaping compliance expectations. See “Examining Security Mandates, Including California’s Draft Audit Regulations, in State Privacy Laws” (Nov. 1, 2023).

Mitigating Risks of Shadow AI and Navigating Related SEC Disclosure Requirements

The surge in AI use has heightened cybersecurity risks, including shadow AI – the unauthorized use of AI tools or misuse of approved ones. Illustrating how those risks can manifest, CB Financial Services, Inc. (CB Financial) recently filed a Form 8‑K with the SEC, disclosing that its wholly owned subsidiary had experienced a material cybersecurity incident arising out of the use of an unauthorized AI application. The filing is apparently the first Form 8‑K to disclose a shadow AI incident. This article examines the CB Financial filing, the relevant SEC obligations and how organizations can mitigate the compliance risks associated with shadow AI, with commentary from partners at Debevoise & Plimpton, Wilson Sonsini and Goodwin. See “Unpacking the AI Risks Disclosed in 2025 SEC Filings” (Sep. 10, 2025).

The Evolving Adtech Landscape

Adtech remains a powerful driver of audience targeting and customer acquisition, but it has also become a compliance challenge and risk. Heightened regulatory scrutiny, evolving state privacy requirements and aggressive litigation under wiretap laws and the Video Privacy Protection Act are forcing companies to reassess how they collect, share and monetize personal data. This article covers recent trends and developments in adtech law, including enforcement focus on location, health and other sensitive data, distilling insights shared by Cooley attorneys during a firm presentation. See “Considerations for Adtech Stemming From Oracle’s $115‑Million Settlement” (Aug. 14, 2024).

Steptoe Welcomes Former DOD and DHS Official to Lead Cybersecurity Practice in D.C.

Michael Gruden has joined Steptoe as a partner in the Washington, D.C., office, where he will lead the firm’s cybersecurity practice. He arrives from Crowell & Moring. For commentary from Gruden, see “Navigating DoD’s Final Cybersecurity Maturity Model Certification Program Rules” (Oct. 1, 2025). For insights from Steptoe, see “The Data Analytics and AI Transition in Compliance” (May 13, 2026).

Privacy and Cybersecurity Partner Joins Cooley in New York

Cooley has welcomed Michael La Marca to the firm as a partner in its global cyber/data/privacy group in New York. He arrives from Hunton Andrews Kurth. For insights from Cooley, see “Ten Developments Reshaping Compliance Obligations As the GDPR Rounds Out Its First Decade” (Jun. 24, 2026); and “Eyewitness Accounts and Recommended Actions to Counter AI’s Strain on Cyber Defense” (May 6, 2026).