Legal & Compliance

situational awareness ai hedge fund sec probe a radar dish on stand

Situational Awareness, Star AI Hedge Fund That Nearly Imploded, Now Being Probed by the SEC

Situational Awareness was the best-performing large fund in the world in June 2026, up 439% net, and by the end of July it had been forced to sell its entire public equity book to Citadel in a single pre-market block. The Securities and Exchange Commission has now subpoenaed Goldman Sachs, JPMorgan Chase, Citigroup and Bank of America for records of the fund’s trades, its borrowing and its conversations with lenders. This breakdown walks through what the regulator has asked for, how four times leverage turned a sector correction into a forced liquidation, what the fund actually owned, why Citadel bought the book at a reported ten per cent discount, why the headline figures in different outlets do not match, and what a business buying AI compute should take from the whole episode.

Read more
twitch ai lawsuit amazon streamers content a play button panel

Twitch and Amazon Hit With Lawsuit for Training AI With Streamers’ Content

Eight days after Twitch switched on AI training by default, a Connecticut streamer filed a class action against Twitch and Amazon in the Northern District of California. The complaint accuses both companies of harvesting broadcasts, videos, clips and chat logs to train Amazon’s generative AI since as far back as 2024 — without consent and without payment. This article breaks the case down in plain language: the four legal claims and why copyright is deliberately missing, Mike Minton’s “nobody would opt in” admission, the same-day terms change, the market price of licensed training data, how the case compares with Bartz, Kadrey and NYT v. OpenAI, and the lessons for any business repurposing user content for AI.

Read more
ai copyright training models on copyrighted books a stack of closed books

Is It Legal to Train AI Models on Copyrighted Books? It’s Complicated

Is it legal to train AI models on copyrighted books? Courts say it’s complicated. This guide walks through the $1.5 billion Anthropic settlement and its 91% claim rate, the fair use four-factor test, the scoreboard of rulings from Bartz v. Anthropic to Kadrey v. Meta and Thomson Reuters v. Ross, why the UK’s March 2026 report kept the status quo after Getty’s hollow High Court win, what the US Copyright Office’s Part 3 report concluded before its author was fired and reinstated, and the practical questions every business using or building AI should be asking about indemnities, provenance and output ownership.

Read more
cyber resilience act uk companies a three ascending rounded pillars

Cyber Resilience Act UK: Does It Apply? Essential Risk Guide

Does the EU Cyber Resilience Act apply to UK companies after Brexit? Yes — whenever software or hardware with digital elements is placed on the EU market, the duties follow the product regardless of where the manufacturer sits. This guide maps which UK businesses are caught and which escape, what placing on the market really means, the September 2026 reporting clocks and December 2027 full-application deadline, the manufacturer, importer and distributor duties, fines of up to 15 million euros or 2.5 percent of worldwide turnover, how the EU regime compares with the UK’s narrower PSTI rules and the services-focused Cyber Security and Resilience Bill, the unresolved Northern Ireland position under the Windsor Framework, and a four-step preparation plan for UK exporters.

Read more
cyber resilience act vulnerability handling requirements a upright funnel

Vulnerability Handling Requirements: Proven Safe CRA Guide

A plain-language walkthrough of the vulnerability handling requirements in Annex I, Part II of the EU Cyber Resilience Act for software teams: the eight duties from SBOM documentation to free security updates, how the five-year support period stretches them across a product’s life, what a coordinated vulnerability disclosure policy must contain, how the handling process feeds the 24-hour and 72-hour Article 14 reporting clocks from September 2026, the fine bands up to 15 million euros, the mistakes that fail assessments, and a 90-day plan to stand the whole process up before the December 2027 deadline.

Read more
sbom requirements eu cyber resilience act a tall stack blank paper sheets

SBOM Requirements: Essential EU CRA Guide to Avoid Risk

A deep-dive on SBOM requirements under the EU Cyber Resilience Act for software teams: what Annex I, Part II actually obliges you to document, the seven minimum data fields every component entry needs, how to choose between SPDX and CycloneDX, how to generate and store SBOMs in your delivery pipeline, keeping them current across versions and patches, the VEX workflow that makes vulnerability matching usable, what market surveillance authorities can demand, the fine bands up to €15 million, and a 90-day plan to get compliant before the December 2027 deadline.

Read more
cyber resilience act checklist software developers a clipboard with check marks

Cyber Resilience Act Checklist: Proven Steps to Avoid Fines

A working Cyber Resilience Act checklist for software developers and engineering leads. Six workstreams in delivery order: inventory and classification, the Annex I secure development requirements, machine-readable SBOMs with CycloneDX or SPDX, vulnerability handling that survives an audit, the 24-hour reporting capability due by 11 September 2026, and the technical file, declaration of conformity and CE marking due by 11 December 2027 — plus the fine bands, the 2026 Commission guidance, the draft harmonised standards, a 16-month plan and the mistakes development teams most often make.

Read more
cyber resilience act reporting requirements a three ascending rounded pillars

Cyber Resilience Act Reporting: Proven Guide to Avoid Fines

Cyber Resilience Act reporting becomes a live legal duty on 11 September 2026, fifteen months before the rest of Regulation (EU) 2024/2847 applies. This operational guide covers the two triggers that start the clock, what “becoming aware” means, the 24-hour early warning, the 72-hour notification and the 14-day or one-month final report, the ENISA single reporting platform and how to choose a coordinating CSIRT, what each submission must contain, who is authorised to file out of hours, the parallel duty to notify users, how the clocks interact with NIS2, DORA and UK GDPR, the evidence pack, the penalty bands, and a four-week readiness plan.

Read more
CHAT