Bakermckenzie Growing Legal Complexity in Cybersecurity and AI Governance
Article Content
- •Australian courts are narrowing the scope for legal privilege in cyber incident reports.
- •Over half of organizations report AI risk management as a significant challenge.
- •New regulations require annual cyber audits under the California Consumer Privacy Act.
Recent developments in cybersecurity law highlight a significant shift towards stricter enforcement and legal complexity, particularly in Australia. The Federal Court's decision in Medibank Private Limited v McClure emphasizes the challenges of maintaining legal professional privilege over cyber incident investigation reports. This ruling indicates that reports created during cyber breaches may serve multiple purposes beyond legal advice, potentially undermining claims of privilege. Additionally, organizations face increasing scrutiny regarding AI governance and data practices, with over half of surveyed executives identifying AI risk management as a major challenge. The California Consumer Privacy Act mandates annual cyber audits for companies, introducing heightened regulatory risks. These developments reflect a broader trend of integrating cyber resilience into organizational governance amidst evolving technological landscapes.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track InspectRealEstate in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…