In 2026, many companies are using AI to identify opportunities, model risks, summarize diligence, compare precedents, stress-test assumptions, and prepare decision memos in days rather than weeks. But if the final step before action is “send it to outside counsel
Debevoise & Plimpton
Debevoise & Plimpton is a law firm that publishes blogs focusing on legal developments and regulatory issues affecting various industries. Their content covers topics such as artificial intelligence regulation, privacy and data protection laws, cybersecurity, financial services compliance, and corporate governance. The firm provides analysis of new legislation, regulatory guidance, and enforcement trends, often highlighting practical implications for businesses and legal practitioners. Their posts also explore emerging risks and best practices related to technology adoption, including AI and cybersecurity frameworks. Debevoise & Plimpton's publications serve as resources for understanding complex legal landscapes and compliance requirements in areas like advertising law, data privacy, financial regulation, and technology law.
Latest from Debevoise & Plimpton - Page 2
What Exactly Is an “AI System,” an “AI Solution,” or an “AI Agent”? Debevoise’s Updated Practical Definitions for Common AI Terms
Last November, we published a blog post setting out our definitions of common AI terms. AI has continued to evolve rapidly since then. This update replaces that post and incorporates newer terminology, including “AI Agent,” “Agentic AI,” and “Harness.”
AI…
Business Email Compromise: Reducing Risk and Litigation Exposure
Business email compromise (“BEC”) attacks are one of the most significant cyber threats facing companies today, and the latest federal data show that the problem is intensifying. In its 2025 Internet Crime Report, the FBI’s Internet Crime Complaint Center…
UK Data Protection Complaints: New Requirements In Force
From 19 June 2026, businesses in the UK are subject to new statutory data protection complaints handling requirements, intended to give individuals a clearer route for raising data protection complaints directly with businesses before escalating matters to the Information Commissioner’s…
New Executive Order Targets Cyber Risks from Frontier AI
On June 2, 2026, President Trump issued an executive order (the “Order”) on artificial intelligence innovation and cybersecurity. The Order focuses on the cyber risks and defensive potential of advanced frontier AI models, including their ability to accelerate both malicious…
Debevoise Data Strategy & Security Group Again Recognized Across AI, Privacy, Cybersecurity, and Securities Regulation & Enforcement in Chambers Rankings
Debevoise is pleased to share that our Data Strategy & Security (“DSS”) Group has again been recognized in the latest Chambers USA rankings across artificial intelligence, privacy and cybersecurity, and securities regulation and enforcement.
The rankings reflect the strength of…
NYDFS’s Frontier AI Guidance: Familiar Vulnerabilities, Faster Threats
On May 21, 2026, the New York State Department of Financial Services (“NYDFS”) issued two related industry letters: an advisory to CISOs of NYDFS-regulated entities addressing heightened cybersecurity risks associated with certain frontier AI models (the “Advisory”), and related guidance…
Preparing for Mythos and Enhanced AI-Enabled Cyber Threats: UK Financial Services Regulator Expectations
Frontier AI models are changing the cyber risk calculus. By helping threat actors identify, weaponise and exploit vulnerabilities more quickly, these models can increase both the speed and scale of cyber attacks. As discussed in our recent post, “Mythos:…
EU AI Act High-Risk AI Systems: EU Commission Publishes Draft Guidance
The European Commission has published draft guidance on the classification of “high-risk” AI systems under the EU AI Act, together with practical examples of systems that, in its view, would – and would not – fall within each of the…
Cybersecurity Incident Disclosure: Form 8-K Tracker (Two-Year Update)
Key Takeaways
Two years after the May 21, 2024 statement by the Securities and Exchange Commission’s (“SEC”) Division of Corporation Finance clarifying the intended use of Item 1.05 of Form 8-K for cybersecurity incident disclosures, voluntary Item 8.01 cybersecurity filings…