Data Privacy + Cybersecurity Insider
CYBERSECURITY
AI Agents A Top 2026 Cybersecurity Threat
Cybersecurity firm Forrester recently issued its annual report, Top Cybersecurity Threats in 2026, which outlines “the most critical risks organizations need to plan for.”
The report predicts the top threats that organizations will face in 2026 based on recent trends and observations. Read more
CMMC Phase 2: A Pause, Not a Pass
On September 10, 2025, the U.S. Department of Defense (DoD) issued the CMMC Procurement Rule, which made cybersecurity compliance a condition of doing business with that agency by requiring contractors and subcontractors to meet specified security standards before accessing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). We previously covered the CMMC Procurement Rule and its requirements in detail here.
Less than a year later, on July 13, 2026, the DoD issued guidance pausing the next scheduled step in the CMMC rollout, which had been expected in November 2026 and would have expanded the use of more formal third-party and government-led assessments. The DoD’s memorandum ties the pause to DoD’s broader effort to reduce acquisition process, speed delivery of new capabilities, and avoid placing unnecessary burdens on small and non-traditional businesses in the Defense Industrial Base. Read more
ENFORCEMENT + LITIGATION
California Privacy Regulator Puts Delivery and Transportation Apps Under the Microscope
California’s privacy regulator has launched its first-ever audit, signaling a new phase of active oversight under the California Consumer Privacy Act (CCPA) and its amendments. The California Privacy Protection Agency (CPPA) is focusing on delivery and transportation apps in the gig economy, examining how platforms collect and use personal information from both consumers and workers, and how individuals can exercise rights to know what data is collected, how it is used, and with whom it is shared. Read more
DATA PRIVACY
New DROP Requirements Raise the Stakes for Data Brokers Handling Californians’ Personal Information
California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request appears, delete the consumer’s personal information within 45 days and direct applicable service providers and contractors to do the same. Once the information is deleted, the data broker generally may not sell or share new personal information about that consumer unless the consumer indicates otherwise. Read more
ARTIFICIAL INTELLIGENCE
Frontier Model Evaluations Show They “Cheat”
A new study by the AI Security Institute (AISI), Cheating Behaviour in Frontier Model Evaluation, found “cheating behaviour in all of our capability evaluations,” and outlines “the implications as models grow more capable.”
AISI defined “cheating” as “taking an action that is out of scope for the task or explicitly disallowed by the rules, in order to achieve a goal through a shortcut, workaround, or unintended solution that the task was not meant to, or should not, permit.” Sounds like cheating to me. Read more
AI In the Dugout: MLB’s AI Crackdown Shows Why Guardrails Matter
Major League Baseball’s (MLB) move to restrict dugout iPad functionality is a reminder that AI governance is showing up everywhere, including in the middle of professional baseball games. According to reports, MLB disabled custom tablet tabs after concerns that teams were using AI-powered tools to support real-time decisions on substitutions, pitch calling, and other in-game strategy. The league’s concern appears less about technology generally, and more about preserving the line between permitted data access and automated strategic recommendations during live competition. Read more
PRIVACY TIP #500
Wow—500 Privacy Tips! Here’s a Recap
It’s hard to believe that today’s post marks the publication of our 500th Privacy Tip. What a milestone!
We started publishing Tips because readers kept asking me about ways to protect themselves from scams, how to keep up with the latest threats, and how to stay informed about emerging technology. Feedback has been overwhelmingly positive, so we will continue publishing the Tips and helping readers navigate the technology landscape—an environment that often feels like the Wild West, with new developments emerging every day.
To commemorate the 500th Privacy Tip, I thought it apropos to recap the top 10 ways to protect your privacy from a cybersecurity perspective. Revisit the most impactful privacy tips and strengthen your cybersecurity habits. Read more
RECENT NEWS
Linn Freedman to Join Panel Discussing AI Risk and Cybersecurity Governance
Data Privacy + Cybersecurity team and AI practice chair Linn Freedman will be among the panelists presenting a session titled, “AI, Cyber Risk, and the Road Ahead,” as part of a collaborative programming effort between the Greater Newport Chamber of Commerce, the Institute of Cybersecurity & Emerging Technologies at Rhode Island College, and the Newport Restoration Foundation, on July 28, 2026, in Newport, RI.
The panel will provide insight into the platforms, policies, governance frameworks, and best practices businesses and nonprofit organizations need to know to effectively, and safely, integrate AI into their operational procedures. For more information, click here.




