Securiti launches Gencore AI, a holistic solution to build Safe Enterprise AI with proprietary data - easily

View

Global AI Regulations Roundup: Top Stories of February 2025

Contributors

Aswah Javed

Associate Data Privacy Analyst at Securiti

Rohma Fatima Qayyum

Assoc. Data Privacy Analyst

Asaad Ahmad Qureshy

Associate Data Privacy Analyst at Securiti

Yasir Nawaz

Digital Content Producer at Securiti

Securiti has initiated an AI Regulation digest, providing a comprehensive overview of the most recent significant global developments, announcements, and changes in the field of AI regulation. Our website will regularly update this information, presenting a monthly roundup of key activities. Each regulatory update will include links to related resources at the bottom for your reference.

North and South America Jurisdiction

1. Minnesota Attorney General Publishes Report On Harmful Effects Of Emerging Technologies Such as AI & Social Media

Date: February 4, 2025
Summary: Attorney General Keith Ellison released a detailed report on the harmful effects of emerging technologies such as AI and social media on the young citizens of Minnesota. The report contains a detailed examination of the harms caused by these technologies, an analysis of the design features causing the harm, evaluation of legislative efforts, and policy recommendations for the Minnesota legislature. As far as AI is concerned, it focuses on the unregulated use of chatbots and potential for GenAI to be used in deepfakes. Furthermore, the report recommends prohibiting the "deceptive patterns", limiting engagement-based optimization algorithms and their use in educational settings, increasing the transparency and empowering the users and guardians.

2. Coalition Of US State Attorney General Blocks Elon Musk & DOGE's Access To Americans' Sensitive Data From The Treasury Department

Date: February 8, 2025
Summary: A coalition of state Attorneys General in the US has secured a federal court order blocking Elon Musk's attempts to access Americans' sensitive data through the US Treasury.

A federal judge granted the temporary restraining order (TRO) that blocks "political appointees, special government employees, and any government employee detailed from an agency outside the Treasury Department from accessing the Treasury Department payment systems or any other data maintained by the Treasury Department containing personally identifiable information."

The order comes after the coalition filed a lawsuit last week alleging the Trump administration's illegal attempts to provide Musk and his Department of Government Efficiency (DOGE) with unauthorized access to the Treasury Department's central payment system and, therefore, to Americans' most sensitive personal information, including bank account details and Social Security numbers.

The restraining order is temporary, but it blocks the defendants from granting access to any Treasury payment recording, payment systems, or any other data maintained by the Treasury containing personally identifiable information and/or confidential financial information of payees other than to civil servants that need to access such systems to perform their jobs as described by the Bureau of Fiscal Services (BFS) and have passed all background checks and security clearances and taken all information security training called for in federal statues and Treasury regulations.

Any prohibited individuals that have had access to such information since January 25, 2025, must immediately destroy any and all copies of materials downloaded from Treasury records and systems. Read More.

3. New York Governor Announces Statewide Ban On DeepSeek Use On Government Devices & Networks

Date: February 10, 2025
Summary: New York Governor Kathy Hochul has announced a statewide ban on downloading DeepSeek on government devices and networks.

This comes after concerns over DeepSeek's potential connection to foreign government surveillance programs that could lead to data and technology theft. The ban is in line with the state's Acceptable Use of Artificial Intelligence Technologies policy that evaluates AI systems and ensures agencies' vigilance. Furthermore, the move builds on the Governor's 2024 guidance related to AI use in government, meant to drive innovation, increase operational efficiencies, and deliver better service to New Yorkers without compromising their privacy or exposing them to additional risks. Read More.

4. Virginia Passes New Law Regulating Development & Deployment Of High-Risk AI Systems

Date: February 20, 2025
Summary: The Virginia legislature passed HB 2094, which regulates the development and deployment of high-risk AI systems within the state.

Based on Colorado's AI Act, HB 2094 is narrower in scope. It only applies to cases where an AI system output would serve as a "principal basis" for a consequential decision without human review, oversight, involvement, or intervention. However, unlike Colorado's AI Act, it does not have any public reporting obligations apart from transparency requirements for high-risk GenAI systems related to the production and modification of synthetic content.

If the Governor approves, the law will become effective from July 1, 2026. Read More.

EMEA Jurisdiction

5. Provision On Prohibited AI Practices & Literacy Come Into Effect

Date: February 2, 2025
Summary: Key parts of the EU's AI Act took effect on February 2, 2025. These include the rules of AI literacy and prohibited AI practices as outlined in Article 5. These banned AI practices pose significant risks, including manipulation techniques, exploiting vulnerabilities, social scoring, crime risk profiling, unauthorized facial recognition, emotion detection, biometric categorization, and certain uses of 'real-time' biometric identification. Similarly, Article 4 requires all AI system providers and deployers to ensure their employees have appropriate training and information on how the AI system is used. The rest of the AI Act will take effect on August 2, 2026, except for rules on general-purpose AI models and penalties, which will be enforced from August 2, 2025. Read More.

6. EU Commission Releases Guidelines On Prohibited AI Practices Per The AI Act

Date: February 4, 2025
Summary: The EU Commission has released its guidelines on prohibited AI practices outlined in the AI Act. These practices are considered unacceptable owing to the risk they pose to European values and fundamental rights.

Some of the specifically banned practices include harmful manipulation, social scoring, and real-time remote biometric identification. The guidelines are meant to ensure the consistent and effective implementation of the AI Act across the EU while offering valuable insights into how the Commission interprets the prohibitions. However, the guidelines are non-binding, with the CJEU holding the final authority on legal interpretations. Read More.

7. EU Commission Releases Guidelines Defining "AI System” Under AI Act

Date: February 6, 2025
Summary: The European Commission has released guidelines clarifying the definition of an AI system per the AI Act. These guidelines are meant to assist providers and relevant stakeholders in determining whether software can be considered an AI system, facilitating the application of the AI Act's rules. The guidelines are non-binding and expected to evolve over time, with regular updates meant to ensure practical experiences and emerging questions are effectively addressed. Read More.

Asia Jurisdiction

8. Chinese PPC Releases Privacy Policy Details For DeepSeek

Date: February 3, 2025
Summary: The PPC has released details on the privacy policy of all the major entities associated with DeepSeek. The privacy policy outlines the following:

  • All personal information collected through DeepSeek's services will be stored on servers in the People's Republic of China.
  • The stored data will be governed by Chinese laws, including the Personal Information Protection Law (PIPL), Cybersecurity Law, Data Security Act, and National Information Law. Read More.

9. Japan Instructs Ministries To Avoid DeepSeek Use

Date: February 3, 2025
Summary: The Japanese government has instructed its ministries and agencies to avoid using AI developed by DeepSeek, citing concerns over data privacy practices. Government institutions using GenAI must avoid inputting confidential information into such models, and any such use is subject to prior approval. It further stated that its ministries would collaborate on all AI-related issues while engaging with their international counterparts via global frameworks. Read More.

10. South Korea’s PIPC Investigates DeepSeeks Data Privacy Practices

Date: February 7, 2025
Summary: The PIPC has investigated DeepSeek to uncover how Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence collect, use, store, and share personal data. The investigation included a comparative analysis of DeepSeek's privacy policies and ToS while collaborating with various international data protection agencies and discussions with China diplomatically. Currently the PIPC has temporarily suspended the services of Hangzhou DeepSeek Artificial Intelligence Co., Ltd. due to deficiencies in privacy policies and non-compliance with the PIPA. Read More.

11. Taiwan's Digital Affairs Ministry Bans Use Of DeepSeek AI

Date: February 10, 2025
Summary: The Ministry of Digital Affairs in Taiwan has restricted its agencies from using DeepSeel owing to the various cybersecurity risks associated with it, such as potential leaks and data transmission interception. This restriction is in line with previous policies that have prohibited the use of such foreign technology in sensitive sectors. Read More.

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share


More Stories that May Interest You

Videos

View More

Mitigation OWASP Top 10 for LLM Applications 2025

Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...

View More

DSPM vs. CSPM – What’s the Difference?

While the cloud has offered the world immense growth opportunities, it has also introduced unprecedented challenges and risks. Solutions like Cloud Security Posture Management...

View More

Top 6 DSPM Use Cases

With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...

View More

Colorado Privacy Act (CPA)

What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...

View More

Securiti for Copilot in SaaS

Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...

View More

Top 10 Considerations for Safely Using Unstructured Data with GenAI

A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....

View More

Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes

As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...

View More

Navigating CPRA: Key Insights for Businesses

What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...

View More

Navigating the Shift: Transitioning to PCI DSS v4.0

What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...

View More

Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)

AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 46:02

Building Safe Enterprise AI: A Practical Roadmap

Watch Now View
Spotlight 13:32

Ensuring Solid Governance Is Like Squeezing Jello

Watch Now View
Spotlight 40:46

Securing Embedded AI: Accelerate SaaS AI Copilot Adoption Safely

Watch Now View
Spotlight 10:05

Unstructured Data: Analytics Goldmine or a Governance Minefield?

Viral Kamdar
Watch Now View
Spotlight 21:30

Companies Cannot Grow If CISOs Don’t Allow Experimentation

Watch Now View
Spotlight 2:48

Unlocking Gen AI For Enterprise With Rehan Jalil

Rehan Jalil
Watch Now View
Spotlight 13:35

The Better Organized We’re from the Beginning, the Easier it is to Use Data

Watch Now View
Spotlight 13:11

Securing GenAI: From SaaS Copilots to Enterprise Applications

Rehan Jalil
Watch Now View
Spotlight 47:02

Navigating Emerging Technologies: AI for Security/Security for AI

Rehan Jalil
Watch Now View
Spotlight 59:55

Building Safe
Enterprise AI

Watch Now View

Latest

Automating EU AI Act Compliance View More

Automating EU AI Act Compliance: A 5-Step Playbook for GRC Teams

Artificial intelligence is revolutionizing industries, driving innovation in healthcare, finance, and beyond. But with great power comes great responsibility—especially when AI decisions impact health,...

Gencore AI Customers Can Now Securely Use DeepSeek R1 View More

Gencore AI Customers Can Now Securely Use DeepSeek R1

Enterprises are under immense pressure to use Generative AI to deliver innovative solutions, extract insights from massive volumes, and stay ahead of the competition....

Navigating Data Regulations in India’s Telecom Sector View More

Navigating Data Regulations in India’s Telecom Sector: Security, Privacy, Governance & AI

Gain insights into the key data regulations in India’s telecom sector and how they impact your business. Learn how Securiti helps ensure swift compliance...

Best Practices for Microsoft 365 Copilot View More

Data Governance Best Practices for Microsoft 365 Copilot

Learn key governance best practices for Microsoft 365 Copilot to ensure security, compliance, and effective implementation for optimal business performance.

5-Step AI Compliance Automation Playbook View More

EU AI Act: 5-Step AI Compliance Automation Playbook

Download the whitepaper to learn about the EU AI Act & its implication on high-risk AI systems, 5-step framework for AI compliance automation and...

A 6-Step Automation Guide View More

Say Goodbye to ROT Data: A 6-Step Automation Guide

Eliminate redundant obsolete and trivial (ROT) data with a strategic 6-step automation guide. Download the whitepaper today to discover how to streamline data management...

Texas Data Privacy and Security Act (TDPSA) View More

Navigating the Texas Data Privacy and Security Act (TDPSA): Key Details

Download the infographic to learn key details about Texas’ Data Privacy and Security Act (TDPSA) and simplify your compliance journey with Securiti.

Oregon’s Consumer Privacy Act (OCPA) View More

Navigating Oregon’s Consumer Privacy Act (OCPA): Key Details

Download the infographic to learn key details about Oregon’s Consumer Privacy Act (OCPA) and simplify your compliance journey with Securiti.

Gencore AI and Amazon Bedrock View More

Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock

Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...

DSPM Vendor Due Diligence View More

DSPM Vendor Due Diligence

DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...

What's
New