On December 16, 2025, the U.S. National Institute of Standards and Technology (“NIST”) published a preliminary draft of the Cybersecurity Framework Profile for Artificial Intelligence (“Cyber AI Profile” or “Profile”). According to the draft, the Cyber AI Profile is intended to “provide guidelines for managing cybersecurity risk related to AI systems [and] identify[] opportunities for
Latest from Covington & Burling LLP - Page 2
New York Governor Signs Frontier AI Safety Legislation
On December 19, New York Governor Kathy Hochul (D) signed the Responsible AI Safety & Education (“RAISE”) Act into law, making New York the second state in the nation to codify public safety disclosure and reporting requirements for developers of frontier AI models. Prior to signing, Governor Hochul secured several commitments from the legislature to…
FINRA Highlights Trends and Risks in Member Firms’ Use of GenAI
With innovation comes regulatory scrutiny. On December 9, 2025, the Financial Industry Regulatory Authority, Inc. (“FINRA”) released its 2026 Annual Regulatory Oversight Report (the “2026 Report”), which includes a new section dedicated to generative artificial intelligence (“GenAI”). The 2026 Report is the latest iteration of FINRA’s yearly summary of insights from its regulatory oversight activities,…
European Commission Launches Consultations on the EU AI Act’s Copyright Provisions and AI Regulatory Sandboxes
The European Commission (“Commission”) recently launched two stakeholder consultations under the EU AI Act. The first (see here), closing on 9 January 2026, relates to the copyright-related obligations for General Purpose AI (“GPAI”) providers under the AI Act and GPAI Code of Practice. The second (see here), closing on 6 January 2026,…
Spain Issues Guidance Under the EU AI Act
In December 2025, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) published a set of detailed guidance documents and templates aimed at helping providers and deployers of high-risk AI systems under the EU AI Act comply with the relevant requirements of the law. All materials are currently available in Spanish only.…
European Commission Adopts Proposal for the Biotech Act
Introduction
On 16 December 2025, the European Commission (“Commission”) published its Proposal for a Regulation on establishing a framework of measures for strengthening the Union’s biotechnology and biomanufacturing sectors particularly in the area of health (“Biotech Act”) (see here). The Proposal follows a public consultation held between August 2025 and November 2025 (see here…
European Commission Announces (Long Awaited) Proposal to Simplify EU Medical Device Regulations
The European Commission announced today (16 December) its plans to simplify the existing EU regulatory framework for medical devices and in vitro diagnostic medical devices (“IVDs”). Many industry stakeholders have criticized the current EU device rules as being slow, costly, unpredictable, and unnecessarily complex. Under the proposed revisions, the Commission aims to make the rules…
President Trump Signs Executive Order to Block State AI Laws
On December 11, President Trump signed an Executive Order on “Ensuring a National Policy Framework for Artificial Intelligence” (“AI Preemption EO”), the culmination of months of efforts by Republican lawmakers to assert federal primacy over AI regulation. The AI Preemption EO, which follows the release of a draft version in November, states that “[t]o win”…
End-of-Year 2025 State and Federal Developments in Minors’ Privacy
Since our mid-year recap on minors’ privacy legislation, several significant developments have emerged in the latter half of 2025. We recap the notable developments below.…
Washington State AI Task Force Releases AI Policy Recommendations for 2026
On December 1, the Washington State AI Task Force (“Task Force”) released its Interim Report with AI policy recommendations to the Governor and legislature. Established by the legislature in 2024, the Task Force is responsible for evaluating current and potential uses of AI in Washington and recommending regulatory and legislative actions to “ensure responsible AI…