Two minute Junior Tech Lawyer Briefing

This is going to be a regular thing, aimed at junior tech lawyers and containing relevant news to be consumed in two minutes or less. Shockingly, this won’t be a detailed analysis. So – here we go!

Regulatory & Legislative Actions

EU AI Policy Acceleration: The European Commission launched new strategies to boost AI adoption across European industry and science. This signals the increasing legal and commercial importance of AI compliance as the EU finalizes the AI Act framework.

Italy Passes National AI Law: Italy adopted a national AI Law, effective October 10, 2025. The law complements the EU AI Act, establishing national rules on using data for AI model training and introducing age-gating requirements (parental consent for minors under 14) for accessing certain AI technologies. This creates a dual layer of AI regulation for companies operating in Italy.

German GDPR Fine for Rights Failure: The Hamburg Data Protection Authority issued a fine for a company that failed to adequately fulfill data subjects’ rights, specifically by not responding properly to opt-out requests for direct marketing. This underscores the enforcement risk associated with basic GDPR compliance obligations, even for traditional marketing methods.

Key Developments

EU Court Limits GDPR Injunctions: An EU court clarified that the GDPR itself does not automatically grant data subjects a right to preventative injunctions against data processing, though national laws may allow it. This impacts the immediate remedies available in GDPR litigation across Europe.

Australia Imposes Privacy Act Penalty for Data Breach: An Australian pathology provider was fined $5.8 million for a 2022 data breach. The court handed down the financial penalty under the Australian Privacy Act for a breach, setting a clear precedent for significant corporate liability and establishing a benchmark for security incident costs.

Cybersecurity & AI Incidents

Consulting Firm Refunds Government Due to AI Errors: Deloitte is providing a partial refund to the Australian government after a report generated with the help of Generative AI contained errors. This is a high-profile, documented instance of an “AI mistake” in a professional service contract, raising critical questions about liability, indemnity, and quality assurance clauses when AI is deployed in client-facing work.

Major Third-Party Data Extortion Threat: A cybercrime group threatened to publicly release data allegedly stolen from Qantas and dozens of other large international corporations (including Toyota, Disney, and HBO Max) by October 10. The breach originated from their use of a third-party customer management platform. This serves as a critical and immediate reminder of the severe legal and commercial risk inherent in supply chain and third-party vendor contracts.

Critical ERP Software Vulnerability: The Australian Cyber Security Centre issued a critical alert regarding a vulnerability in Oracle E-Business Suite, a widely used enterprise resource planning (ERP) system. Commercial clients relying on this software must be advised of the need for urgent patching and the legal exposure arising from failure to address a critical, published vulnerability.

Leave a Reply

Discover more from Pixels and Precedents

Subscribe now to keep reading and get access to the full archive.

Continue reading