Sep. 2, 2026

Protecting the AI Supply Chain From a Growing Wave of Attacks

A two-stage ransomware attack discovered in July 2026 exploited software widely used to develop and operate AI systems, enabling attackers to destroy a trained model. The incident highlights a growing security gap from a new class of AI-adjacent enterprise software proliferating faster than organizations and security teams can adapt their defenses. This article highlights key takeaways from this incident, labeled Jadepuffer, and an earlier attack in 2026 on a popular AI gateway. It also offers several practical steps for strengthening security across AI development and deployment, with governance insights from experts at Black Duck, Fisher Phillips, JFrog, Snyk, ZwillGen and Sysdig, whose researchers first described Jadepuffer. See “How the Whole-of-State Movement Is Protecting the Community Organizations the Private Sector Depends On” (Jul. 15, 2026).

Navigating the AI Omnibus: Key Changes to the E.U. AI Act

Companies that have been racing to prepare for the European Regulation on Artificial Intelligence (E.U. AI Act) now have more time to comply with many of its most significant requirements – but the compliance burden remains largely intact. The E.U. Digital Omnibus on AI (AI Omnibus), which entered into force on July 27, 2026, amends the E.U. AI Act with the stated goals of streamlining regulation and supporting innovation and competitiveness. The extent to which it will achieve those goals, however, remains an open question. This first article in a two-part series offers an overview of the AI Omnibus’ principal amendments to the E.U. AI Act, with insights from European experts at Bird & Bird, Freshfields, Gibson Dunn, Orrick and Taylor Wessing. Part two will discuss what companies can do to prepare for the new compliance deadlines and the impact of the AI Omnibus on enforcement. See our three-part series answering top questions about the E.U. AI Act: “Reach and Unique Requirements” (Apr. 24, 2024), “Risk Tiers and Big-Player Transparency” (May 1, 2024), and “Practical Steps and What’s Next” (May 8, 2024).

Compliance Reps and Warranties: Adapting to Emerging Risks

Compliance representations (reps) and warranties can be an underestimated element of a merger, acquisition or third-party contract, often reduced to boilerplate afterthoughts. However, in a moment of technological change, cut-and-paste language runs the risk of being woefully out of date by the time a deal closes. This fourth article in a series about compliance reps and warranties covers how language in third-party contracts has evolved as supply chain issues represent a larger portion of companies’ risk profiles, and how reps and warranties should shift in response to technological and regulatory shifts. The first article in the series reported on the continuing relevance of compliance reps and warranties, the second article suggested negotiation strategies, and the third article addressed their verification and enforcement. See “Key Terms and Negotiation Issues in Data Processing Agreements” (Sep. 13, 2023).

Ashurst Perkins Coie Adds Former DOJ Attorney As Partner in Chicago

Ashurst Perkins Coie has welcomed Prava Palacharla as a partner in its complex litigation practice in Chicago. She joins from the National Security Cyber Section of the DOJ’s National Security Division, where she handled cross-border cybersecurity prosecutions. For insights from Ashurst Perkins Coie, see “Enforcement Lessons From Disney and Four Other FTC Children’s Privacy Actions” (Jan. 28, 2026); and “Reference Guide to 2025 Executive Orders for Compliance Professionals” (Apr. 9, 2025).