Artificial Intelligence

Joint Guidance on AI Agent Security Carves a Path to International Standards


AI agents’ transformation of business grows more profound by the month. At some companies, corporate leaders have started drawing up hybrid organization charts showing both humans and agents. On one side, these charts show the human employees and the cost of salaries and benefits. The other half of the page shows the computing and integration budget to maintain digital labor teams.

Company leaders recognize such budgets must include adequate funds for security and governance measures to contain agents’ distinctive risks but have been hindered by the lack of neutral guidance and standards. The AI governance frameworks issued since 2023 have not been updated for autonomous AI. That leaves a crucial gap. “Past standards assume that human decision-makers are somewhere in the implementation process,” Jones Walker partner Jason Loring told the Cybersecurity Law Report.

The need for updated guidance on agent implementations arises daily, observed Freshfields partner Megan Kayo. “Companies and security teams are hungry for those standards. Clients are grasping for whatever they can get” to help with security and governance, she told the Cybersecurity Law Report.

Governments have now moved to fill the vacuum. In May 2026, the cybersecurity agencies of the Five Eyes countries, including the National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), issued lengthy joint guidance (Guidance) recommending more than 50 best practices for agent security. Later in the same month, the Government of Canada issued a guide for managing and governing agentic AI, as well (Canadian Guide).

This article discusses the new guidance’s recommendations and impact, and presents insights on what companies should do while standards slowly develop, with perspective from Kayo, Loring and experts at Norton Rose and Panoptic Systems.

See “Eyewitness Accounts and Recommended Actions to Counter AI’s Strain on Cyber Defense” (May 6, 2026).

Five Eyes Guidance on “Careful Adoption” of Agents

CISA and the NSA co-authored the Guidance with the cybersecurity authorities in Australia, Canada, New Zealand and the United Kingdom, each part of the Five Eyes alliance on signals intelligence. The Guidance, titled “Careful Adoption of Agentic AI Services,” describes agents’ security risks, lists the cybersecurity prerequisites for implementing agents, and presents best practices for designing, developing, deploying and operating agents, detailed in separate sections.

Summary of Agents’ Novel Risks

The Guidance identifies five broad categories of risk, rooted in the agents’ autonomy, their ability to communicate and act across many organizations’ systems, and their “evolving capabilities.”

The first section examines agents’ access to digital terrain. Granting agents too many privileges can cause a trail of damage even when operating properly. The second section covers design and setup flaws, where poor configurations create security issues, putting many systems at risk.

The third section focuses on behavioral risks, including when an agent pursues a goal in ways its designers never predicted. The fourth addresses structural risk from interconnected networks of agents that can rapidly spread failures across networks and companies.

The Guidance’s fifth section addresses accountability. Many agentic systems in 2026 could leave inadequate evidence of what caused a particular action, making it hard to trace what went wrong and why.

The Guidance notes that agents have caused concrete incidents, including altered files, changes to system permissions and deleted audit trails. The authors warn, too, that agents are already acting inside critical infrastructure, and that many organizations have granted agents far more access than they can safely monitor or control. A separate May 2026 report by Token Security and the Cloud Security Alliance found that 65% of 400 organizations surveyed had experienced an agent-caused incident. Of those episodes, 61% involved the exposure of sensitive data, 43% disrupted business operations, 41% produced incorrect or unintended actions within business processes, and 35% carried a financial cost.

See our two-part series on AI agent security: “Companies See Rogue Incidents but Lag on Controls” (Mar. 18, 2026), and “What CISOs and GCs Need to Know to Defend the Enterprise” (Mar. 25, 2026).

Recommendations for the Agent Supply Chain

The cyber authorities’ expectations start with design of the agents. The Guidance’s 14 recommended practices for designers include incorporating:

  • human control points;
  • strong identity mechanisms;
  • instructions to constrain agents; and
  • overlapping layers of security controls in any agentic AI systems they build.

The Guidance also sets forth 34 recommended practices for agent developers, which include:

  • integrating “comprehensive artifact logging mechanisms”;
  • strengthening adversarial training by using synthetic data;
  • structurally limiting each agent’s duties into separate “roles such as ‘Orchestrator’, ‘Reader’ and ‘Actuator’ with clear boundaries”; and
  • managing third-party components in AI products, with 14 practices specified.

The authors urge the entire supply chain to pay attention to developer and designer practices. “Operators may want to reference these best practices when choosing AI agents and agentic applications,” they advised.

See “Contracting With Vendors to Mitigate Third-Party AI Risk” (Feb. 18, 2026).

Recommendations for Deployers and Operators

For the broad swath of companies that use agents, the Guidance offers 23 practices for “deploying” them and 37 for “operating” them. Throughout the Guidance, which uses British Commonwealth spelling, the authorities urge companies to apply established principles like zero-trust segmentation of systems, “layered defence,” and strict access controls to protect their systems, data and business.

The Guidance emphasizes the need for “monitoring and auditing,” offering 14 recommendations, while also focusing on “privileges and authentication,” listing 10 best practices.

One of the Guidance’s top messages for deployers and operators is that agentic AI does not require an entirely new security program. The authorities suggest that organizations start by applying their existing cybersecurity frameworks and governance structures to their new AI agentic systems. “AI systems are fundamentally IT systems, as they run on software and hardware, operate over networks and interact with other digital services,” the Guidance notes.

However, the Guidance points out that existing frameworks are inadequate for agents’ array of challenges, cautioning companies to go slow. “Until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly and plan deployments accordingly, prioritising resilience, reversibility and risk containment over efficiency gains,” the authorities wrote.

See “Benchmarking AI Governance Practices and Challenges” (May 7, 2025).

The Guidance’s Impact

The Guidance focuses more on agents’ security than their risks to the broader enterprise, an approach that usefully addresses the most obvious threats but does not satisfy all of companies’ concerns.

Useful Recommendations for Many Deployers of Agents

The Guidance offers companies’ cybersecurity program managers a practical boost. “CISOs and other leaders have acknowledged and understand their teams’ need to be involved with these deployments,” but few have created a full roadmap, Loring observed.

The Guidance’s reference to established security concepts throughout “helps some organizations avoid the paralysis that can come with not having any idea where to start,” said Jones Walker special counsel Michelle Ramsden.

To anchor its best practice recommendations, the Guidance usefully provides examples and scenarios, Norton Rose partner Susana Medeiros told the Cybersecurity Law Report. “We can expect that organizations’ legal, security and even their red teams will attempt to test their agentic systems in line with many of the issues that CISA has highlighted using real-world scenarios,” she predicted.

See “Using ‘Red-Teaming’ to Test and Improve Cyber Defenses” (Sep. 11, 2019).

A Breakthrough Contribution

The Guidance likely will earn influence as a practical aid because CISA and the other cybersecurity agencies collectively have “access to insight from around the world,” which is “a really helpful benchmark for organizations to understand the realistic attack vectors to expect in these systems,” Medeiros predicted.

The Guidance offers an early stabilizing guidepost amid the marketplace’s churn forward in 2026 and 2027. “We’re seeing traction developing everywhere with agents. Without a consistent framework that everybody can refer back to, and with the speed at which everybody is moving, companies and developers are all going to spread out and do their own thing,” Panoptic Systems CEO Dave Medeiros told the Cybersecurity Law Report. This first set of recommendations will need to be followed by an array of technical standards and neutral frameworks. Otherwise, “that vacuum is going to be filled by commercial interests that want to set the standards the way they want to set them,” he added.

Agent security discussions often omit accountability or treat it as a secondary consideration, so the Guidance stands out for issuing strong recommendations in this area. The Guidance helpfully frames the lack of visibility into agents’ decisions and actions “as a top-tier risk” and governance bottleneck, Dave Medeiros continued. “The real critical gap with agents is going to be attribution,” i.e., not being able to say who took a troubling action or why it happened, he said. The Guidance urges organizations to retain “unified audit logs for all inter-agent interactions” and “ensure observability of and reasoning behind agent decisions.”

See “Navigating NIST’s AI Risk Management Framework” (Nov. 15, 2023).

Practical Limitations

Despite offering useful guardrails, the Guidance leaves key gaps and may have limited practical impact for more advanced adopters. Some of the Guidance’s suggested practices are concrete or technical, while others are higher-level statements about what is needed.

As with earlier frameworks, companies must adapt the Guidance’s best practices for their idiosyncratic governance and risk management operations, Freshfields partner Anna Gressel advised. “For example, the Five Eyes framework talks about validating outputs with a human in the loop – but giving some color and meaning to that requires a company to put it into employee guidance and playbooks” as well as assigning engineers to help, she elaborated.

Moreover, the Guidance’s “‘start small’ recommendation will likely be taken to heart by organizations that are not the ones that the Five Eyes and CISA are most concerned about,” Ramsden noted. “The organizations that are really on the cutting edge of agentic AI, developing and pushing tools that may have a broader impact, are likely way past starting small,” she pointed out. Companies that have strategically focused on deploying agents may have moved past the Guidance’s recommendation to use phased deployments and permissions, for example.

The Guidance also excludes practical recommendations for non-security governance controls for agentic AI systems, such as steps to increase transparency, accountability and enterprise risk assessment.

See “New Jersey and Oregon Advisories Contribute to AI Guidance From State AGs” (Feb. 12, 2025).

How Companies Can Navigate a Transitional Moment in Governance

Agents’ autonomy and speed in completing tasks expose the limits in “traditional” AI governance tools, but companies can prepare for the regulatory mandates for agent oversight that eventually will be issued by using the Guidance and Canadian Guide, as well as other advisories and frameworks that also have begun to appear.

Monitor for Updated Frameworks

Finding best practices to adopt and technological tools to govern agents has become an “enormous area of focus for organizations as they attempt to implement agents at scale, extract value from them, and really come up with a working paradigm for having employees functioning in tandem with agents as members of their team and organizations,” Gressel observed.

Beyond the Guidance, other governance frameworks and technical standards for agents are under development. The National Institute of Standards and Technology’s (NIST) Center for AI Standards and Innovation launched the “AI Agent Standards Initiative” in February 2026 and received more than 500 public comments through March in response to an associated Request for Information about AI agent security. In May 2026, the Cloud Security Alliance started administering the Agentic Trust Framework, which includes an associated assessment companies can use. That same month, Singapore released an updated agentic AI governance framework that might be a helpful resource for many companies, Gressel pointed out.

See “Anthropic’s Mythos Model Forces Companies to Regroup for a New Cyber Era” (Apr. 22, 2026).

Prioritize Safeguards Early On

Several preventive strategies are emerging in the Guidance and other recent discussion about agent security, commentators said.

Inventories

Organizations must address foundational issues such as inventorying systems and identifying “shadow agents,” ensuring they understand where agents are already in use, experts said, echoing the Guidance. According to the Token Security survey, 82% of respondents have discovered previously unknown agents in their systems in the past year, with 41% of respondents saying this happened multiple times.

Zero Trust

The frameworks released so far have converged around a Zero Trust security model, Dave Medeiros noted. “They all are looking in the same direction,” he said. Because agents “have no real concept of consequences,” organizations must “assume fallibility. And the only way that you can operate under that assumption is in a Zero Trust world, giving agents only provisional access to” tools in segmented environments, he emphasized. The Guidance directs organizations to harmonize AI agent controls with Zero Trust principles, citing NIST’s and NSA’s Zero Trust implementation publications.

Bounded Autonomy

The Canadian Guide urges organizations to focus on “bounded autonomy,” only running agents “with tight, explicit parameters that limit data, tools, permissions and scope.” This preventive control “reduces the chance of unsafe actions before they happen.” Other commentators call this idea the “least agency” principle, echoing the principle of granting users the least access necessary for a task.

Installing Brakes

Given all the uncertainty and flux in agent architecture, companies need to focus on creating controls to advance resilience, Susana Medeiros stressed. Empowering systems “to stop an agent in its tracks because it performs risky actions” using mechanisms like kill switches is an important measure, she said.

The highest costs a company might face with agents are from their actions, Dave Medeiros observed, agreeing that “it is important that the company can govern what the agents do” during their workflows with safeguards enforced before execution.

Reversing unintended actions will be a key layer of control, too, Susana Medeiros highlighted. “There’s a desire for more guidance around what level of auditability, traceability and rollback controls organizations will need so that they can manage cyber and legal risk, and also business continuity,” she pointed out. The Canadian Guide urges organizations to focus on “recoverability,” in which agents can be “guided easily, paused or stopped when needed, and quickly returned to a safe and stable state.”

See “AI Compliance Playbook: Adapting the Three Lines Framework for AI Innovations” (Jun. 2, 2021).

Mind the Gap

As consensus grows on governance principles, a significant tooling gap remains, Kayo noted. “The tools still don’t necessarily exist to fully implement what these frameworks set out,” she said.

There is a demand for tools to manage, observe and control agents, Gressel observed. “Many companies are working on entering this space and maturing the orchestration layer [of controls], but it’s definitely an area where there is still work to be done,” she said. It likely will change in the near term, with many “industry actors rowing together to make that happen,” she predicted.

Chief Privacy Officer

Strengthening the Business Case for Privacy Investment


Privacy teams might become more effective at securing sufficient budget by linking privacy initiatives to measurable business outcomes rather than to a “the government’s going to get us” narrative. At this stage, underfunded C‑suites are aware of enforcement risk – they just have chosen to accept it. To secure more budget, CPOs should shift the pitch toward operational impact, suggested Aaron Weller, Privacy Innovation & Assurance Leader at HP, during a webinar on building a better business case for privacy. This article covers ways to position privacy as an element of business infrastructure rather than as a cost center, distilling insights from Weller and Steven Robinson, former CPO and associate GC at Ricoh USA. The presentation was moderated by Ben Werner, product marketing lead at Privado AI.

See “How CPOs Can Manage Evolving Privacy Risk and Add Value to Their Organizations” (Mar. 12, 2025).

Why Compliance-Focused Rationales Lose Effectiveness

In contrast with business or marketing programs, “the return on investment in privacy programs is not obvious,” Robinson said. So, the pitch to the C‑suite often becomes something of a threat: “Either fund the privacy program or face the risk of huge fines and reputational damage when violations occur,” he added.

Although that risk is very real, “it is not particularly new or motivating, and it does not apply equally to all businesses,” Robinson observed.

“Seeking funding on the basis of avoiding enforcement risk alone is just a poor tactic,” Robinson opined. As important as enforcement is, there is a “boy-who-cries-wolf aspect of this,” he noted.

An argument to fund privacy compliance “gets weaker over time,” Robinson observed. “As months and years pass with no regulatory action – [with] other companies the ones that are making the news – your executives can be forgiven for inferring that your organization just isn’t that big a target,” he said. The result can be that privacy is insufficiently funded.

See “Statistics on Privacy Staffing, Budgets and Compliance Culture” (Apr. 2, 2025).

Opening the Door by Framing Risks of Privacy Litigation and Violations

Of course, privacy litigation remains a very real risk and can be a significant cost category, both in terms of hard costs, such as legal defense and settlement payouts, and soft costs, such as time taken to audit systems and implement corrective action, Weller observed. Reputational impact can also be significant but difficult to measure, he added.

Even if an organization wins, “it is not really a win, because the cost to respond is material,” Weller noted. “It also pulls time away from higher-value work,” he said.

Breach notification costs, whether the breach involves litigation or not, can also be significant components of privacy violations, Robinson said, referencing IBM’s 2025 Cost of a Data Breach Report, which found the breach notification costs average $4.4 million globally and more than $10 million in the United States.

Those are figures the C‑suite might notice. Nevertheless, “enforcement risk is really just table stakes,” Weller asserted. “Although it gets you attention, it doesn’t always get you investment because budgets, in practice, usually flow to things that drive savings, productivity and growth,” he said.

Ultimately, risk “opens the door,” Weller said, but “being able to quantify operational impact really helps to close the deal for the funding,” he added.

Building a Funding Strategy With Operational Efficiency

Building a return-on-investment business case for privacy should include discussion of privacy as infrastructure, data governance, AI enablement, as well as compliance process efficiency and enforcement avoidance, the Weller suggested. Addressed together, they can help build a “complete, well-rounded privacy business case,” he said.

In essence, privacy considerations should be baked into “all of the business processes that collectively roll up to good data governance, AI enablement and the other approaches that help the business do business,” Robinson suggested.

See “Making the Business Case for Privacy” (Sep. 4, 2024).

Framing Privacy As Infrastructure-Focused to Avoid Late Flagging

Privacy teams should consider the internal customers with whom they are working, Weller said. “Nobody wants a privacy review process,” he acknowledged. Rather, “they want a privacy approval process,” he stressed. Accordingly, privacy leaders should reframe the privacy process as being more infrastructure-focused “so that teams can make better decisions earlier, with fewer surprises later on in the development cycle,” he suggested.

A common pain point is “late flagging,” when privacy issues surface only after designs are finalized, vendors are selected or code is shipped, Weller observed. Privacy teams may then learn decisions were made without their input, forcing them to escalate concerns and potentially delay product launches – an approach that rarely builds support. The alternative – accepting risk until post-launch remediation – “is not great either,” he said.

Privacy needs to be reconfigured as infrastructure rather than as an artisanal approach where someone hand-crafts a privacy review and it is slightly different every time one is conducted, Weller suggested, pointing to a chatbot review as an example. Rather than conducting a different review every time a chatbot review is needed, infrastructure should be created so that the same approach can be taken for subsequent reviews, thus freeing up specialist resources for matters that are particularly risky or novel, he said.

By treating privacy as infrastructure, the consideration and resolution of privacy issues become organic to the development of products and services – in addition to creating efficiencies and operationalizing the principles of privacy by design and privacy by default, Robinson said. Treating privacy as infrastructure also “creates a culture of compliance and a culture of awareness of privacy, so now what you’re asking the C‑suite to fund is not just something that will lower enforcement risk, but something that expedites operations of the business in multiple respects,” he explained.

See “CPOs Weigh In on Navigating Myriad Privacy and Security Laws Amid Dizzying Technological Advancements” (Jun. 28, 2023).

Leaders Will Pay for Predictability

A post-hoc approach to privacy will not reduce work or create predictability, Weller said. But that very predictability, when engaging in a compliance function, “is something that leaders will pay for,” he added.

If leadership knows that the privacy team will consistently meet service-level agreements and understands that privacy concerns are likely to arise during development or rollout, business teams can plan more effectively and allocate resources more efficiently, Weller posited. That predictability decreases the prospect that leadership will need to divert resources to address privacy concerns late in the process, he added.

See “Transparency Needed, This Time in Roles for Privacy Professionals” (Dec. 18, 2024).

Support for AI Innovation

Privacy as infrastructure becomes even more compelling with the use of AI. “Organizations that will move forward most efficiently with respect to AI are those with the privacy programs that provide clear guidance for its efficient, replicable, scalable adoption and implementation,” Robinson said. “These are the organizations that know what personal data they have, and they know the extent of the consent or other legal basis they have for processing it, so they do not have to make these determinations individually, one-off, for each new AI initiative,” he continued.

See “Benchmarking AI Governance Practices and Challenges” (May 7, 2025); and “AI Governance: Striking the Balance Between Innovation, Ethics and Accountability” (Feb. 12, 2025).

Addressing the Challenge of Unmanaged Data

Organizations can build a stronger case for privacy funding by showing how unmanaged data drives cost and risk. Improving data quality is both a risk-reduction and efficiency exercise. It includes considering whether data should be collected at all and ensuring the data that is collected comes from authoritative sources rather than downstream systems that may not be reliable.

Companies need a clear view of what data they hold, how it flows, and where it is duplicated or no longer needed. “A surprising amount of risk and cost comes from data the business isn’t using,” Weller said.

Many organizations retain data for years simply because storage is inexpensive. But “storage isn’t the primary cost,” Weller noted. The real expense lies in securing data, monitoring it, responding to data subject access requests, and the risk of litigation or a breach.

Data with no business value falls into two categories. ROT – redundant, obsolete and trivial data – is not needed for legal or business purposes, Robinson said. Dark data has unknown value and remains unclassified. In both cases, the data generates no revenue but increases cost and exposure. These costs can spike significantly during breaches, litigation or regulatory enforcement, creating a persistent, often untracked, financial burden.

Data mapping is central to addressing the problem. It helps identify and delete unnecessary data, assess the value of dark data and align data practices with business priorities. Organizations may also benefit from shifting their default approach: rather than retaining data unless deletion is required, they should delete data unless there is a clear legal or business justification.

To reduce unnecessary retention and improve data quality, which is particularly important as organizations train AI systems, companies can implement a policy where they ask if there is a legal or business need to retain the data. If there is not, they must follow an approved data deletion and destruction process, Weller suggested, noting that he used this approach with a Fortune 50 company.

Framed this way, privacy investment becomes a straightforward business decision. Organizations can either absorb ongoing, unpredictable costs from maintaining low-value data or fund a structured privacy program that reduces risk, lowers operating costs and supports faster product development. The latter also helps embed compliance into everyday business operations, Robinson said.

See our two-part series “AI Meets GDPR”: EDPB Weighs In on AI Models (Feb. 5, 2025), and Mitigating Risks and Scaling Compliance in the Development and Deployment of AI Models (Feb. 19, 2025).

Takeaways

Ultimately, privacy should not be a bottleneck, the presenters suggested. There are ways for the privacy program to function efficiently while the team makes a strong case for funding.

“Instead of the underfunded privacy story, which ends with increased breach notification costs, litigation, expense, delays to product development and implementation, the story can be, ‘We undertook a planned privacy program, proportionate to what we were doing,’” Robinson suggested. Being able to say, the privacy program helped decrease costs and, “when the inevitable breach occurred, we could get our hands around it faster, remediation was cheaper, and to the extent we had exposure, it was within the limits of our insurance coverage,” is a much better outcome, he said.

Risk Assessment

A Quick Start Guide to Risk Assessments in Trump 2.0


The pace of change in 2026 can challenge even the most seasoned practitioners. Following the DOJ’s 2024 edits to its Evaluation of Corporate Compliance Programs (ECCP) suggesting ways companies could modernize their risk assessment programs, the second Donald Trump presidential administration (Trump 2.0) completely rearranged the U.S. enforcement landscape in 2025. During Trump 2.0, geopolitical risks have evolved and generative and agentic AI have impacted both risks and the tools used to detect them, demanding more dynamic compliance programs.

This quick start guide to risk assessments during Trump 2.0 provides a roadmap for how companies can keep their risk assessments nimble in the face of rapid change.[1]

See “Unifying Risk Assessments: Breaking Silos to Enhance Efficiency and Manage Risk” (Jan. 29, 2025).

Understanding the Basics

To start, it is important to understand what a risk assessment is (and is not) and the elements that comprise one.

What Is a Risk Assessment?

  • A Basic Definition: A compliance risk assessment involves the identification, review and analysis of the consequences of potentially failing to comply with the laws and regulations to which a company is subject to determine whether existing risk mitigation measures reduce the risk of noncompliance to an acceptable level.
  • Different From a Compliance Program Assessment: Companies often confuse or conflate risk assessments and program assessments, which assess whether a compliance program is functional and effective.
  • Also Different From ERM: A compliance risk assessment is also narrower than an enterprise risk management (ERM) exercise, which seeks to identify and manage root cause risks, such as legal, regulatory, commercial, geopolitical and all other risks to the company achieving its strategic goals.

Elements of a Risk Assessment

A risk assessment can be broken down into four key phases or elements.

  • Identification: The first step is identifying the inherent legal, regulatory and reputational risks considering the company’s business activities and footprint. A compliance risk assessment is more than a laundry list of threats to an organization, however, and should address variations in risk faced by different aspects of the company and as a result of M&A activity. The company should also attempt to quantify the likelihood that a particular outcome will occur.
  • Evaluation: A company must evaluate the consequences of failing to comply with laws and regulations that create risk for the company. The ECCP emphasizes the importance of using a company’s internal data – from hotlines, expense reimbursements and internal investigations, among other sources – in evaluating a company’s risks.
  • Mitigation: The company must confirm the existence of mitigating controls and measures that reduce the likelihood or severity of legal or regulatory violations or reputational damage and develop additional strategies to mitigate the risks from noncompliance.
  • Monitoring: A company must monitor the effectiveness of the mitigating controls and measures implemented, as well as changes in the business and compliance environment.

See “Guide to AI Risk Assessments” (Jun. 18, 2025).

Emerging and Evolving Areas of Risk

With shifts in enforcement priorities in Trump 2.0 evolving to systemic realignment, touching everything from foreign bribery to export controls to sustainability disclosures and human rights obligations, it is important for companies to consider what new and emerging areas of risk they face.

Cybersecurity, Data Privacy and AI

Changes in technology are impacting risk, as are changes to how those technologies are regulated both in the U.S. and abroad.

  • Multiple Regimes: In the U.S., some federal and state regulators have their own flavor of cybersecurity, data privacy and AI regulations. In the E.U., in addition to the principle-based requirements of the GDPR, companies also face heightened requirements in the NIS2 Directive, Digital Operational Resilience Act (DORA) and Cyber Resilience Act.
  • Industry-Specific Requirements: Industry standards have also emerged, both from within industries and from regulators, adding an extra layer of complexity.

See “Updating Compliance Programs to Address the CPPA’s Regulations on ADMT and Risk Assessments” (Sep. 17, 2025).

Other Corporate Risk Areas

Cartels and TCOs

In multiple policy documents, Trump 2.0 has made clear that it is focused on the total elimination of cartels and transnational criminal organizations (TCOs). As cartels and TCOs become more embedded in everyday businesses such as gas stations and logistics, corporations are increasingly likely to have touchpoints that could lead to scrutiny from U.S. enforcers.

FTOs

Trump 2.0 has also designated an increasing list of TCOs as foreign terrorist organizations (FTOs,) which gives the U.S. government significant power to seize and forfeit assets related to these organizations. It also increases risk for companies that come into business contact with FTOs as they can be charged with “material support” of a terrorist organization.

Sanctions

Sanctions are a key tool used by countries to influence the actions of other nations. For example, in the wake of Russia’s 2022 actions in Ukraine, the U.S., U.K. and E.U. collectively initiated the most extensive and rapidly escalating sanctions regime in history. Cuba, Venezuela and Iran have faced economic sanctions for many years but recent actions by the U.S. government – such as the capture of Venezuelan president Nicolás Maduro and the U.S.’ military actions against Iran in early 2026 – have further complicated an already knotty situation.

Tariffs

Tariffs are taxes imposed on goods imported into the U.S. and Trump 2.0 is significantly focused on tariffs, despite legal setbacks. The administration has promised to more aggressively investigate and prosecute tariff evasion, significantly heightening the risks associated with these otherwise business-as-usual expenses.

Modern Slavery and Human Rights

Corporations also face supply chain compliance risks that are multidimensional and not necessarily legal in nature, such as the risks associated with human rights violations and modern slavery. Organizations should remember that a focus on the DOJ’s priorities may blind them to real risks in areas governed by technical standards, cross-border regulations and contractual expectations.

When to Assess

  • Responding to Changed Circumstances: In Trump 2.0, experts suggest moving away from a calendar-based approach – once every one, two or three years, depending on circumstances – and moving toward risk assessments that are more responsive to changing circumstances.
  • When Internal Changes Occur: Companies should consider a reassessment when they change their business model or commercial operations, including by:
    • entering and exiting from geographic markets;
    • increasing or decreasing their reliance on third-party sales channels and consultants;
    • completing transformative M&A transactions;
    • launching new or materially altering relationships with critical third parties either through joint ventures or contractual agreements;
    • expanding vertically in the value chain;
    • modifying its sourcing model and key suppliers; and
    • changing customer payment models.
  • External Developments to Consider: Companies should also reassess in the face of changing:
    • world events such as pandemics and wars;
    • industry standards;
    • government regimes;
    • legal or regulatory requirements;
    • enforcement patterns; and
    • technologies.

See “Checklist for Framing and Assessing Third-Party Risk” (Aug. 16, 2023).

Who Should Assess

Risk assessment is often a collaborative effort between a variety of functions within the organization, including legal and compliance and the internal audit team.

  • Taking the Lead: Whether legal, compliance or internal audit will take charge depends on applicable law and a company’s risk profile.
    • In companies with an independent compliance function, it can make sense for that department to take the lead.
    • If a company thinks a risk assessment might turn up issues requiring legal advice or involving litigation, it may be best to have the legal department take the lead need to ensure necessary attorney-client or work product privilege protections.
  • Input From Multiple Teams: Outside of leadership, a risk assessment should be sure to incorporate input and expertise from throughout the company.
  • Involving Company Leadership: To ensure that the findings of a risk assessment are actionable, senior executives and the board of directors should be included in the process, as well.

What Tools to Use

A risk assessment is a multistep process that uses a mix of high- and low-tech tools to gather information about risk. Review starts with gathering available data to perform a desktop review, and then it can include surveys and interviews to fill in a more detailed picture of risk.

Existing Data

Companies in general, and compliance programs in particular, generate significant amounts of data, much of which can be used to inform and shape a risk assessment.

  • KRIs: Companies must first choose which key risk indicators (KRIs) they will use to measure risk. They can include:
    • number and location of geographies in which the company operates;
    • prices on key inputs or outputs;
    • scores on key risk measures such as Transparency International’s Corruption Perception Index;
    • due diligence risk scores on third parties and other business partners; and
    • benchmarking data from consulting firms and non-governmental organizations and other third parties.
  • KPIs: Then companies must choose which key performance indicators (KPIs) they will use to assess mitigation measures. KPIs can include:
    • time to discover an underlying violation of law or regulations;
    • time to investigate and resolve any detected violations;
    • number and severity (measured by a standard scale) of compliance and other internal audit findings;
    • time to remediate audit findings;
    • cost and expense from underlying violations (including for criminal or regulatory matters related to civil litigation);
    • the budgets of the legal, compliance and HR departments;
    • compliance costs;
    • compliance headcount;
    • number of violations detected;
    • number of hotline reports received;
    • number of whistleblower reports received; and
    • training completion rates.
  • Consolidating Data: An underrated step in all data analysis is getting data into one location, cleaned up and standardized so that analysis can be performed effectively.

See “How eBay and PayPal Use Key Performance Indicators to Evaluate and Improve Privacy Programs” (Jan. 8, 2020).

Surveys and Interviews to Generate New Data

KPIs should be bolstered with questionnaires that are designed to surface risks that might not be apparent in the data generated in the regular course of business.

  • Format Options: The survey format can be just as important as the content, as different types of questions can illicit different types of information.
  • Multiple Choice Questions: Surveys that feature yes-no checklists or multiple-choice answers are easy to tabulate, but they tend not to generate much insight into a company’s actual compliance culture.
  • Unstructured Questions: Open-ended questions – whether in a written survey or in interviews with key stakeholders – allow respondents to provide a free-form answer about the risks they are encountering. These answers might contain highly valuable information, but can themselves carry some risk if employees provide sensitive information or discuss issues with legal consequences.

Data Analysis

An effective risk assessment requires more than collecting data. Results must be reviewed and analyzed to detect risk.

  • Looking for Patterns: Companies may organize and review their data to explore differences and trends across specific geographies and third-party populations, which can further inform the identification of specific compliance risks to which the company is exposed.
  • A Holistic Approach: When interpreting the implications behind KRIs and KPIs, companies need to take a holistic view of risk, incorporating possible impacts to stakeholders in addition to direct risks to the business itself.
  • Red Flags: Even if a company takes care in framing survey questions – and weeds out irrelevant data points such as the complaints of disgruntled employees – there should always be a plan in place to raise genuine red flags and follow up.

See “DOJ’s 2024 Edits to the ECCP: Data Analytics to Find Risks and Measure Effectiveness” (Nov. 20, 2024).

Incorporating AI

Considering the ubiquity of machine learning algorithms, as well as generative and agentic AI in all areas of life, organizations would be remiss if they did not incorporate AI into a risk assessment.

  • Expected by Enforcers: The ECCP makes clear that enforcers expect companies to incorporate whatever cutting-edge technology they are using in their business to assist with compliance, including machine learning and AI.
  • Background Research: AI can be helpful in researching applicable legal requirements and is useful in scanning public reports that can serve as a baseline for identifying emerging issues. It can also be helpful in translating research documents into local languages.
  • Triaging Large Data Pools: AI can help with the sorting, categorizing and prioritization of large volumes of data such as expense reimbursement data.
  • Interpreting Unstructured Data: AI can identify anomalies or help sort through open-ended survey responses by searching for high-risk keywords and performing sentiment analysis.
  • Mapping Supply Chains: AI can be used to draw on public records to better understand where a supply chain extends beyond the first tier.
  • Understanding the Limitations: AI output hallucinations (outright fabrications), confabulations (plausible errors where a cited source might actually exist but not stand for the proposition asserted) and bias can mar the accuracy of a risk assessment, so companies should take care to keep humans in the loop at every step.

See “Benchmarking AI Uptake by Compliance Functions” (Dec. 3, 2025).


[1] This Quick Look incorporates original reporting by Lori Tripoli.

People Moves

Cooley Strengthens Cybersecurity, Data and Privacy Practice


Cooley has welcomed Meredith Halama and Katie Cramer to its litigation department’s cyber/data/privacy practice. Halama joins as a partner in the firm’s Washington, D.C., office, and Cramer is of counsel in the Denver office. Both attorneys arrive from Perkins Coie and specialize in the application of consumer privacy laws to advertising technology.

Halama’s practice sits at the intersection of privacy laws and the adtech ecosystem. With more than 20 years of privacy law experience, she advises clients – including major technology platforms, streaming services, publishers, retailers and advertising technology intermediaries – on the ever-evolving U.S. privacy legal landscape with a practical, results-oriented approach, and defends them before regulators in matters concerning the use and disclosure of PI for advertising purposes. Most recently, Halama was co-chair of the privacy and security practice at Perkins Coie. She also previously served as the deputy GC and director of policy and compliance for the Network Advertising Initiative, the industry trade group for online advertising.

Cramer advises top technology and AI companies as well as global consumer-facing brands, including leading advertising technology companies, on privacy issues that inform product design, advertising and revenue strategies, and data governance decisions. Most recently, she was a partner at Perkins Coie, where she focused on state consumer privacy laws, Section 5 of the FTC Act, state laws governing consumer health data and children’s privacy issues.

For insights from Cooley, see “Eyewitness Accounts and Recommended Actions to Counter AI’s Strain on Cyber Defense” (May 6, 2026); and “Connected Cars: Privacy Compliance Guidance” (Apr. 8, 2026).

People Moves

Privacy, Cybersecurity and AI Partner Joins McDermott in Brussels


Elisabeth Dehareng has joined McDermott Will & Schulte in its regulatory practice group as a partner based in Brussels. She arrives from Baker McKenzie.

Dehareng advises on IT, intellectual property and new technology law, with a focus on privacy, cybersecurity and AI. She provides strategic advice on European and worldwide data protection compliance projects, and cybersecurity and data breach management. She also advises clients on the data protection and cybersecurity aspects of corporate transactions and reorganizations.

In addition, Dehareng leads complex cross-border data protection matters, and counsels clients on E.U. digital regulation, including the Digital Services Act, AI Act, Data Act, Cyber Resilience Act and NIS2 Directive. She represents clients across a range of industries, with a strong focus on technology, healthcare and financial services.

Prior to joining the firm, Dehareng was a partner at Baker McKenzie.

For insights from McDermott, see “Connected Cars: Addressing Cybersecurity Issues” (Apr. 22, 2026); and “Cookie Compliance Strategies for 2026” (Apr. 15, 2026).