GRC Report Staff

APRA Warns AI Risk Controls Are Falling Behind as Financial Sector Accelerates Adoption

The Australian Prudential Regulation Authority is urging banks, insurers and superannuation trustees to move faster, and think harder, about how they govern artificial intelligence, warning that risk controls are struggling to keep pace with the technology’s rapid expansion across the financial system.

European Football Set for AML Overhaul as EU Targets Clubs & Agents

European football is heading toward one of its most significant regulatory shifts in decades, as the European Union prepares to bring professional clubs and agents into its anti-money laundering framework by July 2029. The move, driven by a sweeping reform package adopted in 2024, reflects growing concern among policymakers that the sport’s global scale, financial complexity, and opaque ownership structures make it vulnerable to illicit financial activity.

South Korea Reworks Privacy Policy Rules to Reflect the Realities of Generative AI

South Korea’s Personal Information Protection Commission is adjusting how it expects companies to explain their data practices, updating its Guidelines on Writing a Privacy Policy to better reflect how information is actually handled in an era shaped by generative AI and on-device computing.

PwC Survey Finds Decarbonization Efforts Holding Firm Despite a Year of Turbulence

A year that many sustainability leaders describe as a “storm” has done little to derail corporate decarbonization efforts, according to PwC’s third annual State of Decarbonization report, released yesterday.

CFTC Broadens Legal Fight as Wisconsin Becomes Latest Front in Prediction Markets Dispute

The Commodity Futures Trading Commission has expanded its fast-moving legal campaign against state regulators, filing a lawsuit against Wisconsin in the latest effort to assert federal control over prediction markets.

EU Finds Meta Falling Short on Child Safety as DSA Probe Intensifies

The European Commission has preliminarily concluded that Meta is failing to adequately prevent children under 13 from accessing Instagram and Facebook, raising fresh concerns about how one of the world’s largest platforms is enforcing its own age restrictions under the Digital Services Act.

Italy’s Privacy Watchdog Tells Hotels to Stop Holding Guest ID Copies

In a notice circulated to trade associations, the Italian Data Protection Authority has said that hotels, bed and breakfasts, and guesthouses must not retain photocopies or digital images of guests’ identity documents beyond the time needed to transmit required information to public security authorities. The clarification comes as the regulator reports a rise in complaints and personal data breaches in recent months.