Abdolmadjid Masoomi
← All topics

regulation

23 pieces

  • AI Companion Chatbot Laws: What They Require for Minors

    Disclosure, crisis protocols and age-aware design are becoming the legal baseline.

    New ai companion chatbot laws mandate disclosure, crisis intervention, and minor protections. These statutes set a legal floor for safety but do not address the engagement mechanics that drive dependency. Builders and parents must look beyond compliance to understand true risk.

    2026-09-14 · technical-essay · 10 min read

  • AI Content Labelling Rules: What Must Be Disclosed, and by Whom

    Transparency duties split between the tool that generates and the person who publishes.

    ai content labeling requirements split responsibility between providers and publishers. Generators must embed machine-readable signals, while deployers must provide visible disclosures. Effective compliance treats labelling and provenance as a single pipeline rather than separate checkboxes.

    2026-09-14 · technical-essay · 9 min read

  • AI in Hiring: Your Rights When an Algorithm Screens You

    Candidates have more room to ask questions than they think, and less than they deserve.

    Automated screening shapes who reaches a human recruiter, yet candidates rarely know it was used or how to challenge it. Understanding ai in hiring rights allows applicants to request data and accommodation, while employers remain liable under anti-discrimination law regardless of vendor claims.

    2026-09-14 · technical-essay · 8 min read

  • AI Meeting Note-Takers: Who Consented to the Recording?

    A bot invited by one participant records everyone, and the transcript lives on after the call.

    AI note taker consent is often assumed rather than obtained, creating legal and ethical risks. One participant’s invitation does not grant permission to record others. This analysis examines the collision between automated transcription and privacy norms.

    2026-09-14 · technical-essay · 7 min read

  • An Incident Response Plan That Fits on One Page

    Plans fail on who decides and who to call, not on the technical steps.

    Most incident response plan template documents gather dust because they prioritise procedure over authority. A one-page sheet that names the decision-maker and external contacts prevents delays when systems are down. This approach minimises confusion and ensures evidence is preserved before cleanup begins.

    2026-09-14 · technical-essay · 7 min read

  • Cyber Incident Reporting Deadlines: Several Clocks, One Incident

    A single breach can trigger 24-hour, 72-hour and materiality-based deadlines to different regulators.

    Organisations often anchor on the GDPR 72-hour window and miss earlier triggers. Mapping the specific events that start each clock matters more than memorising durations. Clear cyber incident reporting requirements prevent regulatory penalties and reputational damage.

    2026-09-14 · technical-essay · 9 min read

  • Deepfakes in Elections: The Bigger Risk Is Disbelieving the Real

    Synthetic clips matter, but the lasting damage is a public that can wave away any genuine recording.

    The threat of deepfakes in elections extends beyond fabricated media persuading voters. The greater danger is the erosion of evidentiary trust, allowing real misconduct to be dismissed as synthetic. We must prioritise provenance for authentic content and robust verification norms to preserve democratic integrity.

    2026-09-14 · technical-essay · 9 min read

  • Digital Replicas and Consent: Who Controls Your Voice and Face?

    A one-time release signed for a job can become permission to generate you forever.

    The law struggles to keep pace with generative models that can reproduce identity indefinitely. Meaningful digital replica consent must be specific, limited, and revocable. We must distinguish between a recording and a living model of a person.

    2026-09-14 · technical-essay · 8 min read

  • EU AI Act Explained: What Applies to Whom

    The Act regulates uses more than models, so classification of your use case comes first.

    The eu ai act explained reveals a common misunderstanding: the law targets applications, not just algorithms. Organisations must classify their role and use case before assessing compliance, as obligations differ sharply between providers and deployers.

    2026-09-14 · technical-essay · 9 min read

  • Fake Citations: How AI Hallucinations Reach Courts and Journals

    The failure is not the model inventing sources; it is institutions that never check references.

    Invented citations persist in legal and academic work because they appear checkable, so no one checks them. The solution is mechanical verification at submission, not exhortation. This essay examines how ai hallucination fake citations bypass institutional safeguards and what systems can catch them.

    2026-09-14 · technical-essay · 9 min read

  • Health Data Outside HIPAA: What Your Apps Are Allowed to Share

    Most people assume medical privacy law follows health data; it mostly follows the doctor.

    HIPAA binds providers, insurers and their contractors, so the same heart-rate or cycle data is protected in a clinic record and largely unprotected in a consumer app. Understanding which laws actually apply to apps tells people what to ask before they log symptoms.

    2026-09-14 · technical-essay · 8 min read

  • How to Get a Deepfake Image Removed Under the Take It Down Act

    The 48-hour removal duty is a real lever, but it works best when the request is prepared like evidence.

    Victims of synthetic media abuse now have a statutory clock to demand removal. A take it down act removal request forces platforms to act quickly, but success depends on precise documentation and understanding the legal boundaries of the duty.

    2026-09-14 · technical-essay · 8 min read

  • Internet-Exposed PLCs: Why Small Utilities Keep Getting Hit

    Attacks on water systems exploit defaults and exposure, not sophistication.

    Intrusions into small utilities generally rely on controllers reachable from the internet with default or shared credentials. This makes them a funding and ownership problem more than a technical mystery. The protective moves are known and cheap relative to the harm.

    2026-09-14 · technical-essay · 8 min read

  • Is AI Training Fair Use? The Questions Courts Actually Ask

    The legal fight is turning on how data was obtained and whether outputs substitute for originals.

    The debate on whether is ai training fair use misses the point. Courts examine data provenance and market harm. Clean datasets are now legal assets.

    2026-09-14 · technical-essay · 8 min read

  • School Apps and Student Data: Questions Parents Can Ask

    Schools adopt dozens of platforms a year; parents can ask five questions that reveal the risk.

    Educational technology is often approved one tool at a time, leaving no one to track the combined data footprint of a child. Parents do not need legal expertise to engage; asking what is collected, who processes it, and how it is deleted surfaces most problems in student data privacy.

    2026-09-14 · technical-essay · 8 min read

  • Should Open-Weight AI Models Be Regulated?

    Weights cannot be recalled once published, which forces regulation to look somewhere else.

    Open weight ai regulation requires a shift from post-deployment control to pre-release scrutiny. Once parameters are public, recall is impossible and monitoring is ineffective. Policy must therefore target the release process and specific downstream applications rather than the model files themselves.

    2026-09-14 · technical-essay · 8 min read

  • Should You Pay a Ransomware Demand? The Case Against Certainty

    Payment buys a promise from a counterparty with no reason to keep it.

    The question of should you pay ransomware is not an ethical dilemma but an epistemic failure. Organisations cannot verify the promises made by attackers, making payment a high-risk gamble against a counterparty with no incentive to honour it. Decisions made under duress lack the evidence required for sound judgement.

    2026-09-14 · technical-essay · 8 min read

  • The Energy and Water Cost of AI: What Is Known and What Is Not

    Per-prompt numbers are real but narrow; the footprint that matters is set by training, siting and model choice.

    Public figures for the cost of a single AI prompt disagree because they measure different boundaries. Individual use is a small share of the total, so the choices that move the footprint are model size and siting. Understanding ai energy and water use requires looking beyond the query to the infrastructure.

    2026-09-14 · technical-essay · 8 min read

  • US State AI Laws: Why the Patchwork Keeps Rewriting Itself

    States are retreating from broad frameworks toward narrow rules on chatbots, deepfakes and decisions.

    The initial wave of broad state ai laws has been narrowed or rewritten. States now prefer targeted rules on specific harms. Organisations must map obligations by use case rather than waiting for a single federal framework.

    2026-09-14 · technical-essay · 7 min read

  • When Ransomware Hits a Hospital, It Is a Patient Safety Event

    Treating a hospital cyberattack as an IT outage underprepares the clinicians who carry it.

    Hospital ransomware patient safety risks are often obscured by technical recovery timelines. Clinicians face immediate care degradation when digital systems fail. This essay argues that cyber incidents must be managed as clinical emergencies, not just IT outages.

    2026-09-14 · technical-essay · 8 min read

  • Who Is Liable When AI Gets It Wrong?

    Blaming the model rarely works; responsibility tends to land on whoever deployed it to the public.

    Organisations often assume disclaimers shift responsibility for AI errors. Existing doctrines generally attach to the party that put the system in front of customers. Deployers should budget for errors rather than disclaim them. Understanding who is liable for ai mistakes requires looking at deployment, not just development.

    2026-09-14 · technical-essay · 7 min read

  • Who Owns AI-Generated Content? Copyright and Human Authorship

    Prompts alone rarely make you an author; what you select, arrange and change can.

    The question of who owns ai generated content hinges on human authorship. Prompts rarely confer copyright. Protection follows human selection, arrangement and modification. Documenting this contribution is essential for defensible rights.

    2026-09-14 · technical-essay · 8 min read

  • Your AI Chat History Is a Record: Courts, Breaches and Reviewers

    The bigger privacy risk is not training; it is logs that can be produced, reviewed or leaked.

    Most people assume the greatest risk of using AI is model training, but the real danger lies in retained chat logs. These records behave like email: they are discoverable in litigation, subject to preservation orders, and exposed in breaches. Understanding whether are ai chats private requires looking beyond training data to how organisations store and process your inputs.

    2026-09-14 · technical-essay · 8 min read