AI has driven massive change in three years, but governance hasn’t kept up, creating integrity and compliance gaps. Risks from hallucinations, misunderstood outputs, and democratized use are now clearer, while some organizations are cutting soaring AI costs.
CW Subscriber Only
DOJ revisions to Justice Manual address False Claims Act enforcement
The DOJ recently revised the Justice Manual to reinstate previous agency policy on how it will enforce FCA cases moving forward, and when it will seek to dismiss whistleblower actions.
Abbott to pay almost $385M in DOJ settlement over infant formula plant allegations
Abbott Laboratories will pay nearly $385 million to settle allegations, first brought by whistleblowers, that two of its infant formula plants had unsanitary conditions that did not comply with federal and state regulations, the DOJ announced.
California presses ahead with executive order for AI safeguards, cites federal government โabject failureโ
California Governor Gavin Newsom has issued an executive order to explore whether companies should develop a โkill switchโ for any potentially harmful AI tech they develop.
CFTC proposes reviving 2012 exemption for pool operators, advisors
The CFTC has proposed a rule that would codify informal registration exemptions that commodity pool operators and commodity trading advisors have been enjoying by virtue of a no-action letter issued in December.
FCA warns firms to tighten non-financial misconduct compliance after Crispin Odey’s lifetime ban upheld
The U.K. financial regulator has warned firms that it wonโt tolerate a โslapdashโ approach to ethics and non-financial misconduct.
Strange Polymarket trades, a KPMG employee, and a prediction market insider trading case
At a time when U.S. enforcement authorities and regulators are more closely scrutinizing insider trading in the prediction-markets space by public-company employees, another alleged insider-trading case is unfolding, this time concerning a KPMG employee.
Experts welcome U.K.โs approach to AI supervision in financial servicesโbut with provisos
The U.K.โs approach to regulating AI in financial services by focusing on outcomes and consumer protection, rather than introducing new rules, has been largely welcomed by expertsโso long as the current regulatory framework is regularly reviewed.
Manufacturers of EU digital products must now report cyber incidents within 24 hours
If you make or sell digital products in the EU, you must now report all exploited vulnerabilities and โsevereโ incidents that impact their security within 24 hours of becoming aware of them. These rules apply to every sector that produces products with a digital element โ from baby monitors to smart watches and apps.
Beyond the AI Hype: Whatโs Actually Working in Third-Party Risk Management
AI has produced no shortage of demos, claims, and new terminology. But after the initial wave of experimentation, TPRM teams need a more useful conversation: What is actually working?


