<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>licens.io Blog</title><description>AI governance, technology due diligence, compliance, and data strategy insights.</description><link>https://licens.io/</link><item><title>Delve and the 494 Fake SOC 2 Reports: What the Compliance Industry Should Learn</title><link>https://licens.io/blog/delve-fake-compliance-soc2-fraud/</link><guid isPermaLink="true">https://licens.io/blog/delve-fake-compliance-soc2-fraud/</guid><description>A Y Combinator-backed compliance startup allegedly fabricated 494 SOC 2 reports with auditor conclusions pre-written before clients submitted any evidence.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>Five Supply Chain Attacks in Twelve Days: March 2026 Broke Open Source Trust</title><link>https://licens.io/blog/march-2026-supply-chain-attacks/</link><guid isPermaLink="true">https://licens.io/blog/march-2026-supply-chain-attacks/</guid><description>In twelve days, attackers compromised Trivy, Checkmarx, LiteLLM, Telnyx, and Axios — and the supply chain security model most organizations rely on did not survive.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>SCOTUS Settles It: No Copyright Without a Human Author</title><link>https://licens.io/blog/scotus-no-copyright-without-human-author/</link><guid isPermaLink="true">https://licens.io/blog/scotus-no-copyright-without-human-author/</guid><description>The Supreme Court’s denial in Thaler v. Perlmutter leaves one rule standing: if no human authorship exists, there is no copyright.</description><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Jillian Bommarito</author></item><item><title>Anthropic at $380B: What a 6x Valuation Jump in 12 Months Tells Us About AI Markets</title><link>https://licens.io/blog/anthropic-380b-valuation-6x-in-12-months/</link><guid isPermaLink="true">https://licens.io/blog/anthropic-380b-valuation-6x-in-12-months/</guid><description>Anthropic’s move to a $380 billion valuation is more than a headline-grabbing fundraise; it is a useful stress test for how AI markets are pricing growth, scarcity, and risk.</description><pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Music Industry Sues Anthropic for $3.1B: AI Training Liability Keeps Growing</title><link>https://licens.io/blog/music-industry-sues-anthropic-3-1-billion/</link><guid isPermaLink="true">https://licens.io/blog/music-industry-sues-anthropic-3-1-billion/</guid><description>Universal Music, Concord, and ABKCO just turned Anthropic’s training-data problem into a $3.1 billion copyright fight.</description><pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Jillian Bommarito</author></item><item><title>Three More States, Three More Privacy Laws: 2026 Compliance Starts Now</title><link>https://licens.io/blog/three-more-state-privacy-laws-2026/</link><guid isPermaLink="true">https://licens.io/blog/three-more-state-privacy-laws-2026/</guid><description>Indiana, Kentucky, and Rhode Island all went live on January 1, 2026, which means privacy compliance just got a little less optional.</description><pubDate>Sat, 03 Jan 2026 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>Federal Preemption of State AI Laws: Trump&apos;s December EO and Its Legal Limits</title><link>https://licens.io/blog/trump-ai-eo-preempt-state-laws/</link><guid isPermaLink="true">https://licens.io/blog/trump-ai-eo-preempt-state-laws/</guid><description>Trump’s December 11 AI order launches a federal challenge to state AI laws, but its legal reach is narrower than the rhetoric suggests.</description><pubDate>Sat, 13 Dec 2025 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>SFC v. Vizio: A Court Says GPL Compliance Is a Contractual Duty</title><link>https://licens.io/blog/sfc-v-vizio-gpl-contractual-duty/</link><guid isPermaLink="true">https://licens.io/blog/sfc-v-vizio-gpl-contractual-duty/</guid><description>A December 4, 2025 tentative ruling in SFC v. Vizio suggests GPL compliance can sound in contract, not just copyright, with real consequences for end users.</description><pubDate>Sat, 06 Dec 2025 00:00:00 GMT</pubDate><category>Engineering</category><author>Michael Bommarito</author></item><item><title>CycloneDX 1.7: Patents, Provenance, and the Next Generation of SBOMs</title><link>https://licens.io/blog/cyclonedx-1-7-patents-provenance-sboms/</link><guid isPermaLink="true">https://licens.io/blog/cyclonedx-1-7-patents-provenance-sboms/</guid><description>CycloneDX 1.7 turns SBOMs from static inventories into richer evidence packs with patent metadata, citations, and better cryptographic transparency.</description><pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>FASB Rewrites Software Cost Accounting: ASU 2025-06 and What CFOs Need to Know</title><link>https://licens.io/blog/fasb-asu-2025-06-software-cost-accounting/</link><guid isPermaLink="true">https://licens.io/blog/fasb-asu-2025-06-software-cost-accounting/</guid><description>FASB’s ASU 2025-06 replaces the old stage-based software capitalization playbook with a single recognition test, forcing CFOs to rethink policy, controls, and valuation.</description><pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Jillian Bommarito</author></item><item><title>Anthropic&apos;s $1.5B Copyright Settlement: What It Means for AI Training Economics</title><link>https://licens.io/blog/anthropic-1-5-billion-copyright-settlement/</link><guid isPermaLink="true">https://licens.io/blog/anthropic-1-5-billion-copyright-settlement/</guid><description>Anthropic&apos;s $1.5 billion settlement shows that copyright risk in AI training data is no longer theoretical; it is a balance-sheet item.</description><pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Jillian Bommarito</author></item><item><title>EU AI Act Phase 2: GPAI Provider Obligations Are Now Enforceable</title><link>https://licens.io/blog/eu-ai-act-gpai-obligations-enforceable/</link><guid isPermaLink="true">https://licens.io/blog/eu-ai-act-gpai-obligations-enforceable/</guid><description>As of August 2, 2025, general-purpose AI model providers are no longer waiting on guidance: the EU AI Act’s GPAI obligations are live.</description><pubDate>Mon, 04 Aug 2025 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>Meta&apos;s $14B Scale AI Deal: The Biggest AI Acqui-Hire in History</title><link>https://licens.io/blog/meta-14b-scale-ai-biggest-acqui-hire/</link><guid isPermaLink="true">https://licens.io/blog/meta-14b-scale-ai-biggest-acqui-hire/</guid><description>Meta’s $14.3 billion Scale AI transaction is a minority-stake deal that looks a lot like an acqui-hire, with major implications for AI valuation and control.</description><pubDate>Thu, 12 Jun 2025 00:00:00 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Copyright Office Part 3: AI Training on Copyrighted Works Is Not Clearly Fair Use</title><link>https://licens.io/blog/copyright-office-ai-training-not-fair-use/</link><guid isPermaLink="true">https://licens.io/blog/copyright-office-ai-training-not-fair-use/</guid><description>The Copyright Office’s Part 3 AI report makes one thing plain: training on copyrighted works is not automatically fair use, so provenance and licensing matter now.</description><pubDate>Sun, 11 May 2025 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Jillian Bommarito</author></item><item><title>NYT v. OpenAI Survives Dismissal: The Copyright Case Moves Forward</title><link>https://licens.io/blog/nyt-v-openai-survives-dismissal/</link><guid isPermaLink="true">https://licens.io/blog/nyt-v-openai-survives-dismissal/</guid><description>A federal judge lets the core NYT copyright claims against OpenAI proceed, reinforcing why every AI company needs a real training data provenance strategy.</description><pubDate>Sun, 06 Apr 2025 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Jillian Bommarito</author></item><item><title>Google Buys Wiz for $32B: The Largest Cybersecurity Acquisition in History</title><link>https://licens.io/blog/google-buys-wiz-32-billion/</link><guid isPermaLink="true">https://licens.io/blog/google-buys-wiz-32-billion/</guid><description>Google’s $32 billion agreement to acquire Wiz is a landmark cybersecurity deal, and it says plenty about cloud security, antitrust risk, and valuation discipline.</description><pubDate>Thu, 20 Mar 2025 00:00:00 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>GitHub Actions Compromised: The tj-actions Supply Chain Attack</title><link>https://licens.io/blog/github-actions-tj-actions-supply-chain/</link><guid isPermaLink="true">https://licens.io/blog/github-actions-tj-actions-supply-chain/</guid><description>A compromised GitHub Action turned a routine changed-files step into a supply chain wake-up call for every CI/CD pipeline.</description><pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>First Court Rejects AI Fair Use: What Thomson Reuters v. ROSS Means for AI Companies</title><link>https://licens.io/blog/thomson-reuters-v-ross-ai-fair-use/</link><guid isPermaLink="true">https://licens.io/blog/thomson-reuters-v-ross-ai-fair-use/</guid><description>On February 11, 2025, Judge Bibas rules that using Westlaw headnotes to train a competing legal AI tool is not fair use.</description><pubDate>Thu, 13 Feb 2025 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Jillian Bommarito</author></item><item><title>EU AI Act Phase 1 Is Live: Prohibited AI Practices You Need to Stop Today</title><link>https://licens.io/blog/eu-ai-act-prohibited-practices-live/</link><guid isPermaLink="true">https://licens.io/blog/eu-ai-act-prohibited-practices-live/</guid><description>The EU AI Act’s Article 5 bans are now live, and teams need to stop any prohibited AI practice before regulators do.</description><pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>Trump Rescinds the Biden AI Executive Order: What It Means for Your Compliance Program</title><link>https://licens.io/blog/trump-rescinds-biden-ai-executive-order/</link><guid isPermaLink="true">https://licens.io/blog/trump-rescinds-biden-ai-executive-order/</guid><description>President Trump’s rescission of Executive Order 14110 changes the federal AI posture, but it does not change your underlying compliance obligations.</description><pubDate>Wed, 22 Jan 2025 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>Five New State Privacy Laws Take Effect Today: Your 2025 Compliance Checklist</title><link>https://licens.io/blog/five-state-privacy-laws-2025-compliance/</link><guid isPermaLink="true">https://licens.io/blog/five-state-privacy-laws-2025-compliance/</guid><description>Delaware, Iowa, Nebraska, New Hampshire, and New Jersey are forcing privacy programs to grow up fast, and the safest response is a clean, repeatable checklist.</description><pubDate>Thu, 02 Jan 2025 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>The EU Cyber Resilience Act Enters Into Force: SBOM Mandates for All Digital Products</title><link>https://licens.io/blog/eu-cyber-resilience-act-enters-force/</link><guid isPermaLink="true">https://licens.io/blog/eu-cyber-resilience-act-enters-force/</guid><description>The EU Cyber Resilience Act is now in force, turning SBOMs, vulnerability reporting, and support-period planning into baseline product discipline.</description><pubDate>Thu, 12 Dec 2024 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>OSI Releases the Open Source AI Definition: Most &apos;Open&apos; AI Models Don&apos;t Qualify</title><link>https://licens.io/blog/osi-open-source-ai-definition/</link><guid isPermaLink="true">https://licens.io/blog/osi-open-source-ai-definition/</guid><description>OSI&apos;s Open Source AI Definition makes clear that most &apos;open&apos; AI models are really open weights, not open source.</description><pubDate>Wed, 30 Oct 2024 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Michael Bommarito</author></item><item><title>FTC Launches Operation AI Comply: Five Companies Charged with AI Washing</title><link>https://licens.io/blog/ftc-operation-ai-comply-ai-washing/</link><guid isPermaLink="true">https://licens.io/blog/ftc-operation-ai-comply-ai-washing/</guid><description>The FTC&apos;s Operation AI Comply shows that AI hype without evidence is now an enforcement problem, not a marketing strategy.</description><pubDate>Thu, 26 Sep 2024 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>The Fed Cuts 50 Basis Points: What It Means for Tech Valuations and M&amp;A</title><link>https://licens.io/blog/fed-cuts-50-bps-tech-valuations/</link><guid isPermaLink="true">https://licens.io/blog/fed-cuts-50-bps-tech-valuations/</guid><description>The Fed&apos;s first rate cut since 2020 changes the math for tech valuations, 409As, and M&amp;A, but not always in the way founders expect.</description><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>The EU AI Act Is Now in Force: Your Timeline Starts Today</title><link>https://licens.io/blog/eu-ai-act-enters-into-force/</link><guid isPermaLink="true">https://licens.io/blog/eu-ai-act-enters-into-force/</guid><description>The EU AI Act is now in force, and the first real deadlines - especially the six-month ban on prohibited practices - are already ticking.</description><pubDate>Fri, 02 Aug 2024 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>The CrowdStrike Outage: When Your Security Tool Becomes the Incident</title><link>https://licens.io/blog/crowdstrike-outage-security-tool-incident/</link><guid isPermaLink="true">https://licens.io/blog/crowdstrike-outage-security-tool-incident/</guid><description>A faulty CrowdStrike update is a reminder that vendor risk is not a footnote; it can become your outage, your grounding order, and your recovery plan.</description><pubDate>Sun, 21 Jul 2024 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>The Polyfill.io Attack: When Your CDN Turns Against You</title><link>https://licens.io/blog/polyfill-io-supply-chain-attack/</link><guid isPermaLink="true">https://licens.io/blog/polyfill-io-supply-chain-attack/</guid><description>The Polyfill.io incident is a reminder that one trusted script tag can become a supply chain liability overnight.</description><pubDate>Thu, 27 Jun 2024 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>Colorado SB 205: The First US State Law Targeting AI Discrimination</title><link>https://licens.io/blog/colorado-sb-205-ai-discrimination-law/</link><guid isPermaLink="true">https://licens.io/blog/colorado-sb-205-ai-discrimination-law/</guid><description>Colorado SB 205 is the first state law squarely targeting AI discrimination in consequential decisions, and it rewrites the compliance playbook for people-facing AI.</description><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>Redis Goes Source-Available: Valkey Fork Launches Within 30 Days</title><link>https://licens.io/blog/redis-source-available-valkey-fork/</link><guid isPermaLink="true">https://licens.io/blog/redis-source-available-valkey-fork/</guid><description>Redis&apos;s March 2024 license change triggered a rapid Valkey fork, reminding buyers that open-source governance can become a real diligence issue overnight.</description><pubDate>Thu, 25 Apr 2024 00:00:00 GMT</pubDate><category>Engineering</category><author>Michael Bommarito</author></item><item><title>GPT-4 Passes the Bar Exam — Published in the Royal Society</title><link>https://licens.io/blog/gpt4-passes-bar-exam-royal-society/</link><guid isPermaLink="true">https://licens.io/blog/gpt4-passes-bar-exam-royal-society/</guid><description>Our paper in the Royal Society shows why benchmark design matters as much as model size when AI starts testing the boundaries of legal work.</description><pubDate>Wed, 17 Apr 2024 00:00:00 GMT</pubDate><category>Research</category><author>Michael Bommarito</author></item><item><title>The xz-utils Backdoor: The Most Sophisticated Supply Chain Attack We&apos;ve Ever Seen</title><link>https://licens.io/blog/xz-utils-backdoor-supply-chain-attack/</link><guid isPermaLink="true">https://licens.io/blog/xz-utils-backdoor-supply-chain-attack/</guid><description>A hidden backdoor in xz-utils shows how a patient supply chain attack can turn a routine dependency into a pre-authentication SSH risk.</description><pubDate>Sun, 31 Mar 2024 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>EU AI Act Formally Adopted: The Countdown to Compliance Begins</title><link>https://licens.io/blog/eu-ai-act-formally-adopted/</link><guid isPermaLink="true">https://licens.io/blog/eu-ai-act-formally-adopted/</guid><description>The EU AI Act is adopted, and the compliance clock starts ticking for AI providers, deployers, and their vendors.</description><pubDate>Mon, 11 Mar 2024 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>Change Healthcare: $22B Company Brought Down by Missing MFA</title><link>https://licens.io/blog/change-healthcare-ransomware-missing-mfa/</link><guid isPermaLink="true">https://licens.io/blog/change-healthcare-ransomware-missing-mfa/</guid><description>Change Healthcare’s ransomware outage is a blunt reminder that one internet-facing portal without MFA can jam the pipes of U.S. healthcare.</description><pubDate>Fri, 23 Feb 2024 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>KL3M: The First Fairly Trained Large Language Model</title><link>https://licens.io/blog/kl3m-first-fairly-trained-llm/</link><guid isPermaLink="true">https://licens.io/blog/kl3m-first-fairly-trained-llm/</guid><description>KL3M shows that large language models can be built on copyright-clean training data, with provenance that enterprises can actually defend.</description><pubDate>Thu, 08 Feb 2024 00:00:00 GMT</pubDate><category>Research</category><author>Michael Bommarito</author></item><item><title>CISA and FBI Call for Memory Safety Roadmaps: Is C++ on Borrowed Time?</title><link>https://licens.io/blog/cisa-fbi-memory-safety-roadmaps/</link><guid isPermaLink="true">https://licens.io/blog/cisa-fbi-memory-safety-roadmaps/</guid><description>CISA and the FBI are turning memory safety from an engineering preference into a board-level issue, and C/C++ is suddenly on the defensive.</description><pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate><category>Engineering</category><author>Michael Bommarito</author></item><item><title>The New York Times Sues OpenAI: The Copyright Case That Could Define AI Training</title><link>https://licens.io/blog/nyt-sues-openai-copyright-ai-training/</link><guid isPermaLink="true">https://licens.io/blog/nyt-sues-openai-copyright-ai-training/</guid><description>The New York Times&apos; lawsuit against OpenAI and Microsoft turns AI training data provenance, fair use, and output risk into a very expensive conversation.</description><pubDate>Thu, 28 Dec 2023 00:00:00 GMT</pubDate><category>Data Strategy</category><author>Michael Bommarito</author></item><item><title>EU AI Act Trilogue Complete: The Final Text and What It Means</title><link>https://licens.io/blog/eu-ai-act-trilogue-final-text/</link><guid isPermaLink="true">https://licens.io/blog/eu-ai-act-trilogue-final-text/</guid><description>The EU institutions have reached political agreement on the AI Act, and the first comprehensive AI law in the world is now moving from theory to enforcement.</description><pubDate>Mon, 11 Dec 2023 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>The Bletchley Declaration: 28 Nations Agree on AI Safety (But Not on How)</title><link>https://licens.io/blog/bletchley-declaration-global-ai-safety/</link><guid isPermaLink="true">https://licens.io/blog/bletchley-declaration-global-ai-safety/</guid><description>The Bletchley Declaration is a real signal that AI safety has gone global, but the hard part is still turning shared concern into enforceable rules.</description><pubDate>Fri, 03 Nov 2023 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>Biden&apos;s AI Executive Order: The Most Comprehensive Federal AI Action to Date</title><link>https://licens.io/blog/biden-ai-executive-order-14110/</link><guid isPermaLink="true">https://licens.io/blog/biden-ai-executive-order-14110/</guid><description>Executive Order 14110 turns AI policy into a real compliance agenda, with federal demands on safety testing, watermarking, privacy, and civil rights.</description><pubDate>Tue, 31 Oct 2023 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>MGM Resorts Hacked: Social Engineering Still Beats Technical Controls</title><link>https://licens.io/blog/mgm-resorts-social-engineering-hack/</link><guid isPermaLink="true">https://licens.io/blog/mgm-resorts-social-engineering-hack/</guid><description>MGM Resorts’ September 2023 cyber incident is a reminder that the easiest path into a hardened environment is often a human with a phone and a reset button.</description><pubDate>Fri, 01 Sep 2023 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>HashiCorp Goes BSL: What the Terraform License Change Means for Your Infrastructure</title><link>https://licens.io/blog/hashicorp-bsl-terraform-license-change/</link><guid isPermaLink="true">https://licens.io/blog/hashicorp-bsl-terraform-license-change/</guid><description>HashiCorp&apos;s move to BSL 1.1 for Terraform and other core products changes the rules for vendors, integrators, and anyone packaging infrastructure tooling commercially.</description><pubDate>Mon, 14 Aug 2023 00:00:00 GMT</pubDate><category>Engineering</category><author>Michael Bommarito</author></item><item><title>SEC Adopts Cybersecurity Disclosure Rules: 4-Day Incident Reporting Begins</title><link>https://licens.io/blog/sec-cybersecurity-disclosure-rules/</link><guid isPermaLink="true">https://licens.io/blog/sec-cybersecurity-disclosure-rules/</guid><description>The SEC&apos;s new cyber rules turn incident response into a filing deadline problem, and the 4-business-day clock starts at materiality.</description><pubDate>Fri, 14 Jul 2023 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>The EU AI Act Passes Parliament: What US Companies Should Start Preparing Now</title><link>https://licens.io/blog/eu-ai-act-passes-parliament/</link><guid isPermaLink="true">https://licens.io/blog/eu-ai-act-passes-parliament/</guid><description>The European Parliament&apos;s June 14 vote signals that AI governance is moving from theory to enforcement, and U.S. companies need to get their house in order now.</description><pubDate>Fri, 16 Jun 2023 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>Meta&apos;s EUR 1.2 Billion Fine: The End of Unchecked Transatlantic Data Flows</title><link>https://licens.io/blog/meta-1-2-billion-euro-gdpr-fine/</link><guid isPermaLink="true">https://licens.io/blog/meta-1-2-billion-euro-gdpr-fine/</guid><description>The Irish DPC&apos;s record fine against Meta is a reminder that cross-border data flows need more than SCCs, more than supplementary measures, and definitely more than hope.</description><pubDate>Mon, 15 May 2023 00:00:00 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>The Samsung ChatGPT Leak: Why Every Company Needs an AI Acceptable Use Policy</title><link>https://licens.io/blog/samsung-chatgpt-leak-ai-acceptable-use-policy/</link><guid isPermaLink="true">https://licens.io/blog/samsung-chatgpt-leak-ai-acceptable-use-policy/</guid><description>Samsung’s ChatGPT leak is a blunt reminder that without an AI acceptable use policy, employees will paste confidential data into whatever tool seems helpful.</description><pubDate>Fri, 07 Apr 2023 00:00:00 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>VC Valuation Methods</title><link>https://licens.io/blog/vc-valuation-methods/</link><guid isPermaLink="true">https://licens.io/blog/vc-valuation-methods/</guid><description>The methods behind valuations used in venture capital are a breed unlike the [operational valuations](/blog/valuation-101/) we’ve discussed in our prior posts.</description><pubDate>Wed, 14 Dec 2022 13:41:29 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>409A Valuations</title><link>https://licens.io/blog/409a-valuation/</link><guid isPermaLink="true">https://licens.io/blog/409a-valuation/</guid><description>It’s not often that you can reference a specific section of the Internal Revenue Code by number and have a wide audience understand what it refers to; Section 409A is a member of this elite club (like.</description><pubDate>Mon, 12 Dec 2022 16:51:15 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Valuation for Financial Reporting</title><link>https://licens.io/blog/valuation-for-financial-reporting/</link><guid isPermaLink="true">https://licens.io/blog/valuation-for-financial-reporting/</guid><description>Perhaps you read our [Valuation 101](/blog/valuation-101/) intro post and thought to yourself “wow, I wish they had talked even more about valuation under GAAP!” If so, today is.</description><pubDate>Thu, 25 Aug 2022 16:29:13 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Valuation 101</title><link>https://licens.io/blog/valuation-101/</link><guid isPermaLink="true">https://licens.io/blog/valuation-101/</guid><description>In theory, a valuation is simply the estimated worth of an asset, liability, or company.</description><pubDate>Tue, 23 Aug 2022 14:37:22 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Fundraising 101: Preferred Shares</title><link>https://licens.io/blog/fundraising-101-preferred-shares/</link><guid isPermaLink="true">https://licens.io/blog/fundraising-101-preferred-shares/</guid><description>**Today’s post is brought to you by one of our fabulous interns – Ann Zhang.**.</description><pubDate>Thu, 14 Jul 2022 13:27:16 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Securing Debt with Intangible Assets</title><link>https://licens.io/blog/securing-debt-with-intangible-assets/</link><guid isPermaLink="true">https://licens.io/blog/securing-debt-with-intangible-assets/</guid><description>In early-stage companies, debt financing is often only used in the specific context of convertible loans.</description><pubDate>Wed, 01 Jun 2022 22:18:46 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Fundraising 101: Debt vs. Equity</title><link>https://licens.io/blog/fundraising-101-debt-vs-equity/</link><guid isPermaLink="true">https://licens.io/blog/fundraising-101-debt-vs-equity/</guid><description>Within finance, capital refers to the corporate securities that have been issued.</description><pubDate>Mon, 23 May 2022 13:46:56 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Why You Need a Privacy Pro on Your Advisory Board</title><link>https://licens.io/blog/why-you-need-a-privacy-pro-on-your-advisory-board/</link><guid isPermaLink="true">https://licens.io/blog/why-you-need-a-privacy-pro-on-your-advisory-board/</guid><description>There are many “strategies” when it comes to drafting an advisory board for startups.</description><pubDate>Fri, 29 Apr 2022 11:58:48 GMT</pubDate><category>Privacy &amp; Security</category><author>Jillian Bommarito</author></item><item><title>Shift Left for Data: Data Processing Agreements and Data Bills of Material</title><link>https://licens.io/blog/shift-left-for-data/</link><guid isPermaLink="true">https://licens.io/blog/shift-left-for-data/</guid><description>It’s hard to make it very far these days without hearing the phrase “Shift Left.” While some argue that Shift Left is just following CMMI and PMBOK practices, it’s clear that the DevOps and DevSecOps .</description><pubDate>Tue, 26 Apr 2022 22:55:55 GMT</pubDate><category>Data Strategy</category><author>Jillian Bommarito</author></item><item><title>Software Escrow is Dead; Long Live AI Escrow!</title><link>https://licens.io/blog/software-escrow-is-dead-long-live-ai-escrow/</link><guid isPermaLink="true">https://licens.io/blog/software-escrow-is-dead-long-live-ai-escrow/</guid><description>Through time immemorial, attorneys negotiating technology deals have recommended that software licensees push for escrow of source code.</description><pubDate>Tue, 19 Apr 2022 07:54:08 GMT</pubDate><category>AI Governance</category><author>Michael Bommarito</author></item><item><title>Why You Really Need a Data BOM, Not a Software BOM</title><link>https://licens.io/blog/why-you-really-need-a-data-bom/</link><guid isPermaLink="true">https://licens.io/blog/why-you-really-need-a-data-bom/</guid><description>The [**Bill of Materials (BOM)** concept has taken over the world of software](sbom), but should most organizations be focused on **Data Bills of Material (DBOM)** instead?.</description><pubDate>Mon, 18 Apr 2022 07:59:19 GMT</pubDate><category>Data Strategy</category><author>Michael Bommarito</author></item><item><title>Strategic Acquisition + Tech Assets: the Good, the Bad, and the Underlying</title><link>https://licens.io/blog/strategic-acquisition-tech-assets/</link><guid isPermaLink="true">https://licens.io/blog/strategic-acquisition-tech-assets/</guid><description>When it comes to strategic acquisitions, few opportunities can present as much promise or peril as tech assets.</description><pubDate>Sat, 16 Apr 2022 16:32:13 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Four Reasons Why SCA Isn&amp;#8217;t Solving Your Supply Chain Security Issues</title><link>https://licens.io/blog/sca-supply-chain-issues/</link><guid isPermaLink="true">https://licens.io/blog/sca-supply-chain-issues/</guid><description>Both types of SCA – [software composition analysis](/blog/software-composition-analysis-limitations/) and static code analysis – can play a crucial role in identifying and remed.</description><pubDate>Tue, 05 Apr 2022 10:18:37 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>What is Software Composition Analysis and What Are the Limitations?</title><link>https://licens.io/blog/software-composition-analysis-limitations/</link><guid isPermaLink="true">https://licens.io/blog/software-composition-analysis-limitations/</guid><description>Software Composition Analysis (SCA – yes…*another* SCA) is a type of analysis designed to identify and document software components.</description><pubDate>Tue, 05 Apr 2022 10:00:23 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>Licens.io CEO Among First Global Independent AI Auditors</title><link>https://licens.io/blog/licensio-ceo-among-first-global-independent-ai-auditors/</link><guid isPermaLink="true">https://licens.io/blog/licensio-ceo-among-first-global-independent-ai-auditors/</guid><description>**MICHIGAN, APRIL 1, 2021** – At Licens.io, interdisciplinary experience and cross-disciplinary collaboration are fundamental values.</description><pubDate>Fri, 01 Apr 2022 10:00:50 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>SBOMs: the Premise, the Promise, the Peril</title><link>https://licens.io/blog/sboms-the-premise-the-promise-the-peril/</link><guid isPermaLink="true">https://licens.io/blog/sboms-the-premise-the-promise-the-peril/</guid><description>Are software bills of material (SBOM) the solution to your software woes? While there are opinions on both sides, the White House has begun to promote their use.</description><pubDate>Wed, 30 Mar 2022 22:39:56 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>How Data Provenance Drives Machine Learning Risk + Value</title><link>https://licens.io/blog/data-provenance-drives-machine-learning-risk-value/</link><guid isPermaLink="true">https://licens.io/blog/data-provenance-drives-machine-learning-risk-value/</guid><description>For many, provenance is a foreign term, frequently (and ironically) confused with the Provence region of France.</description><pubDate>Sat, 26 Mar 2022 13:12:56 GMT</pubDate><category>AI Governance</category><author>Michael Bommarito</author></item><item><title>AI without Compliance: A Cautionary Tale of FTC Enforcement</title><link>https://licens.io/blog/ai-without-compliance-a-cautionary-tale-of-ftc-enforcement/</link><guid isPermaLink="true">https://licens.io/blog/ai-without-compliance-a-cautionary-tale-of-ftc-enforcement/</guid><description>First, software was eating the world; now, it’s supposedly AI – or the data used to create that AI – that’s eating the world.</description><pubDate>Fri, 25 Mar 2022 20:25:56 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>The Exponentially Zero Valuation of IPython — or, Why Valuing Software is so Hard.</title><link>https://licens.io/blog/why-valuing-software-is-so-hard/</link><guid isPermaLink="true">https://licens.io/blog/why-valuing-software-is-so-hard/</guid><description>A [CPA and recovering financial engineer](/about/team/) sit down at a bar.</description><pubDate>Thu, 10 Feb 2022 12:19:41 GMT</pubDate><category>Due Diligence &amp; Valuation</category><author>Michael Bommarito</author></item><item><title>Snake JARs, Part III: Data Science Sssssss-security</title><link>https://licens.io/blog/snake-jars-part-iii-data-science-security/</link><guid isPermaLink="true">https://licens.io/blog/snake-jars-part-iii-data-science-security/</guid><description>In this series, we’ve been talking about cross-language dependencies — in particular, Python packages vendoring Java JARs.</description><pubDate>Wed, 09 Feb 2022 11:15:35 GMT</pubDate><category>Privacy &amp; Security</category><author>Michael Bommarito</author></item><item><title>Releasing our Responsible Data Science Policy Framework</title><link>https://licens.io/blog/responsible-data-science-policy-framework/</link><guid isPermaLink="true">https://licens.io/blog/responsible-data-science-policy-framework/</guid><description>[**FICO recently surveyed over 100 of the world’s largest, most sophisticated organizations**](https://www.fico.com/en/latest-thinking/analystpartner-collateral/building-ai-driven-enterprises-disrupte.</description><pubDate>Sun, 17 Oct 2021 18:23:54 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>ESG: G is for Governance</title><link>https://licens.io/blog/esg-governance/</link><guid isPermaLink="true">https://licens.io/blog/esg-governance/</guid><description>You may have noticed that regulations and standards have played a frequent role in our discussions of “E is for Environment” and “[S is for Social](htt.</description><pubDate>Mon, 27 Sep 2021 13:20:40 GMT</pubDate><category>AI Governance</category><author>Jillian Bommarito</author></item><item><title>What is Static Code Analysis?</title><link>https://licens.io/blog/what-is-static-code-analysis/</link><guid isPermaLink="true">https://licens.io/blog/what-is-static-code-analysis/</guid><description>Static code analysis (not to be confused with [software composition analysis](/blog/software-composition-analysis-limitations/), which is also abbreviated as SCA) is a critical .</description><pubDate>Thu, 01 Jul 2021 15:00:24 GMT</pubDate><category>Engineering</category><author>Michael Bommarito</author></item><item><title>What are software dependencies?</title><link>https://licens.io/blog/what-are-software-dependencies/</link><guid isPermaLink="true">https://licens.io/blog/what-are-software-dependencies/</guid><description>You wouldn’t think that a 16th century poet from England would know much about software.</description><pubDate>Sun, 13 Jun 2021 16:02:08 GMT</pubDate><category>Engineering</category><author>Michael Bommarito</author></item></channel></rss>