Engineering Patent Applications

Explore top LinkedIn content from expert professionals.

  • View profile for James Patto
    James Patto James Patto is an Influencer

    🌟Your friendly neighbourhood Australian {Privacy & Data | Cyber | AI} legal professional...🌟🕷️🕸️| LinkedIn Top Voice🗣 | Speaker🎤 | Thought Leader🧠|

    4,537 followers

    🚨 𝐀𝐮𝐬𝐭𝐫𝐚𝐥𝐢𝐚𝐧 𝐀𝐈 𝐑𝐞𝐠𝐮𝐥𝐚𝐭𝐨𝐫𝐲 𝐀𝐥𝐞𝐫𝐭!🚨 Fresh news from the Federal Government’s Digital Transformation Agency (DTA)! They've just rolled out a new standard for Agencies on how to draft their AI transparency statements. So, what's the scoop? Let's break it down! 👇 🗓️ 𝐌𝐚𝐫𝐤 𝐘𝐨𝐮𝐫 𝐂𝐚𝐥𝐞𝐧𝐝𝐚𝐫𝐬 By 28 February 2025, all Agencies must make their AI adoption transparency statements public. We knew they'd have to update these statements regularly, covering: - Compliance with the AI policy - How they monitor AI effectiveness - Their efforts to shield the public from any negative impacts But this new standard gives us a lot more information on what these statements will look like. 🤔 𝐖𝐡𝐲 𝐓𝐡𝐢𝐬 𝐌𝐚𝐭𝐭𝐞𝐫𝐬 The aim here is to standardise these statements across the board, making it easier to build trust, understand the AI landscape, and compare approaches across different agencies. It’s all about transparency, baby! 🌐 📋 𝐖𝐡𝐚𝐭 𝐍𝐞𝐞𝐝𝐬 𝐭𝐨 𝐁𝐞 𝐈𝐧𝐜𝐥𝐮𝐝𝐞𝐝? The DTA demands that transparency statements are clear and in plain language – no technical jargon! This may not be an easy task when addressing AI! Here’s what the DTA wants to see in these transparency statements: 𝐈𝐧𝐭𝐞𝐧𝐭𝐢𝐨𝐧𝐬: Why the agency is using (or thinking about using) AI 𝐂𝐥𝐚𝐬𝐬𝐢𝐟𝐢𝐜𝐚𝐭𝐢𝐨𝐧: Where and how AI is being used based on the AI use classification system in the standard (think decision-making, fraud detection, law enforcement, etc.) 𝐏𝐮𝐛𝐥𝐢𝐜 𝐈𝐧𝐭𝐞𝐫𝐚𝐜𝐭𝐢𝐨𝐧: Any AI the public might interact with directly, without a human in between 𝐀𝐈 𝐀𝐬𝐬𝐮𝐫𝐚𝐧𝐜𝐞: Governance and processes to ensure AI works as intended 𝐋𝐞𝐠𝐚𝐥 𝐂𝐨𝐦𝐩𝐥𝐢𝐚𝐧𝐜𝐞: How the AI system follows all applicable laws (yes, this means a legal audit to understand what laws apply! 🕵️♂️) 𝐏𝐮𝐛𝐥𝐢𝐜 𝐏𝐫𝐨𝐭𝐞𝐜𝐭𝐢𝐨𝐧: Steps to protect people from any negative impacts 𝐏𝐨𝐥𝐢𝐜𝐲 𝐂𝐨𝐦𝐩𝐥𝐢𝐚𝐧𝐜𝐞e: Meeting all requirements under the responsible AI use policy 𝐔𝐩𝐝𝐚𝐭𝐞 𝐇𝐢𝐬𝐭𝐨𝐫𝐲: When the statement was last updated 🖥️ 𝐖𝐡𝐞𝐫𝐞 𝐭𝐨 𝐅𝐢𝐧𝐝 𝐈𝐭? These statements need to be front and centre on each Agency’s website—just like their Privacy Policies. And don’t forget, Agencies must also include a public contact email for any curious minds out there. 🔄 𝐖𝐡𝐞𝐧 𝐭𝐨 𝐔𝐩𝐝𝐚𝐭𝐞? At least once a year, but more often if there are significant changes or new factors affecting the accuracy of the statement. 🤷♂️𝐖𝐡𝐚𝐭 𝐝𝐨𝐞𝐬 𝐢𝐭 𝐚𝐥𝐥 𝐦𝐞𝐚𝐧? These new AI transparency statements are a goldmine for organisations aiming to work with the Federal Government. It helps them align with agency AI practices from day one, suggesting improvements and ensuring compliance. Plus, it could spark healthy competition among agencies, pushing everyone towards top-tier responsible AI use—a win for both the public and the agencies! 💼✨ Stay tuned! 🤖✨ #AI #ArtificialIntelligence #AIRegulation #Regulation #Policy

  • View profile for Sharat Chandra

    Driving Impact at the Intersection of Technology, Policy & Regulation

    50,206 followers

    U.S. Securities and Exchange Commission's Guidance: Crypto Asset Offerings and Registrations. •Issuers offering #securities in the crypto asset markets under the Securities Act or registering a class of securities under the Exchange Act should base their disclosures on issuer-specific facts and circumstances, focusing on common issues identified during the Division's reviews. •Issuers should consider their own facts and circumstances when preparing disclosures and provide scaled disclosure where appropriate, but should not omit information where a particular disclosure requirement is not applicable or they believe it is not responsive. •Similar disclosure items should be read together, and issuers should avoid redundant disclosure in multiple places. •For the Description of Business, SEC rules require a narrative description of the material aspects of the issuer's business, including their general development, intended business, and information material to understanding the business as a whole. •Disclosure should be tailored to the issuer's business and presented in clear, concise, and understandable language. •Specific disclosure areas for the business include current and proposed business, stage of development, public statements and promotional materials, and current or proposed business plans. •Issuers developing or acquiring a network or application should provide a narrative description of the network or application and its operation, including details about the development team, current state and timeline, milestones, objectives, technology, intellectual property, validation process, and products/services offered. •The Risk Factors section requires disclosure of the material factors that make an investment in the registrant or the offering speculative or risky, considering the unique aspects of crypto asset markets. •The Description of Securities requires a materially complete description of the securities, depending on the particular type of security . For subject crypto assets, this includes the terms, rights, and characteristics of the security in their specific context. •Key aspects of the description of securities include rights, obligations, and preferences of holders; voting rights; rights related to transactions impacting the issuer or network; transferability, term, and other characteristics EmpowerEdge Ventures

  • View profile for Alyssa Zucker

    Carbon l Sustainability

    3,449 followers

    Voluntary SB 261 Disclosures: What the CARB Docket Tells Us So Far Despite the Ninth Circuit’s injunction on SB 261 enforcement, companies have begun submitting reports voluntarily to the public docket. So what trends are we seeing so far in how companies are disclosing climate-related financial risk? 📊 The Numbers: - Total Submissions: 50+ companies have already voluntarily filed links to their disclosures since the docket opened on Dec 1, 2025. - Corporate Structure: Over 70% of filings are at the Parent/Consolidated level. These submissions typically include a formal letterhead statement listing all subsidiaries (often dozens of LLCs) covered under the single report to ensure comprehensive coverage of the $500M revenue threshold. 🏗️ Industry Leaders: The most active sectors aren't surprising—they are the ones with some of the highest physical and transition risk exposure: - Utilities & Energy: Leading the charge with the most robust technical disclosures. - Financial Services: Banks and insurers are leveraging existing TCFD frameworks. - Retail & Consumer Goods: High volume of filings from brands with significant CA footprints. 📄 Report Archetypes: What are they actually uploading? It’s not "new" CA-specific reports, but a repurposing of global frameworks: - TCFD: The dominant framework (~65% of submissions). - CDP Climate Change Questionnaires: Frequently used by private entities, many of which indicated they would replace this reference with IFRS S2 or TCFD-aligned reports, pending enforcement certainty (20% of submissions). - Distribution of Years: Most reports reference FY2023 or FY2024 data, following CARB’s guidance to use the "best available" information for this initial cycle. ⚖️ The "Injunction Statement": Nearly 40% of submitters included specific language noting that they are filing "in good faith" while the legal stay is in place. Crucially, about 1 in 5 companies explicitly stated they intend to provide supplemental or expanded disclosures once the Courts confirm the law’s legality and CARB finalizes the formal reporting format. The Takeaway: While not all companies are voluntarily submitting, the work is quietly being done in preparation, demonstrating that climate risk transparency is becoming a permanent fixture of corporate strategy and enterprise risk management. Are you filing voluntarily or waiting for the final gavel? Let’s discuss in the comments. #SB261 #ClimateRisk #CARB #ESGReporting #Workiva #Sustainability #TCFD

  • View profile for Arpit Sharma

    Leading Sustainability Upskilling Mission | End to End ESG Reporting

    42,640 followers

    🚀 New must-read for #CSRD & #ESRS practitioners I came across this article and leant a lot myself in last two days. I’m delighted to share the recent publication from EY — Illustrative Sustainability Statement for Good Bank ESRS (International) Limited — which offers a very practical walk-through of the disclosure expectations under the Corporate Sustainability Reporting Directive (CSRD) framework and the European Sustainability Reporting Standards (ESRS). For anyone building or advising on sustainability reporting, especially in the second year of ESRS application, this is a gold standard resource. Why this matters for you If you are in ESG reporting, sustainability management or governance roles, this gives a live example of how a disclosure package according to CSRD/ESRS could look — not just theory, but how someone is doing it. As someone transitioning into corporate sustainability, or advising on ESG strategy or reporting, you can use this as a benchmark to compare your organisation’s readiness or your client’s maturity. As someone building an internal roadmap (and I know you are doing, given your interest in ESG reporting, materiality, frameworks etc.), this helps convert regulatory text into a structured set of disclosure options, which helps with planning, data-collection, stakeholder engagement and assurance readiness. My take-away for next-steps Review your current materiality assessment: does it cleanly cover both financial and impact materiality? Map your disclosures against the ESRS topical standards (E, S, G) highlighted in this publication — identify gaps or where you defaulted to high-level narrative rather than quantified disclosures. Look at your sustainability statement to assess the connectivity with the financial statements: Are you showing how sustainability issues influence your business model, strategy, performance and position? Be aware of phase-in provisions and transitional reliefs: Are you collecting data now for items you may currently be exempting? Use the structure of this illustrative statement (governance → strategy → risk management → performance/disclosures) as a template for your next reporting cycle or advisory client. Link: https://lnkd.in/e5upjq8j #CSRD #ESRS #SustainabilityReporting #SustainableFinance #ESG #CorporateSustainability #Governance #ClimateAction #Materiality #DoubleMateriality #SustainabilityStrategy #ESGConsulting #ModernESG #Disclosure #SustainabilityFrameworks #GRI #SASB #IFRSS1 #IFRSS2

  • View profile for Noah G. Susskind

    Security Trust & Assurance @Wiz/Google Cloud

    4,711 followers

    Over-lawyering your firm’s vulnerability disclosure policy makes you less secure. Walter Haydock and I were chatting about something baffling. It’s almost 2025, but he still sees companies’ Terms and Conditions that say “attempting to probe, scan, or test” their tech for security vulnerabilities without authorization is prohibited. Why? Here’s our guess. Some Legal departments wouldn’t know a pentest from an nmap scan, so they’re making two mistakes. One, they’re copying each other’s boilerplate that equates running vulnerability scans, fuzzing, and other probing techniques with hacking. And two, they didn’t see the 2022 memo from the US Department of Justice. It said even accessing computer systems as part of good faith research does not violate the Computer Fraud and Abuse Act. This is not the grey area it used to be. Today, encouraging researchers to disclose security vulnerabilities on your tech is best practice. Which is why Tesla, Microsoft, and MAANG do it. Look at Apple’s OS and iOS updates. They credit researchers who helped make Apple products safer in this way. In fact, for all baselines in NIST SP 800-53, a public disclosure program is required (RA-5(11)). So it’s mandatory for any FedRAMP-tastic Cloud Service Offering used by the US federal government. Your assets are not so fragile that basic scans are threats. Probing like that is going to happen no matter what. Historically, we have responsible disclosure to thank for surfacing weaknesses and breaches at Capital One, Morgan Stanley, and Jeep. In the open-source community, a whistleblower told the Apache Software Foundation – and the world – about Log4j. What does a “responsible” disclosure program look like? 1. Have a written policy. Make it easy to find with a security.txt file and/or webpage. 2. Define the guardrails, and offer safe harbor to those who follow them. Maybe direct attention to certain domains while disallowing DDoS, social or reverse engineering, and clickjacking. 3. Establish a mechanism for receiving reports. Assign responsibility for triage. 4. Acknowledge submissions quickly. Set expectations about timelines and publication embargoes. 5. Communicate updates with the submitters. Ask questions if you’re skeptical or need help validating. 6. Fix important vulnerabilities on a risk-based timeline. Notify customers in advance if needed. 7. Give credit where it’s due via public release notes alongside patches. Many researchers welcome the prestige of a CVE on their resume. 8. Anything else? As for paying bug bounties, that’s a nice-to-have. Top tech firms offer it, but many SMBs can’t afford to. Just don’t YOLO-ship weak product, hoping the public will catch your mistakes in return for silence. Folks, if we can’t get responsible disclosure right for security vulnerabilities, we’re in for a world of pain with AI vulnerabilities. Disclaimer: Consult cyber-savvy attorneys instead of mistaking this or any LinkedIn post for legal advice.

  • View profile for Antonio Vizcaya Abdo

    Turning Sustainability from Compliance into Business Value | ESG Strategy & Governance Advisor | TEDx Speaker | LinkedIn Creator | UNAM Professor | +129K Followers

    129,183 followers

    TCFD Disclosure Framework 🌍 The TCFD Disclosure Framework was established to integrate climate risk into financial decision-making, recognizing climate change as a source of financial risk and opportunity, rather than merely an environmental issue. The framework is organized around four key pillars that reflect corporate governance and management practices: - Governance: This pillar addresses how boards and senior management oversee climate-related risks and opportunities, clarifying accountability and decision rights while elevating climate considerations to the highest level. - Strategy: This aspect examines the impact of climate risks and opportunities on business models, strategies, and financial planning, requiring companies to evaluate effects over the short, medium, and long term. Scenario analysis is crucial, testing the resilience of strategies under various climate pathways. - Risk Management: This pillar focuses on the identification, assessment, and management of climate risks, emphasizing their integration into existing enterprise risk management processes rather than creating separate systems. It ensures that climate risk is treated with the same rigor as other strategic and financial risks. - Metrics and Targets: This component connects climate performance to measurement and accountability, incorporating greenhouse gas emissions, risk indicators, and targets for managing performance. These four pillars create a cohesive structure linking climate, strategy, risk, and finance. Although reporting formats have evolved, the fundamental logic remains unchanged. With the introduction of IFRS sustainability standards, climate disclosure has transitioned from voluntary alignment to formal requirements. IFRS S2 builds on the TCFD structure, maintaining the same four pillars and financial focus. Thus, TCFD continues to be highly relevant in 2026 as the foundation for current climate disclosure standards. Source: From Promise to Action: Decoding Climate Disclosure, The SustainAbility Institute by ERM

  • View profile for Eli W.

    Cyber Threat Intelligence Advisor & AI Threat Researcher | AI-Integrated Honeypot Architect

    7,472 followers

    How do you share CTI without exposing sensitive tradecraft? I deleted an earlier post because the framing made it too easy for the discussion to become about a specific person instead of the broader CTI tradecraft issue I was trying to raise. That was not my intent, and my point about nuanced communication could have used more nuanced communication. In cyber threat intelligence, we often have to protect sensitive sources, telemetry, victims, and collection methods. That is real. Nobody should be expected to burn access, expose victims, or dump raw indicators into a public conversation just to satisfy curiosity. But there is also a meaningful difference between protecting sources and asking everyone to accept a public claim with no way to assess it. If we make public statements connecting a tool, actor, repo, campaign, or technique to real-world activity, it helps the broader community when we provide some sanitized context. That does not mean sharing raw data. It can be as simple as: “Based on infrastructure analysis and artifacts observed during incident-related telemetry, we assess with high confidence that this toolset was used in activity associated with the campaign.” That statement does not expose victims. It does not reveal sensitive collection. It does not hand out IOCs. But it gives analysts something useful. It tells them the sourcing category. It gives them a confidence level. It helps them understand whether the statement is a guess, a rumor, a direct observation, or an analytic assessment. That matters. CTI is at its best when we help each other reason through uncertainty. We can protect sensitive information and still communicate with enough nuance to be useful. The goal should be: “Here is what I can responsibly say, here is how confident I am, and here is the general basis for the assessment.”

  • View profile for Iwan Dharmawan

    Risk Monitoring Committee Member @OCBC Indonesia | Audit Committee Member @Zurich Insurance | Risk Management Expert

    34,414 followers

    The IFRS Foundation's educational material highlights the significance of disclosing anticipated financial effects under ISSB Standards (IFRS S1 and IFRS S2). Companies are required to articulate how sustainability-related risks, particularly those associated with climate change, influence their operations. These disclosures furnish investors with crucial insights for decision-making, complementing conventional financial statements and aligning with the TCFD framework. Central principles stress the importance of coherence with financial statements, averting redundancy, and integrating both quantitative and qualitative information. Quantitative disclosures may encompass specific amounts or ranges, while qualitative disclosures offer context in areas with notable measurement uncertainty. It is imperative for companies to delineate and disclose their time horizons, connecting these disclosures with strategies, decision-making processes, and climate-related metrics. To address implementation hurdles, ISSB Standards introduce proportionality mechanisms: - Utilizing all reasonable and supportable information available without undue cost or effort. - Customizing disclosures to a company's expertise, resources, and capabilities, with expectations for advancement over time. - Permitting exceptions for inseparable effects, high uncertainty, legal constraints, or commercially sensitive matters. Examples include risks like carbon pricing, floods, and water scarcity, as well as opportunities such as timber housing demand and e-waste recycling. ISSB disclosures strive to transparently associate sustainability impacts with financial outcomes, advocating for progressive, standardized, and investor-centric reporting. These endeavors contribute to a more enlightened investment environment and reinforce sustainable business practices.

  • View profile for Umanhonlen Gabriel

    You are the strength behind the system | CVE-2025-63289 | Cyber Security Professional & Security Researcher. @ umanhonlengabriel.com

    12,416 followers

    The 5th stage of penetration testing "Reporting" is often treated as the final administrative step. In practice, it can be the most demanding. Finding a vulnerability requires technical skill. Explaining it so that a developer can reproduce and fix it, while helping senior management understand the business risk, requires communication, judgement, and context. A vulnerability report is not complete simply because a payload worked or a screenshot was captured. It is what clearly explains what is vulnerable, how it can be exploited, which users, assets, or business processes are affected, what could the organisation lose, how urgent the issue is, and the practical path to remediation. Different stakeholders requires different forms of communication from how the developers need technical evidence, reproducible steps, and clear remediation guidance, how security managers need severity, exploitability, and prioritisation and how executives need to understand the possible effect on revenue, operations, regulatory obligations, reputation, and customer trust. This is not mainly about using AI to make a report sound polished. AI can help improve structure and wording, but it cannot replace professional judgement, organisational context, accountability, or the ability to defend a finding during a real conversation. This is where some technically brilliant professionals struggle. They can identify the vulnerability, but they cannot translate it into meaningful action. Over the years, I have deliberately strengthened this skill through industry-recognised cybersecurity certifications and practical experience beyond penetration testing alone. The objective is not merely to prove that a system can be broken. It is to explain what the weakness means to the organisation and decision-makers responsible for resolving it. Even a technically small flaw can create serious exposure when it affects a valuable business process. A recent example was my responsible disclosure of a security vulnerability to KlickTipp, a platform for email and SMS marketing automation. The disclosure earned me recognition as well as a bounty. 👉 https://lnkd.in/exyhcwvu More importantly, my experience has reinforced a principle I strongly believe in that "The value of security research is not only in discovering a vulnerability, it is also in reporting it responsibly, clearly, and constructively enough for the organisation to act." Although I am currently taking a career break. However, my current areas of engagement include application-security assessments of pilot, pre-production, and deployed assets; independent security consultation; vulnerability-reporting guidance; and practical training for teams of 5 or more. 👉 https://lnkd.in/dUuNJ9Bt Cybersecurity is not just about discovering vulnerabilities. It is about turning technical evidence into business understanding and turning that understanding into timely action.

  • View profile for Arnoud💻 Engelfriet

    Legal specialist AI, data, IT, privacy/GDPR, software, open source, IP. Author of various books on IT and law, including "ICT en Recht", "AI and Algorithms" and "The Annotated AI Act". Ask me to make you CAICO®

    13,258 followers

    🤖 📋 Why GPAI Training Data Disclosures Matter for Your AI Compliance Work Ever wondered what's in ChatGPT's training data? So have countless copyright holders. With modern general-purpose AI models trained on literally billions of documents, images and videos, rightholders are demanding transparency. The EU AI Act's response? Mandatory disclosures for GPAI providers. This week, the EU AI Office unveiled its draft template (art. 53.1(d) AIA) for these disclosures, setting clear expectations for transparency while protecting trade secrets. In parallel, the Commission has announced development of a centralized register for Text & Data Mining opt-outs, giving rightholders more control over their content's use in AI training (art. 4 Directive 2019/790). Why should you care about GPAI transparency? Because most enterprise AI systems today aren't built from scratch - they're fine-tuned versions of existing general-purpose models. Understanding what's in your foundation model becomes crucial for regulatory compliance. When conducting your mandatory risk assessments under Article 9, you'll need to consider potential biases and limitations inherited from the base model's training data. Your technical documentation under Article 11 must account for the complete data lineage, including the GPAI foundation (also see Annex IV item 2(d)). The template's timeline is tight - template finalization is expected in Q2 2025, with mandatory implementation starting August 2025. Now is the time to prepare. Start by mapping which of your AI systems rely on general-purpose models. Review your vendors' documentation practices and establish processes for analyzing GPAI disclosures as part of your compliance framework. This isn't just about checking boxes - it's about understanding the foundations your AI systems are built upon. Want to learn more? My book "The Annotated AI Act" dives deep into transparency requirements and their practical implementation. Let me know in the comments what aspects of GPAI compliance you find most challenging. AnnotatedAIAct.com #AICompliance #AIAct #AIGovernance #GPAI #EULaw #TechLaw

Explore categories