Some big news around regulation.
California Governor Gavin Newsom vetoed a strict AI regulation bill, S.B. 1047, which would have required companies to test powerful AI systems and held them liable for harmful uses. Newsom plans to collaborate with academics to develop alternative guidelines for AI deployment, while the veto highlights the ongoing debate over AI safety and regulation. Newsom cited that it was wrong to single out large models, mainly when smaller ones are more likely to be involved in critical decision-making.
NIST has revised its password guidelines, no longer recommending complexity requirements or mandatory password resets. The new guidelines advocate for passwords of at least 15 characters, allowing up to 64 characters, and including ASCII and Unicode characters. The focus has shifted from complexity to length, as longer passwords are harder to crack and easier for users to remember. Password resets should only occur after a credential breach, as frequent changes often lead to weaker passwords.
From a legislative perspective, perfect has become the enemy of good here. Newsom’s reasoning is flawed, as this isn’t a zero-sum game.
The good news is that a client refresh of password policies is due. Moving away from complex, frequently changing passwords to longer, more user-friendly passwords addresses the long-standing issues of password fatigue and weak security practices. Users will like this one, and it’s worth highlighting the change in a positive way.

