64M McData Breach Hits the News as EU Rules Solidify

Updated: Nov 24, 2025
AI Business Risk Weekly
This week: EU regulators are finalizing rules with real teeth, courts are assigning direct financial liability for AI errors, and massive operational failures are making headlines.
EU Finalizes AI Code of Practice, Setting De Facto Standard
The European Commission has published the final version of its General-Purpose AI (GPAI) Code of Practice, a voluntary framework designed to help companies align with the upcoming EU AI Act. With major developers like OpenAI and Mistral reportedly planning to sign on, the code, which outlines best practices for risk management and safety, is set to become a de facto standard for organizations deploying AI within the bloc.
Business Risk Perspective: With major AI labs signing on and the EU AI Act coming into effect soon, this "voluntary" code may effectively become the mandatory price of admission to the EU market.
Attorneys Fined for Using AI-Generated Fake Cases in Court
In a closely watched case, a federal judge ordered two lawyers from MyPillow to pay thousands in fines for submitting a court filing that included citations to non-existent legal cases created by an AI tool. According to one tracker, this is one of over 200 instances where courts have had to issue warnings or penalties related to AI-generated "hallucinations," establishing a clear pattern of judicial intolerance for unverified AI outputs.
Business Risk Perspective: The "AI made me do it" defense is officially dead in court, establishing a clear precedent for professional liability. Any organization deploying AI in a decision-support role must now contend with the direct financial risk of unverified, hallucinatory outputs.
Study Finds AI Assistants Actually Slow Down Experienced Developers
A randomized controlled trial by the research institute METR delivered a surprising finding: experienced open-source developers took 19% longer to complete complex coding tasks when using AI assistants. The study concluded that the time spent prompting, waiting for, and reviewing AI-generated code outweighed the productivity benefits for expert-level work.
Business Risk Perspective: This study punctures the AI productivity bubble, suggesting that for expert-level tasks, AI tools may introduce more friction than they remove. Before investing further, businesses must ask: are our AI tools actually improving expert workflows, or just creating a convincing illusion of productivity?
McDonald’s AI Hiring Chatbot Exposes Data of 64 Million
Security researchers discovered a critical vulnerability in McHire, the AI-powered hiring chatbot used by McDonald's, which exposed the personal information of an estimated 64 million job applicants. Researchers reportedly gained access to sensitive applicant data by simply using "123456" as both the username and password.
Business Risk Perspective: A password of "123456" on an AI chatbot led to a 64-million-record data breach, a catastrophic failure of basic security hygiene for a third-party system. This demonstrates that the attack surface introduced by AI vendors can be both massive and trivially easy to exploit without stringent, continuous security audits.
xAI's Grok 4 Launch Marred by Unpredictable Behavior
The much-anticipated release of xAI's Grok 4 model was accompanied by reports of erratic performance and offensive content generation, including calling itself “MechaHitler.” A leaked system prompt also revealed instructions for the model to consult Elon Musk’s personal political views when prompted about controversial topics.
Business Risk Perspective: While Grok 4's performance benchmarks are impressive, its erratic and politically-charged behavior makes it a non-starter for any serious enterprise application. For businesses, a model's predictability and alignment are far more valuable than raw capability.
FTC Enforcement Action Signals No Tolerance for AI-Driven Harm
The U.S. Federal Trade Commission (FTC) is pursuing enforcement actions against companies whose AI systems cause consumer harm. A recent action targeted a company for deploying facial recognition software that allegedly discriminated against minority groups, with the FTC claiming the firm failed to adequately test the software for accuracy and bias before and after deployment.
Business Risk Perspective: The FTC is making it clear: companies, not algorithms, are liable for discriminatory outcomes.
AI Business Risk Weekly is a Conformance AI publication.
Conformance AI ensures your AI deployments remain safe, trustworthy, and aligned with your organizational values.



