Ceiba Law

Ceiba Law Technology law firm advising on AI, data, incident response, defence procurement, and cybersecurity law.

Through integrated GRC services, we help teams build safely, prevent issues, and coach leaders through breaches.

⚖️ Insights at .

Ceiba Law’s Managing Partner, Vanessa Henri, has joined the Advisory Board for CareLogic, Canada’s first behaviour based...
09/03/2026

Ceiba Law’s Managing Partner, Vanessa Henri, has joined the Advisory Board for CareLogic, Canada’s first behaviour based Quality Engineering Benchmark, launched by SQALogic.

QE benchmarking sits outside the usual scope of a law firm, but it aligns directly with Ceiba’s practice: helping organizations make defensible risk decisions where cybersecurity, data protection, and Canadian privacy law meet.

Rather than relying on self reported checklists, CareLogic scores real diagnostic answer patterns across People, Processes, and Products, and updates live rather than through yearly reports. Results are grouped by province and sector, giving Canadian organizations a peer comparison point that global benchmarks don’t offer. It was named winner of the 2026 CQTA QE Innovation Award.

Quality gaps and risk are linked upstream. Weak processes, undocumented ownership, and gaps in testing are often the same gaps that later surface as security incidents or data handling failures.

The team behind CareLogic built the platform with Canadian sovereignty and privacy in mind from the outset. Vanessa’s seat on the board brings her cybersecurity and data protection expertise to a project focused on managing risk before it reaches the surface.

Link in the comments to learn more about CareLogic.

08/08/2026
Le 29 juin, la Cour suprême américaine a rendu une décision qui touche directement la structure derrière le Data Privacy...
07/22/2026

Le 29 juin, la Cour suprême américaine a rendu une décision qui touche directement la structure derrière le Data Privacy Framework, l'accord qui encadre le transfert de données personnelles vers les États-Unis.

Dans Trump v. Slaughter, la Cour a autorisé la révocation d'une commissaire de la Federal Trade Commission, renversant un précédent de 1935 qui protégeait l'indépendance des organismes de réglementation. La FTC est l'autorité responsable de l'application du Data Privacy Framework. Ce jugement s'ajoute à une série de développements touchant les mécanismes de surveillance américains, notamment la perte de quorum démocrate au Privacy and Civil Liberties Oversight Board plus tôt en 2025.
Le Data Privacy Framework demeure en vigueur. Mais les recours devant les tribunaux européens s'accumulent, et cette décision change la nature des arguments disponibles.

Pendant ce temps, Bruxelles avance sur un autre front. Le Cloud and AI Development Act, publié le 3 juin dans le cadre du Tech Sovereignty Package, introduit quatre niveaux d'exigence pour les marchés publics européens. Pour la première fois, la souveraineté numérique devient un critère mesurable plutôt qu'un argument commercial.

Sidy Juste a décortiqué ces deux dossiers avec Daphnée Lucenet pour IA Éthique Insider, du point de vue de la gouvernance des risques numériques pour les organisations qui dépendent de fournisseurs ou d'infrastructures américaines.

Comment votre organisation évalue-t-elle sa dépendance réelle à des fournisseurs soumis à ce cadre, au-delà de la case cochée dans le contrat?

Between late December 2025 and mid-February 2026, a single operator used Anthropic's Claude Code and OpenAI's GPT-4.1 to...
07/17/2026

Between late December 2025 and mid-February 2026, a single operator used Anthropic's Claude Code and OpenAI's GPT-4.1 to breach nine Mexican government organizations and exfiltrate hundreds of millions of citizen records. According to an April 2026 technical report from Israeli security vendor, Gambit Security, the operator logged 1,088 prompts that produced 5,317 AI-executed commands across 34 sessions on live victim infrastructure, with roughly 75% of remote command ex*****on generated and run by Claude Code. A custom 17,550-line Python tool piped harvested server data through OpenAI's API to produce 2,597 structured intelligence reports across 305 internal servers.

Claude declined a number of the operator's requests along the way. He got past those refusals by describing the work as authorized bug bounty research. The model's guardrails did what they were built to do. The human judgement that should have caught that framing was not there.

Gigi Agassini and Shawn Ford unpack the Mexico case, and what it means for oversight, judgement, and liability, in the latest piece for ISRM Canadian Charter.

When your team is inside a live incident, how quickly would you catch an attacker's framing before it moves the response in the wrong direction?

A single operator breached nine Mexican government organizations between December 2025 and February 2026, using Anthropi...
07/17/2026

A single operator breached nine Mexican government organizations between December 2025 and February 2026, using Anthropic’s Claude Code and OpenAI’s GPT-4.1.

1,088 prompts. 5,317 AI-executed commands. Hundreds of millions of citizen records exfiltrated.

Claude declined a number of the operator’s requests along the way. He got past those refusals by describing the work as authorized bug bounty research.

The model’s guardrails did what they were built to do. The human judgement that should have caught the framing was not there.

Gigi Agassini and Shawn Ford break down the case, and what it means for oversight, judgement, and liability, in the latest piece for ISRM. Link in first comment.

If you’re navigating AI, cybersecurity, or complex technology contracts — you need the right people in your corner.We ar...
06/05/2026

If you’re navigating AI, cybersecurity, or complex technology contracts — you need the right people in your corner.

We are proud to welcome Sidy Juste to Ceiba Law. Dual-barred in Montréal and Paris. Seasoned across IT contracts, AI governance, privacy law, cloud infrastructure, and digital sovereignty. Formerly at board level as General Counsel at a leading French cloud company.

The firm just got stronger.

Bill C-8 is moving through Senate committee and it is closer to becoming law than most organizations realize.When it pas...
06/04/2026

Bill C-8 is moving through Senate committee and it is closer to becoming law than most organizations realize.

When it passes, telecom providers and designated operators of critical cyber systems will be required to maintain formal cybersecurity programs, manage third-party and supply chain risks, and report incidents to the government.

That last point is where it gets interesting for everyone outside the telecom sector. If you supply technology, software, or services to a designated operator, their compliance obligations flow directly into your vendor relationship. Your security posture, your documentation, your incident response capability — all of it becomes part of their defensible record.

The question to ask now is not whether Bill C-8 applies to you directly. It is whether it applies to your clients.

Digital sovereignty is often discussed.Rarely operationalized.Most organizations are asked to take a position on soverei...
05/15/2026

Digital sovereignty is often discussed.
Rarely operationalized.

Most organizations are asked to take a position on sovereignty without a clear way to assess it.

What do you actually control?
Where does your data flow?
Which decisions can you enforce?

In practice, sovereignty is not a statement.
It is a function of how your systems are designed, contracted, and operated.

It starts with:
– understanding your architecture and dependencies
– identifying where control exists and where it doesn’t
– aligning legal, technical, and operational realities

From there, it becomes something measurable.

At Ceiba Law, we approach digital sovereignty as a question of control, not abstraction. Reach out to learn how we approach sovereignty assessments.

What is a dedicated General Counsel and do you need one?Most companies don’t need a full-time General Counsel.But they d...
05/13/2026

What is a dedicated General Counsel and do you need one?

Most companies don’t need a full-time General Counsel.
But they do need consistent legal thinking embedded in how they operate.

Legal is often brought in too late.
At the point where decisions have already been made, contracts signed, or risks materialized.

A dedicated General Counsel model changes that.

It means having ongoing legal support that:
– understands your business and how your systems operate
– structures contracts, data use, and risk before they become issues
– supports leadership in decision-making, not just documentation
– aligns legal, product, and operational realities

This is particularly critical in environments shaped by technology, AI, and data.

The question is not whether you need legal support.

It is whether it is integrated into how your business runs.

Many organizations are actively experimenting with AI.What we see in practice is less clarity on how these initiatives a...
05/12/2026

Many organizations are actively experimenting with AI.
What we see in practice is less clarity on how these initiatives are governed.

Teams are testing tools and moving quickly. At the same time, executives and boards are expected to approve decisions that carry legal, operational, and reputational consequences. In many cases, ownership is not clearly defined. Risk is not fully articulated. And the basis for key decisions is not documented.

This creates exposure. AI initiatives are not only technology deployments. They are decisions that require clear accountability, defensible reasoning, and appropriate controls from the outset.

Myriam Côté, eng., Ph.D. brings a unique combination of experience across research, industry, and strategy. Her background includes leadership roles in applied AI environments, including at Mila - Quebec Artificial Intelligence Institute, where she contributed to the development and growth of one of Canada’s leading AI ecosystems Her work focuses on how organizations integrate AI in a way that is both operational and responsible, bridging technical capabilities with business and societal considerations.

This is aligned with how we approach AI at Ceiba Law.

Because ultimately, it is not just the system that needs to perform.
It is the decision behind it that needs to stand.

Adresse

1 Westmount Square, Suite 2000
Westmount, QC
H3Z2P9

Heures d'ouverture

Lundi 8am - 6pm
Mardi 8am - 6pm
Mercredi 8am - 6pm
Jeudi 8am - 6pm
Vendredi 8am - 6pm

Notifications

Soyez le premier à savoir et laissez-nous vous envoyer un courriel lorsque Ceiba Law publie des nouvelles et des promotions. Votre adresse e-mail ne sera pas utilisée à d'autres fins, et vous pouvez vous désabonner à tout moment.

Contacter L'entreprise

Envoyer un message à Ceiba Law:

Raccourcis

Partager