You bought cyber insurance because you knew a serious cyber theft could threaten the business you have spent years building.

Your company paid premiums year after year, maintained payment controls, and worked to protect its systems and financial information. No CEO expects perfect security or expects every loss to be covered by insurance. But a company that buys coverage for computer fraud, funds-transfer fraud, and social engineering reasonably expects the policy to matter when criminals compromise company communications and divert a seven-figure payment.

Insurance is supposed to be the company’s financial backstop when prevention fails. The company did not buy an insurance policy to debate technical definitions after a loss. It bought the policy to keep a sophisticated theft from becoming an uninsured loss, an unpaid vendor obligation, and another crisis for management.

This is how quickly a routine vendor payment can become a cyber crisis.

Continue Reading When Your Cyber Insurer Sends You in Circles: A Hacked CFO Email, a Stolen Vendor Payment, and the Coverage Maze That Can Follow

This is the third installment in our coverage of the Anthropic/Department of War dispute. Our first alert addressed the Trump administration’s February 27 directives barring federal contractors from using Anthropic and its Claude platform, including Secretary Hegseth’s designation of Anthropic as a supply chain risk to national security and the resulting requirement that all DoW contractors sever commercial ties with the company. Our second alert covered the March 26 preliminary injunction, in which Judge Lin found Anthropic had demonstrated a likelihood of success on the merits and was suffering irreparable harm from the challenged actions. This post covers where things stand now following the latest Federal Court ruling.

The Ruling

On August 27, 2026, U.S. District Judge Rita F. Lin of the Northern District of California granted summary judgment largely in favor of Anthropic PBC, ruling that the DoW’s designation of the company as a supply chain risk to national security was “illegal and baseless.” In a 59-page order, Judge Lin concluded that the designation was not based on any credible threat, but was instead retaliation for Anthropic’s public criticism of the Trump administration’s position during contract negotiations over the use of its AI model, Claude.

Continue Reading Federal Court Rules Government’s Anthropic Supply Chain Designation Was Unlawful Retaliation: What Government Contractors Need to Know

In Mid-August, Taft published the latest edition of The Big Long List of U.S. AI Laws. The list now includes over 60 entries focused on the commercial regulation of AI by the states.

Persistent rumors to the contrary, AI law compliance is anything but a detail and triviality.

There is nothing particularly glamorous about notifying your job applicants of your AI, putting disclaimers on your chat bot, conducting risk assessments, disclosing data sources, developing policies, or ensuring contracting standards. But, increasingly, requirements such as these are required or advisable under law for a growing number of particular AI applications. Businesses which develop and deploy AI without considering the growing list of compliance issues carefully do so at their own risk.

Continue Reading Big Long List of AI Laws – Notable Updates

On August 2, 2026, the EU AI Act (the AI Act) entered a new implementation phase with two key developments: (i) the European Commission’s AI Office and Member State authorities began enforcing applicable AI Act requirements, including the rules for general-purpose AI (GPAI) models; and (ii) the AI Act’s Article 50 (transparency obligations) also took effect, requiring certain providers and businesses using AI to disclose when people are interacting with AI. Although the AI Act entered into force over two years ago, August 2026 marks a new chapter in its implementation. Businesses should expect increased regulatory oversight and scrutiny of AI developed, offered, or used in the EU.

Continue Reading Enforcement and Transparency Obligations Under the EU AI Act are Now in Effect

A new wave of comprehensive state privacy laws is on the horizon for 2026 and beyond. Alabama, Louisiana, Oklahoma, and Vermont have each enacted consumer data privacy statutes that will come online over the next few years, extending the patchwork and raising the stakes for multi‑state compliance programs.

Below, we provide the general thresholds for each law and a few additional key takeaways.

Continue Reading Coming Soon Near You: New Privacy Laws in Alabama, Louisiana, Oklahoma, and Vermont

California’s Delete Request and Opt-Out Platform (DROP) requirements went into effect on August 1, 2026, marking a meaningful operational shift for regulated data brokers and a clear reminder that enforcement of the Delete Act is no longer theoretical.

Separately, several other states have advanced their own data broker frameworks. New Jersey introduced an aggressive data broker regime, Connecticut expanded its privacy law to build out a data broker registration and centralized deletion framework, and Vermont updated its existing data broker law. Against that backdrop, and with regulators taking action, it is a good time for personal data-driven companies to take stock of their compliance obligations and risk exposure under these evolving data broker laws.

Continue Reading Just DROPped: A Data Broker Law Update

With what is becoming the regular cadence of a daily soap opera, the developments in what has become known as “CIPA law” continue to evolve quickly. 

In the past couple of weeks, we have written on several instances that could impact the litigation posture for any company sued or threated to be sued in California for alleged violations of the both potential legislative action and action in the courts that might provide relief to businesses being sued or threatened to be sued for violations of the California Invasion of Privacy Act (CIPA).

Continue Reading As the CIPA World Turns…

Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy disclosures, limitations on data collection and profiling, and duties to act in the best interests of minors.

State legislatures have also recently begun directly regulating the privacy practices of companies that provide social media solutions to consumers, often with an eye to protecting underage users. Common amongst these new laws are age verification requirements and parental control and consent requirements. Some laws go further, such as requiring ‘deplatforming’ in certain circumstances and restricting ‘shadow banning’ practices. Many of these statutes define “social media” to broadly include any technologies that facilitate interactions among end users and can carry significant penalties for noncompliance.

Below is a summary of certain recent state laws regulating these topics.

Continue Reading Children’s Data & Social Media Privacy Laws

Clients, recent speaking engagements, the explosion of state AI regulation and guidance from financial authorities have all forced me to think and re-think how companies should practically approach their AI governance.

On the one hand, AI-powered tools promise to advance productivity for most tech-powered companies, and most companies find themselves eager to harness the power of these solutions. On the other hand, the regulatory, legal, and reputational risks are increasingly non-trivial, including the potential for private litigation and enforcement, failed customer engagement strategy, and other challenges.

Continue Reading Internalizing AI Governance: The Practical Thinking So Far

We have been writing about the California Invasion of Privacy Act (CIPA) for a while now (and, earlier this year, we predicted this law would continue to be a major issue in 2026).

From demand letters flooding our clients’ inboxes to the wave of litigation targeting standard website tracking tools, this 1967 wiretapping statute has proven uniquely susceptible to claims that bear little resemblance to the covert surveillance it was designed to prevent. On July 1, 2026, the California Assembly Committee on Privacy and Consumer Protection passed an amended version of Senate Bill 690, and the result is both encouraging and incomplete.

Continue Reading California Legislature Takes Aim at CIPA Abuse