On August 2, 2026, the EU AI Act (the “AI Act”) entered a new implementation phase with two key developments: (i) the European Commission’s AI Office and Member State authorities began enforcing applicable AI Act requirements, including the rules for general-purpose AI (GPAI) models; and (ii) the AI Act’s Article 50 (transparency obligations) also took effect, requiring certain providers and businesses using AI to disclose when people are interacting with AI. Although the AI Act entered into force over two years ago, August 2026 marks a new chapter in its implementation. Businesses should expect increased regulatory oversight and scrutiny of AI developed, offered, or used in the EU.

Continue Reading Enforcement and Transparency Obligations Under the EU AI Act are Now in Effect

A new wave of comprehensive state privacy laws is on the horizon for 2026 and beyond. Alabama, Louisiana, Oklahoma, and Vermont have each enacted consumer data privacy statutes that will come online over the next few years, extending the patchwork and raising the stakes for multi‑state compliance programs.

Below, we provide the general thresholds for each law and a few additional key takeaways.

Continue Reading Coming Soon Near You: New Privacy Laws in Alabama, Louisiana, Oklahoma, and Vermont

California’s Delete Request and Opt-Out Platform (DROP) requirements went into effect on August 1, 2026, marking a meaningful operational shift for regulated data brokers and a clear reminder that enforcement of the Delete Act is no longer theoretical.

Separately, several other states have advanced their own data broker frameworks. New Jersey introduced an aggressive data broker regime, Connecticut expanded its privacy law to build out a data broker registration and centralized deletion framework, and Vermont updated its existing data broker law. Against that backdrop, and with regulators taking action, it is a good time for personal data-driven companies to take stock of their compliance obligations and risk exposure under these evolving data broker laws.

Continue Reading Just DROPped: A Data Broker Law Update

With what is becoming the regular cadence of a daily soap opera, the developments in what has become known as “CIPA law” continue to evolve quickly. 

In the past couple of weeks, we have written on several instances that could impact the litigation posture for any company sued or threated to be sued in California for alleged violations of the both potential legislative action and action in the courts that might provide relief to businesses being sued or threatened to be sued for violations of the California Invasion of Privacy Act (CIPA).

Continue Reading As the CIPA World Turns…

Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy disclosures, limitations on data collection and profiling, and duties to act in the best interests of minors.

State legislatures have also recently begun directly regulating the privacy practices of companies that provide social media solutions to consumers, often with an eye to protecting underage users. Common amongst these new laws are age verification requirements and parental control and consent requirements. Some laws go further, such as requiring ‘deplatforming’ in certain circumstances and restricting ‘shadow banning’ practices. Many of these statutes define “social media” to broadly include any technologies that facilitate interactions among end users and can carry significant penalties for noncompliance.

Below is a summary of certain recent state laws regulating these topics.

Continue Reading Children’s Data & Social Media Privacy Laws

Clients, recent speaking engagements, the explosion of state AI regulation and guidance from financial authorities have all forced me to think and re-think how companies should practically approach their AI governance.

On the one hand, AI-powered tools promise to advance productivity for most tech-powered companies, and most companies find themselves eager to harness the power of these solutions. On the other hand, the regulatory, legal, and reputational risks are increasingly non-trivial, including the potential for private litigation and enforcement, failed customer engagement strategy, and other challenges.

Continue Reading Internalizing AI Governance: The Practical Thinking So Far

We have been writing about the California Invasion of Privacy Act (CIPA) for a while now (and, earlier this year, we predicted this law would continue to be a major issue in 2026).

From demand letters flooding our clients’ inboxes to the wave of litigation targeting standard website tracking tools, this 1967 wiretapping statute has proven uniquely susceptible to claims that bear little resemblance to the covert surveillance it was designed to prevent. On July 1, 2026, the California Assembly Committee on Privacy and Consumer Protection passed an amended version of Senate Bill 690, and the result is both encouraging and incomplete.

Continue Reading California Legislature Takes Aim at CIPA Abuse

On June 22, 2026, President Trump issued two Executive Orders entitled “Ushering the Next Frontier of Quantum Innovation” (Quantum EO) and “Securing the Nation Against Advanced Cryptographic Attacks” (Cryptographic EO) demonstrating the increasing focus of the administration on quantum. 

Quantum technology is a rapidly growing technology using quantum-mechanical principles to process data in ways not possible with classical computers. Quantum computers and quantum technologies like photonics and sensors are undergoing significant research and development efforts that will impact every industry. One of the most immediately impactful issues related to quantum computers is their ability to break even the best classical computer encryption protocols. As a result, the United States and many other countries and large companies are dedicating significant funds to quantum research in an effort to ensure the protection of critical encrypted data. Quantum is both an amazing new technology and an imminent security threat.

Continue Reading Quantum Homework for Everyone: New Executive Orders on Quantum Technology

The California Information Privacy Act (CIPA) has become a go‑to vehicle for plaintiffs’ counsel attacking website tracking technologies, such as cookies, pixels, beacons, chat bots, and video or session replay tools.

Over the last few years, website operators have been hit with a wave of demand letters claiming CIPA violations. But the tide may be shifting – marking smoother sailing for website operators. A recent decision from a California court narrows CIPA to telephonic communications and significantly undercuts the viability of CIPA claims against commercial websites.

Continue Reading Changing Tides: A Los Angeles Court Delivers a Major CIPA Defense Win

Last week, I had the pleasure of taking the main stage at CincyAI Week in Cincinnati, Ohio to talk with entrepreneurs, business leaders, academics, and artificial intelligence enthusiasts about the current state of AI policy, privacy, and compliance across the United States.

Here are the key takeaways from the presentation.

Continue Reading The State of AI Policy, Privacy, and Compliance in the United States