Photo of Beau Braswell

Beau advises clients on data privacy and cybersecurity matters for more than eight years. He began his legal career in the U.S. Department of Justice, where he obtained a TS/SCI clearance and advised on data protection in the law enforcement and intelligence contexts.

Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy disclosures, limitations on data collection and profiling, and duties to act in the best interests of minors.

State legislatures have also recently begun directly regulating the privacy practices of companies that provide social media solutions to consumers, often with an eye to protecting underage users. Common amongst these new laws are age verification requirements and parental control and consent requirements. Some laws go further, such as requiring ‘deplatforming’ in certain circumstances and restricting ‘shadow banning’ practices. Many of these statutes define “social media” to broadly include any technologies that facilitate interactions among end users and can carry significant penalties for noncompliance.

Below is a summary of certain recent state laws regulating these topics.

Continue Reading Children’s Data & Social Media Privacy Laws

Connecticut’s Governor Ned Lamont announced on May 29, 2026 that he had ratified sweeping artificial intelligence legislation in Senate Bill 5, titled “An Act Concerning Online Safety.” The law is unique in its breadth among the growing list of state AI laws, in that it regulates several distinct applications or categories of AI.

Specifically, the law addresses: 1) subscription-based AI services; 2) frontier AI models; 3) automated employment-related decision technology; 4) AI companions; and 5) AI in social media. Below, we summarize certain requirements pertaining to each regulated topic.

Continue Reading Connecticut Enacts Sweeping AI Legislation

In February 2026, a public-private partnership headed by the U.S. Department of the Treasury concluded an investigative process aimed at strengthening cybersecurity and risk mitigation for AI in the financial services sector.

The partnership consisted of executives from over 100 financial institutions, U.S. and international agencies, federal and state financial regulators, and other key stakeholders. One of the partnership’s key deliverables announced at the conclusion of the investigation is the Financial Services AI Risk Management Framework (Financial Services AI RMF), which adopts and expands the AI Risk Management Framework provided by the National Institute of Standards and Technology (NIST Framework) for specific application to the financial services industry.

Continue Reading Financial Services AI Risk Management Framework: Expanded Controls for the Financial Services Industry

On April 22, 2026, the Federal Trade Commission will begin enforcing compliance with its most recent amendments to the Children’s Online Privacy Protection Rule (the COPPA Rule). As discussed in more detail below, the FTC published amendments in a 2025 final rule that, among other updates, expands the scope of the COPPA Rule, expands notice requirements, and requires specific data retention and information security policies and procedures.

Continue Reading Enforcement Begins Soon for Significant COPPA Rule Amendments

The use of AI in hiring and employment contexts has become a special area of interest for U.S. state legislatures in recent years. Does your business utilize AI solutions for recruiting, hiring, or other HR-related functions? Are these teams planning on implementing such technologies to increase efficiency?

Several states have enacted laws specifically regulating the use of AI in these contexts. Human resources and hiring teams need to ensure that current and planned AI use is understood and that new legal risks are identified and addressed.

Continue Reading The Use of AI in Interviewing, Hiring, and HR

Under newly implemented regulations of the California Consumer Privacy Act (CCPA), California now requires a formal risk assessment “before initiating any processing activity” of certain (sensitive) sorts. The regulation explicitly contemplates that businesses will complete risk assessments now, in 2026.

Eventually, such risk assessments – including those completed this year – must be signed by an executive and submitted to the California regulator under penalty of perjury.

Continue Reading New CCPA Risk Assessment Requirements Now In Effect

Enforcement activity surged in 2025, with landmark judgments and settlements—some reaching eight and nine figures—targeting issues such as ad tracking, analytics, wiretapping, text messaging, data subject rights, and sensitive data collection. This aggressive trend shows no signs of slowing as we move into 2026.

Taft continues to help its clients find the correct answers in their context for addressing these risks. Building on our year-end post, here are some issues you may want to consider as you take on the new year.

Continue Reading Your 2026 Privacy, Security, and Artificial Intelligence Checklist