Photo of Michael Young

Michael Young

Michael’s practice advises and represents clients on complex privacy, AI and data protection issues. From pre-venture startups to some of the most recognizable brands in the world, whether strategic or transactional, Michael specializes in helping companies find answers that are right for them given their unique challenges.

In Mid-August, Taft published the latest edition of The Big Long List of U.S. AI Laws. The list now includes over 60 entries focused on the commercial regulation of AI by the states.

Persistent rumors to the contrary, AI law compliance is anything but a detail and triviality.

There is nothing particularly glamorous about notifying your job applicants of your AI, putting disclaimers on your chat bot, conducting risk assessments, disclosing data sources, developing policies, or ensuring contracting standards. But, increasingly, requirements such as these are required or advisable under law for a growing number of particular AI applications. Businesses which develop and deploy AI without considering the growing list of compliance issues carefully do so at their own risk.

Continue Reading Big Long List of AI Laws – Notable Updates

Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy disclosures, limitations on data collection and profiling, and duties to act in the best interests of minors.

State legislatures have also recently begun directly regulating the privacy practices of companies that provide social media solutions to consumers, often with an eye to protecting underage users. Common amongst these new laws are age verification requirements and parental control and consent requirements. Some laws go further, such as requiring ‘deplatforming’ in certain circumstances and restricting ‘shadow banning’ practices. Many of these statutes define “social media” to broadly include any technologies that facilitate interactions among end users and can carry significant penalties for noncompliance.

Below is a summary of certain recent state laws regulating these topics.

Continue Reading Children’s Data & Social Media Privacy Laws

Clients, recent speaking engagements, the explosion of state AI regulation and guidance from financial authorities have all forced me to think and re-think how companies should practically approach their AI governance.

On the one hand, AI-powered tools promise to advance productivity for most tech-powered companies, and most companies find themselves eager to harness the power of these solutions. On the other hand, the regulatory, legal, and reputational risks are increasingly non-trivial, including the potential for private litigation and enforcement, failed customer engagement strategy, and other challenges.

Continue Reading Internalizing AI Governance: The Practical Thinking So Far

Among the growing number of state AI statutes, multiple states have now enacted laws governing the use of artificial intelligence technology by health insurers when determining whether or not to cover claims.

This article outlines some considerations for insurers, focusing on Nebraska, Georgia and Colorado statutes. 

Continue Reading AI and Insurance Claims: Beware Fully Automated Decision Making

Under new regulations effective January 1, 2026, California regulators now expect businesses to conduct an annual “cybersecurity audit” that assesses “how the business’s cybersecurity program protects personal information from unauthorized access, destruction, use, modification, or disclosure; and protects against unauthorized activity resulting in the loss of availability of personal information.”

Now is the time to prepare for these requirements.

As explained below, these requirements are detailed and contemplate a rigorous, professional, independent, evidence-based audit. Audits must be certified to the California regulator under penalty of perjury.

Continue Reading Understanding California Cyber Audit Requirements

Under newly implemented regulations of the California Consumer Privacy Act (CCPA), California now requires a formal risk assessment “before initiating any processing activity” of certain (sensitive) sorts. The regulation explicitly contemplates that businesses will complete risk assessments now, in 2026.

Eventually, such risk assessments – including those completed this year – must be signed by an executive and submitted to the California regulator under penalty of perjury.

Continue Reading New CCPA Risk Assessment Requirements Now In Effect

Enforcement activity surged in 2025, with landmark judgments and settlements—some reaching eight and nine figures—targeting issues such as ad tracking, analytics, wiretapping, text messaging, data subject rights, and sensitive data collection. This aggressive trend shows no signs of slowing as we move into 2026.

Taft continues to help its clients find the correct answers in their context for addressing these risks. Building on our year-end post, here are some issues you may want to consider as you take on the new year.

Continue Reading Your 2026 Privacy, Security, and Artificial Intelligence Checklist