Photo of Michael Young

Michael’s practice advises and represents clients on complex privacy, AI and data protection issues. From pre-venture startups to some of the most recognizable brands in the world, whether strategic or transactional, Michael specializes in helping companies find answers that are right for them given their unique challenges.

Clients, recent speaking engagements, the explosion of state AI regulation and guidance from financial authorities have all forced me to think and re-think how companies should practically approach their AI governance.

On the one hand, AI-powered tools promise to advance productivity for most tech-powered companies, and most companies find themselves eager to harness the power of these solutions. On the other hand, the regulatory, legal, and reputational risks are increasingly non-trivial, including the potential for private litigation and enforcement, failed customer engagement strategy, and other challenges.

Continue Reading Internalizing AI Governance: The Practical Thinking So Far

Among the growing number of state AI statutes, multiple states have now enacted laws governing the use of artificial intelligence technology by health insurers when determining whether or not to cover claims.

This article outlines some considerations for insurers, focusing on Nebraska, Georgia and Colorado statutes. 

Continue Reading AI and Insurance Claims: Beware Fully Automated Decision Making

Under new regulations effective January 1, 2026, California regulators now expect businesses to conduct an annual “cybersecurity audit” that assesses “how the business’s cybersecurity program protects personal information from unauthorized access, destruction, use, modification, or disclosure; and protects against unauthorized activity resulting in the loss of availability of personal information.”

Now is the time to prepare for these requirements.

As explained below, these requirements are detailed and contemplate a rigorous, professional, independent, evidence-based audit. Audits must be certified to the California regulator under penalty of perjury.

Continue Reading Understanding California Cyber Audit Requirements

Under newly implemented regulations of the California Consumer Privacy Act (CCPA), California now requires a formal risk assessment “before initiating any processing activity” of certain (sensitive) sorts. The regulation explicitly contemplates that businesses will complete risk assessments now, in 2026.

Eventually, such risk assessments – including those completed this year – must be signed by an executive and submitted to the California regulator under penalty of perjury.

Continue Reading New CCPA Risk Assessment Requirements Now In Effect

Enforcement activity surged in 2025, with landmark judgments and settlements—some reaching eight and nine figures—targeting issues such as ad tracking, analytics, wiretapping, text messaging, data subject rights, and sensitive data collection. This aggressive trend shows no signs of slowing as we move into 2026.

Taft continues to help its clients find the correct answers in their context for addressing these risks. Building on our year-end post, here are some issues you may want to consider as you take on the new year.

Continue Reading Your 2026 Privacy, Security, and Artificial Intelligence Checklist