Photo of Zachary Heck

Zachary Heck

Zach’s practice focuses on privacy, data security and artificial intelligence (“AI”) counseling. Specifically, Zach assists clients in the areas of privacy compliance, data governance, and guidance in the aftermath of an information security incident. He regularly advises organizations on the responsible development, deployment, and governance of artificial intelligence systems, including compliance with emerging state, federal, and international AI regulations. In addition, he counsels technology providers on the regulatory, security, and governance considerations associated with FinTech innovations, including blockchain, digital assets, and AI-driven financial tools.

This is the third installment in our coverage of the Anthropic/Department of War dispute. Our first alert addressed the Trump administration’s February 27 directives barring federal contractors from using Anthropic and its Claude platform, including Secretary Hegseth’s designation of Anthropic as a supply chain risk to national security and the resulting requirement that all DoW contractors sever commercial ties with the company. Our second alert covered the March 26 preliminary injunction, in which Judge Lin found Anthropic had demonstrated a likelihood of success on the merits and was suffering irreparable harm from the challenged actions. This post covers where things stand now following the latest Federal Court ruling.

The Ruling

On August 27, 2026, U.S. District Judge Rita F. Lin of the Northern District of California granted summary judgment largely in favor of Anthropic PBC, ruling that the DoW’s designation of the company as a supply chain risk to national security was “illegal and baseless.” In a 59-page order, Judge Lin concluded that the designation was not based on any credible threat, but was instead retaliation for Anthropic’s public criticism of the Trump administration’s position during contract negotiations over the use of its AI model, Claude.

Continue Reading Federal Court Rules Government’s Anthropic Supply Chain Designation Was Unlawful Retaliation: What Government Contractors Need to Know

We have been writing about the California Invasion of Privacy Act (CIPA) for a while now (and, earlier this year, we predicted this law would continue to be a major issue in 2026).

From demand letters flooding our clients’ inboxes to the wave of litigation targeting standard website tracking tools, this 1967 wiretapping statute has proven uniquely susceptible to claims that bear little resemblance to the covert surveillance it was designed to prevent. On July 1, 2026, the California Assembly Committee on Privacy and Consumer Protection passed an amended version of Senate Bill 690, and the result is both encouraging and incomplete.

Continue Reading California Legislature Takes Aim at CIPA Abuse

On June 22, 2026, President Trump issued two Executive Orders entitled “Ushering the Next Frontier of Quantum Innovation” (Quantum EO) and “Securing the Nation Against Advanced Cryptographic Attacks” (Cryptographic EO) demonstrating the increasing focus of the administration on quantum. 

Quantum technology is a rapidly growing technology using quantum-mechanical principles to process data in ways not possible with classical computers. Quantum computers and quantum technologies like photonics and sensors are undergoing significant research and development efforts that will impact every industry. One of the most immediately impactful issues related to quantum computers is their ability to break even the best classical computer encryption protocols. As a result, the United States and many other countries and large companies are dedicating significant funds to quantum research in an effort to ensure the protection of critical encrypted data. Quantum is both an amazing new technology and an imminent security threat.

Continue Reading Quantum Homework for Everyone: New Executive Orders on Quantum Technology

Last week, I had the pleasure of taking the main stage at CincyAI Week in Cincinnati, Ohio to talk with entrepreneurs, business leaders, academics, and artificial intelligence enthusiasts about the current state of AI policy, privacy, and compliance across the United States.

Here are the key takeaways from the presentation.

Continue Reading The State of AI Policy, Privacy, and Compliance in the United States

On May 14, 2026, Colorado Governor Jared Polis signed SB 26-189, the new Colorado artificial intelligence statute which goes into effect January 1, 2027.  SB 26-189 replaces SB 24-205, the  controversial AI statute that had not yet become effective.

SB 26-189 was the result of several years of negotiations between groups seeking more regulation of AI, particularly with respect to consumer protection, and those concerned that SB 24-205 would impose significant costs and burdens on companies with employees, customers or other stakeholders in Colorado. 

Many technology industry participants would rather kiss a Wookiee than comply with SB 24-205 and expressed concern that SB 24-205 would cause technology companies to avoid Colorado due to its burdensome requirements.

Continue Reading Colorado Act Legislation: The AI Strikes Back

Oklahoma has joined the growing chorus of states enacting comprehensive consumer privacy legislation. With the passage of Senate Bill 546, the Sooner State has a new data protection framework taking effect on January 1, 2027.

Here is what businesses need to know.

Continue Reading “Oh What a Beautiful Morning” for Oklahoma Privacy:  Key Takeaways from the Sooner States’ New Consumer Data Protection Law

The Video Privacy Protection Act (VPPA), signed into law by President Ronald Reagan on November 18, 1988, grew out of one of Washington’s more underwhelming privacy scandals. During Judge Robert Bork’s Supreme Court confirmation hearings, a newspaper published his video rental history, which had been leaked by a video store clerk. This incident was intended to reveal his character but revealed nothing too controversial; the Bork Tapes showed that Judge Bork was partial to Alfred Hitchcock films, spy thrillers, and British costume dramas. Indeed, the enduring legacy of the Bork Tapes was not salacious, but legislative— the episode sparked bipartisan concern that something as personal as an individual’s viewing habits could be exposed without consent. In response, Congress moved swiftly to pass the VPPA, a law designed to shield Americans from unwarranted intrusions into their video rental and viewing records.

Continue Reading Defining “Consumer” in the Digital Age: The Supreme Court Takes Up the VPPA Divide

As we begin 2026, Kentucky has officially enacted the Kentucky Consumer Data Protection Act (KCDPA), a comprehensive privacy statute that took effect on January 1, 2026. As with Indiana, is KCDPA is modeled on the now‑familiar Virginia‑style framework. The KCDPA establishes consumer data rights, imposes governance obligations on businesses, and grants exclusive enforcement authority to the Kentucky Attorney General.

Continue Reading Kentucky Consumer Data Protection Act: Key Takeaways for the New Bluegrass Statute

Indiana has joined the growing list of states with a comprehensive consumer privacy statute, codified at Indiana Code 24‑15 and effective January 1, 2026.

The law follows the “Virginia model,” but introduces several nuances that will matter for organizations doing business in, or targeting residents of, Indiana.

Continue Reading HOO- HOO- HOO- HOOSIERS Brace for Indiana Consumer Data Protection Act

President Trump’s Dec. 11, Executive Order, “Ensuring a National Policy Framework for Artificial Intelligence” (the “order”), targets what the administration views as burdensome and fragmented state AI regulation in favor of a single national framework.

Although the order does not overturn any existing or proposed state AI law, it directs federal agencies to challenge certain state AI laws, condition federal funding on compliance with the order, and propose federal preemption legislation.

Continue Reading President Trump Signs Executive Order to Limit State AI Regulation