State Privacy Laws

A new wave of comprehensive state privacy laws is on the horizon for 2026 and beyond. Alabama, Louisiana, Oklahoma, and Vermont have each enacted consumer data privacy statutes that will come online over the next few years, extending the patchwork and raising the stakes for multi‑state compliance programs.

Below, we provide the general thresholds for each law and a few additional key takeaways.

Continue Reading Coming Soon Near You: New Privacy Laws in Alabama, Louisiana, Oklahoma, and Vermont

California’s Delete Request and Opt-Out Platform (DROP) requirements went into effect on August 1, 2026, marking a meaningful operational shift for regulated data brokers and a clear reminder that enforcement of the Delete Act is no longer theoretical.

Separately, several other states have advanced their own data broker frameworks. New Jersey introduced an aggressive data broker regime, Connecticut expanded its privacy law to build out a data broker registration and centralized deletion framework, and Vermont updated its existing data broker law. Against that backdrop, and with regulators taking action, it is a good time for personal data-driven companies to take stock of their compliance obligations and risk exposure under these evolving data broker laws.

Continue Reading Just DROPped: A Data Broker Law Update

The California Information Privacy Act (CIPA) has become a go‑to vehicle for plaintiffs’ counsel attacking website tracking technologies, such as cookies, pixels, beacons, chat bots, and video or session replay tools.

Over the last few years, website operators have been hit with a wave of demand letters claiming CIPA violations. But the tide may be shifting – marking smoother sailing for website operators. A recent decision from a California court narrows CIPA to telephonic communications and significantly undercuts the viability of CIPA claims against commercial websites.

Continue Reading Changing Tides: A Los Angeles Court Delivers a Major CIPA Defense Win

Last week, I had the pleasure of taking the main stage at CincyAI Week in Cincinnati, Ohio to talk with entrepreneurs, business leaders, academics, and artificial intelligence enthusiasts about the current state of AI policy, privacy, and compliance across the United States.

Here are the key takeaways from the presentation.

Continue Reading The State of AI Policy, Privacy, and Compliance in the United States

On June 4, 2026, Representatives Jay Obernolte and Lori Trahan released a discussion draft of the Great American Artificial Intelligence Act of 2026 (GAAIA). The GAAIA is the latest federal attempt at timely and coherent technology-based regulations.

This bill, however, takes a notably different approach. Narrow enough to be effective, GAAIA sidesteps the pitfalls that have plagued federal privacy law efforts by limiting scope and preemption. Not yet formally introduced, this nearly 270-page discussion draft seems to mostly target the big players (the large AI companies building foundational AI models) and is centered around transparency and innovation.

This article covers the key provisions of GAAIA, what organizations are actually in the crosshairs, and how it fits alongside the June 2nd Executive Order related to artificial intelligence.

Continue Reading The Great American Artificial Intelligence Act: An Attempt to Federally Regulate AI

Connecticut’s Governor Ned Lamont announced on May 29, 2026 that he had ratified sweeping artificial intelligence legislation in Senate Bill 5, titled “An Act Concerning Online Safety.” The law is unique in its breadth among the growing list of state AI laws, in that it regulates several distinct applications or categories of AI.

Specifically, the law addresses: 1) subscription-based AI services; 2) frontier AI models; 3) automated employment-related decision technology; 4) AI companions; and 5) AI in social media. Below, we summarize certain requirements pertaining to each regulated topic.

Continue Reading Connecticut Enacts Sweeping AI Legislation

On May 14, 2026, Colorado Governor Jared Polis signed SB 26-189, the new Colorado artificial intelligence statute which goes into effect January 1, 2027.  SB 26-189 replaces SB 24-205, the  controversial AI statute that had not yet become effective.

SB 26-189 was the result of several years of negotiations between groups seeking more regulation of AI, particularly with respect to consumer protection, and those concerned that SB 24-205 would impose significant costs and burdens on companies with employees, customers or other stakeholders in Colorado. 

Many technology industry participants would rather kiss a Wookiee than comply with SB 24-205 and expressed concern that SB 24-205 would cause technology companies to avoid Colorado due to its burdensome requirements.

Continue Reading Colorado Act Legislation: The AI Strikes Back

Among the growing number of state AI statutes, multiple states have now enacted laws governing the use of artificial intelligence technology by health insurers when determining whether or not to cover claims.

This article outlines some considerations for insurers, focusing on Nebraska, Georgia and Colorado statutes. 

Continue Reading AI and Insurance Claims: Beware Fully Automated Decision Making

Last week, on May 8, 2026, the public comment period for New York City’s own version of the “click-to-cancel rule” closed. The proposed rule (NYC Subscription Rule) was issued following an Executive Order from January 2026 by New York City Mayor, Zohran Mamdani, which focuses on ensuring New Yorkers are not forced to remain in unwanted subscriptions.

This Executive Order focuses on ensuring New Yorkers are not stuck with subscriptions. Under the Executive Order, NYC’s Department of Consumer and Work Protection (DCWP) will prioritize monitoring, investigating and taking enforcement action against subscription-related practices that deceive or mislead consumers.

Continue Reading Click‑to‑Cancel Comes to NYC: The Big Apple Cracks Down on Bad Apples (i.e., Bad Subscription Practices)

State privacy regulators continue to focus on consumers’ rights to opt out of the sale of personal information and targeted advertising, signaling that this issue remains a top enforcement priority across the United States.

As comprehensive state privacy laws mature, regulators are increasingly emphasizing not just the existence of opt‑out mechanisms, but whether businesses are properly honoring them in practice, particularly when those signals are conveyed through universal opt‑out tools such as the Global Privacy Control.

Continue Reading States Continue to Focus on the Right to Opt‑Out of the Sale of Personal Information and Targeted Advertising