Listen to this post

California has enacted three new laws governing employer use of artificial intelligence and automated tools in layoffs, workplace monitoring, discipline, and termination. These laws are separate from the California Consumer Privacy Act’s automated decisionmaking technology (ADMT) rules and apply more broadly to employers and public entities that are not covered by the CCPA. CCPA covered employers may need to integrate compliance with ADMT and Risk Assessment requirements (for sensitive personal information processing activities and automated decisionmaking technology).

Updates to Cal/WARN and workplace-surveillance requirements take effect January 1, 2027. The rules for automated discipline and termination decisions take effect July 1, 2027. Employers should use the remainder of 2026 to identify covered systems, assign responsibility, and update their processes and notices.

1. Cal/WARN Notices for AI-Related Job Displacement

Effective January 1, 2027, SB 951 adds disclosure requirements to the California Worker Adjustment and Retraining Notification Act (Cal/WARN). Cal/WARN generally requires 60 days’ advance notice of a covered mass layoff, relocation, or termination at a covered establishment. Violations may result in civil penalties of up to $500 per day, in addition to other remedies. If AI or automation causes all or a substantial part of a covered event by replacing or automating positions, the employer must add specified information to the notices to affected employees and the Employment Development Department (EDD).

Continue Reading California Just Expanded Regulation of Workplace AI Beyond CCPA ADMT
Listen to this post

California has officially entered a new era of artificial intelligence regulation. Governor Newsom has signed Senate Bill 574 (SB 574) into law—a “first-in-the-nation” measure establishing clear statutory boundaries for how attorneys and arbitrators operating in California use generative AI tools in their professional practice.

As a practical matter, effective as of January 1, 2027, SB 574 creates several core obligations for attorneys. Among them: (1) a duty not to enter confidential, personal identifying, or other nonpublic information into a generative AI system unless access to that system is restricted to the attorney and authorized persons bound to protect its confidentiality; (2) a duty to take reasonable steps to verify the accuracy of AI-generated output, including all case and statutory citations, and to correct any “hallucinated” results; and (3) a duty to disclose the use of generative AI to the court for documents submitted.

If you are an attorney or arbitrator navigating the evolving landscape of legal technology, here is what you need to know about the new requirements.

Continue Reading California Enacts First-of-Its-Kind Legislation Governing Lawyer AI Use
Listen to this post

The Pentagon wants commercial AI, and AI companies want the Pentagon’s business. But the terms that make or break these deals are often about data, security, and rights, not algorithms.  That demand runs deep across U.S. defense customers and the defense industrial base, and AI companies are increasingly eager to supply it, directly or through primes, subcontractors, vendors, or technology partners.  These transactions raise consequential legal issues that extend well beyond model performance, bias, or weapons-system integration.  For privacy, security, product, IP, and government contracting teams, the early questions are practical but high-stakes: where the solution will run, what government or contractor data it will touch, whether Controlled Unclassified Information (CUI) will enter the company’s environment, whether prompts and outputs will be retained or reused, and what rights a government or defense customer may seek in AI-related deliverables.

The use case and contracting path both matter. AI sold into the defense market may support logistics, cyber, training, procurement, or other mission-support functions, or it may be integrated into, support, or influence weapons systems, where additional weapons-system rules may apply. Obligations may also depend on how the solution is acquired, including through the General Services Administration (GSA) Multiple Award Schedule, a governmentwide contracting program available to federal agencies. GSA has proposed a rule on basic safeguarding of AI systems and intellectual property rights that, if finalized and included in an applicable procurement, could add obligations related to government data, incident reporting, oversight, and downstream providers as well as potentially broad government ownership of modifications, customizations, configurations, and other broadly defined “Custom Development,” without corresponding rights for the AI provider. Companies should treat both use case and contracting path as threshold diligence questions.

Deployment is equally important. Companies should map where the application runs; where training, tuning, and inference occur; and where prompts, outputs, logs, and customer data are processed or stored. Requirements will differ depending on whether the solution is deployed in a defense agency or prime contractor environment, a customer-controlled environment, or provider-hosted SaaS. Even where the solution runs outside the provider’s environment, the company may still receive Controlled Unclassified Information (CUI) through proposals, implementation, support, or contract administration. Depending on the contract and flowed-down requirements, that may require a segregated environment aligned with NIST SP 800-171, Defense Federal Acquisition Regulation Supplement (DFARS) incident reporting obligations, and potentially Cybersecurity Maturity Model Certification (CMMC) requirements.

Customer data needs a sharp definition. Contracts should clearly address whether government, prime contractor, or subcontractor data may be used to train, fine-tune, or improve the provider’s model or service. For GenAI tools, customer data may appear in prompts, outputs, logs, or telemetry; even if the provider is not “training” on that data, it may still be processing or retaining information subject to enhanced obligations.

Not every “data rights” clause is about privacy or data processing. In defense contracting, data rights address government license and use rights in software, technical data, documentation, outputs, and other deliverables. These clauses can affect product strategy, IP protection, and valuation, so legal teams should identify them early and involve relevant stakeholders before accepting customer or flowed-down terms.

The practical takeaway: before negotiating defense-related contracts or supplier terms, companies should map the data flows, classify the data, confirm the contracting path and applicable flowdowns, and review privacy, cybersecurity, AI governance, government contracting, and data rights issues together.

Listen to this post

California has shut down one increasingly popular theory of website-tracking liability. With Governor Gavin Newsom’s signature, SB 690 amends the California Invasion of Privacy Act (“CIPA”) and eliminates the private right of action under Section 638.51 for pen-register and trap-and-trace claims involving websites, online applications, and mobile applications. Enforcement of Section 638.51 will now rest solely with the California Attorney General’s Office. The legislation responds to a wave of lawsuits alleging that commonplace tools – including cookies, pixels, and other tracking technologies – operate as pen registers by capturing information about users’ online activity.

Limitations on Scope

But the relief is narrower than many businesses initially anticipated. The version introduced in February 2025 would have created a “commercial business purposes” exception not only for Section 638.51 claims, but also for claims under Section 631, CIPA’s wiretapping provision, and Section 632, which governs the recording of confidential communications. That broader language did not survive. Private claims under Sections 631 and 632 therefore remain intact, as does Section 638.51’s substantive prohibition and the Attorney General’s enforcement authority.

Other Avenues for Plaintiffs 

SB 690 narrows the battlefield; it does not end the fight. Sections 631 and 632 still carry statutory-damages exposure of $5,000 per violation. Plaintiffs may also turn to the federal Electronic Communications Privacy Act, the Video Privacy Protection Act, and state wiretap laws.  Our tracking technology litigation heatmap reflects which jurisdictions are experiencing increased filings, notably including Florida and Pennsylvania. Complaints based exclusively on Section 638.51 are the clearest candidates for dismissal, but those cases represent only a subset of the broader CIPA litigation landscape.

Effective Date and Retroactivity 

The amendment takes effect January 1, 2027, and reaches back two years, potentially sweeping in claims filed since the beginning of 2025. Courts may soon have to decide how that retroactivity provision applies to pending cases. The measure’s practical effect will also turn on how quickly the plaintiffs’ bar pivots to surviving CIPA theories under Sections 631 and 632, or to alternative federal and state statutes.

Key Considerations and Action Items

For businesses, they should reassess the procedural posture of each pending matter, preserve arguments concerning SB 690’s retroactive application, and keep website-tracking compliance on the active governance agenda rather than a one-time fix. Regular audits of website technologies, consent and disclosure practices, vendor contracts, data flows, and document oversight remain essential. SB 690 removes one private enforcement route, but it does not necessarily condone the underlying conduct. Website-tracking litigation under CIPA will continue, the next round will simply be fought on a different front.

If you have questions about website tracking technology considerations or any other privacy-related matters, please contact the authors or anyone on our Tracking Technology Litigation & Counseling team.

Listen to this post

If you weren’t quite sure about the EU Cyber Resilience Act, this is what it does:

The Cyber Resilience Act (CRA) Regulation establishes mandatory cybersecurity requirements for “products with digital elements” (PDEs) that are placed on the EU market, in the course of commercial activity, whether in return for payment or free of charge. The stated objectives are: 1) ensuring that manufacturers improve the security of PDEs; 2) a coherent cybersecurity framework for hardware and software producers; 3) enhancing transparency; and 4) enabling businesses and consumers to use products with digital elements securely.

What are PDEs?

PDEs are software or hardware products and their remote data processing solutions, including software or hardware components being placed on the market separately. Remote data processing  is processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the PDE from performing one of its functions.

The scope is intended to cover products that have the ability to exchange digital information (not just respond or activate in response to a signal) and therefore may put it at risk. Further, software downloaded and installed or supplied to the user and that executes on the user’s system (e.g., a browser extension or mobile app downloaded from an app store) is in scope. Hardware and software provided by the same manufacturer in order for a product to function (e.g., drivers or interface apps), are together a PDE, even if supplied separately. But software that executes remotely and is only accessed by the user, is not necessarily a PDE (e.g., websites, unless they support the functionality of a PDE through remote processing).

From last Friday,  manufacturers of PDEs must report actively exploited vulnerabilities and severe security incidents using ENISA’s Single Reporting Platform. This is effectively first CRA deadline for manufacturers. The essential cybersecurity requirements — the ones most compliance programs are built around — don’t arrive until December 11, 2027, so we will not bore you with those here.

Continue Reading The EU Cyber Resilience Act’s Reporting Started last Friday, September 11. Here’s a Very, Very Brief Primer
Listen to this post

California lawmakers have sent Senate Bill 690 to Governor Gavin Newsom, teeing up a narrowing of website-tracking litigation under the California Invasion of Privacy Act (CIPA), who has until September 30 to sign or veto the legislation. If signed, the bill would eliminate private lawsuits asserting website-based “pen register” and “trap and trace” claims under Section 638.51 of CIPA. For businesses that have received demand letters or are defending lawsuits premised on routine website technologies—such as cookies, pixels, analytics tools, or similar tracking technology—the bill would offer relief from certain types of claims asserted under CIPA. Additionally, the bill would apply retroactively to pending claims in actions commenced within two years before its operative date, which is expected to be January 1, 2027, if the bill becomes law. 

The Impetus

The legislation responds to a surge of CIPA claims built on a statute originally designed for telephone-era wiretapping, not modern website traffic. Because CIPA carries statutory damages that can reach at least $5,000 per violation without proof of actual harm, even ordinary commercial web practices have created substantial litigation leverage for plaintiffs to demand large sums from website owners. SB 690 targets that specific theory by removing the private right of action for Section 638.51 claims.

Continue Reading California SB690 – A Bill That Significantly Narrows Website Tracking Claims – Sent to Governor’s Desk
Listen to this post

The California Court of Appeal, Second Appellate District, has issued its tentative ruling in Variety Media, LLC v. Superior Court, the closely watched writ proceeding that asks whether the pen register provisions of the California Invasion of Privacy Act (“CIPA”) apply to common website tracking technologies. The tentative decision would grant Variety’s petition in part and direct the trial court to sustain Variety’s demurrer with leave to amend. The court’s reasoning cuts in both directions. The panel would hold that CIPA’s pen register statute reaches internet communications, rejecting the threshold defense that has anchored many motions to dismiss. But it would also hold that a pen register captures only metadata identifying the destination of an outgoing communication, and that a website visitor’s IP address identifies the source of a communication rather than its destination. Under that construction, the complaint before the court fails to state a claim.

Background

Penal Code section 638.51 prohibits installing or using a pen register without a court order or the user’s consent. Over the past three years, plaintiffs and pro se litigants have filed hundreds (if not thousands) of lawsuits, arbitration demands, and pre-suit letters alleging that cookies, pixels, analytics tools, and similar technologies are unlawful pen registers because they collect visitors’ IP addresses and device information. Trial courts have divided on whether the statute, enacted with telephone surveillance in mind, reaches these tools at all. No California appellate court has answered the question in a published decision.

Continue Reading California Court of Appeal Tentatively Holds That Collecting a Website Visitor’s IP Address Alone Does Not Constitute Pen Register Activity Under CIPA
Listen to this post

On August 11, 2026, the Colorado Department of Law released a single set of proposed rules  substantially building out two 2026 statutes: the Automated Decision-Making Technology Act (“ADMT Act”) and the Conversational Artificial Intelligence Service Operator Requirements (the “Chatbot Safety Act”). Both laws take effect January 1, 2027, and the proposed rules would become effective the same day. The Rules are not yet final – for covered organizations and interested parties the weeks until September 4 are the time to submit comments to be considered for a redraft – and there is a specific ask to help shape the definition of covered ADMT.

The Automated Decision-Making Technology & Conversational Artificial Intelligence Services Rules (“Rules”) clarify open terms and add operational obligations, and they signal that Colorado’s revised AI framework may demand significantly more compliance infrastructure than the statutes alone suggest.

Continue Reading Colorado Releases Proposed Rules for Its AI and Chatbot Safety Laws: These Create More Operational Work than the Statutes Suggest
Listen to this post

Senior United States District Judge William H. Orrick, sitting in the Northern District of California, denied a motion to dismiss last week in an Automated License Plate Recognition (“ALPR”) matter, McGinty v. Reimagined Parking LLC, d/b/a Imperial Parking.[1] Judge Orrick held that the plaintiff plausibly alleged actionable harm based on his “right to know” about the use of ALPR systems in two garages. The order follows Bartholomew v. Parking Concepts, Inc.[2] and the guidance of Mata v. Digital Recognition Network, Inc.,[3] concluding that the California Supreme Court would likely recognize violation of a consumer’s “right to know” as actionable harm under California’s ALPR law if presented with the question.

The decision is significant because it marks the first time a federal judge adopted the state-court trajectory created in Bartholomew and Mata. Bartholomew treated the alleged failure to make required ALPR disclosures in an ALPR Privacy Policy as an actionable injury to a consumer’s right to know under the law. Though Mata did not deal with the failure to present an ALPR Privacy Policy, the decision in Mata did offer further guidance on how courts should analyze asserted ALPR harms.

Continue Reading Federal Court Follows Bartholomew Reasoning in Denying Motion to Dismiss ALPR Lawsuit
Listen to this post

Seyfarth Synopsis: On Thursday 30 July, the European Commission issued a press release advising that EU AI Act enforcement begins this SUNDAY, 2 August 2026, when the Act’s transparency rules start to apply. Chatbots and other interactive AI systems need to be ready to identify themselves. Deepfakes and AI generated content needs to be labelled. There are limited exceptions.

The EU AI Act’s Article 50 transparency obligations apply broadly, with the stated goal of reducing the risks of impersonation, deception, misinformation and manipulation at scale and fraud and mitigating the potential detrimental effects of AI generated or manipulated content and interactions. Organizations (and in some cases, individuals) using chatbots, generative AI, deepfake functionality, emotion recognition, biometric categorization, or AI-generated public-interest content should assess whether disclosures, labeling, or content-marking requirements apply without delay. The principal exception is a short implementation period for the Article 50(2) machine-readable marking requirement. Under the EU’s Digital Omnibus reforms, providers of certain generative AI systems already placed on the EU market before August 2, 2026 have until December 2, 2026 to implement those marking measures, while the remaining Article 50 transparency obligations continue to take effect on August 2, 2026. Noncompliance carries fines of up to €15 million or 3% of total worldwide turnover.

Continue Reading European Commission Press Release: EU AI Act Transparency Enforcement Starts This Sunday! Do You Know Who Your Chatbots Are? We Break Down the Commission’s Guidelines on Transparency Below