Photo of Yana Komsitsky

On August 11, 2026, the Colorado Department of Law released a single set of proposed rules  substantially building out two 2026 statutes: the Automated Decision-Making Technology Act (“ADMT Act”) and the Conversational Artificial Intelligence Service Operator Requirements (the “Chatbot Safety Act”). Both laws take effect January 1, 2027, and the proposed rules would become effective the same day. The Rules are not yet final – for covered organizations and interested parties the weeks until September 4 are the time to submit comments to be considered for a redraft – and there is a specific ask to help shape the definition of covered ADMT.

The Automated Decision-Making Technology & Conversational Artificial Intelligence Services Rules (“Rules”) clarify open terms and add operational obligations, and they signal that Colorado’s revised AI framework may demand significantly more compliance infrastructure than the statutes alone suggest.

Continue Reading Colorado Releases Proposed Rules for Its AI and Chatbot Safety Laws: These Create More Operational Work than the Statutes Suggest

Seyfarth Synopsis: On Thursday 30 July, the European Commission issued a press release advising that EU AI Act enforcement begins this SUNDAY, 2 August 2026, when the Act’s transparency rules start to apply. Chatbots and other interactive AI systems need to be ready to identify themselves. Deepfakes and AI generated content needs to be labelled. There are limited exceptions.

The EU AI Act’s Article 50 transparency obligations apply broadly, with the stated goal of reducing the risks of impersonation, deception, misinformation and manipulation at scale and fraud and mitigating the potential detrimental effects of AI generated or manipulated content and interactions. Organizations (and in some cases, individuals) using chatbots, generative AI, deepfake functionality, emotion recognition, biometric categorization, or AI-generated public-interest content should assess whether disclosures, labeling, or content-marking requirements apply without delay. The principal exception is a short implementation period for the Article 50(2) machine-readable marking requirement. Under the EU’s Digital Omnibus reforms, providers of certain generative AI systems already placed on the EU market before August 2, 2026 have until December 2, 2026 to implement those marking measures, while the remaining Article 50 transparency obligations continue to take effect on August 2, 2026. Noncompliance carries fines of up to €15 million or 3% of total worldwide turnover.

Continue Reading European Commission Press Release: EU AI Act Transparency Enforcement Starts This Sunday! Do You Know Who Your Chatbots Are? We Break Down the Commission’s Guidelines on Transparency Below

The handbrake has been pulled on aspects of the EU’s AI Act (Act), with key workplace rules, particularly those on high-risk systems, pushed back from August 2, 2026, to December 2, 2027. 

The delay may feel welcome for multinational employers keeping up with the spread of AI adoption across their organization, but it is an opportunity to get the groundwork done. 

The European Commission in late May published draft guidelines on the classification of high-risk AI systems (Guidelineshttps://bit.ly/4vDtgOV) for the Act. This is the clearest indication yet of how EU workplace AI tools will be treated, using many real examples.

 To function efficiently across borders, business must incorporate these rules into their global compliance framework for legal, HR, talent acquisition, procurement, IT, data, compliance and operations. 

The extra months are useful runway, because HR, recruitment, performance management and workforce allocation tools will require the full gamut of “high-risk” systems compliance. Global employers need time to work this into a matrix of other global rules — including in multiple US jurisdictions (e.g., California, Colorado, Connecticut, New York), Canada, Korea’s Basic AI Act, the updated UK GDPR and emerging rules elsewhere. 

Below is a pragmatic look at what use cases trigger the Act, and what global employers need to do from governance, procurement, data protection and employee relations perspectives. 

Continue Reading Workplace AI — How Employers Should Prepare for the New EU AI Act Deadline

As another piece of harmonization legislation, the AI Act is unsurprisingly reminiscent in regulatory philosophy to the GDPR. Many of the same data principles (transparency, accuracy, security) are present, as is an explicit risk-based approach. Understanding precisely where there is overlap with your existing GDPR program is a head start in your AI Act compliance program design. But it is also important to recognize where the two frameworks diverge. The GDPR regulates what happens to personal data, the legal basis for collection, how it is used, how long it is kept, who can access it. The AI Act generally regulates the AI system itself – namely, how it is designed, tested, documented, governed, and deployed. While that difference in regulatory object creates structural differences in inputs and outputs, the framework itself does have a lot of commonalities.

This post suggests a strategy for efficiently building a unified compliance framework for both regimes.

Continue Reading One Compliance Program for Two Frameworks: Aligning the EU AI Act and GDPR for Efficiency

On July 24, 2025, the California Privacy Protection Agency (“CPPA”) unanimously voted to adopt a package of Proposed Regulations for the California Consumer Privacy Act (“CCPA”), marking a significant development in California privacy law. These cover Automated Decision-making Technology (“ADMT”), mandatory Cybersecurity Audits, Risk Assessments, and clarifications for the CCPA’s applicability to Insurance Companies. The package will move into its final review stage before formal enactment, once filed with the California Office of Administrative Law.

CCPA Steering Toward Operational Compliance

This is a clear signal that privacy compliance expectations in California are trending toward a more operational phase. The new rules are designed to give Californians greater control over how their personal information is used while pushing businesses toward higher levels of transparency and accountability, especially when automated decision-making and high-risk data processing is involved. For companies, this is more than just a theoretical update – it’s a clarion call to ensure these requirements are built into day-to-day governance, technology and process design, and vendor management practices.

Continue Reading California Privacy Protection Agency (CPPA) Finally Voted to Adopt Much Debated Update to CCPA Regulations: What Your Business Should Know

The UK’s Data (Use and Access) Act received Royal Assent last Thursday, June 19th, bringing into law some significant changes to the country’s post Brexit data protection framework, among an array of other, related rules (on matters ranging from financial conduct to smart meters and “underground assets,” which is more to do with

The Personal Data Protection (Amendment) Bill 2024 (“PDPB”) was at last passed by the Malaysian Parliament at the end of July. After Royal Assent and publishing, it will become law (on a date to be determined by the Minister of Digital to be specified in the Gazette). The PDPB introduced several changes intended to better align Malaysia’s 2010 Personal Data Protection Act with global standards.

Continue Reading Malaysian Parliament Passes Personal Data Protection (Amendment) Bill 2024

On October 5, 2023, Seyfarth offered a Masterclass, hosted by Lexology, which was designed to familiarize in-house counsel and privacy professionals, in and out of Washington state, with the My Health My Data Act legislation. Portions of the Act are already in effect and go into further effect on March 31, 2024.

We explored its

Thursday, October 5, 2023
1:00 p.m. – 2:00 p.m. ET
12:00 p.m. – 1:00 p.m. CT
11:00 a.m. – 12:00 p.m. MT
10:00 a.m. – 11:00 a.m. PT

REGISTER HERE

About the Program

Seyfarth is pleased to offer this Masterclass, hosted by Lexology, which is designed to familiarize in-house counsel and privacy professionals, in and

On July 10th, the European Commission issued its Implementing Decision regarding the adequacy of the EU-US Data Privacy Framework (“DPF”). The Decision has been eagerly awaited by US and Europe based commerce, hoping it will help business streamline cross-Atlantic data transfers, and by activists who have vowed to scrutinize the next framework arrangement (thereby maintaining their relevance). Regardless of the legal resiliency of the decision, it poses an interesting set of considerations for US businesses, not the least of which is whether or not to participate in the Framework.

For those who followed the development and demise of the Privacy Shield program and the Schrems II case, it has been apparent for some time that the fundamental objection of the activists and the Court of Justice of the EU (“CJEU”) to the original Privacy Shield was the perception that the US intelligence community had an ability to engage in disproportional data collection without any possibility of recourse by EU residents whose personal information may be swept into an investigation. The actual functioning of the program for the certifying businesses were much less controversial.

Since the structure of the program wasn’t the primary reason for Privacy Shield’s revocation, from a business perspective, the current DPF looks a lot like the old Privacy Shield. For businesses who made the decision to participate in the Privacy Shield program in the past, the operational burden shouldn’t be much different under the new DPF, if they have already taken steps to operationalize the requirements.

What is interesting about the new DPF is how it may impact a company’s decision to choose  between the Standard Contractual Clauses (“SCCs”) and the alternative adequacy mechanism for transfers. There is also some interest vis-à-vis the DPF and its interactions with state privacy laws.

Continue Reading Adequacy for the US (kind of) – But What Are the Side Effects?