On August 11, 2026, the Colorado Department of Law released a single set of proposed rules  substantially building out two 2026 statutes: the Automated Decision-Making Technology Act (“ADMT Act”) and the Conversational Artificial Intelligence Service Operator Requirements (the “Chatbot Safety Act”). Both laws take effect January 1, 2027, and the proposed rules would become effective the same day. The Rules are not yet final – for covered organizations and interested parties the weeks until September 4 are the time to submit comments to be considered for a redraft – and there is a specific ask to help shape the definition of covered ADMT.

The Automated Decision-Making Technology & Conversational Artificial Intelligence Services Rules (“Rules”) clarify open terms and add operational obligations, and they signal that Colorado’s revised AI framework may demand significantly more compliance infrastructure than the statutes alone suggest.

Continue Reading Colorado Releases Proposed Rules for Its AI and Chatbot Safety Laws: These Create More Operational Work than the Statutes Suggest

Seyfarth Synopsis: On Thursday 30 July, the European Commission issued a press release advising that EU AI Act enforcement begins this SUNDAY, 2 August 2026, when the Act’s transparency rules start to apply. Chatbots and other interactive AI systems need to be ready to identify themselves. Deepfakes and AI generated content needs to be labelled. There are limited exceptions.

The EU AI Act’s Article 50 transparency obligations apply broadly, with the stated goal of reducing the risks of impersonation, deception, misinformation and manipulation at scale and fraud and mitigating the potential detrimental effects of AI generated or manipulated content and interactions. Organizations (and in some cases, individuals) using chatbots, generative AI, deepfake functionality, emotion recognition, biometric categorization, or AI-generated public-interest content should assess whether disclosures, labeling, or content-marking requirements apply without delay. The principal exception is a short implementation period for the Article 50(2) machine-readable marking requirement. Under the EU’s Digital Omnibus reforms, providers of certain generative AI systems already placed on the EU market before August 2, 2026 have until December 2, 2026 to implement those marking measures, while the remaining Article 50 transparency obligations continue to take effect on August 2, 2026. Noncompliance carries fines of up to €15 million or 3% of total worldwide turnover.

Continue Reading European Commission Press Release: EU AI Act Transparency Enforcement Starts This Sunday! Do You Know Who Your Chatbots Are? We Break Down the Commission’s Guidelines on Transparency Below

The handbrake has been pulled on aspects of the EU’s AI Act (Act), with key workplace rules, particularly those on high-risk systems, pushed back from August 2, 2026, to December 2, 2027. 

The delay may feel welcome for multinational employers keeping up with the spread of AI adoption across their organization, but it is an opportunity to get the groundwork done. 

The European Commission in late May published draft guidelines on the classification of high-risk AI systems (Guidelineshttps://bit.ly/4vDtgOV) for the Act. This is the clearest indication yet of how EU workplace AI tools will be treated, using many real examples.

 To function efficiently across borders, business must incorporate these rules into their global compliance framework for legal, HR, talent acquisition, procurement, IT, data, compliance and operations. 

The extra months are useful runway, because HR, recruitment, performance management and workforce allocation tools will require the full gamut of “high-risk” systems compliance. Global employers need time to work this into a matrix of other global rules — including in multiple US jurisdictions (e.g., California, Colorado, Connecticut, New York), Canada, Korea’s Basic AI Act, the updated UK GDPR and emerging rules elsewhere. 

Below is a pragmatic look at what use cases trigger the Act, and what global employers need to do from governance, procurement, data protection and employee relations perspectives. 

Continue Reading Workplace AI — How Employers Should Prepare for the New EU AI Act Deadline

When Colorado enacted the first comprehensive state AI law in 2024, it imported the conceptual architecture of the EU AI Act: a risk-based regime built on duties of care, risk management programs, and impact assessments. Two years later, and within a matter of weeks, the state has dismantled that legislation. On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189, which repeals SB 24-205 and replaces it with a disclosure-and-rights framework focused on automated decision-making technology (“ADMT”). The new framework takes effect January 1, 2027.

The substance of the rewrite has been well-covered already. Less examined is how Colorado got here, and what the speed and direction of the pivot signal for the rest of the state AI regulatory landscape. The new bill was introduced and signed within two weeks of its introduction. The Governor’s AI Policy Working Group did the heavy lift in advance: roughly six months of stakeholder consultation produced the draft framework released on March 17, 2026. But the final two-week sprint reflects pressure to land the rewrite before the original AI Act’s June 30, 2026 effective date and amid escalating federal headwinds.

Continue Reading Colorado’s AI Reset: Two Weeks, a White House Callout, and a Pivot Away from the EU Model

Legal500 featured an article by Seyfarth partners Kathleen McConnell and Lauren Gregory Leipold, and associate Daniel Riley“AI Governance In (and Beyond) Privacy: Regulatory Tensions in Automated Decision‑Making, the Digital Authenticity Crisis, and Restrictions on Professional Use.

The piece, published as a part of the Legal500 Country Comparative Guides, examines the rapidly

The lesson from the PocketOS database deletion is not that agentic AI is dangerous. It’s about governance and controls.

You have probably seen some version of the headline by now: “AI Agent Deletes Company’s Entire Database in 9 Seconds.” It is a compelling story. But the headline, while technically accurate, obscures the far more important lesson buried in the details.

So what actually happened? PocketOS, a small SaaS company that makes software for car rental businesses, was using a popular AI-powered code editor running on Anthropic’s Claude Opus 4.6 model. The AI agent was tasked with resolving a routine issue in a staging environment. When it hit a credential mismatch, the agent decided on its own initiative to “fix” the problem by deleting a volume on Railway, the company’s cloud hosting provider. The agent found a password in an unrelated file and used it to execute a deletion command. Because of permissions made available to the agent and the way access to the infrastructure was configured, that single command using a password which was valid across all systems wiped both the production database and all associated backups.  

The agent, when asked to explain itself, produced what multiple outlets described as a “confession,” acknowledging it had violated its own safety instructions. The story has gone viral. The framing in most coverage puts the AI squarely at the center of the narrative: the agent “went rogue,” it “confessed,” it acted autonomously and destroyed a business. But the reports are not entirely accurate and usually miss the point.

Continue Reading The AI Didn’t Go Rogue. Guardrails Were Never There.

Introduction

Robotics and artificial intelligence are converging at an unprecedented pace. As robotics systems increasingly integrate AI-driven decision-making, businesses are unlocking new efficiencies and capabilities across industries from manufacturing and logistics to healthcare and real estate.

Yet this convergence introduces complex legal and regulatory challenges. Companies deploying AI-enabled robotics must navigate issues related to data privacy, intellectual property, workplace safety, liability, and compliance with emerging AI governance frameworks.

The Shift: Robotics as an AI Subset

Traditionally, robotics was viewed as a standalone discipline focused on mechanical automation. Today, robotics is increasingly powered by machine learning algorithms, natural language processing, and predictive analytics—hallmarks of AI technology.

This evolution raises critical questions for legal teams:

  • Who owns the data generated by AI-enabled robots?
  • How do we allocate liability when autonomous systems make decisions without human intervention?
  • What contractual safeguards should be in place when outsourcing robotics solutions to third-party vendors?

As robotics increasingly incorporates AI functionality, traditional contract structures for hardware procurement and service agreements require significant updates. This evolution introduces new risk categories that must be addressed through precise drafting and negotiation.

Continue Reading The AI-Driven Evolution of Robotics
test

You may have recently seen press reports about lawyers who filed and submitted papers to the federal district court for the Southern District of New York that included citations to cases and decisions that, as it turned out, were wholly made up; they did not exist.  The lawyers in that case used the generative artificial intelligence (AI) program ChatGPT to perform their legal research for the court submission, but did not realize that ChatGPT had fabricated the citations and decisions.  This case should serve as a cautionary tale for individuals seeking to use AI in connection with legal research, legal questions, or other legal issues, even outside of the litigation context.

In Mata v. Avianca, Inc.,[1] the plaintiff brought tort claims against an airline for injuries allegedly sustained when one of its employees hit him with a metal serving cart.  The airline filed a motion to dismiss the case. The plaintiff’s lawyer filed an opposition to that motion that included citations to several purported court decisions in its argument. On reply, the airline asserted that a number of the court decisions cited by the plaintiff’s attorney could not be found, and appeared not to exist, while two others were cited incorrectly and, more importantly, did not say what plaintiff’s counsel claimed. The Court directed plaintiff’s counsel to submit an affidavit attaching the problematic decisions identified by the airline.

Continue Reading Use of ChatGPT in Federal Litigation Holds Lessons for Lawyers and Non-Lawyers Everywhere

Seyfarth Synopsis: Since ChatGPT became available to the public at large in November 2022, employers have been wondering, and asking their employment lawyers, “What kind of policies should we be putting in place around the use of ChatGPT in the workplace?”  Although at this stage it is difficult to imagine all of the different ways ChatGPT, and its subsequent iterations, could be used by employees in the workplace, it is important to consider some of the more obvious usage cases and how employers might choose to address them in workplace policies.

What is ChatGPT?

ChatGPT is a form of artificial intelligence (AI) — an AI language model that is trained to interact in a conversational way.  At its most basic level, AI is a computer system able to perform tasks that normally require human intelligence.  In order to achieve this, AI needs to be trained.  First, massive data sets are fed into a computer algorithm.  Then the trained model is evaluated in order to determine how well it performs in making predictions when confronted with previously unseen data.  For ChatGPT, it is predicting the next word in a given context to provide that conversational tone for which it has become known.  Lastly, the AI goes through a testing phase to find out if the model performs well on large amounts of new data it has not seen before.  This is the phase in which ChatGPT finds itself. 

Continue Reading ChatGPT – What Employers Should Be Worried About Now