About
Privacy

Privacy

Tracking Privacy legal and regulatory developments.

46 entries in In-House Counsel Tracker

LawSnap Briefing Updated May 11, 2026

State of play.

  • State enforcement is the dominant vector. The Florida AG has launched a formal investigation into OpenAI and ChatGPT citing national security concerns, and California's Privacy Protection Agency has opened rulemaking on CCPA employee data obligations — both moving through existing statutory authority without waiting for federal action .
  • Biometric and health data from consumer tech products are the sharpest compliance edge. Omnibus state privacy laws in California, Connecticut, Indiana, Kentucky, Rhode Island, Washington, and Nevada now classify facial-mapping, body-scan, and wearable health data as sensitive personal information, with state AGs actively investigating tracking practices in the fashion and beauty sectors .
  • Shadow AI inside the enterprise is a live data-breach and regulatory exposure. A 2025 Gartner survey found 69% of organizations have confirmed or suspect prohibited generative AI tool use; a third of employees admit sharing enterprise research or datasets through unsanctioned platforms .
  • Standing doctrine is tightening in federal privacy litigation. The Southern District of Florida dismissed a DPPA class action with prejudice for lack of concrete injury, signaling that data-misuse alone — without tangible financial harm — will not clear Article III in at least some circuits .
  • For counsel advising technology companies, consumer brands, or employers, the practical baseline is a multi-front exposure: state AG enforcement through existing law, an accelerating patchwork of sector-specific biometric and health-data rules, and an internal AI-governance gap that creates breach and regulatory risk before any incident occurs.

Where things stand.

  • State omnibus privacy laws are now operative across a majority of U.S. commerce. California, Connecticut, Indiana, Kentucky, Rhode Island, Washington, and Nevada have enacted consumer privacy frameworks with sensitive-data tiers covering biometrics and consumer health information; enforcement is active, not theoretical .
  • CCPA employee data coverage is hardening. The employment exemption expired January 1, 2023; the California Privacy Protection Agency is now examining whether current notice and disclosure rules require employment-specific revisions, following a 2023 AG enforcement sweep against large employers .
  • New York's synthetic-performer consent regime takes effect June 19, 2026. The Fashion Workers Act and synthetic performer disclosure laws require explicit consent before digital replication of human likenesses and mandate disclaimers for AI avatars in advertising; California has enacted parallel consent laws (AB 2602/AB 1836) .
  • Surveillance pricing is emerging as a distinct privacy-enforcement category. The FTC's Section 6(b) study on consumer-data-driven individualized pricing is active; more than 40 state bills have been introduced in 2026 targeting the practice, and the House Oversight Committee has launched a formal investigation into revenue management algorithms .
  • DPPA standing doctrine is unsettled across circuits. The S.D. Florida dismissal in Cicale v. Professional Parking Management requires tangible injury beyond data misuse; parallel DPPA cases involving Carfax's crash-report data in Maryland are surviving dismissal — courts are distinguishing data-commercialization models .
  • Shadow AI governance is an unresolved enterprise liability. A 2025 Gartner survey found 69% of organizations have confirmed or suspect prohibited generative AI tool use; 27% of employees have exposed employee data through unsanctioned tools, and 23% have input company financial information — creating HIPAA, financial-services, and state privacy exposure simultaneously .
  • Data litigation is broadening beyond tech companies. Claims centered on algorithmic bias, unauthorized data use, AI system liability, and worker surveillance now reach organizations of every size; courts are currently establishing precedents on data ownership, AI procurement obligations, and corporate accountability for algorithmic harms .
  • Federal AI regulatory framework remains contested. The White House "America's AI Action Plan" rejects broad federal regulation in favor of corporate self-management; a Sanders-AOC federal moratorium proposal represents the opposing pole; no comprehensive federal privacy or AI statute has been enacted .

Latest developments.

Active questions and open splits.

  • How far does concrete-injury standing doctrine extend in federal privacy suits? The S.D. Florida DPPA dismissal requires tangible harm beyond data misuse; the Maryland Carfax case is surviving — the split turns on data-commercialization model, but no circuit has resolved the broader question of when statutory privacy violations alone satisfy Article III .
  • Will federal preemption displace state AI and synthetic-performer consent regimes? The December 2025 White House EO seeks federal harmonization of conflicting state AI laws; New York and California have enacted consent mandates that may collide with any federal preemption framework — the interaction is unresolved before New York's June 19 effective date .
  • What constitutes an adequate CCPA employee privacy notice? The CalPrivacy Agency's rulemaking is examining whether current rules require employment-specific revisions; until final rules issue, employers face uncertainty about what notice architecture satisfies the statute .
  • Where is the line between lawful dynamic pricing and actionable surveillance pricing? Regulators are drawing a distinction between market-condition-based pricing and consumer-data-driven individualized pricing, but no court has defined the boundary; companies using revenue management algorithms face simultaneous FTC investigation and multi-state legislative exposure .
  • What governance framework satisfies the duty to prevent shadow AI data exposure? No regulator has issued guidance on what internal controls are required; HIPAA, financial-services, and state privacy regulators could each assert jurisdiction over breaches originating from unsanctioned employee AI use, and the allocation of liability between employer and tool provider is untested .
  • How will courts allocate liability for algorithmic harms across the data supply chain? Early litigation is establishing precedents on data ownership, AI procurement obligations, and corporate accountability for algorithmic bias and worker surveillance — the rules are being written in real time, with no settled framework .

What to watch.

  • CalPrivacy Agency final rules on CCPA employee data notices — whatever issues from this rulemaking will become the compliance floor for all California employers and a template other states will reference.
  • New York Fashion Workers Act and synthetic performer disclosure law enforcement posture after the June 19, 2026 effective date — first enforcement actions will define what "explicit consent" and "clear disclaimer" require in practice.
  • EU AI Act labeling requirements effective August 2026 — the penalty structure (up to €15 million) will drive multinational compliance decisions that affect U.S. operations.
  • FTC Section 6(b) surveillance pricing study output and any resulting rulemaking — the agency's framing of the dynamic-pricing versus consumer-data-pricing distinction will set the enforcement standard nationally.
  • Whether additional state AGs follow Florida's template of investigating AI companies through existing consumer protection and national security authority — the Florida OpenAI probe is the leading indicator of a broader enforcement pattern.
  • Resolution of the DPPA circuit split on concrete injury — if the Maryland Carfax case produces a ruling inconsistent with the S.D. Florida dismissal, a circuit conflict on statutory privacy standing becomes a cert-worthy question.

46 Contributing Entries

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based law firm, faces two proposed class-action lawsuits over a data breach that exposed sensitive information on 57,554 current, former, and prospective clients. The breach occurred in May 2026 when a cybercriminal impersonated the firm's IT department and convinced an attorney to upload client files to an external Google Drive account. The exposed data includes names, Social Security numbers, addresses, dates of birth, driver's license numbers, passport numbers, medical records, and health insurance information. Blank Rome announced the breach to affected clients on June 26, 2026—nearly a month after the incident occurred. The firm stated it will "aggressively defend" against the suits and claims they lack merit.

26 Meta Employees Sue Company Over AI-Driven Layoffs Targeting Disabled and Leaved Workers

Twenty-six current and former Meta employees filed a federal lawsuit Monday in the U.S. Northern District Court of California alleging the company used artificial intelligence systems to systematically target workers with disabilities or those on protected medical, parental, or family leave during its May 2024 mass layoff. The plaintiffs claim Meta replaced managerial discretion with AI-driven metrics—including productivity scores, keystroke monitoring, and AI token consumption data—to generate termination lists, effectively penalizing employees for approved absences. The complaint names specific tools including Metamate, Meta's internal AI assistant, and employee-built monitoring dashboards that allegedly recorded absences as "disengagement" and suppressed performance ratings. One plaintiff was terminated while on approved pre-birth leave; another alleges a manager discouraged medical leave by warning that leadership would "definitely" fire them if they took it.

Brands Warn as Creators Flood TikTok Shop with AI Avatar Affiliate Videos

TikTok Shop is being flooded with AI-generated product demonstrations, fake creator personas, and duplicate avatars that are undercutting human creators and eroding consumer trust. Merchants and affiliate creators are using TikTok's built-in AI tools to mass-produce makeup tutorials, clothing reviews, and product showcases without holding inventory—a low-cost strategy that prioritizes algorithmic reach over authenticity. Some operators have deployed synthetic personas, including a fabricated Black creator named "Aliyah," to sell dropshipped goods from retailers like Shein, exploiting algorithmic biases that reward emotional connection to creators.

Former Mayo Clinic AI Director Sues System Over Alleged Retaliation and AI Safety Cover-Up

Traci Tamiko Eto, former research director at Mayo Clinic, filed a federal lawsuit on July 6, 2026, alleging retaliation and wrongful termination after she raised concerns about AI safety failures and patient privacy violations. According to the complaint, Eto was demoted in July 2025, placed on involuntary medical leave, and fired in December 2025 when her position was eliminated in a reduction in force that reportedly affected only her role. The suit was filed in U.S. District Court for the District of Minnesota under the False Claims Act's retaliation provision, the Americans with Disabilities Act, and the Family and Medical Leave Act.

North Korean Laptop Farms Enable $5M Identity Fraud Scheme Posing as U.S. Remote Workers

The Department of Justice announced the sentencing of two U.S. nationals for operating a multiyear scheme that deployed North Korean IT workers under stolen American identities to infiltrate over 100 U.S. companies. Kejia Wang, 42, and Zhenxing Wang, 39, used at least 80 fraudulent identities to secure remote positions across the corporate sector, generating more than $5 million in illicit revenue for the DPRK regime. The operation relied on "laptop farms"—physical U.S.-based facilities hosting computers that allowed overseas workers to bypass location-based security checks, making employers believe they were hiring domestically based remote staff.

UN releases 2026 International AI Safety Report warning of enormous benefits and existential risks

The United Nations released the International AI Safety Report 2026, a comprehensive assessment concluding that advanced artificial intelligence presents both transformative opportunities and escalating dangers. The report, led by the UN agency for digital technology, finds that AI can accelerate development in health, education, and financial services in developing nations while simultaneously enabling cyberattacks, deepfake fraud, non-consensual intimate imagery, and biological weapon design. The core finding: AI capabilities in critical fields like biological research are advancing faster than governance frameworks, creating a dangerous gap between what is technologically possible and what remains safe.

Anthropic Banned from U.S. Federal Use After DOJ Refuses Unrestricted AI for Military Surveillance

In early 2026, the Trump administration ordered all federal agencies to cease using Anthropic's Claude AI models and designated the company a "Supply-Chain Risk to National Security" under the Federal Acquisition Supply Chain Security Act. The conflict originated when the Department of Defense demanded unrestricted access to Claude for "all lawful purposes," including potential use in autonomous weapons and domestic surveillance. Anthropic refused, citing civil liberties and human rights concerns. On February 27, President Trump issued an immediate cease directive with a six-month phase-out period. By March 5, the DOD's supply-chain designation took effect, barring military contractors from any commercial activity with Anthropic and removing the company from federal procurement systems.

FTC Seeks Public Comment on AI Policy Statement Curbing Ideological Manipulation

The Federal Trade Commission has opened a public comment period on a proposed policy statement addressing AI companies' manipulation of system outputs to serve undisclosed ideological objectives. The FTC asserts that such conduct violates Section 5 of the FTC Act by constituting unfair or deceptive practices that undermine consumer expectations for accuracy and objectivity. Comments are due by July 31, 2026, and will be published on Regulations.gov. FTC Chairman Andrew N. Ferguson authorized the notice with a 2-0 vote and invited feedback from businesses and consumers about their experiences with AI system manipulation.

Judge Approves $46.75M Bankruptcy Settlement for 23andMe 2023 Data Breach Victims

A U.S. bankruptcy judge has approved a $46.75 million settlement to compensate victims of 23andMe's 2023 data breach, resolving claims after the genetic testing firm exposed the genetic data of nearly 6.9 million people worldwide. U.S. Bankruptcy Judge Brian Walsh in St. Louis ordered Chrome Holding—the entity that acquired 23andMe following its bankruptcy filing—to disburse the funds through Kroll Restructuring within five days.

China Bans Claude Code After Anthropic Embeds Covert Geolocation Tracking

Anthropic embedded undisclosed geolocation tracking code in Claude Code designed to identify Chinese users and report their location to company servers without consent. Security researchers discovered the steganographic markers across multiple versions of the coding assistant, flagging them as high-risk software. Alibaba responded by imposing an enterprise-wide ban effective July 10, 2026, citing "back-door risks" and security vulnerabilities in an internal notice.

Federal Judge Denies Meta's Summary Judgment, Allowing NJ Youth Mental Health Trial to Proceed

A federal judge in California has denied Meta Platforms' motion for summary judgment, clearing the way for a multistate lawsuit over youth mental health to proceed to trial in August 2026. The ruling, issued June 29 by the U.S. District Court for the Northern District of California, rejects Meta's attempt to have the case dismissed and confirms that the attorneys general's claims have sufficient legal merit to survive pretrial scrutiny.

Anthropic and Pentagon Clash Over AI Guardrails, Leading to Contract Termination

The Department of War terminated its $200 million partnership with AI firm Anthropic on February 27, 2026, after the company refused to remove safety restrictions on its Claude model for military use. Defense Secretary Pete Hegseth had issued a three-day ultimatum on February 24 demanding Anthropic disable all guardrails. When CEO Dario Amodei declined, Hegseth designated Anthropic a "supply chain risk," and President Trump issued a presidential order barring all federal agencies from using Anthropic's systems. The dispute centered on two non-negotiable demands from Anthropic: no fully autonomous lethal weapons and no mass surveillance of Americans.

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based national law firm, faces a proposed class action lawsuit alleging it failed to protect sensitive client data after a May 2026 social-engineering attack compromised information on over 57,000 individuals. An unauthorized third party impersonated IT staff and tricked a Blank Rome attorney into uploading confidential files to an external Google Drive account, exposing names, Social Security numbers, and potentially financial and medical records. The lawsuit names Blank Rome as defendant and alleges violations of common law, industry standards, the Federal Trade Commission Act, and HIPAA due to inadequate cybersecurity safeguards and delayed notification.

Federal consumer protection clashes with state AI laws as preemption fight grows

The FTC's proposed consumer-protection framework would not permit AI companies to use compliance with state AI laws as a defense against federal deception claims, according to recent analysis. This creates a direct conflict between federal and state enforcement regimes at a moment when AI governance is fragmenting across jurisdictions. Colorado's SB24-205 is already in effect, while California, New York, and Illinois have enacted or proposed their own AI transparency and deployment rules, forcing companies to navigate overlapping and potentially contradictory obligations.

MedCity News Spotlights AI Health Tech’s Patent, FDA, and HIPAA Tradeoffs

Healthcare AI developers face a three-front legal challenge that requires coordinated planning from product inception, not sequential problem-solving after development. Patent counsel, FDA regulators, and HIPAA compliance teams must align on strategy before the first commercial release, according to a MedCity News analysis. The core tension is structural: companies must lock down product specifications early enough for FDA review while maintaining the technical flexibility that makes AI valuable, document human inventorship to satisfy patent law, and design data systems that support model monitoring and retraining without violating privacy rules.

NY Legislature Advances Two Pending AI Bills on Disclosure and Hiring Reports

New York legislators are advancing two bills that would impose distinct compliance obligations on businesses using artificial intelligence. Assembly Bill 3411B would require any user of generative AI systems to display a clear notice on the interface warning that outputs may be inaccurate. Assembly Bill 9581B targets employers and businesses using AI in hiring and workforce management, mandating annual reports to the New York Department of Labor detailing AI's impact on employment—including estimates of displaced workers, reduced hours, and unfilled positions. Businesses that fail to submit the required report by March 1 face civil penalties of up to $500 per day.

42 States Secure Multistate Settlement for 23andMe 2023 Genetic Data Breach

A coalition of 42 state attorneys general, led by Washington AG Nick Brown, announced a settlement with 23andMe's bankruptcy trustee on July 14 resolving claims over a 2023 data breach that exposed genetic data of more than 220,000 Washington customers. Washington will receive approximately $500,000 as part of the multistate agreement, which addresses the company's failure to safeguard sensitive user information.

Article outlines 8 critical AI misuse cases including privacy leaks, hallucinated facts, and unverified legal advice

An advisory article cataloging eight high-risk uses of AI assistants like ChatGPT and Claude has highlighted the gap between widespread adoption and user safety guidance. The piece identifies specific domains where these large language models pose unacceptable risk: legal and compliance decisions, hiring or termination calls, medical diagnostics, and generation of final financial figures. The core problem is familiar—LLMs hallucinate statistics and present false information with unwarranted confidence—but the article emphasizes a secondary issue: AI providers themselves offer little guidance on what users should avoid, leaving organizations to independently identify pitfalls around data privacy, accuracy requirements, and inappropriate outputs.

Courts Block Federal AI-Driven DEI Funding Cuts as Unconstitutional

The federal judiciary has established a clear constitutional prohibition on federal grant termination based on recipients' involvement with Diversity, Equity, and Inclusion initiatives. The Southern District of New York ruled in the ACLS case that the government's withdrawal of DEI-related humanities grants violated both the First Amendment and the Fifth Amendment's Equal Protection Clause, characterizing the actions as "textbook examples" of unconstitutional discrimination. Courts in the Northern District of California and elsewhere have reached similar conclusions, blocking the Department of Justice and Department of Education from enforcing new DEI-related conditions on community policing grants and other federal funding.

AI Tools Now Enable Employers to Trace Employees’ Full Online History, Sabotaging Careers

Artificial intelligence has fundamentally altered the employment landscape by enabling employers to reconstruct comprehensive digital histories of workers—including deleted posts, archived social media accounts, and browsing activity—making attempts to obscure past behavior a potential liability rather than a privacy safeguard. AI monitoring platforms including Teramind, Controlio, ActivTrak, and Worklytics now track keystrokes, screen activity, website visits, and sentiment analysis across workplace communications. When employees attempt to sanitize their online presence, algorithms frequently flag these deletions as suspicious activity, potentially triggering hiring rejections or termination.

FTC Proposes Policy Treating Undisclosed AI Output Steering as Deceptive Under Section 5

On July 1, 2026, the Federal Trade Commission issued a proposed policy statement applying Section 5 of the FTC Act to AI companies that manipulate their systems' outputs contrary to consumers' reasonable expectations for truth and accuracy. The FTC is accepting public comment through July 31, 2026. The Commission voted 2-0 to authorize the Federal Register notice.

DOJ Establishes AI Litigation Task Force as Courts Adapt AI Discovery Tools

The Department of Justice announced the establishment of an Artificial Intelligence Litigation Task Force on January 9, 2026, formalizing AI's role in federal legal operations. The Task Force will oversee how the DOJ integrates AI into litigation workflows, marking an institutional shift from experimental adoption to regulated practice. The move reflects broader industry momentum: legal technology firms including Esquire Solutions, Baker Botts, and Lexis+ AI are now advising law firms on AI-assisted discovery and technology competence as standard practice rather than competitive advantage.

Enterprise buyers are standardizing AI contracts around tighter data, IP, and renewal terms

Enterprise buyers, AI vendors, and system integrators are converging on a recognizable contract template for AI services. The emerging standard includes shorter terms (often capped at 12 months), no automatic renewals, customer-controlled pilots, strict limits on data use for training, explicit output ownership, and tighter indemnity and audit provisions. The shift reflects a market-wide negotiation playbook rather than a single deal or regulatory mandate, though compliance frameworks like the EU AI Act and NIST are being mapped into contract language to define risk and governance obligations.

Former SDNY Cybercrime Chief Dina McLeod Joins Bracewell as Partner

Bracewell LLP has hired Dina McLeod as a partner in its New York government enforcement and investigations practice. McLeod, who spent 11 years at the U.S. Attorney's Office for the Southern District of New York, most recently served as chief of the Complex Frauds and Cybercrime Unit. In that role, she oversaw investigations and prosecutions involving white-collar crime, cybercrime, AI-related fraud, cryptocurrency schemes, digital assets, money laundering, securities fraud, trade secrets theft, tax fraud, healthcare fraud, bankruptcy fraud, FCPA violations, and national security cyber cases.

Anthropic adds $20 million to AI-regulation political group ahead of elections

Anthropic announced a $20 million additional donation to Public First Action, a 501(c)(4) political advocacy group, bringing its total commitment to the organization to $40 million. The funding supports Public First Action's efforts to back candidates and advocacy campaigns favoring AI regulation, transparency, and safety measures. Public First Action has supported candidates across party lines, including Republicans Marsha Blackburn and Pete Ricketts, who have advocated for stronger AI safeguards. Anthropic stated the money is intended to advance policy debate rather than directly support individual candidates.

UN independent panel warns unchecked AI progress poses catastrophic risks

On July 1, 2026, the UN's Independent International Scientific Panel on Artificial Intelligence released a preliminary report warning that unregulated AI development is outpacing both scientific understanding and government policy, with no guarantee against catastrophic harm. Led by UN Secretary-General António Guterres and computer scientist Yoshua Bengio, the panel identified specific risks: loss of control over autonomous systems, deceptive AI behaviors, and exploitation for fraud, cyberattacks, and biological threats. The report notes that AI already demonstrates expert-level reasoning in mathematics and science, with task complexity doubling every four to seven months, while current models trained on only a fraction of the world's 7,000 languages produce dangerous errors in health diagnoses for many populations.

Apple Intelligence AI service officially registered in China with Alibaba and Baidu partnerships

Apple Intelligence, the company's on-device generative AI service, has received official registration from China's Cyberspace Administration of China (CAC), clearing the path for deployment on iPhones in mainland China. The filing, submitted by Apple Technology Development (Shanghai) Co., Ltd., was approved on July 8 and publicly confirmed by the CAC on July 15 as part of a batch of seven approved mobile AI models. The approval ends a regulatory standoff that had blocked the service's rollout in the world's largest smartphone market.

Lawyers Moonlight to Train AI While Scammers Impersonate Immigration Attorneys

The legal profession faces a convergence of ethics crises driven by artificial intelligence and fraud. Attorneys are increasingly taking side work training AI models, while scammers deploy AI-generated deepfakes and cloned identities to impersonate immigration lawyers and steal from vulnerable clients. The problem intensified with the exposure of Washington State attorney Alexandra Lozano, who fabricated thousands of domestic abuse and trafficking narratives to secure humanitarian visas without client consent. Her scheme, which enlisted hundreds of employees across Colombia, Mexico, and Argentina to process fraudulent applications, affected tens of thousands of immigrants and drained client bank accounts while exposing victims to deportation risk.

AI workplace surveillance is spreading, drawing backlash over privacy and productivity

Companies including Walmart, Starbucks, Delta, and Chevron are deploying AI-powered employee monitoring systems that track keystrokes, idle time, email and Slack activity, meeting participation, location data, and even tone analysis to assess productivity and flag retention risk. These tools have moved beyond niche management software into widespread workplace surveillance, often integrated into performance reviews and employment decisions without full employee visibility. The Consumer Financial Protection Bureau has begun enforcement action related to the practice, while legal scholars and researchers are actively analyzing employee privacy rights in this context.

Blank Rome Hit With Two Class Actions After May Data Breach Exposes 57,000 Clients

Blank Rome LLP, a Philadelphia-based firm, faces two proposed class-action lawsuits following a May 2026 data breach that compromised the personal information of 57,554 current, former, and prospective clients. A cybercriminal impersonating an IT staff member tricked an attorney into uploading sensitive files to an unauthorized external Google Drive. The exposed data includes Social Security numbers, medical records, driver's license numbers, passport information, and health insurance details.

Meta Alleged to Have Used AI to Target Users With Scam Ads, Drawing Consumer Watchdog Suit

Meta faces a lawsuit filed by the Consumer Federation of America in Washington, DC, alleging that the company violated consumer protection laws by allowing fraudulent advertisements to proliferate on Facebook and Instagram. The CFA claims Meta's AI-powered advertising tools have enabled scams including fake government checks and counterfeit product offers despite the company's stated commitment to combating fraud. The suit also highlights Meta's AI ad-generation tool, which has produced errors that distort product images, compromise text legibility, and misrepresent people in advertisements. Separately, the Tech Transparency Project documented instances where Meta approved harmful ads targeting minors—promoting drug use, alcohol, and eating disorders—using Meta's own AI-generated imagery and targeting children as young as 13.

Dubai CEO Pleds Guilty in Decade-Long BigLaw Insider Trading Scheme

A Dubai-based CEO and trader has pleaded guilty in federal court in Massachusetts to conspiring with a former BigLaw M&A associate to run a decade-long insider trading operation that generated tens of millions in illicit profits. The scheme involved 30 defendants—corporate attorneys and financial professionals—who allegedly stole confidential client data from nearly 30 major M&A transactions to trade on material nonpublic information between March 2014 and August 2024.

$45M Multistate Settlement Reached with Block Over Cash App Fraud

California Attorney General Rob Bonta and 46 state attorneys general have secured a $45 million settlement with Block, Inc., the parent company of Cash App, over allegations that the company misled consumers about fraud protections and failed to safeguard users from theft. The agreement requires Block to implement 24-hour live customer support, halt false marketing claims about safety features, and comply with a separate Consumer Financial Protection Bureau settlement obligating the company to distribute $75 million to $120 million in consumer redress.

Waymo Begins Mapping Chicago for Autonomous Testing as Statedebates Driverless Vehicle Bill

Waymo has begun manual mapping and data collection on Chicago streets, operating a limited fleet of human-driven vehicles east of I-90 from the South Loop to Wrigleyville. The testing started in late February 2026 after residents spotted Waymo vehicles in the area and in a Loop parking garage. The current phase does not include passenger pickup services. Waymo spokesperson Chris Bonelli confirmed the limited operations, while Chicago Mayor Brandon Johnson's office acknowledged the testing but stated that no autonomous operations are currently authorized in the city.

New York Judge Lets Letitia James’s Zelle Fraud Suit Move Forward

A New York state court on July 20 allowed Attorney General Letitia James's lawsuit against Early Warning Services, operator of Zelle, to survive a motion to dismiss. Judge Phaedra F. Perry-Bond ruled that the complaint plausibly alleges fraud and deceptive marketing under New York Executive Law § 63(12). The court did not find that Early Warning violated the law—only that James's allegations warrant proceeding to discovery.

China Enforces First National Ban on AI Virtual Partners for Minors and Emotional Dependency

On July 15, 2026, China's Provisional Measures on Human-like Interactive AI Services took effect, establishing the first national regulatory framework specifically targeting AI companions and virtual lovers. The rules, jointly issued April 10 by the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation, explicitly prohibit AI services from inducing emotional dependency, damaging real-world relationships, or using emotional manipulation to drive unreasonable user decisions. Companies must ensure their bots clearly identify as AI, remind users of this fact after two hours of continuous interaction, and intervene immediately if signs of self-harm are detected. Violations carry fines up to 200,000 RMB (approximately $28,000) and potential service shutdowns.

ChatGPT and Claude Account Sharing Leads to Privacy Breaches, Data Mix-ups, and Cybersecurity Risks

Users are sharing login credentials for premium AI services—ChatGPT Plus and Claude Pro—exposing themselves to serious privacy breaches. Connor Effrain, a 22-year-old digital fundraising associate, shared his ChatGPT account and inadvertently gave others access to sensitive health information about his Crohn's disease and personal details he had discussed with the chatbot. Both OpenAI and Anthropic explicitly prohibit account sharing in their terms of service, classifying these subscriptions as single-user only. The platforms detect concurrent sessions and suspend accounts that violate this rule.

DOJ Bulk Data Rule enforcement begins after grace period ends, triggering class actions

The Department of Justice has begun full enforcement of the Bulk Sensitive Data Rule, a regulation codified at 28 C.F.R. Part 202 and mandated by Executive Order 14117. The rule prohibits or restricts the transfer of Americans' bulk sensitive personal data and government-related data to designated countries of concern—China, Russia, Iran, and Cuba. A three-month grace period that began April 8, 2025 has now expired. Companies face civil penalties up to $368,136 per violation and criminal exposure of up to 20 years imprisonment for willful breaches.

Tech Workers Adopt AI Apps to Record and Transcribe All Conversations for Productivity

Technology professionals are rapidly adopting AI-powered recording and transcription tools to automatically capture, transcribe, and summarize virtually all digital interactions—from workplace meetings and internal chats to personal dates. The practice is driven by productivity gains: users leverage applications like Fathom, Otter AI, Fireflies, Avoma, Granola, tl;dv, Zoom AI Companion, and NotebookLM to create searchable archives and extract action items without manual effort. Granola has gained particular traction by addressing the "bot problem"—the concern that a visible recording presence alters what participants are willing to say—through local call detection that avoids inserting a bot into conversations.

Ransomware group World Leaks exposes 19,000 Kudankulam nuclear plant files, including blueprints

A ransomware group called World Leaks has posted nearly 19,000 files related to India's largest nuclear power plant, Kudankulam, on the dark web. The leaked materials include purported blueprints of facility components and supplier details allegedly obtained from Reliance Group, a major contractor at the plant. Reliance Group confirmed a partial breach of data stored on a server hosted by Yotta, an Indian data center provider, and reported the incident to the Indian government. The compromised files represent the most sensitive portion of approximately 858,000 Reliance files now accessible on the World Leaks website.

President Trump Signs Executive Order 14409 to Advance AI Innovation and Cybersecurity

On June 2, 2026, President Trump signed Executive Order 14409, directing federal agencies to accelerate U.S. artificial intelligence development while fortifying cybersecurity defenses against AI-enabled threats. The order tasks the Department of Defense, CISA, the NSA, and the Office of Management and Budget with prioritizing cyber protection for National Security Systems and critical infrastructure—specifically naming rural hospitals and utilities. It establishes a voluntary framework for "covered frontier models" without imposing mandatory licensing, explicitly rejecting what the order characterizes as the "overly burdensome regulation" of the prior administration. The Attorney General receives a directive to prioritize enforcement against AI-facilitated crimes. The order also creates an AI cybersecurity clearinghouse to coordinate voluntary industry participation in remediating software vulnerabilities at scale.

Meta Faces Class Action Lawsuit Over AI Glasses Footage Sent to Overseas Human Reviewers

Meta faces a federal class action lawsuit alleging that its Ray-Ban smart glasses secretly transmit user-captured video to thousands of human contractors in Kenya for AI training—contradicting the company's privacy commitments. Filed March 4, 2026, by plaintiffs Gina Bartone and Mateo Canu, the suit claims Meta and Luxottica violated federal and state law by routing footage to overseas servers for manual labeling without user disclosure, rather than processing it solely through AI models.

Scammers impersonate Netflix, Coca-Cola and FIFA with fake recruiting sites using big-brand logos

Scammers launched a coordinated campaign in July 2026 impersonating Netflix, Coca-Cola, and FIFA through counterfeit hiring pages designed to harvest job seekers' credentials. The fake sites mimic legitimate career portals but use mismatched domains—adding terms like "jobs," "careers," or "hiring" around brand names—and embed sign-in boxes directly on the pages rather than redirecting to authentic Google, Microsoft, or LinkedIn authentication. Security firms Norton and Malwarebytes identified the scheme, which specifically targets marketing professionals.

mail Subscribe to Privacy email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap