California Senate Bill 690 (“SB 690”) continues to advance in the California state legislature. SB 690 seeks to limit litigation brought pursuant to the California Invasion of Privacy Act (“CIPA”) given the avalanche of website technology litigation, which continues unabashedly. While SB 690 has been scaled back since its first introducion in February 2025, it would still have a meaningful impact on businesses faced with these lawsuits.
Continue Reading California’s SB 690: Legislative Relief on the Horizon for Website Privacy ClaimsPrivacy
New Frontiers in Spoliation: Preserving AI Records in Litigation
The explosion of generative AI in the workplace has created a new and largely unaddressed category of litigation risk. In May 2025, a federal court in the Southern District of New York ordered OpenAI to preserve and segregate all ChatGPT output log data that would otherwise be destroyed under its default 30-day deletion policy, marking…
California’s Automated License Plate Recognition Law Draws Increased Litigation Exposure
In February 2026, the California First District Court of Appeal held that, at the pleading stage, the plaintiff had sufficiently pled that a parking garage’s failure to publicly display an automated license plate recognition (“ALPR”) usage and privacy policy violated California Civil Code Section 1798.90.51(b).
Continue Reading California’s Automated License Plate Recognition Law Draws Increased Litigation ExposureDoW Suspends CMMC Phase II Requirements – Launches 60-Day Review
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of all Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had originally been scheduled to take effect Nov. 10, 2026, including the transition to mandatory third-party assessments by CMMC Third-Party Assessment Organizations for contractors handling Controlled Unclassified Information. The DoW simultaneously…
AI-Assisted Billing Could Create FCA Pitfalls: How Healthcare Companies Can Get Ahead of Risk
Across the healthcare industry, providers are increasingly relying on AI-assisted billing tools to automate medical coding, prior authorization workflows, and the submission of claims to Medicare, Medicaid and other federal payors. The efficiency gains can be substantial, as can the heightened False Claims Act (FCA) exposure these systems can create. As AI continues to develop…
The Great American AI Act: What It Means — and Doesn’t Mean — for Companies Using AI
On June 4, 2026, Reps. Jay Obernolte and Lori Trahan released a discussion draft of the Great American Artificial Intelligence Act. The proposal has generated significant attention, but many organizations may be overestimating its practical significance for day-to-day operations. The bill is directed primarily at developers of “frontier” AI models, so its requirements will not…
GSA AI Procurement Rules Would Introduce New Disclosure and Use-Rights Requirements for Federal Contractors
The General Services Administration Federal Acquisition Service has released draft contract terms and conditions related to AI-related procurements through a new proposed GSAR clause 552.239-7001, “Basic Safeguarding of Artificial Intelligence Systems” (February 2026), that would impose material new requirements on contractors and service providers supplying AI capabilities to the federal government. If adopted, the clause…
Seventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies Retroactively
On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit, which consolidated three interlocutory appeals, issued a significant ruling in Clay v. Union Pacific Railroad Co., that resolves the question of whether Illinois’s 2024 amendment to the Biometric Information Privacy Act (“BIPA”) applies retroactively to cases pending when it was enacted.[1] The court answered in the affirmative, and held that the amendment applies retroactively. This decision is a victory for businesses facing astronomical exposure in pending BIPA litigation.
Continue Reading Seventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies RetroactivelyCalPrivacy Ramps Up Privacy Enforcement
The California Privacy Protection Agency (CalPrivacy) is entering an aggressive new phase of privacy regulation and enforcement, of which companies doing business in California should be aware. CalPrivacy already brought enforcement actions against many companies, maintains over 100 active investigations and has signaled an increased pace of enforcement.
Continue Reading CalPrivacy Ramps Up Privacy Enforcement
Data Privacy Day 2026: What Changed on Jan. 1 — And What to Watch Next
Data Privacy Day offers a natural checkpoint to take stock of a fast‑moving legal landscape. As of January 1, 2026, several significant U.S. state privacy laws and regulatory updates are now live, with additional U.S. and global milestones queued up throughout 2026. Below we summarize important changes already in effect and highlight issues to monitor as the year unfolds.
Continue Reading Data Privacy Day 2026: What Changed on Jan. 1 — And What to Watch Next