Welcome to this month’s issue of The BR Privacy, Security & AI Download, the digital newsletter of Blank Rome’s Privacy, Security & Data Protection practice. We invite you to share this resource with your colleagues and visit Blank Rome’s Privacy, Security & Data Protection webpage for more information about our team.
RECENT HIGHLIGHT
Did I Do Bot?! When AI Agents Create Real-World Consequences
Blank Rome partner Jeffrey N. Rosenthal and associates Timothy J. Miller and Liam M. Leahy authored this Legal Intelligencer article discussing how as AI agents become increasingly autonomous in conducting business on behalf of companies, organizations may be legally bound by their AI-generated agreements and held liable for any resulting harm, making the defense that “the bot did it” unlikely to succeed.
Read More»
STATE & LOCAL LAWS & REGULATIONS
Illinois Enacts AI Safety Legislation: Illinois Governor JB Pritzker signed Senate Bill 315, the Artificial Intelligence Safety Measures Act (the “Act”). The law applies to “large frontier developers,” which are entities with annual revenues exceeding $500 million that train foundation models using computing power above 10²⁶ integer or floating point operations. The bill requires large frontier developers to publish a “frontier AI framework” detailing how developers identify and mitigate “catastrophic risks,” which are risks contributing to death or serious injury of more than 50 people or over $1 billion in property damage. The law mandates annual independent third-party audits and imposes 72-hour incident reporting obligations (24 hours for imminent risks of death or serious physical injury). Developers must also publish transparency reports in machine-readable format before deploying new models. The Act includes whistleblower protections for employees reporting catastrophic risks and authorizes civil penalties of up to $1 million for initial violations and $3 million for subsequent violations, enforceable exclusively by the Attorney General. No private right of action is established. The bill is modeled after California’s SB-53 and New York’s Responsible AI Safety and Education Act. The Act takes effect on January 1, 2027, with most substantive compliance obligations beginning on January 1, 2028.
New Jersey Delays Enforcement of Sweeping Data Broker Law: New Jersey’s Division of Consumer Affairs (“DCA”) announced it will suspend enforcement of a newly enacted data broker law while the state builds a registration infrastructure and addresses concerns about the statute’s scope and clarity. The law, enacted on June 30, 2026, requires data brokers and data controllers that collect, sell, or license personal data to register annually with DCA and pay registration fees ranging from $5,000 to $1.5 million based on volume. Unlike similar laws in other states, including California’s Delete Act, the New Jersey statute extends to data collectors that gather information directly from consumers and then sell or license it to data brokers. The law also prohibits covered entities from selling or licensing “sensitive data,” including data revealing racial or ethnic origin, religious beliefs, health conditions, biometric data, children’s data, and precise geolocation information, with violations carrying penalties of $50,000 per record. DCA stated it expects to launch the public registry in spring 2027, with the first registration period open from April 1, 2027, through June 30, 2027. DCA indicated it will issue additional guidance in the coming months to clarify the law’s requirements, particularly regarding the sensitive data sales prohibition.
New Jersey Enacts “Fair Price Protection Act” Banning Surveillance Pricing for Groceries: New Jersey Governor Mikie Sherrill signed Assembly Bill 4085, known as the “Fair Price Protection Act,” (the “Act”) into law. The legislation prohibits the use of “surveillance pricing” for groceries and other foodstuffs, defined as pricing strategies that determine or vary the sale price of grocery items based, in whole or in part, on personal data processed by an algorithm or automated system. This includes the use of electronic surveillance technology such as device tracking, biometric monitoring, and other data collection methods that gather information about a consumer’s behavior, characteristics, or location. Violations constitute an unlawful consumer fraud practice enforceable by the Attorney General, with penalties of up to $20,000 per negligent violation or the profits derived from the violation, whichever is greater. The law includes exemptions for price differences based on reasonable delivery costs, bona fide discounts with publicly disclosed eligibility criteria, and loyalty programs meeting specified transparency requirements. The Act also imposes a one-year moratorium on the installation of new electronic shelf labels while the New Jersey Innovation Authority conducts a study on their impact on surveillance pricing. Maryland and Connecticut have enacted similar laws.
New York Releases Final SAFE for Kids Act Rules: New York Attorney General Letitia James announced the release of final rules implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, establishing requirements for how social media companies must restrict addictive algorithmic feeds and nighttime notifications for users under 18 absent parental consent. The rules define “addictive online platforms” as platforms where users spend 20 percent or more of their time on algorithmically personalized feeds, with an exemption for platforms with fewer than five million monthly active users or fewer than 20,000 minor users. The regulations establish age assurance standards requiring platforms to verify users are adults before granting access to restricted features, with specified accuracy minimums and annual testing requirements. Platforms must offer at least one alternative to government-issued ID for age verification, and all data collected for age assurance or parental consent must be used only for that purpose and promptly deleted or de-identified. Nighttime notifications are prohibited between 12 a.m. and 6 a.m. Eastern without parental consent. The rules take effect January 25, 2027, with civil penalties of up to $5,000 per violation.
Vermont AG Publishes Proposed Rules Under Age-Appropriate Design Code: The Vermont Attorney General’s Office published proposed rules under Vermont’s Age-Appropriate Design Code (“AADC”), with an effective date of January 1, 2027. The rulemaking addresses two key areas. The first proposed rule, adopted pursuant to 9 V.S.A. § 2449f, establishes prohibited data processing and design practices for online services used by covered minors. It imposes strict data minimization requirements, prohibits the use of personal or behavioral data to personalize or recommend media to minors, and bans design features that promote compulsive use, including autoplay, infinite scroll, engagement-based notifications, and behavioral recommendation systems. The rule also prohibits social pressure features, reinforcement mechanisms, and asymmetrical interfaces that make disengagement harder than engagement. The second proposed rule, adopted pursuant to 9 V.S.A. § 2449g, governs age assurance privacy. It mandates a graduated escalation approach, requiring covered businesses to begin with low-intrusion methods before escalating to more data-intensive techniques. The rule imposes strict data minimization for age assurance data, prohibits its use for profiling or advertising, and requires deletion of raw data immediately after the age determination. Covered businesses must provide fallback mechanisms, meaningful appeal processes with human review, and conduct documented compliance assessments. The Vermont Attorney General’s office is accepting public comments through October 2, 2026.
FEDERAL LAWS & REGULATIONS
White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse: The White House announced the launch of “Gold Eagle,” a clearinghouse enabling coordination between the federal government and private sector to identify and patch cybersecurity vulnerabilities using artificial intelligence (“AI”). Established pursuant to President Trump’s June 2, 2026, Executive Order “Promoting Advanced Artificial Intelligence Innovation and Security” (EO 14409), Gold Eagle is a coordinated system built by open-source software partners and critical infrastructure companies to receive and remediate cyber vulnerabilities. The initiative involves the White House, the U.S. Department of the Treasury, the U.S. Department of Homeland Security through the Cybersecurity and Infrastructure Security Agency, and the U.S. Department of Defense (“DOD”). Gold Eagle intends to leverage frontier AI capabilities to advance faster than adversaries, reduce duplicative scanning efforts, and deliver prioritized, actionable threat and remediation information to defenders across the federal government and private sector.
DOD Suspends CMMC Phase Two Requirements, Initiates Program Review: The DOD announced the immediate suspension of the Cybersecurity Maturity Model Certification (“CMMC”) program’s Phase Two requirements, which would have required Level Two contractors handling controlled unclassified information to complete third-party cybersecurity assessments by November 10, 2026. The DOD cited prohibitive compliance costs and bureaucratic burdens that are forcing innovative companies out of the defense industrial base (“DIB”), ultimately threatening to delay delivery of critical military capabilities. Phase One self-assessment requirements remain in place, and all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information under Defense Federal Acquisition Regulation Supplement clause 252.204-7012 and National Institute of Standards and Technology SP 800-171 Rev 2. The DOD has established a CMMC Reform Task Force to conduct a 60-day comprehensive review of the program, synthesize industry feedback, and recommend scalable security measures that lower barriers for small and non-traditional businesses. Suspension does not relieve contractors of underlying cybersecurity obligations and companies should continue compliance efforts to minimize exposure to potential False Claims Act and whistleblower litigation arising from self-attestation deficiencies. Companies should also assess whether to engage in voluntary third-party assessments as a risk-mitigation measure, even absent a contractual mandate.
FTC and States Sue Telehealth Provider Over Health Data Sharing and Deceptive Practices: The Federal Trade Commission (“FTC”), joined by Utah and California, announced the filing of a federal lawsuit against Hims & Hers Health Inc. (“Hims & Hers”), alleging that the telehealth provider shared consumers’ sensitive health information with third-party advertising platforms such as Meta and Snap despite promising to protect patient privacy. The complaint alleges that Hims & Hers shared health information through customer lists provided to advertising platforms and through third-party tracking technologies that automatically transmitted consumer actions on the company’s website to those platforms. The FTC further alleges that Hims & Hers deceived consumers about its billing practices by charging them for prescription treatments and enrolling them in subscription plans almost immediately after they submitted medical intake forms, without providing a meaningful opportunity to review or consent to a provider’s recommended treatment. The complaint also alleges that Hims & Hers made cancellation unreasonably difficult, including by hiding cancellation buttons behind multiple navigation steps. The suit asserts violations of the FTC Act, the Restore Online Shoppers’ Confidence Act, California’s False Advertising and Unfair Competition Laws, and Utah’s Consumer Sales Practices Act. The case was filed in the U.S. District Court for the Northern District of California.
U.S. LITIGATION
Supreme Court Allows Enforcement of Texas App Store Age Verification Law: The U.S. Supreme Court declined to block enforcement of the Texas App Store Accountability Act (the “Act”), which requires app stores to verify users’ ages and obtain parental consent before minors can download apps or agree to in-app contractual terms. In two unsigned orders, the justices upheld the Fifth Circuit’s decision staying a district court injunction that had blocked the law. The challengers, Students Engaged in Advancing Texas and the Computer & Communications Industry Association, argued that the law violates the First Amendment by broadly restricting access to apps regardless of content, exposing app stores and developers to significant liability and compliance costs. Texas countered that the Act regulates commercial transactions. Specifically, Texas argued the Act regulates the conditions under which minors can agree to contractual terms of service that may permit tracking of children’s data rather than protected speech, and that the law advances the state’s substantial interest in protecting children’s data, safety, and privacy. The Court’s orders, which contained no noted dissents, permit enforcement of the law while the underlying litigation continues.
Seventh Circuit Rules TCPA Do-Not-Call Private Right of Action Does Not Cover Text Messages: In Steidinger v. Blackstone Medical Services, the Seventh Circuit affirmed dismissal of Telephone Consumer Protection Act (“TCPA”) claims brought by plaintiffs who received unwanted marketing text messages advertising home sleep tests. The Court held that § 227(c)(5) of the TCPA, which creates a private right of action for individuals who receive unwanted “telephone calls” in violation of do-not-call regulations, does not extend to text messages. Applying an original public meaning analysis, the Court found that “telephone call” referred to communication via sound in 1991, when the TCPA was enacted, and that text messages, which were first sent in 1992, do not reproduce sounds. The Court further noted that § 227(c)(5) refers only to “telephone calls,” while surrounding provisions use the broader term “telephone solicitation,” which encompasses both calls and messages, indicating Congress intended a narrower scope for the private right of action. The panel declined to follow the Federal Communication Commission’s (“FCC”) interpretation equating texts with calls, citing Loper Bright’s elimination of Chevron deference. Although unwanted spam texts may still be addressed through FCC enforcement under other provisions of § 227, the decision eliminates the private right of action under § 227(c)(5) for text message recipients in the Circuit.
Fifth Circuit Partly Upholds Injunction Against Texas Content Filtering Law: A Fifth Circuit panel affirmed in part a preliminary injunction blocking key provisions of Texas House Bill 18, the Securing Children Online through Parental Empowerment Act (“SCOPE Act”), which regulates social media platforms’ obligations to protect minors. The majority held that the SCOPE Act’s central monitoring and filtering requirement, which mandates that digital service providers (“DSPs”) implement strategies to prevent minors’ exposure to content promoting self-harm, substance abuse, bullying, and other harmful categories, is preempted by Section 230 of the Communications Decency Act (“CDA”). The Court found that enforcement of the filtering requirement constitutes claims “stemming from [DSPs’] actions as publishers,” including their monitoring, screening, and deletion of content, and is therefore “squarely preempted” by Section 230. However, the panel vacated the lower court’s injunction against the SCOPE Act’s age-verification requirement, citing the Supreme Court’s intervening decision in Free Speech Coalition v. Paxton, which upheld a similar age-verification mandate for pornographic websites. The panel also found that the nonprofit group Students Engaged in Advancing Texas (“SEAT”) lacked standing to challenge multiple provisions, holding that fears of censorship based on indirect regulation were insufficient.
U.S. Enforcement
CalPrivacy Launches Inaugural Sectoral Privacy Audit Targeting Gig Economy Platforms: The California Privacy Protection Agency (“CalPrivacy”) announced the launch of its first formal sectoral privacy audit, targeting gig economy platforms operating in California. The audit will evaluate whether major app-based transportation, delivery, and task service platforms are meeting their obligations under the California Consumer Privacy Act (“CCPA”), with a specific focus on compliance with consumers’ and workers’ rights to access and exercise control over their personal information. CalPrivacy noted that gig platforms collect extensive personal information, including precise geolocation data, behavioral and performance metrics, biometric data, financial information, and communications records, which is processed through algorithmic systems to make consequential decisions about workers’ assignments, ratings, earnings, and account status. Notably, California is the only state whose comprehensive privacy law extends data access rights to workers, including employees and independent contractors. The audit will examine whether platforms honor access requests within the 45-day statutory window and provide complete responses. CalPrivacy described the audit as the first in a planned series of sectoral audits intended to identify risks, highlight strong practices, and publish trend reporting to inform the public.
FTC Settles with Tenant Screening Company over FCRA and FTC Act Violations: The FTC announced a settlement with RentGrow, Inc., a Massachusetts-based provider of consumer reports for tenant screening, whereby RentGrow agreed to pay $2.25 million to settle FTC allegations that the company violated the Fair Credit Reporting Act (“FCRA”) and the FTC Act. The Department of Justice filed a complaint in the U.S. District Court for the District of Columbia alleging that RentGrow failed to maintain reasonable procedures to ensure the maximum possible accuracy of its tenant screening reports. Specifically, the FTC alleged that RentGrow included duplicate case records and multiple entries for the same criminal or eviction action in its reports, creating false impressions that applicants had more convictions or eviction proceedings than they actually had. The complaint further alleged that RentGrow failed to disclose all sources of data used in its reports when requested by consumers, including its use of LexisNexis Accurint for historical address and middle name data, impeding consumers’ ability to dispute inaccuracies. RentGrow also allegedly violated the FTC Act by misleading consumers about dispute outcomes, telling consumers that property managers had been notified of successful disputes while instead informing those property managers that no changes had been made. Under the proposed consent order, RentGrow must pay the $2.25 million penalty and is prohibited from failing to maintain reasonable accuracy procedures and misrepresenting dispute outcomes to consumers.
Multistate Coalition Settles Bankruptcy Claims Against 23andMe Over Genetic Data Breach: A coalition of 42 state attorneys general (“AG”), led by Connecticut AG William Tong, announced a settlement with the bankruptcy trustee for direct-to-consumer genetic testing company 23andMe, resolving claims arising from a 2023 data breach that compromised the genetic data of 6.9 million customers worldwide. The multistate investigation found that 23andMe engaged in unreasonable data security practices, including failing to employ safeguards against credential stuffing attacks, failing to implement multifactor authentication, and failing to deploy adequate logging and monitoring tools to detect the breach. Under the settlement, filed in the U.S. Bankruptcy Court for the Eastern District of Missouri, the states’ claims were allowed in the aggregate amount of $150 million, with actual recovery limited to an immediate cash payment of $18 million from available bankruptcy funds. The stipulation also prohibits the wind-down debtor from engaging in direct consumer sales or collecting or maintaining personally identifiable information for five years. Notably, the settlement releases do not extend to 23andMe Research Institute (formerly TTAM Research Institute), the nonprofit entity that acquired 23andMe’s consumer data assets as part of the bankruptcy sale, which is subject to separate enhanced data security and privacy requirements. The settlement also preserves the states’ ability to pursue any regulatory liability arising after the plan’s effective date that is unrelated to the 2023 breach.
INTERNATIONAL LAWS & REGULATIONS
EU Publishes AI Digital Omnibus Regulation, Revising AI Act Deadlines and Requirements: The European Union (“EU”) published Regulation (EU) 2026/1744, the “Digital Omnibus on AI,” in the Official Journal on July 24, 2026, entering into force on July 27, just days before the AI Act’s original August 2, 2026, compliance date for high-risk AI systems. The Omnibus Regulation restructures the AI Act’s implementation timeline. Obligations for high-risk AI systems under Annex III (e.g., systems used in education, employment, and credit scoring) are deferred to December 2, 2027, while obligations for high-risk AI systems embedded in products regulated by EU harmonization legislation are extended to August 2, 2028. For generative AI systems placed on the market before August 2, 2026, a transitional period until December 2, 2026, applies for compliance with synthetic content labeling requirements. The regulation also introduces new prohibited practices, including the use of AI to generate non-consensual intimate imagery and child sexual abuse material, effective on December 2, 2026. Of particular note to privacy professionals, the regulation expands the legal basis for processing special categories of personal data (such as health data or ethnicity) for bias detection and correction, extending this authority beyond providers of high-risk AI systems to deployers and providers of other AI systems and models. The AI literacy obligation is scaled back to requiring measures that “support the development” of literacy rather than mandating specific literacy levels. Organizations developing, deploying, or using AI systems in the EU should reassess their compliance roadmaps in light of the revised deadlines and modified obligations.
European Commission Publishes Guidelines on AI Transparency Obligations Under the AI Act: The European Commission (“EC”) published guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the EU AI Act. The guidelines address four categories of transparency obligations: (1) providers of AI systems that interact directly with natural persons must ensure individuals are informed they are interacting with an AI system; (2) providers of AI systems generating or manipulating synthetic content (image, video, audio, or text) must mark outputs in a machine-readable format and enable their detection; (3) deployers of emotion recognition or biometric categorization systems must inform exposed individuals of the system’s operation; and (4) deployers of AI systems generating deep fakes or AI-generated text published on matters of public interest must disclose the artificial origin of the content. The guidelines clarify that compliance obligations extend to providers and deployers regardless of whether they are established in the EU, provided AI system outputs are used within the Union. Penalties for non-compliance include fines of up to €15 million or three percent of worldwide annual turnover. A voluntary Code of Practice on Transparency of AI-Generated Content is also available to assist providers and deployers in demonstrating compliance with the marking and labelling obligations.
EDPB Adopts Guidelines on Anonymization, Web Scraping for Generative AI, and Blockchain: The European Data Protection Board (“EDPB”) adopted three sets of guidelines during its latest plenary session. The first set of guidelines clarifies the notion of anonymous data under the General Data Protection Regulation (“GDPR”), incorporating the Court of Justice of the European Union’s (“CJEU”) ruling in EDPS v SRB (C-413/23 P). The guidelines intend to establish a practical framework using three criteria to assess whether data has been successfully anonymized: No Record Isolation, No Linkage, and No Inference. Controllers may apply either a “contextual approach,” which considers the capabilities of different entities, or a “simplified approach” that disregards such differences for convenience. The second set of guidelines addresses web scraping for generative AI training, clarifying GDPR compliance requirements including the legitimate interest legal basis, transparency obligations, and data minimization measures. The EDPB also addresses the incidental collection of special categories of personal data during scraping, noting the potential applicability of the CJEU’s GC & Others ruling. The third publication finalizes guidelines on blockchain technologies, providing practical guidance on GDPR-compliant use of blockchains, including recommendations to store personal data off-chain, conduct Data Protection Impact Assessments, and favor permissioned blockchain architectures. The anonymization and web scraping guidelines are open for public consultation until October 30, 2026.
China Introduces AI Governance Rules Addressing Ethics, AI Agents, and Anthropomorphic AI: China introduced three new regulatory rules marking a shift from broad AI principles toward detailed, operational, and risk-based rules for emerging AI technologies. The regulations address AI ethics, autonomous AI agents, and anthropomorphic AI interaction services, emphasizing that AI should assist people without harming, deceiving, or exploiting them. The developments respond to emerging risks associated with AI agent frameworks, including credential theft, enterprise data leakage, and prompt injection attacks, as well as concerns about emotional dependence, manipulation, and psychological harm from AI companions, particularly among minors and older adults. The Interim Measures for the Administration of Anthropomorphic AI Interaction Services took effect on July 15, 2026, establishing standards for AI-powered “emotional interaction services” that simulate personality traits and communication styles of natural persons. Provider requirements include mandatory emotional distress detection, crisis intervention, and curbs on addictive use. The measures also prohibit using sensitive personal data from companion interactions to train AI models. The Cyberspace Administration of China will oversee compliance, with penalties for noncompliance ranging up to CNY100,000 for simple violations and CNY200,000 where harmful consequences to citizens’ life, health, or safety occur.
EU Commission Publishes Cyber Resilience Act Implementation Guidance: The European Commission published guidance to assist manufacturers, developers, and businesses in complying with the Cyber Resilience Act (“CRA”), which entered into force in December 2024 and imposes mandatory cybersecurity requirements across the full lifecycle of products with digital elements. The guidance addresses questions regarding scope, including when remote data processing solutions and free and open-source software fall within the CRA’s ambit; what constitutes a “substantial modification” triggering new compliance obligations; how support periods should be determined and applied; and how to meet reporting obligations for actively exploited vulnerabilities and severe incidents. Notably, vulnerability reporting obligations under Article 14 apply from September 11, 2026, even for products placed on the market before the CRA’s full application date of December 11, 2027. The guidance emphasizes a risk-based approach to cybersecurity risk assessments, requiring manufacturers to address identified risks through product-level measures rather than transferring responsibility to users. Special attention is given to SMEs and microenterprises, with 67 practical examples and use cases to ensure proportionate compliance.
© 2026 Blank Rome LLP. All rights reserved. Please contact Blank Rome for permission to reprint. Notice: The purpose of this update is to identify select developments that may be of interest to readers. The information contained herein is abridged and summarized from various sources, the accuracy and completeness of which cannot be assured. This update should not be construed as legal advice or opinion, and is not a substitute for the advice of counsel.
