Welcome to this month’s issue of The BR Privacy, Security & AI Download, the digital newsletter of Blank Rome’s Privacy, Security & Data Protection practice. We invite you to share this resource with your colleagues and visit Blank Rome’s Privacy, Security & Data Protection webpage for more information about our team.


RECENT HIGHLIGHT

How I Made Law Firm Leadership: ‘Have Strong Relationships with People at All Levels,’ says Sharon Klein of Blank Rome

Blank Rome vice chair of artificial intelligence Sharon R. Klein was featured in this Law.com article discussing her career journey as a lawyer and firm leader while offering insights into the evolving legal landscape.

Read More»


STATE & LOCAL LAWS & REGULATIONS

Louisiana Enacts Comprehensive Consumer Privacy Law: Louisiana Governor Jeff Landry signed the Louisiana Data Privacy Act (“LDPA”), making Louisiana the 22nd state to enact a comprehensive consumer privacy law and setting an effective date of January 1, 2027. The LDPA largely follows the Washington Privacy Act framework but uses California Consumer Privacy Act (“CCPA”)-style applicability thresholds, covering businesses that meet revenue, data-volume, or personal-information sales thresholds. Covered controllers must provide consumers with rights to access, correct, and delete personal data, and opt out of targeted advertising, sales, and certain profiling. Similar to other state comprehensive privacy laws, the law also requires privacy notices, data minimization, reasonable administrative, technical, and physical security measures, consent for sensitive-data processing, processor contracts, and data protection assessments for high-risk activities such as targeted advertising, sales, sensitive-data processing, and certain profiling. Enforcement rests exclusively with the Louisiana Attorney General (“AG”). The LDPA provides for a temporary cure period that runs from January 1 through July 31, 2027.

Vermont Enacts Consumer Privacy and Online Surveillance Act: Vermont Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act, making Vermont the 23rd state to enact a comprehensive consumer privacy law and the fourth state to do so in 2026. The law takes effect January 1, 2028, and applies to businesses that process the personal data of at least 35,000 Vermont consumers, process sensitive data of at least 3,000 Vermont consumers, or sell the personal data of at least 3,000 Vermont consumers. The statute provides consumers with familiar rights to access, correct, and delete personal data, and opt out of targeted advertising, sales, and certain profiling. Controllers must honor opt-out preference signals, disclose whether personal data is used or sold to train large language models, and obtain consent before processing or selling sensitive data. The law also prohibits targeted advertising and sales involving known minors between 13 and 17, requires data protection assessments for high-risk processing, and imposes special restrictions on consumer health data, including a geofencing restriction around health care facilities. Enforcement rests exclusively with the Vermont AG, with no private right of action, and a 60-day cure period applies until June 30, 2029. Governor Scott also signed related data broker registration and genetic privacy laws, signaling a broader state focus on data commercialization and sensitive-data controls.

New Jersey Enacts Data Broker Law: New Jersey Governor Mikie Sherrill signed Assembly Bill 5328 into law, making New Jersey the seventh state to enact a data broker law and creating a framework that applies not only to traditional data brokers but also to “data collectors” that have a direct consumer relationship and sell or license personal data to data brokers. The law requires covered entities to register annually with the Division of Consumer Affairs, submit detailed information about opt-out and deletion rights, purchaser credentialing, processors, cybersecurity events, and data practices regarding minors, and pay tiered registration fees ranging from $5,000 to $1.5 million based on the number of New Jersey consumers whose personal data is sold or licensed. The law also broadly prohibits data brokers and data collectors from selling or licensing sensitive data, including health, financial, biometric, child, and precise geolocation data. Violations of the law may trigger penalties of $50,000 per record. Failure to register or update required information can result in uncapped daily penalties of $2,500, creating meaningful compliance exposure for adtech, data monetization, analytics, and data-supplier relationships.


FEDERAL LAWS & REGULATIONS

White House Issues Executive Order on Frontier AI Cybersecurity: President Trump signed Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” (the “Order”) establishing a federal framework intended to advance artificial intelligence (“AI”) innovation while addressing cybersecurity and national security risks associated with frontier AI systems. The Order directs the Treasury Department, the Cybersecurity and Infrastructure Agency (“CISA”), the National Security Agency (“NSA”), the National Institute of Standards and Technology (“NIST”), and other agencies to create a classified benchmarking process for assessing advanced cyber capabilities and determining when an AI model qualifies as a “covered frontier model”. Developers may voluntarily provide the federal government access to covered frontier models for up to 30 days before release to trusted partners, subject to confidentiality, cybersecurity, insider-risk, intellectual property, and nondisclosure protections. The Order expressly disclaims any mandatory licensing, preclearance, or permitting requirement for AI model development or release, reflecting an effort to balance model-security review against industry concerns about innovation burdens. The Order also calls for an AI cybersecurity clearinghouse to coordinate vulnerability scanning, validation, remediation, and patch distribution, while directing expanded AI-enabled cyber defense tools for federal systems, state and local authorities, and critical infrastructure operators such as hospitals, community banks, and utilities.

House Members Release Discussion Draft of Federal AI Governance Framework: Representatives Jay Obernolte and Lori Trahan released a bipartisan discussion draft of the “Great American Artificial Intelligence Act of 2026,” which would create a federal AI governance framework focused primarily on “frontier” AI model development and catastrophic risk mitigation. The draft would require large frontier developers with more than $500 million in annual gross revenue to write, implement, comply with, and publicly post a frontier AI framework addressing catastrophic risks, including risks involving mass casualties, significant property damage, cyberattacks, chemical, biological, radiological, nuclear, and high-yield explosives (“CBRNE”) assistance, and loss of model control. Developers also would need to publish transparency reports before or concurrently with deploying a new or substantially modified frontier model, including information about intended use, restrictions, catastrophic-risk assessments, and assessment results. The proposal would require semiannual audits by licensed Independent Verification Organizations and could impose civil penalties of up to $1 million per day for noncompliance. The draft would preempt state laws specifically regulating AI model development for three years, while preserving state laws of general applicability and laws governing post-deployment use, including consumer privacy laws.

White House Directs Accelerated AI Use Across National Security Enterprise: President Trump issued National Security Presidential Memorandum 11 on June 5, 2026, directing the federal national security enterprise to accelerate the development and deployment of AI for intelligence, defense, and other national security applications. The memorandum is organized around four pillars: adoption of AI in mission areas, adaptation of commercial and open-source AI technologies, assurance that systems are reliable and secure, and accountability for civil liberties, privacy, and constitutional protections. The memorandum also calls for updated procurement processes, partnerships with private-sector companies to secure cutting-edge AI technologies against threats such as malicious distillation attacks, and a joint AI risk-management and assurance strategy establishing baseline AI security practices. These measures may create new contracting, governance, security-testing, incident-response, and privacy-compliance expectations for technology providers supporting national security use cases.

House Leaders Announce Bipartisan Children’s Online Safety Package: House Energy and Commerce Chair Brett Guthrie and Ranking Member Frank Pallone announced agreement on the Kids Internet and Digital Safety Act (“KIDS Act”), a revised bipartisan package combining portions of 14 proposals, including the Kids Online Safety Act (“KOSA”), the Children and Teens’ Online Privacy Protection Act (“COPPA 2.0”), the Shielding Children’s Retinas from Egregious Exposure on the Net Act (“SCREEN Act”), the Safeguarding Adolescents from Exploitive BOTs Act (“SAFE Bots Act”), the Safe Guarding of Adolescents from Malicious Interactions on Network Games Act (“Safer GAMING Act”), data broker disclosures, and online safety education measures. The bill would establish default safety and privacy protections for minors, require parental control tools and teen messaging controls, restrict certain harmful advertising to minors, and mandate reporting mechanisms and annual independent audits for covered platforms. It would also expand COPPA-style protections to teens, prohibit individual-specific advertising to children or teens, add deletion and correction rights, require reasonable security practices, and create federal registration obligations for data brokers trafficking in minors’ personal data. Additional provisions address age verification for pornography sites, safeguards for online gaming communications, chatbot disclosures and crisis resources, and educational resources on chatbot privacy and data collection practices. The proposal has already drawn criticism from Senate KOSA sponsors and digital rights advocates concerned about enforceability, privacy, age verification incentives, and First Amendment risks.

White House Issues Executive Orders on Post-Quantum Cryptography and Quantum Innovation: President Trump signed two Executive Orders (here and here) establishing a federal roadmap for post-quantum cryptography (“PQC”) migration and accelerated U.S. quantum technology development. The cryptography order responds to “harvest now, decrypt later” risks by requiring federal agencies to transition high value assets and high impact systems to NIST-approved PQC for key establishment by December 31, 2030, and digital signatures by December 31, 2031. CISA and NIST must issue guidance on cryptographic bills of materials, which may become a key tool for assessing cryptographic assets across software, hardware, vendors, cloud services, identity systems, and embedded devices. A companion quantum innovation order directs agencies to advance quantum computing, sensing, networking, supply chains, workforce development, and international controls intended to prevent countries of concern from acquiring critical quantum-enabling technologies.

FTC Seeks Comment on Proposed AI Accuracy Policy Statement: The Federal Trade Commission (“FTC”) issued a proposed policy statement addressing AI companies’ alleged manipulation of AI system outputs in ways that may conflict with consumers’ reasonable expectations of objectivity and accuracy. The proposal states that AI companies have often represented, expressly or implicitly, that their systems are designed to provide outputs that faithfully and accurately respond to user objectives, and that undisclosed efforts to steer outputs toward ideological or other hidden objectives may constitute deception under Section 5 of the FTC Act. The FTC specifically highlights state AI laws, including Colorado’s revised Artificial Intelligence Act, as potentially pressuring companies to alter AI outputs in ways that could create federal consumer protection risk. The FTC notes that clear and conspicuous disclosures may reduce deception risk, but buried terms or one-time disclaimers are unlikely to be sufficient where they contradict broader marketing impressions. Public comments are due July 31, 2026.


U.S. LITIGATION

Supreme Court Ends Protections on Removal of FTC Commissioners: The U.S. Supreme Court ruled in Trump v. Slaughter that the FTC Act’s for-cause removal protection for FTC Commissioners violates separation-of-powers principles, overruling Supreme Court precedent after President Trump removed Commissioners Rebecca Slaughter and Alvaro Bedoya without identifying statutory cause. The majority emphasized that the modern FTC exercises executive power through rulemaking, investigations, in-house adjudications, and federal court enforcement actions, and therefore must be subject to presidential control. The FTC is a central federal regulator for consumer protection, deceptive practices, privacy, and data security matters, and the ruling may cause enforcement priorities, investigations, rulemaking, and settlements to more directly track White House policy preferences. Although the majority noted that the ruling does not apply to the Federal Reserve and likely does not apply to non-Article III courts, it calls into question similar statutory protections for other independent agencies, including the National Labor Relations Board (“NLRB”), the Securities and Exchange Commission (“SEC”), and Federal Energy Regulatory Commission (“FERC”). The dissent warned that the decision replaces 90 years of settled practice with uncertainty, while Justice Gorsuch’s concurrence suggested future cases may revisit broader delegations of legislative and adjudicative authority to agencies.

Supreme Court Preserves Key Federal Agency Enforcement Tools: The U.S. Supreme Court issued two decisions that preserve certain federal agency enforcement authority in the wake of recent Seventh Amendment challenges to administrative penalties and remedies. In FCC v. AT&T, the Court upheld the Federal Communication Commission's ability to issue forfeiture orders against wireless carriers arising from alleged failures to protect customer location data, concluding that the orders do not violate the Seventh Amendment because they do not themselves conclusively establish payment obligations and may be enforced only through a Department of Justice collection action with de novo judicial review. In Sripetch v. SEC, the Court unanimously held that the SEC may obtain disgorgement without proving that investors suffered pecuniary loss, so long as the remedy targets unjust gains tied to the violation of protected interests. Both rulings reject efforts to further narrow agency enforcement after Jarkesy, while leaving open future questions about when agency monetary remedies may require jury-trial protections.

Supreme Court Rules Geofence Warrants Are Fourth Amendment Searches: The U.S. Supreme Court issued a 6-3 decision in Chatrie v. United States, holding that law enforcement conducts a Fourth Amendment search when it obtains Google Location History data through a geofence warrant, even where the data covers a limited period and is held by a third-party technology company. The case arose from a 2019 Virginia credit union robbery investigation in which police used a 150-meter geofence around the crime scene and a three-step process that first produced anonymized data for 19 users, then expanded location histories for nine users, and ultimately disclosed identifying information for three users, including Chatrie. The Court rejected the government’s reliance on the third-party doctrine, emphasizing that users retain a reasonable expectation of privacy in cell phone location information notwithstanding Google’s possession of the data. The Court did not decide whether the warrant satisfied probable cause and particularity requirements at each stage, remanding that issue to the Fourth Circuit.

California Court Dismisses CIPA Pen Register Claims Against Website Operator: A Los Angeles County Superior Court dismissed with prejudice claims against NetScout Systems, Inc. alleging that the company violated the California Invasion of Privacy Act’s (“CIPA”) pen register and trap and trace provisions by deploying a third-party software development kit on its commercial website. The Court held that California Penal Code Section 638.51 applies to telephone communications, not to software operating on commercial websites. The ruling is significant for companies using pixels, web beacons, software development kits (“SDKs”), session replay tools, identity resolution tools, and other website analytics technologies, as plaintiffs have increasingly invoked CIPA to challenge routine web tracking practices. The Court emphasized that the legislature added the relevant provisions in 2015, when internet data collection and commercial websites were already widespread, but did not expressly extend the statute to website technologies. For privacy and security professionals, the decision provides persuasive authority for early dismissal of similar claims and may weaken arguments that CIPA requires affirmative opt-in consent for ordinary website analytics. However, because the ruling is a state trial court decision and does not address other CIPA theories, companies should continue evaluating website tracking disclosures, consent flows, and vendor configurations in light of ongoing litigation risk.

Washington Federal Court Says Refer-a-Friend Texts Not Exempt from CEMA: A Washington federal judge denied Chime Financial Inc.’s (“Chime”) motion to dismiss a putative class action alleging that Chime violated Washington’s Commercial Electronic Mail Act (“CEMA”) and Consumer Protection Act through its refer-a-friend texting program. The complaint alleges that Chime users could select phone contacts in the Chime mobile application and, with “just a few taps,” send pre-populated marketing texts with customized referral links encouraging recipients to download the Chime app. The Court rejected Chime’s argument that the program fell within CEMA’s exception for technologies with “commercially significant” uses, reasoning that Chime’s interpretation would allow almost any company to avoid liability for commercial texts by identifying some alternative business purpose. The Court also found that CEMA does not contain an exception for unsolicited commercial texts sent by friends or trusted contacts, and that the plaintiff plausibly alleged recipients had not provided advance consent. The decision is notable for companies using referral, affiliate, or viral marketing tools because it underscores that app-facilitated “friend-to-friend” messages may still create exposure under CEMA where commercial texts are prewritten, incentivized, and sent without legally sufficient consent.

Fifth Circuit Unblocks Texas App Store Age Verification Law During Appeal: The Fifth Circuit stayed preliminary injunctions against Texas Senate Bill 2420, the App Store Accountability Act (“SB 2420”), allowing the law to move forward while Texas appeals the district court’s ruling blocking enforcement. The law requires app store operators to verify users’ ages, link minors’ accounts to a parent or guardian, obtain parental consent for minors’ app downloads and in-app purchases, and provide age gating and content information, while also limiting developers’ collection and processing of minors’ personal data. The panel concluded that app store transactions are commercial in nature and therefore likely subject, at most, to intermediate scrutiny rather than strict scrutiny, emphasizing that “free” apps are often monetized through access to user data and private information. The court further found that SB 2420 likely advances Texas’s substantial interest in protecting children’s data, safety, and privacy online without burdening substantially more speech than necessary.

Sixth Circuit Revives Ohio Social Media Parental Consent Law: A divided Sixth Circuit reversed a district court order blocking Ohio’s Parental Notification by Social Media Operators Act (the “Act”), which requires covered social media operators to obtain verifiable parental consent before unemancipated minors under 16 create accounts, provide parents with information about content-moderation features, and deny access absent consent. The majority held that NetChoice was not the proper party to assert minor users’ First Amendment rights and that NetChoice failed to show the Act was facially unconstitutional or impermissibly vague. Although the lead opinion concluded that the Act burdens protected speech and is content-based, it found the law survived strict scrutiny because Ohio’s interests in protecting minors and promoting parental involvement were compelling and the parental-consent mechanism was sufficiently tailored to address risks from unsupervised social media use. The ruling adds to the unsettled national landscape over age assurance, youth online safety laws, and the constitutional limits of regulating minors’ access to social media platforms.

Washington AG States Text Breach Notifications Insufficient: The Washington AG moved for partial summary judgment against T-Mobile, arguing that the company's post-breach text messages failed to comply with Washington's data breach notification statute and independently violated the state's Consumer Protection Act. The motion arises from T-Mobile's August 2021 breach, which allegedly exposed personal information of more than two million Washingtonians, including names, Social Security numbers, driver's license information, phone numbers, addresses, dates of birth, and device identifiers. The Washington AG contends that T-Mobile sent breach notices solely by text message to 361,030 current Washington customers, even though Washington's substitute-notice framework requires email notice when the business has email addresses for affected individuals. The Washington AG further alleges that the texts omitted required information, including T-Mobile's contact information, the categories of personal information exposed, the breach time frame, and contact information for major credit reporting agencies. The Washington AG argues that T-Mobile's notices downplayed risk by emphasizing what data was not exposed while directing consumers to shortened links for critical breach details, despite T-Mobile's own anti-smishing guidance cautioning customers not to click links in text messages.


U.S. ENFORCEMENT

HHS OCR Settles Ransomware Investigation with Employer-Sponsored Health Plan: The U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a $450,000 settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (the “Plan”), resolving alleged Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy and Security Rule violations following a ransomware incident affecting the protected health information (“PHI”) of 10,023 individuals. The incident began following employee complaints about virtual private network (“VPN”) access issues, leading the Plan to discover that an unauthorized actor had accessed the company network in November 2021, deployed ransomware, and encrypted data on systems that included servers storing Plan PHI. OCR identified potential failures to conduct an accurate and thorough HIPAA Security Rule risk analysis and to implement reasonable and appropriate HIPAA policies and procedures before the breach. The settlement is OCR’s 20th ransomware enforcement action and 14th enforcement action under its Risk Analysis Initiative, underscoring that OCR continues to treat pre-incident risk analysis as a core cybersecurity compliance obligation. The two-year corrective action plan requires the Plan to conduct a risk analysis, revise HIPAA policies and procedures as needed, and train workforce members on those policies and procedures. OCR also emphasized practical safeguards for regulated entities, including mapping ePHI flows, maintaining risk management plans, reviewing system activity, implementing audit controls and authentication, encrypting ePHI where appropriate, incorporating incident lessons learned, and providing role-specific HIPAA training.

Navy Contractor Settles FCA Cybersecurity Claims: The Department of Justice (“DOJ”) entered into a $507,144 settlement with LOGZONE, Inc. (“LOGZONE”), a logistics services provider, to resolve civil claims arising from Navy contracts for logistical, inventory, and facilities support services at Stennis Space Center, Mississippi. The contracts incorporated the U.S. Department of Defense’s Defense Federal Acquisition Regulation Supplement(“DFARS”) 252.204-7012, requiring adequate security for covered contractor information systems by implementing NIST SP 800-171 controls, as well as DFARS 252.204-7019 and 252.204-7020, requiring contractors to post current NIST SP 800-171 self-assessment scores in the supplier performance risk system (“SPRS”). LOGZONE submitted a perfect SPRS score of 110 in October 2021, but a February 2024 Defense Contract Management Agency (“DCMA”) Defense Industrial Base Cybersecurity Assessment Center (“DIBCAC”) Medium Assessment resulted in a score of -170. The United States alleged that, from May 2021 through March 2025, LOGZONE had not fully implemented required cybersecurity controls on systems processing, storing, or transmitting covered defense information and nevertheless submitted claims for reimbursement while knowing it had not complied with DFARS 252.204-7012. The settlement underscores the enforcement risk associated with inaccurate cybersecurity attestations, particularly where contractual cybersecurity obligations are tied to federal payment claims. Notably, the DOJ expressly reserved criminal liability, administrative remedies, and suspension and debarment rights, reinforcing that civil settlement may not end cybersecurity-related exposure for government contractors.

DOJ and BIS Announce First National Security Division Corporate Enforcement Policy Declination: DOJ’s National Security Division (“NSD”) declined to prosecute Robert Bosch GmbH (“Bosch”) after Bosch voluntarily disclosed potential export control violations involving foreign-produced sensor products and automotive software provided to Huawei and its affiliates on the Entity List maintained by the Department of Commerce’s Bureau of Industry and Security (“BIS”) without required authorization from BIS. BIS separately alleged that Bosch committed 109 violations between September 2020 and September 2024 involving approximately $72.4 million in Micro-Electro-Mechanical Systems sensor products and software. The products included sensors used in smartphones, wearables, and automobiles, as well as automotive firmware that secures electronic control units and vehicle network data transmissions. According to BIS, Bosch’s U.S. export compliance team lacked sufficient expertise and resources to address the August 2020 Foreign Direct Product Rule expansion for Huawei, and Bosch continued shipments despite supplier warnings and internal indications that further diligence was required. Bosch agreed to disgorge approximately $11.4 million in profits, while BIS assessed a $36.18 million civil penalty, with payment tied to Bosch’s continuing export privileges.

New Jersey Bureau of Securities Annual Adviser Examination Focuses on AI and Cybersecurity: The New Jersey Bureau of Securities (the “Bureau”) has launched its 2026 annual examination of nearly 800 state-registered investment adviser firms, with a particular focus on how firms use AI and protect investors’ sensitive data online. The examination will assess whether advisers use AI to construct portfolios, develop client recommendations, gather data, or conduct research, and will review how firms market or advertise AI-enabled capabilities and disclose those practices to clients. The Bureau also will evaluate whether firms maintain written cybersecurity policies and procedures, conduct periodic employee training, and perform ongoing due diligence on third-party vendors, including review of vendor cybersecurity practices. Registered investment advisers must complete the electronic examination by June 30, 2026.

Florida AG and Streaming Service Provider Announce Resolution of Privacy Enforcement Action: Florida AG James Uthmeier and streaming service provider, Roku announced a negotiated resolution of an enforcement action filed under the Florida Digital Bill of Rights concerning children’s privacy in streaming services. Under the resolution, Roku agreed to enhance child protection features and provide parents with greater control over their children’s streaming experience, including tools to decide how children’s data are used. The resolution does not include any finding of wrongdoing or civil fine, but Roku agreed to devote an estimated $25 million in engineering resources to implement the changes, reflecting a significant operational compliance commitment. Implementation is expected to begin immediately, with full nationwide deployment anticipated within 12 months.


INTERNATIONAL LAWS & REGULATIONS

Canada Introduces Major Private-Sector Privacy Reform Bill: The Government of Canada introduced Bill C-36, which would enact the Protecting Privacy and Consumer Data Act (“PPCDA”) and represent the most significant overhaul of Canada’s private-sector privacy law in more than 25 years. The bill would recognize privacy as a fundamental right, strengthen meaningful consent and transparency requirements, permit individuals to request deletion or disposal of personal information in certain circumstances, support data mobility, and increase transparency around automated decision systems, including AI-enabled systems. The PPCDA would also require organizations to treat children’s personal information with heightened protections and to assess and mitigate privacy risks before transferring personal information outside Canada. The bill would also establish a new Digital Safety and Data Protection Commission of Canada, with a designated Privacy and Consumer Data Commissioner leading PPCDA oversight. The Commission would have authority to issue binding orders, impose administrative monetary penalties up to $10 million or three percent of global revenue, and seek fines up to $25 million or five percent of global revenue for the most serious offenses.

EU Commission Publishes Code of Practice on AI-Generated Content Transparency: The European Union (“EU”) Commission published the final voluntary Code of Practice on marking and labeling AI-generated content (the “Code”), providing practical steps for providers and deployers of generative AI systems to meet EU AI Act transparency obligations that apply beginning August 2, 2026. The transparency rules require clear labeling for deepfakes and AI-generated or AI-manipulated text published on matters of public interest, and require users to be informed when they are interacting with an interactive AI system such as a chatbot. For providers, the Code addresses machine-readable marking and detection of AI-generated or manipulated audio, images, video, and text. For deployers, the Code explains labeling obligations for deepfakes and AI-generated or manipulated text made available to inform the public on matters of public interest where there has been no human review or editorial control. Although signing the Code is voluntary, the EU AI Act’s Article 50 transparency obligations remain legal requirements, and signatories may rely on the Code’s measures to demonstrate compliance once the Commission and AI Board assess it as adequate.

Canada Launches National AI Strategy: Canada announced its “AI for All” national strategy, a broad federal plan to accelerate AI adoption, strengthen sovereign AI infrastructure, and address governance risks while maintaining protections for personal data. The strategy sets an ambitious goal of increasing business AI adoption from 12 percent to 60 percent by 2034, creating up to 250,000 jobs through AI adoption by 2031, and generating nearly CAD $200 billion in gross domestic product (“GDP”) gains through productivity and commercialization in key sectors. For privacy and security professionals, the most significant elements are the government’s commitments to modernize consumer privacy legislation, enshrine a fundamental right to privacy, safeguard children’s information, strengthen control over personal data, and address AI-enabled harms such as deepfakes, unsafe chatbot interactions, online harms, algorithmic bias, and surveillance pricing. In parallel, Canada will invest in sovereign compute, cloud, secure government systems, health data infrastructure, and international technology partnerships, reflecting a strategy that treats data governance, infrastructure control, and trustworthy AI as core elements of national competitiveness.

EDPB Adopts Common Data Breach Notification Template: The European Data Protection Board (“EDPB”) adopted a common data breach notification template designed to harmonize and streamline notifications to supervisory authorities under Article 33 of the General Data Protection Regulation (“GDPR”). The template is intended to help organizations structure notifications, ensure required information is included, reduce time and cost burdens, and assist smaller organizations that may lack dedicated data protection officer (“DPO”) or legal resources. The template includes predefined response options and field-level guidance, and it will remain open for public consultation until August 5, 2026. Following the consultation, the EDPB will determine the timeline for practical implementation by data protection authorities.

UN Human Rights Office Issues Guidelines on Getting Children’s Online Safety Right: The United Nations (“UN”) Human Rights Office (the “Office”) issued guidance urging governments and technology companies to strengthen children’s online safety through effective regulation, oversight, and accountability, while preserving children’s rights to privacy, expression, access to information, and participation. The guidance emphasizes that online harms are not inherent to digital services but often result from platform design choices and business practices, including addictive features such as infinite scroll, autoplay, and persistent notifications. Of particular interest to privacy and security professionals, the Office calls for maximum default protection of children’s data, limits on data collection and use, purpose limitation, heightened safeguards, meaningful parental and child control, and a prohibition on commercial micro-targeting of children. While acknowledging growing interest in age-based restrictions following Australia’s under-16 social media law and similar measures in other countries, the Office cautions that blanket bans may be easy to circumvent and could push children toward less monitored platforms. The Office instead recommends targeted restrictions tied to specific harms, robust guardrails for age verification, and privacy-preserving approaches to age assurance.


RECENT PUBLICATIONS & MEDIA COVERAGE

What CIOs Need to Know About AI Notetaking Security

Blank Rome vice chair of artificial intelligence Sharon R. Klein and Chief Information Officer Frank Spadafino authored this TechTarget article discussing how AI meeting-recording and transcription tools can significantly improve collaboration, accountability, as well as follow-through, yet organizations must deploy them with proper privacy, security, and information-governance controls to manage any potential risks associated with their use.


© 2026 Blank Rome LLP. All rights reserved. Please contact Blank Rome for permission to reprint. Notice: The purpose of this update is to identify select developments that may be of interest to readers. The information contained herein is abridged and summarized from various sources, the accuracy and completeness of which cannot be assured. This update should not be construed as legal advice or opinion, and is not a substitute for the advice of counsel.