Welcome to this month’s issue of The BR Privacy, Security & AI Download, the digital newsletter of Blank Rome’s Privacy, Security & Data Protection practice. We invite you to share this resource with your colleagues and visit Blank Rome’s Privacy, Security & Data Protection webpage for more information about our team.
RECENT HIGHLIGHT
Colorado Replaces AI Act with Narrower New AI Law
Blank Rome vice chair of artificial intelligence Sharon R. Klein, partners Alex C. Nisenbaum and Rachel L. Schaller, and associates Karen H. Shin and Gabrielle N. Ganze authored this alert discussing Colorado’s new AI law, which replaces prior legislation with a narrower, business-friendly framework emphasizing transparency, notice, and consumer rights for high-impact automated decisions while also easing compliance requirements.
STATE & LOCAL LAWS & REGULATIONS
Colorado Repeals and Replaces Colorado AI Act: Colorado Governor Jared Polis signed Senate Bill 189, a bill that repeals and replaces the 2024 Colorado AI Act with a narrower, more business-friendly framework focused on automated decision-making technology (“ADMT”) used in consequential decisions. The new law significantly scales back the obligations that would have applied under the 2024 Colorado AI Act that was set to take effect on June 30, 2026, while preserving notice, recordkeeping, consumer rights, and certain other obligations for ADMT used in high-impact contexts. Colorado will continue to have one of the most far-reaching legislatively enacted private-sector AI or ADMT laws in the United States. For a detailed overview of the new law, see our Client Alert.
California Attorney General Announces $12.75 Million Privacy Settlement with Auto Manufacturer over Unlawful Sale of Driver Data: California Attorney General Rob Bonta, together with the District Attorneys of San Francisco, Los Angeles, Napa, and Sonoma Counties, and with support from the California Privacy Protection Agency (“CalPrivacy”), announced a $12.75 million settlement with General Motors LLC (“GM”) and OnStar LLC (“OnStar”). The settlement represents the largest California Consumer Privacy Act (“CCPA”) penalty in California history to date. The complaint alleged that from 2020 to 2024, GM collected and sold the names, contact information, precise geolocation data, and driving behavior data of hundreds of thousands of California OnStar subscribers to data brokers without consumer knowledge or consent. The data was intended to develop driver-rating products for auto insurers, despite GM’s privacy policy stating it did not sell driving or location data. The case represents the Attorney General’s first enforcement of the CCPA’s data minimization principle, alleging GM retained data long after it was needed for OnStar services and sold it for an entirely unrelated purpose. The settlement requires GM to stop selling driving data to consumer reporting agencies for five years, delete retained driving data within 180 days, improve its privacy compliance program, and report its privacy assessments to the California Department of Justice, the District Attorneys, and CalPrivacy.
Georgia and Iowa Enact Artificial Intelligence (“AI”) Chatbot Laws: Georgia and Iowa enacted new laws imposing requirements on operators of AI-powered conversational chatbots. Georgia’s S.B. 540 regulates “AI companion chatbots” designed to simulate sustained human-like relationships with users. Iowa’s Senate File 2417 similarly targets “conversational AI services” whose primary purpose is simulating human conversation. Both statutes require operators to clearly disclose to users that they are interacting with AI, mandate protocols for detecting and responding to suicidal ideation or self-harm, and impose content restrictions to protect minors from sexually explicit material and simulated romantic interactions. Both laws vest enforcement authority exclusively in the State Attorney General and do not create a private right of action. Georgia authorizes civil penalties of up to $10,000 per knowing violation per user per day, while Iowa imposes penalties of up to $1,000 per violation, capped at $500,000 per operator. Both laws take effect on July 1, 2027.
Colorado Legislature Passes Bill Prohibiting Individualized Price and Wage Setting Using Surveillance Data: The Colorado legislature passed House Bill 26-1210, which prohibits businesses from engaging in individualized price and wage setting through the use of “surveillance data.” The law defines a “price or wage setting algorithm” (“PWSA”) as any technology, software, or computational process that uses statistical modeling, data analytics, AI, or other data processing techniques to analyze surveillance data and is a substantial factor in setting prices or wages offered to individuals. “Surveillance data” broadly encompasses data obtained through observation, inference, or surveillance of consumers or workers related to personal characteristics, online behaviors, or biometrics. The law carves out several exceptions, including differential pricing based on cost differences, supply-and-demand fluctuations, publicly disclosed loyalty or rewards programs, need-based discount programs, and credit decisions by licensed financial institutions. For wage setting, exceptions apply when individualized wages are based solely on worker seniority or task-specific performance data, provided the employer discloses what data is considered. Businesses using PWSAs must publish procedures ensuring data accuracy and allowing workers to correct or challenge the data used. Violations constitute deceptive trade practices under the Colorado Consumer Protection Act. The Colorado Attorney General has rule-making authority to implement and enforce the law. If signed, the law will take effect on August 12, 2026.
California Attorney General Releases Proposed Regulations under SB 976 “Protecting Our Kids from Social Media Addiction Act”: The California Department of Justice released proposed regulations implementing Senate Bill 976, the Protecting Our Kids from Social Media Addiction Act (the “Act”), which was enacted in September 2024. The Act makes it unlawful for operators of “addictive internet-based services or applications” to provide addictive feeds or send notifications during specified hours to minors without first obtaining verifiable parental consent. The proposed regulations establish requirements for age assurance and parental consent, including permissible age assurance methods such as biometric facial analysis, behavioral signals, cryptographic techniques, and government-issued identification. The regulations prohibit operators from relying solely on self-declaration, contractual terms of service, or payment methods available to minors to determine that a user is not a minor. Operators must publish transparency reports detailing their age assurance methods and implement protocols to prevent circumvention. A 45-day public comment period is open through June 30, 2026.
NYDFS Issues Guidance on Heightened Cybersecurity Risks from Frontier AI Models: The New York State Department of Financial Services (“NYDFS”) issued an Industry Letter and accompanying guidance addressing cybersecurity risks posed by frontier AI models capable of amplifying the potency, scale, and speed of identifying vulnerabilities and exploits in information systems. NYDFS Acting Superintendent Kaitlin Asrow stated that the guidance offers regulated entities with steps they can take when the threat environment escalates. While the guidance does not impose new legal requirements, it urges entities regulated under 23 NYCRR Part 500 to review and update risk assessments to reflect the evolving risks posed by frontier AI, including by replacing end-of-life or legacy information systems and confirming full compliance with existing cybersecurity regulations. Key recommendations include expediting vulnerability management timelines, coordinating with third-party service providers to secure material downstream dependencies, strengthening the security of programming practices, and evaluating whether existing logging and alerting capabilities are sufficient to address heightened threats. The guidance follows NYDFS’s October 2024 guidance addressing AI-related cybersecurity risks such as deepfakes, phishing schemes, and enhanced cyberattacks.
Louisiana Legislature Passes Comprehensive Data Privacy Act: The Louisiana Legislature unanimously passed Senate Bill 386, the Louisiana Data Privacy Act (“LDPA”). The LDPA applies to entities doing business in Louisiana that meet at least one of three thresholds: annual gross revenues exceeding $25 million; annually buying, selling, or sharing the personal data of 75,000 or more consumers, households, or devices; or deriving 50 percent or more of annual revenue from selling consumers’ personal data. The LDPA grants consumers the right to access, correct, delete, and obtain portable copies of their personal data, and to opt out of targeted advertising, data sales, and certain profiling activities. Controllers must maintain accessible privacy notices, implement reasonable data security practices, and obtain affirmative consent before processing sensitive data, including biometric data, precise geolocation data, and data revealing racial origin, health diagnoses, or sexuality. Regulated entities are also required to conduct data protection assessments for high-risk processing activities. The LDPA exempts HIPAA-covered entities, financial institutions subject to the Gramm-Leach-Bliley Act, nonprofits, and institutions of higher education. Enforcement rests exclusively with the Louisiana Attorney General, with no private right of action. A temporary 30-day cure period would apply until July 31, 2027, after which the cure right expires. If enacted, the law will take effect on January 1, 2027.
Illinois General Assembly Passes Frontier AI Safety Bill: The Illinois General Assembly approved Senate Bill 315, the Artificial Intelligence Safety Measures Act (the “Act”), which Governor JB Pritzker has indicated he will sign. The bill, which would take effect on January 1, 2027, establishes a comprehensive transparency and safety framework for “frontier models.” “Frontier models” are defined as foundation models trained using computing power exceeding 10²⁶ operations. “Large frontier developers,” defined as those with annual gross revenues exceeding $500 million, must publish and comply with a “frontier AI framework” addressing catastrophic risk assessment, mitigation, cybersecurity practices, and internal governance. “Catastrophic risk” is defined to include models capable of mass harm or damages exceeding $1 billion through cyberattacks or malfunction beyond human control. The bill introduces a first-of-its-kind requirement for annual independent third-party auditing of compliance. Developers must publish pre-deployment transparency reports detailing model capabilities, intended uses, and risk assessments. The bill includes whistleblower protections prohibiting retaliation against employees who report safety risks, critical safety incident reporting to the Illinois Emergency Management Agency, and civil penalties up to $1 million for initial violations and $3 million for subsequent violations, enforceable exclusively by the Illinois Attorney General.
Connecticut Enacts Broad AI and ADMT Bill: The Connecticut Legislature passed Senate Bill 5 (“S.B. 5”), a comprehensive AI law addressing frontier model regulation, automated employment-related decision technology (“ADMT”), and AI companions. With respect to ADMT, S.B. 5 requires deployers to disclose to employees and applicants when automated technology is used to make or materially influence employment-related decisions, including hiring, promotion, discipline, and discharge. Deployers must provide written notice identifying the technology’s purpose, the categories of personal data analyzed, the data sources, and deployer contact information. The law expressly provides that use of ADMT is not a defense against employment discrimination claims, though courts may consider evidence of anti-bias testing. Developers must furnish deployers with information necessary for compliance, unless the technology was not marketed for employment decisions. Violations constitute unfair or deceptive trade practices enforceable solely by the Attorney General, with a cure period for violations occurring before December 31, 2027. No private right of action is created. The law is effective on October 1, 2026.
FEDERAL LAWS & REGULATIONS
OCC Highlights AI as Both Cybersecurity Threat and Defense Tool for Banks: The Office of the Comptroller of the Currency (“OCC”) released its Spring 2026 Semiannual Risk Perspective report, finding that AI is “significantly transforming” the cybersecurity threat landscape for financial institutions. The OCC noted that AI lowers the barrier to entry for threat actors while increasing the speed, scale, and sophistication of cyberattacks, including facilitating fraud, automated reconnaissance, rapid vulnerability discovery, targeted social engineering, and adaptive malware capable of evading traditional defenses. At the same time, the OCC acknowledged that banks can deploy AI defensively for risk management, threat monitoring, and cybersecurity functions. The OCC identified unique risks associated with generative AI and agentic AI, including lack of explainability, data privacy concerns, data poisoning issues, and validation challenges.
House Energy and Commerce Committee Ranking Member Launches Surveillance Pricing Inquiry: Energy and Commerce Committee Ranking Member Frank Pallone, Jr. (D-NJ) launched a congressional inquiry into corporate surveillance pricing practices, sending an initial round of letters to 25 major corporations requesting detailed information about their use of consumers’ personal data to set individualized prices. Surveillance pricing, as defined by the Federal Trade Commission (“FTC”), involves companies using a consumer’s online data, including location, demographics, browsing history, shopping habits, and device type, to curate different prices, often charging higher amounts based on an inferred willingness to pay. The inquiry was prompted in part by an investigation by Consumer Reports and Groundwork Collaborative revealing that Instacart used an AI tool to conduct pricing tests for online shoppers, a practice the company described as generating “millions of dollars in annual incremental sales” for major grocery partners. Pallone emphasized that the absence of comprehensive federal privacy legislation has created a regulatory gap enabling these practices to proliferate. The letters request documentation, including all customer data elements used to inform pricing, whether companies use AI or machine learning algorithms to set prices, and whether customers are able to opt out of data collection for pricing purposes. The inquiry parallels state-level enforcement activity, including California Attorney General Bonta’s investigative sweep into surveillance pricing practices announced in recognition of Data Privacy Day.
State Attorneys General Oppose KIDS Act in Letter to Congressional Leaders: A bipartisan coalition of 42 state Attorneys General (“AG”) and the District of Columbia Attorney General, led by Connecticut AG William Tong, sent a letter to congressional leaders opposing the Kids Internet and Digital Safety Act (“KIDS Act”). The AGs argue the bill would insulate technology companies from meaningful oversight by broadly preempting conflicting state law across multiple domains, including online obscenity, online harms to children, social gaming platforms, and AI chatbots. The AGs highlighted several alleged deficiencies in the legislation: (1) the bill expressly disclaim any duty of care; (2) the bill imposes no age assurance obligations on covered platforms; (3) it permits market and product-focused research on minors under a broad “privacy, security, transparency, or safety” exception; and (4) its AI chatbot provisions contain a significant enforcement loophole for chat functions deemed “incidental” to a platform’s primary purpose. Although the KIDS Act allows limited enforcement by state AGs, it empowers federal preemption and intervention in all such actions. The letter contrasts the KIDS Act unfavorably with the Kids Online Safety Act, which, according to the AGs, preserves state authority, prohibits product-focused research on children, and imposes a meaningful duty of care. The AGs cautioned that the KIDS Act would undermine significant state-level progress on technology regulation and urged Congress not to foreclose the states’ role as “laboratories of democracy” on these rapidly evolving issues.
U.S. LITIGATION
California Supreme Court Issues Decision on Scope of CMIA and Customer Records Act: The California Supreme Court unanimously reversed a California Court of Appeal decision in J.M. v. Illuminate Education, Inc., holding that education technology company Illuminate did not qualify as a “provider of healthcare” under the Confidentiality of Medical Information Act (“CMIA”) and that the student plaintiff was not a “customer” entitled to sue under the California Customer Records Act (“CRA”). The case arose from a 2022 data breach that exposed students’ personal and medical information maintained by Illuminate on behalf of school districts. The Court found that Illuminate’s software, which stores health-related data to support educational evaluation and planning, did not make medical information available for individual health management or diagnosis and treatment purposes as required by the CMIA’s definition of a covered provider. The Court also rejected plaintiff’s CRA claim because the Ventura County Office of Education, not the plaintiff student, contracted with Illuminate and provided student data to the company. However, the Court adopted a new, more plaintiff-favorable standard for CMIA breach of confidentiality claims, holding that a plaintiff need not prove medical information was actually viewed by an unauthorized party. Instead, the Court held that liability attaches when data is exposed to a “significant risk of unauthorized access or use.” The Court specifically noted that AI-facilitated cyberattacks can exploit stolen data without human viewing, making an “actually viewed” standard unworkable in the modern threat landscape. Companies that maintain health-related data should review their data security practices, incident response protocols, and vendor agreements in light of this newly articulated standard.
43 States and DC File Amicus Brief Supporting Colorado Social Media Warning Label Law: A coalition of 43 states and the District of Columbia filed an amicus brief in the Tenth Circuit urging reversal of a district court’s preliminary injunction blocking enforcement of Colorado’s social media warning label law. The law requires social media platforms to notify minor users about the effects of social media on their developing brains or to provide regular notices about time spent on the platform and use during nighttime hours. The bipartisan coalition, led by Utah, argues that states have a compelling interest in protecting minors from the harm of excessive social media use, and that the law would survive even under the strict scrutiny standard applied by the district court. The brief details how social media companies deliberately engineer addictive features such as push notifications, autoplay, and infinite scrolling to maximize engagement, particularly among minors whose developmental immaturity makes them especially susceptible. The states cite research showing that adolescents spending more than three hours daily on social media face double the risk of anxiety and depression, while studies demonstrate that limiting use improves mental health outcomes. The case is NetChoice v. Weiser, No. 25-1456 (10th Cir.).
U.S. ENFORCEMENT
Pennsylvania Board of Medicine Files First-of-Its-Kind AI Enforcement Action Against Chatbot Operator: The Pennsylvania Department of State, acting on behalf of the State Board of Medicine, filed a Petition for Review in the Commonwealth Court seeking to enjoin Character Technologies, Inc., operator of the Character.AI platform, from engaging in the unlawful practice of medicine through its AI chatbot system. Character.AI is a generative AI platform with over 20 million monthly active users that allows individuals to create and interact with customizable chatbot characters. A Professional Conduct Investigator with the Department of State discovered a character named “Emilie,” described as a “doctor of psychiatry,” which had engaged in approximately 45,500 user interactions. During the investigation, Emilie offered to perform a psychiatric assessment, claimed licensure in Pennsylvania, and provided a fabricated license number. The Commonwealth alleges these actions constitute the unauthorized practice of medicine under Pennsylvania’s Medical Practice Act and seeks injunctive relief. Character Technologies responded that its characters are “fictional and intended for entertainment and roleplaying,” noting that disclaimers appear in every chat. The case signals a novel regulatory theory under which AI platforms may face unauthorized practice liability when chatbot outputs hold themselves out as licensed professionals.
NYDFS Secures $2.25 Million Cybersecurity Settlement with Dental Insurer: NYDFS announced a $2.25 million consent order with Delta Dental Insurance Company and Delta Dental of New York, Inc., resolving alleged violations of the state’s Cybersecurity Regulation. In mid-2023, threat actors exploited a zero-day vulnerability in Progress Software’s MOVEit Transfer platform, exfiltrating approximately 60,000 files containing consumers’ nonpublic information, including names, social security numbers, driver’s license numbers, financial account information, and patient health information. NYDFS found that the companies violated the Cybersecurity Regulation by failing to maintain policies and procedures for the secure periodic disposal of nonpublic information no longer necessary for business operations, failing to maintain adequate written incident response policies addressing regulatory reporting obligations, and failing to provide timely notice of the cybersecurity event to NYDFS. Delta reported the incident on December 15, 2023, more than six months after discovering the incident.
FTC Bans Sale of Sensitive Location Data by Data Broker: The FTC announced a proposed stipulated order resolving its enforcement action against data broker Kochava Inc. and its subsidiary, Collective Data Solutions (“CDS”), which has assumed Kochava’s data broker operations. The FTC originally sued Kochava in August 2022, alleging that the company’s collection, use, and disclosure of precise geolocation data from hundreds of millions of mobile devices constituted unfair practices under Section 5 of the FTC Act by revealing consumers’ movements to sensitive locations, including medical facilities, places of worship, and educational institutions serving minors. Under the proposed order, Kochava and CDS are prohibited from selling, licensing, transferring, or disclosing sensitive location data without the consumer’s affirmative express consent, and only where the data is used to provide a service the consumer directly requested. The order further requires CDS to establish a Sensitive Location Data Program to maintain and regularly update a comprehensive list of sensitive locations, implement a Supplier Assessment Program to confirm that consumers have consented to the collection of location data, report third-party data-sharing incidents to the FTC, provide consumers with a mechanism to identify recipients of their data and to withdraw consent, and create a data retention and deletion schedule. The consent framework defined in the order requires specific, informed, and unambiguous consent separate from any privacy policy or terms of service and prohibits the use of dark patterns or interfaces that subvert user autonomy.
Texas AG Sues Streaming Platform for Deceptive Data Collection and Surveillance of Users and Children: Texas AG Ken Paxton announced his office filed suit against Netflix, Inc., alleging that the streaming platform built a “behavioral-surveillance program of staggering scale” while publicly representing itself as an ad-free, privacy-respecting alternative to data-driven platforms like Google and Facebook. The petition alleges that Netflix’s CEO and senior executives repeatedly assured consumers that the company did not collect, integrate, or sell user data and that a paid subscription would shield users from surveillance-based advertising. In reality, the State alleges, Netflix quietly constructed a massive data pipeline to log behavioral events, including clicks, pauses, viewing duration, device information, household network data, and location, and subsequently disclosed this information to commercial data brokers and ad-tech platforms. The petition further alleges that Netflix misrepresented children’s profiles as “safe,” segregated spaces free from behavioral advertising while subjecting children to the same extensive data-logging infrastructure used for adults. The State also contends that Netflix employs “dark patterns,” such as default autoplay, to maximize screen time and data extraction, particularly from children. The suit, brought under the Texas Deceptive Trade Practices Act, seeks civil penalties of up to $10,000 per violation, an order to purge deceptively collected data, injunctive relief requiring informed consent for data collection and advertising, and a mandate to disable autoplay by default on children’s profiles.
Texas Attorney General Settles Lawsuit with TB Manufacturer over Smart TV Data Collection Practices: Texas AG Ken Paxton announced a settlement with LG Electronics U.S.A., Inc. (“LG”), resolving claims that LG unlawfully collected consumers’ viewing data through automatic content recognition (“ACR”) technology embedded in its Smart TVs without obtaining informed consent. Under the settlement, LG is prohibited from collecting or processing viewing data without obtaining consumers’ “Affirmative Express Consent,” defined as a freely given, specific, informed, and unambiguous indication of agreement following clear and conspicuous disclosure of the data collected, its purposes, and a simple means to withdraw consent. LG must update its Smart TV onboarding screens and website to include a clear summary of its ACR data practices, and model year 2027 and later TVs must display a pop-up notice during setup. LG also stipulated that viewing data has not been and will not be transmitted to the People’s Republic of China. The settlement follows Attorney General Paxton’s December 2025 lawsuit against five major TV manufacturers alleging unlawful consumer surveillance through ACR technology; cases against the remaining manufacturers are ongoing.
Oklahoma Sues Online Gaming Platform for Failing to Protect Children; Connecticut Launches Investigation: Oklahoma AG Gentner Drummond filed suit against Roblox, alleging the online gaming platform has failed to implement adequate safeguards to protect its minor users from sexual predation and exploitation. The complaint alleges that approximately two-thirds of U.S. children ages nine to 12 have Roblox accounts, that children as young as five can create accounts without parental knowledge, and that the platform lacks age verification, enabling predators to create accounts posing as children to groom and lure victims. The state alleges violations of the Oklahoma Consumer Protection Act and seeks civil penalties and a permanent injunction requiring the platform to implement meaningful safeguards and inform the public of the associated risks. Shortly thereafter, Connecticut AG William Tong announced an investigation into Roblox’s “harm to children,” issuing a civil investigative demand seeking information regarding user age data, revenue generated from minors, parental controls, and measures taken to prevent exploitation on the platform.
Oklahoma Attorney General Files Lawsuit Against Online Marketplace for Unlawful Data Collection and Consumer Deception: Oklahoma AG Gentner Drummond filed a lawsuit against Temu, the Chinese online shopping platform, alleging unlawful data collection, consumer privacy violations, and counterfeiting of well-known Oklahoma brands. The complaint alleges that Temu engaged in deceptive business practices designed to mislead consumers while secretly harvesting sensitive user data for the benefit of entities tied to the Chinese Communist Party. Specifically, the lawsuit alleges that Temu illegally collects users’ data without knowledge or consent, steals the intellectual property of U.S.-owned companies (including the Oklahoma City Thunder, Oklahoma State University, and the University of Oklahoma), employs bait-and-switch signup schemes, and fails to disclose its use of forced labor from Chinese ethnic minorities. The lawsuit alleges Temu’s mobile app secretly infiltrates users’ devices to access precise physical location, microphone and camera access, and private activity on other installed apps, all without user knowledge or consent.
FTC Settles Charges against Media Company Over Deceptive AI Marketing Claims: The FTC announced settlements totaling $930,000 with Cox Media Group (“CMG”), MindSift LLC, and 1010 Digital Works LLC, resolving allegations that the companies deceived customers by falsely claiming to offer an AI-powered “Active Listening” marketing service capable of targeting localized advertisements based on conversations captured from consumers’ smart devices. According to the FTC’s complaints, the service did not actually listen to or use consumer voice data; instead, the companies resold e-mail lists obtained from other data brokers at a significant markup. The FTC further alleged that the companies falsely represented that consumers had “opted in” to the service, when in reality no meaningful consent was obtained. The companies pointed to consumers’ acceptance of mandatory app terms of service, which the FTC stated does not constitute opt-in consent for such invasive data practices. The consent orders require CMG to pay $880,000, with MindSift and 1010 Digital Works each paying $25,000. Going forward, all three companies are prohibited from misrepresenting the capabilities of their advertising services, the collection and use of voice data, and whether consumers have provided consent to the collection, use, or disclosure of their voice data.
INTERNATIONAL LAWS & REGULATIONS
EU Reaches Provisional Agreement on AI Omnibus to Amend AI Act: The European Parliament and Council of the European Union reached a provisional agreement to amend the EU AI Act through the “Digital Omnibus on AI” simplification package. The agreement postpones compliance deadlines for high-risk AI systems. Stand-alone high-risk systems are now subject to a December 2, 2027, deadline, and high-risk AI systems embedded in products are given until August 2, 2028. The agreement expands the ability to process sensitive personal data (such as ethnicity or health data) for bias detection and correction in AI systems, subject to safeguards. The deal also introduces a new prohibition on AI-generated non-consensual sexual content (“nudifier” tools) and child sexual abuse material. Additionally, the agreement exempts machinery from direct AI Act applicability where overlap with the Machinery Regulation exists, while other sectors, including medical devices, toys, and connected devices, will be addressed through implementing acts. The deal reinstates the obligation for providers to register AI systems in the EU’s high-risk systems database and reduces the grace period for AI-generated content transparency solutions from six to three months. The agreement awaits formal adoption, which co-legislators intend to complete before the original August 2, 2026, deadline. Privacy professionals should also monitor the forthcoming “Data Omnibus,” which may carry more far-reaching implications for AI and personal data, including potential changes to the GDPR.
European Commission Publishes Draft Guidelines on High-Risk AI Classification: The European Commission released draft guidelines on classifying high-risk AI systems under Article 6 of the EU AI Act, opening a public consultation through June 23, 2026. The guidance, initially due in February 2026, was delayed as stakeholders lobbied for extended compliance timelines. The three-part guide addresses general classification principles and the two categories of high-risk AI: systems used as safety components of products under Annex I, and stand-alone systems deployed across eight sensitive areas under Annex III, including biometrics, critical infrastructure, education, employment, law enforcement, and migration. The guidelines clarify that AI systems with broad intended purposes that do not consistently exclude high-risk uses will be deemed high-risk, and that merely asserting exclusions in terms of service is insufficient to avoid classification. Implementation deadlines have been extended under the Digital Omnibus on AI, with stand-alone high-risk system rules now applying December 2, 2027, and product-embedded system rules applying August 2, 2028.
European Commission Publishes Draft Transparency Guidelines under the EU AI Act: The European Commission published draft guidelines clarifying the transparency obligations applicable to certain AI systems under Article 50 of the EU AI Act, with an accompanying public consultation open through June 3, 2026. The guidelines address four categories of transparency obligations taking effect on August 2, 2026: (1) providers of AI systems that interact directly with individuals must inform users they are engaging with an AI system; (2) providers of generative AI systems must mark outputs in a machine-readable format and ensure they are detectable as AI-generated or manipulated; (3) deployers of emotion recognition and biometric categorization systems must inform exposed individuals; and (4) deployers must disclose deep fakes and AI-generated text published to inform the public on matters of public interest. The guidelines provide detailed examples of compliant and non-compliant disclosure techniques, emphasize protection for vulnerable groups, including children, and address interplay with existing EU data protection, consumer protection, and digital services legislation. Non-compliance may result in fines of up to EUR 15 million or three percent of worldwide annual turnover.
Canada Launches Age Assurance Guidance for Online Services: Privacy Commissioner of Canada Philippe Dufresne launched new guidance on age assurance during Privacy Awareness Week 2026. The guidance, directed at operators of websites and online services as well as age assurance developers, sets out how organizations can create safer online experiences for children while mitigating adverse privacy impacts. The Office of the Privacy Commissioner’s (“OPC”) accompanying Policy Note identifies key privacy risks associated with age assurance, including breach of information collected during the assurance process, tracking or profiling of individuals’ online activities, disproportionate collection of personal information, and unequal impacts on specific populations. The OPC takes the position that neither age verification, estimation, nor inference is inherently more or less privacy-protective, and that privacy impacts depend on system design and use. The operational guidance requires organizations to first determine whether age assurance is necessary by demonstrating either a legal requirement or a potential harm specific to children, then to select a proportionate method that minimizes personal information collection, and finally to implement privacy-protective safeguards, including purpose limitation, prohibition on correlating visits, appeal mechanisms, and user choice among assurance methods. The guidance is open for public comment until August 4, 2026.
Canada Publishes Guidance on Government Use of Agentic AI: The Government of Canada’s Treasury Board Secretariat published a guide on the responsible use of agentic AI by federal departments and agencies. Unlike generative AI, which produces content in response to prompts, agentic AI systems can autonomously plan, execute tasks, interact with digital systems, and pursue defined goals with limited human supervision. The guide identifies key privacy and security risks specific to agentic systems, including unauthorized actions, unclear permissions, material privacy breaches through unauthorized access to or disclosure of personal or sensitive information, prompt injection attacks, and “automation drift” where employees begin treating AI-generated outputs as actual decisions. To mitigate these risks, the guidance introduces two principles: “bounded autonomy,” requiring that AI agents operate within tight, explicit parameters limiting data access, tools, permissions, and scope; and “recoverability,” mandating that all agent actions be fully logged in tamper-proof systems and that agents be designed to fail safely. The guide requires departments to consult privacy, security, and legal experts before deploying agentic AI; implement human-in-the-loop checkpoints for actions that alter system states; treat external content as untrusted data rather than instructions; and maintain a “kill switch” to immediately pause agent operations.
RECENT PUBLICATIONS & MEDIA COVERAGE
Allocating AI Risk—Negotiating AI Tool Terms and Conditions
Blank Rome vice chair of artificial intelligence Sharon R. Klein and partner Alex C. Nisenbaum will serve as speakers for the Association of Corporate Counsel’s Allocating AI Risk—Negotiating AI Tool Terms and Conditions, taking place Tuesday, June 30, 2026, from 2:00 to 3:00 p.m. EDT, as part of the 2026 Contracts & Negotiations Master Class Series. Blank Rome is pleased to sponsor the Series.
Illinois Opens for Public Comment Proposed Regulations Implementing the Use of AI in Employment Act
Blank Rome partners Rachel L. Schaller and Daniel R. Saeedi authored this alert discussing the state of Illinois seeking public comment on rules implementing its AI Employment Act, which broadly regulates employer AI use with notice, anti-discrimination, and recordkeeping obligations.
Blank Rome Attorneys Recognized in the 2026 Lawdragon 500 Leading Global Cyber Lawyers
Blank Rome LLP is pleased to announce that Sharon R. Klein, vice chair of artificial intelligence and co-chair of the Privacy, Security & Data Protection practice; Philip N. Yannella, co-chair of the practice; and partners Jennifer J. Daniels, Alex C. Nisenbaum, and Kenneth J. Nunnenkamp have been recognized in the 2026Lawdragon 500 Leading Global Cyber Lawyers guide.
© 2026 Blank Rome LLP. All rights reserved. Please contact Blank Rome for permission to reprint. Notice: The purpose of this update is to identify select developments that may be of interest to readers. The information contained herein is abridged and summarized from various sources, the accuracy and completeness of which cannot be assured. This update should not be construed as legal advice or opinion, and is not a substitute for the advice of counsel.
