State attorneys general are increasingly shaping the regulatory landscape for organizations that rely on technology, data and artificial intelligence. In the latest episode of Squire Patton Boggs’ Antitrust Amplified podcast, antitrust partner Lauren Briggerman sits down with representatives from the California Department of Justice and the District of Columbia Attorney General’s Office to discuss evolving state enforcement priorities.

While the conversation focuses on antitrust enforcement, it addresses issues that are highly relevant to privacy, cybersecurity and compliance professionals. Topics include algorithmic pricing investigations, AI-driven technologies, coordination among state attorneys general and practical compliance considerations for businesses deploying algorithmic tools.

As regulators continue to examine technology-enabled business practices through multiple enforcement lenses, organizations should be aware of the growing convergence of antitrust, privacy, consumer protection and AI governance considerations.

Listen to the full podcast: Attorneys General on Antitrust in the US: Perspectives from the States

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

As privacy regulation, AI governance, and cybersecurity requirements continue to evolve globally, members of Squire Patton Boggs’ Data Privacy, Cybersecurity & Digital Assets team will be speaking on legal developments at several upcoming webinars, conferences, and CLE programs. Explore the events and hot topics below. For many of these programs we can arrange free passes for clients and are noted below. We look forward to connecting with you!

Continue Reading Upcoming Speaking Engagements and CLE Opportunities with the SPB Data Team

As we flagged last month in our mid-year U.S. privacy roundup, the Delaware legislature recently passed House Bill 380 (“HB 380”), which amends the Delaware Personal Data Privacy Act (the “Act”) in ways that impose significant new, and in many ways complex and novel, requirements on controllers, processors and third parties.  On September 2, 2026, Delaware Governor Matt Meyer signed House Bill 380 into law and thus amended what was already a fairly strict state consumer privacy law. These amendments significantly lower the volume-based thresholds for applicability, create new obligations for providers of “reports” used to make certain types of decisions and businesses that use that data, add new requirements for consumer rights, impose restrictions on profiling job applicants, employees and independent contractors, and require contracts with and obligations from third parties that receive personal data (e.g., sales), among many other changes. These amendments will become effective on January 1, 2027.

Businesses that are subject to the Act (of which there will be many more as a result of HB 380) should carefully review the amended Act to determine their new obligations, including the significant amendments discussed below.  Financial institutions in particular should determine whether they must now comply with the Act, as the broad exemption for financial institutions subject to Title V of the Gramm-Leach-Bliley Act (the “GLBA”) has been replaced by a narrower exemption for only certain types of financial institutions and certain of their affiliates (see discussion below).

Continue Reading Amendments to Delaware’s Consumer Privacy Law Deepen the Morass of State Privacy Regulation

In this second of a three-part series on US data law updates, we cover state laws related to development and deployment of artificial intelligence (AI) systems.

In Part I, we focused on the trend of more restrictive state consumer privacy laws. In this Part II, we review how state AI laws are focused on the most potentially harmful uses of AI systems. While state legislatures enacted a steady stream of new and amended consumer privacy laws during Q1 and Q2, legislative activity on AI and AI-related laws accelerated during May through  August. This Part II focuses on some of the more significant developments during this period.  

Continue Reading U.S. AI Law –  2026 Midyear State Update

As AI becomes more powerful, the questions facing businesses become more complex. How do you govern AI responsibly? How do you manage emerging risks? And how do you seize the opportunities without losing control? In this video series, our lawyers and industry professionals share their perspectives on the issues shaping the future of AI and its impact on organizations around the world.

In our first episode, international affairs advisor Matthew Kirk speaks with partner Tanvi Mehta Krensel about the role of in-house counsel in evaluating, deploying and governing AI across multinational organizations.

Watch the video here.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

To harmonize cybersecurity requirements across the EU, the Cyber Resilience Act (CRA) applies to hardware and software products made available in the EU whose intended or reasonably foreseeable use involves a direct or indirect connection to a device or network. This includes software applications, Internet-of-Things (IoT) products, routers, connected machinery and separately marketed digital components (e.g., smartphones, laptops, smart home products, smartwatches, connected toys, microprocessors, firewalls, connected machinery, accounting and finance software, games and apps, as well as open-source software supplied in the course of a commercial activity).

While most CRA obligations will apply from 11 December 2027, manufacturers must comply with reporting obligations under CRA Article 14 from 11 September 2026. This also applies to products with digital elements that have already been placed on the EU market. These reporting obligations concern

  • Actively exploited vulnerabilities, i.e., security weaknesses for which there is reliable evidence that a malicious actor has exploited them. For example, the confirmed exploitation of an authentication flaw to obtain unauthorized access.
  • Severe incidents affecting the security of a product, for example, an incident that comprises the confidentiality or integrity of sensitive data.

The reporting process under the CRA is staged as follows:

  • An early warning must be submitted without undue delay and, in any event, within 24 hours of the manufacturer becoming aware of the vulnerability or incident. The notification must be submitted through the CRA single reporting platform (SRP), operated by the EU Agency for Cybersecurity (ENISA), and is made available to the relevant computer security incident response team (CSIRT) designated as coordinator and, generally, simultaneously to ENISA. The competent CSIRT is determined in accordance with the CRA and selected by the manufacturer when submitting the notification. It is generally the CSIRT of the member state in which the manufacturer has its main establishment, i.e., where decisions concerning the cybersecurity of its products are predominantly taken.
    • The individual submitting the notification on behalf of the manufacturer must have an EU login account (EU LOGIN) and register as an “Assigned Representative” of the relevant manufacturer. Advance registration with the SRP is not required. Registration and association with the relevant manufacturer can be competed in connection with the first notification. Prior validation of the association by the CSIRT is not a prerequisite for submission. However, an EU login account should be set up in advance.
  • Within 72 hours, the manufacturer must submit a more detailed notification. Depending on the event, this must include available information on the affected product, the nature, severity and impact of the vulnerability or incident, as well as any corrective or mitigating measures taken or available.
  • A final report must subsequently be submitted: for an actively exploited vulnerability, generally no later than 14 days after a corrective or mitigating measure becomes available; for a severe incident, within one month after the 72 hour notification.

In addition, after becoming aware of an actively exploited vulnerability or severe incident, manufacturers must inform impacted users without undue delay and, where appropriate, all users. The information must include any measures users can take to mitigate or correct the risk where necessary.

Although the CRA’s general product compliance requirements do not yet apply to the relevant product, manufactures nevertheless become subject to these reporting obligations from 11 September 2026.

In-scope businesses should therefore assess

  • Which hardware and software products fall within the CRA’s scope
  • Which entity qualifies as the manufacturer and which CSIRT will be competent
  • Whether identified vulnerabilities are merely theoretical or are actively exploited, and whether incidents meet the CRA’s severity criteria based on their impact on sensitive or important data or functions or the execution of malicious code
  • Whether robust internal 24 and 72 hour identification, escalation and reporting processes are in place

For further practical guidance, the German Federal Office for Information Security (BSI) has published the Technical Guideline BSI TR 03183-1, “Cyber Resilience Requirements for Manufacturers and Products Part 1: General requirements” (BSI TR), which provides nonbinding, introductory guidance on the implementation of the CRA, and is aimed particularly at manufacturers that have not yet established mature IT security processes for product development and vulnerability handling.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

Last week, a European Data Protection Authority imposed a substantial fine for a company’s use of an algorithmic system that automatically restricted individuals’ access to income-generating opportunities via an online platform and the failure to provide adequate transparency.  Accounts were deactivated where the system detected suspected fraud or low customer ratings and no human assessment took place. According to the authority, this constitutes prohibited automatic decision making within the meaning of Art. 22 GDPR, which states that a “data subject shall have the right not to be subject to a decision based on automated processing, including profiling, which produces legal effects concerning him or her or similarly significant affects him or her”. 

The investigation followed complaints from 171 individuals. The fine was calculated by reference to the company’s worldwide annual turnover. The decision is not yet final and is subject to appeal.

The case is not merely a platform-economy issue.  Automated scores and system-generated flags increasingly influence everyday business decisions, including decisions affecting employees and customers. While many automated processes are routine and legally unproblematic, Art. 22 GDPR may apply where a decision is based solely on automated processing and produces legal or similar significant effects. Examples include loss of income, as in the decision at hand, denial of credit or insurance, rejection of a job application, or exclusion from an important service.  

Where automated-decision making is permitted under one of the limited exceptions in Art. 22 GDPR, businesses must implement appropriate safeguards. These include meaningful human intervention, transparent information about the decision-making process and an effective opportunity to contest the decision. A nominal review or a routine approval of a system generated recommendation is unlikely to be sufficient.

Relevant use cases may include, for example, automated recruitment screening, allocation or withdrawal of shifts, performance scoring, fraud detection, refusal of returns or payment options, as well as automated access restrictions. Business should identify where automated outputs trigger adverse consequences and assess whether the decision is genuinely reviewed by a person with sufficient information, authority and ability to depart from the system’s recommendation. 

While the decision concerns the GDPR and does not determine whether the system in question qualifies as an AI system under the AI Act, the decision may nevertheless provide useful context for the AI Act’s human oversight requirements. In the employment context, AI-supported recruitment, performance evaluation, task allocation or disciplinary decisions may qualify as high-risk under Annex III. This may be the case even where a human formally makes the final decision. Effective human oversight under the AI Act must therefore be substantive rather than merely procedural: the responsible person must be able to understand and critically assess the system’s output and, where appropriate, disregard, override or reverse it. 

Businesses should review their inventories of automated and AI-supported systems, conduct or update a data protection impact assessment where required, update their privacy information where necessary, establish effective procedures for dealing with objections to automated decisions and document both the decision-making process and any human review. Although the AI Act requirements for Annex III high risk systems will not apply until 2 December 2027, the necessary governance and documentation should be developed now.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

2026 started with 20 state consumer privacy laws (SCPLs), three of which went into force on January 1, 2026. During the first half of 2026, four new SCPLs were added, bringing the count to 24 – all since the California legislature passed the California Consumer Privacy Act (CCPA) in June 2018. Also, during the first half of 2026, state legislatures enacted significant amendments to their existing SCPLs. We cover the state privacy laws developments in this first of a three-part series on mid-year US data law updates – stay tuned for updates on teen online privacy and safety, as well as AI.

Continue Reading Adding to the Count: The latest in state consumer privacy laws

In case you missed it, below are recent posts from Privacy World covering the latest developments on data privacy, security and innovation. Please reach out to the authors if you are interested in additional information.

China Introduces Simplified Personal Information Protection Regime for Small-Scale Personal Information Handlers

Upcoming CLE Opportunities with the SPB Data Team

Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

How Deep is Your Fake? A 3-Minute-Guide on Labelling Obligations under the EU AI Act

Another Omnibus package – no.’VII’ – this time on all things AI

Upcoming Events in Asia

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

On July 22, 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers (the “Provisions”), which will take effect on September 1, 2026.

The Provisions are designed to reduce compliance burdens for smaller businesses, while maintaining baseline personal information protection requirements. They introduce a series of streamlined compliance measures for qualifying entities in China.

Continue Reading China Introduces Simplified Personal Information Protection Regime for Small-Scale Personal Information Handlers