Artificial Intelligence

Last week, a European Data Protection Authority imposed a substantial fine for a company’s use of an algorithmic system that automatically restricted individuals’ access to income-generating opportunities via an online platform and the failure to provide adequate transparency.  Accounts were deactivated where the system detected suspected fraud or low customer ratings and no human assessment

The Guidelines 03/2026 on web scraping in the context of generative AI, adopted by the European Data Protection Board “EDPB” for public consultation on 7 July 2026, are notable not only for what they require but for what they acknowledge. The document is unusually candid about three limitations: an epistemic one (the controller may not always know what it has collected), a technical one (what a model has learned cannot, today, be easily unlearned), and an institutional one (some of the assessments woven into the GDPR analysis sit, at least in part, with other authorities and courts). These acknowledgements are welcome, and they distinguish the text from more declaratory guidance. The tension is that the requirements built on top of them are not always adjusted accordingly, and that gap, between what the EDPB admits and what it nonetheless requires, is where the most interesting questions of the consultation lie.

Briefly, the Guidelines cover scraping performed by private entities, whether carried out in-house, commissioned from a third party or effected through the acquisition of pre-scraped datasets. They work through the familiar sequence: allocation of controller and processor roles, the core principles of Article 5 GDPR (purpose limitation, transparency, minimization, accuracy), the choice of legal basis, with legitimate interest under Article 6(1)(f) GDPR treated as the realistic candidate and consent all but discarded, and the treatment of special categories of data incidentally swept up in the collection, for which the EDPB adapts the CJEU’s GC & Others framework. Little of this structure will surprise anyone who has followed the Board’s recent work on AI. What rewards attention is how each of these familiar steps is made to function once the three limitations above enter the analysis.

Continue Reading Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

The EU Artificial Intelligence (AI) Act requires companies to disclose in certain cases whether content has been created or modified by AI. This also applies to companies that make use of AI such as image-generation programs for product advertising.

Given that the new rules are enforceable from 2 August 2026, with fines up to EUR

Consistent with the recent strategic shift in policy around EU regulations, the EU’s seventh package of changes to simplify/lighten their burden has just been approved and, with it, we will see changes to the way the EU’s Artificial Intelligence Act will be applied (although some obligations under this legislation are already in force).

The EU’s

Recently, we hosted an intimate dinner in Los Angeles with a group of general counsels and senior executive leaders to discuss the evolving challenges posed by artificial intelligence (AI), data privacy and cybersecurity, particularly as they relate to HR and production environments. The roundtable discussion was dynamic and insightful, reflecting the real-world risks and strategic

The Colorado AI Act (SB24-205) is effectively frozen just weeks before its June 30, 2026 effective date, following a stay in enforcement of the law by a Magistrate Judge in the District of Colorado on April 27, 2026.

Background

By way of background, on April 9, xAI filed suit in federal court seeking to enjoin

Our team members will be participating in several speaking engagements over the coming months, sharing perspectives on emerging trends, regulatory developments, and practical challenges across the global data privacy, AI, and cybersecurity landscape.

Continue Reading Upcoming Speaking Engagements: Insights on Data Privacy, AI, and Cybersecurity

Connecticut Attorney General William Tong recently issued an advisory memorandum (“Advisory”) to all “State Officials, Agencies and Concerned Parties” about how existing Connecticut laws apply to artificial intelligence (“AI”).

In the Advisory, Attorney General Tong hints at enforcement priorities and offers businesses a roadmap for compliance in describing how Connecticut’s civil rights, privacy and data security, competition, and consumer protection laws apply to AI system use.  Businesses operating in Connecticut are reminded that, even without a statewide AI law, obligations under these laws regulate their AI system use.  Those Connecticut residents who read the Advisory are reminded of their rights and encouraged to report AI related harms to the Connecticut Office of the Attorney General (“OAG”).

Continue Reading Old Laws, New Tricks: Connecticut AG Issues Advisory on How Current Connecticut Laws Apply to Artificial Intelligence

A recording is now available for “California and Beyond: HR Data Risk Issues for Employers,” a highly relevant webinar covering the rapidly shifting world of HR data, privacy obligations, and AI regulation. Presented by Squire Patton Boggs Partners Alan Friel and Michael Kelly, and Associate Sam Kim, this session will give employers the clarity they need as new rules take effect and enforcement ramps up.

Continue Reading A Timely Look at HR Data and AI Regulation Trends: Webinar Recording Available

PrivacyWorld’s Alan Friel and Kyle Fath broke down what companies need to consider in 2026 to meet new and ongoing data laws and regulations in a Stafford / Barbri presentation on January 7, 2026. The PowerPoint is available here and includes appendices that break down details of, and compare and contrast, consumer privacy laws. Coverage