2026 Q2: Top Updates in Privacy and AI
The following insights reflect Jackie’s personal analysis of the recent updates. While we hope you find them helpful, they are not legal advice. Reading this does not create an attorney-client relationship. You should not act on this information without seeking professional counsel.
Big themes for Q2:
Data broker expansion with intensifying requirements and rising costs
Continued proliferation of state privacy laws and obligations around minors’ privacy
Surveillance pricing laws emerging in multiple states
Continued strong CCPA enforcement
AI:
Key themes: Backsliding on certain comprehensive AI legislation in U.S. states; new U.S. federal framework emerging; the EU AI Act is moving forward.
It’s goodbye trail runners, hello sandals for Colorado. The state, once a trailblazer in AI legislation, has now stepped back in the face of increasing pressure. In May, the Colorado AI Act was repealed and replaced with a new version of the law (SB 189) that is significantly narrower in scope, focusing on automated decision making technology (ADMT) and implementing certain ADMT-related requirements such as transparency and consumer rights, in line with other state ADMT laws. The new law is set to go into effect on January 1, 2027. This repeal and replace move follows an order by the Colorado District Court that the CO Attorney General not enforce the original CO AI Act in the x.AI v. Weiser case, in which x.AI is challenging the constitutionality of the CO AI Act with the Federal DOJ intervening on its side.
** Take-away: It’s time to re-assess if the new ADMT version of the CO AI Act might apply to your processing activities. Given similarities between the CO law and other ADMT requirements, you likely are already evaluating necessary compliance measures. While the about-face may give companies that would have been covered a temporary reprieve on compliance, requirements are likely to show up again in another law down the road.
As the capabilities of frontier models have reached a level prompting deepening concern (think, the Anthropic Fable delay, as one example), Federal regulation remains absent. That said, in June, President Trump signed the Executive Order “Promoting Advanced Artificial Intelligence Innovation and Security,” (EO 14409), directing federal agencies to establish a framework for the secure deployment of frontier AI models. The cornerstone is a voluntary pre-release engagement program through which AI developers would provide the federal government with up to 30 days of access to qualifying “covered frontier models” before broader release. Note the keyword, voluntary. There’s speculation around how voluntary this really will be. The EO also tasks a multi-agency group led by Treasury, DOD/NSA, and DHS/CISA, in consultation with the White House Chief of Staff through the National Cyber Director, the Assistant to the President for Science and Technology, and Commerce/NIST, with developing a classified benchmarking process to assess AI models’ advanced cyber capabilities. This was due to be completed on August 1, 2026. (Note: The White House is holding meetings in early August with frontier labs to review the framework.) On June 5, 2026, the President issued a separate National Security Presidential Memorandum (NSPM) on Artificial Intelligence in the National Security Enterprise establishing a framework for procurement and use of AI for defense and intelligence purposes guided by four pillars: Adoption, Adaptation, Assurance, and Accountability.
** Take-away: AI developers in particular should track the benchmarking process as it’s likely to shape regulatory moves. Companies should consider updating incident response playbooks to address AI-enabled cybercrime reporting expectations in light of the EO’s focus on the issue.
Have the hydration and the completion medals ready! The EU AI Act leg of the Digital Omnibus marathon is nearing an end and the finish line is in sight. Agreement on the Digital Omnibus on AI has been reached and the remaining steps are in the works (as of the end of Q2). In May, EU negotiators reached a provisional political agreement, and in June the European Parliament formally endorsed it and the Council gave its final green light. (Spoiler alert, the finalized Digital Omnibus on AI was published in the Official Journal of the European Union in late July.) Some key updates: The European Parliament formally endorsed it, with the Council giving its final green light.
Compliance deadlines for High Risk AI Systems have been extended, with Annex III (use-based) compliance extended to December 2, 2027, which covers use cases such as AI in employment, credit, education, law enforcement, and similar high-stakes contexts. The compliance deadline for Annex I (product-embedded) is extended to August 2, 2028.
The watermarking (Art. 50(2)) grace period for legacy systems runs to December 2, 2026 (a 4-month, not 6-month, extension).
The August 2, 2026 general applicability date remains the same.
The updated AI Act includes new prohibited practices: generation of non-consensual sexual and intimate content or child sexual abuse material (CSAM) and generation of nude images of real people or editing clothes out in existing photos.
In June, The European Commission and AI Office published the Final Code of Practice on Transparency of AI-Generated Content. It includes two sections: Section 1 for providers (marking AI content in machine-readable formats) and Section 2 for deployers (labeling deepfakes and AI-generated public-interest text).
** Take-away: We have the clarity we’ve been awaiting and no more delays are coming. Prepare to comply, as the Commission’s GPAI enforcement powers and the Article 50 transparency obligations take effect on August 2, 2026. For high-risk use cases, you have more time, but use that time wisely to get your compliance house in order.
Privacy:
Key themes: New privacy laws are introducing novel requirements; amendments are expanding out existing privacy laws into brave new territories of regulation; minors’ privacy remains a prominent area of legislation and age assurance is catching on across states; intensifying data broker laws are emerging in additional new states.
We couldn’t close out the first half of 2026 without a few additional states adopting privacy legislation now could we?! Pop quiz: Which states passed privacy laws in Q2? Hint: There may be some you wouldn’t expect! Ready? Alabama (HB 351, effective May 1, 2027), Louisiana (SB386, January 1, 2027), and Vermont (S.71, January 1, 2028) all adopted privacy laws in Q2. That puts the total number of U.S. states that have enacted comprehensive privacy legislation at 24 as of the date of this recap. Alabama’s and Vermont’s laws track the Connecticut model, while Louisiana tracks the Texas model with a healthy splash of Connecticut and California mixed in. All three laws exempt B2B use cases (“commercial or employment context”) and include precise geolocation data in the scope of sensitive personal data. Requirements worth noting:
Alabama: Signed into law April 17, 2026. No sale or targeted advertising of a minor’s (between 13 and 15) personal data without consent, where there is actual knowledge that the individual is a minor. Note that “sensitive personal data” includes only children under age 13. Does not include an impact assessment requirement.
Louisiana: Signed into law May 29, 2026. Includes a 30-day cure period that sunsets after July 31, 2027. (The cure period applies prior to the AG initiating an investigation.) Requires specific notice statements for sale of sensitive personal data or biometric data.
Vermont: Signed into law June 16, 2026. Requires privacy policies to include a statement disclosing whether the controller collects, uses, or sells personal data for the purpose of training large language models. Provides a 60-day cure period through June 30, 2029.
** Take-away: If you’ve already been implementing compliance measures for other state privacy laws, you should be in good shape to extend them for these new states. Prepare for the specific AI and sale disclosure statements under VT’s and LA’s laws (respectively). Despite AL’s exception, continue building out those impact assessments. You have some time to prepare, but we all know that time is flying now that we’re having fun complying with 24 state privacy laws!
In our newest recap segment, “Amended, Already” (or maybe “Amendments Abound” or “Actively Amending”?!), we cover notable state privacy law amendments entering the scene. Don’t get too used to the law as passed, friends, because it’s changing soon! (Possible tagline?!) The grand themes: broader applicability and enhanced requirements. In Q2’s segment, we’re covering amendments to Connecticut’s privacy law. In late May and early June, Connecticut adopted Senate Bill 4 (Public Act 26-64), House Bill 5222, and House Bill 5563, which together establish a multi-framework omnibus statute that establishes new regulatory frameworks for data brokers, surveillance pricing, facial recognition, and direct-to-consumer genetic testing, while also amending the CTDPA itself. If you’re having a deja vu moment, it’s not you! SB 4 and House Bill 5222 build on amendments adopted in June 2025 (SB 1295, Public Act 25-113), which had already lowered applicability thresholds and added AI/LLM disclosure rules effective July 1, 2026 (Note: We mention these in the “upcoming” summary above). Effective dates begin October 1, 2026 and are staggered for different requirements, so be sure to consult the law to determine when certain requirements start to apply.
Implement a data broker registry and accessible deletion mechanism (effective October 1, 2026, registration requirement effective January 1, 2027, requirement to access registry for deletion requests effective October 1, 2028).
Impose surveillance pricing disclosure requirements and restrictions (effective July 1, 2027); impose an outright ban on sale of precise geolocation data (effective October 1, 2026).
Apply sensitive data processing requirements to businesses of any size (effective October 1, 2026).
Plus, other requirements and restrictions. Combine this with the lowered applicability threshold, and you have one potent package of legal obligations.
** Take-away: If you handle sensitive data or engage in processing that could cross into one of these newly covered territories established by the amendments, take a close look at your processing and compliance measures. Many of these requirements/restrictions are coming online quickly, so prepare now to avoid a stressful scramble later.
Silly rabbit, privacy IS for kids (and teens too)! As expected, youth privacy laws continued to proliferate in Q2. (As you might recall, in Q1 we saw more states adopting age-appropriate design code acts. See our Q1 recap for more.) (a) This quarter, Colorado passed SB26-051, the Age Attestation on Computing Devices law. The law goes into effect July 1, 2028. It requires OS and app store providers to collect age information at device or account setup and transmit a device-level age signal to apps. App developers must request and honor the signal. The law was modeled in part on California’s Digital Age Assurance Act. Other states currently have children’s privacy legislation pending, including New Jersey and Michigan. (b) The see-saw ride may finally be over for the Texas App Store Accountability Act. That law is back in effect after the Fifth Circuit Court of Appeals stayed the preliminary injunctions that had been in place since the end of 2025, which had temporarily stopped the law from being implemented. App developers have been caught in a “should we or shouldn’t we” dilemma around whether to take steps to comply with the law given its uncertain applicability. The next stop after the Fifth Circuit would be the Supreme Court. In the meantime, the Act is in effect.
** Take-away: Based on the latest from Texas, it appears that age verification is here to stay, at least for a while. App developers should dust off their compliance approach if it got shelved and start implementing the necessary compliance measures. It’s possible that advocacy groups may continue to fight these laws as they emerge, but it appears that it will be a long battle ahead and compliance will be required in the interim.
The stakes (and costs) keep rising for data brokers as more laws are being passed, marked by ever increasing requirements and restrictions, not to mention expanding applicability. On June 30, New Jersey passed a landmark data broker law, A.5328 (P.L.2026, c.25), the most stringent and expensive data broker law in the US to date. If you’re keeping count at home, New Jersey is the seventh state to enact a data broker law and the second in 2026 following Connecticut. The law took immediate effect, with the exception of the public data broker registry provision, which is delayed until March 27, 2027. Noteworthy aspect: The law covers data brokers AND data collectors, which covers businesses that collect data from consumers directly and sell or license it to a data broker. Some other key highlights of the law: Bans sale of sensitive data; creates a data broker AND “data collector” registry; annual registration fees tiered and range from $5,000 to $1.5 million annually, based on consumer counts and sensitive data volumes, with the top tier applying at just 100,000 NJ consumers. Penalties for non-compliance are steep at up to $2,500 per day for registration/reporting violations (over 10x California’s $200/day maximum) and up to $50,000 per record for sensitive data sale violations.
** Take-away: Even if you may not be a “data broker” under the other state data broker laws, it’s advisable to check your status under the NJ law. You may be a “data collector” under this newly introduced category, which means you may need to register for the public registry, as well as meet the other compliance requirements. The potential fines are steep, so it may be worth investing in a review now and taking steps to mitigate your risk.
The epic digital omnibus journey continues for the GDPR. (I’m imagining the GDPR with a backpack, trekking up a big mountain, transforming along the way!) While the EU AI Act portion of the Omnibus has made strides (more below), the data portion of the package is making slow progress. Apparently, the Cypriot Presidency of the Council of the EU circulated compromised texts. Other updates worth noting: In April, the European Data Protection Board (EDPB) published the first harmonised template for Data Protection Impact Assessments (DPIAs) and opened it for public consultation, which concluded June 9.
** Take-away: While no updates are solidified yet, it’s worth staying aware of the latest developments. Take a look at the DPIA template to get a sense of where you could begin refining your own.
It’s July, and we’re starting to see summer corn at the market! Why the “corny” reference? We’re starting to see surveillance pricing laws emerging, “popcorn” style, in various states, and an initial focus appears to be the food industry. For more, check out the Maryland Protection from Predatory Pricing Act (HB0895). It applies to food retailers and delivery services and goes into effect October 1, 2026. Also check out the references to the CT Amendments (above) and the new VT privacy law (also above).
** Take-away: If you’re using algorithms and personal data to set different prices across your customer base, restrictions and requirements could be coming your way. Pay attention to the “fields” of new legislation, as these laws seem to be growing rapidly. If you happen to be in the food industry, pay particular attention. You may be impacted earlier than other industries.
Enforcement:
Key themes: Ever increasing CCPA penalties; EU-US cross-border transfers in rough seas, again; FTC cracks down on AI hype.
Throw on those sunglasses and slather on some sunblock, it’s a scorcher for CCPA enforcement! Indeed CCPA enforcement has been heating up over time, with each quarter bringing enhanced enforcement activity and ever-increasing penalties. Q2 is no exception. In May, the California Attorney General announced a $12.75 million settlement with General Motors and OnStar. The settlement is the largest CCPA penalty issued to date (surpassing the previous $2.75 million record against Disney from February 2026) and is framed as the state’s first action to enforce the CCPA’s data minimization principle. The CA AG, joined by the district attorneys of San Francisco, Los Angeles, Napa and Sonoma Counties and CalPrivacy, asserted that GM collected precise geolocation data and detailed driving-behavior metrics via its OnStar service from hundreds of thousands of California subscribers and sold that data to LexisNexis Risk Solutions and Verisk (which provide risk scores for insurance companies) without adequately disclosing this use or providing required opt-out mechanisms. In addition to violations of the data minimization requirements, the complaint alleged violations of the CCPA’s purpose limitation requirements, the CCPA’s notice and opt-out requirements around the sale of personal information, as well as California’s Unfair Competition Law and the False Advertising Law. Worth noting: The complaint also stated that GM could not produce a risk assessment for its decision to sell driving data. That allegation concerned GM’s own internal privacy program rather than the CCPA’s new regulatory requirement, but it previews how regulators are likely to treat missing documentation as the CCPA risk assessment requirement (effective January 1, 2026) phases in. The terms of the settlement include, in addition to the monetary penalties, a ban on selling driving data to consumer reporting agencies for 5 years, mandatory deletion of retained driving data within 180 days absent affirmative express consent, request for deletion of previously sold data from LexisNexis and Verisk, and development and maintenance of a documented privacy program with formal risk assessments.
** Take-away: The GM enforcement action emphasizes the importance of knowing what data is being disclosed and to what third parties (and for what purposes). This is especially significant when sensitive personal information is involved. Go back and review your data flows, particularly your third-party data recipients, with a close focus on any of those data recipients that might be data brokers. Check your compliance measures and make sure they’re fortified to withstand heat from the AG and CalPrivacy.
The FTC is continuing its efforts to crack down on all things “AI-washing” and combat AI hype. In May, the FTC announced proposed consent orders that would require CMG Media Corporation (d/b/a Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a combined $930,000 for charges that they deceived business customers with false claims about an “Active Listening” AI marketing service. The companies marketed the service as an AI-powered tool that could capture snippets from consumer conversations near smart home devices and use them to generate hyper-targeted local ads. In fact, the companies were reselling email lists and pocketing the markup. My favorite of the marketing claims that the FTC listed in its complaint (page 2) was “Creepy? Sure. Great for marketing? Definitely.” (Apparently this was also the FTC’s favorite, as it was bolded and followed by “emphasis added.”) The FTC asserted claims of false AI capability, misrepresentation of consumer consent, and deceptive marketing impacting business customers. Important points to note: AI hype will be enforceable, so be prepared to back it up. B2B deception is in scope, at least when data flows can be traced back to consumers.
** Take-away: Watch your AI-based marketing claims. If you’re making marketing claims about AI capabilities that you offer, whether to consumers or businesses, make sure you can substantiate them. If you’re representing that you’ve obtained consent, you’ll also need to substantiate that consent.
Hold on to your hats and get ready for a possible privacy enforcement bonanza in H2. In June, FTC Chairman Ferguson stated that the FTC is preparing for a significant increase in data privacy enforcement actions during the second half of the year. This is particularly true if Congress adopts the SECURE Data Act. Ferguson stated, "I think in the second half of 2026, you're going to have a hard time keeping up with the number of cases we're gonna be bringing." Apparently businesses have been warned.
** Take-away: In light of potentially increased enforcement activity, it’s advisable to review your disclosures and compliance measures, especially if you’re handling data of children or minors or sensitive data.
Could this be the end for the EU-US Data Privacy Framework (DPF)? (Cue the suspense music.) Well friends, it’s not looking very good. To close out Q2 with a bang, on June 29 the U.S. Supreme Court issued its decision in the Trump v. Slaughter case. The Slaughter case centered on the question of whether President Trump’s removal of FTC Commissioners Slaughter and Bedoya was legal, where the Commissioners were told that their continued service was inconsistent with the Administration's priorities and that they were removed pursuant to the President’s Article II authority. (Commissioner Bedoya was removed at the same time but later resigned, and his claims were dismissed.) The claim was that the Commissioners could only be dismissed for cause, based on the “for cause” removal protections under the FTC Act. The Supreme Court held that the statutory “for cause” removal provisions violate the Constitution, meaning that FTC Commissioners (as well as Commissioners of other similar Federal agencies) serve at the President’s discretion, which overturned long-standing precedent under Humphrey’s Executor, a Supreme Court decision from 1935. This holding throws the entire concept of the FTC’s independence into question, which has the ripple (or tidal wave) effect of potentially negating the underlying EU Commission adequacy determination that serves as the foundation for the DPF. The Commission's adequacy determination rests on the premise that the FTC is an independent oversight body. By negating that core independence support beam, the entire DPF structure is potentially no longer sound.
** Take-away: Prepare for the next phase of instability in the cross-border transfer world. Most businesses have already been implementing Standard Contractual Clauses instead of, or in addition to, relying on the DPF. It’s time to make sure your SCCs are tightened up and in place, and go back to those transfer impact assessments and ensure they’re up to date.
Point the spotlight on Max Schrems and the NOYB, because it’s their time to shine at what they do best! Max and the NOYB closed out Q2 with a classic big move in light of the Slaughter decision by the U.S. Supreme Court. Max and team are citing stats and sending letters–read, it’s “on” NOYB style. Not long after the gavel dropped on Slaughter, on June 30, the NOYB issued a formal letter to the European Commission requesting an “orderly exit” from the Data Privacy Framework and a plan for repeal of the Commission implementing decision granting adequacy to the DPF. The NOYB has also stated that it plans to file a lawsuit that would push the CJEU to annul the DPF. That’s right, we’re looking at a Schrems III on our hands! The NOYB also noted that SCCs and BCRs aren’t necessarily safe from this crumbling sandcastle of a situation, as transfer impact assessments still need to be completed, and in this political climate, there may be little ground to stand on that data transfers are legal. As quoted on the NOYB blog, according to Max Schrems, “Given that there are no independent authorities in the US anymore, we call on the European Commission to orderly withdraw the adequacy decision on the US.” Fightin’ words indeed. And so Schrems III begins.
** Take-away: As noted above for Slaughter, prepare for another period of uncertainty around data transfers. It may be wise to begin shoring up additional safeguards to the extent possible. It’s possible that future congressional action could provide some relief, but that could be far out into the future.