0
What to know about CIPA and Shine the Light claims

What to Know About CIPA and Shine the Light Claims

Doing Business in California? What To Know About CIPA and Shine the Light Claims

  Blog Contributor: Madeline Yuki Gaudlitz, 2L at the University of Michigan Law School In recent months, companies operating in California have reported an increase in demand letters requesting damages for alleged violations under new and existing privacy laws. Under current data privacy legislation, companies can expect these claims to continue. Plaintiffs’ attorneys have relied on two statutes as a basis for their demands, the California Invasion of Privacy Act (“CIPA”) and California Civil Code § 1798.83 (“Shine the Light”).

What is CIPA?

Originally enacted in 1967 to “protect the right of privacy” of California residents, CIPA bans wiretapping, eavesdropping, or recording private communications. In recent years, Plaintiffs’ attorneys compared real-time consumer-tracking software embedded in companies’ websites to the type of behavior CIPA prohibits. In addition to imposing criminal penalties and fines of up to $10,000, the statute allows private individuals whose personal data has been intercepted by businesses to sue for $5,000 per violation.

Who does CIPA apply to?

CIPA may apply to:
  • Companies with consumer facing-websites or applications used by a California resident
  • Both companies that use these technologies in their consumer-facing website or application and third-party developers

What technologies may leave my company exposed under CIPA?

Potential CIPA liability may apply to a range of real-time consumer tracking technologies that are a standard part of website or application design, which may include:
  • Website analytics
  • Software developer kits
  • Third-party tracking pixels and software
  • Fingerprinting software
  • Application programming interfaces
  • Conversation intelligence software-as-a-service (SaaS)
  • Cookies and identity profiles
*Notably, CIPA is sensitive to the processes used to collect customers’ information. Likewise, Shine the Light may not apply to businesses that share information with third parties only for administrative or customer service purposes. To assess liability under these statutes, businesses may want to coordinate with third parties to ensure awareness of their own business practices and awareness and compliance under CIPA.

What is Shine the Light?

Originally enacted in 2003, the Shine the Light law was aimed at increasing customer awareness of how their personal information may be shared with third parties for direct marketing purposes. CIPA requires businesses to disclose their information-sharing practices upon request or allow customers to consent to information sharing. Failure to comply may result in a civil penalty of $500 per violation, and $3,000 if the violation is willful, intentional, or reckless.

Who does Shine the Light apply to?

The Shine the Light law may apply to: 1. For-profit companies with 20 or more full or part-time employees, 2. that collect personal information from California residents, and 3. that have shared customer information with third parties for direct marketing purposes 4. within the immediately preceding calendar year. Direct marketing may include spamming, telemarketing, or mail. Personal information may include name, address, e-mail address, telephone numbers, date of birth, medical or financial information, information about children, race, religion, occupation and education, and information about the transaction.

Best Practices

While these statutes impose distinct obligations, compliance may be able to be addressed by general practices that reflect their obligations to limit data collection and sharing of personal information. To work toward compliance, a company may consider:
  • Reviewing your company’s privacy policy to ensure that it accurately informs consumers in California of their privacy rights.
  • Clearly communicating your company’s privacy policy to consumers.
  • Ensuring that the consumer consents to the collection and sharing of personal information.

For CIPA

Regarding liability under CIPA, businesses may want to consider:
  • Reviewing your website or application design for features that collect personal information of users.
  • Coordinating with third party providers to ensure their awareness and compliance with CIPA risks and requirements.
  • If utilizing real-time tracking technologies, securing a consumer’s affirmative consent to data tracking.

For Shine the Light:

There are a couple of avenues that may limit risk under the Shine the Light Law:
  • Ensure that website or application design, physical store, or employees clearly disclose consumer data privacy rights.
  • Ensure that that website or application design allows consumers to actively and easily consent to personal information sharing.

OR

  • Maintain awareness of sales of customers’ personal information within the preceding year.
  • Establish a designated address–email, mail, or toll-free number–that customers may use to contact a business and request information about how their personal information is used.
  • Be prepared to disclose the types of information shared and the names and contact points for third parties that received or purchased the information within the preceding year within 30 days.

What’s Next?

In the coming years, we may see legislation that responds to the challenges CIPA claims pose to regular business operations in the digital age. SB 690 proposes an exception to CIPA liability for companies that use personal data for commercial purposes. However, the current status of this critical amendment is stalled. What we know now:
  • It will not be reconsidered until the 2026 legislative session, currently set to run from January 5-August 31, 2026.
  • Legislative history indicates that any exception would only apply to future cases, not currently pending claims or claims filed before the amendment is finalized.
  • Unanimous approval in the state senate may reflect policymakers’ concern with applying CIPA to commercial data collecting practices.
Ultimately, the amendment’s status is uncertain, but there is reason for companies to be optimistic about an eventual tapering down of CIPA claims. Despite this, businesses should remain cognizant of other regulations aimed specifically at digital data collection. Credit: Madeline Yuki Gaudlitz
0
AI and Legal Privilege

AI and Legal Privilege: Updates from Federal District Courts

AI and Legal Privilege: Updates from Federal District Courts 

US v. Heppner and Warner v. Gilbarco

“Chat, is our conversation protected?”  As usual, the answer may be “it depends.”

Highlights from two recent federal district court cases, US v. Heppner and Warner v. Gilbarco, provide different answers to this question. The learning? If you are using AI tools for legal-related matters, you should think twice before entering personal information or other case-related information.

United States v. Heppner

On February 17, 2026, the federal district court for the Southern District of New York found that neither attorney-client privilege nor the work product doctrine applied in protecting legal strategy materials that were generated using a public version of Claude. In its memorandum of reasoning, the court states its ruling “appears to answer a question of first impression nationwide: whether, when a user communicated with a publicly available AI platform in connection with a pending criminal investigation, are the AI user’s communication protected by attorney-client privilege or the work product doctrine?” The court answers with a resounding “no,” given the circumstances of the case. In Heppner, the court first ruled that the defendant’s conversations with AI were not covered by attorney-client privilege. This is because attorney-client privilege attaches with:
  1. Communications between a client and their attorney,
  2. which are intended to be, and were, kept confidential,
  3. for the purposes of obtaining or providing legal advice.
The court held that the AI-generated communications failed at least two, if not all three of these elements. Not only were the conversations not with counsel, but Heppner’s communications were not confidential because he used a public or consumer version of the Claude platform. The court notes that the platform’s privacy policy specifies that user inputs and outputs are used for training purposes, and that the platform reserves the right to disclose this information to third parties, including governmental regulatory authorities. In Heppner, the court also held that the work product doctrine also did not apply to the materials generated from the public or consumer version of Claude. This is because the work product doctrine requires that materials are prepared by or at the direction of counsel. Because these documents were not prepared by or on behalf of counsel, and did not reflect the defense counsel’s strategy, the court held the work product doctrine did not apply.

Warner v. Gilbarco

On February 10, 2026, the Eastern District of Michigan heard a similar – but not identical case – and found that the work generated by AI was attorney-client work product. In this case, the AI tools were used to prepare legal materials. However, in contrast to Heppner, the court reasoned that “ChatGPT (and other generative AI programs) are tools, not persons” and found that both the attorney-client privilege and work product doctrine apply. Although the court determined that sensitive information pertaining to the case was provided to ChatGPT, they found that this was not equivalent to a “voluntary disclosure to a third person,” which would ordinarily waive attorney-client privilege, did not apply. This is because the AI was not considered a third person. Additionally, the court found that work product waiver requires disclosure to an adversary or in a manner likely to reach an adversary. Because this was not found to be the case with the disclosure to ChatGPT, this doctrine was not waived.

Key Takeaways

Although these two similar cases come to different conclusions, it is important to note that they are not factually identical. It is also important to emphasize that these are early federal district court cases, and these matters of first impression are likely to evolve in the coming year. In the meantime, individuals (and other entities) using generative AI for legal advice should consider these cases and their outcomes. If you are planning on using generative AI for legal advice, you should consider the AI tools you’re using, the configurations of those tools, and the purposes for which you are using the tools. Credit: Emma Wallace
0
Data Safety Laws You Can't Ignore

Kids, Clicks, and Compliance: Data Safety Laws You Can’t Ignore

Understanding age assurance vs. age verification vs. age signals and their impact on children and developers

For companies operating online, safeguarding kids in a digital world means navigating complex data protection rules along with many compliance challenges.  In the vacuum of federal legislation, individual states started passing their own regulations, creating a fast-growing patchwork of age-verification laws across the country. In several U.S. states, such as Florida, Texas, Louisiana, and Utah, among others, “age gating” for adult content is now or will become mandatory. In addition, many social media apps and app stores are now voluntarily “age gating” to meet privacy compliance requirements or reduce liability for AI-generated content. These laws and requirements vary substantially in their scope, applicable age thresholds, definitions of covered platforms, and enforcement frameworks.  For companies operating nationwide, that inconsistency is a major compliance obstacle, with implications reaching well beyond the protection of children online. Clear divisions have emerged between those who regard age verification as a necessary safeguard and critics who warn it could normalize a surveilled and censored internet. Profound consequences regarding privacy, speech and digital rights would affect every American, regardless of age. A legal battleground is taking shape around age assurance, age verification and age signals. The motivations behind these laws are generally positive. Lawmakers want to (i) prevent children from accessing pornographic or other harmful content; (ii) provide age-appropriate content and guardrails regarding suicide, self-harm, and addictive content; and (iii) provide more parental controls around children’s data.  The right way to implement these policy goals, however, is a lot messier.  Here’s the key question everyone needs to consider: How much information are we going to ask people to hand over to “know” their age? Before wading into this quagmire, let’s at least agree on some key definitions: Age Assurance – These are techniques to determine a person’s age and can be as low-tech as getting a user to self-report their age, or as high-tech as using AI techniques to “guess” a person’s age based on facial estimation, behavioral analysis or an analysis of data broker information. Age Verification – This is a subset of age assurance, where there is a high level of proof concerning a person’s age. This includes turning over a driver’s license or other types of digital IDs to access a service.  Age Signals – This is a signal from a device, operating system, or browser that can be based on age assurance or age verification techniques.  California’s Digital Age Assurance Act (AB 1043) set to take effect January 1, 2027 requires operating systems and app stores to obtain age verification upon account creation and then send age brackets via an age signal to developers. Developers cannot use this data or share it for purposes other than identifying a user’s age.  Compared to other age verification laws, which may require multiple websites or services to obtain vast amounts of personal data, this seems like a balanced approach. This law seems to limit the number of parties that collect sensitive data but still provides some level of age assurance for developers. In addition, we would strongly encourage app stores and operating systems to use on-device storage and processing, to further protect sensitive data. So what do you think? Do you agree with the California approach, and should this approach be adopted nationally? 
0
Automated decision-making technologies (ADMT) in employment decisions

Using AI’s Tools in Hiring, Firing, and Compensation Decisions

What Employers Need to Know About Using ADMT in Employment Decisions

Decisions about hiring, termination, and compensation represent substantial administrative costs for employers. Automated decision-making technologies (“ADMT”) can significantly streamline the process. However, employers using ADMT should be aware of recent and existing regulations governing the use of AI tools in evaluating prospective and current employees.

In addition to recent AI-specific regulation, use of AI tools in making employment decisions may be regulated by existing anti-discrimination statutes. Use of an algorithm that discriminates against a protected class identified in federal statutes – most notably Title VII of the Civil Rights Act and the Americans with Disabilities Act (ADA) – may expose employers to liability. What is ADMT? ADMT, or automated decision-making technology, is any technology that processes personal information and uses computation to replace or substantially replace human decision-making. AI tools used in employment may be one type of ADMT available to employers. In the context of ADMT, significant employment decisions may include:
  • Hiring
  • Allocating work or compensation
  • Promotion and demotion
  • Suspension and termination
State and local compliance requirements may create exceptions for businesses that do not use the AI tool’s recommendations as a substitute for human discretion. However, this may be a high bar to overcome, and not all types of human involvement qualify for an exception. For further explanation, please refer to the “Best Practices for Employers” section below. What are the risks of employment discrimination? AI and other ADMT tools involved in significant employment decisions may pose two key risks regarding employment discrimination. There is a risk they may: 1) Exclude or disadvantage applicants from a protected group identified in Title VII or applicants with disabilities. Groups are protected by the statute on the basis of race, color, sex, religion, or national origin. This may apply even if there is no intent to discriminate: If the technology is shown to have a disproportionate effect on a protected group, the employer may be vulnerable to a lawsuit. For example, if ADMT tends to exclude candidates with names that suggest a particular racial or national identity, this could pose risk to the employer using this ADMT. 2) Screen out candidates based on aspects of their application that characterize a disability recognized by the ADA. This screening process may apply to a seemingly neutral selection criterion. For example, an AI tool that screens employees out for a resume gap lasting longer than four months could raise a risk of liability if the individual has a disability requiring substantial recovery periods after medical intervention. What types of ADMT pose particular risks of discrimination? Certain types of ADMT may pose particular risks of violating state and federal regulations. This may include AI-hiring tools with algorithms that:
  • Fail to take into account reasonable accommodations or available workplace alternatives in their assessment of a candidate’s ability to uphold the employer’s performance standards
  • Fail to include measures to mitigate against sensitivity to names of candidates – which contain information as to the gender and/or ethnic or racial origins of the applicant
  • Are overly reliant on inferences between the applicant and existing successful employees, which may reinforce existing hiring biases
  • Fail to account for possible reasonable accommodations related to their disability that are available to the applicant
  • Rely on an empirical evaluation of an individual’s conformity with a subjective standard such as “culture fit”.Additionally, video-interviewing software that includes emotion-recognition technology without human involvement in their hiring decision, and hiring tools that require the applicant to provide medical information prior to employment may also create additional risk.
Best Practices for Employers When selecting an AI tool for use in your employment decisions, there are measures employers can take to potentially reduce the risk of discrimination. 1. Transparency. Measures may include requesting transparency from the developer about mitigating measures to insulate decisions against particular risk factors.For example, seek tools that do not weigh factors posing particular risks of discrimination in the scoring process so heavily that they disqualify candidates. Transparency is also useful in preparing risk assessments which may be required by state and local regulations when using AMDT. 2. Human Involvement. Employers may also consider assessing the degree of human involvement in the decision-making process to see if the applied use qualifies for an exception from the regulation. If seeking an exception, a certain degree of human involvement may be required. Examples of insufficient degrees of human involvement may include situations where the decision-maker:
  • Is tasked with merely reviewing AI output
  • Lacks authority to change the decision
  • Lacks access necessary to make an independent decision
  • Operates under time constraints insufficient for substantive review
  • Only intervenes for obvious mistakes
In general, businesses should not recommend that the human decision-maker follow the AI’s decision by default in policy or in practice and should encourage independent human review. 3. Preparation. When using AI to assist in employment decisions, businesses may want to consider:
  • Conducting and submitting a risk assessment evaluating the risks of potential discrimination or data privacy balanced against the benefit to the business
  • Disclosing use of an AI tool in the applicant selection process before an applicant submits their application
  • Consulting state and local regulations to confirm compliance with required procedures and components. For example, CA, NY, IL, and CO are among the states that mandate some type of pre-disclosure when using ADMT or similar tools. Depending on the jurisdiction, it may be helpful for employers to consult relevant statutes to determine specific compliance requirements and timelines for disclosure.
  • Maintaining alternative processes to ADMT for selecting qualified candidates and allow potential applicants to opt-out of its use in evaluating their application. For candidates with disabilities, this may also include providing candidates with reasonable accommodations, including specialized equipment or extended timing or other modifications for timed skill assessments.
  • Establishing an appeal process for employment decisions made using AI tools.
  • Anticipating possible requests for deletion of personal data in response to evolving privacy rights across various jurisdictions. For example, in California, applicants may have existing privacy protections that include the rights to:
    • Be notified regarding a business’s use of AI in making employment decisions
    • Know what data is being collected, its purpose, and with whom it will be shared
    • Request deletion of personal information
    • Correct inaccurate personal information
    • Stop or limit the sale of sensitive personal information
    • And non-discrimination for exercising the rights provided.
What’s Next? The recent Executive Order suggests that national policy may soon tend away from allowing applicants and/or employees to bring claims based on an AI tool’s disproportionate effect on a protected group. (Executive Order, Ensuring a National Policy Framework for Artificial Intelligence, Sections 6 & 9, issued December 11, 2025). However, as state and local-level protections take effect and as federal minimum standards continue to be fleshed out, some caution is required as these standards are interpreted by relevant state and federal agencies.
0
California Sets Rules for AI Nationwide

California Sets National AI Policy

 

In The Vacuum Of Federal Legislation, California Sets National AI Policy by Lily Li | Founder of Metaverse Law | Cybersecurity & AI Lawyer

Within a day of taking office, President Trump overturned Biden’s Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.[1] The agencies quickly followed suit. The EEOC and DOL withdrew their guidance on AI and workplace discrimination, and the HHS stalled on its proposed updates to the HIPAA security rule in the face of a Texas court order. This past summer, the House added a ten-year moratorium on state AI laws in the “One Big Beautiful Bill Act,” only to have this provision repealed 99-to-1 in the Senate.[2] Overall, the message from the White House is clear: deregulate AI. These federal efforts may have created a backlash, however, by spurring an aggressive state response. Regardless of your politics and whether you think this is a good thing or a bad thing, California has stepped into the vacuum to set national AI policy. The state’s 2025 legislative session was a banner year, setting records for the number and scope of new AI laws. From AI Safety to AI Transparency & Risk Assessments On September 29, 2025, Governor Gavin Newsom signed Senate Bill 53 into law, the Transparency in Frontier Artificial Intelligence Act. Starting in January 2026, California will require large frontier AI developers to publish a framework detailing how they incorporate safety, security, and testing standards into their AI models. SB 53 also creates a mechanism for AI developers and the public to report critical safety incidents, and protects internal whistleblowers who report risks posed by frontier AI models. The law establishes significant penalties for companies who fail to comply, with fines of up to $1 million per violation. Governor Newsom signed this law in order to spur federal action. In his signing note, he stated that if the federal government adopted similar or more demanding national AI standards, further action would be taken to align the policy to the national standard. Per Governor Newsom, “In enacting this law, we are once again demonstrating our leadership, by protecting our residents today while pressing the federal government to act on national standards.”[3] Governor Newsom’s action on SB 53 contrasts with his position on AI legislation a year ago. On September 29, 2024, exactly a year before signing SB 53, he vetoed SB 1047 (the Safe and Secure Innovation for Frontier Artificial Intelligence Models Act) – the precursor bill to SB 53. The veto message pointed to the importance of the AI industry to California, and noted that the proposed legislation may overlook smaller, more dangerous models, among other concerns. Just as importantly, the veto message pointed to growing federal standards under the NIST’s U.S. AI Safety Institute, and Governor Newsom’s hope to coordinate with federal partners and experts.[4] With the U.S. AI Safety Institute scrapped and federal AI efforts under fire, Governor Newsom’s about-face on SB 53 seems less about the surface-level changes between SB 53 and SB 1047, and more about the growing political divide on AI legislation. The California approach to AI transparency and safety legislation also needs to be read in conjunction with the California Privacy Protection Agency’s (CPPA’s) recently approved regulations. In addition to more traditional privacy concerns, the CPPA’s most recent 127-page rulemaking package contains requirements governing cybersecurity audits, risk assessments, and automated decision-making technology (ADMT).[5] AI developers and systems that process personal information and meet certain California privacy thresholds will now face substantial cybersecurity audit and risk assessment requirements. In addition, if they engage in automated and significant decisions concerning the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services, they will also have significant notice, opt out and risk assessment requirements. These ADMT regulations also have a history. They are five years in the making and stem from Prop 24, a 2020 ballot initiative to amend California’s privacy laws. During the CPPA’s consideration of these draft ADMT regulations, Governor Newsom sent a letter to the Agency, asking them to pare down the scope of the regulations. Per Governor Newsom, “enacting these regulations could create significant unintended consequences and impose substantial costs that threaten California’s enduring dominance in technological innovation.”[6] The final version was a compromise, paring away references to generative AI and artificial intelligence generally, but maintaining the bulk of the remaining requirements. Thus, we see the unique political circumstances of California play out in AI regulation. A double whammy through SB 53 by the state legislature, and through ADMT regulations by the CPPA (founded through the direct democracy of California’s ballot initiative process). Civil Rights, Employment Bias, and Discrimination In 2023, the EEOC issued guidance that cautioned employers to use AI workplace tools responsibly, addressed the use of AI software and algorithms in the employment selection processes under Title VII and employers’ compliance responsibilities related to the ADA. In 2024, the DOL further issued a document entitled “Artificial Intelligence and Worker Well-Being – Principles and Best Practices for Developers and Employers.”[7] This document recommended that employers include workers in the AI adoption process, bargain with unions in good faith regarding the adoption of AI technologies, establish AI governance and human oversight, not rely on AI systems in making “significant employment decisions” without “meaningful human oversight,” and monitor AI to safeguard worker rights, including leaves of absence, accommodations, wages, and break times. While President Trump’s recission of Biden’s executive order on AI did not expressly rescind these guidance documents, the EEOC and DOL removed these publications from their websites.[8] In contrast, California’s Civil Rights Council promulgated regulations that implemented California’s civil rights laws, explicitly stating that California’s antidiscrimination laws apply to AI workplace tools. On October 1, 2025, these new regulations went into effect.[9] Per the new regulations, it is unlawful for an employer to use automated-decision systems or selection criteria that discriminates based on a basis protected by existing California law. Relevant to any such claim or available defense is evidence, or lack thereof, of anti-bias testing or similar proactive efforts to avoid unlawful discrimination, including the quality, efficacy, recency and scope of such an effort, the results of the testing, and the response to the results. Healthcare AI and Chatbots California is also taking the stage in healthcare and AI regulation. In January of 2025, California Attorney General Rob Bonta issued a “Legal Advisory on the Application of Existing California Law to Artificial Intelligence in Healthcare.”[10] This advisory set forth California’s existing consumer protection, civil rights, competition, and data privacy laws governing healthcare and highlighted the passage of several healthcare AI bills in 2024. In 2025, California continued to advance healthcare AI legislation with the passage of AB 489, prohibiting AI systems from falsely indicating or implying possession of a medical license or certificate through marketing or other functionality.[11] AI Safeguards for Children: Converging Standards While California and the federal government may be at odds on broad AI legislation, there is convergence in one area: protection of minors. Lawmakers on both sides of the aisle agree that children should be protected from harmful AI content, whether it is suicidal ideation, self-harm, or sexually explicit imagery. Partly, this is spurred by the tragic suicides of a teenager in Orange County, California and another in Florida, both of whom formed close relationships with generative AI systems before their deaths.[12] Partly, this is driven by the furor over a leaked internal Meta document, disclosing content standards that allowed AI systems to “engage a child in conversations that are romantic or sensual.”[13] In California, for instance, Governor Newsom signed SB 243, landmark AI chatbot legislation that require “companion chatbots” to address suicidal ideation, sexually explicit imagery, and extended use by minors.[14] This law applies to chatbots that provide human-like interactions and capable of sustaining relationships across multiple interactions, and requires AI disclosures, referrals to suicide hotlines or crisis text lines, and break reminders. SB 243 further requires companion chatbots to institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct. The legislation includes a private right of action to individuals who suffer “an injury in fact” with statutory damages of one thousand dollars ($1,000) per violation, or actual damages if greater. California also passed companion bills AB 1043 and 56, which further require age verification and warning labels for covered online platforms. At the federal level, the FTC launched inquiries into seven major consumer-facing chatbot companies, asking for information on how these firms measure, test, and monitor potentially negative impacts of this technology on children and teens.[15] This followed investigations by the Texas AG into Meta and Character.AI for alleged unfair and deceptive practices towards children.[16] The Attorney Generals of fourty-four different states signed onto a letter following the alarming reports of Meta AI chatbots engaging in sexually inappropriate conversations with children.[17] Given the common interests in protecting children online, we anticipate further efforts at both the state and federal level in 2026 to impose online age verification, parental consents and additional guardrails on children’s interactions with AI systems. Why Follow California? While California might be motivated to set AI national policy, why do businesses and lawmakers in other states follow California’s lead? Partially, this is due to practicality. The largest AI companies train and deploy systems at scale. It does not make sense creating a different user interface and back-end system for each state, rather than embedding the highest privacy, security, and safety controls into the system as a whole. Partially, this is due to risk appetite. Unlike other state and federal AI laws, California’s legislature is far more willing to adopt private rights of action and statutory damages in its legislation – incentivizing lawsuits. This in turn develops a whole body of law that provides guidance and interpretation for statutory language that might be similar across state lines. Finally, let’s not forget that California is home to some of the largest AI companies in the world. Even a world of AI, remote work, and borderless systems, sometimes there still is a hometown advantage. ENDNOTES [1] White House, Initial Rescissions of Harmful Executive Orders and Actions (Jan. 20, 2025), https://www.whitehouse.gov/presidential-actions/2025/01/initial-rescissions-of-harmful-executive-orders-and-actions/ [2] Senate Strikes AI Moratorium from Budget Reconciliation Bill in Overwhelming 99-1 Vote, (July 1, 2025) https://www.commerce.senate.gov/2025/7/senate-strikes-ai-moratorium-from-budget-reconciliation-bill-in-overwhelming-99-1-vote/8415a728-fd1d-4269-98ac-101d1d0c71e0 [3] Office of the Governor, SB 53 Signing Message, (September 29, 2025) https://www.gov.ca.gov/wp-content/uploads/2025/09/SB-53-Signing-Message.pdf [4] Office of the Governor, SB 1047 Veto Message, (September 29, 2024) https://www.gov.ca.gov/wp-content/uploads/2024/09/SB-1047-Veto-Message.pdf [5] CA Privacy Protection Agency, TEXT OF REGULATIONS (CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations), https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf [6] Tyler Katzenberger, Big Tech has another California problem (04/25/2025 10:00 AM EDT), Politico, https://www.politico.com/news/2025/04/25/big-tech-california-data-privacy-regulation-fight-newsom-00309171 [7] Department of Labor releases AI Best Practices roadmap for developers, employers, building on AI principles for worker well-being (October 16, 2024), https://www.dol.gov/newsroom/releases/osec/osec20241016 [8] Gone but Not Forgotten: Federal Laws Still Apply Despite AI Guidance Disappearance Act, Cooley Alert (February 21, 2025), https://www.cooley.com/news/insight/2025/2025-02-21-gone-but-not-forgotten-federal-laws-still-apply-despite-guidance-disappearance-act [9] Civil Rights Council Secures Approval for Regulations to Protect Against Employment Discrimination Related to Artificial Intelligence (June 30, 2025), https://calcivilrights.ca.gov/2025/06/30/civil-rights-council-secures-approval-for-regulations-to-protect-against-employment-discrimination-related-to-artificial-intelligence/ [10] https://oag.ca.gov/system/files/attachments/press-docs/Final%20Legal%20Advisory%20-%20Application%20of%20Existing%20CA%20Laws%20to%20Artificial%20Intelligence%20in%20Healthcare.pdf [11] https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB489 [12] Associated Press, Parents of teens who died by suicide after AI chatbot interactions to testify to Congress, Orange County Register (September 16, 2025, 12:54 PM PDT), https://www.ocregister.com/2025/09/16/chatbots-teens-safety-congress/ [13] Jeff Horwitz, Meta’s AI rules have let bots hold ‘sensual’ chats with kids, offer false medical info, (Aug. 14, 2025, 6 a.m. GMT), Reuters, https://www.reuters.com/investigates/special-report/meta-ai-chatbot-guidelines/ [14] Governor Newsom signs bills to further strengthen California’s leadership in protecting children online (Oct. 13, 2025), https://www.gov.ca.gov/2025/10/13/governor-newsom-signs-bills-to-further-strengthen-californias-leadership-in-protecting-children-online/ [15] FTC Launches Inquiry into AI Chatbots Acting as Companions (September 11, 2025) https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions [16] Attorney General Ken Paxton Investigates Meta and Char​ac​ter​.AI for Misleading Children with Deceptive AI-Generated Mental Health Services (August 18, 2025) https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-investigates-meta-and-characterai-misleading-children-deceptive-ai [17] National Association of Attorneys Generals (August 25, 2025) https://oklahoma.gov/content/dam/ok/en/oag/news-documents/2025/august/AI%20Chatbot_FINAL.pdf Lily Li is an AI, data privacy, and cybersecurity lawyer and founder of Metaverse Law. She is a certified information privacy professional for the United States and Europe and is a GIAC Certified Forensic Analyst for advanced incident response and computer forensics. She can be reached at info@metaverselaw.com.
1 2 3