Privacy Policies and Practices: Hims & Hers Enforcement

Most people are familiar with the idea of a privacy policy – the long document we often agree to when signing up for a service or purchasing goods. But what does a privacy policy actually do? In short, it outlines how a business collects, uses and shares personal information. The contents of a privacy policy may depend on the size and function of the business, the sector in which the business operates, and the jurisdictions in which the business is located or does business. 

Drafting and publishing the policy is only part of the job though. Businesses also need to also confirm that their actual practices, including the technology operating behind their website, match the promises that they make to their consumers in these policies.

The Federal Trade Commission (FTC) has long warned businesses that if they make privacy representations, they must honor them. The FTC specifically advises companies to review their privacy policies and ensure that their actual practices are consistent with those representations. As the recent FTC  lawsuit against Hims & Hers demonstrates, it is imperative that consumers are adequately informed about business practices in a clear and conspicuous manner. 

What are the risks of misalignment between business practices and consumer representations? 

In the United States, the FTC has the power to enforce the terms of privacy practices via the authority in Section 5 of the FTC Act, which prohibits unfair or deceptive advertising practices. The Commission’s landmark 1999 consent order with the web host GeoCities was the FTC’s first public settlement in the area of internet privacy, and as of 2023, the FTC has brought at least 97 internet privacy cases. 

Most recently, in July 2026, the FTC was joined by California and Utah authorities in a lawsuit against the telehealth company Hims & Hers for deceptive and unlawful privacy practices. This lawsuit alleged that the company shared customers’ sensitive health data, including medical conditions, with advertising platforms, despite implying that they keep health information private on their privacy policy. 

According to the FTC, some information was shared to third-party advertising platforms through customer lists, while other information was transmitted through third-party tracking technologies; the consumers’ health information was allegedly shared with Meta, Snap and other third parties. In its complaint, the FTC states that Hims & Hers also fails to disclose its billing practices adequately and makes it difficult for consumers to cancel their subscriptions. Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection claims this creates a scenario where “consumers [are] unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers’ most private health information without their consent.” 

This case remains pending and the allegations have not been adjudicated. Still, the lesson here is clear: a business’s sharing and selling practices must be accurately disclosed to the consumer via their privacy policy. 

This does not mean that businesses need to abandon tracking, analytics, or subscription services. Rather, this case – and many of the other enforcement actions highlighted by the FTC – emphasize an organization’s need to understand what these technologies do before describing their privacy practices to consumers and ensure that privacy policies accurately disclose these practices. 

Key Takeaways: 

Privacy policies should accurately disclose the business’s privacy practices to the consumer in a clear and conspicuous way. By reviewing both their privacy representations and the technologies behind them, an organization can take steps to ensure their privacy practices are accurate and up to date. Some of these compliance review measures may include: 

  • Inventorying pixels, cookies, analytical tools, chat-bot features, and other third-party technologies. 
  • Identifying what personal information each tool may collect or transmit, and who receives it. 
  • Paying particular attention to sensitive information and data entered into forms, portals and chat features. 
  • Reviewing vendor configurations and contractual terms governing data use.
  • Comparing actual data flows against the company’s privacy policy and other consumer-facing statements.
  • Requiring reviews before changing internal business practices that impact personal privacy.

Drafting and publishing a privacy policy may be required under certain state laws. However, this policy – like most privacy and compliance efforts – should not be treated as a one-time task. Websites, vendors and business practices change, and privacy policies should stay in alignment with these changing practices.  

AI Watermarking: Key Updates on New Transparency Rules

As generative artificial intelligence (AI) continues to advance, it’s becoming increasingly difficult to distinguish human-created content from AI-generated material. In turn, regulators are requiring certain AI systems to disclose where and how content is created. 

Two important examples are the European Union’s AI Act and California’s AI Transparency Act. While both of these laws address AI-generated content, neither requires businesses to use the same type of disclosure in every situation. Instead, the rules distinguish between different forms of transparency, including machine-readable markings that may not be visible to the human eye. These requirements may apply to both the provider of the AI system and the deployer, or the entity that makes the AI available to consumers.

The laws are falling into place, but how do they work in practice? For businesses developing or using generative AI, the challenge is not only whether AI-generated content should be watermarked, but how different types of media should carry that watermark. 

The EU AI Act 

Transparency requirements under Article 50 of the EU AI Act became generally applicable on August 2, 2026, with a grace to December 2, 2026, for certain products that were already on the market as of August 2, 2026. 

Among other requirements, providers of AI systems that generate synthetic text, images, audio or video must generally ensure that the output can be detected as artificially generated or manipulated. This may include machine-readable markings built into the content rather than displayed as a visible layer. 

The AI Act also creates separate disclosure requirements for certain users of AI-generated content. For example, deepfakes generally must be clearly disclosed as AI-generated or manipulated; AI-generated or manipulated text about matters of public interest may also require disclosure when it is published without human review. 

While the law provides the end goal, it does not necessarily define how to achieve it. For example, the EU AI Act was accompanied by the Guidelines on Transparency Obligations for Providers and Deployers of Certain AI Systems. These guidelines provide definitions and explain how compliance with the AI Act’s transparency obligations may be demonstrated. But still, these guidelines defer to “providers and deployers [who] can determine adequate measures themselves, while taking into account these guidelines.” In short, this means the EU AI Act sets the standard but leaves the means of meeting it to the AI provider or deployer. 

This means AI transparency can look different, both because of the media involved and because the provider or deployer can determine how best to meet these transparency standards. For example, a machine-readable watermark may help technology detect that AI was involved, while a visible or audible disclosure is meant to inform the person viewing or interacting with the content that it was AI- generated or altered. But the form and format of these transparency measures may largely be subject to the organisation’s discretion. 

The California AI Transparency Act 

California has also adopted AI-content transparency requirements through the California AI Transparency Act. Originally enacted through SB 942 and amended through AB 853, this law went into effect on August 2, 2026. 

The law generally requires providers of any “large online platform” – that is, a publicly available generative AI platform with over 2 million unique monthly visitors over the preceding 12 months – to provide tools that can help users determine whether covered image, video or audio content was created or altered by an AI system. 

The California AI Transparency Act distinguishes between two different types of disclosures: latent and manifest. A latent disclosure is built into the content, but it’s not readily visible to the average person. A manifest disclosure is one that a layperson can more easily see and understand. 

California’s requirements are also evolving. Businesses subject to the law may need to monitor legislative changes as lawmakers revisit how disclosure and detection requirements need to operate. 

What does AI watermarking look like? 

Anthropic’s recent changes to Claude provide one example of how companies may approach these requirements. 

In August 2026, Anthropic announced that the new Claude models would include machine-readable markings in response to the EU AI Act and other similar legislative requirements. For generated text, Claude uses an imperceptible watermark based on patterns in how the model selects words. According to Anthropic’s press release, the watermark is not a visible or hidden set of characters and does not identify the person or company who generated the content. 

However, these tools are far from perfect. Anthropic explains that a text watermark can disappear or weaken; they describe it as not “foolproof” if content is heavily rewritten, translated or combined with other materials. File-based provenance information can also get lost if files are converted, resaved or captured by screenshot. 

This means that businesses should not treat watermarking as a perfect way to determine whether something was created by AI. Instead, it may be one tool to provide more information about where content came from and whether AI was involved. 

Can EU rules affect U.S. businesses? 

United States companies may also feel the effects of the EU AI Act even when a particular use of an AI product occurs outside Europe. 

For a company operating in multiple countries, creating different versions of the same product for each jurisdiction can become expensive and technically complicated. A business may instead choose and decide to build one version that satisfies the strictest applicable requirements and use that version more broadly.

For example, Anthropic has said that although its Claude watermarking changes were driven by the EU AI Act, it is applying them globally rather than limiting them to European users. 

This can create a spillover, where a law passed in one jurisdiction changes how an AI product operates for users everywhere else.  Similar regulatory concepts are also appearing in U.S. state AI laws. California and other states have adopted requirements involving transparency, disclosures, and AI governance that overlap with themes found in the EU AI Act, even though the laws differ in their scope and specific requirements.

As AI regulations continue to develop across different jurisdictions, companies may consider whether maintaining different disclosure mechanisms per jurisdiction makes sense. Alternatively, companies may comply with the most stringent regulations across all markets, setting a higher standard of compliance across the board. 

What should businesses take away?

Businesses do not necessarily need to approach every type of AI generated content in the same way. However, companies developing or using generative AI may want to review how their systems identify AI generated content, and whether their disclosure practices meet the requirements that might apply to them. Some steps businesses may want to consider include:

  • Identifying what types of AI-generated content the business uses or provides to consumers, including text, images, audio and video. 
  • Determining whether applicable laws require machine-readable markings or visible disclosures.
  • Understanding how watermarks or provenance information may change if content is edited or redistributed. 
  • Checking if AI-generated content from outside vendors keeps its watermark or disclosure when the business edits, downloads, or republishes it into another product. 
  • Considering whether maintaining different product versions across jurisdictions is practical.
  • Monitoring United States, EU, and other developing AI transparency requirements and laws. 

AI watermarking is still rapidly developing both technically and legally. Businesses do not necessarily need to treat every AI-generated output the same way, but they may need to increasingly understand when AI-generated content should be identified and whether their current systems can provide that transparency. For businesses using AI-generated content in marketing, customer communications, and other business activities, understanding when and how that content must be identified can help reduce compliance risks as these rules continue to develop 

Shadow AI: How Can Companies Protect Against Unknown Uses?

Employees don’t always wait for their employers to approve new technology. This could be using a personal chatbot account to summarize a document, installing an AI browser extension, uploading information into an AI analysis tool or using an AI feature built into software without their employer knowing about it. This practice is often referred to as “shadow AI.”

Shadow AI is typically not malicious. Often, it’s the result of employees wanting to work more efficiently, or as a result of unclear AI use policies. However, shadow AI can create security and confidentiality issues. If employees send personal or company information into an AI system that has not been reviewed, the business may not have an accurate picture of where its information is going, how it’s being used, or for how long it is being stored. 

What does shadow AI look like?

Shadow AI could include any number of unapproved AI tools used for work purposes. For example, an employee may paste customer information into an LLM to create a summary, upload internal presentation information for editing or use an AI tool to analyze a spreadsheet. 

The problem is that using shadow AI can result in company information being sent to a third-party provider that the original company may not know about. By hiding in the “shadows,” employees who use AI tools in this way can create governance gaps. Without proper review of the AI tools being used by its employees, a company may not know what information is being provided, how long it will be retained for, who can access it or whether the vendor can use it for other purposes, like training its own systems. 

How can companies address employee AI usage?

Company AI policies can bring clarity to issues surrounding shadow AI. 

By addressing what kinds of technologies may be used, these policies can explain which AI tools are approved, what information employees may enter into those tools, and when a new AI tool or use requires review. In general, companies drafting these policies may want to specifically and clearly state what information may and may not be used. For example, a general policy telling employees to use AI responsibly may not provide enough guidance when someone is deciding whether to upload a confidential document or customer data into a new tool. 

These policies should also be communicated clearly. Without understanding the policies that a company has in place, employees may inadvertently engage in shadow AI use. With clarity on approved tools, uses, and inputs, an effective employee AI use policy could lower these risks. Within this policy, a company may may consider creating a process to request new AI tools. This way, relevant business teams can review any AI tools and uses before company information is provided.  

What should businesses take away?

Businesses do not necessarily need to prohibit AI use. However, companies may consider reviewing which tools employees are using and what information is being provided to them. Some steps companies may consider in this review process include, but are not limited to: 

  • Identifying AI tools employees are actually using, including personal accounts, browser extensions and AI features within existing software.
  • Explaining which tools are approved, restricted or prohibited and what information employees may enter.
  • Considering privacy, confidentiality, retention, deletion and AI-training terms with vendors.
  • Determining whether AI uses involve processing that requires a CCPA risk assessment or updates to privacy documentation.
  • Establishing rules preventing employees from providing sensitive company information to unapproved AI tools.
  • Giving employees a clear way to request new AI tools before using them for company work.

While AI in the workplace may boost efficiency, it may also create risk if the company is not aware of it. By providing employees with guidance on AI, businesses may be able to reduce the risks of shadow AI. 

AI Notetakers: Key Takeaways for Recording Calls

Use of AI notetakers is quickly becoming routine. These tools can automatically join video calls, listen to conversations, generate transcripts, create summaries, and identify key points in a meeting. 

While these tools have an argument for efficiency, they also create legal, privacy, and confidentiality risks. 

This issue is a lot more complicated than simply asking participants of a meeting for their consent to be “recorded.”  This is because recording, transcription, and AI processing are separate activities – and each may have its own notice and consent requirements.

As a result, businesses using these tools need to understand both what is happening during the meeting and what happens to the information after the meeting has ended.

What are AI notetakers?

An AI notetaker is a tool that captures meeting content and uses artificial intelligence to create transcriptions, summaries, action items, and log other important meeting records. Most operate as a bot that joins a video conference meeting as an additional participant. 

Many AI notetakers process information from meetings through cloud-based services rather than keeping the conversation only on an employee’s local computer. Depending on the provider, the service may receive audio transcripts and other meeting information and then use an AI system to analyze and summarize the dialogue. This means meeting content may be transferred outside of the company’s own system and processed or stored by a third-party provider, which may have privacy and data-sharing implications. 

Why do recording and consent laws matter?

Recording laws differ across the United States. Some states generally follow a one-party consent approach, meaning the consent of one participant is sufficient to record a conversation.  However, other states follow an all-party consent approach, sometimes referred to as “two-party consent” which generally requires the consent of everyone involved in a conversation for recording. The specific details and exceptions vary by jurisdiction. 

What actually counts as consent?

Sometimes consent can be more complicated than just simply displaying a recording symbol. Video-conference platforms may use different methods to alert participants when recording a meeting begins: a pop-up requiring participants to acknowledge the recording, an audible announcement, a banner or an icon that’s displayed during the meeting, some hosts may also require verbal consent.

But notice and consent are not always the same thing and what constitutes legally sufficient consent can depend on the applicable law and the circumstances at hand.

What happens to meeting information after the call?

Once an AI notetaker has captured a meeting, businesses should understand what rights the provider has over that information. Vendor terms can address data ownership, licensing, data retention, and whether information may be used to develop or improve the provider’s service. 

This becomes especially important as ordinary workplace conversations frequently include information that employees may not intentionally send to a third party: customer information, personnel issues, financial projections, internal strategy, product development and many other confidential materials may all be discussed while the AI notetaker captures the conversation. 

The transcription or summary can also create additional security concerns once the meeting ends. For example, automatically generated notes may be distributed via email, downloaded, forwarded and stored in employee accounts long after an original conversation has occurred. Meeting summaries create additional opportunities for sensitive information to spread or remain stored indefinitely. 

Businesses should therefore review not only what the tool captures but also who receives the resulting transcript, where it is stored, how long it is retained and who has the ability to delete it.

What about attorney-client privilege?

Adding an AI notetaker to a legal discussion can create questions about whether confidentiality has been maintained, and depending on the circumstances, whether privilege could be challenged or waived. You can read more updates from Federal District Courts on the issue here. 

This does not mean that all use of technology during a legal meeting automatically destroys attorney-client privilege. Whether privilege is affected may depend on the circumstances such as how the AI provider handles information and why the tool is being used. Therefore, businesses should be more cautious about allowing AI notetakers into meetings that involve legal advice or other professionally protected information. 

The same concern applies to trade secrets and other confidential business information. Meetings involving sensitive product plans or internal strategies and other proprietary information may not be appropriate for AI transcription unless the tool and its data practices have been reviewed carefully. 

What should businesses take away?

AI notetakers can be useful workplace tools, but businesses should have clear policies in place before employees begin using them regularly. Below are some high-level tips that businesses may want to consider when onboarding a new AI notetaker: 

  • Approve specific tools: Employees should know which AI notetakers are permitted and how those tools record, transcribe, store and process meeting information.
  • Create clear notice and consent procedures: Businesses may consider the laws that may apply to meeting participants and make sure notices accurately reflect how AI is being used.
  • Limit use in sensitive meetings: Legal, HR, disciplinary investigation and other confidential discussions may require additional approval or no AI notetaker at all.
  • Review vendor data practices: Companies should understand how meeting information is used, stored, retained and deleted, including whether it may be used to train or improve AI systems.
  • Set rules for transcripts and summaries: Businesses may want to determine who can access or share AI-generated notes, how long they are kept and whether they are treated as official company records.

AI Companion Chatbot Regulations: New State Laws Target Child Safety, Disclosures & Crisis Response

Eyes on AI Chatbots: New State Laws Target Child Safety, Disclosures and Crisis Response 

AI companion chatbots have recently become a focus of state AI regulation. Unlike task-oriented chatbots, companion chatbots may be designed to simulate conversation, friendship, emotional support or other ongoing personal relationships. These features may create heightened legal and safety concerns, especially when users are minors, emotionally vulnerable or may mistake automated responses for human support. 

State legislatures are beginning to address some of these risks.  While some enacted laws focus more on transparency and AI disclosures, proposed bills go further by addressing youth safety, emotional dependence, crisis response, age verification, data protection and human oversight. The Future of Privacy Forum is currently tracking 98 chatbot-specific bills across 34 states and three federal proposals, showing how quickly and unevenly chatbot regulation is developing.

Why are companion chatbots receiving regulatory attention?

Companion chatbots raise unique risks compared to traditional automated tools as they are often designed to boost user interaction, and keep users engaged over longer periods of time. In some cases, they may remember previous conversations, provide emotionally validating responses and create the impression of a meaningful relationship. These features may make the product engaging but also raise concerns about manipulation, emotional dependency and the collection of sensitive and personal data.

These risks are especially significant when the user is a minor. Because minors may have a harder time recognizing the limits of AI systems or identifying persuasive design techniques, they may be more vulnerable to mistaking automated responses for genuine human support. Regulators are also paying closer attention to situations in which a user discloses mental health concerns or expresses self-harm thoughts during a chatbot interaction. 

Across these proposals, there are several recurring regulatory themes: transparency, age verification, content safety, harm prevention, data protection, liability and enforcement practices. These themes suggest that lawmakers are not only concerned with whether users know they are interacting with AI but also with how chatbot systems are designed, how they collect data, and how they respond if a user may be at risk. 

What laws have already been passed?

Connecticut recently enacted one of the broader state laws addressing youth online safety and AI-related protections. On June 2, 2026, Governor Lamont signed Public Act 26-15, describing it as a bipartisan law intended to protect children and adults from digital-age harms, including youth social media addiction and concerns over the growing use of AI. The law also includes chatbot-related protections, such as requiring chatbot operators to make reasonable efforts to detect suicidal ideation or indicators of self-harm expressed by users and to maintain a protocol for responding with appropriate resources. Connecticut’s law goes into effect October 1, 2026.

California has also already taken steps to regulate companion chatbots through SB 243, which established baseline disclosure and safety requirements for companion chatbot operators. This law is in effect, with additional requirements for operators beginning July 1, 2027. 

Together, these enacted laws show that states are beginning to regulate AI systems directly, even without a comprehensive federal AI law. For businesses, this means AI compliance may increasingly depend on tracking different state requirements rather than relying on one national standard.

What pending proposals should companies watch?

Pending California bills highlight how companion chatbot regulations may become more specific. For example, SB 1119 focuses on chatbot interactions with child users, defined as consumers under 18 years of age. If enacted, it would require operators to take a more proactive approach to safety by conducting annual child safety risk assessments, creating public child safety policies, setting privacy and safety defaults for minors, providing parental controls, and conducting audits. It would also restrict certain chatbot behaviors like responses that encourage self-harm, substance use, disordered eating, or harm to others. This bill is currently active in the Assembly committee process.

California’s AB 1988, also known as the PAUSE Act, focuses more directly on crisis response. Unlike SB 1119, this bill is not limited to minors. If enacted, AB 1988 would require companion chatbot operators to identify and respond to credible crisis expressions, provide 988 Suicide and Crisis Lifeline information, pause chatbot responses after repeated crisis expressions, and require human moderator review before ending that pause. This bill is currently active in the Senate committee process.

These proposals show that chatbot regulation is moving beyond basic transparency requirements. Lawmakers are increasingly focused on how AI systems are designed, how they interact with vulnerable users, and whether companies have real safety procedures in place when a chatbot conversation becomes harmful or high risk.

What should companies take away?

For companies that are developing or deploying companion chatbots, one key takeaway is that basic AI disclosure may not be sufficient. Emerging state laws are narrowing in on how chatbots interact with minors, respond to self-harm or crisis-related statements, collect sensitive data, and whether meaningful human oversight is available. Businesses operating across multiple states should track both enacted laws and pending proposals as chatbot obligations may differ by state and are continuing to rapidly change. 

1 2 3