On June 10, 2026, the European Commission published a Code of Practice on marking and labeling of AI-generated content (the Code) following a public consultation that took place last year. The Code is divided into two sections:

  • Section 1 sets out provenance requirements applicable to providers offering generative AI systems.
  • Section 2 sets out transparency rules for AI-generated content applicable to deployers of AI tools, such as requirements to visibly label deepfakes and AI-generated text on matters of public interest.
Continue Reading EU Commission Publishes AI Transparency Code of Practice

On June 29, 2026, the U.S. Supreme Court issued its opinion in Trump v. Slaughter, where the six-Justice majority held that appointed agency officials who wield executive power are subject to presidential removal. In so holding, the Court overruled its 1935 decision in Humphrey’s Executor v. United States, 295 U.S. 602 (1935), which for nearly a century stood for the principle that Congress can create independent agencies whose leaders can only be removed for cause.

Continue Reading The FTC After Slaughter: What Businesses Need to Understand

Last month, the Connecticut legislature passed two bills that amend and expand the Connecticut Data Privacy Act (CTDPA): Senate Bill 4 (SB 4) and House Bill 5222 (HB 5222). SB 4 (which was signed into law on May 27, 2026) and HB 5222 (which amends parts of SB 4 and was signed into law on June 2, 2026) contain new requirements for businesses and data brokers operating in the Constitution State.

Continue Reading Connecticut Updates Its Data Privacy Act, Imposing Significant New Privacy Requirements

As we ring in the new year, we want to make you aware of key issues that we expect lawmakers and regulators to focus on this year. Below are the top U.S. data, privacy, and cybersecurity issues to watch out for in 2026:

Continue Reading 2026 Year in Preview: U.S. Data, Privacy, and Cybersecurity Prediction

On June 18, 2025, the United States District Court for the Northern District of Texas vacated most of the rules designed to enhance reproductive healthcare privacy promulgated by the U.S. Department of Health and Human Services (HHS) in 2024. More specifically, the court ruled in Purl v. United States Department of Health and Human Services et al, No. 2:2024cv00228 (N.D. Tex. 2025) (the Decision) that the “Health Insurance Portability and Accountability Act Privacy Rule to Support Reproductive Health Care Privacy” (the “2024 HIPAA Rule”) is contrary to law because it unlawfully limits state public health laws; impermissibly redefines certain terms in contravention of federal law and in excess of statutory authority; and exceeds HHS’s authority. Regulations promulgated under HIPAA prior to the 2024 HIPAA Rule remain unchanged.

Continue Reading Texas District Court Vacates 2024 HIPAA Rule Designed to Enhance Reproductive Healthcare Privacy, Effective Nationwide

On March 25, 2025, Utah Governor Spencer Cox signed HB 452, which establishes new rules for the use of artificial intelligence (AI) mental health chatbots accessible to any “Utah user,” defined as, “an individual located in the state at the time the individual accesses or uses a mental health chatbot.” Digital health companies and AI chatbot providers should take note of this new law to ensure compliance with its requirements.

Continue Reading Utah Enacts Mental Health Chatbot Law

Companies that may have child users, or whose competitors have child users, take note. On January 16, 2025, the Federal Trade Commission (FTC) announced the final amendments to the Children’s Online Privacy Protection Rule (COPPA Rule). At a high level, the COPPA Rule requires websites or online services to provide notice and obtain verifiable parental consent before collecting information from children under the age of 13. The Rule’s amendments slightly expand the Rule’s scope, change the previous notice and consent provisions, and implement new data security requirements. Violations of the Rule would be subject to $53,088 in civil penalties per violation.

Continue Reading New Federal Children’s Privacy Requirements Are Not Child’s Play: FTC Amends COPPA Rule, Imposing New Obligations on Child-Directed Services