Listen to this post

If your business recently received a demand letter accusing your website of violating California’s wiretapping law, you’re not alone. On September 17, 2026, Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofits about a surge in demand letters alleging violations of the California Invasion of Privacy Act (CIPA). The letters target ordinary website tools — cookies, pixels, analytics software, and search bars — claiming they amount to illegal surveillance.

How a 1960s Wiretapping Law Became a Website Litigation Tool

CIPA was enacted in 1967, long before cookies, chat widgets, session-replay tools, or website search bars existed. But plaintiffs have increasingly stretched the statute to cover modern website technologies, arguing that these tools amount to unlawful “wiretapping” or tracking when deployed without adequate consent.

As discussed in Bradley’s prior Online and OnPoint coverage, many companies aren’t being sued right away — they’re receiving demand letters first. These letters typically include screenshots of routine website functionality and a demand for payment to avoid litigation.

Texas AG to Businesses: Slow Down Before You Pay Up

Paxton’s message is straightforward: Some of these letters may be fraudulent, deceptive, or at least overstated. His office cautions businesses not to respond directly or make any payment without first consulting qualified counsel.

The alert also names Vivek Shah, a serial pro se litigant closely associated with the CIPA demand-letter wave. Shah has reportedly sent thousands of pre-litigation demand letters to businesses and nonprofits nationwide, alleging that common website technologies violate California law.

That campaign has hit a speed bump. In July 2026, a federal judge in the Central District of California declared Shah a vexatious litigant, requiring him to obtain court permission before filing new CIPA-related cases in that district.

The ruling gives businesses useful leverage, but it isn’t a complete shield. It applies only in that federal district and does not prevent Shah — or others — from sending demand letters or pursuing claims in other forums.

For Out-of-State Businesses, Jurisdiction May Be the First Question

For Texas businesses and other out-of-state companies, one threshold issue is whether a California court even has personal jurisdiction. A California resident’s visit to a company’s website does not automatically mean the company can be forced to litigate in California. Depending on the facts, jurisdictional defenses — or proactive declaratory judgment strategies — may be part of the response plan.

What Businesses Should Do Now

  • Don’t panic — but do not ignore the letter. The demand may be overstated, but CIPA website-tracking claims remain an active litigation risk.
  • Don’t pay or respond without counsel. The Texas AG specifically recommends seeking legal guidance before engaging with the sender or making any payment.
  • Review your website technologies. Work with counsel to evaluate cookies, pixels, analytics tools, chat widgets, search bars, and consent mechanisms.
  • Preserve your defenses. Evaluate whether the claims are legally viable, whether California has jurisdiction, and whether a proactive response strategy makes sense.
  • Report suspected abuse. If a letter appears fraudulent or deceptive, consider reporting it to the Texas Attorney General’s Consumer Protection Division.

The Bottom Line

The Texas AG’s alert is a helpful reality check for businesses caught in the CIPA demand-letter storm. It does not eliminate the risk, but it does reinforce an important point: A demand letter is not the same thing as liability. Businesses should use this moment to evaluate their website-tracking practices, confirm that consent and disclosures are appropriately calibrated, and develop a thoughtful response strategy before reacting to aggressive payment demands.

Listen to this post

For retailers, consumer brands, and digital commerce companies, text messaging has become a central part of the customer experience. The same consumer may receive promotional offers, loyalty updates, order confirmations, delivery notices, account alerts, and customer-service messages from the same brand, often through different platforms and vendors.

That makes a seemingly simple question increasingly complicated: When a customer replies “STOP,” what communications exactly have to stop?

A draft order circulated by the Federal Communications Commission (FCC) on September 9, 2026, could give businesses more flexibility in answering that question. The FCC is scheduled to consider the proposal at its upcoming September 30 open meeting.

If adopted substantially as proposed, the changes would allow businesses to distinguish among certain categories of informational communications when processing revocations and to establish a designated method for consumers to opt out. The proposal does not, however, create the same flexibility for marketing communications.

For consumer-facing businesses, the stakes extend well beyond TCPA compliance. The proposal raises questions about how brands classify customer communications, configure messaging platforms, manage third-party vendors, and translate a consumer’s preference across increasingly complex digital ecosystems.

“STOP” May Not Mean Stop Everything

One of the most significant proposed changes concerns the scope of a consumer’s revocation.

As adopted, the FCC’s 2024 rule treats a revocation made in response to one type of informational robocall or robotext as revoking consent to all future robocalls and robotexts from that caller, even on unrelated matters. The FCC has stayed that broader “revoke-all” application until January 31, 2027, while it weighs comments to its October 2025 Further Notice of Proposed Rulemaking on whether to modify the requirement. Under the stay, a business may already treat a revocation as applying only to the category to which the consumer responded, and the draft order now before the commission would make that narrower approach permanent rather than let the revoke-all requirement take effect.

For a retailer or consumer brand, that distinction matters. A customer who no longer wants one type of informational text, for example, may still want delivery updates, account-security notifications, customer-service communications, or messages relating to another transaction. Under the proposed approach, businesses would have greater ability to honor a consumer’s more limited choice without necessarily suppressing unrelated informational communications.

Promotional communications remain different. A consumer’s revocation of consent to receive a marketing or telemarketing message would continue to apply to future promotional calls or texts from that sender. That distinction makes message classification particularly important. Businesses should know not only what communications they send, but why they send them and how those communications are categorized for purposes of consent and revocation.

For companies operating sophisticated customer-engagement programs, that may require looking beyond the language of individual messages to the architecture behind them.

Businesses Could Designate the Opt-Out Channel

The draft order would also address another recurring TCPA issue: how a consumer can revoke consent. Under the existing framework, businesses generally must recognize revocations made through any reasonable method. In an omnichannel environment, that can create significant operational complexity. A consumer may interact with a company through SMS, a mobile application, a website, a customer-service center, social media, or another channel, while the systems responsible for processing TCPA consent may sit somewhere else entirely.

The FCC’s proposal would allow businesses to designate a particular method for revocation, provided that method is clearly disclosed. The designated mechanism could include an automated voice or keypad opt-out during a call, specified keywords in response to a text, or a dedicated telephone number or website established to process revocations. Businesses that do not designate a particular method would remain subject to the broader reasonable-method standard.

For retailers and digital commerce companies, a designated channel could create a more predictable and auditable opt-out process. Instead of attempting to identify and interpret potential revocations submitted across a variety of customer touchpoints, a company could direct consumers to a defined mechanism designed to capture and implement those requests.

But the legal ability to designate a channel does not eliminate the business considerations surrounding it. A company will still need to consider what happens when a customer tells a call-center representative to stop texting, complains through an app, or otherwise expresses a preference outside the formal mechanism. A process that satisfies the TCPA but creates friction for customers may present a different set of brand and customer-experience concerns.

The Technology May Be More Complicated Than the Rule

Even where the law allows more flexibility, the real challenge for many consumer-facing companies will be implementation. A single brand may use separate vendors and platforms for promotional SMS campaigns, loyalty programs, order notifications, customer support, authentication, and other communications. Consent information may reside in a customer-data platform, CRM, messaging vendor, e-commerce platform, or several systems at once.

The FCC proposal could make the legal rules more flexible, but taking advantage of that flexibility may require companies to understand whether their technology can actually support it. For example, can the company’s systems distinguish an opt-out from promotional messages from an opt-out affecting a particular category of informational communications? Can that preference be transmitted accurately among vendors? Can the company demonstrate when and how a revocation was received and implemented?

Those are not simply technical questions. In TCPA litigation, they can become evidence.

A Shorter Compliance Runway

Timing is another reason companies should pay attention now. The FCC previously extended the effective date of portions of its revocation requirements until January 31, 2027. The draft order would alter that timetable and make the revised requirements effective 30 days after publication in the Federal Register. Companies that have been working toward a January implementation date should therefore reassess their timelines.

Retailers, consumer brands, and digital commerce companies should consider reviewing:

  • The automated calls and texts currently being sent to consumers and the purpose of each;
  • How marketing, transactional, informational, loyalty, and customer-service communications are classified;
  • Where consent and revocation information is stored;
  • How opt-outs move across brands, business units, internal systems, and third-party vendors;
  • Whether establishing a designated revocation method would improve compliance and operational consistency;
  • How that method would be disclosed to consumers; and
  • Whether customer-service and escalation procedures align with the company’s technical opt-out process.

More Questions Are Coming

Beyond the changes it may adopt this month, the FCC is also seeking comment on several issues that could be particularly important for companies with sophisticated digital customer-engagement programs.

Among other things, the commission is considering whether to shorten the current 10-business-days period for implementing revocations, whether certain one-way texting platforms should support reply-based opt-outs, whether businesses should be required to provide a method for consumers to stop all robocalls and robotexts at once, and how revocations should operate across affiliates and business lines.

The last issue may be especially important for companies operating multiple brands, loyalty programs, websites, or affiliated businesses. A rule governing how consumer preferences travel across related entities could have consequences well beyond an individual SMS campaign.

The Takeaway for Consumer-Facing Businesses

The FCC’s proposal could ultimately give businesses more flexibility in managing TCPA revocations, particularly when consumers receive different categories of communications from the same company.

But flexibility is useful only if a company’s systems can support it. For retailers, consumer brands, and digital commerce companies, this is a good opportunity to examine TCPA compliance as part of the broader customer-engagement ecosystem. That means understanding not just whether a consumer consented, but which communications that consent supports, how preferences are captured, how those preferences move among systems and vendors, and whether the company’s operational practices match the distinctions the law permits.

For businesses that communicate with customers across multiple digital channels, the FCC’s proposal is therefore more than a change to an opt-out rule. It is another reason to understand how consumer consent actually works across the enterprise.

Listen to this post

For years, retailers have used data to understand what consumers want, when they want it, and how much they may be willing to pay. As artificial intelligence and increasingly sophisticated pricing tools make it possible to tailor prices at the individual level, the Federal Trade Commission (FTC) is signaling that the line between legitimate pricing strategy and unlawful consumer deception may turn on a deceptively simple question: What did the consumer know?

Specifically, the FTC has clearly stated: “Where consumers reasonably expect that prices for a product or service will not vary based on their personal data, businesses that engage in personalized pricing should clearly and conspicuously disclose not just that the price is personalized, but also the basis for that personalization and the types of data on which the personalization is based.”

On August 19, 2026, the FTC issued a proposed enforcement policy statement addressing personalized pricing — the use of personal data to set a price based on what a business believes a particular consumer is willing to spend. The proposal does not ban personalized pricing, create a new cause of action, or bind courts or businesses. It does, however, put retailers and other consumer-facing companies on notice that the FTC may treat undisclosed personalized pricing as an unfair or deceptive practice under Section 5 of the FTC Act.

The Commission approved publication of the proposal by a 2–0 vote. Public comments will be due 30 days after the statement appears in the Federal Register.

The Important Distinction: Dynamic Pricing Is Not Necessarily Personalized Pricing

Not every price change is personalized pricing. Dynamic pricing typically adjusts prices based on market-wide or transaction-specific conditions, such as supply and demand, time of day, inventory, seasonality, delivery distance, or driver availability. Airlines, hotels, rideshare companies, and retailers have used versions of dynamic pricing for decades.

Personalized pricing, by contrast, uses information about a particular consumer — such as browsing history, purchase patterns, location, device information, household characteristics, or inferred income — to estimate that consumer’s willingness to pay. In the FTC’s framing, the concern is not merely that two consumers may pay different prices. It is that a business may silently use information that is personal to each consumer to decide how much each will be charged.

That distinction should be central to any retailer’s compliance analysis. A price that rises for everyone because demand spikes is materially different from a price that rises only for a consumer whose data suggests urgency, limited alternatives, willingness to pay more, or a reduced likelihood of comparison shopping.

The FTC’s Theory Under Section 5

The FTC candidly acknowledges that Congress has not authorized it to prohibit personalized pricing in all circumstances. Instead, the agency relies on its existing authority over unfair or deceptive acts or practices.

Deception – The proposed statement reasons that consumers generally expect a listed retail price to be the same price offered to other consumers shopping at the same place and time. A retailer may therefore mislead consumers if it expressly or implicitly represents that a price is static or broadly available when the price has, in fact, been personalized. The FTC also views the omission as potentially material because a consumer who knows the price is personalized could comparison shop, use private browsing or a virtual private network, choose a different retailer, or decline the transaction.

Unfairness – The FTC separately suggests that an undisclosed higher personalized price may cause substantial injury that consumers cannot reasonably avoid. According to the proposal, any legitimate benefits of personalization could still be achieved without concealing that personalization. Whether that reasoning will withstand scrutiny in a particular enforcement action will depend on the evidence, including actual consumer injury, reasonable avoidability, and countervailing benefits to consumers or competition.

In plain terms, the FTC’s concern is transparency. If shoppers are led to believe a price is generally available, but it has actually been tailored to them using personal data, the retailer may face Section 5 risk. The key point: Consumers need to know when personalization is affecting the price so they can comparison shop, use privacy tools, choose another retailer, or walk away.

The agency also connects pricing practices to data privacy. Collecting, using, or disclosing personal data for personalized pricing without adequate notice or consent — or without verifying that the consumer consented to the data’s collection for that purpose — may present a separate Section 5 risk.

What Would the FTC Expect Retailers to Disclose?

Where consumers reasonably expect a generally available price, the FTC says a disclosure should be clear and conspicuous and explain:

  • The fact of personalization – The consumer should be told that the displayed price is personalized.
  • The basis for personalization – The disclosure should explain why or how the price was personalized.
  • The types of data used – The consumer should understand what categories of personal information influenced the price.

A vague statement that a consumer has received a “specially selected” price likely would not satisfy the FTC. The agency instead offers as potentially sufficient a complete and accurate disclosure that a price reflects the consumer’s estimated willingness to pay, derived from prior purchases made through the same account.

The proposal stops short of prescribing specific language, placement, timing, or formatting. Those unresolved details matter. Retailers considering disclosures should evaluate whether consumers will encounter them before the pricing information affects their shopping decisions — not only at checkout after the consumer has invested time in the transaction.

The FTC’s Examples Show Where It Sees the Greatest Risk

The proposed statement identifies several nonexclusive scenarios that the agency believes could raise Section 5 concerns if not adequately disclosed, including:

  • Urgency or vulnerability – Higher prices based on data suggesting that a consumer cannot leave home, is traveling for a funeral, needs emergency medical transportation, or was recently the victim of a crime.
  • Household characteristics – A higher grocery-delivery price for milk because data indicates that children live in the household.
  • Reduced competition – A rideshare company charging more because the consumer does not have a competitor’s app installed.
  • Real-time location – A retailer increasing an online price because the consumer is currently inside the retailer’s store or parking lot.

These examples are intentionally provocative, but they illustrate the broader enforcement principle: Using intimate, sensitive, or situational data to exploit a consumer’s perceived lack of alternatives is more likely to draw scrutiny than a conventional discount or a market-wide price adjustment.

The Risk Extends Beyond the FTC

The federal proposal arrives against a rapidly changing state backdrop. New York already requires disclosure when a price is set by an algorithm using personal data. Maryland and New Jersey have enacted grocery-focused restrictions, while Connecticut requires an explicit consumer-facing notice when personal data increases a price. Additional bills are pending across the country, and state attorneys general can investigate pricing practices under broad state consumer-protection statutes even without a law specifically addressing personalized pricing.

For retailers, this creates at least three layers of exposure: regulatory inquiries, enforcement under federal or state consumer-protection and privacy laws, and follow-on private litigation. A regulator’s inquiry letter, public report, or settlement can quickly become the roadmap for a putative consumer class action alleging deceptive pricing, undisclosed data use, or economic injury.

Pricing vendors create another potential fault line. A retailer may not design the algorithm or possess every data input, but regulators and private plaintiffs are unlikely to accept “the vendor did it” as a complete defense. Companies should understand what data their tools ingest, where it comes from, whether it is shared across customers or competitors, and whether the vendor’s descriptions of the product match its actual operation.

What Retailers Should Do Now

The policy statement remains a proposal, and its final form may change. Still, retailers should not wait for an investigation to understand their own pricing systems. The FTC has clearly stated that this will be an enforcement priority.

As such, some practical steps that companies can begin to consider include:

  • Inventory pricing practices across channels – Identify where prices, fees, discounts, promotions, loyalty benefits, delivery charges, and product recommendations can vary by user, account, device, location, or customer segment.
  • Map the data inputs – Determine whether pricing tools use individual-level data, inferred characteristics, third-party data, or sensitive information — and distinguish those inputs from aggregate market signals.
  • Audit vendor relationships – Review technical documentation, data rights, audit rights, indemnification, regulatory-cooperation provisions, and restrictions on cross-client or competitor data.
  • Pressure-test disclosures – Assess whether existing notices accurately and prominently explain the fact, basis, and data inputs of personalization before the consumer makes a purchasing decision.
  • Examine consent and privacy representations – Confirm that actual data uses align with privacy notices, consumer consents, loyalty-program terms, and applicable state privacy requirements.
  • Test for unintended outcomes – Evaluate whether algorithms rely on proxies for protected characteristics or disproportionately raise prices for vulnerable consumers.
  • Document legitimate business reasons – Preserve contemporaneous records explaining pricing differentials, market-based inputs, testing, human oversight, and the company’s efforts to avoid consumer harm.
  • Prepare for inquiries and litigation – Establish ownership across legal, privacy, marketing, pricing, and technology teams, and preserve a defensible record before a regulator or plaintiff asks for it.

The bottom line: Personalized pricing is not off limits, but undisclosed personalization is becoming harder to defend. Retailers that understand how their pricing tools work, disclose personalization clearly, and align pricing practices with privacy promises will be better positioned as regulators, lawmakers, and plaintiffs’ lawyers continue to focus on this issue.

Listen to this post

Demand letters and copycat lawsuits are piling up on the desks of in-house counsel and business owners around the country, all making the same claim: that an ordinary website is secretly running an illegal wiretap. We’ve watched California Invasion of Privacy Act (CIPA) claims climb sharply over the past several months. The playbook is easy to spot. A small group of repeat claimants combs through business websites, records what data each site hands off to outside vendors, and then sends a formal-looking package threatening suit in California. Any website a California visitor can open is a potential target. Size, industry, and where you’re headquartered don’t matter much. If a letter hasn’t shown up yet, don’t assume it won’t. We’re following this closely and defending clients against it right now, and we’d rather you be ready than caught flat.

What Is CIPA, and Why Is It Showing Up on Your Website?

CIPA goes back to 1967, when the worry was wiretapped phones and surveillance. Plaintiffs have repurposed it for the web, and lately for AI-driven tools, arguing that pulling a visitor’s IP address and browsing data off a site without consent is the modern equivalent of that same unlawful interception. The features they go after are the ones almost every site uses: third-party pixels, software development kits (SDKs), analytics, chat windows, and search boxes.

The money is what keeps the letters coming. CIPA gives plaintiffs a private right of action, statutory damages of up to $5,000 per violation or treble the actual damages (whichever is larger), and a shot at an injunction on top. That has made it the statute of choice for website-tracking claims, and plaintiffs are pushing it hard while the courts are still deciding whether it fits the technology at all.

Right now the law is unresolved, and the courthouse often matters more than the facts. Federal judges in California have been readier than their state counterparts to let these claims survive a motion to dismiss, though a plaintiff in federal court still has to clear a standing hurdle the state courts don’t bother with. The Legislature hasn’t stepped in, so the answers are coming one case at a time. Two companies running identical tracking can land before two judges and walk out with opposite results.

Most claims run on one of two theories. The first is wiretapping under Section 631(a): intercepting the contents of a visitor’s communication in transit, without consent. Those “contents” are usually search queries carrying personal information or the give-and-take of a chat, which is why chat tools, session-replay software, and embedded third-party scripts draw most of the fire. But data moving from A to B doesn’t automatically make an interception. A court might decide that reaching stored or copied data isn’t “interception” at all, or that no one ever showed the vendor actually read what it got.

The second theory leans on CIPA’s pen-register and trap-and-trace provisions, Sections 638.50 and 638.51. The complaint there isn’t about the contents of the visit but the record of it: timestamps, add-to-cart events, clicks, scrolling, cursor movement. The problem is that the line between “contents” and a “record” is blurry, and courts have drawn the line in opposite places.

On the pen-register theory the divide runs even deeper, all the way down to whether the statute touches the internet at all. California’s state courts largely say it doesn’t, reading these provisions as being about telephones. Federal courts have gone the other way.

Standing is the other pressure point. A federal plaintiff has to plead a concrete, particularized injury, not just a technical statutory violation. Collect sensitive information without consent — say health conditions, financial details, or personal identifiers — and the injury usually clears that bar. Collect nothing but routine technical data and the claim is far more likely to be dismissed. The same sensitivity requirement usually sinks the tag-along common-law claims for invasion of privacy and intrusion upon seclusion, which need a “highly offensive” intrusion involving sensitive or confidential information.

CIPA rarely travels alone. Plaintiffs often tack on a claim under the California Comprehensive Computer Data Access and Fraud Act (CDAFA), Cal. Penal Code § 502, which makes it illegal to knowingly access, use, or interfere with computers, networks, or data without permission and carries statutory damages and attorneys’ fees. Knowledge is usually where these claims live or die. From there, plaintiffs will often repackage the alleged CDAFA violation as an “unlawful” business practice under California’s Unfair Competition Law (UCL), reaching for an injunction on top of the damages.

What These Demands Look Like

The letters are hitting companies of every size and industry, most with no real tie to California beyond a website a resident there can open. A handful of repeat claimants are behind most of them, and they tend to look alike:

  • They do their homework first. By the time a letter arrives, the sender has usually already been through your site and logged what it hands off to third-party vendors.
  • It’s dressed up as a lawsuit. Expect a formal package: a cover letter, a draft complaint, and screenshots that supposedly capture the data transfer.
  • The numbers add up fast. At $5,000 per violation (or three times actual damages), a demand can reach the tens of thousands without anyone proving actual harm.
  • It’s not only about money. Senders frequently want the challenged technology pulled off the site, too.

Why This Should Be on Your Radar

  • A form letter is still a real threat. Most of these are churned out from a template, but templated doesn’t mean toothless. Ignoring one is a mistake and so is paying just to make it disappear without legal advice.
  • There’s a class action hiding behind the single demand. The theory reaches every visitor who loaded the site from California, so one letter can be the opening move in a much bigger class claim.
  • The facts drive everything. An out-of-state business may have a real argument that a California court can’t hear the case in the first place.
  • Don’t touch the site before you preserve it. Rushing to change things the moment a letter lands, before you’ve documented how the site was set up, can look like you destroyed evidence even when that was the last thing on your mind.

If a Demand Letter Arrives, Here Is What to Do

Two things not to do: Don’t answer the sender yourself, and don’t change the website until its current state is locked down. Beyond that:

  • Get it to counsel. Send it over right away and calendar every deadline the letter mentions.
  • Preserve the site. Capture it exactly as it stands now, including source code, tag manager and analytics settings, consent-tool configuration, privacy policy, and vendor agreements before anyone starts making changes.
  • Size up the exposure. Have counsel test what the letter claims against how the site actually works before you decide how to answer.
  • Then fix the root cause. Once the immediate demand is handled, sit down with counsel and your website or marketing team to review the tracking setup and clean it up where needed, so no one can run the same theory at you again.
Listen to this post

A year ago, Congress put online platforms on the clock. On May 19, 2025, President Trump signed the Take It Down Act into law, creating a new federal framework aimed at stopping the online spread of nonconsensual intimate imagery, such as real images, AI-generated “deepfakes,” and other harmful content circulated across websites, social-media platforms, messaging tools, and even video games. The act does two things: It creates criminal liability for knowingly publishing certain nonconsensual intimate imagery (NCII for short), and it requires covered online platforms to maintain a notice-and-removal process for takedown requests. The criminal provisions took effect immediately, and the platform obligations, enforced by the Federal Trade Commission, came with a one-year runway.

That runway has now ended. On May 19, 2026, the notice-and-removal requirements took effect, and the FTC announced it had begun enforcement. The agency immediately sent warning letters to several unnamed platforms for possible violations — consistent with Chairman Andrew Ferguson’s earlier calls for major platforms, including Amazon, Alphabet, Meta, TikTok, and X, to establish the required systems and procedures and his warning that the FTC would “vigorously enforce” the act.

This post explains who is covered, what the act requires, how the FTC may enforce it, and what practical risks platforms should address now. Given the FTC’s prompt enforcement of this law, companies should pay close attention to who and what the act covers, how certain terms are defined, and what the FTC is focused on from an enforcement perspective.

The Take It Down Act: A Brief Overview

The Take It Down Act covers (1) any person who knowingly publishes or threatens to publish certain kinds of NCII using an interactive computer service, and (2) “covered platforms” (a defined term that is explained in more detail below).

Individuals: Criminal Liability for Publication of NCII

For authentic “intimate visual depictions” of identifiable adults, the government must prove that (i) the defendant knowingly published the depiction, (ii) the defendant knew, or under the circumstances should have known, that the identifiable individual being depicted had a reasonable expectation of privacy, (iii) what was depicted was not a matter of public concern, (iv) what was depicted was not voluntarily exposed by the identifiable individual in either a public or commercial setting, and (v) the defendant’s publication caused or was intended to cause harm, including psychological, financial, or reputational harm.

Although these elements are nuanced and merit close analysis, it is important to note that the law does not prohibit the publication of every image a person would rather keep private. For example, an “intimate visual depiction” is defined by refence to certain types of nudity or sexual content, under which an ordinary swimsuit photo would likely not qualify. Other elements narrow the offense further. For example, the prohibited content cannot be something the depicted person had at some point voluntarily displayed in public. A key point for companies is that the question of whether content crosses the line may be something that is highly fact-specific or legally uncertain.

For “digital forgeries” (e.g., AI-generated images), the requirements are almost identical. Digital forgeries are defined as (i) “any intimate visual depiction of an identifiable individual created” using “computer-generated or technological means” (including AI) (ii) that are “indistinguishable from an authentic visual depiction” to a reasonable viewer. For digital forgeries, instead of a reasonable expectation of privacy, the government must prove that the forgery was published without the consent of the individual being depicted.

Minors get special protection. For depictions of minors, authentic or forged, the government need only prove (i) knowing publication and (ii) the intent to (a) abuse, humiliate, harass, or degrade or (b) arouse or gratify someone’s sexual desire.

The act also prohibits making threats to engage in any of the above-described conduct for the purpose of intimidation, coercion, extortion, or to create mental distress.

And anyone who violates any of these prohibitions may be punished, fined, imprisoned, or subjected to forfeiture or restitution.

“Covered Platforms”: Notice and Removal Obligations

Who is covered? The second part of the act applies to “covered platforms.” As defined, these are online services, applications, websites and mobile applications that (a) “serve[] the public” and (b) either (i) “primarily provide[] a forum for use-generated content” or (ii) in the regular course of business “publish, curate, host, or make available content of nonconsensual intimate visual depictions.”

The act contains a notable carveout, however, that excludes certain services, applications, or websites even if they have chat, comment, or interactive functionality. For it to apply, (a) the functionality must be “incidental to, directly related to, or dependent on” providing non-user-generated, preselected content and (b) the relevant service, application, or website must “consist[] primarily” of that kind of content. The carveout does not apply, however, to platforms that “publish, curate, host, or make available” NCII content  “in the regular course of” their business.

In short, the act is largely aimed at social-media platforms and other kinds of apps and websites or services with similar functionalities, like image and video sharing. But who specifically is covered may turn on challenging questions, like which features are “incidental” or what the “primary” type of content on an app is. Therefore, any company that provides a service, application or website to the general public that can be used to send or receive content should carefully assess whether they are covered by the act.

What must “covered platforms” do? Covered platforms must have a notice-and-removal process that (a) allows individuals (or someone acting on their behalf) to notify platforms that they are hosting NCII and (b) allows them to request that it be removed. Platforms must provide users with clear-and-conspicuous notice of this functionality in easy-to-read, plain language. And once a valid removal request is received, platforms must remove the content within 48 hours and make reasonable efforts to identify and remove known identical copies.

The act requires that requests to take down NCII include (i) a physical or electronic signature, (ii) sufficient information to locate the NCII, (iii) a brief statement of the requester’s good-faith belief that the depiction was not consensual, and (iv) the requester’s contact information.

The act gives platforms a safe harbor that precludes them from liability for removing material in good faith and based on facts or circumstances from which it seems apparent that the content was NCII. This safe harbor applies even if it is later determined that the reported material that was taken down was not NCII and was published legally.

What is the enforcement regime? The act empowers the FTC to enforce the notice-and-removal regime (including against nonprofits that would otherwise exceed its jurisdiction). A violation of the act’s notice-and-removal requirements is considered an unfair or deceptive act or practice that also violates Section 5 of the FTC Act. As a result, the FTC may impose civil penalties in addition to seeking equitable relief, such as restitution, disgorgement, injunctions, bans, and the imposition of mandatory remediation and compliance programs.  

Anticipated Challenges and Potential Risks

Critics of the act have raised significant First Amendment concerns. The 48-hour takedown deadline is short, and the act incentivizes platforms to remove content. Platforms face liability if they fail to take down unlawful material fast enough, while they also are granted a safe harbor that may protect them from liability if they remove lawful content. In the eyes of critics, the incentive is to over remove content, potentially sweeping in lawful and protected speech, such as satire, art, journalism, and political commentary.

There are also questions about scope and definitional ambiguity in the act. Services that primarily host original content but have comment, chat, or messaging features, services that aggregate or curate user content without hosting it, and emerging generative-AI tools that produce (rather than merely host) imagery all must consider potential risk under the act.

Open Questions for Businesses with Limited Social Features

All websites and apps that let users communicate must ask themselves (or their counsel) whether they are covered by the act. The above-mentioned questions about the act’s scope have real-world implications that extend beyond companies that identify as legacy social-media platforms. For example, businesses of all kinds frequently incorporate “social-media-lite” features into their products and services — for example, letting users share comments, videos, or photos. Consider a fitness app that hosts an online forum for members to share workout photos. Or a supplement brand that lets customers post before-and-after shots. In either situation, if it’s possible for a user to upload a nude photo of someone without their consent, there may be a real question of whether the company must implement a notice-and-removal system.

Until the act starts to be interpreted and applied, many of these legal questions will remain open — like how to determine what a website’s “primary” kind of content is, especially when apps and websites host all sorts of content, some user-generated and some intermixed with material created or selected by the companies themselves. Likewise, which features in an integrated product are considered “incidental”? Answers to these and similar questions will start to be clarified by the FTC and by courts, but the process will take time.

For now, uncertainty creates risk. Companies operating on the internet or in the app store cannot assume that they fall outside of the act, as an incorrect assumption means exposure to enforcement and the specter of large civil penalties. Instead, a prudent approach is for companies to carefully analyze their business, including by (1) thoughtfully identifying each and every product and feature that might let users share visual content, (2) assessing whether businesses qualify as “covered platforms” under the sometimes complex provisions of the act, and (3) if the answer is unclear, considering whether to adopt notice-and-removal processes to mitigate risk. Companies should consult counsel rather than assume the act is irrelevant to them.

Moreover, the act does not exist in a vacuum. It sits alongside, and in some places overlaps with, an existing patchwork of state NCII laws, Section 230 of the Communications Act of 1934, the Digital Millennium Copyright Act, and private civil remedies that could exist, including under 15 U.S.C. § 6851. In particular, companies that may have grown comfortable relying on the protections of Section 230 may nevertheless risk liability under the Take It Down Act due to hosting user content.

Key Takeaways

For platforms that host or enable user-generated content, the first question is coverage. Companies should assess each product or service — not just the overall business — to determine whether it qualifies as a “covered platform.”

If the act applies (or might apply), the next question is operational readiness. Platforms need a clear, easy-to-find, plain-language process that allows individuals — or someone acting for them — to report NCII and request removal. They also need internal workflows capable of meeting the 48-hour deadline, including after hours and on weekends, as well as procedures for identifying and removing known identical copies. Even if platforms already operate mature trust-and-safety programs, they will need to revisit whether their existing processes satisfy the act.

Finally, documentation matters. The act’s safe harbor may protect good-faith removals, but platforms should be able to show what they received, what they did, when they did it, and why. Strong records of requests, decisions, timing, and rationale will be critical if months or years later the FTC or a federal judge asks how a platform handled a takedown request.

Listen to this post

As in years past, the government continued its efforts to combat cybersecurity threats utilizing the False Claims Act (FCA). Overall, 2025 saw the highest FCA recoveries amount to date — over $6.8 billion in recoveries were awarded. With the ongoing Civil Cyber-Fraud Initiative, the focus remained on companies’ noncompliance with cybersecurity controls and allegations of knowledge of failed security requirements. As the Civil Cyber-Fraud Initiative moves into its fifth year, all federal contractors should remain mindful of federal cybersecurity requirements. To keep you apprised of the current enforcement trends and the status of the law, Bradley’s Government Enforcement and Investigations Practice Group is pleased to present the False Claims Act: 2025 Year in Review, our 14th annual review of significant FCA cases, developments, and trends.

Listen to this post

Florida lawmakers are once again weighing whether to provide litigation protections to companies that invest in meaningful cybersecurity safeguards. A revised proposal now pending before the Florida Legislature seeks to strike a balance between encouraging proactive data security measures and preserving consumer remedies following a breach. Data incidents are commonly met with class action lawsuits filed on behalf of individuals alleging harm stemming from the unauthorized access, acquisition, or exposure of personal information. As a result, what begins as a criminal act against a business often evolves into a complex web of regulatory, reputational, and litigation challenges.

A cyber incident, in and of itself, is not necessarily evidence of a breach of a duty to safeguard data. The unfortunate reality of our modern age means extremely secure entities may still be breached due to the evolving techniques of adversaries, both foreign and domestic. Even so, companies that experience cybersecurity incidents are often met with a wave of class action lawsuits in the aftermath. These complaints frequently rely on broadly framed allegations that the organization failed to implement or maintain “reasonable” data security measures, often without regard to the specific safeguards that were in place or the evolving nature of cyber threats.

Prompted by the escalating cost of these class action data breach litigations and the numerous headline-grabbing cyberattacks, particularly those in the healthcare industry, the Florida Legislature is once again pushing for cyber litigation reform that raises the liability standard for class action lawsuits arising from cybersecurity events.

The 2024 Effort and Its Veto

In 2024, the Florida Legislature passed House Bill 473, a measure designed to provide litigation protections to companies that suffer data breaches despite maintaining robust cybersecurity programs. The bill conditioned immunity on two primary requirements: compliance with Florida’s data breach notification law and implementation of a cybersecurity program aligned with recognized industry frameworks or legal standards.

The legislation was intended to address the growing wave of class action lawsuits filed in the wake of data incidents — many of which allege technical statutory violations even where companies have acted in good faith and maintained reasonable security controls. Proponents argued that offering a litigation presumption in favor of compliant businesses would incentivize stronger cybersecurity practices while helping mitigate the mounting costs of opportunistic breach litigation.

Although the Legislature approved the bill in March 2024, Gov. Ron DeSantis vetoed it. In his veto message, the governor expressed concern that the proposed immunity could limit meaningful recourse for consumers harmed by data breaches. He encouraged stakeholders to continue working with the Florida Cybersecurity Advisory Council to develop a framework that protects both businesses and consumers. See our previous blog on House Bill 473 here.

Senate Bill 635: A More Targeted Approach

Two years later, lawmakers have returned with Senate Bill 635, a revised version that attempts to address the concerns raised in 2024 while preserving incentives for cybersecurity investment. Like its predecessor, SB 635 would provide a presumption against liability in certain class action lawsuits arising from cybersecurity incidents. However, the scope of the protection has been narrowed, and the standards have been heightened.

Key provisions include:

  • Substantial Compliance Standard – Defendants must demonstrate “substantial compliance” — not merely “substantial alignment” — with standardized cybersecurity frameworks, such as from the National Institute of Standards and Technology (NIST), the Center for Internet Security (CIS) Critical Security Controls, ISO/IEC 27000, HITRUST CSF, SOC 2 Type 2, and/or other similar industry frameworks or standards.
  • Limited to Class Actions – The presumption applies only to class action lawsuits. Individual plaintiffs would retain the ability to pursue damages, and the presumption would not apply in those individual cases.
  • Government-Specific Requirements – Government entities must maintain a disaster recovery plan to qualify for the presumption.
  • Defined Personal Information – The bill includes a specific definition of “personal information,” clarifying the scope of covered incidents.

Under SB 635, private businesses and their third-party agents would be entitled to a presumption against liability in class action litigation if they substantially comply with the Florida Information Protection Act and implement cybersecurity policies consistent with recognized frameworks. The law aims to incentivize better, documented security practices rather than just penalizing breaches after they occur. 

The bill also includes provisions offering complete liability protection to local governments in certain circumstances and restricts local governments from imposing heightened cybersecurity standards on IT vendors beyond those imposed on the governmental entity itself, subject to limited exceptions.

Current Status and Implications

On February 11, 2026, the Senate Committee on Governmental Oversight and Accountability advanced SB 635. The bill now awaits consideration by the Appropriations Committee. If enacted, the legislation could alter the cybersecurity litigation landscape in Florida. Supporters contend it would reduce cyber liability insurance costs, encourage stronger adherence to established security frameworks, and decrease the volume of class action litigation following data incidents.

As cyber incidents remain a persistent operational risk across industries, Florida’s renewed effort reflects a broader national debate: how to encourage meaningful cybersecurity investment without insulating companies from accountability. The outcome of SB 635 may signal how far states are willing to go in recalibrating that balance.

Listen to this post

Retailers. Banks. Healthcare systems. E-commerce platforms. Across industries, live chat, session replay software, and website analytics have become standard tools for customer engagement. These technologies help businesses respond to consumer inquiries in real time, improve website functionality, reduce cart abandonment, train customer service teams, and resolve disputes.

For companies operating nationally, the landscape is shifting quickly. Most businesses are already familiar with litigation under California’s Invasion of Privacy Act (CIPA), which has become one of the highest per-violation risk statutes in the country for website-based claims. Florida is now emerging as a growing and unsettled litigation front under its own wiretapping statute, and other states are watching closely. From a compliance standpoint, businesses should treat Florida website disclosures and consent mechanisms with the same seriousness they now apply in response to CIPA, recognizing that proactive risk mitigation is far less costly than defending statutory damages claims after the fact.

The Florida Security of Communications Act

In Florida, these commonplace tools are increasingly being challenged under a statute enacted in 1969 — long before the internet existed. The Florida Security of Communications Act (FSCA), codified in Chapter 934 of the Florida Statutes, prohibits the intentional interception of “wire, oral, or electronic communications” without the prior consent of all parties. Florida is a two-party consent state. The statute was designed to prevent covert surveillance: hidden tape recorders, wiretapped phone lines, and unauthorized eavesdropping. It was not drafted with website analytics, customer service chatbots, or session replay software in mind. Yet plaintiffs’ attorneys have filed hundreds of lawsuits alleging that modern website technologies violate the FSCA by “intercepting” communications between website visitors and businesses.

How Standard Website Tools Became Litigation Targets

1. Live Chat Recording

Live chat features, often recorded for quality assurance, dispute resolution, compliance monitoring, or AI training, are now being characterized as unlawful electronic interceptions when prior express consent is not allegedly obtained. Plaintiffs argue that a website visitor engaging in live chat is engaged in an “electronic communication,” and recording or storing that chat without explicit consent violates the FSCA.

2. Session Replay Software

Session replay tools capture user interactions such as mouse movements, scrolls, clicks, and form entries. Businesses use this data to identify technical problems and improve user experience. The litigation theory asserts that these tools intercept communications between the visitor and the website itself.

3. Analytics and Tracking Tools

Standard analytics platforms that track navigation patterns, page views, and site interaction have likewise been targeted. Plaintiffs argue that tracking how a visitor interacts with a site constitutes interception of electronic communications, particularly where there is no explicit, real-time consent mechanism.

The Litigation Pattern

These cases follow a familiar pattern seen in ADA, TCPA, CIPA, and biometric privacy litigation:

  • Nearly identical complaints filed by a small number of firms
  • Heavy reliance on statutory damages
  • Minimal allegations of concrete consumer harm
  • Settlement demands calibrated below the cost of full defense

Under the FSCA, statutory damages may be awarded at $1,000 per violation or $100 per day, whichever is greater, along with attorneys’ fees. In a class context involving thousands of website users, the theoretical exposure can escalate rapidly. Even in individual cases, fee-shifting risk alone can drive significant settlement pressure. Adding to the uncertainty, many cases resolve before courts issue definitive rulings. Where courts have addressed these issues, results have been mixed. Some have dismissed claims where disclosures were deemed sufficient. Others have allowed cases to proceed past the pleading stage. This lack of uniformity is precisely what fuels ongoing filings.

Why Privacy Policies Alone May Not Be Enough

Many businesses assume that general privacy policy disclosures provide sufficient protection. That assumption is increasingly being tested. Plaintiffs argue that buried privacy policy language stating that a business “may collect website usage data” or “may record customer service interactions” does not constitute the “prior consent of all parties” required under Florida’s two-party consent framework. Whether passive website disclosures satisfy statutory consent requirements remains an unsettled legal question. Until appellate clarity emerges, or the Legislature acts, businesses face continued litigation risk.

Industries Being Targeted

The defendants in these suits are not engaging in covert surveillance. They are using standard commercial website tools. Industries increasingly targeted include:

  • Online retailers using session replay to optimize checkout
  • Banks and financial services firms improving digital banking interfaces
  • Healthcare providers offering appointment scheduling and inquiry chats
  • SaaS and technology companies tracking user interaction

The common denominator is meaningful website traffic combined with routine data collection tools.

The Broader Trend

Florida’s website wiretapping litigation reflects a broader national trend: Legacy statutes drafted for analog surveillance are being applied to digital commerce. Until appellate courts provide consistent guidance or legislative clarification narrows the scope of the FSCA in the website context, consumer-facing businesses must operate in a legally unsettled environment.

Live chat and analytics tools are not fringe technologies. They are central to modern customer engagement. But in Florida, businesses deploying them should do so thoughtfully, with an understanding that yesterday’s wiretapping statute is today’s website litigation vehicle.

While no compliance strategy eliminates risk entirely, proactive steps can materially reduce exposure. Businesses should (1) audit the use of website technology, including evaluating the business necessity or value of certain technology; (2) implement categorization, notice, and consent mechanisms to manage website technology; (3) review website privacy notices and related terms of use; and (4) review vendor agreements with website technology providers; and (5) evaluate change control processes for the implementation of technology that pose risk under the FSCA.

An ounce of prevention is (still) worth a pound of cure.

Listen to this post

Age Verification Compliance Obligations

Age verification requirements have rapidly moved from a niche policy concept to a central feature of the U.S. regulatory landscape. Over the last two years, and accelerating sharply in 2025, states have increasingly adopted laws that require online services to confirm a user’s age before allowing access to certain types of content or platform features. What began as a targeted effort to restrict minors’ access to sexually explicit material is now expanding into broader regulation of social media platforms, account creation, and even algorithm-driven feeds.

For companies operating online, this shift creates a familiar modern compliance challenge: a fast-growing patchwork of state laws with inconsistent requirements, evolving definitions, and uncertain enforcement outcomes driven by ongoing constitutional litigation.

Age Verification Goes Mainstream

By 2025, age verification had crossed a critical threshold. Roughly half of U.S. states now mandate some form of age gating for adult content or social media access, and additional laws are expected to take effect in 2026. The practical result is that companies can no longer treat age verification as a niche issue limited to a handful of jurisdictions. For many businesses, it has become an operational reality with immediate implications.

This trend reflects broader legislative momentum around children’s privacy and online safety. State lawmakers have increasingly focused on perceived harms to minors online, including exposure to inappropriate content, excessive social media use, and the design features that encourage prolonged engagement.

The Texas Model and the First Amendment Framework

A key development driving legislative confidence in this space stems from litigation over Texas H.B. 1181, enacted in 2023. That law requires certain commercial websites that publish sexually explicit content deemed obscene to minors to verify that visitors are at least 18 years old. Industry representatives challenged the statute as unconstitutional under the First Amendment, arguing that adults have a right to access lawful content without being forced to identify themselves or pass through an age gate.  The U.S. Supreme Court upheld Texas’s age-verification statute, H.B. 1181, in Free Speech Coalition v. Paxton (June 2025). The Court concluded that Texas may require certain websites featuring substantial sexually explicit content to verify that users are adults before granting access. Applying intermediate scrutiny, the Court determined the law permissibly advances the state’s interest in shielding minors from inappropriate material and does not create a First Amendment entitlement for adults to access that content without confirming age.

Practical and Privacy Consequences for Users

Age gates often require users to provide personal information, interact with third-party verification tools, or submit identification credentials. This can deter lawful adult access, reduce anonymity, and create friction that changes consumer behavior. Some individuals may be blocked entirely, including those who lack government-issued identification or are incorrectly flagged by automated systems.

Age-verification age gates can create significant privacy and cybersecurity risk because they often require users to submit sensitive personal information — such as date of birth, government ID credentials, or biometric verification — frequently through third-party tools. That process reduces user anonymity and can generate records linking individuals to particular categories of online activity, which may be highly sensitive. From a security standpoint, collecting and transmitting identity data expands the company’s attack surface and increases exposure if systems or vendors are compromised, since ID images and related verification data are high-value targets for fraud, identity theft, and extortion. Even when implemented with good intentions, age verification can therefore introduce new compliance and incident-response risks if businesses do not tightly control vendor access, data minimization, retention, and security safeguards.

The Expansion to Social Media: Parental Consent and Account Restrictions

In 2025, lawmakers increasingly moved beyond adult content and began targeting minors’ social media usage. Multiple states passed laws that require platforms to verify age and obtain parental consent before allowing minors to create accounts or access certain services. Some proposals focus on younger children, while others extend restrictions to anyone under age 18.

In total, eight states have enacted laws that either ban minors from obtaining social media accounts outright and/or require parental consent for certain minors to open accounts. During the 2025 legislative session alone, nearly 30 bills were introduced across 18 states attempting to impose similar restrictions.

These laws vary widely in scope, age thresholds, definitions of covered platforms, and enforcement mechanisms. For companies operating nationwide, that inconsistency is a major compliance obstacle. A product design and onboarding process that works in one state may be noncompliant in another.

Regulating Design and “Addictive” Features

A related legislative trend involves targeting features viewed as designed to increase usage among minors. In 2024, California and New York pioneered efforts to regulate “addictive algorithms” by restricting the delivery of certain feeds or engagement-driven features to minor accounts without parental consent. Some states followed with their own versions of “addictive feed” legislation in 2025, with varying levels of success.

These efforts represent an important shift. Rather than regulating only what content minors can access, lawmakers are increasingly attempting to regulate how platforms deliver content and how digital products are designed to keep users engaged.

For companies, these proposals can implicate product design decisions, internal testing, algorithmic ranking systems, and even liability theories tied to youth mental health. Even where laws are challenged or delayed, the legislative intent is clear: Design-based regulation is likely to remain on the table.

Practical Takeaways

For companies navigating this landscape, the challenge is not only meeting legal requirements, but it is building a program that can adapt quickly as laws change and court decisions reshape what is enforceable.

Key steps include:

  • Inventory applicable state requirements. Companies should map where their users are located and which laws may apply based on access and operations.
  • Assess verification tools with privacy and security in mind. Age verification solutions can create significant data risk if they involve collection, storage, or third-party processing of identity information.
  • Prepare for rapid legal shifts. Many laws are being challenged, modified, or replaced, meaning compliance strategies must be designed for change rather than permanence.
  • Coordinate across legal, privacy, cybersecurity, and product teams. Age verification impacts product architecture, user experience, and security posture — not just legal risk.
  • Document decisions and risk tradeoffs. Given uncertainty and evolving standards, maintaining a record of compliance reasoning and design choices can be valuable for regulatory inquiries and litigation defense.

Companies should expect continued state activity in 2026 and beyond and should plan now for a future in which age verification, youth safety compliance, and platform design restrictions remain central issues for online business.

Listen to this post

In 2026, a wide range of California laws regulating the development, marketing, and use of artificial intelligence (AI) go into effect. Together, these bills impose new requirements on generative AI developers, frontier-model companies, healthcare-related AI tools, platforms distributing AI-generated content, and businesses that rely on algorithmic pricing. With the deadline to comply coming up quickly, companies operating in California (or offering AI-enabled products or services to California residents) should assess how these laws apply to their technologies and update their governance and disclosure practices accordingly.

Most of the new obligations take effect in 2026, with some requirements extending into 2027 and 2028. Below is an overview of the key components of enacted bills AB 316, AB 325, AB 489, AB 621, and AB 2013.

AB 316: Liability for AI-Related Harms (Effective: January 1, 2026)

AB 316 applies broadly to any civil action where AI involvement is alleged to have caused damage. The bill limits affirmative defenses for civil liability, prohibiting defendants (which could include developers, modifiers, or users of AI) from raising an “autonomous-harm defense” in lawsuits alleging harm caused by AI-generated or AI-modified content. This defense, which might otherwise allow parties to shift blame to the technology’s independent decision-making, is explicitly barred to ensure human responsibility remains as AI models are deployed.

AB 325: Algorithmic Pricing and Antitrust (Effective: January 1, 2026)

AB 325 amends the Cartwright Act, a California anti-trust statute, to prohibit anticompetitive use or distribution of “common pricing algorithms.” A common pricing algorithm includes any methodology (computer-based or otherwise) that uses competitor data to recommend, align, stabilize, or influence prices or commercial terms. The statute creates two categories of liability: (i) use or distribution of a common pricing algorithm as part of a contract, combination, or conspiracy to restrain trade; and (ii) coercion to adopt an algorithm-recommended price or commercial term.

AB 489: Misleading Statements on Health Care Professional Oversight of  Artificial Intelligence (Effective: January 1, 2026)

AB 489 prohibits developers and deployers of AI and generative AI technologies from using titles, terms, icons, post-nominal letters, or design elements that could falsely suggest the system is providing services from a licensed healthcare professional. Any implication — direct or subtle — that a licensed professional oversees the output is barred unless such oversight exists. This prohibition applies both to advertising and to in-product functionality for both AI and generative AI systems. Each misleading representation may constitute a separate offense, and state licensing boards are authorized to investigate and enforce violations, including through civil penalties.

AB 621: Expanded Protections Against Digitized Sexually Explicit Deepfakes (Effective: January 1, 2026)

AB 621 strengthens legal protections against non-consensual, sexually explicit “deepfakes.” The law broadens the definition of “digitized sexually explicit material,” clarifies that minors cannot consent to its creation or distribution and increases damages (up to $250,000 for malicious violations), and grants public prosecutors civil enforcement authority. These expanded remedies meaningfully increase the risks for individuals and entities involved in creating or distributing such material.

AB 2013: Mandatory Dataset Disclosure for Generative AI Developers (Compliance by: January 1, 2026)

AB 2013 requires developers of generative AI systems to publicly disclose detailed information about the datasets used to train their models. Disclosures must be posted on the developer’s website and updated when substantial system modifications occur. The law raises concerns from developers related to protection of intellectual property, confidentiality, and potential litigation exposure due to the breadth of required disclosures.

Takeaways to Prepare for Compliance

With multiple California AI-related statutes becoming enforceable in 2026 (and additional obligations later in 2027, and 2028 that will be covered in a subsequent post) companies need to assess the applicability of these laws now, which may include:

  • Mapping and documenting training datasets now to ensure readiness for AB 2013.
  • Evaluating the use of shared or third-party algorithmic pricing tools under AB 325.
  • Reviewing their risk exposure related to the enabling of deepfake pornography under AB 621.
  • Considering the allocation of liability in agreements given the prohibition on autonomous harm defenses by AB 316.
  • Ensuring that their use of AI does not imply that their services are provided by a licensed healthcare professional unless overseen by a healthcare provider to comply with AB 489.

California’s AI regulatory framework is expanding rapidly. These new statutes are in addition to California’s regulations regarding Automated Decision-Making Technology, which were promulgated under the California Consumer Privacy Act and go into effect on January 1, 2026. Early preparation will help your company navigate the state’s emerging compliance landscape. If you have questions about these new California laws or their impact on your operations, please contact one of the authors.