I am a big fan of Verizon’s yearly Data Breach Investigations Report. I follow it closely, as it confirms what we are seeing in the field, and provides validation for defense strategies employed to protect against attacks. The 2026 Report was recently published, and as I have mentioned before, it is well worth reading.
Robinson & Cole LLP Blogs
Latest from Robinson & Cole LLP
Shadow AI Continues to Expose Company IP
Verizon recently published its 2026 Data Breach Investigations Report, which is full of helpful information for cybersecurity professionals to implement strategies for protection of systems. For a summary, click here.
The Report notes that a whopping “67% of users are using non-corporate accounts on their corporate devices to access AI services” and “45%…
Colorado Rewrites Its AI Law Before It Takes Effect
Colorado has now significantly revised its AI governance framework before the law ever takes effect. SB 26-189, approved by Governor Jared Polis on May 14, 2026, repeals and reenacts key portions of the Colorado Artificial Intelligence Act (CAIA) and reframes the law around “automated decision-making technology” (ADMT) used to materially influence consequential decisions in areas such…
Privacy Tip #493 – Stop Using Shadow AI!
As you can tell, I am obsessed with Verizon’s Data Breach Investigations Report. It is worthy of full immersion, and I am picking it apart with precision (here and here). I always spend a lot of time delving into it as it informs and confirms strategies to assist others with prevention and resilience.…
Why AI Risk Needs Its Own Insurance Conversation
Many insurers, and the businesses they cover, are still treating artificial intelligence (AI) risk as if it were cyber risk cloaked in a costume. That instinct is understandable since AI systems process data, rely on vendors, create operational dependencies, and sit inside digital infrastructures. However, early litigation is showing why that framing is likely incomplete.…
FTC’s TAKE IT DOWN Act Stakeholder Letter Signals Heightened Compliance Priority
The spread of AI generated intimate imagery has turned what was already a serious online safety issue into a fast- moving platform governance problem. The Federal Trade Commission’s (FTC) latest stakeholder letter makes clear that covered platforms will be expected to have systems in place before enforcement begins. This week, the FTC sent a stakeholder…
When an AI Chatbot Calls Itself a Doctor
Pennsylvania’s lawsuit against Character Technologies, Inc., is a notable early test of how professional licensing laws may apply to consumer-facing AI chatbots. The Commonwealth, acting through the Department of State and State Board of Medicine, filed a Petition for Review in the Commonwealth Court of Pennsylvania seeking to restrain what it alleges is the unlawful…
Privacy Trends Fashion, Beauty, and Wearable Tech Brands Need to Watch
Fashion, beauty, and wearable technology brands are heading into 2026 with a lot more to think about concerning data privacy. What used to feel like a back-end legal issue is now shaping how companies design products, personalize experiences, and build trust with customers. With new state privacy laws taking effect in Indiana, Kentucky, and Rhode…
Phishing Now Top Method for Initial Unauthorized Network Access
According to Cisco Talus researchers, phishing is the primary method threat actors use to gain unauthorized access to networks, accounting for more than one-third of all incidents in the first quarter of 2026. This increase is attributed to threat actors using legitimate AI tools to enhance phishing campaigns, particularly against health care and government sectors.…
Tempus AI Faces Class Action Cases for Collection of Genetic Information in Acquisition
Multiple class action cases have been filed against Tempus AI alleging that, during its acquisition of Ambry Genetics, the company improperly collected and disclosed genetic information without obtaining prior written consent from individuals during its acquisition of Ambry. Tempus acquired Ambry, a genetic testing firm, in February 2025 for $600 million. The acquisition included the…