We have been writing about the California Invasion of Privacy Act (CIPA) for a while now. From demand letters flooding our clients’ inboxes to the wave of class action filings targeting standard website tracking tools, this 1967 wiretapping statute has proven uniquely susceptible to claims that bear little resemblance to the covert surveillance it was
Taft Stettinius & Hollister LLP Blogs
Latest from Taft Stettinius & Hollister LLP
AI-Powered Call Transcription Tools Present Class Action BIPA Risk

We have all become accustomed to seeing pop-up notices on our video calls saying that an AI-powered technology is recording us. Sometimes the AI service even appears as a participant. Notwithstanding how commonplace these features have become, a recent decision from a federal court in California may signal that such call transcription services present a…
Federal Court Rules Government’s Anthropic Supply Chain Designation Was Unlawful Retaliation: What Government Contractors Need to Know
This is the third installment in our coverage of the Anthropic/Department of War dispute. Our first alert addressed the Trump administration’s February 27 directives barring federal contractors from using Anthropic and its Claude platform, including Secretary Hegseth’s designation of Anthropic as a supply chain risk to national security and the resulting requirement that all DoW…
Big Long List of AI Laws – Notable Updates
In mid-August, Taft published the latest edition of The Big Long List of U.S. AI Laws. The list now includes over 60 entries focused on the commercial regulation of AI by the states.
Despite persistent rumors to the contrary, AI law compliance is anything but a detail or triviality.
There is nothing particularly glamorous…
Enforcement and Transparency Obligations Under the EU AI Act are Now in Effect

On August 2, 2026, the EU AI Act (the AI Act) entered a new implementation phase with two key developments: (i) the European Commission’s AI Office and Member State authorities began enforcing applicable AI Act requirements, including the rules for general-purpose AI (GPAI) models; and (ii) the AI Act’s Article 50 (transparency obligations) also took…
Coming Soon Near You: New Privacy Laws in Alabama, Louisiana, Oklahoma, and Vermont

A new wave of comprehensive state privacy laws is on the horizon for 2026 and beyond. Alabama, Louisiana, Oklahoma, and Vermont have each enacted consumer data privacy statutes that will come online over the next few years, extending the patchwork and raising the stakes for multi‑state compliance programs.
Below, we provide the general thresholds for…
The Risk Of AI In ERP Software
Just DROPped: A Data Broker Law Update

California’s Delete Request and Opt-Out Platform (DROP) requirements went into effect on August 1, 2026, marking a meaningful operational shift for regulated data brokers and a clear reminder that enforcement of the Delete Act is no longer theoretical.
Separately, several other states have advanced their own data broker frameworks. New Jersey introduced an aggressive data…
As the CIPA World Turns…
With what is becoming the regular cadence of a daily soap opera, the developments in what has become known as “CIPA law” continue to evolve quickly.

In the past couple of weeks, we have written on several instances that could impact the litigation posture for any company sued or threated to be sued in California…
When Employees Don’t Trust AI: Sabotage, Shadow AI, and What In-House Counsel Should Know
General counsel face growing pressure to support aggressive AI adoption. At the same time, they must protect their organization’s legal and governance posture.
This video directly addresses that tension.
Employee resistance to AI rarely stems from a dislike of technology. It stems from unmanaged uncertainty about job security, performance evaluation, and data use. That uncertainty…
