Senate Bill (SB) 1130, legislation that would establish criminal penalties for certain uses of wearable recording devices, continues to move through the California legislature. I’ve had the honor of discussing this measure with staff of the bill’s sponsor, California State Senator Eloise Gómez Reyes, and anticipate there will be more efforts to enact laws seeking to impose measured responses to the privacy, security, and other challenges posed by the latest generation of AI-enabled wearables.

The Rise of AI-Enabled Smart Glasses

SB 1130 arrives at a critical moment. Modern AI glasses blend high-resolution cameras, always-on microphones, and real-time AI assistants into a hands-free wearable that can capture, analyze, and even transcribe ambient information around the wearer. Unlike traditional recording devices that require deliberate action, AI glasses and similar wearables can passively capture and transcribe conversations throughout the day, creating permanent searchable records of discussions that participants never knew were being documented.

Several institutions and organizations have taken steps to minimize the impact of these devices. For example, in July 2026, New York became the first state to prohibit AI-enabled smart glasses in all state courthouses. Outside the U.S., in August 2026, England and Wales followed suit when His Majesty’s Courts & Tribunals Service (HMCTS) announced that AI glasses will be confiscated from anyone entering its judicial buildings. The UK has also seen its first criminal prosecution involving smart glasses, with a guilty plea for voyeurism at Warrington Magistrates’ Court after a man recorded sex with a woman without her consent using smart glasses.

As we explored in our four-part series on AI glasses, “The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses,” these devices no doubt raise compliance issues spanning biometrics, two-party consent, workplace surveillance, labor law, data security, and third-party AI processing risks.

What SB 1130 Would Do?

Specifically, SB 1130 would make it a misdemeanor to operate a wearable recording device to capture sound or video of another person in any area within a place of business where that person has a reasonable expectation of privacy, without their explicit consent. Penalties include up to one year in county jail, a fine of up to $1,500 per violation, or both.

The bill also targets the circumvention of recording indicators such as small lights or sounds that signal a device is actively recording. Disabling an indicator would itself be a misdemeanor, and the manufacture, sale, or use of technology primarily designed to disable recording indicators would carry civil penalties of up to $2,500 per violation.

What is a wearable recording device?

SB 1130 defines wearable recording device to mean:

“any device that is designed to be worn on or attached to the body, rather than held by the user, that has the capacity to make sound or video recordings or to transmit sound or video to another device or to the internet.”

This definition likely would capture a broad array of devices beyond AI glasses. However, recent amendments adding “rather than held by the user,” potentially indicate an intention to avoid capturing smartphones, which generally are not designed to be worn or attached to the body (parents of 13-17 years old children may disagree) and typically are held by the user.

What is a place of business?

SB 1130 defines a place of business to mean:

“any physical office or retail establishment in which members of the public receive goods or services from the business.”

What is a reasonable expectation of privacy?

It is not clear at this point and may never be. While walking down a public sidewalk in California does not generally give rise to a reasonable expectation of privacy for visual observation, California law can be more protective than many other states when it comes to audio recording of conversations, targeted or technologically enhanced surveillance, and publication of private facts, even when the underlying events occurred in technically “public” spaces. The context, the nature of the information, and the technology used all matter.

This may be why SB 1130 focuses specifically on places of business where a person has a reasonable expectation of privacy, rather than attempting to regulate all public recording.

Are there provisions which would affect some employees directly?

The bill carves out of the definition of wearable recording devices:

“a headset, two-way radio, or similar device that is operated by an employee during the normal course of their business duties and is provided by their employer for that purpose.”

This description potentially includes positions such as call center representatives and order processors at some fast food restaurants. While providing some relief from its reach, SB 1130 also provides that employees who record sound or video of a customer using such devices must inform the customer that they are being recorded. So, in addition to assessing the implications of more cutting-edge technologies entering the workplace, some employers may need to revisit how their employees use more traditional recording equipment.

What comes next?

SB 1130 has not yet been enacted and must still clear the full legislature and receive the Governor’s signature. But the trajectory is clear: California is moving to close the gap between legacy wiretapping statutes and modern wearable technology and, as noted, it is part of a global trend.

We will continue monitoring SB 1130 as it moves through the legislative process. In the meantime, if you have questions about this bill or related issues, contact a Jackson Lewis attorney to discuss.

AI notetakers illustrate how artificial intelligence is fundamentally changing how people work. For example, there are now “AI Assistants” that snap onto the back of cell phones like a wireless battery pack. Instead of taking detailed notes during a meeting, preparing a summary, and identifying follow-up items, employees can use an AI notetaker to complete these tasks almost instantly. These tools can reduce administrative burdens, improve follow-up, and allow employees to focus on a conversation rather than on taking notes. An assistant, wrapped in a small, inconspicuous package.

Until recently, many AI notetakers were relatively easy to identify. A virtual notetaker, for example, might appear as a participant in a videoconference, which gives the meeting organizer and other attendees an opportunity to approve its use or remove it from the meeting. Organizations could also restrict which applications employees installed on company devices or connected to company systems.

But what if the AI notetaker does not appear on the meeting’s participant list? What if it is already sitting on the conference-room table, or in an employee’s pocket?

  1. What are Portable AI Notetakers?

Portable AI notetakers can record in-person conversations and telephone calls, store recordings while offline, and later synchronize the recordings to generate searchable transcripts, summaries, action items, and other AI-enabled content. Some are small enough to fit in a pocket or attach to a cell phone. As a result, an AI notetaker no longer needs to join a virtual meeting, operate on an organization’s network, or be installed on an organization-issued computer. An employee-controlled device may be able to record a conference-room discussion, interview, telephone call, or informal workplace conversation and later send that information to a third-party AI service without the organization’s knowledge.

While portable AI notetakers may provide meaningful benefits, they can also expose organizations to significant privacy, security, employment, and litigation risks.

  1. What Notice and Consent Issues Can Portable AI Notetakers Create?

Federal and state laws may restrict the recording of telephone calls and other communications. In most states, the consent of one party to the conversation is sufficient. Other states generally require the consent of all parties. The analysis can become particularly complicated when participants are located in different states or countries. Additionally, portable devices expand the settings where the issue may arise, including job interviews, customer calls, workplace investigations, accommodation meetings, and conversations involving patients or visitors.

Even when participants consent to being recorded, that consent alone may not authorize the recording and associated information to be shared with a third-party AI vendor. Participants may not understand that the service will receive their voices and statements and use that information to create a transcript, identify speakers, summarize the discussion, and generate additional records.

  1.  How Can Portable AI Notetakers Circumvent Existing Security Controls?

Many organizations have implemented controls to prevent employees from using unapproved AI tools on their systems. An organization might block AI meeting bots, restrict browser extensions, prevent software installations, or limit access to public AI platforms from company devices.

Portable AI recorders can bypass these controls. An employee may be able to record a workplace conversation without installing software on an organization’s computer or connecting the recorder to its network, then upload the recording through a personal device or account. This is a practice known as “shadow AI”: technology used without organizational approval or oversight. The organization may not know which tools are being used, what information is collected, where it is sent, which third parties process it, or how long it is retained.

  1. What Conversations are at Risk of Exposure?

Workplace conversations frequently include information that should not be disclosed outside the organization. A discussion may concern an employee’s medical condition, a workplace complaint, customer or patient data, business strategy, or trade secrets. A portable recorder may capture incidental information that would never appear in formal meeting notes, such as an employee discussing a family member’s health, a trip to a place of worship, or another personal matter unrelated to the purpose of the meeting.

Outside the workplace, there may also be discussions with customers, auditors, government regulators, legal counsel, or other unsuspecting parties containing sensitive or privileged information. These third parties may have their own confidentiality expectations or legal protections that an undisclosed recording could undermine.

An AI recorder captures what participants say, not just what the organization ultimately determines should be memorialized. Participants may speculate, discuss incomplete information, raise concerns that are later determined to be unfounded, or change their views as a discussion progresses. An AI-generated summary may nevertheless preserve, reorganize, and present those statements as a searchable (and perhaps incomplete) record.

  1. Why Does an AI Vendor’s Privacy and Security Matter?

When an employee uses an unapproved AI notetaker, the organization loses the opportunity to evaluate whether the vendor’s privacy, security, and contractual protections are appropriate for the organization’s intended use. Marketing statements or general compliance representations may not establish which specific AI services are covered, which third parties process the information, where the information is stored, or whether the vendor will accept appropriate contractual obligations.

Before approving an AI notetaker, an organization should understand what the service collects and how that information travels through the vendor’s systems. That review should account not only for the audio recording, but also for transcripts, summaries, prompts, speaker labels, voice data, integrations, and other information generated from the conversation.

  1. What Policies, Approval Processes, and Training Should Organizations Implement?

Organizations should not wait until they discover an unauthorized recording to address these risks. There are several measures organizations can take to help manage the use of portable AI notetakers before sensitive information leaves their control.

  • Adopt a Workplace Recording Policy: Organizations should consider adopting a workplace recording policy that generally prohibits employees from recording workplace conversations without (1) prior organizational approval and (2) the knowledge and express consent of all participants. The policy should apply broadly to audio and video recordings made through electronic devices, including personal devices. It should also identify categories of conversations that may not be recorded even with consent, such as discussions involving trade secrets, personally identifiable information, or privileged communications. However, organizations must be careful to ensure that any recording policy does not restrict employee activity protected by applicable labor and employment laws.
  • Implement an AI Workplace Usage Policy: Organizations should also adopt or update an AI workplace usage policy that addresses AI tools by function, not merely by brand name or software format. The policy should require approval of both the specific tool and the proposed use, prohibit employees from conducting organization business through personal AI accounts or unapproved devices, and make clear that information submitted to an AI service should be treated as a disclosure to a third party. Approved tools and permitted purposes should be identified, while uses involving confidential information, employment decisions, regulated data, or other higher-risk activities should require additional review.
  • Establish an Approval and Vendor-Review Process: An approval process should evaluate the particular tool, the proposed use, the people whose conversations may be recorded, and the categories of information likely to be captured. Approval for routine internal meetings should not automatically authorize recording workplace investigations, accommodation discussions, privileged communications, patient interactions, or customer calls. Organizations should also decide who has authority to approve a tool and who may require recording to stop.
  • Employee Training: While written policies and procedures are critical, they will have limited value if employees do not understand what AI tools are permitted or prohibited. Training should explain the risks of portable AI notetakers, the organization’s approval process, when notice and consent are required, and which conversations may not be recorded. Managers, human resources personnel, and meeting leaders should also know how to respond when they identify an unauthorized recording device or learn that a workplace conversation has been recorded.

***

AI notetakers can provide significant value and convenience. As portable AI notetakers become more common, organizations should ensure that their policies and procedures account for these devices. Organizations that focus only on the AI bot in the virtual waiting room may miss the recorder already sitting on the conference-room table. Policies, diligence, and training should address not only who joins the meeting, but also which devices are listening, where the resulting information goes, and what happens to it next.

If you have heard of CIPA, BIPA, GIPA, or TCPA litigation, you may have an idea of where this post is headed. These acronyms reference federal and state laws that permit a private right of action for certain privacy-related claims, affording successful plaintiffs with statutory remedies. In a recent case, Bartholomew v. Parking Concepts, Inc., an appellate court in California may have opened the door to a new line of similar litigation stemming from a state law regulating automated license plate recognition (“ALPR”) technology.

What is ALPR?

Automated license plate recognition (ALPR) technology uses fixed or mobile cameras paired with computer algorithms to capture license plate images and convert them into searchable, computer-readable data.

Why is ALPR used?

Common uses include locating stolen vehicles, identifying wanted individuals, managing parking access and payment, supporting toll collection, investigating crimes, and monitoring access to secured facilities. For example, Flock, an AI startup that leverages ALPR technology, has been cited for helping to solve crime, albeit not without some controversy.

Is ALPR use becoming more common?

Yes. ALPR systems are often used in the public sector, usually by law enforcement, but private sector use cases have been increasing with parking operators, repossession companies, insurers, HOAs, retail/commercial property owners, and others, as noted in a recent Car and Driver article.

Are there federal requirements for ALPR?

No comprehensive federal ALPR statute exists, although some legislative efforts have been made to limit their use nationally. Regulation is primarily state-by-state, though federal privacy and surveillance law (e.g., Fourth Amendment case law limiting warrantless, prolonged tracking) can inform how ALPR data may be collected, retained, and shared, particularly by government users.

What states regulate ALPR?

At least 16 states have ALPR-specific statutes, including California, Arkansas, Colorado, Florida, Georgia, Maryland, Minnesota, Montana, Nebraska, and New Hampshire, among others. Roughly six of those states restrict private-sector or government use outright, about eight impose data retention limits, and several exempt ALPR data from public records disclosure.

What does California’s ALPR law require?

California’s ALPR statute (Civil Code §§ 1798.90.5–1798.90.55) applies to both government and private-sector “ALPR operators” and “ALPR end-users.” It requires:

  • Reasonable security safeguards (administrative, technical, physical) to protect ALPR information from unauthorized access, use, or disclosure.
  • A written, publicly available usage and privacy policy; if the entity has a website, posted conspicuously on that site.
  • The policy must address: authorized purposes for collecting/using ALPR data; job titles of personnel with authority to use and access the ALPR system; monitoring and audit procedures; rules on sale, sharing, or transfer of data; the custodian responsible for compliance; accuracy safeguards; and data retention/destruction timelines.
  • Public agencies generally may not sell, share, or transfer ALPR data except to another public agency.

Note also that California’s data breach notification law (Cal. Civ. Code Sec. 1798.82) provides that information or data collected through an ALPR system, if breached, could trigger a notification requirement.

Does failing to post an ALPR policy online create liability, even without a data breach?

Potentially yes, at least in California. In the Bartholomew v. Parking Concepts, Inc. case noted above, the court held that a parking garage’s camera system qualified as an ALPR system, and that operating it without a publicly posted usage and privacy policy violates an individual’s statutory “right to know,” which alone is sufficient to allege cognizable harm under Civil Code § 1798.90.54, although not every violation of the law will trigger relief for a plaintiff. The court reasoned:

“In other words, while the ALPR Law does not impose specific restrictions on the use of ALPR information, it grants individuals the right to know which entities are collecting their ALPR data and how it is being used and maintained.  Collecting and maintaining individuals’ ALPR information without implementing and making public the statutorily required policy harms these individuals by violating this right to know…  If an ALPR operator has failed to implement and make public the statutorily required policy establishing authorized uses, it is much more difficult to hold them accountable for unauthorized uses, even though this is an example of a harm-causing violation expressly stated in the ALPR Law.  This further underscores the significance of the publicly available policy to the ALPR Law’s statutory scheme”

What can a plaintiff recover under California’s ALPR law?

Section 1798.90.54 allows an individual “harmed” by a violation to sue any person who knowingly caused the harm, and recover: actual damages (or liquidated damages of at least $2,500 per violation), punitive damages for willful or reckless violations, attorney’s fees and litigation costs, and equitable relief.

Do any other states offer a private right of action or statutory damages like California?

Some do. For example, an Arkansas law (Ark. Code § 12-12-1807) permits a person injured in business, person, or reputation by a violation may sue for actual damages or liquidated damages of $1,000, whichever is greater, plus litigation costs. Nebraska (Neb. Rev. Stat. § 60-3208) allows a private suit for damages that proximately cause injury to business, person, or reputation, but sets no liquidated-damages floor. Washington’s new Driver Privacy Act (SB 6002) creates a civil remedy for an injured person and, for certain government contractors, treats violations as per se unfair/deceptive acts under the state Consumer Protection Act, which carries its own private right of action, treble damages up to $25,000, and attorney’s fees.

What steps should businesses take to comply with the California ALPR law?

  1. Determine whether any camera/software system used (including third-party parking, security, or access-control vendors) meets the statutory definition of an ALPR system.
  2. Draft a written usage and privacy policy covering all statutory elements (purpose, authorized personnel, monitoring/audit process, sharing restrictions, custodian, accuracy measures, retention/destruction schedule).
  3. Post the policy conspicuously on the company website, not merely buried in an internal manual.
  4. Implement reasonable administrative, technical, and physical security safeguards for ALPR data.
  5. Update incident response plans to include ALPR system data.
  6. Restrict data sharing and sale consistent with the policy and applicable law.
  7. Audit vendor contracts (parking operators, repossession firms, security vendors) to confirm their ALPR practices align with the business’s own compliance obligations.
  8. Monitor other states where the business operates, since requirements vary significantly by jurisdiction.

For much of the past two years, discussions regarding generative artificial intelligence (AI) in professional services seems to have focused on lawyers, and perhaps for good reason. Courts have sanctioned attorneys who submitted briefs containing fabricated case citations. In response to these and other mishaps, several state bars issued ethics opinions often applying existing professional obligations to AI such as technological competence, confidentiality, supervision, and billing. Those same themes, however, are increasingly relevant to other professional service providers, such as tax professionals, including employee benefit plan advisors in some cases.

When Do the IRS OPR Guidelines Apply?

The IRS has now made clear that ethics and compliance obligations extend well beyond litigation and the legal profession generally. In June 2026, the Internal Revenue Service’s Office of Professional Responsibility (OPR) issued Introductory Guidelines for Responsible AI Use in Federal Tax Practice (Alert 2026-19), explaining how existing Circular 230 obligations apply when tax practitioners, including attorneys, certified public accountants (CPAs), and enrolled agents, use generative AI. Specifically, the Alert arises out of IRS Circular 230 which governs practice before the IRS and establishes standards of competency, diligence, ethical behavior, and procedures for discipline. Rather than creating AI-specific rules, the Alert applies these existing obligations to the use of AI. It confirms an emerging regulatory principle likely to apply across virtually every licensed profession: AI may assist professional judgment, but it may not replace it.

The work of tax professionals extends well beyond Form 1040 preparation (individual federal tax return preparation). By way of example, professionals working on corporate tax issues, payroll taxes, estate taxes, and the qualified plan rules for employee benefit plans may all need to consider Alert 2026-19 when incorporating AI into their practice.  The Alert offers a roadmap for ethical AI use that such professionals can adapt when performing tax-related services and advising clients.

How Do The Guidelines Address Accuracy?

One of the central themes of the Alert is that AI-generated work must always be independently verified, a principle familiar to every practicing attorney.

When using GAI, practitioners must thoroughly review all AI-created documents and language incorporated into writings before delivery to a client or submission to the IRS. Due diligence requires verifying the accuracy of facts, citations, and calculations produced by AI. Practitioners cannot rely solely on AI; human scrutiny and editing are essential to ensure correctness and compliance with IRS expectations.

In short, AI-generated content should be treated as a draft requiring professional review rather than as a final work product, whether that content is a tax return filed with the IRS, a tax memorandum to the client, or a benefit plan communication addressing tax consequences.

How Do The Guidelines Address Competence?

The IRS also emphasizes that professional competence increasingly requires understanding the technology itself.

Practitioners must understand both the law and the technology used in their representation of clients before the IRS, including AI systems’ operational mechanics, limitations, and risks.

They must understand how AI develops content, recognize the potential for bias or errors, and be able to evaluate whether AI outputs are suitable for use in IRS matters. Lack of technological competence could lead to improper advice or flawed filings.

This mirrors a growing consensus among regulators and professional organizations that technological competence is no longer optional. Professionals need not become computer scientists, but they should understand:

  • when AI is appropriate to use;
  • when independent research or analysis remains necessary;
  • what information AI systems retain or transmit;
  • what risks exist regarding confidentiality and cybersecurity; and
  • how AI outputs should be validated before being relied upon.

Professional competence today increasingly includes the ability to use and supervise the use of AI effectively. The challenge of addressing AI “hallucinations” is not limited to litigation attorneys who fail to identify miscited or nonexistent caselaw. A Bloomberg Tax article, AI Hallucinations in Tax: The Risks and How to Mitigate Them, discusses several examples of AI hallucinations facing tax professionals:

Errors that silently compound across calculations. A single inaccurate assumption can flow through provision calculations, effective tax rate analyses, and disclosures without immediate detection. These errors can then distort financial reporting across entities, jurisdictions, and reporting periods.

Understanding the limitations of the technology is critical for all users and, in particular, for those with professional obligations.

How Do The Guidelines Address Confidentiality and Data Security?

The IRS guidance also underscores another issue rapidly becoming central to AI governance: protection of confidential client information.

Practitioners must strictly handle all client data using only secure, enterprise-approved AI. AI systems should be utilized with robust confidentiality safeguards firmly in place. Willful mishandling of taxpayer information through AI may lead to disciplinary actions under Circular 230.

Whether preparing individual tax returns, payroll taxes, or representing a client in connection with a tax audit of its qualified retirement plan, tax professionals very likely are processing their client’s sensitive confidential information, which may not be limited to personal information. Including such information in AI prompts or documents uploaded to an LLM can present significant risks to the confidentiality of that information. Among the questions organizations should consider are:

  • Has the AI vendor contractually agreed not to use prompts or uploaded information to train its models?
  • Is client data encrypted in transit and at rest?
  • Where is information stored?
  • Does the platform comply with applicable privacy laws and contractual confidentiality obligations?
  • Are employees prohibited from entering confidential client information into consumer AI platforms?

What Role Do Governance, Policies and Procedures Play Under the IRS Guidance?

The IRS makes clear that individual diligence is not enough on its own:

  • Firms must deploy internal policies and procedures for compliance with Circular 230 in the AI space, with coverage that includes:
    • Staff: Comprehensive training on use of AI (the risks, technological and otherwise, and the requirements).
    • Rules applicable internally (within the firm): Established protocols for secure data handling, AI accuracy monitoring, etc.
    • Contracting with external providers: Outsourced or third-party AI tools should be vetted.

Organizations that provide professional services, including law firms, accounting firms, consulting firms, engineering firms, benefit consultants, and healthcare providers should treat AI governance not merely as an IT initiative, but as an enterprise-wide professional responsibility. For example, policies governing approved AI platforms, employee training, confidentiality safeguards, validation procedures, documentation, and client communications are quickly becoming as important as traditional cybersecurity policies.

How Do The Guidelines Address Client Fees?

Perhaps the most interesting portion of the IRS guidance concerns professional billing.

Circular 230 prohibits unconscionable fees, and the OPR goes further, cautioning that billing should reflect any efficiencies AI brings to research, drafting, or analysis.

Practitioners should not only disclose, in general or specific terms as needed, the AI activities performed, but also fairly credit to the client’s account any cost reductions.

For example, if AI reduces an eight-hour task to two hours, firms should consider how that efficiency affects client billing—though the guidance does not address offsetting costs, such as AI licensing, training, and maintenance.

Looking Ahead

The IRS guidance is noteworthy not because it creates new obligations, but because it reinforces a broader reality. Generative AI is changing how professionals perform their work. It is not changing who remains responsible for that work. Whether the practitioner is a lawyer, CPA, enrolled agent, engineer, consultant, or another licensed professional, the emerging regulatory message is remarkably consistent: AI may be an extraordinarily valuable assistant, but it is not the professional of record nor a substitute for sound judgment.

The Alabama State Bar has joined a growing number of jurisdictions providing formal guidance on lawyers’ use of artificial intelligence. Formal Opinion 2026-01, Artificial Intelligence Use: Best Practices Under Existing Professional Conduct Rules, does not create new ethical obligations. Instead, it explains how longstanding duties under the Rules of Professional Conduct apply when lawyers use generative AI and emerging agentic AI tools in practice.

Below are answers to some of the most important questions for law firms and legal departments.

Why did the Alabama State Bar issue this guidance?

The opinion recognizes that AI has rapidly moved from an experimental technology to an everyday tool used to draft documents, summarize evidence, conduct research, analyze contracts, and communicate with clients. Rather than waiting for disciplinary issues to arise, the Alabama State Bar sought to explain how existing professional conduct rules govern these technologies.

Importantly, the opinion emphasizes that AI does not create new ethical duties. Instead, it “recontextualizes” existing duties—including competence, confidentiality, supervision, communication, candor, and reasonable fees—in light of AI-assisted legal practice.

Does the opinion prohibit lawyers from using AI?

No.

To the contrary, the opinion recognizes AI’s potential to improve efficiency, reduce costs, and expand access to legal services. Alabama acknowledges that AI is becoming an ordinary component of modern legal practice and that lawyers should understand both its benefits and its limitations.

The opinion also notes that as AI becomes more integrated into legal education and practice, technological competence increasingly includes understanding AI tools.

What are the most important takeaways for lawyers?

The opinion consistently returns to one central principle: Lawyers remain responsible for the final work product—even when AI assisted in creating it.

Among the practical expectations discussed are:

  • Verify all AI-generated legal analysis and citations.
  • Independently exercise professional judgment.
  • Protect confidential client information.
  • Understand how AI vendors process and retain data.
  • Supervise lawyers and staff using AI.
  • Communicate with clients when appropriate.
  • Ensure billing practices remain reasonable.
  • Develop firm-wide governance for AI use.

What guidance does the opinion provide regarding competence?

The opinion explains that competent representation now includes understanding how AI works sufficiently to appreciate both its capabilities and its risks.

Lawyers should understand issues such as:

  • hallucinated citations and factual errors;
  • incomplete or biased outputs;
  • limitations of predictive AI;
  • differences among AI platforms; and
  • circumstances requiring human review.

The opinion makes clear that blindly accepting AI-generated work is inconsistent with a lawyer’s duty of competence. Importantly, the opinion makes clear that:

“deploy[ing] an AI tool without basic due diligence on how that tool works and what it can get wrong has not satisfied Rule 1.1.”

In other words, failing to assess an AI vendor and its product could constitute a violation of the duty of competence.

What does the opinion say about confidentiality?

Confidentiality receives substantial attention. Before entering client information into an AI platform, lawyers should understand:

  • whether prompts are retained;
  • whether information may be used for model training;
  • who can access submitted information;
  • the vendor’s contractual commitments; and
  • the security controls protecting client data.

For many firms, this means AI can no longer be treated as simply another software application. Vendor due diligence, approved-use policies, and secure enterprise AI platforms are becoming increasingly important.

Can law firms have chatbots?

Yes, but. There is a lot to consider when developing and deploying a chatbot. For the Alabama Bar, it includes whether the chatbot “could cross into or facilitate the unauthorized practice of law (“UPL”)” and provides the following example:

Example. A law firm deploys a chatbot on its website that answers prospective clients’ legal questions in real-time. If the chatbot provides specific legal advice without flagging that it is not an attorney and without attorney review of its responses, this may constitute UPL—and the lawyer who deployed it may be responsible under Rules 5.5, 5.3, and 8.4.

What does the opinion say about billing?

The opinion reminds lawyers that AI should not become a vehicle for unreasonable fees. If AI substantially reduces the time required to complete a task, lawyers must continue to comply with the rules governing reasonable fees. Lawyers remain responsible for ensuring clients are billed appropriately and transparently regardless of how the work was performed.

How does Alabama compare with other states?

Alabama’s opinion generally aligns with the growing national consensus reflected in ABA Formal Opinion 512, which likewise concludes that existing ethical rules adequately govern lawyers’ use of AI. Other jurisdictions have reached similar conclusions while emphasizing different practical considerations.

Here are some examples:

  • Florida’s Opinion 24-1 similarly stresses competence, confidentiality, supervision, and verification of AI-generated work, while also adopting court rules addressing attorney responsibility for AI-generated filings.
  • North Carolina focuses extensively on client confidentiality, independent professional judgment, and supervisory responsibilities.
  • California’s practical guidance goes further into operational issues such as AI governance, vendor evaluation, and documenting internal controls for responsible AI use.
  • Georgia has published a practical AI toolkit emphasizing governance, education, and firm implementation rather than solely disciplinary analysis.

While terminology and emphasis differ, a clear national trend has emerged: state bars are not banning AI—they are requiring lawyers to use it competently, responsibly, and under appropriate professional supervision.

What should law firms do now?

The Alabama opinion should be viewed as more than an ethics opinion—it is a practical roadmap for AI governance. Law firms should consider:

  • inventorying approved AI tools;
  • developing written AI use policies;
  • implementing vendor due diligence procedures;
  • training attorneys and staff;
  • establishing review requirements for AI-generated work;
  • protecting confidential information through secure AI platforms;
  • documenting supervisory responsibilities; and
  • periodically reviewing AI governance as technology evolves.

For firms developing AI governance programs, Alabama Formal Opinion 2026-01 provides another authoritative reference confirming that successful AI adoption is no longer simply a technology issue—it is an issue of professional responsibility and sound law firm management.

New York has become the first state to prohibit AI-enabled smart glasses and other recording-enabled eyewear in all state courthouses. The new policy reflects growing concern over the ability of these devices to discreetly capture audio, video, photographs, and AI-generated transcripts. Below are answers to some common questions about the new rule and what it may signal for how organizations approach this technology.

Are AI Glasses Permitted in New York Courts?

Effective July 20, 2026, according to a memorandum by New York’s Office of Court Administration Executive Director, Justin Barry, on July 1, 2026, the New York State Unified Court System prohibits visitors from bringing smart glasses and other eyewear or headwear equipped with cameras, microphones, or other recording technology into any New York state courthouse. The prohibition applies to more than 1,200 state, county, city, town, and village courts throughout the state.

“This prohibition applies to all individuals entering court facilities, including litigants,
attorneys, witnesses, family members, UCS employees, and all other individuals who seek to enter a UCS facility for any reason.”

Why did New York adopt this policy?

The court system explained that AI-enabled smart glasses present unique challenges because they can record proceedings, conversations, and participants without being readily apparent to others. The statewide rule is intended to reinforce existing prohibitions on unauthorized recording in court facilities and to protect the integrity of judicial proceedings, confidential communications, and courthouse security.

Are prescription smart glasses prohibited?

Yes. Individuals who wear prescription smart glasses are expected to bring a conventional pair of prescription glasses if they need to enter a courthouse.

Is New York the first state to take this step?

New York appears to be the first state to implement a statewide prohibition applicable to every state court. However, courts in other jurisdictions have already begun restricting smart glasses through local rules, courthouse policies, or individual judicial orders. As adoption of AI-enabled wearables accelerates, additional statewide restrictions would not be surprising.

Why should organizations care about a courthouse policy?

For starters, lawyers and litigants who are not aware, or think they will get a pass, may show up at court with prescription AI glasses. According to the memorandum, “no individual possessing smart glasses will be permitted to enter a UCS facility unless they voucher the smart glasses for safekeeping by uniformed personnel while the individual remains in the facility.”  Without a backup pair of conventional glasses, they will not be able to enter the facility and participate in their case.

The New York policy also reflects a broader trend. Organizations across many industries are recognizing that existing “no recording” policies often were not drafted with AI-enabled wearable devices in mind. Smart glasses may continuously capture audio, video, images, location information, and AI-generated summaries while appearing no different from ordinary eyewear.

What are the broader legal and compliance issues with AI glasses?

There are many. We summarized a range of issues in our four-part series examining the legal and practical implications of AI-enabled smart glasses:

  • Part 1: Biometrics, facial recognition, and emerging privacy concerns.
  • Part 2: Audio recording, wiretapping, and consent laws.
  • Part 3: Workplace privacy, surveillance, and labor law considerations.
  • Part 4: Cybersecurity, data governance, and incident response implications.

What are some terms an organization should consider including in a policy on these devices?

A short list includes:

  • Defining AI-enabled wearable devices covered by the policy;
  • Recording in the workplace;
  • Protection of confidential and proprietary information;
  • Attorney-client privileged communications;
  • Customer and employee privacy;
  • Visitor access policies; and
  • Appropriate use of AI-enabled technologies.

Are other organizations taking similar action?

Yes. Courts are only one example. Law firms, healthcare providers, schools, financial institutions, retailers, entertainment venues, and other organizations are evaluating whether to restrict or regulate AI-enabled smart glasses in sensitive environments. Some organizations have already prohibited their use in conference rooms, client meetings, secure facilities, or other locations where confidential information is routinely discussed.

What is the takeaway?

New York’s action demonstrates that organizations are beginning to move beyond generic recording-device policies and adopt rules specifically addressing AI-enabled wearable technology. As smart glasses become increasingly sophisticated and widely used, organizations should expect additional legislation, court rules, and organizational policies governing their use.

For organizations that have not yet evaluated the implications of AI-enabled smart glasses, now may be an appropriate time to review workplace policies, security protocols, and AI governance programs to determine whether they adequately address this rapidly evolving technology.

New York organizations using artificial intelligence should keep a close eye on two pending state bills that could create new notice and reporting obligations. Both bills have passed the Senate and Assembly, but as of June 25, 2026, neither appears to have been signed by the Governor. Still, they offer a clear signal that New York lawmakers are focused on transparency and workplace impact surrounding AI technologies.

The first bill, AB 3411B, would amend the General Business Law to require notices on generative artificial intelligence systems. The second, AB 9581B, would amend the Labor Law to require certain businesses to submit annual reports to the New York Department of Labor about how AI affects hiring and workforce decisions. Note, taking a different approach to tracking AI-related job loss trends, California recently announced the California AI-Unemployment Tracker (CAIT), a public tracker based on unemployment insurance claims.

Assembly Bill (AB) 3411B

AB 3411B would apply to the owner, licensee, or operator of a generative AI system. The bill defines a generative AI system as a class of AI models that are “self-supervised” and “emulate input data to generate synthetic content, including text, images, videos, audio, and other digital content.”

If enacted, the bill would require covered parties to “clearly and conspicuously” display a notice on the system’s user interface stating that outputs of the generative AI system may be inaccurate. Note the bill does not limit its reach to certain use cases, such as commercial or employment activities. The bill would take effect 90 days after becoming law.

Organizations that develop, license, operate, or deploy generative AI systems for employees, applicants, customers, or the public may need to evaluate whether their user interfaces include the required notice. This may include chatbots, applicant-facing tools, customer service systems, document-drafting tools, or AI-enabled decision-support platforms.

Failure to provide the required notice could result in a civil penalty of up to $1,000 per violation, with each user who does not receive the notice treated as a separate violation for each instance. Organizations using third-party AI tools should consider whether contracts clearly allocate responsibility for required notices, interface design, indemnification, and compliance updates.

If this law is passed, it will take effect on the 90th day after it is signed.

Assembly Bill (AB) 9581B

AB 9581B is more directly tied to employment compliance. It would apply to a “covered business,” defined as a business entity doing business in New York that either employs more than 50 people or is publicly traded.

Covered businesses would be required to report to the Department of Labor by March 1 each year regarding AI use during the prior calendar year. The report would need to address the impact of AI on hiring and the nature of the company’s AI use.

Required employment data would include estimates of the number of employees displaced, employees whose hours were reduced, employees hired or whose hours increased, and previously filled positions that the business chose not to refill because of AI. The report would also require information about the objectives of AI use, human oversight, frequency and length of use, use of AI with sensitive personal data, storage and access protections, and risk-reduction measures.

The Department of Labor would develop standard reporting forms and processes, and it could create additional reporting requirements. The Department would also prepare a public annual report using aggregate data, including analysis by sector, geography, and business size.

Noncompliance could be costly. A covered business that fails to report could face a civil penalty of up to $500 for each day it remains in violation. However, the bill provides a 90-day cure period after notice of violation, and penalties may be waived or reduced if the violation is cured to the Commissioner’s satisfaction.

If passed, this law will take effect immediately.

What Organizations in New York Should Do Now

Because both bills are still pending, there are no imminent mandatory action items. However, as legislatures in New York and across the country are working a wide range of measures to address AI, organizations would benefit from maintain a well-developed governance program, one that tracks the AI tools and technologies in use by the organization, as well as its service providers and vendors. This one step would put organizations in a strong position to quickly identify whether a new law affects them.

If you have questions about these or other laws about AI in the workplace, contact a Jackson Lewis attorney to discuss.

Vermont has passed Senate Bill 71, a comprehensive privacy law that will regulate how covered entities collect, use, disclose, sell, and protect personal data.

The law is scheduled to take effect on January 1, 2028.

To whom does the law apply?

The law applies to people who conduct business in Vermont or produce products or services targeted at Vermont residents and meet one of several thresholds during the preceding calendar year. A business may be covered if:

  • It controls or processes the personal data of at least 35,000 consumers (not counting personal data controlled or processed solely to complete a payment transaction);
  • Controls or processes the sensitive data of at least 3,000 consumers (not counting personal data controlled or processed solely to complete a payment transaction); or
  • Offers for sale the personal data of at least 3,000 consumers.

The Act also contains specific provisions for consumer health data, which seem to be in line with efforts in other states to fill perceived gaps in the protection of health data left by HIPAA. Those provisions apply more broadly to people conducting business in Vermont or producing products or services targeted at Vermont residents.

The law includes numerous exemptions, including for certain government entities, certain HIPAA-regulated entities and data, financial institutions and data subject to the Gramm-Leach-Bliley Act, Fair Credit Reporting Act activities, and other regulated or limited categories.

Who is protected by the law?

The Act protects “consumers,” defined generally as Vermont residents.

However, the definition excludes individuals acting in a commercial or employment context, including employees, owners, directors, officers, contractors, or representatives of an organization when their communications or transactions occur solely within that role.

The law also includes heightened protections for children and minors, such as restricting targeted advertising and the sale of personal data.

What data is protected by the law?

The Act protects “personal data,” defined broadly to include information that is linked or reasonably linkable to an identified or identifiable individual or to a device associated with such an individual. This includes derived data and unique identifiers but excludes deidentified data and publicly available information.

The law provides heightened protections for “sensitive data.” Sensitive data includes data revealing racial or ethnic origin, religious beliefs, sex life, sexual orientation, nonbinary or transgender status, citizenship or immigration status, health conditions, disability, or treatment. It also includes consumer health data, genetic or biometric data, children’s data, precise geolocation data, neural data, certain financial account credentials, and government-issued identification numbers.

What are the rights of consumers?

Under the law, consumers may require a controller to do the following:

  • Confirm whether the controller is processing the consumer’s personal data and accessing that data.
  • Correct inaccuracies.
  • Delete personal data.
  • Provide a portable and, where technically feasible, readily usable copy of personal data previously provided by the consumer;
  • Allow the consumer to opt out of processing for targeted advertising, sale of personal data, and profiling in furtherance of solely automated significant decisions; and
  • Provide a list of third parties to whom the controller has sold personal information. 

What obligations do controllers have?

Controllers have several duties, including:

  • Controllers must limit the collection of personal data to what is reasonably necessary and proportionate to disclosed purposes. Remember, data minimization.
  • They may not process personal data for a materially new purpose (other than what is reasonably necessary and proportionate in relation to the purposes for which the data are processed, as disclosed to the consumer) unless they obtain consent.
  • They also must maintain reasonable administrative, technical, and physical safeguards appropriate to the volume and nature of the personal data. For sensitive data, controllers generally must obtain consent before processing or selling the data.
  • They must provide an effective mechanism for consumers to revoke consent and stop processing within 15 days after receiving the revocation request.
  • Controllers also must avoid unlawful discrimination and refrain from discriminating against consumers for exercising privacy rights.
  • Controllers must maintain certain contractual terms with processors.
  • Controllers must provide clear, accessible (e.g., website homepage, app settings menu, etc.) privacy notices. Those notices must disclose, among other things, categories of data processed, processing purposes, consumer rights, categories of personal data sold to third parties, and the categories of those third parties, “clear and conspicuous” disclosures concerning targeted advertising, contact information, whether personal data is used to train large language models, and the date of the latest update.

Controllers must also provide secure methods for consumers to exercise their rights, honor qualifying opt-out preference signals, and conduct data protection assessments for certain high-risk processing activities, including targeted advertising, sales of personal data, sensitive data processing, and certain profiling.

How is the law enforced?

The Vermont Attorney General enforces the Act. The law does not create a private right of action, meaning consumers generally may not sue directly for violations under the Act.

The Attorney General must provide guidance to controllers and processors and submit annual reports to the General Assembly regarding enforcement activity. During the period from January 1, 2028, through June 30, 2029, the Attorney General must provide notice and a 60-day opportunity to cure when the Attorney General determines that a cure is possible before initiating an enforcement action.

If you have questions about Vermont’s new privacy law or related issues, please reach out to a member of our Privacy, AI, and Cybersecurity practice group to discuss.

With the Governor of Louisiana’s signature on Senate Bill 386, Louisiana becomes one of the latest states to enact a comprehensive consumer privacy law, joining more than twenty states that have adopted similar frameworks in recent years. Like laws in Texas, Virginia, Colorado, and other states, the Louisiana Data Privacy Act (LDPA) adopts a controller/processor framework, grants consumers rights over their personal data, and authorizes enforcement by the state attorney general rather than private litigants. The Act takes effect January 1, 2027.

To whom does the law apply?

The law applies to a person or entity that does business in the state and meets at least one of these thresholds:

  • Annual gross revenues over $25 million
  • Annually buys, receives, sells, or shares for commercial purposes the personal information of 75,000 or more consumers, households, or devices.
  • Derives 50 % or more annual revenues from selling consumers’ personal information.

Notably, Louisiana’s applicability thresholds differ from many recent state privacy laws that focus primarily on the volume of consumer data processed. Instead, the LDPA incorporates revenue-based thresholds similar to those found in California’s privacy framework, applying to businesses with annual gross revenues exceeding $25 million regardless of the amount of personal data processed.

The law does not apply to various categories, including state agencies, certain financial institutions, and GLBA-regulated data, HIPAA-covered entities and business associates, nonprofits, and institutions of higher education.

Who is protected by the law?

The law protects consumers, defined as Louisiana residents acting only in an individual or household context. The law expressly excludes individuals acting in a commercial or employment context.

Under the law, a child’s parent or legal guardian may exercise the child’s consumer rights on the child’s behalf.  

What data is protected by the law?

The law protects personal data, which is information that is linked or reasonably linkable to an identified or identifiable individual. It excludes deidentified data or publicly available information.

Under the law, “sensitive data” is protected and includes personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, citizenship or immigration status, genetic or biometric data used to uniquely identify an individual, personal data collected from a known child, and precise geolocation data. Businesses should pay particular attention to the law’s treatment of sensitive data. Like many recently enacted state privacy laws, Louisiana generally requires consumer consent before processing sensitive data.

What rights do consumers have?

Under the law, consumers may require a controller to do the following:

  • Confirm whether the controller is processing the consumer’s personal data and access that data;
  • Correct inaccuracies;
  • Delete personal data;
  • Provide a portable and, where technically feasible, readily usable copy of personal data previously provided by the consumer; and
  • Allow the consumer to opt out of processing for targeted advertising, sale of personal data, and profiling in furtherance of solely automated significant decisions. 

Controllers generally must respond within 45 calendar days, with one additional 45-day extension when reasonably necessary to such requests.

What obligations do controllers have?

Under the law, controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary for the disclosed purpose and must maintain reasonable administrative, technical, and physical security practices appropriate to the data.

Controllers must provide a reasonably accessible and clear privacy notice describing categories of personal data processed, processing purposes, how consumers may exercise rights and appeal decisions, categories of personal data sold, categories of third parties to whom data is sold, and request submission methods.

If a controller sells sensitive data or biometric data, it must have a specific notice to that effect.

A contract between a controller and a processor must address the processor’s data processing procedures with respect to processing performed on behalf of the controller. Similar to other state privacy laws, the LDPA requires such contracts to include certain provisions, such as:

  • clear instructions for processing data;
  • the type of data subject to processing;
  • the duration of processing; and
  • a requirement that the processor make available to the controller, on reasonable request, all information in the processor’s possession necessary to demonstrate the processor’s compliance with the requirements of the LDPA.

Controllers must also conduct and document data protection assessments for targeted advertising, the sale of personal data, certain risky profiling, the processing of sensitive data, and other activities. Controllers that already maintain privacy impact assessments under other state laws may be able to leverage existing compliance processes.

How is the law enforced?

The state attorney general may enforce the law. And violations shall constitute an unfair and deceptive trade practice pursuant to the Unfair Trade Practices and Consumer Protection law, excluding private rights of action. Note, however, that the LDPA provides a 30-day cure period that sunsets on July 31, 2027, providing organizations with a limited opportunity to address alleged violations during the law’s early implementation period.

Although the LDPA largely follows the increasingly familiar state privacy law framework, businesses should not assume existing compliance programs automatically satisfy Louisiana’s requirements. Organizations with multi-state privacy compliance programs should review their privacy notices, consumer rights request procedures, consent mechanisms for sensitive data, and data protection assessment processes before the law takes effect on January 1, 2027.

If you have questions about Louisiana’s new privacy law or related issues, please reach out to a member of our Privacy, AI, and Cybersecurity practice group to discuss.

Artificial intelligence has quickly become part of the modern lawyer’s toolkit. Attorneys are using generative AI platforms to assist with legal research, drafting, editing, and document review. While these technologies can improve efficiency, a growing number of court filings across the country demonstrate a significant risk: AI-generated hallucinations, including fabricated case citations, nonexistent authorities, and inaccurate quotations.

Recent sanctions decisions from federal and state courts have highlighted the problem. Judges have encountered briefs containing cases that do not exist, citations that do not support the propositions for which they are offered, and legal analyses generated by AI systems without adequate attorney verification. These incidents have reinforced a fundamental principle of legal practice: lawyers—not software—remain responsible for the accuracy of every filing submitted to a court.

Recognizing these concerns, the Florida Supreme Court has amended Florida Rule of General Practice and Judicial Administration 2.515 to establish a clear statewide standard governing representations made when documents are filed in Florida courts.

Florida’s New Rule

Effective June 15, 2026, Rule 2.515(d)(2) requires every signer of a court filing to represent that:

“the legal authorities identified exist and are accurately cited.”

The amendment applies not only to attorneys but also to self-represented litigants.

The Court’s action reflects growing concern about the use of generative AI tools that may produce authoritative-sounding but inaccurate information. In its per curiam opinion, the Court expressly noted that generative AI systems “can generate content that appears plausible but is in fact inaccurate, including fabricated or ‘hallucinated’ authorities.”

A Statewide Response to a Growing Problem

Florida is not alone in confronting AI-related filing issues. Courts throughout the United States have issued sanctions, show-cause orders, and standing orders addressing AI-generated errors in briefs and motions. Some judges have required certifications regarding AI use, while others have focused on counsel’s duty to verify all citations and legal authorities before filing.

Rather than adopting a patchwork of local requirements, the Florida Supreme Court chose a statewide approach. According to the Court’s commentary, the amendments were adopted

“principally to create a statewide, uniform replacement for varied circuit court administrative orders imposing disclosure and certification requirements about the use of artificial intelligence in filings.”

New Sanctions Authority

The amended rule also expressly authorizes courts to impose sanctions when a filing is inconsistent with the signer’s certification. The rule provides that sanctions may be imposed after notice and an opportunity to be heard and may include:

  • Reprimand;
  • Contempt;
  • Striking the document;
  • Dismissal of proceedings;
  • Costs;
  • Attorneys’ fees; or
  • Other appropriate sanctions.

Although courts already possessed various sanctioning powers, the Florida Supreme Court made clear that the new provision is intended to eliminate uncertainty regarding courts’ authority to address inaccurate filings in the AI context.

What This Means for Lawyers

The amendment does not prohibit the use of AI. Nor does it require attorneys to disclose every instance in which AI assisted with drafting or research. Instead, it reinforces a basic professional obligation that predates artificial intelligence: lawyers must independently verify the accuracy of the legal authorities cited in their filings.

As generative AI becomes more sophisticated and more widely used, attorneys should consider implementing safeguards such as:

  1. Independently reviewing every citation generated by AI tools.
  2. Confirming that all cited authorities actually exist.
  3. Reading the underlying cases rather than relying on AI-generated summaries.
  4. Verifying quotations, pinpoint citations, and procedural histories.
  5. Establishing firm policies governing AI-assisted drafting and legal research.
  6. Training lawyers and staff regarding the risks of AI hallucinations and citation errors.

The Continuing Duty of Professional Judgment

The Florida Supreme Court’s amendment serves as a reminder that technological innovation does not alter a lawyer’s fundamental duties of competence, diligence, and candor to the tribunal. AI may assist in the drafting process, but it cannot replace the attorney’s obligation to ensure that every legal authority presented to a court is real, accurate, and properly cited.

As courts continue to encounter AI-related filing errors, Florida’s approach may provide a model for other jurisdictions seeking to balance innovation with the integrity of the judicial process. The message is straightforward: use AI if you choose, but verify before you file!