A recent Seventh Circuit decision offers a reminder to exercise caution when applying the financial services safe harbor under the Illinois Biometric Information Privacy Act (BIPA). In Cisneros v. Nuance Communications, Inc., No. 24-02982 (7th Cir. Aug. 28, 2026), the court held that the technology vendor’s storing of voiceprint data on behalf of a broker-dealer in securities fell within the financial-institution exemption to the BIPA. But that exemption is narrow—and companies outside the financial services industry, including their vendors, should take notice.

The Case

Norma Cisneros, a broker-dealer customer, alleged that Nuance, a third-party technology vendor, collected and stored her biometric voiceprint in violation of the BIPA. The broker-dealer contracted with Nuance to authenticate telephonic requests from customers, such as Cisneros, to permit financial transactions. Nuance used voiceprint technology to provide this service. Cisneros alleges Nuance violated the BIPA by failing to obtain her written consent and failing to publish retention and deletion schedules for the voiceprint data (claimed to be biometric information under the BIPA). The district court dismissed the case, and the Seventh Circuit affirmed.

The Court held that reading the BIPA in conjunction with Federal Reserve regulations made clear that Nuance qualified for the financial-institution exemption “to the extent that it authenticates the identity of [broker-dealer’s] customers in financial transactions.” The Court noted it was following the reasoning of a Delaware case affirmed by the Third Circuit, and ruling for Cisneros “would need to create a conflict among the circuits on a question of Illinois law…not an attractive prospect,” as the Court put it.

The financial institution exemption under the BIPA is not a blanket pass for any vendor performing identity verification. It applies specifically because the biometric data was collected and used to authenticate identity in the context of financial transactions regulated under federal banking law. Strip that context away, and the analysis changes dramatically.

What If the Vendor Isn’t Working for a Financial Institution?

Consider a company that uses the very same voiceprint or facial-recognition technology to verify identity, but the company is not a financial institution. In that scenario, the BIPA financial-institution exemption would almost certainly not apply. The vendor likely would be subject to BIPA’s full notice-and-consent requirements, including the obligation to obtain informed written consent before collecting biometric data.

Employment Examples:

  • Recruiting services. With recruitment fraud on the rise, organizations are strengthening authentication procedures to help ensure an applicant is who they say they are. Leveraging voiceprint technology or similar biometric technology in the course of that process potentially raises compliance concerns under the BIPA.
  • Call center onboarding. A staffing agency uses a vendor’s voiceprint technology to verify the identity of new remote IT hires during remote onboarding. Because the staffing agency is not a financial institution, neither it nor its vendor can claim the BIPA exemption.
  • Benefit plan administration. Employers want to be sure that only eligible employees receive benefits provided under retirement, welfare, and other benefit programs provided by the employer. Increasingly, employers (more likely their vendors) are leveraging ID verification for this purpose. Not all plans are the same – vendors administering retirement plans for the employer may be more likely to fit under the financial services exemption than vendors administering health, welfare, and fringe benefit plans.

Commercial Examples:

  • Telehealth patient verification. A healthcare platform contracts with a vendor to use biometrics to verify patient identity before appointments. Healthcare entities likely would not be covered by the financial institution exemption under the BIPA for this use case. The platform and its vendor likely need to independently comply with the BIPA’s consent and retention requirements.
  • Retail loyalty programs. A national retailer uses a vendor’s facial-recognition technology at kiosks to verify customer identity for a rewards program. Again, it is unlikely that the financial institution exemption applies. Both the retailer and the vendor face increased risk under BIPA.

Know What Your Vendors Are Doing and How They Are Doing It

In some cases, organizations that obtain ID verification services may not be aware of how their vendor is performing the service. The Cisneros decision underscores a critical point for companies in every industry: you must assess what your vendors are actually doing to verify; are they using biometric data. Authenticating by itself does not trigger the BIPA.

For organizations outside financial services using third party ID verification services, including when functioning as an employer, the practical steps remain the same:

  1. Map your vendor relationships. Identify every vendor that collects, stores, or processes biometric identifiers on your behalf.
  2. Assess the legal landscape. Determine whether any statutory exemption actually applies to your industry and use case. Do not assume your vendor’s compliance program covers you.
  3. Require BIPA compliance contractually. Your vendor agreements should include clear representations regarding notice, consent, retention, and destruction of biometric data.
  4. Implement consent workflows. Ensure that informed, written consent is obtained before any biometric data is collected—whether for employees, customers, or other individuals.

The Seventh Circuit gave the broker-dealer’s vendor a pass. Organizations that lack the same regulatory footing should not expect the same result.

AI is accelerating cybersecurity threats. Learn how data minimization, incident response, data mapping, and vendor governance can help reduce risk.

Recent reports involving leading artificial intelligence (AI) developers have heightened concern about whether AI agents can operate beyond their intended boundaries and/or be used by cyber criminals to perpetuate attacks that are more difficult to prevent and contain. For organizations adopting AI across business functions, the issue is larger than any single model or incident: AI may allow threat actors to identify vulnerabilities, develop exploits, and move through connected systems at a speed that outpaces traditional defenses.

That does not make existing safeguards obsolete. Multifactor authentication, endpoint detection and response, encryption and other controls remain essential. But organizations may need to reassess what constitutes “reasonable safeguards” in an environment where attacks can become faster, more adaptive, and more difficult to contain.

Co-leaders of Jackson Lewis’ Privacy, Data & Cybersecurity group, Joe Lazzarotti and Damon Silver, recently discussed how legal, privacy, and security teams can respond. Their central message: prevention remains critical, but organizations also need to reduce the data and access available to an intruder and prepare to respond when controls are overcome.

Key Takeaways

  • AI may enable threat actors to discover and exploit vulnerabilities faster than organizations can remediate them.
  • Technical controls alone are unlikely to provide a complete legal or operational risk-management strategy.
  • Data minimization, accurate data maps, access restrictions, and network segmentation can help limit the scope of an incident.
  • De-identification should be tested against current re-identification capabilities rather than treated as a complete solution.
  • Vendor diligence should address AI use, downstream providers, incident obligations, and meaningful contractual protections.

How Is AI Changing the Cybersecurity Threat Landscape?

Many security programs were designed around the speed and methods of human attackers. AI can change that equation. A malicious actor may use AI to identify a vulnerability, adapt code, and build an exploit on a compressed timeline, potentially before a patch or other defensive measure is available.

The practical implication is not that organizations should abandon their existing security investments. Rather, leaders should evaluate whether controls are configured, monitored, and updated for AI-enabled threats—and whether the organization can identify, contain and recover from an intrusion that succeeds.

Should Organizations Shift Their Focus From Prevention to Preparedness?

Organizations need both. Prevention supports compliance and reduces the likelihood of an incident, while preparedness reduces the business, legal, and reputational consequences when prevention fails. The familiar assumption that a breach is a matter of “when,” not “if,” is becoming more important as AI accelerates—and tips the balance, unfavorably, in—the contest between attackers and defenders.

Incident response plans should address decision-making authority, internal escalation, preservation of evidence, business continuity, communications, and potential notification obligations. Tabletop exercises can reveal whether the plan works under pressure and whether legal, privacy, security, HR, communications, and business leaders understand their roles.

“Prevention remains critical, but preparedness determines how effectively an organization can contain disruption and meet its obligations when controls fail.”

How Can Data Minimization Reduce AI-Related Exposure?

AI makes it easier to extract value from large datasets, creating a powerful incentive to collect and retain more information. That same footprint increases exposure. If an attacker gains access, a larger and more connected data environment can increase the number of affected individuals, the sensitivity of compromised information, operational disruption, and downstream litigation or regulatory risk.

Organizations should define what data they need, why they need it, and how long it should remain in active systems. Information that has a valid business or legal purpose may be archived more securely, redacted, or otherwise restricted; information without a continuing purpose may be eligible for defensible deletion.

The goal is not deletion for its own sake. It is aligning the organization’s data footprint with legitimate operational, legal and compliance needs.

“The larger and more connected the data footprint, the more an intruder may be able to access—and the greater the potential legal and operational impact.”

Can Organizations Continue to Rely on De-Identified Data?

De-identification and aggregation remain useful tools, but they should not be treated as automatic safe harbors. Even before generative AI, removing a name did not necessarily prevent a person from being identified through other data points. AI can make that reconstruction faster and more effective.

Organizations should document the standard used to de-identify data, assess the likelihood of re-identification using current capabilities, and restrict attempts to re-identify information. Vendor agreements should define de-identification rather than relying on an undefined promise that data will be “aggregated” or “de-identified.”

Why Are Data Mapping and Access Controls More Important Now?

AI tools increasingly connect with email, documents, collaboration platforms, and other business applications. Those integrations can improve productivity, but they may also allow a compromised account or agent to reach multiple repositories and move laterally through the environment.

Current data maps can help an organization determine which systems contain personal, health, employment, financial, confidential, or proprietary information; how those systems interact; who can access them; and where backups are maintained. Without that visibility, the early stages of incident response can become a costly search for what the organization is actually responding to.

Access should be limited according to job responsibilities, with heightened controls for privileged and administrative accounts. Network segmentation and restrictions between connected applications can further reduce the ability of an intruder to turn one compromised system into an enterprise-wide event.

What Should Organizations Ask Their AI Vendors?

A vendor’s size, reputation, or security budget does not eliminate risk. Organizations should “trust but verify” by conducting diligence proportionate to the sensitivity of the data, the tool’s integrations, and the potential operational consequences of an incident.

The review should address what information the vendor receives, whether it may use the information to train models or develop products, how long it retains the information, where it is processed, and which downstream service providers can access it. Contracts should address appropriate security measures, incident notification and cooperation, data usage restrictions, data return or deletion, audit or assurance rights, indemnification (where feasible), and responsibility for subprocessors.

Because visibility may diminish farther down the vendor chain, organizations should at least understand how the primary vendor evaluates, contracts with, and monitors its own providers. Consistent documentation of the review can help demonstrate a reasoned process if an incident or regulatory inquiry occurs.

What Should Legal, Privacy, and Security Leaders Do Next?

Cybersecurity is not solely an IT responsibility. When an organization must explain its conduct to a regulator, court, customer, or business partner, a list of technical tools will rarely tell the entire story. A stronger position combines appropriately configured safeguards with evidence of governance, preparation, and risk-based decision-making.

A Practical AI Cybersecurity Checklist

  • Reassess cybersecurity risk to account for AI-enabled attack speed and system connectivity.
  • Update and rehearse your incident response plan, including legal, regulatory, operational, and communications workflows.
  • Refresh data maps as AI pilots and integrations are introduced or expanded.
  • Apply collection, use, retention, archival, and deletion rules to personal and confidential information.
  • Review privileged access, application permissions, and network segmentation.
  • Evaluate whether de-identification methods remain effective against current re-identification capabilities.
  • Strengthen AI vendor diligence, contract protections and oversight of downstream providers.

Takeaway

AI may make cyber incidents more frequent, faster, and more harmful and disruptive, but organizations have multiple levers available to manage the risk. The most resilient programs will not rely on a single technology or policy. They will combine prevention with practiced response, minimize the data and access available to an intruder, maintain visibility into connected systems, and manage downstream risk.

Organizations evaluating or deploying AI should coordinate legal, privacy, security, HR, procurement, and business stakeholders before risks become incidents. A focused review of data flows, access, retention, vendor relationships, and incident response readiness can identify practical improvements and help build a defensible record of risk-based decision-making.

On January 1, 2026, Texas’s newest law addressing the growing issues of data privacy and the use of Artificial Intelligence went into effect. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) was passed by the 89th Texas Legislature and signed into law by Gov. Greg Abbott in 2025.

The law’s central focus is on restricting and regulating the use of Artificial Intelligence (AI) systems in Texas, which includes adding new prohibitions and requirements on anyone who develops or deploys AI systems in the private sector.

What does TRAIGA prohibit?

Under TRAIGA, private entities are prohibited from developing or deploying AI systems in a manner that:

  • Intentionally aims to incite or encourage a person to commit physical self-harm (including suicide), harm another person, or engage in criminal activity;
  • Serves the sole intent of producing, assisting or aiding in producing or distributing child pornography or certain sexually explicit “deep fake” videos or images;
  • Impairs a person’s individual rights guaranteed under the U.S. Constitution; or
  • Unlawfully discriminates against a protected class in violation of state or federal law.

TRAIGA also prohibits governmental entities from using or deploying AI systems for uniquely identifying a specific individual using biometric data or gathering images or other media without the individual’s consent if such gathering would infringe on the individual’s rights, as well as barring “social scoring” by government entities to evaluate or classify people based on social behavior or personal characteristics, or developing or deploying such systems for the purpose of identifying individuals using biometric data or data from the internet or other public sources without the individual’s consent.

How does TRAIGA prohibit unlawful discrimination?

While TRAIGA’s prohibitions against self-harm and sexual content attract more attention as “high risk” AI systems, the law’s emphasis on unlawful discrimination is of particular concern for many businesses that utilize AI in aspects of their Human Resources, employee evaluation, or recruitment process. Although TRAIGA expressly notes that disparate impact alone is not sufficient to establish a violation, the law otherwise bars any intentional discrimination.

Are any industries treated differently under TRAIGA?

Yes. Although TRAIGA’s requirements generally apply across all industries, the law carves out two unique cases. First, the law’s prohibition on unlawful discrimination does not apply to insurance companies for the purposes of providing insurance services if the company is already subject to statutes regulating unfair discrimination, unfair methods of competition, or unfair or deceptive acts or practices related to the insurance industry.

Additionally, if an AI system is used to provide health care services or treatment, the provider of such service or treatment must provide a clear and conspicuous disclosure to the patient (or patient’s representative) no later than the date the service or treatment is first provided (except in case of emergency).

What are the penalties for violating TRAIGA and who can enforce its prohibitions?

Like other recent efforts by Texas to secure residents’ data privacy and biometric data, TRAIGA does not provide a private cause of action, but tasks the Texas Attorney General with enforcing any violations of TRAIGA following a sixty-day cure period following a notice of violation. Civil penalties under the law can range for $10,000 to $12,000 per violation for any “curable” violation, while penalties for “uncurable” violations can be as high as $80,000 to $200,000 per violation. The law further incentivizes prompt remediation by applying civil penalties for ongoing violations of between $2,000 and $40,000 daily as long as the violation continues.

What can businesses do to comply with TRAIGA?

As AI use is a developing field, TRAIGA also encourages businesses to take proactive steps to adopt compliance measures and self-audit protocols by providing various safe harbors and affirmative defenses for parties who identify potential violations through internal review, adversarial testing, or compliance with recognized risk management frameworks, such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework.

The Texas Attorney General has demonstrated a growing interest in prosecuting technology-related violations in recent years, resulting in several high-profile settlements in the hundreds of millions and billions of dollars. In light of this enforcement priority, Texas businesses should proactively take steps to ensure their actions are compliant with TRAIGA and all other recent data privacy and data security laws in effect, including:

  • Evaluating whether and how they are using any AI system in the workplace, especially with regard to employment decisions
  • Creating AI-specific policies and procedures to ensure any AI use, now or in the future, is regulated and potential violations can be identified and cured promptly
  • Developing procedures for self-auditing and internal review of AI systems prior to full roll-out, and
  • Adopting a recognized AI risk management framework, such as the NIST AI Risk Management Framework

If your organization is one of the many adopting AI use in any aspect of its operations, it is essential that you conduct a prompt review of your usage to ensure your entity is not at risk of non-compliance.

As AI-powered hiring tools become more widespread, it is important to remember that some states have acted early and their laws should be reflected in an organization’s governance, risk, and compliance program. Maryland’s Labor and Employment Code Section 3-717 which became effective October 1, 2020, is one example. We break down the key requirements and highlight multistate considerations.

Q: Who does the law apply to?

The law applies to employers who use facial recognition services during applicant interviews. Its protections run to applicants, generally individuals who are interviewing for employment. The law does not, by its terms, extend to current employees or to other stages of the employment relationship beyond the interview. It is unclear, however, whether the law may also protect employees of an organization applying for other positions at the same organization.

Q: What does Maryland Section 3-717 actually prohibit?

The statute prohibits an employer from using a “facial recognition service” to create a “facial template” during a job applicant’s interview, unless the applicant has first provided consent. A “facial recognition service” is defined as technology that analyzes facial features and is used for the recognition or persistent tracking of individuals in still or video images, and a “facial template” is the machine-interpretable pattern of facial features extracted from one or more images of an individual by such a service.

Q: How does an applicant give consent under the Maryland law?

Consent must be provided through a signed waiver. The waiver must be written in plain language and include: (1) the applicant’s name, (2) the date of the interview, (3) a statement that the applicant consents to the use of facial recognition during the interview, and (4) whether the applicant has read the consent waiver.

Q: Does Section 3-717 apply to all uses of AI in hiring?

No. The Maryland statute is narrowly focused on facial recognition services used to create facial templates during interviews. It does not broadly regulate other AI-based tools an employer might use in the hiring process, such as resume-screening algorithms or chatbot-based assessments, unless those tools incorporate facial recognition technology as defined in the statute.

Q: How does the Maryland law differ from the Illinois Artificial Intelligence Video Interview Act (AIVIA)?

Although both laws regulate the use of technology during applicant interviews, there are several notable differences:

  • Scope of technology covered. Maryland’s Section 3-717 targets only “facial recognition services” used to create a facial template. The Illinois AIVIA, which became effective January 1, 2020, is broader: it applies whenever an employer asks applicants to record video interviews and uses “artificial intelligence analysis” of those videos, which can encompass a wider range of AI evaluations beyond facial recognition alone.
  • Disclosure and transparency. The Illinois AIVIA requires employers to (a) notify the applicant before the interview that AI may be used to analyze the video and assess their fitness for the position, and (b) provide an explanation of how the AI works and what general types of characteristics it evaluates. Maryland’s statute has no comparable pre-interview disclosure or transparency requirement — it requires only a signed consent waiver.
  • Form of consent. Maryland requires a specific written waiver containing the applicant’s name, interview date, a consent statement, and an acknowledgment of whether the applicant read the waiver. Illinois requires consent to be obtained before the interview but does not prescribe the same formalized waiver requirements.
  • Video sharing and deletion. The Illinois AIVIA includes additional protections that have no counterpart in the Maryland statute. Under the Illinois law, employers may not share applicant videos except with persons whose expertise or technology is necessary to evaluate the applicant, and employers must delete interview videos (including backup copies) within 30 days of an applicant’s request. Maryland’s Section 3-717 does not address video sharing or data deletion.

Q: What should multi-state employers take away from these laws?

An ongoing challenge for organizations operating in multiple states is the patchwork of similar laws addressing similar technologies, but sometimes with a different scope or context, along with some unique provisions.

Here, we focused on two laws that address the interview process for job applicants. One might ask whether there are other statutes that regulate the interview process in this way. Focusing only on regulation of job interviews might cause one to miss other critical compliance requirements.

The Maryland and Illinois laws discussed above may involve the collection of biometric information that, for example, also is protected under more general laws, such as the California Consumer Privacy Act (CCPA), the Illinois Biometric Information Privacy Act (BIPA), and other states with protections for such information (e.g., Colorado and Texas).

Additionally, neither the Maryland nor Illinois job interview laws includes obligations to safeguard the facial scan data collected during covered interviews. However, other state laws may include such a requirement. Maryland’s own Personal Information Protection Act (PIPA) requires:

a business that owns, maintains, or licenses personal information of an individual residing in the State [to] implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal information owned, maintained, or licensed and the nature and size of the business and its operations.

Under the PIPA, personal information includes biometric information.

It is not enough to think about just the activity the organization is engaged in – a job interview – employers need to consider a range of other issues to fully appreciate the regulatory environment for that activity – the kind of data collected, the location of the collection, who is collecting it, the state of residency of the person providing the information, how that data is collected and analyzed, among other things.

On September 2, 2026, Delaware’s Governor signed House Bill (HB) 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), which was enacted in 2023 and became effective January 1, 2025. HB 381 separately amends Delaware’s computer security breach notification law.

In short, what changes were made to the Delaware privacy and data-breach laws?

Together, the bills expand the businesses and data covered by existing law, increase protections for sensitive data, impose new vendor-management and automated decision-making requirements, and strengthen breach-notification obligations.

When do the changes take effect?

The HB 380 amendments to the DPDPA take effect January 1, 2027, while the HB 381 amendments to the breach-notification law take effect upon signing.

Which organizations does the amended DPDPA cover?

HB 380 lowers the DPDPA’s applicability thresholds. The law previously covered businesses that control or process the personal data of at least 35,000 consumers during the preceding calendar year. That threshold is now reduced to 10,000 consumers. For businesses that derive more than 20% of their gross revenue from selling personal data, the alternative threshold drops from 10,000 to 5,000 consumers.

The amendments also cause the DPDPA to apply to third parties that acquire personal data from a controller. Recall that third parties are defined broadly to include, with respect to personal data controlled by a controller, any person other than the relevant consumer, the controller of such personal data, or a processor or an affiliate of the processor or the controller.

Accordingly, organizations that fell below the original thresholds and potential third parties should reassess whether they are now subject to the DPDPA under the lower thresholds and changes enacted by HB 380. However, the changes also clarified organizations and categories of data that are excluded from the DPDPA, largely affecting financial institutions and the healthcare sector.

How did consumer rights change?

Consumer rights under the DPDPA have expanded in some significant ways. Consumers can now confirm whether controllers are including inferences about the consumer derived from personal data and processing personal data for profiling purposes to make significant decisions about the consumer.

Additionally, under the prior law, consumers had the right to obtain a list of “categories of third parties to which the controller has disclosed” their personal information. Under HB 380, consumers can obtain the list of the actual third parties, subject to several exceptions, including if the list would reveal a trade secret or that list cannot be compiled with reasonable effort. However, in that case, the controller must disclose all third parties to which it disclosed personal information.

The amendment also limits the consumer right of access with respect to certain sensitive data elements. For example, controllers may not disclose a consumer’s SSN or account password, but may only inform the consumer that the controller possesses that information.

Did the contents of the controller privacy notice change?

Yes, privacy notices must identify the controller for contact purposes, and include a description of the consumer’s personal data rights.

What new categories of sensitive data does HB 380 add?

HB 380 expands the definition of sensitive data to include national origin; health treatment or status; neural data; certain financial-account information and credentials; and government-issued identification numbers. It also covers inferences drawn from other information when those inferences are used to reveal or identify a sensitive characteristic.

What are the new requirements for processing sensitive data under Delaware law?

Processing sensitive data requires the consumer’s consent and must be reasonably necessary and proportionate to the disclosed purpose.

Are there restrictions on selling sensitive data?

Yes. A controller may sell sensitive data only when the disclosure is strictly necessary to provide or maintain a product or service affirmatively requested by the consumer. The controller must provide a clear and conspicuous notice, obtain the consumer’s consent, and retain a record of that consent for five years.

What new vendor-management obligations does HB 380 impose?

Controllers must enter into contracts with third parties receiving personal data. Those contracts must identify limited and specific purposes for the data, require the third party to provide the same level of privacy protection as the controller, and permit the controller to address unauthorized uses. Controllers must also conduct reasonable due diligence regarding third parties, including, at minimum, questionnaires and reviews of relevant documents.

What does HB 380 require for automated profiling and decision-making?

HB 380 adds requirements for profiling and reports used in decisions that produce legal or similarly significant effects, such as decisions about employment, housing, lending, insurance, education, or healthcare. When a report contributes to an adverse action, contractual provisions must require notice to the affected Delaware resident, identification of the data relied upon, and information about requesting human review where technically feasible.

Are impact assessments required for automated profiling?

Yes. Controllers engaging in covered automated profiling must conduct and document impact assessments. These assessments must address risks, inputs, outputs, performance measures, limitations, transparency, and post-deployment safeguards.

Does the employee-data exclusion still apply?

The existing employee-data exclusion is narrowed for personal data used in the context of profiling or disclosing to a third party a report for use in connection with any decision that produces legal or similarly significant effects on a resident of Delaware. In such cases, controllers and third parties have several requirements, including notice requirements to the residents concerning adverse actions, contract obligations, and additional consumer rights requests relating to personal information use in profiling.

What changes does HB 381 make to Delaware’s breach-notification law?

Like many states, the Delaware breach notification law provides an alternative way to provide notice (called “substitute notice”) when the cost of notification will exceed $75,000, the number of affected Delaware residents exceeds 100,000, or the organization does not have sufficient contact information to provide notice. Substitute notice typically involves email notice, conspicuous website notice, and notice to major statewide media. HB 381 updated the substitute notice requirement to also include notice to the Delaware Attorney General.

Additionally, in situations when an organization, through reasonable diligence, cannot identify within 60 days that personal information of Delaware residents was involved in a breach, it must provide required notification as soon as practicable after it determines such information was involved. HB 381 adds that notice to the Attorney General also must be provided within 60 days of that determination.

Does compliance with HIPAA or the Gramm-Leach-Bliley Act satisfy Delaware’s breach-notification requirements?

HB 381 narrows the existing exemption for entities regulated under laws such as HIPAA or the Gramm-Leach-Bliley Act. In short, compliance with regulator-established breach procedures now satisfies only Delaware’s 60-day timing requirement, rather than the entire state breach-notification law.

Who enforces the amended DPDPA?

The DPDPA amendments retain enforcement by the Delaware Department of Justice. The amendments do not create a private right of action.

What steps should businesses take to prepare for the new requirements?

Businesses should reassess whether they are covered under the lower applicability thresholds, inventory sensitive data and automated decision-making activities, update incident-response procedures, and review privacy notices, consent processes, third-party contracts, and vendor due diligence practices.

On June 4, 2026, Connecticut Governor Ned Lamont signed Public Act No. 26-73 (SB 472), “An Act Concerning the Electronic Surveillance of Employees,” which repeals and replaces Conn. Gen. Stat. § 31-48d. The law takes effect October 1, 2026, and significantly updates Connecticut’s longstanding requirements governing electronic monitoring of employees by employers.

Connecticut has regulated workplace electronic monitoring since 1998, and presently, several states have some form of notice, acknowledgment, and/or consent requirement for organizations engaging in electronic monitoring of their workforce.  These states include California, Delaware, Maine, New Jersey, and New York.

Before discussing the updated notice requirements, it is important to note that the new law does not change the definition of electronic monitoring. It remains:

“Electronic monitoring” means the collection of information on an employer’s premises concerning employees’ activities or communications by any means other than direct observation, including the use of a computer, telephone, wire, radio, camera, electromagnetic, photoelectronic or photo-optical systems, but not including the collection of information (A) for security purposes in common areas of the employer’s premises which are held out for use by the public, or (B) which is prohibited under state or federal law.

The use of cameras or the tracking of activities and communications on a company’s information systems quickly come to mind. However, the rapid expansion of AI technologies and the various use cases also should be assessed. Consider AI tools and use cases such as AI transcription and note taking tools, chatbots, and performance management platforms. These and other tools and use cases may require employers to revisit their notice and posting obligations under this expanded law in Connecticut.

What also remains the same is the definition of employee:

“Employee” means any person who performs services for an employer in a business of the employer, if the employer has the right to control and direct the person as to (A) the result to be accomplished by the services, and (B) the details and means by which such result is accomplished.

Updated Prior Written Notice and Posting Requirements

The updated monitoring law enhances the existing prior written notice requirements for employers engaging in electronic monitoring. Beginning October 1, 2026:

  • in addition to providing prior written notice to all employees who may be affected by electronic monitoring and specifying the types of monitoring, employers must inform those employees of the specific locations on the employer’s premises where such monitoring may occur; and
  • the existing obligation to post a notice of electronic monitoring in a conspicuous place which is readily available for viewing by employees, must also be posted in the specific location on the employer’s premises where the monitoring may occur. That posting also must describe the specific locations on the employer’s premises where the monitoring may occur.

Additionally, for employees hired on and after October 1, 2026, employers engaged in electronic monitoring must provide to such employees (prior to commencement of employment) a plain language written statement advising which activities are prohibited and may be monitored without giving prior written notice. Such activities include employees engaged in conduct which (i) violates the law, (ii) violates the legal rights of the employer or the employer’s employees, or (iii) creates a hostile workplace environment, and for which electronic monitoring can produce evidence of this misconduct.

Notably, the requirement to disclose the specific location of the premises being monitored does not apply where the premises is an airport, or when the employer has reasonable grounds to conduct such monitoring for security and employee safety purposes.

The updated monitoring law did not change the enforcement provisions. The Labor Commissioner may impose a civil penalty on any person that violates the notice and posting requirements. The maximum penalties are $500 for the first offense, $1,000 for the second, and $3,000 for the third and subsequent offenses.

Connecticut employers should review their monitoring activities, including deployments of AI tools and their respective use cases, and assess compliance with applicable posting, notice, and/or acknowledgment requirements in Connecticut and other states as applicable.

A family’s ordinary afternoon was shattered when an unknown number added multiple relatives, including a teenager, to a group chat and shared what appeared to be AI-generated explicit images of a family member, the Wall Street Journal (WSJ) reported. The goal was simple: to extort money by threatening to release the images more widely. The scheme was sophisticated, leveraging publicly available social media photos and AI tools to fabricate convincing pornographic content and to map out family relationships for maximum emotional impact.

Why This Matters for Your Organization

Sextortion, generally speaking, is the use of real or fabricated explicit images to coerce victims into paying money. According to reports, the practice is accelerating, and AI is the catalyst. Scammers no longer need to manually research their targets. Open-weight AI models running on dedicated machines can scrape social media profiles, analyze public data, and piece together personal relationships at scale.

What does this mean for organizations?  Whether the target is the employee or the organization, the organization could face significant disruption to the business, distracted employees, and reputational harm. Reported tactics by online extortionists include threats to post or send explicit imagery of employees in places online designed to be seen by the organization and its customers, such as social media platforms or, as in the scenario reported in the WSJ, by group text. Much the same as threat actors who plan spear phishing attacks, sextortionists do their research in order to understand and leverage their victims’ connections. The result could be a demand to the organization for large sums paid in cryptocurrency, in exchange for keeping the images fake though they may be, out of the public eye.

In addition to facing an extortion demand and the risk of harm to the brand and reputation, organizations also need to consider the impact on the victim employee(s). These kinds of attacks can cause the subject employees severe emotional distress distracting them from their job. The employee’s personal and business accounts, including email, also may have been compromised, helping the threat actor to expand the impact of the attack.

Are You Prepared?

Many organizations have robust cybersecurity protocols for protecting corporate systems, but far fewer address the human side of digital exploitation. Here are the questions every organization should be asking today:

  • Do your employees know what sextortion looks like? Many people still assume they aren’t targets because they aren’t wealthy or famous. The reality is that these AI-driven scams are automated and opportunistic— no one is too small a target. Consider updating your training programs to address this threat.
  • Does your security awareness training cover AI-generated threats? Traditional phishing training may not address the emotional manipulation involved in sextortion or the use of deep-fake technology to create convincing explicit images.
  • Do your employees know what to do if it happens to them? Experts, including the FBI, advise victims not to pay, to block and report the scammer to the FBI’s Internet Crime Complaint Center, and to immediately change passwords and end unknown device sessions. Does your organization have clear guidance or an employee assistance program that covers this type of incident?
  • Are you encouraging good digital hygiene? Simple steps—setting social media accounts to private, using strong and unique passwords, and enabling two-factor authentication—can significantly reduce exposure.
  • Does your incident response plan address this threat? Preparedness is critical for any significant business threat. In addition to ensuring there is a clear path for employees to report these incidents confidentially, whether they occur through personal or corporate channels, businesses should expand their incident response plan. They also should practice how they might respond to such an attack, which would know knowing what resources they have to provide support for the organization and affected employees. 

The Bottom Line

AI is supercharging old scams into something faster, more convincing, and more invasive. Sextortion is no longer a risk that only affects teenagers or public figures. It can reach anyone through any group chat, at any time. Organizations should consider this risk and improve preparedness.

A broad coalition of artificial intelligence developers, cybersecurity companies, financial institutions, technology providers, and other organizations has issued an open letter calling for a coordinated effort to strengthen cyber defenses.

“We have a limited window to strengthen cyber defenses.”

The letter warns that AI-enabled cyberattacks have become more widespread and sophisticated. At the same time, it argues that advances in AI can help defenders identify vulnerabilities, remediate weaknesses, and respond to incidents more efficiently. Importantly, the letter points to several industries facing significantly higher levels of risk for organizations in those industries and the sometimes many thousands or millions of people they serve, e.g., critical infrastructure, manufacturing, supply chain, utilities (water), health care.

The signatories propose three overarching principles:

  1. Recognize that existing security practices may no longer be sufficient;
  2. Expand access to AI-enabled defensive capabilities; and
  3. Build a collective response involving businesses, technology providers, governments, and frontier AI companies.

While not a new recommendation, the letter calls for cybersecurity to become an “immediate leadership priority.” It advocates that particular attention be given to high-risk vulnerabilities, least-privilege access, strong authentication, layered defenses, and security standards for technology that organizations purchase, develop, or deploy. In short, the letter suggests that the measures for achieving the standard of “reasonable safeguards” may have changed as the threat landscape rapidly evolves, and so too must the measures for safeguarding assets from those threats.  What constitutes “reasonable safeguards” is now a fast-moving target.

For those responsible for cybersecurity preparedness and incident response, the letter reinforces an important point: Organizations should not view AI defense as simply a technology-acquisition project. It is a governance, legal-risk, and operational-resilience issue. New tools will not compensate for unclear responsibility, incomplete asset inventories, weak vendor oversight, or incident-response plans that have never been tested. Organizations also should evaluate AI security tools carefully, including what data the tools collect, where that data is stored and how it is safeguarded, how model outputs are validated, and whether contracts appropriately allocate responsibility for security incidents.  

Taking these steps, among others, will help organizations make the best use of this limited window to strengthen their cyber defenses, positioning them as less vulnerable targets for AI-powered cyberattacks and to defend themselves against the class action lawsuits that are likely to become even more prevalent as these attacks gain steam. 

Artificial intelligence is rapidly transforming human resources operations. From AI-powered recruiting platforms that screen résumés and rank candidates, to onboarding tools that personalize new-hire experiences, performance management systems that predict attrition, identity verification solutions using biometrics, and platforms administering ERISA-governed benefit plans, employers are increasingly relying on third-party vendors whose products are built on or enabled by AI. For labor and employment lawyers, this shift demands a fresh look at how we negotiate and structure vendor agreements.

While most states have not yet enacted AI-specific employment legislation, all employers deploying such technologies should pay careful attention to the terms in their AI vendor agreements. A patchwork of state laws is emerging across the country, federal agencies are actively extending existing frameworks to AI, and even a vendor’s home-state obligations can shape the contractual landscape. This article offers a high-level overview of several key issues practitioners should consider when negotiating agreements with HR technology vendors that use AI.

Define What You’re Buying

Vendor agreements should clearly define service provided under the agreement, capturing not only products explicitly marketed as AI but also any service that includes, incorporates, or is based upon or enabled by artificial intelligence, including generative AI, and agentic AI systems that autonomously act and make decisions in response to prompts and other actions.

Equally important is defining the vendor’s obligation to disclose the nature and extent of its use of AI. Require that the vendor mark or otherwise identify for Customer in writing all deliverables that incorporate or derive from AI, and provide upon request, a full disclosure of the use of AI services in connection with the preparation of any deliverables. Similarly, consider requiring the vendor to notify the employer of a new AI use case, particularly when the current services do not involve AI. Without this transparency, employers cannot assess their own compliance obligations under emerging state and federal laws.

Data Ownership and Restrictions on Training

HR data is among the most sensitive information an organization holds. Vendor agreements should unambiguously establish employer ownership of all content, prompts, inputs, and—critically—all generated output, meaning results or derivative works created by the AI using the employer’s data. Perhaps most important, the agreement should expressly prohibit the vendor from using employer data to train, retrain, or improve its AI models without approval. This is not a theoretical concern—HR data used to train a general-purpose model could expose the employer to claims under data privacy laws and compromise confidential workforce information.

Bias Testing and Anti-Discrimination Protections

The risk of algorithmic bias is the headline issue for AI-driven decision making, particularly in certain areas including health care, housing, financing, and, of course, employment. A growing number of jurisdictions are imposing affirmative obligations on employers who deploy these tools.

New York City’s Automated Employment Decision Tool (AEDT) law, for example, requires employers to ensure an independent bias audit was conducted within the past year before using an AEDT for hiring or promotion decisions, and to publish a summary of the audit results. California’s Civil Rights Department regulations do not have an express bias audit requirement, but recognize that evidence of anti-bias testing or similar proactive efforts to avoid unlawful discrimination is relevant to defending a claim. A similar rule is present in Connecticut’s new AI law.

Because of these regulatory developments, and considering the extent to which organizations rely on vendors for these technologies, employers should negotiate the right to request and receive documentation of the vendor’s bias testing methodology, frequency, and results, and include contractual obligations for the vendor to maintain governance standards and validation procedures.

Cybersecurity Assessment and AI Incident Response

Before onboarding any AI vendor (or, really, any vendor that processes confidential or personal information), employers should conduct a thorough cybersecurity assessment, particularly where the vendor will process biometric data, health information, or other sensitive employee data. The agreement should require the vendor to maintain a written information security program that includes, without limitation, administrative, physical, technical, and organizational safeguards. The agreement also should establish a robust AI incident response protocol, requiring the vendor to notify the employer promptly in writing of any AI incident, and to take corrective action to remediate the issue and prevent recurrence.

Change Management

AI models are not static, they are updated, retrained, and sometimes fundamentally altered. A performance management tool that worked as expected last quarter may behave differently after a model update. Vendor agreements should require advance written notice of material changes to AI services, with enough lead time for the employer to assess potential impacts. The agreement should also grant the employer the right to test and validate changes prior to implementation and require the vendor to maintain appropriate version control, monitoring, and change management procedures throughout the lifecycle of the AI services.

Subcontractors and Third-Party AI Providers

Many vendors do not build their AI models in-house; they integrate third-party AI models or systems, APIs, and/or subprocessors. The agreement should require the vendor to disclose all third-party AI providers, including the nature and scope of their access to employer data. And, liability for those downstream risks to data should be made clear. Preferably, the vendors should remain liable for all acts and omissions of its subcontractors to the same extent as if the acts or omissions were those of the vendor.

Record Retention

Emerging AI laws are creating new recordkeeping obligations. Colorado’s AI Act, for instance, requires deployers to “maintain records to demonstrate compliance” for at least three years after the date of a consequential decision, which may include version identifiers, change logs, and documentation of mitigation changes. Vendor agreements should include record retention obligations that align with these requirements and ensure that the employer has access to the records it needs to demonstrate compliance.

Liability Allocation: Lessons from Colorado and Beyond

Liability allocation is where vendor negotiations often get most contentious. Colorado’s AI Act offers an instructive framework: it provides that liability in discrimination actions involving AI shall be “allocated based on relative fault” between developers and deployers. Colo. Rev. Stat. § 6-1-1707(2). Notably, the Colorado law:

shields a developer from liability when the developer’s covered AI tool is used by the deployer in the manner that was not intended, documented, marketed, advertised, configured, or contracted for by the developer.

In other words, if an employer repurposes an AI tool for a use the vendor never intended or contracted for, the employer may not shift liability to the vendor. For the deployer, managing the use of the tool to align with the services agreement (i.e., governance) will be critical.

This statutory framework underscores the importance of clearly defining the permitted use of AI services in the vendor agreement and having the governance structure to abide by those provisions. A strong indemnification clause should cover claims arising from allegations that the AI service or its output infringes third-party intellectual property rights, privacy and security has been breached, and breaches of AI-specific obligations.

Looking Ahead

The regulatory landscape for AI in employment is evolving rapidly. Connecticut’s new AI law takes effect in October 2027 and will require employers to provide certain disclosures, including the purpose of the technology, the categories of personal data analyzed, and the data sources used. California’s CCPA automated decisionmaking regulations, with a compliance deadline of January 1, 2027, will require pre-use notices, opt-out mechanisms, and risk assessments. 

For employers, the message is clear: the critical role vendors play in AI deployment, together with the combination of multi-state compliance obligations, federal agency guidance, the risk to personal information, and the sheer pace of AI adoption in HR, means that vendor agreements are a foundational component of compliance and risk management. Taking the time to negotiate comprehensive, AI-specific terms today will pay dividends when, not if, the regulatory and litigation landscape catches up.

Senate Bill (SB) 1130, legislation that would establish criminal penalties for certain uses of wearable recording devices, continues to move through the California legislature. I’ve had the honor of discussing this measure with staff of the bill’s sponsor, California State Senator Eloise Gómez Reyes, and anticipate there will be more efforts to enact laws seeking to impose measured responses to the privacy, security, and other challenges posed by the latest generation of AI-enabled wearables.

The Rise of AI-Enabled Smart Glasses

SB 1130 arrives at a critical moment. Modern AI glasses blend high-resolution cameras, always-on microphones, and real-time AI assistants into a hands-free wearable that can capture, analyze, and even transcribe ambient information around the wearer. Unlike traditional recording devices that require deliberate action, AI glasses and similar wearables can passively capture and transcribe conversations throughout the day, creating permanent searchable records of discussions that participants never knew were being documented.

Several institutions and organizations have taken steps to minimize the impact of these devices. For example, in July 2026, New York became the first state to prohibit AI-enabled smart glasses in all state courthouses. Outside the U.S., in August 2026, England and Wales followed suit when His Majesty’s Courts & Tribunals Service (HMCTS) announced that AI glasses will be confiscated from anyone entering its judicial buildings. The UK has also seen its first criminal prosecution involving smart glasses, with a guilty plea for voyeurism at Warrington Magistrates’ Court after a man recorded sex with a woman without her consent using smart glasses.

As we explored in our four-part series on AI glasses, “The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses,” these devices no doubt raise compliance issues spanning biometrics, two-party consent, workplace surveillance, labor law, data security, and third-party AI processing risks.

What SB 1130 Would Do?

Specifically, SB 1130 would make it a misdemeanor to operate a wearable recording device to capture sound or video of another person in any area within a place of business where that person has a reasonable expectation of privacy, without their explicit consent. Penalties include up to one year in county jail, a fine of up to $1,500 per violation, or both.

The bill also targets the circumvention of recording indicators such as small lights or sounds that signal a device is actively recording. Disabling an indicator would itself be a misdemeanor, and the manufacture, sale, or use of technology primarily designed to disable recording indicators would carry civil penalties of up to $2,500 per violation.

What is a wearable recording device?

SB 1130 defines wearable recording device to mean:

“any device that is designed to be worn on or attached to the body, rather than held by the user, that has the capacity to make sound or video recordings or to transmit sound or video to another device or to the internet.”

This definition likely would capture a broad array of devices beyond AI glasses. However, recent amendments adding “rather than held by the user,” potentially indicate an intention to avoid capturing smartphones, which generally are not designed to be worn or attached to the body (parents of 13-17 years old children may disagree) and typically are held by the user.

What is a place of business?

SB 1130 defines a place of business to mean:

“any physical office or retail establishment in which members of the public receive goods or services from the business.”

What is a reasonable expectation of privacy?

It is not clear at this point and may never be. While walking down a public sidewalk in California does not generally give rise to a reasonable expectation of privacy for visual observation, California law can be more protective than many other states when it comes to audio recording of conversations, targeted or technologically enhanced surveillance, and publication of private facts, even when the underlying events occurred in technically “public” spaces. The context, the nature of the information, and the technology used all matter.

This may be why SB 1130 focuses specifically on places of business where a person has a reasonable expectation of privacy, rather than attempting to regulate all public recording.

Are there provisions which would affect some employees directly?

The bill carves out of the definition of wearable recording devices:

“a headset, two-way radio, or similar device that is operated by an employee during the normal course of their business duties and is provided by their employer for that purpose.”

This description potentially includes positions such as call center representatives and order processors at some fast food restaurants. While providing some relief from its reach, SB 1130 also provides that employees who record sound or video of a customer using such devices must inform the customer that they are being recorded. So, in addition to assessing the implications of more cutting-edge technologies entering the workplace, some employers may need to revisit how their employees use more traditional recording equipment.

What comes next?

SB 1130 has not yet been enacted and must still clear the full legislature and receive the Governor’s signature. But the trajectory is clear: California is moving to close the gap between legacy wiretapping statutes and modern wearable technology and, as noted, it is part of a global trend.

We will continue monitoring SB 1130 as it moves through the legislative process. In the meantime, if you have questions about this bill or related issues, contact a Jackson Lewis attorney to discuss.