If you have heard of CIPA, BIPA, GIPA, or TCPA litigation, you may have an idea of where this post is headed. These acronyms reference federal and state laws that permit a private right of action for certain privacy-related claims, affording successful plaintiffs with statutory remedies. In a recent case, Bartholomew v. Parking Concepts, Inc., an appellate court in California may have opened the door to a new line of similar litigation stemming from a state law regulating automated license plate recognition (“ALPR”) technology.

What is ALPR?

Automated license plate recognition (ALPR) technology uses fixed or mobile cameras paired with computer algorithms to capture license plate images and convert them into searchable, computer-readable data.

Why is ALPR used?

Common uses include locating stolen vehicles, identifying wanted individuals, managing parking access and payment, supporting toll collection, investigating crimes, and monitoring access to secured facilities. For example, Flock, an AI startup that leverages ALPR technology, has been cited for helping to solve crime, albeit not without some controversy.

Is ALPR use becoming more common?

Yes. ALPR systems are often used in the public sector, usually by law enforcement, but private sector use cases have been increasing with parking operators, repossession companies, insurers, HOAs, retail/commercial property owners, and others, as noted in a recent Car and Driver article.

Are there federal requirements for ALPR?

No comprehensive federal ALPR statute exists, although some legislative efforts have been made to limit their use nationally. Regulation is primarily state-by-state, though federal privacy and surveillance law (e.g., Fourth Amendment case law limiting warrantless, prolonged tracking) can inform how ALPR data may be collected, retained, and shared, particularly by government users.

What states regulate ALPR?

At least 16 states have ALPR-specific statutes, including California, Arkansas, Colorado, Florida, Georgia, Maryland, Minnesota, Montana, Nebraska, and New Hampshire, among others. Roughly six of those states restrict private-sector or government use outright, about eight impose data retention limits, and several exempt ALPR data from public records disclosure.

What does California’s ALPR law require?

California’s ALPR statute (Civil Code §§ 1798.90.5–1798.90.55) applies to both government and private-sector “ALPR operators” and “ALPR end-users.” It requires:

  • Reasonable security safeguards (administrative, technical, physical) to protect ALPR information from unauthorized access, use, or disclosure.
  • A written, publicly available usage and privacy policy; if the entity has a website, posted conspicuously on that site.
  • The policy must address: authorized purposes for collecting/using ALPR data; job titles of personnel with authority to use and access the ALPR system; monitoring and audit procedures; rules on sale, sharing, or transfer of data; the custodian responsible for compliance; accuracy safeguards; and data retention/destruction timelines.
  • Public agencies generally may not sell, share, or transfer ALPR data except to another public agency.

Note also that California’s data breach notification law (Cal. Civ. Code Sec. 1798.82) provides that information or data collected through an ALPR system, if breached, could trigger a notification requirement.

Does failing to post an ALPR policy online create liability, even without a data breach?

Potentially yes, at least in California. In the Bartholomew v. Parking Concepts, Inc. case noted above, the court held that a parking garage’s camera system qualified as an ALPR system, and that operating it without a publicly posted usage and privacy policy violates an individual’s statutory “right to know,” which alone is sufficient to allege cognizable harm under Civil Code § 1798.90.54, although not every violation of the law will trigger relief for a plaintiff. The court reasoned:

“In other words, while the ALPR Law does not impose specific restrictions on the use of ALPR information, it grants individuals the right to know which entities are collecting their ALPR data and how it is being used and maintained.  Collecting and maintaining individuals’ ALPR information without implementing and making public the statutorily required policy harms these individuals by violating this right to know…  If an ALPR operator has failed to implement and make public the statutorily required policy establishing authorized uses, it is much more difficult to hold them accountable for unauthorized uses, even though this is an example of a harm-causing violation expressly stated in the ALPR Law.  This further underscores the significance of the publicly available policy to the ALPR Law’s statutory scheme”

What can a plaintiff recover under California’s ALPR law?

Section 1798.90.54 allows an individual “harmed” by a violation to sue any person who knowingly caused the harm, and recover: actual damages (or liquidated damages of at least $2,500 per violation), punitive damages for willful or reckless violations, attorney’s fees and litigation costs, and equitable relief.

Do any other states offer a private right of action or statutory damages like California?

Some do. For example, an Arkansas law (Ark. Code § 12-12-1807) permits a person injured in business, person, or reputation by a violation may sue for actual damages or liquidated damages of $1,000, whichever is greater, plus litigation costs. Nebraska (Neb. Rev. Stat. § 60-3208) allows a private suit for damages that proximately cause injury to business, person, or reputation, but sets no liquidated-damages floor. Washington’s new Driver Privacy Act (SB 6002) creates a civil remedy for an injured person and, for certain government contractors, treats violations as per se unfair/deceptive acts under the state Consumer Protection Act, which carries its own private right of action, treble damages up to $25,000, and attorney’s fees.

What steps should businesses take to comply with the California ALPR law?

  1. Determine whether any camera/software system used (including third-party parking, security, or access-control vendors) meets the statutory definition of an ALPR system.
  2. Draft a written usage and privacy policy covering all statutory elements (purpose, authorized personnel, monitoring/audit process, sharing restrictions, custodian, accuracy measures, retention/destruction schedule).
  3. Post the policy conspicuously on the company website, not merely buried in an internal manual.
  4. Implement reasonable administrative, technical, and physical security safeguards for ALPR data.
  5. Update incident response plans to include ALPR system data.
  6. Restrict data sharing and sale consistent with the policy and applicable law.
  7. Audit vendor contracts (parking operators, repossession firms, security vendors) to confirm their ALPR practices align with the business’s own compliance obligations.
  8. Monitor other states where the business operates, since requirements vary significantly by jurisdiction.

For much of the past two years, discussions regarding generative artificial intelligence (AI) in professional services seems to have focused on lawyers, and perhaps for good reason. Courts have sanctioned attorneys who submitted briefs containing fabricated case citations. In response to these and other mishaps, several state bars issued ethics opinions often applying existing professional obligations to AI such as technological competence, confidentiality, supervision, and billing. Those same themes, however, are increasingly relevant to other professional service providers, such as tax professionals, including employee benefit plan advisors in some cases.

When Do the IRS OPR Guidelines Apply?

The IRS has now made clear that ethics and compliance obligations extend well beyond litigation and the legal profession generally. In June 2026, the Internal Revenue Service’s Office of Professional Responsibility (OPR) issued Introductory Guidelines for Responsible AI Use in Federal Tax Practice (Alert 2026-19), explaining how existing Circular 230 obligations apply when tax practitioners, including attorneys, certified public accountants (CPAs), and enrolled agents, use generative AI. Specifically, the Alert arises out of IRS Circular 230 which governs practice before the IRS and establishes standards of competency, diligence, ethical behavior, and procedures for discipline. Rather than creating AI-specific rules, the Alert applies these existing obligations to the use of AI. It confirms an emerging regulatory principle likely to apply across virtually every licensed profession: AI may assist professional judgment, but it may not replace it.

The work of tax professionals extends well beyond Form 1040 preparation (individual federal tax return preparation). By way of example, professionals working on corporate tax issues, payroll taxes, estate taxes, and the qualified plan rules for employee benefit plans may all need to consider Alert 2026-19 when incorporating AI into their practice.  The Alert offers a roadmap for ethical AI use that such professionals can adapt when performing tax-related services and advising clients.

How Do The Guidelines Address Accuracy?

One of the central themes of the Alert is that AI-generated work must always be independently verified, a principle familiar to every practicing attorney.

When using GAI, practitioners must thoroughly review all AI-created documents and language incorporated into writings before delivery to a client or submission to the IRS. Due diligence requires verifying the accuracy of facts, citations, and calculations produced by AI. Practitioners cannot rely solely on AI; human scrutiny and editing are essential to ensure correctness and compliance with IRS expectations.

In short, AI-generated content should be treated as a draft requiring professional review rather than as a final work product, whether that content is a tax return filed with the IRS, a tax memorandum to the client, or a benefit plan communication addressing tax consequences.

How Do The Guidelines Address Competence?

The IRS also emphasizes that professional competence increasingly requires understanding the technology itself.

Practitioners must understand both the law and the technology used in their representation of clients before the IRS, including AI systems’ operational mechanics, limitations, and risks.

They must understand how AI develops content, recognize the potential for bias or errors, and be able to evaluate whether AI outputs are suitable for use in IRS matters. Lack of technological competence could lead to improper advice or flawed filings.

This mirrors a growing consensus among regulators and professional organizations that technological competence is no longer optional. Professionals need not become computer scientists, but they should understand:

  • when AI is appropriate to use;
  • when independent research or analysis remains necessary;
  • what information AI systems retain or transmit;
  • what risks exist regarding confidentiality and cybersecurity; and
  • how AI outputs should be validated before being relied upon.

Professional competence today increasingly includes the ability to use and supervise the use of AI effectively. The challenge of addressing AI “hallucinations” is not limited to litigation attorneys who fail to identify miscited or nonexistent caselaw. A Bloomberg Tax article, AI Hallucinations in Tax: The Risks and How to Mitigate Them, discusses several examples of AI hallucinations facing tax professionals:

Errors that silently compound across calculations. A single inaccurate assumption can flow through provision calculations, effective tax rate analyses, and disclosures without immediate detection. These errors can then distort financial reporting across entities, jurisdictions, and reporting periods.

Understanding the limitations of the technology is critical for all users and, in particular, for those with professional obligations.

How Do The Guidelines Address Confidentiality and Data Security?

The IRS guidance also underscores another issue rapidly becoming central to AI governance: protection of confidential client information.

Practitioners must strictly handle all client data using only secure, enterprise-approved AI. AI systems should be utilized with robust confidentiality safeguards firmly in place. Willful mishandling of taxpayer information through AI may lead to disciplinary actions under Circular 230.

Whether preparing individual tax returns, payroll taxes, or representing a client in connection with a tax audit of its qualified retirement plan, tax professionals very likely are processing their client’s sensitive confidential information, which may not be limited to personal information. Including such information in AI prompts or documents uploaded to an LLM can present significant risks to the confidentiality of that information. Among the questions organizations should consider are:

  • Has the AI vendor contractually agreed not to use prompts or uploaded information to train its models?
  • Is client data encrypted in transit and at rest?
  • Where is information stored?
  • Does the platform comply with applicable privacy laws and contractual confidentiality obligations?
  • Are employees prohibited from entering confidential client information into consumer AI platforms?

What Role Do Governance, Policies and Procedures Play Under the IRS Guidance?

The IRS makes clear that individual diligence is not enough on its own:

  • Firms must deploy internal policies and procedures for compliance with Circular 230 in the AI space, with coverage that includes:
    • Staff: Comprehensive training on use of AI (the risks, technological and otherwise, and the requirements).
    • Rules applicable internally (within the firm): Established protocols for secure data handling, AI accuracy monitoring, etc.
    • Contracting with external providers: Outsourced or third-party AI tools should be vetted.

Organizations that provide professional services, including law firms, accounting firms, consulting firms, engineering firms, benefit consultants, and healthcare providers should treat AI governance not merely as an IT initiative, but as an enterprise-wide professional responsibility. For example, policies governing approved AI platforms, employee training, confidentiality safeguards, validation procedures, documentation, and client communications are quickly becoming as important as traditional cybersecurity policies.

How Do The Guidelines Address Client Fees?

Perhaps the most interesting portion of the IRS guidance concerns professional billing.

Circular 230 prohibits unconscionable fees, and the OPR goes further, cautioning that billing should reflect any efficiencies AI brings to research, drafting, or analysis.

Practitioners should not only disclose, in general or specific terms as needed, the AI activities performed, but also fairly credit to the client’s account any cost reductions.

For example, if AI reduces an eight-hour task to two hours, firms should consider how that efficiency affects client billing—though the guidance does not address offsetting costs, such as AI licensing, training, and maintenance.

Looking Ahead

The IRS guidance is noteworthy not because it creates new obligations, but because it reinforces a broader reality. Generative AI is changing how professionals perform their work. It is not changing who remains responsible for that work. Whether the practitioner is a lawyer, CPA, enrolled agent, engineer, consultant, or another licensed professional, the emerging regulatory message is remarkably consistent: AI may be an extraordinarily valuable assistant, but it is not the professional of record nor a substitute for sound judgment.

The Alabama State Bar has joined a growing number of jurisdictions providing formal guidance on lawyers’ use of artificial intelligence. Formal Opinion 2026-01, Artificial Intelligence Use: Best Practices Under Existing Professional Conduct Rules, does not create new ethical obligations. Instead, it explains how longstanding duties under the Rules of Professional Conduct apply when lawyers use generative AI and emerging agentic AI tools in practice.

Below are answers to some of the most important questions for law firms and legal departments.

Why did the Alabama State Bar issue this guidance?

The opinion recognizes that AI has rapidly moved from an experimental technology to an everyday tool used to draft documents, summarize evidence, conduct research, analyze contracts, and communicate with clients. Rather than waiting for disciplinary issues to arise, the Alabama State Bar sought to explain how existing professional conduct rules govern these technologies.

Importantly, the opinion emphasizes that AI does not create new ethical duties. Instead, it “recontextualizes” existing duties—including competence, confidentiality, supervision, communication, candor, and reasonable fees—in light of AI-assisted legal practice.

Does the opinion prohibit lawyers from using AI?

No.

To the contrary, the opinion recognizes AI’s potential to improve efficiency, reduce costs, and expand access to legal services. Alabama acknowledges that AI is becoming an ordinary component of modern legal practice and that lawyers should understand both its benefits and its limitations.

The opinion also notes that as AI becomes more integrated into legal education and practice, technological competence increasingly includes understanding AI tools.

What are the most important takeaways for lawyers?

The opinion consistently returns to one central principle: Lawyers remain responsible for the final work product—even when AI assisted in creating it.

Among the practical expectations discussed are:

  • Verify all AI-generated legal analysis and citations.
  • Independently exercise professional judgment.
  • Protect confidential client information.
  • Understand how AI vendors process and retain data.
  • Supervise lawyers and staff using AI.
  • Communicate with clients when appropriate.
  • Ensure billing practices remain reasonable.
  • Develop firm-wide governance for AI use.

What guidance does the opinion provide regarding competence?

The opinion explains that competent representation now includes understanding how AI works sufficiently to appreciate both its capabilities and its risks.

Lawyers should understand issues such as:

  • hallucinated citations and factual errors;
  • incomplete or biased outputs;
  • limitations of predictive AI;
  • differences among AI platforms; and
  • circumstances requiring human review.

The opinion makes clear that blindly accepting AI-generated work is inconsistent with a lawyer’s duty of competence. Importantly, the opinion makes clear that:

“deploy[ing] an AI tool without basic due diligence on how that tool works and what it can get wrong has not satisfied Rule 1.1.”

In other words, failing to assess an AI vendor and its product could constitute a violation of the duty of competence.

What does the opinion say about confidentiality?

Confidentiality receives substantial attention. Before entering client information into an AI platform, lawyers should understand:

  • whether prompts are retained;
  • whether information may be used for model training;
  • who can access submitted information;
  • the vendor’s contractual commitments; and
  • the security controls protecting client data.

For many firms, this means AI can no longer be treated as simply another software application. Vendor due diligence, approved-use policies, and secure enterprise AI platforms are becoming increasingly important.

Can law firms have chatbots?

Yes, but. There is a lot to consider when developing and deploying a chatbot. For the Alabama Bar, it includes whether the chatbot “could cross into or facilitate the unauthorized practice of law (“UPL”)” and provides the following example:

Example. A law firm deploys a chatbot on its website that answers prospective clients’ legal questions in real-time. If the chatbot provides specific legal advice without flagging that it is not an attorney and without attorney review of its responses, this may constitute UPL—and the lawyer who deployed it may be responsible under Rules 5.5, 5.3, and 8.4.

What does the opinion say about billing?

The opinion reminds lawyers that AI should not become a vehicle for unreasonable fees. If AI substantially reduces the time required to complete a task, lawyers must continue to comply with the rules governing reasonable fees. Lawyers remain responsible for ensuring clients are billed appropriately and transparently regardless of how the work was performed.

How does Alabama compare with other states?

Alabama’s opinion generally aligns with the growing national consensus reflected in ABA Formal Opinion 512, which likewise concludes that existing ethical rules adequately govern lawyers’ use of AI. Other jurisdictions have reached similar conclusions while emphasizing different practical considerations.

Here are some examples:

  • Florida’s Opinion 24-1 similarly stresses competence, confidentiality, supervision, and verification of AI-generated work, while also adopting court rules addressing attorney responsibility for AI-generated filings.
  • North Carolina focuses extensively on client confidentiality, independent professional judgment, and supervisory responsibilities.
  • California’s practical guidance goes further into operational issues such as AI governance, vendor evaluation, and documenting internal controls for responsible AI use.
  • Georgia has published a practical AI toolkit emphasizing governance, education, and firm implementation rather than solely disciplinary analysis.

While terminology and emphasis differ, a clear national trend has emerged: state bars are not banning AI—they are requiring lawyers to use it competently, responsibly, and under appropriate professional supervision.

What should law firms do now?

The Alabama opinion should be viewed as more than an ethics opinion—it is a practical roadmap for AI governance. Law firms should consider:

  • inventorying approved AI tools;
  • developing written AI use policies;
  • implementing vendor due diligence procedures;
  • training attorneys and staff;
  • establishing review requirements for AI-generated work;
  • protecting confidential information through secure AI platforms;
  • documenting supervisory responsibilities; and
  • periodically reviewing AI governance as technology evolves.

For firms developing AI governance programs, Alabama Formal Opinion 2026-01 provides another authoritative reference confirming that successful AI adoption is no longer simply a technology issue—it is an issue of professional responsibility and sound law firm management.

New York has become the first state to prohibit AI-enabled smart glasses and other recording-enabled eyewear in all state courthouses. The new policy reflects growing concern over the ability of these devices to discreetly capture audio, video, photographs, and AI-generated transcripts. Below are answers to some common questions about the new rule and what it may signal for how organizations approach this technology.

Are AI Glasses Permitted in New York Courts?

Effective July 20, 2026, according to a memorandum by New York’s Office of Court Administration Executive Director, Justin Barry, on July 1, 2026, the New York State Unified Court System prohibits visitors from bringing smart glasses and other eyewear or headwear equipped with cameras, microphones, or other recording technology into any New York state courthouse. The prohibition applies to more than 1,200 state, county, city, town, and village courts throughout the state.

“This prohibition applies to all individuals entering court facilities, including litigants,
attorneys, witnesses, family members, UCS employees, and all other individuals who seek to enter a UCS facility for any reason.”

Why did New York adopt this policy?

The court system explained that AI-enabled smart glasses present unique challenges because they can record proceedings, conversations, and participants without being readily apparent to others. The statewide rule is intended to reinforce existing prohibitions on unauthorized recording in court facilities and to protect the integrity of judicial proceedings, confidential communications, and courthouse security.

Are prescription smart glasses prohibited?

Yes. Individuals who wear prescription smart glasses are expected to bring a conventional pair of prescription glasses if they need to enter a courthouse.

Is New York the first state to take this step?

New York appears to be the first state to implement a statewide prohibition applicable to every state court. However, courts in other jurisdictions have already begun restricting smart glasses through local rules, courthouse policies, or individual judicial orders. As adoption of AI-enabled wearables accelerates, additional statewide restrictions would not be surprising.

Why should organizations care about a courthouse policy?

For starters, lawyers and litigants who are not aware, or think they will get a pass, may show up at court with prescription AI glasses. According to the memorandum, “no individual possessing smart glasses will be permitted to enter a UCS facility unless they voucher the smart glasses for safekeeping by uniformed personnel while the individual remains in the facility.”  Without a backup pair of conventional glasses, they will not be able to enter the facility and participate in their case.

The New York policy also reflects a broader trend. Organizations across many industries are recognizing that existing “no recording” policies often were not drafted with AI-enabled wearable devices in mind. Smart glasses may continuously capture audio, video, images, location information, and AI-generated summaries while appearing no different from ordinary eyewear.

What are the broader legal and compliance issues with AI glasses?

There are many. We summarized a range of issues in our four-part series examining the legal and practical implications of AI-enabled smart glasses:

  • Part 1: Biometrics, facial recognition, and emerging privacy concerns.
  • Part 2: Audio recording, wiretapping, and consent laws.
  • Part 3: Workplace privacy, surveillance, and labor law considerations.
  • Part 4: Cybersecurity, data governance, and incident response implications.

What are some terms an organization should consider including in a policy on these devices?

A short list includes:

  • Defining AI-enabled wearable devices covered by the policy;
  • Recording in the workplace;
  • Protection of confidential and proprietary information;
  • Attorney-client privileged communications;
  • Customer and employee privacy;
  • Visitor access policies; and
  • Appropriate use of AI-enabled technologies.

Are other organizations taking similar action?

Yes. Courts are only one example. Law firms, healthcare providers, schools, financial institutions, retailers, entertainment venues, and other organizations are evaluating whether to restrict or regulate AI-enabled smart glasses in sensitive environments. Some organizations have already prohibited their use in conference rooms, client meetings, secure facilities, or other locations where confidential information is routinely discussed.

What is the takeaway?

New York’s action demonstrates that organizations are beginning to move beyond generic recording-device policies and adopt rules specifically addressing AI-enabled wearable technology. As smart glasses become increasingly sophisticated and widely used, organizations should expect additional legislation, court rules, and organizational policies governing their use.

For organizations that have not yet evaluated the implications of AI-enabled smart glasses, now may be an appropriate time to review workplace policies, security protocols, and AI governance programs to determine whether they adequately address this rapidly evolving technology.

New York organizations using artificial intelligence should keep a close eye on two pending state bills that could create new notice and reporting obligations. Both bills have passed the Senate and Assembly, but as of June 25, 2026, neither appears to have been signed by the Governor. Still, they offer a clear signal that New York lawmakers are focused on transparency and workplace impact surrounding AI technologies.

The first bill, AB 3411B, would amend the General Business Law to require notices on generative artificial intelligence systems. The second, AB 9581B, would amend the Labor Law to require certain businesses to submit annual reports to the New York Department of Labor about how AI affects hiring and workforce decisions. Note, taking a different approach to tracking AI-related job loss trends, California recently announced the California AI-Unemployment Tracker (CAIT), a public tracker based on unemployment insurance claims.

Assembly Bill (AB) 3411B

AB 3411B would apply to the owner, licensee, or operator of a generative AI system. The bill defines a generative AI system as a class of AI models that are “self-supervised” and “emulate input data to generate synthetic content, including text, images, videos, audio, and other digital content.”

If enacted, the bill would require covered parties to “clearly and conspicuously” display a notice on the system’s user interface stating that outputs of the generative AI system may be inaccurate. Note the bill does not limit its reach to certain use cases, such as commercial or employment activities. The bill would take effect 90 days after becoming law.

Organizations that develop, license, operate, or deploy generative AI systems for employees, applicants, customers, or the public may need to evaluate whether their user interfaces include the required notice. This may include chatbots, applicant-facing tools, customer service systems, document-drafting tools, or AI-enabled decision-support platforms.

Failure to provide the required notice could result in a civil penalty of up to $1,000 per violation, with each user who does not receive the notice treated as a separate violation for each instance. Organizations using third-party AI tools should consider whether contracts clearly allocate responsibility for required notices, interface design, indemnification, and compliance updates.

If this law is passed, it will take effect on the 90th day after it is signed.

Assembly Bill (AB) 9581B

AB 9581B is more directly tied to employment compliance. It would apply to a “covered business,” defined as a business entity doing business in New York that either employs more than 50 people or is publicly traded.

Covered businesses would be required to report to the Department of Labor by March 1 each year regarding AI use during the prior calendar year. The report would need to address the impact of AI on hiring and the nature of the company’s AI use.

Required employment data would include estimates of the number of employees displaced, employees whose hours were reduced, employees hired or whose hours increased, and previously filled positions that the business chose not to refill because of AI. The report would also require information about the objectives of AI use, human oversight, frequency and length of use, use of AI with sensitive personal data, storage and access protections, and risk-reduction measures.

The Department of Labor would develop standard reporting forms and processes, and it could create additional reporting requirements. The Department would also prepare a public annual report using aggregate data, including analysis by sector, geography, and business size.

Noncompliance could be costly. A covered business that fails to report could face a civil penalty of up to $500 for each day it remains in violation. However, the bill provides a 90-day cure period after notice of violation, and penalties may be waived or reduced if the violation is cured to the Commissioner’s satisfaction.

If passed, this law will take effect immediately.

What Organizations in New York Should Do Now

Because both bills are still pending, there are no imminent mandatory action items. However, as legislatures in New York and across the country are working a wide range of measures to address AI, organizations would benefit from maintain a well-developed governance program, one that tracks the AI tools and technologies in use by the organization, as well as its service providers and vendors. This one step would put organizations in a strong position to quickly identify whether a new law affects them.

If you have questions about these or other laws about AI in the workplace, contact a Jackson Lewis attorney to discuss.

Vermont has passed Senate Bill 71, a comprehensive privacy law that will regulate how covered entities collect, use, disclose, sell, and protect personal data.

The law is scheduled to take effect on January 1, 2028.

To whom does the law apply?

The law applies to people who conduct business in Vermont or produce products or services targeted at Vermont residents and meet one of several thresholds during the preceding calendar year. A business may be covered if:

  • It controls or processes the personal data of at least 35,000 consumers (not counting personal data controlled or processed solely to complete a payment transaction);
  • Controls or processes the sensitive data of at least 3,000 consumers (not counting personal data controlled or processed solely to complete a payment transaction); or
  • Offers for sale the personal data of at least 3,000 consumers.

The Act also contains specific provisions for consumer health data, which seem to be in line with efforts in other states to fill perceived gaps in the protection of health data left by HIPAA. Those provisions apply more broadly to people conducting business in Vermont or producing products or services targeted at Vermont residents.

The law includes numerous exemptions, including for certain government entities, certain HIPAA-regulated entities and data, financial institutions and data subject to the Gramm-Leach-Bliley Act, Fair Credit Reporting Act activities, and other regulated or limited categories.

Who is protected by the law?

The Act protects “consumers,” defined generally as Vermont residents.

However, the definition excludes individuals acting in a commercial or employment context, including employees, owners, directors, officers, contractors, or representatives of an organization when their communications or transactions occur solely within that role.

The law also includes heightened protections for children and minors, such as restricting targeted advertising and the sale of personal data.

What data is protected by the law?

The Act protects “personal data,” defined broadly to include information that is linked or reasonably linkable to an identified or identifiable individual or to a device associated with such an individual. This includes derived data and unique identifiers but excludes deidentified data and publicly available information.

The law provides heightened protections for “sensitive data.” Sensitive data includes data revealing racial or ethnic origin, religious beliefs, sex life, sexual orientation, nonbinary or transgender status, citizenship or immigration status, health conditions, disability, or treatment. It also includes consumer health data, genetic or biometric data, children’s data, precise geolocation data, neural data, certain financial account credentials, and government-issued identification numbers.

What are the rights of consumers?

Under the law, consumers may require a controller to do the following:

  • Confirm whether the controller is processing the consumer’s personal data and accessing that data.
  • Correct inaccuracies.
  • Delete personal data.
  • Provide a portable and, where technically feasible, readily usable copy of personal data previously provided by the consumer;
  • Allow the consumer to opt out of processing for targeted advertising, sale of personal data, and profiling in furtherance of solely automated significant decisions; and
  • Provide a list of third parties to whom the controller has sold personal information. 

What obligations do controllers have?

Controllers have several duties, including:

  • Controllers must limit the collection of personal data to what is reasonably necessary and proportionate to disclosed purposes. Remember, data minimization.
  • They may not process personal data for a materially new purpose (other than what is reasonably necessary and proportionate in relation to the purposes for which the data are processed, as disclosed to the consumer) unless they obtain consent.
  • They also must maintain reasonable administrative, technical, and physical safeguards appropriate to the volume and nature of the personal data. For sensitive data, controllers generally must obtain consent before processing or selling the data.
  • They must provide an effective mechanism for consumers to revoke consent and stop processing within 15 days after receiving the revocation request.
  • Controllers also must avoid unlawful discrimination and refrain from discriminating against consumers for exercising privacy rights.
  • Controllers must maintain certain contractual terms with processors.
  • Controllers must provide clear, accessible (e.g., website homepage, app settings menu, etc.) privacy notices. Those notices must disclose, among other things, categories of data processed, processing purposes, consumer rights, categories of personal data sold to third parties, and the categories of those third parties, “clear and conspicuous” disclosures concerning targeted advertising, contact information, whether personal data is used to train large language models, and the date of the latest update.

Controllers must also provide secure methods for consumers to exercise their rights, honor qualifying opt-out preference signals, and conduct data protection assessments for certain high-risk processing activities, including targeted advertising, sales of personal data, sensitive data processing, and certain profiling.

How is the law enforced?

The Vermont Attorney General enforces the Act. The law does not create a private right of action, meaning consumers generally may not sue directly for violations under the Act.

The Attorney General must provide guidance to controllers and processors and submit annual reports to the General Assembly regarding enforcement activity. During the period from January 1, 2028, through June 30, 2029, the Attorney General must provide notice and a 60-day opportunity to cure when the Attorney General determines that a cure is possible before initiating an enforcement action.

If you have questions about Vermont’s new privacy law or related issues, please reach out to a member of our Privacy, AI, and Cybersecurity practice group to discuss.

With the Governor of Louisiana’s signature on Senate Bill 386, Louisiana becomes one of the latest states to enact a comprehensive consumer privacy law, joining more than twenty states that have adopted similar frameworks in recent years. Like laws in Texas, Virginia, Colorado, and other states, the Louisiana Data Privacy Act (LDPA) adopts a controller/processor framework, grants consumers rights over their personal data, and authorizes enforcement by the state attorney general rather than private litigants. The Act takes effect January 1, 2027.

To whom does the law apply?

The law applies to a person or entity that does business in the state and meets at least one of these thresholds:

  • Annual gross revenues over $25 million
  • Annually buys, receives, sells, or shares for commercial purposes the personal information of 75,000 or more consumers, households, or devices.
  • Derives 50 % or more annual revenues from selling consumers’ personal information.

Notably, Louisiana’s applicability thresholds differ from many recent state privacy laws that focus primarily on the volume of consumer data processed. Instead, the LDPA incorporates revenue-based thresholds similar to those found in California’s privacy framework, applying to businesses with annual gross revenues exceeding $25 million regardless of the amount of personal data processed.

The law does not apply to various categories, including state agencies, certain financial institutions, and GLBA-regulated data, HIPAA-covered entities and business associates, nonprofits, and institutions of higher education.

Who is protected by the law?

The law protects consumers, defined as Louisiana residents acting only in an individual or household context. The law expressly excludes individuals acting in a commercial or employment context.

Under the law, a child’s parent or legal guardian may exercise the child’s consumer rights on the child’s behalf.  

What data is protected by the law?

The law protects personal data, which is information that is linked or reasonably linkable to an identified or identifiable individual. It excludes deidentified data or publicly available information.

Under the law, “sensitive data” is protected and includes personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, citizenship or immigration status, genetic or biometric data used to uniquely identify an individual, personal data collected from a known child, and precise geolocation data. Businesses should pay particular attention to the law’s treatment of sensitive data. Like many recently enacted state privacy laws, Louisiana generally requires consumer consent before processing sensitive data.

What rights do consumers have?

Under the law, consumers may require a controller to do the following:

  • Confirm whether the controller is processing the consumer’s personal data and access that data;
  • Correct inaccuracies;
  • Delete personal data;
  • Provide a portable and, where technically feasible, readily usable copy of personal data previously provided by the consumer; and
  • Allow the consumer to opt out of processing for targeted advertising, sale of personal data, and profiling in furtherance of solely automated significant decisions. 

Controllers generally must respond within 45 calendar days, with one additional 45-day extension when reasonably necessary to such requests.

What obligations do controllers have?

Under the law, controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary for the disclosed purpose and must maintain reasonable administrative, technical, and physical security practices appropriate to the data.

Controllers must provide a reasonably accessible and clear privacy notice describing categories of personal data processed, processing purposes, how consumers may exercise rights and appeal decisions, categories of personal data sold, categories of third parties to whom data is sold, and request submission methods.

If a controller sells sensitive data or biometric data, it must have a specific notice to that effect.

A contract between a controller and a processor must address the processor’s data processing procedures with respect to processing performed on behalf of the controller. Similar to other state privacy laws, the LDPA requires such contracts to include certain provisions, such as:

  • clear instructions for processing data;
  • the type of data subject to processing;
  • the duration of processing; and
  • a requirement that the processor make available to the controller, on reasonable request, all information in the processor’s possession necessary to demonstrate the processor’s compliance with the requirements of the LDPA.

Controllers must also conduct and document data protection assessments for targeted advertising, the sale of personal data, certain risky profiling, the processing of sensitive data, and other activities. Controllers that already maintain privacy impact assessments under other state laws may be able to leverage existing compliance processes.

How is the law enforced?

The state attorney general may enforce the law. And violations shall constitute an unfair and deceptive trade practice pursuant to the Unfair Trade Practices and Consumer Protection law, excluding private rights of action. Note, however, that the LDPA provides a 30-day cure period that sunsets on July 31, 2027, providing organizations with a limited opportunity to address alleged violations during the law’s early implementation period.

Although the LDPA largely follows the increasingly familiar state privacy law framework, businesses should not assume existing compliance programs automatically satisfy Louisiana’s requirements. Organizations with multi-state privacy compliance programs should review their privacy notices, consumer rights request procedures, consent mechanisms for sensitive data, and data protection assessment processes before the law takes effect on January 1, 2027.

If you have questions about Louisiana’s new privacy law or related issues, please reach out to a member of our Privacy, AI, and Cybersecurity practice group to discuss.

Artificial intelligence has quickly become part of the modern lawyer’s toolkit. Attorneys are using generative AI platforms to assist with legal research, drafting, editing, and document review. While these technologies can improve efficiency, a growing number of court filings across the country demonstrate a significant risk: AI-generated hallucinations, including fabricated case citations, nonexistent authorities, and inaccurate quotations.

Recent sanctions decisions from federal and state courts have highlighted the problem. Judges have encountered briefs containing cases that do not exist, citations that do not support the propositions for which they are offered, and legal analyses generated by AI systems without adequate attorney verification. These incidents have reinforced a fundamental principle of legal practice: lawyers—not software—remain responsible for the accuracy of every filing submitted to a court.

Recognizing these concerns, the Florida Supreme Court has amended Florida Rule of General Practice and Judicial Administration 2.515 to establish a clear statewide standard governing representations made when documents are filed in Florida courts.

Florida’s New Rule

Effective June 15, 2026, Rule 2.515(d)(2) requires every signer of a court filing to represent that:

“the legal authorities identified exist and are accurately cited.”

The amendment applies not only to attorneys but also to self-represented litigants.

The Court’s action reflects growing concern about the use of generative AI tools that may produce authoritative-sounding but inaccurate information. In its per curiam opinion, the Court expressly noted that generative AI systems “can generate content that appears plausible but is in fact inaccurate, including fabricated or ‘hallucinated’ authorities.”

A Statewide Response to a Growing Problem

Florida is not alone in confronting AI-related filing issues. Courts throughout the United States have issued sanctions, show-cause orders, and standing orders addressing AI-generated errors in briefs and motions. Some judges have required certifications regarding AI use, while others have focused on counsel’s duty to verify all citations and legal authorities before filing.

Rather than adopting a patchwork of local requirements, the Florida Supreme Court chose a statewide approach. According to the Court’s commentary, the amendments were adopted

“principally to create a statewide, uniform replacement for varied circuit court administrative orders imposing disclosure and certification requirements about the use of artificial intelligence in filings.”

New Sanctions Authority

The amended rule also expressly authorizes courts to impose sanctions when a filing is inconsistent with the signer’s certification. The rule provides that sanctions may be imposed after notice and an opportunity to be heard and may include:

  • Reprimand;
  • Contempt;
  • Striking the document;
  • Dismissal of proceedings;
  • Costs;
  • Attorneys’ fees; or
  • Other appropriate sanctions.

Although courts already possessed various sanctioning powers, the Florida Supreme Court made clear that the new provision is intended to eliminate uncertainty regarding courts’ authority to address inaccurate filings in the AI context.

What This Means for Lawyers

The amendment does not prohibit the use of AI. Nor does it require attorneys to disclose every instance in which AI assisted with drafting or research. Instead, it reinforces a basic professional obligation that predates artificial intelligence: lawyers must independently verify the accuracy of the legal authorities cited in their filings.

As generative AI becomes more sophisticated and more widely used, attorneys should consider implementing safeguards such as:

  1. Independently reviewing every citation generated by AI tools.
  2. Confirming that all cited authorities actually exist.
  3. Reading the underlying cases rather than relying on AI-generated summaries.
  4. Verifying quotations, pinpoint citations, and procedural histories.
  5. Establishing firm policies governing AI-assisted drafting and legal research.
  6. Training lawyers and staff regarding the risks of AI hallucinations and citation errors.

The Continuing Duty of Professional Judgment

The Florida Supreme Court’s amendment serves as a reminder that technological innovation does not alter a lawyer’s fundamental duties of competence, diligence, and candor to the tribunal. AI may assist in the drafting process, but it cannot replace the attorney’s obligation to ensure that every legal authority presented to a court is real, accurate, and properly cited.

As courts continue to encounter AI-related filing errors, Florida’s approach may provide a model for other jurisdictions seeking to balance innovation with the integrity of the judicial process. The message is straightforward: use AI if you choose, but verify before you file!

Key Takeaways

  • Outlines key considerations for businesses using productivity management and monitoring platforms – such as, Teramind, ActivTrak, and Insightful – and whether their use may require a CCPA risk assessment.
  • Identifies the specific CCPA risk assessment triggers most relevant to such productivity technologies.

Productivity management and monitoring platforms have become a fixture of the modern workplace—particularly for remote and hybrid workforces. These tools can track application usage, keystrokes, website visits, active and idle time, and even capture periodic screenshots of employee screens. Some platforms go further, using artificial intelligence to generate productivity scores, assess engagement levels, and flag behavioral anomalies. Businesses subject to the California Consumer Privacy Act (CCPA) and deploying this type of technology, should carefully consider whether a risk assessment is required before or during that use.

The first question is always whether the CCPA applies to the business at all. If the business has not yet made that determination, our comprehensive CCPA FAQs is a helpful starting point. Assuming the CCPA applies, the next question is whether the specific processing activity at issue presents a “significant risk” to consumer privacy—the standard that triggers the assessment obligation.

Our earlier posts on CCPA risk assessment basics discuss when the CCPA risk assessment requirement applies and the general requirements for conducting and reporting a risk assessment. This post focuses specifically on productivity management and monitoring platforms.

What Do Productivity Management and Monitoring Platforms Do?

Modern productivity platforms vary considerably in their capabilities and configurations. At a minimum, many log which applications an employee uses and for how long. More sophisticated deployments capture screenshots at regular intervals, record keystrokes, monitor email and messaging communications, and track time spent on specific websites or documents. AI-enhanced platforms layer on behavioral analytics, producing output that can characterize an employee’s work patterns, predict disengagement, or rank individuals against their peers.

The breadth of data collected—and the degree to which it is processed automatically to draw inferences about individual employees—is precisely what makes these platforms significant from a CCPA risk assessment perspective.

Which CCPA Risk Assessment Triggers Apply?

The updated CCPA regulations, which became effective in 2026, identify specific processing activities that require a risk assessment. Businesses using productivity management and monitoring platforms should evaluate at least three of them:

First, the regulations require a risk assessment when a business profiles a consumer (which includes employees and contractors) through “systematic observation.” The term “systematic observation” is defined broadly to include “methodical and regular or continuous observation,” and expressly covers “video or audio recording or live-streaming” and “technologies that enable physical or biological identification or profiling.” Periodic screenshots, continuous application logging, and keystroke capture may fall within this definition. “Profiling” itself is defined to include “any form of automated processing of personal information to evaluate certain personal aspects… relating to a natural person,” specifically including analysis of “performance at work,” “reliability,” “predispositions,” and “behavior.” A platform that generates productivity scores or behavioral profiles may fall within this definition.

Second, to the extent a productivity monitoring platform uses automated decision-making technology (ADMT) to make or meaningfully contribute to significant decisions about employees—such as decisions about compensation, employment opportunities, or similar matters—a risk assessment may be independently required on that basis. Businesses should carefully examine whether the platform’s output is used in any formal or informal employment decision-making process.

Third, if the platform processes any “sensitive personal information” as defined under the CCPA—such as health information (e.g., inferences about mental health from behavioral data), or biometric data (e.g., keystroke dynamics used for identity verification)—that processing could independently trigger a risk assessment requirement. The regulations include a narrow exception for certain human resources functions such as payroll and benefits administration, but businesses should not assume that exception is broad enough to cover behavioral analytics or performance profiling. Also, remember that the CCPA excludes certain categories of personal information including protected health information covered under the Health Insurance Portability and Accountability Act (HIPAA) and medical information under the California Confidentiality of Medical Information Act (CMIA). Importantly, however, not all health and medical information is covered under these laws, and could be covered by the CCPA.

Other Federal and State Laws to Consider

The CCPA is not the only federal or state law to consider when deploying performance management and monitoring platforms. To fully address compliance, the business needs to take into account, among other things, the regulatory environment of the business, the data collected by the platform, and the features of the platform. By way of example, the platform could trigger laws regulating biometric data, the recording of conversations, and the safeguarding of health information.

What Should Businesses Do?

Businesses that have deployed—or are considering deploying—productivity management and monitoring platforms should begin with a thorough inventory of what data the platform collects, how that data is processed or analyzed, and what outputs or decisions flow from that processing. Where the platform involves systematic behavioral observation, AI-generated productivity profiles, or ADMT that contributes to employment decisions, a CCPA risk assessment should be considered.

For the procedural requirements of completing a risk assessment—including the required contents of the risk assessment report and the certification obligation to the CPPA—Part 2 of our risk assessment series provides relevant information.  

A recent federal court decision offers important lessons for businesses that use cookies, pixels, and other tracking technologies on consumer-facing websites. Although the court dismissed one federal wiretap claim with leave to amend, it allowed other privacy claims to proceed, including claims under California’s pen register statute and common law intrusion upon seclusion.

The case involved allegations that a company’s website began collecting visitor data immediately upon a user landing on the site, before the user had a meaningful opportunity to reject non-essential cookies via a consent banner. The plaintiff alleged that, despite selecting “reject,” certain information had already been collected and transmitted to third parties, including browsing activity, website interactions, device information, session data, user identifiers, and geolocation data.

The court found that these allegations were sufficient, at the pleading stage, to establish a concrete privacy injury for damages. Importantly, the court emphasized that privacy harms may depend on the sensitivity and nature of the information collected. Browsing history, user interactions, identifiers, and location-related information may, in some instances, be enough to support standing when allegedly collected without consent.

The decision also highlights that a plaintiff’s status as a privacy “tester” does not automatically defeat standing. While courts may scrutinize whether a tester genuinely expected privacy and indeed have declined standing when a tester’s expectations that their information would be accessed, recorded, and disclosed are met, this court accepted the allegation that the user had expressly rejected non-essential tracking, which supported a reasonable expectation that tracking would not occur.

For businesses, the most practical lesson is that cookie consent tools must work as promised. A banner that allows users to reject non-essential cookies may create risk if tracking begins before a user has an opportunity to review the banner or make a selection, or if third-party technologies continue to operate despite a rejection. Businesses should not assume that having a banner alone is enough; they should test whether it is operating as intended or represented.

The decision also underscores the need to understand what data third-party tools collect. Courts are increasingly willing to consider whether website tracking technologies may fall within older privacy statutes, including laws originally written for telephone-era tracking devices. That means businesses should carefully evaluate pixels, analytics tags, advertising scripts, session replay tools, and related technologies.

If you have questions about web tracking and privacy issues for your business, contact a Jackson Lewis attorney to discuss.