For much of the past two years, discussions regarding generative artificial intelligence (AI) in professional services seems to have focused on lawyers, and perhaps for good reason. Courts have sanctioned attorneys who submitted briefs containing fabricated case citations. In response to these and other mishaps, several state bars issued ethics opinions often applying existing professional
Governance, Risk, and Compliance
AI Glasses Not a Good Look in New York Courthouses
New York has become the first state to prohibit AI-enabled smart glasses and other recording-enabled eyewear in all state courthouses. The new policy reflects growing concern over the ability of these devices to discreetly capture audio, video, photographs, and AI-generated transcripts. Below are answers to some common questions about the new rule and what it…
Is a CCPA Risk Assessment Required When Using AI-Powered Hiring and Screening Tools?
Key Takeaways
- Examines how AI-driven hiring and applicant screening tools interact with the CCPA’s new risk assessment requirements.
- Identifies the CCPA risk assessment triggers most likely to apply—including automated decision-making and systematic observation of applicants.
Artificial intelligence has made significant inroads into the hiring process. Employers increasingly rely on AI-driven tools to screen resumes, analyze…
The Delve Scandal: Why a SOC 2 Report Can’t Be a “Check-the-Box” Exercise for Vendor Management
A recent Inc. article highlights an unsettling controversy involving Delve, a Y Combinator-backed compliance startup, and allegations that strike at the heart of how organizations rely on SOC (System and Organization Controls) 2 reports which evaluate an organization’s internal controls over security, availability, and privacy.
According to the report, a whistleblower investigation alleges that Delve…
AI Meeting Assistants and Biometric Privacy: Governance Lessons from the Fireflies.AI Lawsuit
A putative class action filed in December 2025 in the U.S. District Court for the Central District of Illinois offers a reminder that AI meeting assistant and transcription tools potentially carry significant legal exposure when organizations deploy them without appropriate governance guardrails in place. It also serves as a reminder to apply strong governance principles…
The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 4: Data Security, Breach Notification, and Third-Party AI Processing Risks
The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 3 –Privacy, Surveillance, and Labor Law Violations
As we have discussed in prior posts, AI-enabled smart glasses are rapidly evolving from niche wearables into powerful tools with broad workplace appeal — but their innovative capabilities bring equally significant legal and privacy concerns. In Part 1, we addressed compliance issues that arise when these wearables collect biometric information. In Part 2…
The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 2 – Two-Party Consent and AI Note-Taking
As we explored in Part 1 of this series, AI-enabled smart glasses are rapidly evolving from niche wearables into powerful tools with broad workplace appeal — but their innovative capabilities bring equally significant legal and privacy concerns. Modern smart glasses blend high-resolution cameras, always-on microphones, and real-time AI assistants into a hands-free wearable that can…
The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 1 – Biometrics
Smart glasses with AI capabilities have evolved from futuristic concept to everyday reality. The market exploded in 2024, with global smart glasses shipments surging 210% year-over-year, driven primarily by Meta’s Ray-Ban smart glasses. From the consumer-focused Meta Ray-Ban Display (featuring a built-in heads-up display announced in September 2025) to Meta’s partnership with Oakley for…
The Hidden Risks of Information Disclosure: A Costly Lesson from Cornwall
When Royal Cornwall Hospital responded to a routine Freedom of Information request in 2023, they had no idea they were about to expose sensitive staff data to the public. The hospital recently apologized after discovering that a spreadsheet published on their website contained hidden sickness absence data for 8,100 current and former employees spanning three…