Trending Issues in State AI Regulation as Seen Through Connecticut’s Omnibus AI Law (SB5)
Earlier this year, Connecticut enacted its Online Safety Act (“SB5”), now retitled the Connecticut Artificial Intelligence Responsibility and Transparency Act (the “CART Act”), which represents one of the most wide-ranging omnibus state artificial intelligence (“AI”) and online-safety laws enacted to date. The broad multi-topic nature of the law contrasts with the recent state legislative trend of more targeted laws and regulations focusing on a particular context, specific digital risk, or broadly impactful player within the AI or online ecosystem. For example, Colorado’s revised AI Act now focuses exclusively on automated decision-making technologies, a number of states (e.g., Georgia, Iowa, Nebraska) have enacted laws focused on AI chatbots, and New York and California have been engaged in rulemaking to operationalize those states’ social media focused law.

South Carolina Takes a Hard Line on Age-Appropriate Design – Audits, Parental Controls, Employee Personal Liability, and More
The recently enacted South Carolina Age Appropriate Design Code Act (S.C. Code Sec. 39-80-10 et seq.) (the “Act”) has the potential to become one of the country’s most consequential privacy laws. It combines prescriptive privacy-by-design controls with restrictions on facilitating targeted advertising to minors under 18, and requires annual independent compliance audits and reports that are publicly posted, coupled with unusually aggressive penalties, including potential personal liability for officers and employees for “willful and wanton” violations. Unlike some other states’ privacy laws that have given entities time to make technical and policy changes before their effective date, South Carolina took a different route. The Act took effect immediately upon enactment in February 2026, and the first audit reports were required to be submitted to the South Carolina Attorney General by July 1, 2026. (more…)

There’s a New Sheriff in Town — Texas as Privacy Regulator
For many years, the privacy community took the position that the state of California was the leading data privacy regulator. The state of New York, with its active cyber enforcement by the New York Department of Financial Services, was a close second. However, in the past two years, Texas has emerged not only as a significant privacy regulator but also as an aggressive enforcer of its laws.

Children’s Privacy in 2026: From Australia’s Under-16 Social Media Ban to a Shift Beyond Notice-and-Consent in the United States
Recent developments in children’s privacy and online safety regulation reflect a global shift away from notice-and-consent frameworks toward access restrictions, design mandates, categorical advertising prohibitions, and ecosystem-level age-assurance mechanisms. Using Australia’s under-16 social media ban as a case study, this article examines four converging regulatory trends emerging across the United States, Europe, and the United Kingdom. These developments increasingly affect product design, advertising, and data governance decisions for companies operating consumer-facing digital services.
Reviewing The Legal Landscape Of Social Media For Minors
A Mid-Year Privacy Check-In – Important Developments and New Compliance Obligations for Privacy Laws
During the first half of 2025, state legislators and regulators have been working overtime to enact new data privacy laws and expand existing laws, all of which are likely to have an impact on businesses in the remainder of the year and into 2026. These efforts reflect key themes such as increased regulation of teen data and social media platforms, enhanced restrictions on the collection and sale of geolocation and biometric data, simplified opt-out mechanisms for tracking technologies, and broader obligations concerning consumer health data and data minimization. In parallel, significant regulatory activity surrounding AI has emerged, including a new federal AI Action Plan and proposed amendments to the CCPA addressing automated decision-making technologies, alongside a wave of new state AI laws.
Texas Age Verification Law Upheld: U.S. Supreme Court Balances Free Speech and Child Protection in the Digital Age
On June 27, 2025, the U.S. Supreme Court issued its opinion in Free Speech Coalition, Inc. v. Paxton, a groundbreaking decision with significant implications for online content regulation. The Court upheld a Texas statute — House Bill 1181 (HB 1181) — requiring commercial websites that host a substantial amount of sexually explicit material to verify users’ ages before granting access. In doing so, the Court applied intermediate scrutiny and upheld the statute as a constitutionally permissible measure to protect minors from harmful content.

Colorado Finalizes Privacy Act Rules: Key Updates for Businesses
The new year brings with it several state privacy law developments, including the effective dates for comprehensive privacy legislation in Delaware, Iowa, Nebraska, New Hampshire and New Jersey. Among this flurry of new state law obligations, however, privacy officers should not lose sight of continuing developments in states that helped pioneer the wave of state privacy laws, such as in Colorado.
The Legal Battles Taking Shape in the Clash Over Internet Content
A federal law known as Section 230 has provided a powerful legal shield for internet companies for nearly three decades. Designed to “promote the internet,” it protects platforms from civil liability for content posted to their sites by third parties.

Heightened Focus in the EU for the Protection of Minors Online
The protection of minors online continues to be a focus for EU regulators. Following the publication last year by the European Parliament of its guidelines on online age verification methods for children, the European Commission has recently announced it will be holding a dedicated stakeholder workshop in September 2024 to discuss guidelines for age verification and protecting minors. Whilst the issue has been flagged as a priority by the European Data Protection Board (“EDPB”) and we are seeing an increase in guidelines and (in some cases) laws addressing the issue at a national Member State level, this is also a focus of the new EU Digital Services Act (“DSA”).

