The second quarter of 2026 marked another period of pivotal impact to our U.S. state privacy, AI, and data governance landscape. Louisiana and Vermont joined the roster of states enacting comprehensive consumer privacy laws, while existing laws substantively amended their comprehensive consumer protection frameworks and threshold applicability. Meanwhile, regulators continued to shape the application of these laws through new enforcement actions and guidance. Most notably, California reached a record $12.75 million settlement under the California Consumer Privacy Act (CCPA), underscoring the importance of data minimization and purpose limitation principles and reinforcing regulators’ heightened scrutiny of sensitive precise geolocation data.
Our spring and early summer also highlighted a broader trend toward more targeted areas of regulation. States continued to expand oversight of the data broker ecosystem through new registration, reporting, and consumer rights requirements, reflecting growing scrutiny over the commercialization of personal information. At the same time, AI legislation is moving toward frameworks regulating specific AI use cases and areas of targeted risks, such as employment-related AI technologies and companion chatbots.
This quarterly update examines these developments and the broader trends that they signal: increased scrutiny of the use of sensitive data, growing accountability for secondary uses of personal information, an expanding patchwork of obligations for data brokers, and a shift toward risk-based AI governance. Together, these developments highlight the need for organizations to maintain adaptable compliance programs capable of responding to a complex and rapidly evolving regulatory landscape.
State Privacy Law Updates
Our Q1 State Privacy blog post eloquently previewed Oklahoma’s consumer privacy law and the Alabama Personal Data Protection Act, both of which remain on the horizon, with effective dates of January 1, 2027, and May 1, 2027, respectively. The Louisiana Data Privacy Act and the Vermont Data Privacy and Online Surveillance Act have since joined the ever-expanding U.S. state privacy law map, with their states becoming the 22nd and 23rd in the U.S. to adopt omnibus consumer privacy laws. While both laws share many features common to existing state privacy frameworks – including consumer rights, transparency obligations, and data protection assessment requirements – they also introduce unique provisions that warrant careful attention.
Louisiana’s law takes effect on January 1, 2027, and includes a 30-day cure period that will be in effect until July 31, 2027. Vermont’s law offers a longer runway for compliance, with an effective date of January 1, 2028, and a 60-day cure period that would remain in effect until June 30, 2029. Notably, Louisiana departs from the approach adopted by most other states when determining applicability of its privacy law. Rather than relying primarily on a consumer data processing threshold, this law incorporates a $25 million revenue threshold factor, mirroring a California-style revenue trigger in determining coverage.
Another interesting feature of both laws is the adoption of a requirement to obtain consumer consent before “selling” sensitive personal data, separate and apart from the common requirement to obtain consent for processing sensitive personal data – perhaps signaling a trend toward the stricter regulation of data monetization of sensitive data. In the case of Louisiana, this consent requirement applies to more limited entities that derive significant revenue based on the commercial sale of personal data, as opposed to Vermont’s broader application of this requirement, positioning Vermont as a leader of stronger consumer privacy rights in this space. In addition to its consent requirements, another notable feature is Vermont’s lack of a broad nonprofit exemption. As a result, Vermont joins the growing list of states (including Colorado, Delaware, Maryland, Minnesota, New Jersey, and Oregon) whose privacy laws limit or exclude exemptions toward nonprofits, signaling a broader trend toward narrowing traditional nonprofit carve-outs from state privacy laws.
Several other states had noteworthy amendments take effect on July 1, 2026, illustrating that legislatures continue to refine existing law. Maryland’s amendment (HB 0711) to the Maryland Online Data Privacy Act redefines sensitive data and implements a ban on personal data sales to immigration-enforcement government units, in addition to prior bans on selling sensitive data. Tennessee’s SB 1735 amended the Tennessee Information Protection Act, which tightened its definition of biometric data to no longer exclude “data generated from a photograph or video or audio recording.” Virginia’s Consumer Data Protection Act was amended (SB 338) to ban the sale of precise geolocation data. Notably, in Virginia, “sale” is defined to only constitute monetary consideration, unlike states that allow monetary or other valuable consideration. Finally, Connecticut’s amendment (SB 1295) to the Connecticut Data Privacy Act implemented multiple changes, including lower applicability thresholds, moving from 100,000 consumers to 35,000 consumers, and enhanced protections for minors, such as implementing an actual knowledge standard on controllers barring processing of a minor’s personal data for profiling. Connecticut’s governor also signed an amendment (SB 4) that includes data broker provisions, discussed below, in addition to requiring the commissioner of consumer protection to establish an accessible deletion mechanism program and banning surveillance pricing outside of a limited exception for insurance and financial institutions.
In consumer health data news, Vermont’s new law contains broad consumer health data provisions that apply to entities conducting business in Vermont or targeting Vermont residents without any minimum processing threshold, unlike the law’s general provisions. Meanwhile, in New York, the much-contested New York Health Information Privacy Act has been reintroduced and, as of June 2026, has passed both the New York Senate and Assembly as a revised bill (S.9269), following Governor Hochul’s veto of the original version in December 2025. While the revised bill has modified certain controversial provisions, if enacted, its regulation of non-HIPAA-covered health data would have a significant impact on the health tech industry and beyond.
Enforcement Shaping the State Privacy Landscape
On May 8, 2026, California regulators announced a $12.75 million settlement with an automaker and its connected vehicle services affiliate over allegations that they sold California consumers’ driving and geolocation data to data brokers. The settlement is the largest penalty under the CCPA to date. According to the complaint, the automaker collected and retained personal information from hundreds of thousands of its connected vehicle service users, including driving behavior and precise geolocation data. Precise geolocation data is considered sensitive under all state comprehensive privacy laws because it reveals detailed information about a consumer’s movements and activities. In the past year, this heightened sensitivity has resulted in states amending their laws to impose enhanced requirements or even outright prohibitions on the sale of consumers’ precise geolocation data.
Against this backdrop, California alleged that beginning in 2020 the automaker sold that sensitive information to data brokers developing driver-rating products for auto insurers, despite representing that driving and geolocation data would not be sold and that insurance-related disclosures would occur only at the consumer’s direction. The complaint alleged violations of several CCPA requirements, asserting that consumers were not informed of the sales, were not provided an effective opportunity to opt out, and were not given the right to limit the use and disclosure of their precise geolocation data before it was disclosed to a data broker. These allegations follow a series of CCPA enforcement actions targeting similar compliance failures.
Notably, California also framed the matter as a purpose limitation and data minimization case, alleging that consumers provided driving and geolocation data to obtain connected vehicle services – not to support insurance-related products – and that the automaker retained and disclosed the personal information beyond what was necessary for those services. This theory is similar to the state’s prior enforcement action against a health information website publisher, where regulators alleged that consumers visited the website to access health-related content but in the course of doing so also had their personal information disclosed to advertising partners in a manner that exceeded reasonable expectations and the purposes for which the information was collected.
This settlement reflects a trend of heightened regulatory scrutiny of sensitive personal information and indicates regulators’ interest in reviewing whether secondary uses of personal information (e.g., advertising, analytics, monetization, AI training, or profiling) are consistent not only with the disclosed purposes for which personal information is collected but also with consumers’ reasonable expectations. For businesses, the key takeaway is that compliance requires more than just accurate disclosures and functional consumer rights mechanisms; businesses must be prepared to justify why certain personal information is collected, retained, and shared.
Data Brokers
In Q2 2026, both Connecticut (SB 4) and New Jersey (Bill A5328) enacted new data broker laws and Vermont (H211) modified its existing data broker law. This marks the first passage of new state data broker laws since 2024. The passage of new laws and recent amendments indicates that states continue to prioritize regulation of data brokers.
Notably, Connecticut’s expanded data broker law is the second law to require the regulator (in this case, Connecticut’s Department of Consumer Protection) to develop a mechanism that allows all consumers to exercise their right to opt out. Previously, California was the only state that required consumers be offered a singular opt-out mechanism; California’s mechanism – the Delete Request and Opt-out Platform – is live and registered data brokers will need to begin complying with requests on August 1, 2026.
New Jersey’s data broker law makes waves as being the first law to tie registration costs to the volume of information that is brokered. As a result, registration costs can range from $5,000 (those that broker up to 100,000 consumers’ information) to $1.5 million (those that broker more than 4.5 million consumers’ information). As a result, New Jersey’s law imposes the highest registration fee under any state data broker law; the second-highest state registration fee is California at $6,000. Unlike other data broker laws, New Jersey’s law imposes obligations on data collectors, which are businesses that sell personal information to data brokers. Unlike data brokers, which by definition do not have a relationship with the consumer, data collectors collect personal information directly from a consumer and sell that information to data brokers. Like data brokers, data collectors will also need to register. Both data brokers and data collectors will be required to provide certain information during registration, such as prior cybersecurity events, and are banned from selling or licensing sensitive data. While the law took effect immediately, the Office of Consumer Protection issued an alert to clarify that companies will not need to register or pay fees until the spring of 2027, which will coincide with the launch of the registry.
Vermont’s data broker law, which was originally enacted in 2018, underwent significant amendments. One of the most significant changes was the broadening of the definition of “brokered personal information”; previously, the statute provided enumerated elements. The amended definition copies California’s definition by specifying that a consumer must intend to interact with a business; otherwise, personal information a business sells about the consumer that is collected outside of that intentional interaction may still be considered brokered personal information even if the consumer is a customer of the business.
The 2026 Q2 developments demonstrate that regulators are still focused on the data broker ecosystem, with states adopting broader definitions, centralized consumer rights mechanisms, higher registration costs, and more expansive obligations that can reach businesses beyond traditional data brokers. Current data brokers, and companies whose activities may qualify them as data brokers, should keep a careful eye on new laws and potential enforcement.
AI
Q2 2026 marked a notable shift in how states are approaching AI regulation. In particular, Colorado significantly reshaped its approach through SB 26-189, which repealed and substantially revised the Colorado AI Act before its effective date. The revisions came after a year of heavy criticism from businesses, industry groups, and other stakeholders that the original requirements under the Colorado AI Act were difficult to operationalize and overly broad, capturing a wide range of commonplace AI uses. Comparatively, the state comprehensive privacy laws regulate automated decision-making only when it is used to make decisions producing legal or similarly significant effects; the original Colorado AI Act imposed obligations across a much broader category of “high risk” AI systems. The revised law abandons many of the broad obligations in favor of focusing more narrowly on consequential decisions involving automated decision-making technologies and emphasizes transparency, consumer notice, and meaningful human review.
In contrast, Connecticut enacted SB 5, one of the most sweeping AI laws passed to date. Rather than regulating AI generally, SB 5 targets specific AI use cases and risks, including automated decision-making technologies used to make consequential decisions, AI-generated or synthetic content, AI companion systems designed for minors, developers of certain frontier AI models, and other specified contexts.
Many of SB 5’s requirements will take effect on a staggered basis between October 2026 and January 2028. Beginning October 2026, providers of subscription-based AI products must provide consumers with disclosures regarding key subscription terms before enrollment or renewal and obtain written acknowledgment of those terms. During 2027, SB 5 imposes governance and reporting obligations on developers of frontier AI models, or AI foundation models trained using more than 100 septillion (1026) computational operations. SB 5 requires that these select companies establish anonymous whistleblower reporting channels, investigate reports relating to catastrophic risks, implement corrective measures where appropriate, provide updates to reporting employees, and periodically report on such issues to company leadership. SB 5 was enacted subsequent to similar laws in New York (the RAISE Act) and California (the Transparency in Frontier Artificial Intelligence Act), which similarly require reports for transparency and safety incidence, governance requirements, and whistleblower protections.
SB 5 will also require that by 2027, AI companion systems implement safety protocols to identify and respond to expressions of self-harm, suicide, or violence; provide clear disclosures that users are interacting with AI; and incorporate additional protections for minors, including parental controls and restrictions on certain engagement-maximizing features. Similar laws have already been adopted in states such as California, New York, Oregon, and Washington, demonstrating a growing legislative focus on companion chatbot-specific harms.
In the employment context, SB 5 will require that by 2027, employers using automated employment-related decision technologies in hiring and other employment-related decisions must provide notice regarding the use of the technology, its purpose, the categories and sources of personal data analyzed, and other information concerning the system before using it to make or materially influence employment-related decisions. This approach resembles existing laws regulating AI in employment, including New York City Local Law 144, which requires bias audits and notice to candidates and employees before certain automated employment decision tools are used. Notably, Connecticut’s approach differs from New York City’s framework by focusing primarily on transparency regarding the use and operation of covered systems rather than mandating independent bias audits.
By January 2028, obligations related to synthetic or AI-generated content and online safety protection for minors will come into effect, completing SB 5’s phased implementation and reflecting a broader trend of existing AI provenance laws in California, Utah, and Washington that impose data provenance obligations on providers of generative AI systems. Collectively, these laws demonstrate a growing focus on synthetic media and content authenticity, with legislators increasingly favoring targeted transparency requirements intended to help consumers evaluate the origin and reliability of digital content.
States also continued integrating AI requirements into existing privacy laws. For example, amendments to the Connecticut Data Privacy Act now require controllers to disclose in their privacy notices whether they use personal data to train large language models. Notably, however, the amendment does not define either “train” or “large language model,” creating uncertainty regarding the scope of this disclosure obligation and how broadly it may apply.
Looking Ahead
The developments of Q2 2026 suggest that state privacy and AI regulation is moving into a more mature phase. Rather than introducing entirely new frameworks, states are refining existing laws, strengthening existing protections for sensitive data, imposing additional obligations on certain business models like data brokers, and addressing emerging technologies through targeted requirements. Enforcement is evolving as well. California’s record-setting $12.75 million CCPA settlement signals that regulators are looking beyond disclosures and consent mechanisms to examine whether data practices align with consumers’ reasonable expectations. As privacy laws mature and enforcement activity increases, organizations should expect greater scrutiny of sensitive data, secondary uses, and data sharing practices. Looking ahead, organizations should prepare for a regulatory environment that is increasingly interconnected across privacy, AI, and consumer protection. New state privacy laws, expanding data broker regimes, and targeted AI regulations are creating overlapping compliance obligations that require coordinated governance rather than siloed compliance efforts. Organizations that maintain ongoing oversight and adaptability with regard to their privacy programs and document the rationale behind these practices will be in the best position to manage ongoing regulatory change.