On June 2, 2026, Connecticut Governor Ned Lamont signed Senate Bill 5 into law, designated as Public Act 26-15 and also known as the Connecticut Artificial Intelligence Responsibility and Transparency Act (the “CART Act” or “Act”).1 The CART Act is among the most comprehensive state AI laws enacted to date, creating distinct obligations for
Ropes & Gray
For the world’s leaders in business and finance, Ropes & Gray’s global team of professionals has the industry savvy and legal experience to identify critical issues, solve problems and pave the way for clients’ success.
Ropes & Gray Blogs
Blog Authors
Latest from Ropes & Gray
Trump’s AI Cybersecurity Order: A Voluntary Framework with Mandatory Implications
On June 2, 2026, President Trump signed an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security” (the “Order”), which establishes a new framework for government collaboration with the AI industry on cybersecurity and the secure deployment of advanced AI models.1 While voluntary in form, the Order builds significant institutional architecture, including classified benchmarks…
Colorado Scales Back AI Law, with Targeted Implications for Health Care
…
China’s NMPA Issues Final Measures on Regulatory Data Protection
On May 15, 2026, China’s National Medical Products Administration (“NMPA”) issued the Implementation Measures for Drug Trial Data Protection (the “Measures”), effective immediately, to formalize China’s protection regime for eligible undisclosed chemistry, manufacturing and control (CMC) and clinical study data submitted in marketing authorization applications. The Measures define the eligible products, protection periods, application process,…
Supreme Court Reinforces Donor Privacy Protections, Permitting Immediate Federal Court Challenge to State Subpoena
On April 29, 2026, the United States Supreme Court issued a unanimous opinion in First Choice Women’s Resource Centers, Inc. v. Davenport, where it held that a nonprofit suffered an injury to its First Amendment right of association when it was subpoenaed by a state attorney general to produce donor information, including donor identities.1 Justice…
The European Data Protection Board Releases New Guidelines on the Processing of Personal Data for Scientific Research
For almost a decade, the scientific research provisions of the General Data Protection Regulation (GDPR) have lacked authoritative, European Union (EU)-wide interpretation, leaving sponsors of clinical trials and research institutions alike to navigate a patchwork of national implementing laws. A 2019 study commissioned by the European Data Protection Board (EDPB) — the body comprising EU…
Newsom Signs Executive Order Establishing AI Vendor Certification and Procurement Framework
On March 30, 2026, Governor Gavin Newsom signed Executive Order N-5-26 (the “Order”), directing California state agencies to develop new certification requirements and procurement standards for companies seeking to provide AI-enabled products or services to the state.1 The Order represents the latest move in an intensifying contest between California and the federal government over…
The White House Legislative Recommendations: National Policy Framework for Artificial Intelligence and Federal Preemption of State AI Laws
On March 20, 2026, the White House released its National Policy Framework for Artificial Intelligence (“Framework”), outlining legislative recommendations for Congress to establish a unified federal approach to AI regulation. The Framework builds on prior executive actions, including the December 2025 Executive Order (the “Executive Order”) and the Trump administration’s “America’s AI Action Plan,” and…
When Cyberwar Hits the Corporate Home Front
As recent events indicate, American companies may be the subject of destructive data “wiper” attacks and potential data theft by Iran-linked hackers. Ongoing tensions in the Middle East underscore the stark and evolving cyberthreat landscape facing companies. These types of cyberattacks blend the regulatory and litigation exposure of a traditional data breach with the extreme…
HHS OCR Announces Civil Enforcement Program for Confidentiality of Substance Use Disorder Patient Records
On February 13, 2026, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced its civil enforcement program to implement the updates to the Substance Use Disorder (“SUD”) confidentiality provisions of the regulation at 42 CFR Part 2 (“Part 2”).1 The new enforcement program became effective February 16, 2026,…