The Digital Download provides a quarterly snapshot of emerging issues at the intersection of privacy, cybersecurity, and data strategy. It brings together Alston & Bird’s thought leadership, publications, events, and firm news into a single, easy to navigate resource.
Publications & Advisories
- July 30, 2026 – Kim Peretti, Lance Taubin, and Alysa Austin published “Privacy, Cyber & Data Strategy Advisory | Autonomous Hacking: Planning for the AI Cyber Agent That Goes Rogue.”
- July 27, 2026 – Rachel Lowe, Dan Felz, Jonathan Kim, and Tray Yao published “Privacy, Cyber & Data Strategy Advisory | California SB 690 Reform Advances as CIPA Claims Persist.”
- July 10, 2026 – Jennifer Everett, Angie Burnette, and Jen Pike published “Health Care / Privacy, Cyber & Data Strategy Advisory | HHS Office for Civil Rights Delays Final HIPAA Security Rule Until 2027 as Privacy Rule Changes Near.”
- June 18, 2026 – Cynthia Cole, Maki DePalo, Jennifer Everett, and Christian Seremetis published “Privacy, Cyber & Data Strategy Advisory | State of the (Artificial) Union: A Midyear Review of U.S. AI Regulation, Enforcement, and Policy Trends.”
- June 16, 2026 – Courtney Quirós, Cynthia Cole, and Lex Mayo published “How Boards Can Shrink the AI Governance Gap” in Law360.
- June 1, 2026 – Kim Peretti, Lance Taubin, and Kristen Bartolotta published “Privacy, Cyber & Data Strategy Advisory | Five Risks GCs Should Know About Frontier AI and Cybersecurity.”
Selected U.S. Privacy & Cyber Updates
IBM’s 2026 Cost of a Data Breach Report Signals a New Era of AI-Driven Cyber Risk
IBM recently released its Cost of a Data Breach Report 2026, which highlights the changing cyberthreat landscape in which artificial intelligence (AI) is accelerating how threat actors identify vulnerabilities, launch attacks, and exploit compromised systems. These trends are reflected in rising average breach costs, with the global average cost rising 12% to a record $4.99 million and the U.S. average reaching $11.5 million, up 14% from last year. Drawing on a survey of 602 organizations that experienced a data security incident between March 2025 and February 2026, the report’s findings underscore the growing financial impact of both AI-driven and traditional cyberthreats.
CMMC Phase II Is Suspended, but Defense Contractors’ Cybersecurity Obligations Are Not
The Department of Defense has announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were scheduled to take effect on November 10, 2026. This announcement is significant because Phase II was expected to move CMMC toward more formal assessment requirements for many defense contractors and subcontractors.
The White House’s Gold Eagle Initiative Signals a New Phase in AI-Enabled Cyber Defense
The White House has launched “Gold Eagle,” a new cybersecurity vulnerability coordination clearinghouse designed to use advanced AI capabilities to accelerate how the government and industry identify, prioritize, verify, and remediate software vulnerabilities. The initiative was established under the June 2, 2026 Executive Order “Promoting Advanced Artificial Intelligence Innovation and Security” and is being framed by the White House as a new operational model for cyber defense.
DROP Is Coming Due: What California’s Delete Act Means for Data Brokers in August
Beginning August 1, 2026, data brokers must begin accessing California’s Delete Request and Opt-Out Platform (DROP) at least once every 45 days to retrieve and process consumer deletion requests as the consumer-facing launch transitions to operational obligations for data brokers. DROP allows California residents to submit a single deletion request to hundreds of registered data brokers through the platform rather than contacting each broker individually. California consumers have been able to submit requests to DROP since January 1, 2026.
GSA Seeks Input on Revised AI Data Safeguarding Clause for Government Contracts
On July 14, 2026, the General Services Administration (GSA) held a public listening session to gather stakeholder feedback on a revised draft General Services Administration Acquisition Regulation clause addressing the basic safeguarding of government data within large language model artificial intelligence systems. The session—part of the GSA’s second round of engagement on the draft clause—invited industry associations, companies, academics, and individual practitioners to comment on the clause’s strengths, weaknesses, and practical improvements. GSA officials emphasized that they were seeking specific, constructive, and actionable feedback to help craft an AI clause that protects the public’s data while enabling agencies to adopt AI quickly and with confidence.
In the Accellion data breach case, the Northern District of California has denied the plaintiffs’ motion to modify the court’s order on class certification. In its first class certification order, the court declined the plaintiffs’ request to certify a broad negligence class and instead certified several narrow subclasses. The court also rejected the plaintiffs’ proposed classwide damages model that attempted to measure the alleged injury to the class resulting from the disclosure of their personally identifiable information by the cost to purchase commercial identity theft protection products, finding that the plaintiffs’ proffered expert was not qualified to opine on that subject. The court therefore limited the class’s ability to recover to nominal damages.
Five Eyes Issues Urgent Call to Action on AI-Driven Cyber Threats
On June 22, 2026, the intelligence alliance known as Five Eyes released a statement warning that frontier AI models will fundamentally transform offensive and defensive cyber capabilities and that the timeline for this transformation is measured in months, not years.
DOJ Settles False Claims Act Case with LOGZONE over Cybersecurity Deficiencies
On June 18, 2026, the Department of Justice announced that it had reached a settlement with defense contractor LOGZONE Inc. in which the company agreed to pay $507,144 to resolve its liability under the False Claims Act for allegedly failing to comply with cybersecurity requirements. LOGZONE provides logistics, medical, training, and other services to the Department of Defense and government civilian agencies.
FTC Targets Edtech Data Practices in Final Order Following Major Student Data Breach
On June 5, 2026, the FTC gave final approval to a modified consent order against Illuminate Education Inc., a K–12 software vendor, settling allegations that Illuminate did not adequately protect the personal data of more than 10 million students. The action—which follows a public comment period and builds on a proposed order issued in December 2025—sends a clear signal to organizations handling student data, children’s information, and other sensitive personal records: The FTC expects security promises to be backed by real controls, and data retention and minimization practices are now squarely in the enforcement crosshairs.
New Executive Order Promotes AI Innovation While Strengthening Cybersecurity Defenses
On June 2, 2026, President Trump signed an Executive Order, “Promoting Advanced Artificial Intelligence Innovation and Security.” The Order reflects the Administration’s stated policy of advancing U.S. AI leadership through collaboration with the private sector, while taking steps to harden government and critical infrastructure systems against emerging cyberthreats. Importantly, the Order maintains the Administration’s approach of favoring voluntary, industry-collaborative mechanisms over mandatory regulatory mandates, expressly disclaiming any authority to create licensing, preclearance, or permitting requirements for the development or distribution of AI models.
Produce the Prompts: A Court Says Expert AI Inputs Are Fair Game in Discovery
A federal court just delivered one of the clearest messages yet on AI in litigation: If an expert used AI to do the work, the prompts may be discoverable. In Conservation Law Foundation Inc. v. Shell Oil Company, Magistrate Judge Thomas O. Farrish ordered the plaintiff to produce the prompts its expert used in preparing her report, treating them as part of the expert’s methodology rather than protected drafting material. That puts AI prompts squarely into the discovery fight.
Louisiana Delays App Store Accountability Effective Date to July 2027
On May 15, 2026, the Louisiana governor signed HB 977 into law, delaying the effective date of the Louisiana App Store Accountability Act (ASAA) by one year, to July 1, 2027. The amendments to the Louisiana ASAA come amid ongoing First Amendment challenges to similar laws in other states and resemble recent developments in Utah, where the Utah ASAA’s effective date was likewise postponed from May 6, 2026, to May 7, 2027.
NYDFS Issues Frontier AI Advisory and Guidance for Heightened Cyber Threat Environment
On May 21, 2026, the New York Department of Financial Services (NYDFS) issued two industry letters to the organizations it regulates: “Heightened Cybersecurity Risks Associated with Frontier AI Models” and “Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment.” The letters discuss various recommended security controls regulated entities should consider in light of a heightened cybersecurity threat environment (defined as a period when “cybersecurity risks are significantly elevated and therefore have a high likelihood of impacting Information Systems, Nonpublic Information or operations”) and in light of the threats presented by frontier AI models (defined as AI models that “amplify the potency, scale, and speed of identifying vulnerabilities and exploits in information systems”).
California Puts Social Media’s Youth Feeds on Notice
On May 14, 2026, California Attorney General Rob Bonta issued proposed regulations and opened a 45-day public comment period addressing compliance with the age determination and parental consent requirements of the Protecting Our Kids from Social Media Addiction Act, or SB 976. Enacted in September 2024, SB 976 is intended to protect users under 18 from addictive features on online platforms, including social media, by restricting operators of addictive internet-based services or applications from providing algorithmically driven addictive feeds or sending notifications during certain nighttime and school hours unless the operator has reasonably determined that the user is not a minor or has obtained verifiable parental consent. The proposed regulations, which the attorney general must adopt by January 1, 2027, seek feedback on how platforms should meet those requirements, with written comments due during the 45-day comment window and a public hearing scheduled for June 30, 2026.
May Flowers Bring Fresh Insight from CalPrivacy
On May 1, 2026, the California Privacy Protection Agency Board held a public meeting to review and discuss enforcement activities, legislative developments, and international data transfer issues.
Colorado Replaces Landmark AI Act—Creating New Trails for AI Rules and Private AI Litigation
On May 12, 2026, the Colorado legislature passed SB 26-189, which repeals and replaces its landmark Artificial Intelligence Act. Colorado is doing away with the concept of “algorithmic discrimination” and moving instead to a notice- and disclosure-based regime focused on automated decision-making. This time, it does so without a carve-out for deployers that are small businesses.
The Era of AI-Driven Data Breaches Has Arrived
A recent lawsuit signals the rapid convergence of issues relating to artificial intelligence, vendor‑managed platforms, and individual arbitration in the data breach ecosystem. In Woodard v. OpenAI Inc. & Mixpanel Inc., No. 3:25-cv-10301 in the Northern District of California, plaintiffs alleged that Mixpanel uses artificial intelligence technologies developed by OpenAI to collect user data. Mixpanel’s data collection came to a head in November 2025, when it was hit by a third-party criminal cyberattack that allegedly impacted consumers’ OpenAI accounts on the Mixpanel platform.
Selected Global Privacy & Cyber Updates
European Commission Publishes New Guidelines and Code of Practice on GenAI Transparency
On July 20, 2026, the European Commission published new Guidelines on Transparency of AI-Generated Content to complement the Code of Practice on Transparency of AI-Generated Content it released on June 10, 2026. The materials arrive just weeks before the AI Act’s transparency obligations take effect on August 2, 2026, and give businesses clearer direction on how to identify, label, and disclose AI-generated content in practice.
EU Regulators Outline GDPR Requirements for AI Web Scraping
On July 8, 2026, the European Data Protection Board, the body that coordinates the EU’s national data protection authorities, published its first draft of Guidelines 03/2026 on web scraping in the context of generative AI. The guidelines address practical compliance challenges for companies that develop AI models or systems and scrape personal data from internet sources to train generative AI, as well as companies that rely on third parties to carry out that scraping. They also matter for deployers and enterprise customers of downstream AI models and systems, including businesses using AI in EU-facing products, services, or operations.
Connected Vehicles Under the Spotlight: French DPA Issues Landmark Guidance on Vehicle Data Privacy
On 30 June 2026, the French Data Protection Authority published comprehensive new guidance on the processing of personal data generated by connected vehicles, with a particular focus on geolocation data. For automotive manufacturers, suppliers, and mobility companies with operations or customers in the EU, this 60-page guidance provides much-needed clarity on how to navigate EU privacy and data protection requirements that apply to vehicle-related data processing.
On May 19, 2026, the European Commission published draft guidance on how to determine whether an AI system qualifies as a high-risk AI system under Regulation (EU) 2024/1689 (AI Act). The draft reflects input from stakeholders and EU Member States through the EU AI Board and represents the most detailed interpretative material issued to date on this topic.
UK Cyber Security Breaches Survey 2025/2026: Key Takeaways
The UK government has published its 2025/2026 Cyber Security Breaches Survey, which is drawn from information received from thousands of UK businesses. The 2025/2026 survey paints a picture of a cyber threat landscape that is stable in its scale but shifting in its character. The publicity surrounding high-profile incidents has not yet resulted in a sustained economy-wide improvement in resilience. The resilience gap between larger organisations and smaller ones persists, and new risks arising from AI adoption are emerging faster than security practices can keep pace.
On April 1, 2026, the Dutch Data Protection Authority imposed a €100 million fine on MLU B.V., the Dutch operator of the Yango taxi app. The AP found that personal data of EU users was unlawfully transferred to affiliated entities in Russia, despite the formal use of the EU standard contractual clauses.
Events
- October 13, 2026 – Rachel Lowe will speak on the panel “Privacy and IR: Navigating the Latest State, Federal, and International Challenges,” and Lance Taubin will speak on the panel “Responding to Third-Party and Supply Chain Cyber Incidents” during Incident Response Forum West 2026.
- October 12 – 13, 2026 – Cynthia Cole will speak on the panel “Keeping Up With AI: The Latest Regulation and Governance,” and Kim Peretti will speak on the panel “Human in the Loop: An AI Crisis Tabletop” during the 2026 Artificial Intelligence and Robotics National Institute.
- September 16, 2026 – Cynthia Cole will moderate the session “Stepping Out and Lifting Others: Mentorship, Succession, and the Power of Intentional Exit Planning” during the WIPL Conference.
- August 31 – September 3, 2026 – Kim Peretti will speak on the panel “Beyond the Board Meeting: Building the Board Relationship That Makes AI Governance Work” during Fal.Con 2026: Securing the AI Revolution.
- August 26, 2026 – Our Privacy, Cyber & Data Strategy Team is hosting our Seventh Annual Privacy, Cyber & Data Strategy Summit. The summit will examine how organizations are responding to heightened regulatory scrutiny, emerging threats, rapid technological change, and growing expectations for collaboration across leadership teams.
In the News
- July 1, 2026 – Cynthia Cole is quoted on compliance reps and warranties in Anti-Corruption Report.
- June 25, 2026 – Cynthia Cole and Steve Ornstein are featured on the Structured Finance Association’s Bright Ideas podcast episode “AI Governance Comes into Focus for Housing Finance,” discussing how recent Fannie Mae and Freddie Mac AI governance frameworks could affect mortgage market participants.
- May 12, 2026 – Jennifer Everett is quoted in a Bloomberg Law article on a Department of Health and Human Services proposal to strengthen the HIPAA Security Rule by imposing tougher standards for safeguarding protected health information amid escalating cyber threats.
Press Releases
Lance Taubin Named a 2026 ‘Rising Star’ by the New York Law Journal
Lance Taubin, partner on Alston & Bird’s Privacy, Cyber & Data Strategy Team, has been named a 2026 “Rising Star” by the New York Law Journal for being among the best and brightest in New York’s legal community. He is one of only three attorneys honored in the Privacy, Cyber and Data Strategy/Litigation category.
Alston & Bird Gains New Honors in The Legal 500 US 2026
Alston & Bird is honored to be recognized in eight practice areas in the 2026 edition of The Legal 500 United States, including Media, Technology and Telecoms: Cyber law. Cynthia Cole is recognized as a Leading Partner in Technology Transactions, and Kim Peretti is recognized as a Leading Partner in Cyber Law.
Partner Cynthia Cole Receives 2026 Burton Award for Distinguished Legal Writing
Alston & Bird is pleased to announce that Cynthia Cole, partner with the firm’s Privacy, Cyber & Data Strategy Team, has received the 2026 Burton Awards’ “Law360 Distinguished Legal Writing Award.” Cynthia was recognized for her co-authored article, “Storytelling and the Art of Creativity: Who Holds the Pen?,” which was named among the most exceptional legal writing works published over the past year. This distinction underscores her broad expertise in the international legal nuances of artificial intelligence and intellectual property.
Chambers USA 2026 Broadens Recognition of Alston & Bird
Alston & Bird stood out in the 2026 edition of Chambers USA: America’s Leading Lawyers for Business, including recognition for the practice areas of Privacy & Data Security: The Elite, Privacy & Data Security: Litigation, and Privacy & Data Security: Healthcare. Kim Peretti is recognized for Privacy & Data Security: Cybersecurity and Privacy & Data Security: Healthcare. Kristy Brown and Rachel Lowe are recognized for Privacy & Data Security: Litigation.
“The Digital Download” is produced by Alston & Bird’s Privacy, Cyber & Data Strategy Team, led by Kim Peretti and David Keating. It is edited by Hanna Hewitt, Alice Portnoy, Seol Namgoong, and Anna von Spakovsky.
For additional updates, please be sure to visit our blog at www.alstonprivacy.com.
Stay ahead of evolving ransomware threats with Alston & Bird’s Ransomware Fusion Center. Our Privacy, Cyber & Data Strategy Team offers comprehensive resources and expert guidance to help your organization prepare for and respond to ransomware incidents. Visit Alston & Bird’s Ransomware Fusion Center to learn more and access our tools.
The Digital Download, as well as any articles or other content linked to or otherwise cited by or attached to it, is not intended to constitute and should not be relied upon as or construed to be legal advice.