Artificial Intelligence (AI)

At the end of August, the California legislature passed three bills that would regulate the use of AI in the employment context. These bills are now on Governor Newsom’s desk, and he has until September 30 to sign or veto. Below is a summary of the three bills.

SB 947 (The “No Robo Bosses Act”)…

Continue Reading California Legislature Advances AI Employment Bills

Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws generally require entities that deploy ADMT in the employment context to, among other requirements, notify…

Continue Reading ADMT Law Round-Up: What Employers Need to Know About Recent ADMT Laws

On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

Continue Reading French CNIL Publishes Note on Agentic AI and Data Protection

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”  

The creation of Gold Eagle is the latest in a series of Administration actions focused…

Continue Reading White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse

This update highlights key legislative and regulatory developments in the second quarter of 2026 related to artificial intelligence (“AI”), connected and automated vehicles (“CAVs”), and Internet of Things (“IoT”).

Continue Reading U.S. Tech Legislative & Regulatory Update – Second Quarter 2026

On June 4, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a sweeping discussion draft of their Great American Artificial Intelligence Act. The latest bipartisan AI legislation quickly met bipartisan skepticism, particularly concerning the draft’s approach to federal preemption of state AI rules, with many House Democrats opposing the broad preemption for frontier model developers, while many House Republicans and other stakeholders lamented the bill’s omission of preemption for state laws reaching other parts of the AI ecosystem. 

The bill would also establish mandatory disclosure and risk-mitigation requirements for frontier models and task the Center for Artificial Intelligence Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) with oversight of federal AI-related research and analysis, standards and guidelines development, and risk-mitigation activities.  

Continue Reading Backlash to Bipartisan AI Omnibus Illustrates Preemption Impasse

Much of the attention on the European Commission’s recent proposal for a Cloud and AI Development Act (“CADA Proposal”) has focused on its proposed cloud sovereignty framework, the implications for cloud service providers and public sector cloud use, and the mechanisms intended to encourage data centre development in the EU (we discuss those aspects of the CADA Proposal in more detail in our post here).

But the CADA Proposal also contains several express references to the development of the EU quantum computing sector, which suggests that quantum computing may be embedded within the EU’s wider cloud, AI, and data centre strategy, and that the Commission may promote the development of the technology in that context (rather than treating it as a separate technology policy issue). That approach is consistent with the Commission’s July 2025 Quantum Strategy and its expected proposal for a Quantum Act later this year, both of which focus on building the industrial base for quantum computers in Europe (we describe the Quantum Strategy and the likely themes of the forthcoming Quantum Act in our prior post here).

In this post, we outline the two main mechanisms through which the CADA Proposal would support the development and deployment of quantum computing in Europe, in advance of the Quantum Act.

Continue Reading How the European Commission aims to promote the EU quantum sector through the Cloud and AI Development Act

On 3 June 2026, the European Commission (“Commission“) published its proposal for a Regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem—the Cloud and AI Development Act (“CADA Proposal“). The CADA Proposal sits at the heart of the Commission’s broader Tech Sovereignty Package (which we describe at…

Continue Reading The EU Cloud and AI Development Act in Depth

On 19 May 2026, the European Commission published its long-awaited draft, non-binding guidelines on the classification of high-risk AI systems (“HRAIs”) under the EU AI Act (the “Guidelines”). Across three documents—covering general principles, high-risk classification in the context of regulated products (Annex I), and high-risk use cases (Annex III)—the Commission sets out its approach to one of the AI Act’s central questions: when does an AI system fall within the high-risk regime (and, just as importantly, when does it not)?

Continue Reading EU AI Act Update: The European Commission Publishes Draft Guidelines on HRAIs

Last month, the Illinois Department of Human Rights (“IDHR”) released draft regulations addressing employers’ use of AI in employment decisions and invited public comment. The IDHR will hold a hearing on the draft regulations on June 10, and the public comment period will close on June 29.

Background

HB 3773 (the “Amendment”), which amended…

Continue Reading Illinois Department of Human Rights Seeks Public Comment on Draft AI Employment Regulations