Busy couple weeks in Privacy, Cyber, & AI land. Let's rundown a short list of things I'm reading lately. As always, thanks and hat tips to the reporters, lawyers, and other folks who help keep me up to date with the chaos.

  • AP News: China’s new AI model halts new subscriptions as demand swamps capacity - Moonshot AI launched its new Kimi K3 model a couple weeks ago and was forced to suspend new subscriptions to its hosted services as it quickly ran out of compute capacity when demand spiked. Moonshot AI responded by making the model open weight and available on Hugging Face. The model is reportedly on par or just behind the latest American frontier models. That's since caused a bit of a fuss by American AI giant Anthropic calling for a ban on Chinese open weight models that quickly met pushback from Nvidia and other industry heavyweights. My privacy senses tingled when I thought about the amount of data possibly going into anything potentially hosted or accessible by the Chinese developer given what I expect to be some fairly imminent enforcement of the DOJ's Bulk Transfer Rules on certain types of personal data to China. There's also potential U.S. export consequences coming for Nvidia and Moonshot AI given that news has now broken that Kimi K3 was trained on Nvidia Blackwell chips and they're seeking more to train their next model despite the ban on exporting the powerful AI GPUs to China.
  • MPR: Elon Musk’s company sues Minnesota over new law to bar manipulated images to fake nudity - Late last year, Musk's Grok AI dropped all rational guardrails and began permitting users to generate nude photorealistic images - or deepfakes - of anyone without any consent requirements or other guardrails. The NYT reported that millions of non-consensual intimate images flooded Grok and X (formerly Twitter) within days of the release. Minnesota promptly responded and passed HF1370, a ban on all AI generated intimate images. Musk has sued, claiming the law violates First Amendment speech rights and is not narrowly tailored. Governor Tim Walz has responded with:
Governor Tim Walz (@governorwalz.mn.gov)
See you in court, creep. [contains quote post or other embedded content]

Having taken a look at the statute and chatted online with some extremely good First Amendment experts and colleagues, unfortunately, Musk's team probably has grounds to push back on the Minnesota ban. As drafted, it currently lacks a consent requirement so the ban isn't narrowly tailored enough to survive scrutiny. I'd expect the MN Legislature to take up an amendment next session to trim the scope down and insert a consent requirement to fix that deficiency if they want the bill to survive and truly curtail the biggest harms. What level of scrutiny (intermediate or strict) is applied is another open question. As we saw from SCOTUS in 2025, Age Verification laws preventing access by minors to obscene content did not rise to strict scrutiny requirements even though significant constitutional privacy and speech concerns were raised in FSC v. Paxton. It seems illogical to me to emphasize that the First Amendment would not bar States from regulating children's access to pornographic content but prohibit those same States from also regulating companies making non-consensual porn of those same children.

  • Wired: A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran - Minnesota stays in the news as earlier this week, municipal water and wastewater authorities in MN and seven other states reported a significant cyberattack. The Minnesota Fusion Center, a state agency that shares law and cyber intelligence, issued a memo connecting the attacks to Iran as part of the ongoing US-Iran War. Designated as critical infrastructure, water and wastewater facilities are often extremely vulnerable to hacks given aging technologies and under-investment in cybersecurity personnel and tools. War finds a new front on the homefront.
  • CalPrivacy will host a board meeting August 6-7. The agenda says the meeting will cover the following:
    • Opt Out Preference Signals history, technology, and proposed rulemaking.
    • CPPA's Audits Division delivers its first annual report.
    • Delete Request and Opt Out Platform (DROP) proposed rulemaking and audits.

The Audits Division report will be interesting given both that it's the first report this division has given and that it recently launched its first sectoral audit of the gig economy in July. I don't expect much here, to be honest, but it will be interesting to see if there are any nuggets dropped about how the division sees itself exercising its authority.

I do expect CalPrivacy will move aggressively to adopt regulations requiring audits of DROP compliance and, if they follow the trend of recent years, forcing annual certifications around those audits to be submitted to CalPrivacy for review. As CalPrivacy matures as an agency, it is increasingly using its regulatory power to push companies to proactively and regularly submit documentation to CalPrivacy for its review rather than relying upon retroactive investigative powers as we see with risk assessment and cybersecurity audit rules going into effect over the next few years. The level of scrutiny here is now moving from the outer shell of compliance to the internal workings behind the scenes. Will be tuning in as CalPrivacy is now the most important US privacy regulator given the collapse of federal agency enforcement under the Trump administration. DROP compliance will be a hot button issue with enforcement kicking off August 1 and the aggressive New Jersey law banning sensitive data sales by data brokers and companies potentially raising the stakes nationwide.

One question: I wonder how aggressively California has marketed the DROP platform operated by CalPrivacy that all registered data brokers must comply with? Are there commercials on TV? A billboard anywhere? YouTube or TikTok ads? The uptake both in the short term and long term here will be fascinating and the success or failure of DROP will have implications for other states given that it's a first-of-its-kind centralized opt-out of data brokers.

  • The National Law Review: Vivek Limited - If you talk to in house privacy professionals, CIPA litigation has become the death by a thousand cuts headache of many a company. CIPA is the California Invasion of Privacy Act, enacted in the 1960s to stop wiretapping and eavesdropping on telephone conversations. In recent years, the plaintiff's bar has unleashed thousands of CIPA claims against websites and apps based on the use of ubiquitous trackers for analytics and marketing purposes that allegedly intercepted communications between users without their consent. This made cookie banner compliance a Very Big Deal and many companies have been woefully inadequate at this. Vivek Shah is one of the most prolific filers of these claims and, as of last week, has now been put on the vexatious litigant list by the Central District of California. (That sound you hear is thousands of attorneys rushing to the court to file motions to get their Vivek-linked lawsuits dropped against their clients). Shah was essentially copy-pasting claims and just changing the name of defendants and websites and filing them en masse. How far this goes from a case and jurisdictional perspective remains to be seen; this is only one case and one plaintiff and one court and one law right now, but I would certainly be looking to leverage this in my client's favor. CIPA claims are something of an odd motivator in Privacy Land. On the one hand, a threat of class action certainly unlocks internal resources when building a compliance program out and companies very much do not want to keep dealing with these so they can be a good lever to use to get a project on the roadmap and resourced. On the other hand, from a legal perspective, these laws were most definitely not written with modern technology in mind and the expansion of them to internet tracking technologies has been somewhat tortured logic. I look at these as a symptom of a larger problem: people want their privacy restored and don't like how the internet has developed so many technologies linked to digital surveillance for any number of reasons. In the absence of better laws and more enforcement by state and federal regulators of laws that are better fit for purpose, the plaintiff's bar is seizing the tools at hand to do what it can.

If you need any help navigating these or any other privacy, security, or AI laws, reach out to us at Brandi@BennettTechLaw.com for help.