Running down the weekly news in Privacy, Cybersecurity, AI Land again. As ever, change is ever afoot.
- CalPrivacy: Data Broker Delete Act enforcement lands twice this week. First, CalPrivacy fined Iowa data broker LocateSmarter, LLC $116,490 for failing to register and ordered them to register and implement DROP compliance. Then, on Thursday, CalPrivacy fined Massachusetts-based data broker Cybba, Inc, $52,400 for failing to register. Like LocateSmarter, Cybba was ordered to register and implement DROP. The California privacy regulator is aggressively leveraging the August 1, 2026 effective date for data brokers to begin processing DROP requests to actively push awareness of the Delete Act and the announcement of these penalties on the heels of that date are part of that larger strategy. If you're in the data broker space, beware.
- Staying in California, the bill looking to amend the California Invasion of Privacy Act, SB 690, looks like it has cleared suspension and is headed to the floor for a vote. There's still a number of steps to go before the legislature wraps up its session on August 31, but as presently drafted, the bill would retroactively eliminate the private right of action under the 1960s wiretapping law that has served as a headache for companies facing class actions over commonly deployed marketing, advertising, and analytics tracking code deployed on millions of websites. The bill would vest sole enforcement authority in the California AG. I don't love using a 1960s law on 2020 technology and obviously there's a ton of abuse by serial litigants, but as someone who wholeheartedly believes in the importance of privacy as a foundation for human and civil rights, I'm discouraged by eliminating one of the more effective ways of getting attention and resources in house because the threat of class actions. Attorney General enforcement dramatically reduces risk for companies because it dramatically reduces the likelihood of getting investigated, fined, or otherwise held accountable and most AGs are not resourced to fully enforce privacy laws.
- 404 Media: Twitch is Mining Peoples' Streams to Train Amazon's AI - News broke this week that Twitch users were opted in by default to allow their streams to be used to train Amazon's Generative AI tools. The opt out provided by Twitch does not apply to any of its safety or captioning tools, per 404 Media and Twitch. Online, Twitch users quickly flooded social media with instructions on how to exercise the opt out while protesting the use of their content to train Amazon's GenAI. This highlights one of my primary issues with US Privacy Law: Opt Out Consent is the Original Sin of US Privacy Law. Opt out is so profoundly entrenched in online design as if it presents any meaningful choice and has now jumped from privacy to AI jurisprudence.
- TechDirt: 16 Groups Warn FCC’s New ‘Robocall Plan’ Is Really About Dramatically Undermining Privacy - Karl Bode reports that the Trump admin is pushing plans to functionally eliminate by burner phones by requiring telecomms to "expand the agency’s Know Your Customer (KYC) requirements by imposing a requirement to 'at a minimum, obtain and retain the name, physical address, government issued identification number, and an alternate telephone number of any new and renewing customer.'” Anonymity has been a foundation of free speech for centuries and this expansion of data collection to the acquisition of a phone number is alarming, yet also par for the course with the creep of privacy invasive technologies from public surveillance technologies such as Flock cameras and facial recognition, age verification laws, and attacks on encryption globally by government and law enforcement agencies. I'll just leave Ben Franklin to speak here for me (despite historical context): "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
- Euronews: EU compliance, delivered globally: Anthropic to watermark Claude's output worldwide - In order to comply with the EU AI Act's transparency requirements, Anthropic is providing invisible watermarks on all Claude output starting August 2. I'm entirely unsure how exactly an invisible watermark is transparent and if the average user can even locate the invisible watermarks but it's interesting that Anthropic chose to extend this globally rather than geo-restricting the content to the EU only. That speaks to burgeoning anti-AI sentiment and an interest in regulating AI content and the companies that produce it emerging globally.
- PR Newswire: China advances global AI governance in a comprehensive manner - Speaking of emerging AI governance, China has been moving aggressively to take on a role as a global leader not just technically but with respect to regulations for AI in recent months. Last month, Xi Jinping spoke at the World AI Conference, emphasizing the importance of open models and "called for AI systems to remain under human control and urged countries to establish early-warning and emergency-response mechanisms to manage AI risks[.]" In September 2025, China released version 2.0 of its AI Safety Governance Framework. China recently clamped down on AI companion bots, forcing companies such as Alibaba and Bytedance to shut down services and leaving users lovelorn. Now the China Cyberspace Administration of China is opening comment on draft rules related to data privacy by large scale processors of personal information. Reform appears hot in China with the aim of positioning China in the AI space similarly to how EU's GDPR conquered the world globally in privacy.
Privacy, AI, and cybersecurity never sleep. What's keeping you awake at night? What news are you tracking?
If you need any help navigating these or any other privacy, security, or AI laws, reach out to us at Brandi@BennettTechLaw.com for help.