Busy week as ever in privacy. Here's the short news I'm reading to stay on top of the chaos:

  • Reuters: US FTC considers requiring disclosure of personalized pricing - The FTC voted 2-0 this week to open comment on a draft enforcement policy prohibiting the use of personal information to set prices, a practice known as "surveillance pricing." Connecticut, Maryland, New Jersey and New York City have already banned the practice for certain retailers and, according to Stateline, 11 states considered bills this year. The FTC would consider it an "unfair and deceptive practice," the traditional measure it has used to enforce privacy laws in the US and, depending on how the final rule emerges and enforcement follows, could ban the practice nationwide.
  • Fast Company: The Great AI Layoff is becoming the Great AI Rehire - One of the concerns of arising out of a AI is whether AI will replace jobs and certainly companies have leaned into that narrative by conducting mass layoffs, particularly in tech, under the auspice of AI. Yet we appear to be seeing the limits of the current generations of AI as companies are struggling to maintain productivity without headcount. Earlier this year, Ford was forced to rehire laid off engineers after AI was unable to ensure quality control on its vehicles. For all the marketing hype around AI, there are limits to what it can replace versus what it can boost and it's been my experience that it has created a vast amount of compliance work to ensure the product is deployed within acceptable guardrails. Maintaining those guardrails proves to be a significant challenge considering the pace at which the underlying models change.
  • TechDirt: Another California Court Has Now Broken Media Advertising, So The Copia Institute Asked Another California Appeals Court To Fix It - I am consistently troubled by the idea that using personal data to target ads must somehow be protected by the First Amendment to the point that it overrides individual privacy rights (as some have argued regarding laws related to data brokers). But Copia and Cathy Gillis aren't wrong here: There's a fundamental legal paradox happening in legislatures around the country with passing laws on one hand that prohibit certain content be shared with groups of people based on age (see, e.g., age verification laws) and, on the other hand, making it illegal to exclude groups based on age (in this case, the ad targeting in question). Practically speaking, this means Pornhub or OnlyFans could be sued for not restricting minors from accessing content while at the same time being sued for not advertising that same content to the same minors. That's an untenable conflict the courts and legislatures will need to resolve preferably sooner rather than later.
  • Colorado AG: Colorado Automated Decision-Making Technology & Chatbot Safety Rulemaking - After a bit of a start and stop that saw Colorado take the lead on AI regulation with the Colorado AI Act only to get repealed and replaced by the narrower Colorado ADMT Act as well as the new Chatbot Safety Act, the Colorado Attorney General has opened rulemaking on the regulatory package designed to implement these laws. More news on this to come from me. I'll be breaking down the new CO laws and regulations in more detail given their prominence as the first real stakes in the ground on this area other than the CCPA ADMT regulations.
  • TechCrunch: In a first, US will allow some private firms to carry out cyberattacks - In what is yet another stunningly shortsighted move out of a White House that has no interest in long term security or governance over quick fixes and news cycles, the US government is now authorizing "Cyber Privateers" to take to the offense against various adversaries. How coordinated this will be with the government, who gets targeted, and how one gets their digital letter of marque is a whole other set of questions. What's not uncertain is that opening the door for private sector involvement in offensive operations opens the door to cybersecurity professionals being ordered by employers to take part in conflicts which could expose them to personal liability and the threat of overseas prosecution. Warfare is increasingly hybrid and the wars in the future may be fought over your water, food, medical or power supplies or even your data. This is another step on that path that could create a future of even more frequent and fraught cyber warfare.