It's been a busy few weeks here at Bennett Tech Law where we made appearances at Twin Cities Startup Week, presented on the State of AI Laws and Governance, and launched some new clients! In the meantime, Privacy, Cybersecurity, and AI laws never sleep, so let's catch up on the last few weeks and what's been catching my eye.

  • Google wants Spirit Airlines’ data. Micro1 wants to pay more - An older story from August 2026 but coming back to life here in the last few weeks with some interesting news. Budget airline Spirit declared bankruptcy earlier this year and, as part of its bankruptcy process, Google emerged as a bidder for Spirit Airlines' corporate data, which includes passenger and employee personal data, to train its AI models. While Google has promised to de-identify any personal data, reasonable minds differ on the efficacy of de-identification methodologies. This isn't the first time personal data has changed hands in bankruptcy proceedings (recently 23andme made significant waves considering the sensitivity of genetic and health data) but it does mark what I believe is the first time that the data is being directly pointed at training AI, so the outcome here will be closely watched for precedent going forward and, of course, raises the ghosts of choice, transparency and whether any preexisting consent is valid for new use cases.
  • Newsom closes final legislative session with changes to privacy, indigent defense laws - You're probably seeing a ton of news about this one, but it's a big driver for exasperated privacy professionals who have been inundated with thousands of complaints, including from a serial litigant, claiming pixel and cookie tracking on websites violates California's 1967 wiretapping law, the California Invasion of Privacy Act (CIPA). The much ballyhooed SB 690, now signed into law by Newson, does not completely close down California CIPA claims, but it does narrow that law and I would expect to see another bill taken up next year or the following to further narrow these claims depending on how the plaintiff's bar responds. This obviously doesn't impact federal ECPA or other state wiretapping claims and, in the absence of federal privacy law preempting these state laws (an extreme long shot!) expect to see this issue continue to devour time and energy for privacy pros. As I've said before, right problem, wrong law. People care about their privacy and the lack of a private right of action in modern state privacy laws has left the plaintiff's bar to creatively use old laws for new tricks. Of course, the plaintiff's bar is the only ones actually making much money from these things if the "up to $10" settlement offer I got from CVS last weekend for similar claims is anything to go by.
  • HackTron: Hacking OpenAI - One key concern with the introduction of AI in the cybersecurity space is the speed at which it moves and the relative low cost to discovering vulnerabilities and creating exploits for those vulnerabilities. I don't know that anyone has come close to remotely solving these problems yet, which puts some rather troubling context into Sam Altman's claims that we need to live with some harms for the benefit of AI. I'll leave you with this quote from the linked article, which is worth a read:
Software has long benefited from a kind of security through complexity. The code and even the vulnerability could be public, but turning a bug into a reliable exploit still required rare expertise, significant time, and knowledge of the target environment. Known memory corruption vulnerabilities were expensive to operationalize, while zero-days were mostly reserved for the highest-value targets.
This was never a real security boundary, but it protected ordinary companies in practice from software vulnerabilities. AI is removing that protection by turning more of this scarce expertise into compute. Work that once required a well-resourced team and months of effort can now be compressed into days.
  • Former FTC Chair Khan dismisses 'constitution' signed by AI leaders to self-police - Last week, in an effort to stave off growing calls for regulation of AI, AI leaders signed a voluntary "Constitution" while at a White House event. Former FTC chair Lena Khan came out Sunday and criticized that AI Constitution, calling for Congress to legislate. Having seen this self-regulatory cycle already in the early days of privacy jurisprudence (and before that cybersecurity), she's not wrong. Self-Regulation was the standard approach for privacy "enforcement" prior to the arrival of GDPR and CCPA on the scene. Those laws landed with huge potential penalties and FTC enforcement of privacy violations ramped up exactly because of the failure of self-regulatory frameworks. Call me cynical, however, in that I don't think a tech-captured and de-regulatory Trump administration has much motivation to pass an AI law or that Congress will get its act together considering it's been failing to pass a national privacy law for over a decade now. I continue to look to state and international laws as far more influential on the developing body of AI governance than I do anything coming out of the US Federal Government.
  • Italy GDPR: PRESS RELEASE - Health data: the Privacy Guarantor sanctions IQVIA for 7 million euros. It does not anonymize the data of one million patients of 800 family doctors - The Italian Data Protection regulator has added to IQVIA's legal troubles in the EU by fining it 7M Euros for, among other violations, failing to properly de-identify or anonymize personal data before using it for targeted advertising for pharmaceuticals and other health-related advertising. Reading the order, it looks like at least some of the violations stem from acquired companies (as early as 2017), which throws into question again what level of diligence is being done during an acquisition, whether transactions are accounting for privacy violations financially, and what level of support integration teams are being given to clean up any deficiencies post-acquisition. It also begs the question of whether IQVIA's de-identification techniques are adequate. Consider this a hot spot to continue watching given that advertising based on sensitive personal data such as health data is hotly contested in the US and globally.
  • BBC: US criticises Australia's proposed algorithm opt-out laws as 'censorship' - After OpenAI's agents breached Australia's Medicare statistics database in June (one in a series of allegedly self-instituted rogue hacks of more than a dozen companies and government entities globally), the Australian government is now looking at law enforcement and legislative remedies, particularly criticizing OpenAI's notification delays and methodology (they sent an email to a generic inbox!). Criminal liability is on the table for OpenAI, according to the Prime Minister, which may mark the first exposure to criminal liability for OpenAI for its agents' conduct and would certainly chart a course on liability that OpenAI and other frontier models and agentic developers have been working to avoid for quite some time.

If you need any help navigating these or any other privacy, security, or AI laws, reach out to us at Brandi@BennettTechLaw.com for help.