Across the United States, evolving data collection and processing practices and advances in artificial intelligence are driving new digital services, technologies, and socially beneficial research – while also raising new opportunities, risks, and questions for individuals and communities. In response, state and federal policymakers are considering new legislative and regulatory frameworks on three interconnected fronts: comprehensive consumer privacy laws that establish baseline rights and protections for personal data across the economy; frameworks that target specific sectors and practices such as automated decisionmaking, biometric identification, companion chatbots, data-driven pricing, data brokerage, frontier AI model safety, genetic data, and health data; and youth-specific privacy and online safety laws that set distinct rules for minors. These three tracks rarely stay in their lanes: a comprehensive privacy law may include AI provisions, an AI safety bill may carve out rules for minors, a youth online safety law may hinge on biometric age verification. Understanding the landscape requires understanding both the individual pieces and how they fit together.
FPF’s U.S. Legislation team provides expert, independent, pragmatic analysis of state and federal legislative and regulatory approaches to privacy, AI, and youth online safety – three distinct but increasingly intertwined issue areas. The team tracks emerging proposals, compares new laws against existing frameworks, analyzes implementation and compliance implications, and helps policymakers and stakeholders understand how legal requirements interact with current technologies, business practices, and data uses.
Through reports, blog posts, legislative and policy analyses, webinars, in-person and virtual peer-to-peer gatherings, and educational programs, FPF helps the broader technology policy and governance community understand the mechanisms and strategies available to protect privacy, promote responsible AI development and deployment, and advance youth online safety. FPF does not typically support or oppose particular bills. Instead, the U.S. Legislation team focuses on explaining the practical and legal implications of proposals – individually and as they interact with one another. This work helps ensure that privacy, AI, and youth safety compliance and policy strategies remain future-looking, adaptable, and workable for the continued, beneficial use of data and AI.
FPF’s U.S. Legislation team is led by Tatiana Rice, Senior Director.
Featured
FPF Releases Issue Brief on New CCPA Regulations for Automated Decisionmaking Technology, Risk Assessments, and Cybersecurity Audits
Since the California Consumer Privacy Act (CCPA) was enacted in 2018, business obligations under the law have continued to evolve due to several rounds of rulemaking by both the Attorney General and the California Privacy Protection Agency (CPPA). The latest regulations from the CPPA are some of the most significant yet. Starting January 1, 2026, […]
California’s SB 53: The First Frontier AI Law, Explained
California Enacts First Frontier AI Law as New York Weighs Its Own On September 29, Governor Newsom (D) signed SB 53, the “Transparency in Frontier Artificial Intelligence Act (TFAIA),” authored by Sen. Scott Wiener (D). The law makes California the first state to enact a statute specifically targeting frontier artificial intelligence (AI) safety and transparency. […]
The State of State AI: Legislative Approaches to AI in 2025
State lawmakers accelerated their focus on AI regulation in 2025, proposing a vast array of new regulatory models. From chatbots and frontier models to healthcare, liability, and sandboxes, legislators examined nearly every aspect of AI as they sought to address its impact on their constituents. To help stakeholders understand this rapidly evolving environment, the Future […]
FPF Submits Comments to Inform Colorado Minor Privacy Protections Rulemaking Process
On September 10th, FPF provided comments regarding draft regulations for implementing the heightened minor protections within the Colorado Privacy Act (“CPA”). Passed in 2021, the CPA, a Washington Privacy Act style-framework, provides comprehensive privacy protections to consumers in Colorado that are enforced by the state Attorney General’s office, which also has rulemaking authority. In 2024, […]
“Personality vs. Personalization” in AI Systems: Intersection with Evolving U.S. Law (Part 3)
This post is the third in a series on personality versus personality in AI systems. Read Part 1 (exploring concepts) and Part 2 (concrete uses and risks). Conversational AI technologies are hyper-personalizing. Across sectors, companies are focused on offering personalized experiences that are tailored to users’ preferences, behaviors, and virtual and physical environments. These […]
A Price to Pay: U.S. Lawmaker Efforts to Regulate Algorithmic and Data-Driven Pricing
“Algorithmic pricing,” “surveillance pricing,” “dynamic pricing”: in states across the U.S., lawmakers are introducing legislation to regulate a range of practices that use large amounts of data and algorithms to routinely inform decisions about the prices and products offered to consumers. These bills—targeting what this analysis collectively calls “data-driven pricing”—follow the Federal Trade Commission (FTC)’s […]
The “Neural Data” Goldilocks Problem: Defining “Neural Data” in U.S. State Privacy Laws
Co-authored by Chris Victory, FPF Intern As of halfway through 2025, four U.S. states have enacted laws regarding “neural data” or “neurotechnology data.” These laws, all of which amend existing state privacy laws, signify growing lawmaker interest in regulating what’s being considered a distinct, particularly sensitive kind of data: information about people’s thoughts, feelings, and […]
Balancing Innovation and Oversight: Regulatory Sandboxes as a Tool for AI Governance
Thanks to Marlene Smith for her research contributions. As policymakers worldwide seek to support beneficial uses of artificial intelligence (AI), many are exploring the concept of “regulatory sandboxes.” Broadly speaking, regulatory sandboxes are legal oversight frameworks that offer participating organizations the opportunity to experiment with emerging technologies within a controlled environment, usually combining regulatory oversight […]
Data-Driven Pricing: Key Technologies, Business Practices, and Policy Implications
In the U.S., state lawmakers are seeking to regulate various pricing strategies that fall under the umbrella of “data-driven pricing”: practices that use personal and/or non-personal data to continuously inform decisions about the prices and products offered to consumers. Using a variety of terms—including “surveillance,” “algorithmic,” and “personalized” pricing—legislators are targeting a range of practices […]
Tech to Support Older Adults and Caregivers: Five Privacy Questions for Age Tech
Introduction As the U.S. population ages, technologies that can help support older adults are becoming increasingly important. These tools, often called “AgeTech”, exist at the intersection of health data, consumer technology, caregiving relationships, and increasingly, artificial intelligence, and are drawing significant investment. Hundreds of well funded start-ups have launched. Many are of major interest to […]