Across the United States, evolving data collection and processing practices and advances in artificial intelligence are driving new digital services, technologies, and socially beneficial research – while also raising new opportunities, risks, and questions for individuals and communities. In response, state and federal policymakers are considering new legislative and regulatory frameworks on three interconnected fronts: comprehensive consumer privacy laws that establish baseline rights and protections for personal data across the economy; frameworks that target specific sectors and practices such as automated decisionmaking, biometric identification, companion chatbots, data-driven pricing, data brokerage, frontier AI model safety, genetic data, and health data; and youth-specific privacy and online safety laws that set distinct rules for minors. These three tracks rarely stay in their lanes: a comprehensive privacy law may include AI provisions, an AI safety bill may carve out rules for minors, a youth online safety law may hinge on biometric age verification. Understanding the landscape requires understanding both the individual pieces and how they fit together.
FPF’s U.S. Legislation team provides expert, independent, pragmatic analysis of state and federal legislative and regulatory approaches to privacy, AI, and youth online safety – three distinct but increasingly intertwined issue areas. The team tracks emerging proposals, compares new laws against existing frameworks, analyzes implementation and compliance implications, and helps policymakers and stakeholders understand how legal requirements interact with current technologies, business practices, and data uses.
Through reports, blog posts, legislative and policy analyses, webinars, in-person and virtual peer-to-peer gatherings, and educational programs, FPF helps the broader technology policy and governance community understand the mechanisms and strategies available to protect privacy, promote responsible AI development and deployment, and advance youth online safety. FPF does not typically support or oppose particular bills. Instead, the U.S. Legislation team focuses on explaining the practical and legal implications of proposals – individually and as they interact with one another. This work helps ensure that privacy, AI, and youth safety compliance and policy strategies remain future-looking, adaptable, and workable for the continued, beneficial use of data and AI.
FPF’s U.S. Legislation team is led by Tatiana Rice, Senior Director.
Featured
FPF Submits Comments to Inform New York Children’s Privacy Rulemaking Processes
At the end of the 2024 legislative session, New York State passed a pair of bills aimed at creating heightened protections for children and teens online. One, the New York Child Data Protection Act (NYCDPA), applies to a broad range of online services that are “primarily directed to children.” The NYCDPA creates novel substantive data […]
Updated FPF Infographic Explores Data in Connected Vehicles
Today, The Future of Privacy Forum is launching the Data and the Connected Vehicle Infographic 2.0, including new updates to account for the types of data associated with connected vehicles, features in and outside of the vehicle, and data handlers who receive and process data. Lawmakers, manufacturers, privacy professionals, and consumers are actively engaged in […]
FPF Unveils Report on Emerging Trends in U.S. State AI Regulation
Today, the Future of Privacy Forum (FPF) launched a new report—U.S. State AI Legislation: A Look at How U.S. State Policymakers Are Approaching Artificial Intelligence Regulation— analyzing recent proposed and enacted legislation in U.S. states. As artificial intelligence (AI) becomes increasingly embedded in daily life and critical sectors like healthcare and employment, state lawmakers have […]
FPF Highlights Intersection of AI, Privacy, and Civil Rights in Response to California’s Proposed Employment Regulations
On July 18, the Future of Privacy Forum submitted comments to the California Civil Rights Council (Council) in response to their proposed modifications to the state Fair Employment and Housing Act (FEHA) regarding automated-decision systems (ADS). As one of the first state agencies in the U.S. to advance modernized employment regulations to account for automated-decision […]
Consumer Health Data Privacy Notices by the Numbers
Today, FPF is releasing an infographic that provides insights into how organizations are responding to the transparency requirements of recently enacted U.S. state health privacy laws. The infographic reflects a survey of privacy notices on the websites of 180+ companies across a variety of industries and sectors, from pharmaceutical to apparel. Two key laws enacted […]
Contextualizing the Kids Online Safety and Privacy Act: A Deep Dive into the Federal Kids Bill
Co-authored by Nick Alereza, FPF Policy Intern and student Boston University School of Law. With contributions from Jordan Francis. On July 30, 2024, the U.S. Senate passed the Kids Online Safety and Privacy Act (KOSPA) by a vote of 91-3. KOSPA is a legislative package that includes two bills that gained significant traction in the […]
Reflections on California’s Age-Appropriate Design Code in Advance of Oral Arguments
Co-authored with Isaiah Hinton, Policy Intern for the Youth and Education Team Update: On Wednesday, July 17th, the U.S. 9th Circuit Court of Appeals heard oral arguments for an appeal of the District Court’s preliminary injunction of the California Age-Appropriate Design Code Act (AADC). Judges Milan Smith Jr., Mark Bennett, and Anthony Johnstone appeared interested […]
A First for AI: A Close Look at The Colorado AI Act
Colorado made history on May 17, 2024 when Governor Polis signed into law the Colorado Artificial Intelligence Act (“CAIA”), the first law in the United States to comprehensively regulate the development and deployment of high-risk artificial intelligence (“AI”) systems. The law will come into effect on February 1, 2026, preceding the March, 2026 effective date […]
Chevron Decision Will Impact Privacy and AI Regulations
The Supreme Court has issued a 6-3 decision in two long-awaited cases – Loper Bright Enterprises v. Raimondo and Relentless, Inc. v. Department of Commerce – overturning the legal doctrine of “Chevron deference.” While the decision will impact a wide range of federal rules, it is particularly salient for ongoing privacy, data protection, and artificial […]
AI Forward: FPF’s Annual DC Privacy Forum Explores Intersection of Privacy and AI
The Future of Privacy Forum (FPF) hosted its inaugural DC Privacy Forum: AI Forward on Wednesday, June 5th. Industry experts, policymakers, civil society, and academics explored the intersection of data, privacy, and AI. In Washington, DC’s southwest Waterfront at the InterContinental, participants joined in person for a full-day program consisting of keynote panels, AI talks, […]