Red Lines under the EU AI Act: Understanding the ban of the untargeted scraping of facial images and facial recognition databases
[…] targets specifically the acts necessary prior to engaging in facial recognition itself, which is tackled separately, under a different provision of the AI Act, Article 5(1)(h). A number of key takeaways emerge from our analysis: The European Commission Guidelines echo Recital 43 AI Act by acknowledging that the untargeted scraping of facial images is […]
The Chatbot Moment: Mapping the Emerging 2026 U.S. Chatbot Legislative Landscape
[…] protocols. Similar to California and New York’s laws, many require operators to provide crisis resources, such as suicide hotline referrals, when detecting indicators of self-harm. A growing number also address anthropomorphic or manipulative interactions, including restrictions on emotional deception or features designed to foster dependency, like rewarding prolonged interaction (HI HB 2502, OR SB […]
Common Chatbot Provisions — Future of Privacy Forum (5)
[…] authority and civil penalties. A significant subset would create private rights of action while a few laws establish non-disclaimable liability for specific harms to minors. A small number of proposals would introduce criminal liability for chatbot behaviors. The mes: N on -d is c la im ab le lia b ilit y ( N […]
Digital Digest: FPF’s Annual Privacy Papers for Policymakers
[…] but also hiding their contact details, their address, their workplace, their roommates, and any other information that could enable their abuser to target them. Yet today, no number of name changes and relocations can prevent data brokers from sharing a victim’s personal information online. Thanks to brokers, abusers can find what they need with […]
FPF-Age-Assurance-v2.0
The age credential is cryptographically bound to Miles’ device passkey. This ensures that if Miles shares his phone with James, a 15-year-old friend, James cannot access 16+ features. The age signal is only released when a PIN, pattern, or local biometric is successfully entered. ID USER ACTIVITY 01 / 02 / 2009 BIRTHDATE In […]
Red Lines under the EU AI Act: Understanding Manipulative Techniques and the Exploitation of Vulnerabilities
[…] ability to recognize deceptive practices and may intersect with other discriminatory factors, such as belonging to an ethnic, racial, or religious minority group. The Guidelines share a number of examples in cases of exploitation of vulnerable people based on their age that fall under prohibited practices, including: An AI-powered toy designed to interact with […]
From Proposal to Passage: Enacted U.S. AI Laws, 2023–2025
[…] and safety protocols, particularly for sensitive use cases involving mental health and emotional companionship. While the majority of these AI laws have already taken effect, a small number have delayed or phased-in effective dates that stakeholders should continue to track: Federal — S 146 (TAKE IT DOWN Act regarding nonconsensual intimate imagery): notice-and-removal requirements […]
FPF Retrospective: U.S. Privacy Enforcement in 2025
[…] be moving from a period of legislative activity into a new era where enforcement is shaping the laws’ meaning, as 2025 saw a significant increase in the number of public enforcement actions. States Demonstrate Increasing Concern for Kids’ and Teens’ Online Privacy and Safety: As legislators continue to consider broad youth privacy and online […]
Operations Internships
The Future of Privacy Forum (“FPF”) is a non-profit organization that serves as a catalyst for privacy leadership and scholarship, advancing principled data practices in support of emerging technologies. FPF brings together industry, academics, consumer advocates, and other thought leaders to explore the challenges posed by technological innovation and develop privacy protections, ethical norms and […]
6 Privacy Tips for the Generative AI Era
Data Privacy Day, or Data Protection Day in Europe, is recognized annually on January 28 to mark the anniversary of Convention 108, the first binding international treaty to protect personal data. The Council of Europe initiated the day in 2006, with the first official celebration held on January 28, 2007, marking this year as the […]