The Deepfake Reckoning: When AI Replicates Reality Without Consent

View in browser

Subscribe to Insights

FINAL REsource Hubsot Header -1
HubSpot Banners (14)
Hubspot Headers (600 x 100 px) (6)

March 2026

The Deepfake Reckoning: When AI Replicates Reality Without Consent

 

Deepfakes are no longer a fringe internet problem—they are a growing enterprise risk. In February 2026, data protection authorities from 61 jurisdictions issued a rare joint statement warning organizations about the dangers of artifical intelligence (AI) systems capable of generating realistic images and videos of identifiable individuals without consent. The coordinated message from regulators across Europe, North America, Asia, and beyond is clear: existing privacy laws already apply to generative AI, and enforcement is coming.

 

The concern extends far beyond viral social media manipulation. Regulators are focusing on the misuse of biometric and personal image data, the rapid spread of non-consensual imagery, and the particular risks these technologies pose to children and vulnerable populations. Many jurisdictions already treat the creation of non-consensual intimate imagery as a criminal offense, and regulators are now signaling that organizations deploying AI tools—whether vendors or enterprise users—may share responsibility when these harms occur.

 

For businesses experimenting with generative AI, the message is straightforward: AI governance is data governance. Organizations developing or deploying image-generation tools are expected to implement safeguards against misuse, ensure transparency about system capabilities, provide mechanisms for individuals to request removal of harmful content, and adopt stronger protections where children’s data may be involved.

 

As AI becomes embedded across marketing, HR, security, and customer engagement platforms, companies must treat the replication of human likeness—faces, voices, and identities—as highly sensitive data processing. Our team continues to explore what this global regulatory alignment means for organizations deploying generative AI and the practical governance steps privacy, security, and operational teams should be taking now.

Insights

Supreme Court 1 (1)

Delaware Supreme Court Expands Cyber Liability Exposure for SaaS & Managed Service Providers

Authored By: Jade Davis and Enisha Smith

Read Here
Outside counsel

Your Outside Counsel Is Using AI. Should Your Legal Spend Be Going Down?

Authored By: Lloyd Wilson

Read Here
Outside Counsel Is Using AI

The Artificial Intelligence Benchmark: The Most Important Clause You've Never Used (Part 2)

Authored By: Brian Focht

Read Here
data centers

Client Alert: New Federal Policy Could Unlock Alternative Water Supplies for Data Centers

Authored By: Ryan Walker, Chris Salemme, Mike Fedorchak, and Jodie Moxley-Ramos

Read Here

Was this email forwarded to you?

SUBSCRIBE HERE

Legislative & Regulatory

After a relatively quiet year in state privacy legislation, 2026 has ushered in a renewed wave of activity across state legislatures. Several states have introduced comprehensive privacy bills during this legislative cycle, continuing the broader national trend toward expanding individual privacy rights and imposing new compliance obligations on organizations that collect, use, and process personal data.

 

While many of these proposals mirror frameworks established in existing state privacy laws, several bills also reflect evolving policy priorities by incorporating provisions addressing emerging issues such as AI governance and heightened protections for consumer health data.

 

Key Takeaways for Businesses

  • State momentum continues. Even without a federal comprehensive privacy law, states continue to expand privacy regulation. Organizations operating nationally should expect an increasingly complex compliance landscape.

  • Data minimization is gaining traction. New proposals—such as Maine’s LD 1822—reflect a growing legislative focus on collecting and retaining only the data necessary for a defined purpose, signaling a shift away from broad data collection practices.

  • AI regulation is accelerating. Oregon’s AI chatbot safety bill highlights a broader trend of states addressing consumer-facing AI systems, particularly those interacting with minors, through transparency and safety requirements.

  • Private litigation risk is expanding. Bills that include a private right of action and statutory damages, such as Oregon’s SB 1546, significantly increase legal exposure and enforcement risk for companies deploying digital tools.

  • Sensitive data protections are tightening. Many proposals emphasize heightened safeguards for health data, children’s data, and biometric or location information, areas regulators increasingly view as high risk.

  • Operational readiness matters. Businesses should ensure they have data inventories, governance frameworks, and vendor oversight mechanisms in place to adapt quickly as new state laws take effect.

The list below summarizes key elements of select state privacy bills introduced during the 2026 legislative cycle.

 

Alabama
HB 351
January 29, 2026
Alabama Personal Data Protection Act
-Expanded authority for authorized agents to exercise consumer rights

-Provides an exemption for AI models in which no personally identifiable data is present in or extractable from the model


Arizona
SB 1815
February 9, 2026
-Defines “child” as someone under the age of 16

 

Iowa
HF 2048

January 14, 2026
- A standalone privacy regime separate from Iowa’s comprehensive privacy law that applies to significantly smaller businesses

-Covers companies that process personal data of at least 5,000 Iowa residents annually
-Requires affirmative opt-in consent for personal data processing, rather than relying on an opt-out framework

 

Illinois

SB 2875
January 16, 2026
Illinois Consumer Data Privacy Act
-Uses a definition of “specific geolocation data” based on latitude and longitude decimals, rather than feet
Requires data inventory for controllers

-Provides a right to contest adverse profiling decisions

 

Illinois
SB 3220
February 2, 2026
Illinois Consumer Data Privacy Act
-Defines “biometric data” more broadly than the norm (covering data from photos, videos, and audio if used to identify an individual)

-Exempts pseudonymous data from consumer rights

 

Illinois
SB 3890
February 6, 2026
Illinois Data Privacy Protection Act
-Requires annual registration of data brokers with the Attorney General

-Mandates creation of a public, centralized deletion mechanism to allow consumers to delete personal data across all registered brokers


Illinois
SB 3548
February 5, 2026
Consumer Data Privacy Act
-Establishes a Consumer Privacy Fund administered by the Attorney General and funded by enforcement proceeds

 

Illinois
HB 5221
February 10, 2026
Consumer Data Privacy Act
-Explicitly pre-empts home‑rule authority with respect to consumer data privacy regulation (i.e., only the State of Illinois – not cities, counties, or other home‑rule local governments – may regulate how personal data is processed)

 

New Mexico
SB 53
January 21, 2026
Community and Health Information Safety and Privacy Act
-Requires highest-level privacy settings as the default
-Requires opt-in consent for sensitive data processing
-Prohibits geofencing around healthcare and immigration services facilities

 

New Mexico
HB 214
January 29, 2026
-Consumer Information and Data Protection Act
-Combines comprehensive privacy law requirements with consumer health data law requirements into one bill
-Provides protections for minors under the age of 18
-Restricts federal agency sharing of New Mexico residents’ sensitive data

 

New Jersey
S2602
January 13, 2026
New Jersey Disclosure and Accountability Transparency Act
-Creates a new state agency

 

Vermont
H. 812
January 29, 2026
Vermont Duty of Data Loyalty Act
-Is largely based on the American Data Privacy and Protection Act
-Defines “sensitive covered data” to include “information identifying individual’s online activities over time and across third-party websites or online services”

 

West Virginia
HB 5123

February 3, 2026
Consumer Data Protection Act
-Bans geofencing healthcare facilities
-Provides a private right of action
-Damages for violations involving minors under the age of 16 can be tripled


Maine Online Data Privacy Act
Comprehensive privacy framework similar to Maryland’s law with strict data minimization requirements, enhanced protections for children, and prohibitions on the sale of sensitive data. Applies to businesses processing data of 35,000 residents or 10,000 residents while deriving at least 20% of revenue from data sales. Senate amendment includes a controversial exemption for political organizations, additional Attorney General enforcement funding, and a Sept. 1, 2027 effective date.


AI Chatbot Safety Act
Establishes safety and transparency obligations for consumer-facing AI chatbots, including disclosure that users are interacting with a chatbot rather than a human, safety notifications, break reminders, and restrictions on addictive algorithmic features. Includes heightened safeguards when operators have reason to believe a user is a minor and provides a private right of action with statutory damages for certain violations. Default effective date Jan. 1, 2027.

Enforcement Actions

Enforcement Spotlight: CPPA v. Ford Motor Company

The California Privacy Protection Agency (CPPA) issued a $375,703 enforcement order against Ford Motor Company for violating the California Consumer Privacy Act (CCPA) by requiring consumers to verify their email before processing opt-out requests for the sale or sharing of personal information. Regulators found this practice created unlawful “opt-out friction,” as the CCPA allows identity verification for access or deletion requests but prohibits additional verification barriers for opt-outs. The order—part of CPPA’s ongoing enforcement sweep of connected vehicle manufacturers—also requires Ford to implement easier opt-out mechanisms, honor Global Privacy Control (GPC) signals, and conduct an audit of website tracking technologies. The action signals heightened scrutiny of digital ecosystems that collect large volumes of consumer data and reinforces a key compliance lesson: opt-out processes must be as easy as the data collection practices they are meant to stop.

 

California Privacy Protection Agency Board (CalPrivacy) fines PlayOn Sports $1.10 million

 

Disney $2.75 million CCPA Settlement for Opt Out Failures 

 

Connecticut 2025 Enforcement Report: 

Health privacy enforcement is here. Connecticut’s Attorney General released its 2025 enforcement report this past month. Not surprisingly, health is a big focus. The report highlighted two actions tied to consumer health data:

  • An ongoing investigation into a fertility tracking product

  • A notice of violation and inquiry letter sent to a large data broker over sensitive data practices, including health

In Connecticut, consumer health data is defined by its purpose. Data you use to identify someone’s health condition.

“Use to” is intent.

So the right risk question is not “Is this Health Insurance Portability and Accountability Act (HIPAA) data?”

It’s:

What is the intent of your audience data?

If your audience data ties health information to an individual, that question is the fastest way to assess risk.

VIEW REPORT

 

UK ICO fines Reddit £14.47M for children’s data failures - Reddit issued with £14.47m fine for children’s privacy failures | ICO

Notable Data Breaches

Odido Data Breach

Odido (formerly T Mobile Netherlands) confirmed a breach of a customer contact system. 6.2 million customers were affected. Names, addresses, phone numbers, email addresses, bank account (IBAN) details, and identity documents were exposed.

 

CarGurus Data Breach

A ransomware group stole data associated with 12-16 million accounts. Data exposed: names, email addresses, phone numbers, IP addresses, user IDs, subscription and dealer‑related data.

 

Wynn Resorts Data Breach

A ransomware group claimed to steal 800,000 records of Wynn employee data. The data included Personally Identifiable Information (PII), Social Security numbers, and other personal information.

 

Substack Data Breach

Unauthorized access to systems allowed malicious actors to extract limited subscriber data. The exposed data included email addresses and phone numbers.  

Learn more about Shumaker's Technology, Data Privacy, Cybersecurity & AI Service Line

Contributors:

Contributors:

Jade Davis
HubSpot - Digital Risk Report Images (2)

Jade Davis

Partner

Brian Focht

Senior Counsel

47
45
HubSpot - Digital Risk Report Images (3)

Nick Carr

Partner

Enisha Smith

Associate

Lloyd Wilson

Associate

Was this email forwarded to you?

SUBSCRIBE HERE
Hubspot Headers (600 x 100 px) (8)
HubSpot Footer -1
Facebook
LinkedIn
X
Instagram
YouTube
TikTok

Manage Preferences | Unsubscribe | Privacy Statement

Shumaker, 1000 Jackson St, Toledo OH 43604