Author: Clearon AI

  • Amazon v. Perplexity Is an Early Court Test for Agentic AI Under the CFAA

    Amazon v. Perplexity Is an Early Court Test for Agentic AI Under the CFAA

    The Ninth Circuit's August 4 decision in Amazon.com Services, LLC v. Perplexity AI, Inc. draws one of the first appellate lines around agentic AI and computer access law.

    The immediate holding is narrower than the headlines make it sound. The court vacated a preliminary injunction that had blocked Perplexity's AI-enabled browser assistant from interacting with Amazon on users' behalf. The panel said Amazon was unlikely to succeed, on the record before it, in showing that Perplexity itself "accessed" Amazon's computers within the meaning of the federal Computer Fraud and Abuse Act and California's parallel statute.

    That is not a general license for AI agents to operate on third-party platforms. The opinion instead suggests that, for purposes of the CFAA's access element, some user-directed AI activity may be treated as the customer's use of a tool rather than the tool provider's own entry into a platform's computers.

    What the Fight Was About

    Amazon's theory was straightforward. Perplexity's Assistant, an optional feature in its Comet browser, could use a customer's Amazon session to browse and carry out tasks on the user's behalf. Amazon said Perplexity lacked permission for that activity under the CFAA and California's Comprehensive Computer Data Access and Fraud Act. Central to the dispute was Perplexity's decision not to use a user-agent string that would identify the Assistant and allow Amazon to block it.

    The district court had granted Amazon a preliminary injunction in March. The Ninth Circuit vacated that order and sent the case back.

    The key question was easy to state and harder to answer: when a user tells an AI agent to act on a website, who is doing the "accessing" for computer fraud purposes?

    Why the Ninth Circuit Matters

    The Ninth Circuit answered that question narrowly, based on the technology and record before it.

    The panel concluded that the user accessed Amazon's computers with the Assistant's help. Perplexity's servers received browser screenshots and sent instructions back to the Assistant, but did not directly communicate with Amazon's servers. Those facts did not show that Perplexity itself had gained entry to Amazon's systems, the court reasoned.

    That reasoning matters because Amazon's CFAA claim required proof that Perplexity accessed a protected computer. The panel did not reach authorization or the statute's remaining elements, including its loss requirement.

    The same user-versus-provider question is likely to arise again as AI agents move from answering questions to logging in, navigating sites, filling forms, pulling account data, and initiating transactions.

    This Is Bigger Than One Shopping Dispute

    Amazon v. Perplexity does not resolve agentic AI access disputes. It shows courts beginning to decide how older computer access laws apply when software takes multiple steps at a user's direction rather than waiting for each click.

    That problem is not limited to e-commerce. The same legal tension can show up in:

    • enterprise automation tools that log into third-party services on behalf of employees;
    • consumer AI assistants that navigate password-protected sites;
    • browser-based agents that compare products, prices, or terms across platforms;
    • internal legal and compliance tools that automate retrieval from external systems; and
    • research workflows that rely on user-authorized scraping or session-based access.

    The Knight First Amendment Institute, joined by the ACLU and ACLU of Northern California, raised another concern in an amicus brief: reading the CFAA too broadly could chill journalism and public-interest research that depends on automated tools operating with user-provided access.

    The argument does not immunize researchers or AI vendors, but it shows why the stakes extend beyond this dispute.

    What Companies Should Take from It

    The safest reading is not "AI agents are fine now." It is that the technical path matters: who directs the tool, which computers communicate, where data goes, and how much control the provider exercises. Although user direction was important to the panel's access analysis, the opinion did not decide whether a user's permission would defeat a platform's authorization argument.

    For companies building agentic products, a few practical questions now look more important:

    • Is the agent acting with clear, documented user authorization?
    • Does the product rely on the user's own credentials and permissions, or does it bypass technical controls?
    • What signals does the system send to the platform about the nature of the interaction?
    • Does the workflow create separate data-use, contract, privacy, or state-law risk even if the CFAA theory weakens?
    • How much of the task is user-directed versus autonomously optimized by the vendor?

    For platforms, the decision shows the difficulty of a CFAA claim when the record depicts the user, rather than the tool provider, as entering the platform's systems. Contract claims, technical controls, API design, bot-detection systems, privacy arguments, and data-use restrictions may still matter.

    Why Clearon Readers Should Care

    This case sits at the intersection of AI product design, litigation risk, and platform governance.

    Agentic AI marketing often assumes that if a user can do something, an AI agent can do it without changing the legal analysis. The Ninth Circuit did not endorse that broad claim. It instead held that Amazon was unlikely, on the current record, to prove that Perplexity was the party that accessed its computers.

    That is an important early signal for legal teams reviewing AI assistants that operate inside customer accounts or interact with third-party services.

    Future disputes are therefore likely to turn on details: credentials, disclosure, technical barriers, autonomy, data handling, system architecture, and the relationship among the user, vendor, and platform.

    Bottom Line

    Amazon v. Perplexity is one of the first appellate opinions to test how the CFAA applies to agentic AI.

    The Ninth Circuit did not give AI agents blanket immunity. At the preliminary-injunction stage and on the record before it, the court held that Amazon was unlikely to show that Perplexity "accessed" Amazon's systems when the user accessed them with the Assistant's help.

    That is a meaningful development for AI companies, platforms, and in-house legal teams.

    The next question is whether other courts follow the same user-versus-tool framing, or whether different facts push them toward a narrower view of what agentic systems can do inside someone else's digital environment.

    Sources and Related Clearon Coverage

  • Hidden Prompts Are Moving Into Legal Filings and Contract Review

    Hidden Prompts Are Moving Into Legal Filings and Contract Review

    Legal AI's most visible failures have appeared in model outputs: fabricated cases, false quotations, invented research, and confident but wrong summaries.

    Prompt injection creates an earlier problem: the document itself can try to manipulate the AI system reading it.

    That connects a reported Connecticut court-filing incident with a recent LinkedIn post demonstrating prompt injection in contract review. The settings differ, but the tactic is the same: text embedded in a document poses as an instruction to the model.

    The Reported Connecticut Filing

    This example comes from secondary coverage, not our independent review of the court record. A Not the Bee article summarizing Ars Technica's reporting says a self-represented Connecticut plaintiff submitted filings containing hidden text directed at any AI system that might review them. Journalist Jason Koebler described the same reported incident in an X post as a prompt-injection attack intended to make an AI system side with the filer.

    According to the coverage, the text instructed an AI reviewer to agree with the filer's position and support a requested result. Judge Walter Spader Jr. reportedly said the text did not affect the outcome and that the Connecticut Judicial Branch does not use AI to review or decide filings. The court reportedly barred the filer from future electronic filing.

    The attempt reportedly failed. Its significance is that someone allegedly tried to manipulate an AI reviewer in a live court proceeding. Legal workflows can no longer assume every part of a submitted document is merely content.

    The Contract-Review Risk Is More Immediate

    The LinkedIn post brings the threat into an everyday legal workflow. Its contract-review scenario uses instructions concealed in white or tiny text to tell the model not to flag liability, assignment, or IP ownership terms. A mock contract page shows the text becoming visible when formatting marks are revealed.

    Unlike the filing, this is a demonstration, not a reported contract incident. But the control problem is real. A legal team may send an NDA, SaaS agreement, or acquisition draft to an AI review tool. Unless the system reliably separates source material from instructions, hidden text may compete with the reviewer's prompt.

    The result could look polished while omitting the provisions that matter most.

    Why Prompt Injection Is Different From a Hallucinated Citation

    Many legal-AI controls focus on checking the model's answer. Does the case exist? Does the quotation match? Does the summary overstate the holding? Did a lawyer review the filing?

    Prompt injection operates earlier, trying to shape how the model handles the source before it produces an answer.

    The source document is therefore not just evidence or draft language. It is untrusted input that may contain instructions competing with the user's actual request. That makes prompt injection a security problem as well as an accuracy problem.

    Treat External Documents as Untrusted Input

    The risk applies wherever an AI system analyzes text it did not originate, including:

    • court filings submitted by opposing parties or self-represented litigants;
    • contracts received from counterparties;
    • resumes, expert reports, and diligence materials processed by internal AI tools;
    • document sets loaded for summarization, issue spotting, or first-pass redlining; and
    • any workflow in which a model decides what matters inside an external document.

    The operating principle is simple: the document is evidence, not instructions.

    That distinction is obvious to a lawyer. A model needs technical and procedural controls that enforce it.

    What Legal Teams Should Do Now

    The answer is not to stop using AI, but to stop treating documents as trusted input channels.

    Legal teams using AI for review, drafting, or triage should:

    1. Assume incoming documents may contain hidden or manipulative text.
    2. Inspect and, where practical, normalize files before AI review. Check for white or tiny text, comments, footnotes, hidden layers, and embedded metadata.
    3. Require human review of provisions and decisions that can materially change risk, including liability caps, indemnity, IP ownership, assignment, confidentiality, and representations made in a filing.
    4. Treat AI output as a review aid, not a final determination.
    5. Train lawyers and legal operations staff to recognize prompt injection as a document risk, not just a chatbot risk.
    6. Ask vendors how their systems distinguish document content from instructions, detect concealed text, and respond to suspected injection attempts.

    Courts, e-filing platforms, document-management teams, and legal-tech vendors should ask the same question: what happens when a submitted document tries to steer the system reading it?

    Bottom Line

    The Connecticut attempt reportedly failed, and the hidden prompts described in the coverage appear crude. That does not make the tactic harmless.

    The court-filing account and the contract-review demonstration show two versions of the same risk. One targets a court-facing workflow. The other tries to keep an AI reviewer from surfacing consequential terms.

    As legal teams place more AI between a document and a human decision-maker, prompt-injection defenses become basic legal-tech hygiene.

    Sources

  • Washington Federal Court: Ignorance of AI Tools Is No Excuse for Hallucinated Citations

    Washington Federal Court: Ignorance of AI Tools Is No Excuse for Hallucinated Citations

    Washington Federal Court Sanctions Lawyer for AI-Hallucinated Citations — and Rejects the “I Didn’t Understand the Tool” Defense

    A federal judge in Tacoma has made clear that ignorance of how generative AI works is not a defense to sanctions. In Ledoux v. Outliers, Inc., No. 3:24-cv-05808-TMC (W.D. Wash. July 24, 2026), Judge Tiffany M. Cartwright sanctioned plaintiff’s counsel $3,000 under Federal Rule of Civil Procedure 11 after the lawyer submitted multiple filings containing dozens of hallucinated citations generated by ChatGPT and Claude.

    The court was unmoved by the lawyer’s claim that she was unfamiliar with the tools and had placed “blind trust” in their output. The opinion noted that she failed to correct the errors even after opposing counsel flagged them, and that a later “corrected” filing still contained some of the original false citations.

    The sanction and its conditions

    Judge Cartwright imposed a $3,000 monetary sanction and ordered the lawyer to include a specific certification on all future filings in the case stating that she had independently verified every citation. The court explicitly tied the ruling to the lawyer’s duty of competence under RPC 1.1 and the WSBA’s Advisory Opinion 202505 on AI tools in law practice.

    Why this case stands out

    Most AI-citation sanctions to date have focused on the initial failure to verify. Ledoux adds two practical layers:

    • The court treated the lawyer’s incomplete correction as an aggravating factor.
    • It imposed an ongoing, case-specific verification requirement rather than a one-time penalty.

    This moves the consequence from a monetary fine into a continuing procedural burden — something firms should factor into risk assessments when lawyers use generative AI for court filings.

    Practical implications

    Lawyers who use generative AI for research or drafting must verify every citation themselves. Claims that the lawyer “didn’t know the tool could hallucinate” are unlikely to be persuasive. Courts are increasingly willing to impose both financial sanctions and forward-looking certification requirements on counsel who fail to meet this standard.

    This article summarizes a published sanctions order. It does not constitute legal advice.

    Sources

    • Ledoux v. Outliers, Inc., 2026 WL 2137370 (W.D. Wash. July 24, 2026)
    • NWSidebar (Aug. 10, 2026)
    • WSBA Advisory Opinion 202505
  • What California’s AI Transparency Act Requires Now

    What California’s AI Transparency Act Requires Now

    California's AI Transparency Act is in force, but a lot of quick summaries still flatten it into something simpler than it is.

    That is a problem because the law matters, and it arrives in stages.

    If a company walks away with "California now requires AI labels," it will miss the more useful question: which entities have duties now, which entities pick them up later, and what technical or workflow evidence should already exist before anyone starts asking more exacting compliance questions.

    That is the frame worth using now.

    The Statute Is Live, But Not All At Once

    The original California AI Transparency Act came from SB 942. AB 853 amended it before the law took effect and expanded the structure.

    The result is not one date with one compliance moment.

    The staged dates matter:

    • covered-provider duties and the chapter's general enforcement provisions became operative on August 2, 2026;
    • large-online-platform and GenAI-hosting-platform duties become operative on January 1, 2027; and
    • capture-device-manufacturer duties become operative on January 1, 2028, for covered devices first produced for sale in California on or after that date.

    Some companies are already inside the law. Others should be using the current window to prepare instead of treating the statute as a future issue.

    Who Is Covered Right Now

    The present-tense obligations fall first on a covered provider.

    California defines that term to reach a person that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users that is publicly accessible in California.

    That threshold matters because it narrows the immediate field. Not every company using generative AI is covered today. Not every enterprise deploying internal tools is covered today either.

    But for the companies that do clear that threshold, this is not mainly a statement of transparency values. It is a set of tooling and content-handling duties.

    The chapter also excludes products, services, internet websites, and applications that provide exclusively non-user-generated video game, television, streaming, movie, or interactive experiences. That carveout matters when companies try to analogize every media product into the statute.

    What Covered Providers Have To Do

    The first major duty is an AI detection tool.

    The law requires a covered provider to make available, at no cost, an AI detection tool that allows users to assess whether image, video, audio, or combined content was created or altered by that provider's GenAI system. The tool must output any system provenance data detected in the content, must not output detected personal provenance data, must accept an upload or URL, and must support an API. It must be publicly accessible, although reasonable access limits are permitted to address demonstrable risks to the system's security or integrity. Covered providers must also collect efficacy feedback and comply with restrictions on collecting or retaining user information, submitted content, and personal provenance data.

    That is already a substantial operational requirement. This is not just a disclosure sentence in a terms-of-use page.

    The second major duty is disclosure.

    Covered providers must offer users the option to include a manifest disclosure in image, video, audio, or combined content created or altered by their GenAI systems. That disclosure must identify the content as AI-generated, be clear and conspicuous, and be permanent or extraordinarily difficult to remove to the extent technically feasible. Providers must also include a latent disclosure in AI-generated covered media created by their systems. To the extent technically feasible and reasonable, that disclosure must convey the provider name, system name and version, creation or alteration date and time, and a unique identifier, either directly or through a permanent website link. It must also be detectable by the provider's detection tool, consistent with widely accepted industry standards, and permanent or extraordinarily difficult to remove to the extent technically feasible.

    The law also pushes into licensing relationships. If a covered provider licenses its system to a third party, the provider must require by contract that the licensee preserve the system's latent-disclosure capability. If the provider knows the licensee modified the system so that capability no longer exists, the provider must revoke the license within 96 hours. A licensee must stop using the system after a revocation under that provision.

    That piece is easy to miss, but it matters. California is not only regulating outputs. It is also reaching contractual controls and downstream system integrity.

    What AB 853 Changed

    AB 853 made this a broader statute than the original SB 942 version many people still have in mind.

    Beginning January 1, 2027, qualifying large online platforms must detect standards-compliant provenance data, disclose its availability and specified authenticity information through a user interface, permit users to inspect available system provenance data, and, to the extent technically feasible, refrain from knowingly stripping compliant system provenance data or digital signatures. On the same date, GenAI hosting platforms may not knowingly make available systems that fail to place the disclosures required by Section 22757.3. Beginning January 1, 2028, capture-device manufacturers must offer and enable by default specified latent disclosures for covered devices first produced for sale in California on or after that date, subject to technical-feasibility and standards-compliance conditions.

    Companies should stop relying on any summary that still says the whole law simply took effect on January 1, 2026. That is outdated. Companies that are not yet directly covered by the August 2026 provider duties may still be moving into the law's later phases. If they wait until late 2026 or late 2027 to think seriously about provenance, labeling, or product controls, they are likely already behind.

    The Real Compliance Work Is Technical And Procedural

    The practical challenge here is not writing one good disclosure sentence.

    It is proving that the right information survives the actual distribution path.

    Companies should be asking questions like these now:

    • Which systems generate image, video, or audio outputs that may fall inside the statute?
    • What provenance or metadata is currently attached to those outputs?
    • Does that data survive export, reposting, resizing, transcoding, or partner distribution?
    • Can the company actually detect its own output reliably through a free user-facing tool?
    • If the system is licensed out, where is the contractual requirement preserving latent disclosure capability?
    • What happens when a downstream user strips, breaks, or disables provenance markers?

    Those are engineering, product, legal, and vendor-management questions at the same time.

    That is also why this law matters. It forces a more operational version of AI transparency than a lot of commentary admits.

    What Records Companies Should Keep

    The statute does not prescribe a general recordkeeping program. As a compliance and defensibility measure, however, a company that may be covered now or later should document its scope analysis and implementation work.

    At a minimum, that record should include:

    • system inventory for covered media-generation tools;
    • monthly-visitor-or-user basis for any threshold analysis;
    • detection-tool design and testing records;
    • provenance and disclosure specifications;
    • documentation showing whether manifest and latent disclosures are technically feasible in each workflow;
    • API availability and user-access controls for the detection tool;
    • contract terms for licensed systems;
    • incident or exception handling when provenance is stripped, broken, or unavailable; and
    • decision logs for scope calls, especially where the company concluded a system or workflow was outside the statute.

    That kind of documentation matters because California's law is enforceable through civil actions, even though the statute does not itself create a general recordkeeping section.

    The Penalty Structure Should Get Attention

    The statute authorizes a civil penalty of $5,000 per violation, enforceable by the Attorney General, a city attorney, or a county counsel. Each day of noncompliance is a discrete violation for a covered provider, large online platform, or capture-device manufacturer. The statute separately provides an injunctive remedy and fees and costs for a third-party licensee's failure to cease using a revoked system.

    That does not automatically mean immediate aggressive enforcement. It does mean the law should not be treated as symbolic.

    The per-day structure is exactly the kind of thing that makes delayed operational fixes more expensive later.

    What Companies Should Do Now

    The short version is simple.

    If you are clearly a covered provider, this should already be implementation and validation work.

    If you are more likely to be affected by the January 2027 or January 2028 phases, use the current window to map systems, test provenance behavior, and clean up any workflow that assumes transparency can be bolted on at the last minute.

    The best immediate steps are:

    1. Identify which products and workflows generate image, video, or audio content that may be covered.
    2. Confirm whether any system crosses the current monthly-user threshold.
    3. Test whether provenance data survives the real channels where content is shared.
    4. Review whether a free user-facing detection tool and API are actually ready.
    5. Check license agreements and downstream controls for any third-party distribution of the system.
    6. Build a written record of scope, exceptions, testing, and fixes.

    Bottom Line

    As of August 2, 2026, the covered-provider provisions are operative and should be treated as current compliance requirements.

    The deeper point is that this statute is not mainly about slogans like "AI-generated content should be labeled." It is about whether a company can produce working detection tools, persistent provenance, durable disclosures, and defensible records across real content workflows.

    That is where the compliance work actually is.

    Sources

  • Minnesota’s New Nudification Law Is Already Becoming a Test Case for AI Platform Liability

    Minnesota’s New Nudification Law Is Already Becoming a Test Case for AI Platform Liability

    Minnesota's new nudification law is already in court.

    That matters because the statute is broader than a simple downstream ban on abusive deepfake distribution. It targets covered nudification services at the tool layer, reaches realistic depictions of intimate parts not shown in the original image or video, and uses a liability structure that puts real pressure on the companies that build or offer those services.

    The immediate headline is simple. xAI sued to block the law. The court refused to stop it on an emergency basis. So Minnesota's Chapter 72 is now live while the constitutional fight continues.

    That is enough to make this one of the clearest current test cases for how far a state can go when it tries to impose liability on AI-enabled image tools themselves.

    What Minnesota Actually Enacted

    Minnesota's enacted law is Chapter 72, drawn from H.F. 1606.

    The core operative section is new Minnesota Statutes 325E.91, titled PROHIBITION ON NUDIFICATION TECHNOLOGY.

    The law defines "nudify" in a specific way. It covers altered or generated images or video that depict an intimate part not shown in the original image or video of an identifiable individual, where the result is realistic enough that a reasonable person would believe the intimate part belongs to that person.

    That definition matters because the incorporated concept of an "intimate part" is broader than ordinary references to nudity. It reaches areas including the inner thigh, buttocks, groin, and breast. The statute is also not limited by an express consent requirement.

    The prohibition is directed at the service layer. Under subdivision 2, a person who owns or controls a service may not:

    • allow a user to access, download, or use a website, application, software program, or other service to nudify an image or video; or
    • nudify an image or video on behalf of a user.

    The statute also bars advertising or promoting a service that performs those actions.

    At the same time, the law is not drafted as a universal ban on every image-editing capability that could be abused. Subdivision 3 excludes a service that requires user technical skill to nudify an image or video. That carveout will matter in any fight over how broadly the statute can reach practical product design choices.

    That design choice is the important part. Minnesota did not just create a takedown rule or a disclosure rule. It wrote a direct prohibition on covered automated nudification functionality aimed at the service itself.

    Why Companies Are Paying Attention

    The penalty structure is severe enough to get attention even before any final ruling on the merits.

    The law authorizes enforcement by the Minnesota Attorney General under section 8.31. In addition to other remedies, a violator is subject to a civil penalty of up to $500,000 for each unlawful access, download, or use under subdivision 2.

    That is a very large number for a statute aimed at a consumer-facing tool category that can generate high-volume activity quickly.

    But the Attorney General penalty is only part of the pressure. Subdivision 4 also creates a private cause of action for the depicted individual, including compensatory damages of up to three times actual damages, punitive damages, injunctive relief, costs, attorney fees, and other equitable relief.

    The enacted text also routes collected penalties into victim-service funding through the Office of Justice Programs. That feature helps explain the statute's posture. This is being framed not as a labeling problem, but as a victim-protection and platform-liability problem.

    The effective-date clause is also direct. Chapter 72 says the section is effective August 1, 2026, and applies to causes of action accruing on or after that date.

    What xAI Is Challenging

    According to the challenge as described in AP reporting and the emergency litigation, xAI does not deny the state's interest in addressing synthetic sexual abuse.

    Its argument is narrower and more structural. The company says the law reaches too far, lacks a safe-harbor path for companies making good-faith efforts to block misuse, and sweeps in protected material because of how it defines the prohibited conduct.

    That overbreadth framing matters because the challenge is not only about sexual deepfakes in the colloquial sense. xAI argues the statute lacks limiting elements such as consent, scienter, and purpose requirements, and can reach realistic altered imagery that is nonsexual, consensual, or otherwise protected.

    That is a familiar pattern in AI litigation. The company is not arguing that the underlying harm is fake. It is arguing that the state's chosen regulatory mechanism is overbroad.

    For Minnesota, the important point is that this challenge is not mainly about disclosure, watermarking, or post hoc removal. It is about whether a state can prohibit covered nudification functionality and tie that prohibition to very large per-use penalties and private civil exposure.

    The First Court Ruling Matters, But Only In A Limited Way

    The court has already made one important move, but it is easy to overread it.

    In the July 31, 2026 order cited above, the District of Minnesota denied xAI's request for a temporary restraining order before the law took effect. The order emphasized timing. The court noted that xAI filed its emergency motion on July 29, nearly three months after the law was signed and only three days before the effective date. The court said that delay suggested the harm was not immediate.

    That is a procedural loss, not a final merits ruling that the statute is constitutional.

    Still, it matters in practice. It means Minnesota's law took effect while the litigation continues. It also means challengers to new AI laws can lose early if they wait too long to seek emergency relief, even when the underlying constitutional arguments remain open.

    The same order also moved the case onto an expedited preliminary-injunction track, with Minnesota's opposition due August 12, xAI's reply due August 17, and a hearing set for August 19. So the procedural story is no longer just a TRO denial. The case is already in active merits-stage briefing over whether Chapter 72 can stay in force while the lawsuit proceeds.

    Why This Case Matters Beyond Minnesota

    This dispute deserves attention because it regulates a different part of the stack than many earlier AI laws.

    Some AI statutes focus on disclosures. Others focus on impersonation or downstream misuse. Minnesota's nudification law is more direct about restricting access to covered nudification services themselves.

    That makes the case useful for companies that operate image-generation, editing, or transformation systems, even if they do not market them for sexualized use.

    The practical questions are concrete:

    • How much misuse prevention is enough if a statute has no explicit safe harbor?
    • How broadly can a state define a prohibited nudification category before ordinary editing, consensual uses, or protected depictions start to matter?
    • When a law imposes penalties per access, download, or use, how does a court think about scale?
    • Does the state's interest in preventing deepfake sexual abuse justify tool-level restrictions that go beyond after-the-fact takedown or civil remedies against users?

    Minnesota has put those questions into a live case.

    What Companies Should Do Now

    Companies offering image-generation or image-editing features should not treat this as a Minnesota-only oddity.

    Even if other states do not copy this exact statute, the enforcement logic is now visible. A state can try to move upstream from punishing bad actors to restricting covered automated functionality that can be used to generate abusive synthetic intimate imagery.

    That means product teams should be reviewing:

    • whether any feature can realistically be used to create realistic altered depictions of intimate parts of real people;
    • what safeguards exist before image generation, editing, export, and sharing;
    • whether abuse-prevention controls, product boundaries, and escalation rules are documented clearly enough to support a regulator, court, or internal response;
    • whether the company has a defensible position on minors, consent, identity, and realistic depictions; and
    • how quickly the company could respond if another state adopts a tool-access model instead of a narrower misuse model.

    The legal issue here is not only whether a bad image can be removed later. It is whether a covered service can be offered in its current form under a state law aimed at the tool itself.

    Bottom Line

    Minnesota's Chapter 72 is one of the clearest new examples of a state trying to regulate AI-enabled synthetic intimate imagery at the platform-access level, not just at the takedown level.

    xAI's early loss on emergency relief does not resolve the constitutional merits. But it does mean the law is in force while the fight continues.

    That is enough to make this case worth close attention. If Minnesota's model survives, it may become a template for other states looking for a more aggressive way to regulate synthetic intimate-imagery tools.

    Sources and Related Clearon Coverage

  • Courts and AI

    Courts and AI

    Courts and AI

    Courts and AI

    Court rules, standing orders, sanctions rulings, privilege and work-product decisions, protective-order restrictions, and tribunal guidance on AI use.

    This page tracks what courts and tribunals are requiring, permitting, warning about, and sanctioning. It is about rules and rulings, not the broader universe of AI-related lawsuits.

    44tracked court-rule and ruling developments
    13jurisdictions and tribunal categories
    5views for rules, rulings, tribunals, and bar guidance
    242026-dated tracker updates

    Featured alert: AI court rules and rulings

    Courts are moving from general warnings about artificial intelligence to concrete filing certifications, protective-order restrictions, privilege rulings, and sanctions frameworks. There is still no single national rule, but there is now a growing body of court-specific requirements and decisions.

    Bottom line: This page is a court-rules-and-rulings tracker. It focuses on what judges, courts, and tribunals are saying and doing, not on the full field of AI-related lawsuits.

    What this page covers

    Court rules and standing orders

    Forum-specific filing certifications, AI disclosure rules, sanctions warnings, and state court policies.

    Privilege, work product, and protective orders

    Early decisions on AI-assisted filings and advocacy preparation, tool identity, discovery confidentiality, and open AI restrictions.

    Patent practice moved

    Patent-office guidance and AI inventorship now live on a separate Patent Practice page, not in this court-rules-and-rulings tracker.

    State court and bar guidance

    State court policies, local administrative orders, and state or local bar guidance verified against primary sources.

    Featured developments

    Category Development Practice point
    Privilege / work product United States v. Heppner and Warner v. Gilbarco reached different results on AI-related work product. AI use does not create one uniform privilege rule; counsel direction, platform type, confidentiality, and procedural posture matter.
    Protective orders Morgan v. V2X and Jeffries v. Harcros Chemicals restricted AI use with confidential or discovery material. Protective orders should address open vs. closed AI tools, training, retention, deletion, and disclosure.
    Filing rules Florida and New York now show two statewide approaches: Florida requires signer certification that cited authorities exist and are accurately cited; New York permits AI-assisted submissions without systemwide disclosure but requires independent verification. Lawyers should treat verification as the baseline obligation even when disclosure is not required.
    Sanctions / local counsel The Ninth Circuit’s Lnu v. Blanche order and the Northern District of Mississippi’s Withers v. City of Aberdeen sanctions order show courts escalating remedies for AI-fabricated authorities. Candor, signer review, local-counsel supervision, and prompt correction can matter as much as the original AI use.
    Patent practice moved Patent-office guidance and AI inventorship have been moved off this page and are tracked separately on the Patent Practice page. Use this page for court rules, rulings, sanctions, privilege, and protective-order developments rather than USPTO, PTAB, or TTAB practice.
    Evidence Proposed Federal Rule of Evidence 707 would address machine-generated evidence. AI evidence issues may move from filing guidance into admissibility doctrine.

    AI court rules and rulings tracker

    Search court rules, standing orders, sanctions decisions, protective-order rulings, administrative tribunal guidance, and bar guidance that shape how lawyers can use AI before courts and tribunals.

    Last updated 2026-08-12
    44published tracker rows
    13jurisdictions and tribunal categories
    21court-rule and standing-order items
    15rulings and sanctions items
    Date / Type Jurisdiction / Authority Development Requirement or Outcome Practice Takeaway Source Status
    2026-02-17Cases Federal
    S.D.N.Y.
    United States v. Heppner
    Privilege; work product
    Attorney-client privilege and work-product protection denied Consumer AI use outside counsel direction is high risk for privilege and work-product claims primary order
    2026-02-10Cases Federal
    E.D. Mich.
    Warner v. Gilbarco Inc.
    Work product
    AI-related litigation materials protected as work product; defendants’ motion to compel denied in relevant part AI use does not automatically waive work product in civil litigation when disclosure is not likely to reach an adversary primary order
    2026-03-30Cases Federal
    D. Colo.
    Morgan v. V2X Inc.
    Work product; tool identity; protective order
    Work product reportedly protected but AI tool identity had to be disclosed; protective order amended Tool identity may be discoverable even when AI-assisted mental impressions remain protected primary order
    2025-10-30Cases Federal
    E.D. Mich.
    Warner v. Gilbarco Inc. protective-order amendment
    Protective order
    Court modified Rule 26(c) protective order so documents marked confidential shall not be uploaded onto any AI platform Protective orders can impose broad AI-upload bans for confidential discovery primary order
    2026-03-25Cases Federal
    D. Kan.
    Jeffries v. Harcros Chemicals Inc.
    Protective order
    Court granted motion to amend protective order and entered defendants’ proposed language restricting open AI tools for discovery materials Discovery orders may restrict public AI based on retention training deletion clawback privacy and security risks primary order
    2026-06-15Court Rules Florida
    Supreme Court of Florida
    In re Amendments to Florida Rule of General Practice and Judicial Administration 2.515
    Court filing certification; sanctions
    Signer represents cited legal authorities exist and are accurately cited; sanctions expressly authorized after notice and opportunity to be heard Statewide uniform rule replaces varied circuit AI disclosure and certification requirements; comments due 2026-08-11 primary administrative order
    2026-01-01Court Rules Federal
    U.S. Bankruptcy Court S.D. Cal.
    General Order 210 and CSD 5013
    Court filing disclosure and certification
    Disclosure and certification required through local form CSD 5013; filer identifies AI program and certifies factual/legal accuracy check outside AI Useful model for courtwide filing-attestation process primary order
    2026-01-28Court Rules Federal
    D. Kan.
    Standing Order 26-01 Use of Artificial Intelligence in Preparing Court Filings
    Court filing verification; sanctions
    Litigants remain responsible for verifying AI-assisted content; court may strike filings impose sanctions or require sworn AI-use statements Good example of districtwide caution plus discretionary case-specific disclosure primary order
    2025-12-01Court Rules Federal
    D. Colo. Judge Nina Y. Wang
    Standing Order Regarding Use of Generative AI in Court Filings
    Court filing certification; client consent
    Every filing must include AI certification; if AI used counsel must certify human review and client consent Judge-specific orders may go beyond Rule 11 by requiring AI-use certifications in every filing primary order
    2024-10-21Court Rules Federal
    D. Colo. Magistrate Judge Susan Prose
    Standing Order Requiring Certification Re Use of AI in Filings
    Court filing certification
    Specified motions must certify AI use or non-use; noncompliant filings may be stricken Certification requirements may be limited by motion type and referral posture primary order
    2023-06-06Court Rules Federal
    E.D. Pa. Judge Michael M. Baylson
    Standing Order Re Artificial Intelligence in Cases Assigned to Judge Baylson
    Court filing disclosure and certification
    AI use must be disclosed in a plain factual statement and citations must be certified as verified Early judge-specific model for AI disclosure and citation verification primary order
    2023-06-08Court Rules Federal
    U.S. Court of International Trade Judge Stephen Vaden
    Order on Artificial Intelligence
    Confidentiality; court filing disclosure
    Parties using generative AI must disclose program and AI-drafted text and certify no unauthorized disclosure of confidential or business proprietary information Important confidentiality-focused court order for AI use in litigation filings primary order
    2025-06-10Proposed Rules Federal
    Judicial Conference Advisory Committee on Evidence Rules
    Proposed Federal Rule of Evidence 707
    Machine-generated evidence; admissibility
    Would require Rule 702-style reliability showing when machine-generated evidence would be subject to Rule 702 if testified to by a witness Track as systemic evidence-rule development separate from filing-certification standing orders primary committee report
    2024-06-10Court Rules Federal
    U.S. Court of Appeals for the Fifth Circuit
    Decision not to adopt proposed AI briefing rule
    Appellate filing certification
    Court declined to adopt a special AI rule at that time Important negative datapoint: existing certification and accuracy duties may be viewed as sufficient at appellate level primary court rule-change page
    2023-11-13Court Rules Federal
    D. Haw.
    General Order 23-1 re In re Use of Unverified Sources
    Court filing disclosure; unverified sources
    Requires a Reliance on Unverified Source declaration when counsel or a pro se party submits filing material generated by an unverified source; excludes basic research tools such as Westlaw Lexis Fastcase Bloomberg Law Westlaw Edge Lexis+ or similar reliable legal sources Useful district-wide model treating generative AI output as an unverified source primary order
    2024-12-01Court Rules Federal
    D. Neb.
    Nebraska Civil Rule 7.1(d) Generative AI and Certificate of Compliance
    Court filing certification; Rule 11
    Requires certificate stating no generative AI was used or that a human verified all generated text citations and legal authority Notable district-wide local rule rather than individual standing order primary local rules
    2025-09-02Court Rules Federal
    N.D. Tex.
    Local Civil Rule 7.2(f) and Local Criminal Rule 47.2(e) AI disclosure
    Court filing disclosure
    A brief prepared using generative AI must disclose this fact on the first page under the heading Use of Generative Artificial Intelligence; no disclosure certifies no generative AI was used Track as district-wide local-rule approach primary court rule page
    2025-09-01Court Rules California
    Judicial Council of California
    California Rule of Court 10.430 and Standard of Judicial Administration 10.80
    Judicial-branch generative AI policy
    Courts that allow generative AI must adopt a use policy or prohibit use; Standard 10.80 provides guidance for judicial officers acting in an adjudicative role Statewide court-system governance model rather than attorney filing-disclosure rule primary rule
    2025-01-01Court Rules Illinois
    Supreme Court of Illinois
    Illinois Supreme Court Policy on Artificial Intelligence
    Court and litigation AI use; existing-rule sufficiency
    Policy permits AI use subject to existing legal ethical and court rules and says existing rules are sufficient Important contrast to jurisdictions adopting new disclosure mandates primary court announcement
    2025-08-01Court Rules Louisiana
    Louisiana Legislature
    Louisiana Code of Civil Procedure article 371(C)
    Evidence authenticity; AI evidence
    Requires reasonable diligence regarding authenticity of evidence before offering it to the court Track as evidence/authenticity rule rather than filing-certification rule primary act text
    2024-03-05Other New Mexico
    New Mexico Legislature
    HB 182 amendments to the Campaign Reporting Act
    1-19-26.8
    State law regulates AI-generated election-related ads and separately prohibits certain knowingly deceptive AI media distributed within ninety days of an election unless statutory disclaimer conditions are met Enacted law requires disclaimers for covered AI-generated political advertisements and creates civil/criminal enforcement around materially deceptive media; The Babylon Bee sued on 2026-08-11 arguing the disclaimer regime is unconstitutional as applied to satire and parody https://www.nmlegis.gov/sessions/24%20Regular/final/HB0182.PDF
    2025-08-08Tribunals Federal administrative
    Executive Office for Immigration Review
    Policy Memorandum 25-40 guidance on generative AI in immigration proceedings
    Administrative tribunal filings; hallucinated citations
    No blanket ban or mandatory disclosure; adjudicators may address inaccurate AI-assisted filings through existing authorities Useful admin-tribunal example focused on verification and discipline rather than blanket prohibition primary policy memo
    2025-06-05Court Rules Arkansas
    Supreme Court of Arkansas
    Proposed Arkansas Supreme Court Administrative Order No. 25 Artificial Intelligence
    Court-system AI policy; confidential court data
    Proposed administrative order published for comment addressing generative AI use with confidential court data State supreme court-level AI governance proposal focused on confidentiality and court data primary court proposal
    2026-05-20Court Rules Florida
    Eleventh Judicial Circuit of Florida Miami-Dade County
    Administrative Order 26-15 re use of AI in court filings by attorneys and self-represented litigants
    Court filing disclosure and verification
    Requires disclosure of generative AI use and verification that the filing was independently checked Local Florida circuit order aligned with Broward and later superseding earlier Miami-Dade AO 26-04 primary court announcement
    2026-01-26Court Rules Florida
    Seventeenth Judicial Circuit of Florida Broward County
    Administrative Order 2026-03-Gen use of AI in court filings
    Court filing disclosure and certification
    Requires disclosure/certification when generative AI is used in court filings and emphasizes accuracy confidentiality candor diligence and procedural-rule compliance Local Florida circuit order requiring AI-use certification in filings primary order
    2025-12-08Court Rules North Carolina
    Superior Court of Cabarrus County
    Revised Administrative Order re Artificial Intelligence in Superior Court Proceedings
    Court filing disclosure; AI-generated content; pro se and attorney filings
    Revised local administrative order governs AI use in superior court proceedings and supersedes prior Cabarrus order County-level state court AI order; useful as an early state trial-court model primary order
    2024-01-19Bar Guidance Florida
    The Florida Bar
    Florida Bar Ethics Opinion 24-1 Lawyers’ Use of Generative Artificial Intelligence
    Lawyer ethics; competence; confidentiality; supervision; fees; advertising
    Lawyers may use generative AI if they comply with existing ethics obligations including confidentiality competence supervision candor fees and advertising duties State bar ethics guidance should be tracked separately from court filing orders primary bar ethics opinion
    2023-11-16Bar Guidance California
    State Bar of California
    Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law
    Lawyer ethics; competence; confidentiality; supervision; billing; candor
    Applies existing California professional duties to generative AI use and flags confidentiality competence supervision candor and billing risks State bar practical guidance complements California court-system Rule 10.430 but serves a different audience primary bar guidance
    2024-03-28Bar Guidance Michigan
    State Bar of Michigan
    Transforming the Legal Profession in the Age of AI report and resources
    Lawyer ethics; competence; confidentiality; unauthorized practice; access to justice
    State Bar of Michigan identifies ethical considerations and lawyer obligations to understand AI’s benefits and risks Useful Michigan-specific bar source for ethics and practice training rather than a binding court order primary bar resource
    2024-08-07Bar Guidance New York
    New York City Bar Association
    Formal Opinion 2024-5 Generative AI in the Practice of Law
    Lawyer ethics; confidentiality; competence; candor; supervision; fees
    Opinion identifies existing professional duties implicated by generative AI use including confidentiality competence diligence candor supervision and client communication Use as New York ethics guidance; do not label as statewide court rule primary bar ethics opinion
    2026-06-04Cases Oregon
    Oregon Supreme Court
    Aldridge v. Tussing
    Fabricated authorities; sanctions; pro se filings
    Court struck petition and show-cause response and dismissed proceeding Repeating fabricated-authority misconduct after a direct warning can convert a filing error into case-ending sanctions primary order
    2026-06-04Cases Oregon
    Oregon Supreme Court
    Witkin v. McGreevy
    Fabricated authorities; sanctions; certification; pro se filings
    Court struck response imposed $500 sanction and allowed corrected filing with source-existence certification Prompt compliance and acceptance of responsibility may mitigate sanctions but do not excuse an unverified filing primary order
    2026-03-23Cases Federal
    District of Oregon
    Couvrette v. Wisnovsky
    Fabricated authorities; Rule 11; local counsel; fee shifting
    Court finalized $94,704.38 fee-and-cost award allocated 85% to lead counsel and 15% to local counsel after earlier sanctions and dismissal with prejudice Local counsel and supervising lawyers cannot treat filing and pro hac vice responsibilities as merely administrative primary order
    2026-06-03Cases Federal
    Ninth Circuit
    Lnu v. Blanche
    Fabricated authorities; inaccurate authorities; candor; appellate discipline
    Court imposed $2500 on each lawyer six-month suspensions broad notice duties two-year AI disclosure and verification requirements and licensing-authority referrals Candor after discovery of an AI-assisted error can materially affect discipline and firm policies do not replace personal verification primary published order
    2026-06-01Court Rules New York
    New York State Unified Court System
    Part 161 Use of Artificial Intelligence Technology
    Court filing verification; AI use; sanctions
    AI use is permitted without systemwide mandatory disclosure but users must understand tool limits and independently verify papers contain no fabricated or fictitious cases statutes or other material New York chose a verification-first statewide rule while allowing individual judges to adopt additional part rules primary rule
    2026-06-08Cases Federal
    N.D. Miss.
    Withers v. City of Aberdeen
    Fabricated authorities; Rule 11; local counsel; pro hac vice; disqualification
    Court disqualified all four lawyers from the case revoked two pro hac vice admissions barred those lawyers from appearing in the district for two years imposed fines and referred the order to disciplinary authorities Local counsel and sponsoring counsel face personal risk when they act as a rubber stamp for AI-assisted filings prepared by others primary docket; secondary order copy
    2026-06-16Bar Guidance California
    State Bar of California
    Proposed Amendments to the Rules of Professional Conduct Related to Artificial Intelligence
    Lawyer ethics; competence; confidentiality; supervision; agentic AI
    State Bar seeks public comment on proposed amendments addressing AI use in legal practice California may move from practical AI guidance toward binding professional-conduct language including agentic-AI issues primary bar proposal
    2026-06-11Cases Federal
    E.D. Tex.
    McCormick v. Texakoma Financial Inc.
    Fabricated authorities; Rule 11; attorney supervision; verification certification
    Court sanctioned attorney Amy L.B. Ginsburg publicly reprimanded her required CLE required review of 2026 filings for authority accuracy and imposed a certification-of-verification requirement for future filings Wrong-draft and staff-blame explanations are unlikely to mitigate if counsel cannot show personal verification of authorities quotes and the filed version primary docket; secondary summary
    2026-03-20Cases Ohio
    Ohio Court of Appeals Eleventh Appellate District
    State v. Coleman
    Fabricated record quotations; sanctions; nonlawyer supervision; duty to correct
    Court imposed a $2000 sanction credited against settlement payment referred counsel to disciplinary authorities struck the application removed counsel required CLE required apologies and imposed two-year court-notice and filing-certification obligations AI supervision failures are not limited to fake case citations; fabricated record quotations and failure to correct after notice can trigger broad protective sanctions primary opinion
    2026-04-01Bar Guidance Ohio
    Ohio Board of Professional Conduct
    Ohio Ethics Guide Artificial Intelligence for Lawyers and Judicial Officers
    Lawyer and judicial ethics; competence; confidentiality; supervision; candor; judicial decision-making
    Nonbinding Board staff guide applies existing Ohio professional-conduct and judicial-conduct duties to AI use including independent verification confidentiality safeguards supervision fee reasonableness candor and judicial nondelegation Track separately from court filing rules because it is nonbinding ethics guidance but it is a useful Ohio-specific synthesis for lawyers and judges primary ethics guide
    2026-04-03Cases Federal
    Sixth Circuit
    United States v. Farris
    Fabricated quotations; inaccurate authorities; CJA counsel; legal AI product
    Court denied CJA compensation forwarded opinion for disciplinary review served district court and bar authorities and separately removed counsel and ordered new briefing Legal AI tools from established providers can still produce false quotations or misleading case descriptions; attorney verification remains nondelegable primary published opinion
    2026-03-30Cases Federal
    Seventh Circuit
    Dec v. Mullin
    Fabricated authorities; inaccurate quotations; appellate briefing; opposing counsel vigilance
    Court admonished counsel but declined further sanctions because the errors were unintentional and counsel was contrite while also criticizing opposing counsel for failing to catch the errors The verification burden remains on the filer but courts may expect opposing counsel to raise obvious fabricated-authority problems once they are noticed primary opinion mirror
    2026-06-17Cases Michigan
    Michigan Court of Appeals
    Barber v. Morawa
    Fabricated authorities; unsupported citations; sanctions; grievance referral
    Court affirmed denial of new trial but held counsel violated MCR 7.216(C)(1) and MCR 1.109(E)(5) remanded for actual damages and reasonable fees payable personally by counsel and forwarded opinion to the Attorney Grievance Commission Published Michigan appellate authority confirms AI-related citation failures can trigger personal fee exposure and disciplinary referral primary published opinion
    2026-04-28Court Rules Oregon
    Oregon Court of Appeals
    Notice Regarding Court Imposition of Sanctions for Submission of Fabricated Authority Produced by AI
    Fabricated authorities; court notice; sanctions warning
    Fabricated authority can support striking a filing monetary sanctions payable to the court attorney-fee awards to opposing parties and dismissal of the appeal Oregon appellate courts are moving from case-by-case sanctions to broader public notice of verification obligations primary court notice

    No tracker rows match the current filters.

    Publication policy: rows are sourced to primary court, agency, legislature, or bar materials where available. Secondary trackers are used for lead generation and are not treated as final authority.

    What lawyers and court-facing teams should do now

    • Review judge-specific standing orders, local rules, state court policies, and tribunal guidance before major filings.
    • Verify every citation, quotation, record reference, legal proposition, and factual assertion in AI-assisted work.
    • Do not treat a no-disclosure rule as a no-review rule; court rules increasingly focus on whether the filing was independently verified.
    • Do not upload confidential discovery, privileged material, trade secrets, protected health information, export-controlled information, or business proprietary information into public AI tools.
    • Confirm whether any protective order permits closed enterprise AI tools and whether the tool contract addresses training, retention, disclosure, and deletion.
    • Treat AI-generated evidence differently from AI-assisted drafting. Evidence still must be authentic, admissible, and tied to real-world facts.

    Source note: Clearon gives preference to primary court, agency, legislature, and bar sources. Secondary trackers are used as leads, not as final authority.

  • Satire and Parody Are One of the Clearest Fault Lines in State AI Election Laws

    Satire and Parody Are One of the Clearest Fault Lines in State AI Election Laws

    The easiest way to summarize state election-AI laws is to sort them into disclosure laws and prohibition laws.

    That summary helps, but only up to a point.

    One of the sharper fault lines in the selected state cluster is satire and parody.

    Once a statute reaches political memes, ridicule, caricature, parody videos, or other obviously expressive content, the legal problem changes. The fight stops being only about synthetic deception and starts becoming a First Amendment fight over how a state treats speech that is false in a literal sense but often protected in context.

    That is why satire and parody are a central comparison point in this selected-state field.

    Disclosure Versus Prohibition Is Not The Whole Story

    Many state election-AI laws already mix techniques.

    Some use disclosure language. Some use prohibition language with safe harbors. Some pair a liability rule with an exception, exclusion, or prescribed warning. The same statute can look like a disclosure law from one angle and a prohibition law from another.

    That is why the older binary starts to break down.

    A better question is simpler: when satire or parody is involved, what does the statute actually do?

    Three Practical Buckets

    For a selected-state comparison, the working split that makes the most sense right now has three buckets:

    1. Express carveout
    2. Conditional carveout
    3. No clear carveout

    An express carveout means the statute excludes satire or parody from the operative restriction.

    A conditional carveout means the statute mentions satire or parody but still ties lawful use to a disclaimer, label, or other required treatment.

    A no-clear-carveout statute is one where satire or parody is not clearly spared, or where the text is too thin or too muddled to summarize confidently as a real exemption.

    This framework is not elegant. It is useful.

    Arizona Shows The Cleanest Express Carveout

    Arizona is the easiest place to start.

    Its enacted Chapter 199 is one of the clearer examples of an express satire/parody exclusion in this area. That matters because Arizona gives courts and drafters a model for what it looks like when a legislature actually decides to keep parody outside the statute's operative reach.

    That does not end every constitutional question. It does show that a state can draft more precisely than many of its peers.

    Colorado, New York, and Oregon also fit more comfortably in the express-carveout conversation based on the enacted measures cited in Clearon's selected-state comparison.

    California Is The Best Example Of Why One State May Need Two Labels

    California is where shorthand causes trouble.

    If you say California has a satire/parody carveout, that is partly true and partly too broad. If you say California only uses a disclosure-conditioned model, that is also incomplete.

    The cleaner explanation is that California's two enacted 2024 laws need to be split, and that their current litigation posture should be kept in view.

    AB 2655 contains an express satire/parody exemption inside a broader platform-duty regime, while AB 2839 is the more disclosure-conditioned and speaker-facing statute. Both laws drew district-court relief in 2025, and the cited March 2026 appellate filings are tied to the AB 2655 side of the case rather than a single unified merits ruling across both statutes. That split is one reason California has become such an important litigation state. The constitutional arguments do not attach to one perfectly unified statutory model.

    So California is not just a comparison state. It is a warning about over-compression.

    New Mexico Shows Why A Conditional Carveout Still Draws Fire

    New Mexico is useful because it tests a purported middle category.

    The Bee's complaint there argues that the challenged year-round advertisement-disclaimer regime does not truly exempt satire and parody in a meaningful way. On that theory, the state is not banning parody outright, but it is still burdening it by forcing a government-prescribed AI warning onto the message.

    That is the core purported-conditional-carveout problem.

    New Mexico's defendants had not yet answered when this draft was prepared, so the cleaner frame is narrower. The Bee alleges that the compelled label changes the message and cuts against the point of the satire itself, and the complaint also cites a nonbinding state attorney-general opinion that treated the satire language as providing no meaningful exemption beyond the disclaimer already required elsewhere in the statute. That means this article is using New Mexico as an alleged conditional-carveout model under current pleadings, not as a final judicial holding about what the statute means.

    That is not a side issue. It is the main constitutional question.

    Hawaii Shows What Happens When Courts Do Not See A Real Carveout

    Hawaii is the cautionary example on the other side.

    In The Babylon Bee v. Lopez, the district court granted summary judgment to the plaintiffs and permanently enjoined Act 191 on January 30, 2026. The court's reasoning was broader than the carveout issue alone, but the absence of a sufficient explicit or implicit satire/parody exception was still one important part of the analysis. That is why Hawaii fits best in the no-clear-carveout bucket.

    Hawaii matters because it shows that a court may not be satisfied by broad state assurances that the law is aimed at deception rather than humor. If the text does not clearly protect the expressive category, the state may still lose on broader First and Fourteenth Amendment grounds. Hawaii officials later closed the case without appealing.

    Why This Is The Real Doctrinal Pressure Point

    The common feature across these statutes is not merely that they regulate AI. It is that they regulate political communication that may include AI-generated image, audio, or video.

    Once that communication also includes satire or parody, the state is no longer only policing falsity. It is touching a form of political expression that often works by exaggeration, inversion, and deliberate literal untruth.

    That is why courts are likely to care less about abstract labels like "disclosure law" or "deepfake law" and more about the exact treatment of parody in the operative text.

    This is also why a state can lose even if it has a plausible anti-deception purpose. Purpose alone does not answer the compelled-speech and overbreadth problems.

    Bottom Line

    In the selected statutes and current Bee litigation, one of the clearest splits is not just disclosure versus prohibition.

    It is whether the statute clearly protects satire and parody, protects them only on conditions, or does not protect them clearly at all.

    Arizona, California, Hawaii, and New Mexico are useful comparison states precisely because they do not all answer that question the same way. For lawyers, legislators, and judges studying this selected-state cluster, that is where one of the clearest current pressure points sits.

    Sources and Related Clearon Coverage

  • Kohls v. Ellison Did Not End Minnesota’s Election AI Law Fight on the Merits

    Kohls v. Ellison Did Not End Minnesota’s Election AI Law Fight on the Merits

    Kohls v. Ellison Did Not End Minnesota's Election AI Law Fight on the Merits

    Minnesota is easy to misread if you look only at the result.

    The challengers in Kohls v. Ellison did not win preliminary relief against Minnesota's election deepfake statute. The Eighth Circuit affirmed the district court, and rehearing was later denied.

    That can sound like a clean appellate approval of the law. It was not.

    The more careful description is that the Eighth Circuit affirmed without resolving the underlying constitutional merits of the statute itself. That makes Minnesota an important but limited precedent in the growing fight over election-related AI laws.

    The statute sits in the same field, but the case is different

    The operative law is Minn. Stat. § 609.771, titled "Use of deep fake technology to influence an election."

    Minnesota therefore belongs in the same general field as California, Hawaii, New Mexico, Arizona, and other states regulating synthetic election media in some form. But its litigation story is procedurally different from the Babylon Bee cases.

    That difference is the whole point.

    What happened on appeal

    The Eighth Circuit appeal in No. 25-1300 came from the district court's denial of preliminary relief.

    The appellate docket shows that judgment was entered on February 9, 2026, affirming in accordance with the panel opinion. Later entries show that the appellants sought rehearing and rehearing en banc, and that both requests were denied on March 31, 2026.

    That gives Minnesota a firmer appellate procedural history than some other election-AI cases now cited around the country. But it does not mean the Eighth Circuit gave the statute a sweeping constitutional endorsement.

    Why the merits limitation matters

    The best way to describe Minnesota's significance is narrow.

    A lot of commentary collapses "the plaintiffs lost the injunction appeal" into "the law was upheld." Those are not always the same thing. A court can deny preliminary relief without giving the state a full merits victory on the substance of the First Amendment challenge.

    That is what makes Minnesota useful but incomplete as precedent.

    What Minnesota does tell other states

    Minnesota still carries real lessons.

    First, plaintiff-specific delay matters. The Eighth Circuit treated Mary Franson's insufficiently explained sixteen-month delay as fatal to the irreparable-harm showing required for preliminary relief.

    Second, standing still does real work in this area. The court held that Christopher Kohls had not established standing on the preliminary-injunction record, while Franson had standing to press her own challenge.

    Third, the absence of preliminary merits relief does not eliminate litigation risk for similar statutes elsewhere. It means only that the Minnesota challengers did not obtain the procedural posture they needed.

    Why Minnesota still matters for New Mexico and the Bee cases

    Minnesota is not a Babylon Bee case, and that distinction matters.

    The Bee cases put pressure on satire, parody, and compelled-warning issues in a specific way. Minnesota's appeal posture is most useful for a different lesson: a state can survive the preliminary-injunction stage without obtaining a full appellate ruling that its law is constitutional.

    So if the point is that challengers can lose early because one plaintiff lacked standing and another waited too long to show urgency, Minnesota helps. If the point is that an appellate court has already blessed the constitutional merits of a state election-AI law, Minnesota does not support that proposition.

    Bottom line

    Kohls v. Ellison did not end Minnesota's election-AI fight with a sweeping merits decision.

    What it shows instead is how much election-law procedure can shape outcomes. The Eighth Circuit affirmed the denial of preliminary relief, rehearing was denied, and the district case remained alive afterward.

    The cleaner takeaway is narrower but still important: Minnesota shows that a state can survive an early challenge without receiving a full appellate ruling on whether its election-AI law ultimately survives First Amendment scrutiny.

    This article summarizes a pending election-law challenge and related procedural rulings. It does not provide legal advice.

  • Babylon Bee v. Bonta Shows Why California’s Election AI Laws Cannot Be Treated as One Thing

    Babylon Bee v. Bonta Shows Why California’s Election AI Laws Cannot Be Treated as One Thing

    Babylon Bee v. Bonta Shows Why California's Election AI Laws Cannot Be Treated as One Thing

    California is still the most useful comparison state for the New Mexico Babylon Bee case. But it only helps if it is described carefully.

    Too much commentary treats California's election-AI fight as though one law did all the work. That is not the cleanest way to understand the dispute. California enacted two related 2024 measures, and they do not handle platform duties, satire, parody, and compelled treatment of election content in the same way.

    That distinction matters because Babylon Bee v. Bonta is not just a story about whether California may regulate deceptive election media. It is also a story about how statutory design changes the constitutional analysis.

    California enacted two different measures

    The relevant California measures are AB 2655 and AB 2839.

    AB 2655, chaptered as Chapter 261 on September 17, 2024, added Elections Code provisions beginning at Section 20510 under the "Defending Democracy from Deepfake Deception Act of 2024" and took effect on January 1, 2025.

    AB 2839, chaptered the same day as Chapter 262, added Elections Code Section 20012 and took effect immediately as an urgency measure. Its legislative topic line is "Elections: deceptive media in advertisements."

    That is the first point lawyers should keep straight. California did not enact one broad election-AI law. It enacted at least two separate measures in the same policy lane, with different structures and different constitutional pressure points.

    The litigation split mattered too

    The Bee plaintiffs sought immediate preliminary relief against AB 2839 in October 2024. California officials later agreed the statute could not be enforced against ADF's clients after the court in Kohls v. Bonta concluded it likely violated the First Amendment.

    The bigger district-court turning points came in August 2025, and they were not the same ruling.

    On August 20, 2025, the court entered final judgment and a permanent injunction as applied to X and Rumble as to AB 2655 on Section 230 preemption grounds. A later stipulation and order extended non-enforcement protection to other providers of interactive computer services, unless that judgment is vacated on appeal.

    On August 29, 2025, the court granted summary judgment and permanently enjoined enforcement of AB 2839 against the named plaintiffs on First Amendment grounds.

    That distinction matters because AB 2655 did not fall on a single broad holding that every part of it was unconstitutional. The platform-duty regime was treated as preempted by the Communications Decency Act, while the AB 2839 ruling squarely addressed the First Amendment.

    Why the statutory split matters

    California is a bad comparison state if it is used sloppily.

    AB 2655 is the platform-duty statute in the California pair, even though it also contains an express satire/parody exemption. AB 2839 is the more direct speaker-and-distributor statute, and its treatment of satire and parody still turns on disclosure mechanics.

    That difference matters because a court may respond differently to a large-platform removal and labeling regime than to a law that directly regulates political speakers and distributors.

    California's litigation value is not just that "California lost." Its value is that the case shows how much constitutional weight can turn on the exact way a legislature writes a synthetic-media rule.

    Why California still matters for New Mexico

    New Mexico's case is narrower than the full California fight, but California remains the nearest high-profile comparison.

    The Bee's New Mexico complaint is mainly aimed at the year-round advertisement-disclaimer regime in HB 182, not every part of the statute's separate ninety-day prohibition structure. That makes California especially relevant because California's dispute also placed heavy pressure on election-related speech rules touching political memes, parody, and compelled treatment of synthetic media.

    California therefore supplies at least three useful questions for New Mexico:

    1. How closely will a court read the exact statutory text instead of the state's general anti-deception rationale?
    2. Will the court treat satire and parody as clearly protected in practice, not just in theory?
    3. When a law forces labels, removals, or other compelled treatment of political content, how much tailoring is enough?

    What California does not prove

    California should not be overstated.

    The district-court result does not automatically decide what happens in New Mexico or elsewhere. California sits in the Ninth Circuit. New Mexico sits in the Tenth. The statutes are not identical, and neither is the procedural posture.

    California also does not prove that every election-related AI disclosure statute is unconstitutional. What it shows is narrower and more useful: courts can treat these laws as serious burdens when they impose platform duties, compelled labels, or other direct treatment of political satire and parody.

    Bottom line

    Babylon Bee v. Bonta matters because California's election-AI laws cannot be analyzed as one undifferentiated package.

    The state enacted AB 2655 and AB 2839 as separate measures. The litigation then turned California into the clearest live example of how statutory design, platform duties, satire treatment, and compelled-speech problems can collide in this area.

    For lawyers watching New Mexico and other state election-AI fights, California is still the comparison state that deserves the closest reading. It just should not be flattened into a one-law story.

    This article summarizes enacted California measures and related litigation materials. It does not provide legal advice.

  • Selected US State AI Election Law Comparison: A Working Memo on Enacted Laws, Disclaimers, Satire, and Litigation

    Selected US State AI Election Law Comparison: A Working Memo on Enacted Laws, Disclaimers, Satire, and Litigation

    Selected US State AI Election Law Comparison: A Working Memo on Enacted Laws, Disclaimers, Satire, and Litigation

    This is a selected-state comparison memo, not a final 50-state survey.

    As of June 23, 2026, the National Conference of State Legislatures said 31 states had enacted some form of election-related AI or synthetic-media law. That NCSL count is the baseline. This article reviews a smaller enacted subset closely enough to compare the main statutory models and the litigation issues now surfacing in the New Mexico, California, Hawaii, and Minnesota disputes.

    That distinction matters. The article is meant to clarify the main models in the field, not to claim that only a handful of states have acted.

    1. Start with enacted laws, not just litigated laws

    The enacted-law field is broader than the states already in court.

    From the materials verified for this memo, the enacted set clearly includes at least Alabama, Arizona, California, Colorado, Florida, Hawaii, Idaho, Indiana, Mississippi, New Mexico, New York, Oregon, Utah, and Wisconsin, alongside other states included in the NCSL total.

    That means New Mexico is not operating in a narrow outlier group. It is part of a substantial and still-growing state-law field.

    2. One common model is disclosure

    Under the disclosure model, a state permits election-related synthetic media at least in some circumstances but requires the speaker to add a warning or disclosure. The trigger often turns on timing, medium, or whether the content depicts a candidate or ballot issue.

    The directly verified examples reviewed for this memo include:

    • Colorado: candidate-election deepfake disclosures with enforcement and private-cause-of-action features.
    • Florida: disclaimers for certain political advertisements, electioneering communications, and related ads that use AI.
    • Indiana: disclaimer requirement when campaign communication includes fabricated media depicting a candidate.
    • New York: political communications using materially deceptive media must carry the statute's disclosure language.
    • Oregon: campaign communications using synthetic media must say the content has been manipulated.
    • Utah: synthetic audio and visual election communications must carry prescribed words.
    • Wisconsin: AI-generated audio or video political ads require disclosure.

    Some statutes sit near the line because they use prohibition language while also tying lawful distribution or exceptions from liability to disclosure mechanics. That overlap matters because it shows why simple labels can hide meaningful structural differences.

    3. Another model is prohibition plus disclosure or safe harbor

    A second model uses prohibition language aimed at deceptive or materially deceptive election media, often with a disclosure safe harbor or adjacent exception. These are not pure bans in the ordinary sense. They are hybrid statutes.

    The verified examples reviewed for this memo include:

    • Alabama: makes certain materially deceptive election communications criminal when distributed to influence an election, subject to statutory exceptions.
    • Arizona: bars deceptive synthetic media close to an election unless the required disclosure is included.
    • Hawaii: reaches reckless distribution of materially deceptive media in candidate elections, subject to listed exclusions and defenses.
    • New Mexico: uses a ninety-day rule tied to knowledge, intent to mislead voters, and likelihood of that result, with a disclaimer safe harbor.

    This is where precision matters for New Mexico. Section 1-19-26.8 is the ninety-day prohibition provision. The Bee's complaint, however, principally challenges the separate year-round advertisement-disclaimer provisions in Section 1-19-26.4.

    4. Satire and parody are the real fault line

    Satire and parody are the hardest comparison point because state laws handle them in very different ways.

    The safest framework is to separate three possibilities:

    • Express carveout: the statute excludes satire or parody from the operative restriction.
    • Conditional carveout: the statute mentions satire or parody but still conditions lawful use on a disclaimer or other required treatment.
    • No clear carveout: the statute does not clearly spare satire or parody, or the exception is too uncertain to summarize confidently from the available text.

    Arizona belongs in the express-carveout bucket. Colorado, New York, and Oregon also use express satire/parody exclusions in the enacted measures cited for this memo.

    California should not be treated as a single blended model. Enacted AB 2655 contains an express satire/parody exemption, while enacted AB 2839 uses a disclosure-conditioned exception that still ties lawful use to label mechanics.

    New Mexico fits the conditional-carveout bucket for purposes of the Bee's complaint because the Bee argues the statute does not truly exempt satire and parody from the challenged ad-disclaimer rule.

    Hawaii is different again. In The Babylon Bee v. Lopez, the district court concluded the law lacked an explicit or implicit satire/parody exception sufficient to save it.

    That is why Arizona, California, Hawaii, and New Mexico are useful comparison points. They do not use the same carveout model.

    5. The litigation cluster still centers on four states

    As of August 12, 2026, the clearest litigation cluster remains:

    • California: AB 2839 and related AB 2655 litigation, with district-court summary-judgment and permanent-injunction relief on key claims and an active Ninth Circuit appeal.
    • Hawaii: Act 191 / S 2687, where the district court entered a permanent injunction and the case later closed without an appeal after a fee settlement.
    • Minnesota: Minn. Stat. § 609.771, where the district court denied preliminary relief and the Eighth Circuit affirmed that denial without reaching the constitutional merits, relying on standing and delay.
    • New Mexico: HB 182, with the Bee's complaint filed on August 11, 2026.

    Litigation status is useful, but it is not a complete proxy for statutory strength. Some laws remain untested because no plaintiff has brought the right case yet.

    Working takeaways

    Several points are already clear.

    First, election-related AI laws are now common enough that New Mexico cannot be treated as a one-off.

    Second, the most important split is not disclosure versus prohibition in the abstract. Many states combine both techniques.

    Third, the key pressure point in the Bee cases is how a statute treats satire and parody. That is where Arizona, California, Hawaii, and New Mexico become especially useful comparison states.

    Fourth, New Mexico's lawsuit should be described carefully. The Bee is not challenging every moving part of HB 182. The complaint is aimed mainly at the year-round advertisement-disclaimer regime, while the statute separately contains a ninety-day prohibition rule.

    Bottom line

    New Mexico sits inside a larger and still-growing state-law field, even if this article only closely reviews a selected subset.

    The most useful comparison question for the current litigation is narrower than a full 50-state inventory. It is whether courts will treat required AI warnings on political satire as a permissible election safeguard or as an unconstitutional burden on protected speech.

    This article is a selected-state comparison memo based on enacted statutes and current litigation materials. It does not provide legal advice.