Author: Clearon AI

  • Babylon Bee’s New Mexico Lawsuit Tests the State’s AI Ad Disclaimer Rule

    Babylon Bee’s New Mexico Lawsuit Tests the State’s AI Ad Disclaimer Rule

    Babylon Bee's New Mexico Lawsuit Tests the State's AI Ad Disclaimer Rule

    The Babylon Bee has opened another front in the fight over state election-deepfake laws, this time in New Mexico.

    On August 11, 2026, the Bee sued members of the New Mexico State Ethics Commission in federal court. The case is The Babylon Bee, LLC v. Castillo, No. 1:26-cv-02628, in the District of New Mexico.

    The complaint does not attack every part of HB 182. Its main target is the law's year-round disclaimer regime for certain covered political advertisements. The Bee argues that those provisions force protected satire and parody to carry a government-prescribed AI warning.

    That framing matters because New Mexico's statute has more than one moving part, and the lawsuit is aimed chiefly at one of them.

    What New Mexico's law does

    New Mexico's 2024 HB 182 amended the Campaign Reporting Act in two different ways relevant here.

    First, Section 1-19-26.4 imposes disclaimer rules on certain election-related advertisements containing materially deceptive media. The required disclaimer format varies by image, video, audio, or mixed media.

    Second, Section 1-19-26.8 creates a separate ninety-day prohibition. It makes it unlawful to distribute materially deceptive media when the speaker knows the media falsely represents the depicted individual, distributes it within ninety days before an election, intends to alter voting behavior by misleading voters, and the distribution is reasonably likely to do so. That provision includes its own disclaimer safe harbor and criminal penalties for willful and knowing violations.

    Those sections are related, but they are not interchangeable. The Bee's complaint is principally aimed at the advertisement-disclaimer provisions, not the separate ninety-day prohibition.

    HB 182 defines "materially deceptive media" as image, video, or audio that depicts an individual engaged in speech or conduct in which the person did not engage, was publicly distributed without the depicted individual's consent, and was produced in whole or in part using artificial intelligence.

    Why the Bee says the law is unconstitutional

    The Bee does not frame the case as a defense of deceptive campaign tricks in general. The complaint alleges compelled speech, overbreadth, vagueness, and content-, viewpoint-, and speaker-based discrimination, both facially and as applied.

    The core theory is that satire, parody, cartoons, and memes often rely on exaggeration, inversion, and literal falsity to make a political point. The Bee says forcing a prescribed AI disclaimer onto that type of expression alters the message and undercuts the joke.

    The complaint also emphasizes that New Mexico did not exempt satire and parody from the challenged disclaimer requirement. It distinguishes between the statute's exclusion for news stories or editorials from the definition of "advertisement" and a separate safe harbor for broadcasters carrying covered material during bona fide news programming.

    Why California and Hawaii matter

    The New Mexico case fits a growing pattern of First Amendment challenges to state election-synthetic-media laws.

    In California, the Bee and related plaintiffs obtained district-court relief against AB 2839, the state's deceptive-media-in-advertisements law. That ruling is part of the larger Babylon Bee v. Bonta litigation, and the California appeal remains active in the Ninth Circuit.

    In Hawaii, the Bee won a permanent injunction against Act 191 in The Babylon Bee v. Lopez. The district court enjoined enforcement in January 2026, and the case later ended without an appeal after a fee settlement.

    Those rulings do not control a federal court in New Mexico. They do, however, show that courts have already treated some state election-synthetic-media laws as serious First Amendment problems when the rules reach political satire or impose broad compelled disclosures.

    Why this case matters beyond the Bee

    As of June 23, 2026, the National Conference of State Legislatures said 31 states had enacted some form of election-related AI or synthetic-media law. The policy trend is real.

    The harder question is how far states may go when regulating content that includes protected political expression, including parody, caricature, ridicule, and political memes.

    That is why the New Mexico case matters beyond one plaintiff. It puts pressure on a common legislative strategy: permit the speech but require a disclosure label when the content falls within the statute's definition of materially deceptive media.

    What to watch next

    Three issues are likely to matter most.

    First, how tightly the court defines the challenged provisions. The case may turn less on the broad idea of election deepfakes and more on whether New Mexico can apply its ad-disclaimer rule to satire and parody.

    Second, whether the state can meaningfully distinguish its statute from the California and Hawaii laws. The text differences matter, and so does the separation between New Mexico's ad-disclaimer regime and its ninety-day prohibition.

    Third, how the court treats the relationship between satire and deception. The Bee's position is that protected satire can depict events that did not happen while still conveying an obvious political message in context. New Mexico will likely argue that the statute targets voter deception, not humor as such.

    Bottom line

    This case chiefly concerns HB 182's advertisement-disclaimer regime, not every part of the law or its separate ninety-day prohibition.

    Its broader significance is where courts draw the constitutional line when election-AI disclosure rules reach protected satire and parody.

    This article summarizes a newly filed federal complaint and related constitutional issues. It does not provide legal advice.

  • Seventh Circuit Says Citation Verification Is Not Just the Filer’s Problem

    Seventh Circuit Says Citation Verification Is Not Just the Filer’s Problem

    Seventh Circuit Says Citation Verification Is Not Just the Filer's Problem

    The Seventh Circuit added an important wrinkle to the growing line of AI-citation cases. The filing lawyer still owns the duty to verify authorities and quotations. But the court also suggested that opposing counsel may face criticism for failing to identify serious citation defects and bring them to the court's attention.

    That is the practical lesson from Dec v. Mullin, a March 30, 2026 immigration decision. The underlying appeal was not about AI. The warning came from the briefing.

    Petitioner's counsel cited two nonexistent cases and included a false quotation in the standard-of-review section. At oral argument, counsel denied using AI. A later letter said she had presumably copied and pasted the language from another brief she could not locate and had failed to verify the citations.

    The Seventh Circuit admonished counsel but stopped short of stronger sanctions. The court emphasized that the errors appeared unintentional, counsel was contrite, and the fabricated authorities were used to support an undisputed legal standard rather than a contested merits issue.

    The more interesting point was about the other side

    The court repeated the familiar rule that trained lawyers must verify the citations and quotations in their own filings. But it then added that opposing counsel's failure to catch the defects and bring them to the court's attention also gave it pause, even if to a lesser degree.

    That is not the same thing as announcing a free-standing duty to audit every sentence in an adversary's brief. The panel did not create such a rule. Still, the signal is clear. When serious authority defects are discovered, courts may expect someone on the other side to raise the problem rather than let it slide.

    Why this matters

    Most sanctions coverage still focuses on the lawyer who filed the defective brief. That remains the main risk, and Dec does not change it.

    What the case adds is a response-side lesson. Citation verification is not just a filing control. It is also part of litigation hygiene once the defect is visible.

    If opposing counsel discovers a nonexistent case, a quotation that does not appear in the source, or a proposition that does not match the cited authority, waiting until oral argument or final disposition may not be the safest choice. The better course may be to raise it promptly through a procedurally appropriate channel.

    That framing fits the broader case pattern. In United States v. Farris, the Sixth Circuit focused on the filing lawyer's failure to verify quotations and case descriptions generated through Westlaw CoCounsel. In Lnu v. Blanche, the Ninth Circuit treated candor after discovery of the error as a major part of the discipline analysis. Dec does not conflict with those cases. It rounds them out.

    A better litigation response pattern

    Law firms do not need a broad new doctrine to act on this. They need a cleaner escalation rule.

    When an adversary filing appears to contain fabricated or materially inaccurate authority, teams should:

    • verify the cited source directly before making the accusation;
    • preserve the defective language and the source comparison;
    • decide quickly whether the issue should be raised through a letter, motion, meet-and-confer process, or the next scheduled hearing;
    • avoid overclaiming if the problem is sloppiness rather than fabrication; and
    • treat the issue as a filing-integrity problem, not a chance for rhetorical theater.

    Bottom line

    Dec v. Mullin does not create a formal duty to re-edit the other side's brief. It does something more practical. It suggests that when serious authority defects are discovered, courts may expect somebody on the other side to say so.

    The filing lawyer still has the primary burden. But the safest appellate posture now looks broader than that: verify your own filing, and if the other side's filing contains serious authority defects, do not assume the court will be impressed if nobody raises them.

    This article summarizes a published appellate decision and related litigation-risk implications. It does not provide legal advice.

  • Four Courts in Three Days Show Citation Failure Is a Filing Risk, Not Just an AI Risk

    Four Courts in Three Days Show Citation Failure Is a Filing Risk, Not Just an AI Risk

    Four Courts in Three Days Show Citation Failure Is a Filing Risk, Not Just an AI Risk

    In a span of three days in early August 2026, four separate courts took action on fabricated, unsupported, or AI-tainted citations. The responses ranged from warnings and published reprimands to monetary sanctions and ongoing verification requirements.

    The cluster matters because it shows the issue moving from isolated incidents to a recognizable pattern across jurisdictions and procedural postures.

    The cases at a glance

    • A federal district court sanctioned a lawyer and imposed a future certification requirement after hallucinated citations appeared in multiple filings.
    • A state appellate court issued a published reprimand after counsel relied on nonexistent authorities.
    • Two other matters involved AI-generated or unsupported citations that triggered show-cause orders or corrective action.

    What stands out is not just the volume, but the range of consequences. Courts are no longer treating these as one-off mistakes. They are treating them as failures of competence and candour that require both punishment and forward-looking controls.

    Why this cluster is different

    Earlier cases often focused on whether the lawyer “should have known” the citation was bad. These decisions increasingly emphasize what the lawyer did after the problem surfaced — how quickly they corrected it, whether they were candid with the court, and whether they put systems in place to prevent recurrence.

    That shift matters for risk management. The exposure is no longer limited to the initial filing error. It now includes the response.

    Practical takeaway

    Firms should treat citation verification as a non-delegable responsibility with documented workflows, not a box-checking exercise. When AI tools are involved, the record should show what the tool produced, what was changed, who reviewed it, and why any remaining risk was accepted.

    The four-court cluster is a reminder that citation failures are no longer rare events that can be handled case-by-case. They are becoming a recurring litigation risk that requires systemic controls.

  • Ontario Lawyer Suspension Moves AI-Citation Failures Into Professional Discipline

    Ontario Lawyer Suspension Moves AI-Citation Failures Into Professional Discipline

    Ontario Lawyer Suspension Shows AI Citation Failures Can Trigger Professional Discipline

    A six-month licence suspension in Ontario demonstrates how quickly an AI-assisted filing error can escalate into a professional-discipline matter when false authorities are followed by misleading statements to the court and dishonesty with the regulator.

    On July 16, 2026, the Law Society Tribunal found that Toronto lawyer Mary Hyun-Sook Lee committed professional misconduct after submitting a factum prepared with generative AI that contained nonexistent or irrelevant case law. The Tribunal ordered a six-month suspension and C$10,000 in costs.

    The panel did not treat this as a simple verification failure. It identified three distinct forms of misconduct:

    • Failure to serve the client competently (Rule 3.1-2)
    • Deliberately misleading the court (Rule 5.1-2)
    • Dishonesty with the Law Society about the use of AI (Rule 2.1-1)

    Why the distinction matters

    Many AI citation cases focus narrowly on whether the lawyer verified the authorities. The Ontario decision adds an important layer: a lawyer’s response after discovering an AI-related error can itself become independent grounds for discipline.

    The panel treated the lawyer’s statements to the court and to the regulator as separate from the initial citation errors. That framing has direct implications for how firms design escalation and disclosure protocols when AI tools produce problematic output.

    Practical implications

    The decision supports several concrete controls:

    • Verify the filed version, not just earlier drafts.
    • Preserve the drafting record so the firm can determine what the AI produced and what was changed.
    • Define an escalation path that includes timely correction and accurate disclosure to the court or regulator.
    • Treat regulatory responses with the same care as representations to a court — the dishonesty finding shows these statements can become part of the misconduct case.

    Bottom line

    AI citation problems are no longer limited to warnings or monetary sanctions. They are now reaching professional discipline, with licence suspensions based on a combination of AI-generated authorities, misleading advocacy, and lack of candour during the regulatory process.

    Verification remains essential, but it is only the first control. Legal teams also need reliable records, a clear correction process, and a plan for accurate responses when a court or regulator starts asking questions.

    This article summarizes a published professional-discipline order. It does not constitute legal advice.

    Sources

    • Law Society Tribunal order (July 16, 2026)
    • Tribunal case-document guidance
    • Clearon AI Courts and AI tracker
  • The EU AI Act’s Enforcement Phase Is Here. What Can Your Company Prove?

    The EU AI Act’s Enforcement Phase Is Here. What Can Your Company Prove?

    The EU AI Act's Enforcement Phase Is Here. What Can Your Company Prove?

    August 2, 2026, was not the day the entire EU AI Act suddenly switched on. It was the day regulators began enforcing the provisions already in application, while Article 50's transparency duties took effect.

    That distinction matters because many internal summaries still collapse the timeline into a single compliance date. The real question is narrower and more useful: can the company identify the systems it provides or uses in the EU, assign the correct legal role, map the applicable duty, and produce evidence that the control actually works?

    August 2 was an enforcement milestone, not a universal deadline

    Regulation (EU) 2026/1744 reset the timetable for major high-risk obligations, but it did not postpone Article 50. Nor did August 2 place every AI Act issue in the AI Office's hands. Enforcement remains divided, with national authorities handling much of the current supervision and the AI Office holding direct powers in narrower areas such as general-purpose AI models.

    The timeline is easier to manage when separated into the parts that are already active and the parts that are still ahead:

    • February 2, 2025: Article 4's AI-literacy duty took effect.
    • August 2, 2026: Article 50 transparency duties took effect, and authorities began enforcing rules already in application.
    • December 2, 2026: the limited transition ends for certain pre-August-2 systems subject to Article 50(2)'s marking and detection duty.
    • December 2, 2027: the main Annex III high-risk requirements move into application under the amended schedule.
    • August 2, 2028: high-risk requirements for AI embedded in regulated products move into application.

    A company that says only that "the AI Act applies from August 2" is missing the structure regulators will expect it to understand.

    The first regulator-facing question is evidence

    The practical challenge is no longer whether the legal team can summarize the timetable. It is whether the business can produce system-level evidence on demand.

    For each material system or model, a company should be able to identify:

    • the system or model;
    • the legal entity responsible;
    • the company's role as provider, deployer, importer, distributor, or more than one;
    • when the system or model was placed on the EU market or put into service;
    • which provisions are currently applicable; and
    • the factual basis for any exclusion, exception, or transition period.

    A spreadsheet that labels something "out of scope" without an explanation is not an evidence file. It is a conclusion.

    Article 50 controls have to work in the real workflow

    Article 50 reaches visible behavior and published outputs. Depending on the system and the party's role, it may require notice of AI interaction, machine-readable marking of certain generated or manipulated content, notice for emotion-recognition or biometric-categorization exposure, deepfake labels, and disclosure of certain AI-generated or manipulated public-interest text.

    The compliance question is not whether those requirements appear in a memo. It is whether they appear where users actually encounter the system and whether they survive the real publishing or product workflow.

    Teams should be able to show the notice, label, or marking method; the system version it covers; the test results; any technical limits; and the owner of exceptions or edge cases. For deepfakes and public-interest text, they should also be able to show whether the label survives publication and redistribution.

    Article 4 needs more than a generic training slide deck

    Article 4 is easy to reduce to annual training. Its amended text points to something more context-specific.

    A marketing team using generative AI for copy, a recruiting team using AI in hiring, and a trust-and-safety team reviewing user content do not present the same literacy needs or the same risk. A regulator may want to know who was covered, what guidance they received, when it was updated, and what changed after incidents or audits.

    That means AI literacy needs its own record, not just a reference in a general compliance presentation.

    Enforcement authority is divided, and the file should reflect that

    National market surveillance authorities are the main enforcers of Articles 4 and 50. The European Data Protection Supervisor enforces Article 50 for AI systems used by EU institutions, bodies, and agencies. The AI Office's Article 50 role is narrower, while its powers over general-purpose AI models are more direct.

    One generic "EU regulator" folder is likely to create confusion. The stronger approach is to identify the likely authority for each product, model, or deployment and index the evidence file accordingly.

    The practical file companies should have now

    The most useful near-term deliverable is a compact enforcement file for each material system or model. It should contain:

    • the system and role classification;
    • the applicable-duty and transition-date analysis;
    • the named business, legal, and technical owners;
    • the control description and implementation evidence;
    • testing results, known limitations, and approved exceptions;
    • AI-literacy records relevant to the system;
    • vendor documents and contract rights relevant to the duty; and
    • a retrieval index showing where the current records live.

    The goal is not to predict the first headline enforcement action. It is to answer a focused regulatory question without opening an internal investigation just to locate the facts.

    Bottom line

    August 2 did not activate the entire AI Act. It moved the rules already in force into a more concrete enforcement phase.

    Companies should separate active duties from delayed high-risk requirements, map the correct authority, and test whether their evidence can be retrieved at the level of a specific system, model, version, and workflow.

    The best measure of readiness is not whether the company has an AI Act slide deck. It is whether it can prove what control applied to a specific system and whether that control actually worked.

    Sources and Related Clearon Coverage

    This article summarizes the current EU AI Act enforcement timeline and related transparency duties. It does not provide legal advice.

  • An AI Tool Drafted the Job Ad. The Employer Still Owned the Legal Risk

    An AI Tool Drafted the Job Ad. The Employer Still Owned the Legal Risk

    An AI Tool Drafted the Job Ad. The Employer Still Owned the Legal Risk

    The Justice Department reached a settlement with Elegant Enterprise-Wide Solutions after the company posted job advertisements that restricted consideration to applicants with H-1B, OPT, or H-4 status. The advertisements were generated by an AI tool. DOJ’s position was unambiguous: responsibility for the content remained with the employer.

    The matter ended in a $9,460 civil penalty and three years of compliance obligations, including policy review, training for personnel involved in recruiting or approving job ads, and record preservation. It was not a court judgment, but the settlement reflects DOJ’s determination that using generative AI does not reduce an employer’s legal exposure.

    Drafting automation is still part of the hiring process

    Many organizations treat job-ad drafting as low-risk compared with screening or interviews. The Elegant settlement shows why that view is too comfortable. A job posting defines who is invited to apply. A restriction in the ad can exclude workers before any application is reviewed.

    Generative tools can introduce unlawful preferences in several ways: through the prompt, through inference from prior examples, or through vague instructions like “make this more targeted.” None of those paths changes who published the advertisement.

    Human review must be specific

    A policy requiring “human review” of AI-generated content is only effective if the reviewer knows what to look for. A useful review should test the posting against the actual legal or contractual basis for any restriction, check whether the language is broader than necessary, and compare the generated version against the approved template.

    Reviewers should also see what changed. If a system silently rewrites previously approved language, a final read can miss new limitations.

    Employers need provenance for job-ad text

    When a challenged advertisement appears, the company should be able to reconstruct how it was created. That record should include the original template, the prompt or inputs given to the AI, the generated draft, the approver, and the platforms and dates on which the ad appeared.

    Without that provenance, the company may know what was published but not why the language appeared or who could have caught it.

    The practical rule

    Automated drafting does not create automated immunity. If a company publishes a job advertisement, it should be ready to explain the source of any restriction, show who approved it, and demonstrate that its review process was designed to catch unlawful language.

    An AI tool can draft the text. The employer still owns the decision to use it.

  • Colorado Replaced Its Landmark AI Act. The New Law Is About Notice, Explanations, and Human Review

    Colorado Replaced Its Landmark AI Act. The New Law Is About Notice, Explanations, and Human Review

    Colorado did more than amend its first AI law. It replaced the law's operating model.

    The 2024 statute was built around high-risk AI systems, algorithmic-discrimination duties, risk-management programs, impact assessments, and a reasonable-care standard. Senate Bill 26-189 repealed and reenacted that framework in May 2026.

    The replacement law uses a different center of gravity. It regulates automated decision-making technology that materially influences consequential decisions. Its main requirements concern notices, technical documentation, explanations after adverse outcomes, correction of inaccurate personal data, and meaningful human review.

    The new law takes effect January 1, 2027. It is narrower in some important ways, but it is not light-touch. Companies still need to know which systems are covered, who is acting as developer or deployer, what role the technology played in a decision, and whether a human reviewer can reconsider the result in a meaningful way.

    The Short Answer

    • Colorado replaced the original "high-risk AI system" framework with a law covering automated decision-making technology, or ADMT, that materially influences consequential decisions.
    • The replacement removes the original law's broad duty-of-care, risk-management, impact-assessment, and algorithmic-discrimination structure.
    • Developers must provide deployers with technical documentation, known limitations, appropriate-use instructions, and human-review guidance.
    • Deployers must give notice at the point of interaction and explain the role of covered ADMT after an adverse outcome.
    • Consumers may request correction of inaccurate personal data and meaningful human review and reconsideration.
    • The Colorado Attorney General has exclusive enforcement authority under the Colorado Consumer Protection Act. The law creates no new private right of action.

    From "High-Risk AI" to Covered ADMT

    The change in terminology is substantive.

    SB 26-189 defines ADMT as technology that processes personal data and uses computation to generate output used to make, guide, or assist a decision about an individual. The output can include a prediction, recommendation, classification, ranking, score, or other information.

    The law applies when ADMT is used to "materially influence" a consequential decision. Covered domains include:

    • education;
    • employment and compensation;
    • housing;
    • financial and lending services;
    • insurance;
    • health-care services; and
    • essential government services and public benefits.

    That framing puts the decision process ahead of the product label. A tool does not become covered simply because a vendor calls it artificial intelligence. A company also cannot assume a system falls outside the law because it uses an older statistical method or carries no AI branding. The relevant questions are whether the technology processes personal data, produces computational output, and materially influences a covered decision.

    The statute excludes several categories of tools, including specified cybersecurity and fraud-prevention technologies, basic spreadsheets that require human analysis, and tools that merely communicate, organize, or summarize information for later human review. Those exclusions make the boundary around "materially influence" especially important. A system that only organizes information may be outside the definition. A system that ranks candidates or recommends a denial may be doing much more.

    What Colorado Removed

    The 2024 law asked developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. It offered a rebuttable presumption of reasonable care for companies that followed a detailed compliance structure.

    For deployers, that structure included a risk-management policy, impact assessments, annual reviews, public disclosures about high-risk systems, and reporting certain algorithmic-discrimination risks to the Attorney General.

    SB 26-189 does not carry that architecture forward.

    The replacement law removes the general reasonable-care duty tied to algorithmic discrimination. It also removes the statutory risk-management-program and impact-assessment requirements that made the original Colorado law resemble an enterprise AI governance regime.

    That is a major narrowing. It matters for both compliance costs and the pending constitutional dispute over the earlier framework.

    It does not mean discrimination risk disappeared. Existing civil-rights and antidiscrimination laws still apply. SB 26-189 also addresses how fault may be allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law. What changed is the AI statute's own regulatory mechanism.

    What Developers Must Provide

    Starting January 1, 2027, a developer of covered ADMT must provide deployers with technical documentation. The documentation must address subjects that a deployer needs in order to use the system appropriately, including:

    • intended uses;
    • categories of training data;
    • known limitations;
    • instructions for appropriate use; and
    • instructions for human review.

    Developers must also notify deployers of material updates or modifications.

    This creates a practical supply-chain obligation. A deployer cannot provide a useful explanation or conduct a meaningful review if the developer supplies only a marketing deck and a generic assurance that the model is compliant.

    Contracts should identify who will provide the required documentation, how updates will be communicated, and what information the deployer will receive about limitations and review. Procurement teams should also check whether the vendor's documentation is specific enough to support a real decision workflow.

    Both developers and deployers must retain records needed to show compliance for at least three years.

    What Deployers Must Tell People

    The replacement law places much of the consumer-facing work on deployers.

    A deployer must provide clear and conspicuous notice at the point where a consumer interacts with covered ADMT. If the ADMT materially influences a consequential decision that produces an adverse outcome, the deployer must provide a plain-language description within 30 days.

    That description must explain the consequential decision and the role the covered ADMT played. The law also requires a process through which the consumer can request more information and exercise the rights provided by the statute.

    This is not satisfied by a general privacy notice that says the company "may use automated tools." The required explanation is tied to an actual adverse decision and the technology's role in it.

    Companies will need to preserve enough decision-level information to answer questions such as:

    • Which model or system version was used?
    • What data about the individual entered the process?
    • What output did the system produce?
    • Who received that output?
    • How did the output affect the final decision?
    • Could a human decision-maker depart from it?

    Without those records, a 30-day explanation requirement can turn into an expensive reconstruction exercise.

    Correction Rights and Meaningful Human Review

    Consumers affected by an adverse outcome may request access to personal data and correction of factually incorrect or materially inaccurate personal data used in the decision. They may also request meaningful human review and reconsideration.

    The word "meaningful" should do real work.

    Review cannot amount to routing the same data through the same system and returning the same answer. A reviewer should have enough authority, information, and time to evaluate the decision. The process should show what the reviewer considered and whether the reviewer could change the result.

    For employers, lenders, insurers, health-care organizations, and government programs, this raises an operational question that should be answered before launch: who can actually reconsider an adverse outcome?

    A policy that promises human review without assigning a qualified reviewer or giving that person authority to act will be hard to defend.

    Enforcement and the Cure Period

    The Colorado Attorney General enforces SB 26-189 through the Colorado Consumer Protection Act. A violation is treated as a deceptive trade practice.

    The statute does not create a new private right of action. Before bringing an enforcement action prior to January 1, 2030, the Attorney General must provide 60 days' notice and an opportunity to cure when a cure is possible.

    The cure period reduces immediate enforcement pressure, but it is not a substitute for implementation. Some failures can be fixed prospectively. Missing decision records, inadequate notices, or a review process that never existed may be much harder to repair after an adverse outcome.

    What the Replacement Means for the xAI Case

    xAI filed its federal lawsuit against the original Colorado law in April 2026. The United States later intervened. Their constitutional claims targeted the earlier statute's algorithmic-discrimination and risk-governance structure.

    SB 26-189 changes the object of that fight.

    The federal court's April 27 order anticipated that possibility. It covers SB 24-205 and legislation enacted during the 2026 session that replaces or amends it. The order also allows xAI to amend its complaint, if necessary, after Colorado adopts final implementing rules. The Attorney General agreed not to enforce covered violations occurring on or before 14 days after the court rules on the forthcoming preliminary-injunction motion.

    There is no final merits ruling. It is also too early to say which constitutional claims will remain live against the replacement law. Removing the earlier algorithmic-discrimination duty may narrow some arguments, while notice, documentation, and decision-review requirements could generate different ones.

    For now, the litigation affects timing and uncertainty. It does not erase the January 1, 2027 statutory effective date or the need to prepare for the final rules.

    What Companies Should Do Before 2027

    Companies can start with the decision process rather than attempting a company-wide inventory of anything labeled AI.

    First, identify systems that use personal data to rank, score, recommend, classify, or otherwise influence decisions in the covered domains.

    Second, document why each system does or does not materially influence the decision. That boundary judgment may become important later.

    Third, map developer and deployer roles. The same company may be a deployer for purchased software and a developer for internally built or substantially modified tools.

    Fourth, test whether vendor documentation covers intended uses, training-data categories, limitations, updates, and human review. Add contract terms where the documentation or update process is weak.

    Fifth, build the adverse-outcome workflow. Decide who sends the explanation, where the decision record lives, how correction requests are handled, and who performs reconsideration.

    Finally, test the human-review process with a real example. A written promise of review is not enough if the reviewer cannot understand the system's contribution or change the outcome.

    Bottom Line

    Colorado's replacement law is less focused on enterprise-wide AI governance and more focused on what happens around an individual decision.

    The central compliance questions are concrete. Was the technology covered? Did it materially influence the outcome? Was the person notified? Can the company explain what happened? Can inaccurate data be corrected? Can a human reviewer reconsider the decision?

    SB 26-189 removed some of the most demanding parts of Colorado's original AI Act. It replaced them with obligations that depend on reliable decision records and working review procedures.

    Companies have until January 1, 2027 to build those procedures. The systems, contracts, and records needed to make them work should be addressed well before then.

    Sources and Related Clearon Coverage

  • If AI Helps Build the Layoff List, Employers Need an Audit Trail

    If AI Helps Build the Layoff List, Employers Need an Audit Trail

    A new lawsuit against Meta asks a question many employers have managed to postpone: what happens when employees say AI helped decide who lost a job, while the employer says humans made the decisions without AI scoring or ranking?

    Twenty-six current and former Meta employees allege that the company used internal AI systems, activity-monitoring data, productivity measures, AI-token consumption, and algorithmically assisted rankings to select workers for a May 2026 reduction in force. The plaintiffs say the process penalized employees who had taken protected medical, parental, pregnancy-related, caregiver, or family leave.

    Meta denies using AI to make the selections. In a declaration filed with the court, a Meta human-resources director said human business leaders made the decisions using documented criteria and that there was no AI-assisted scoring or ranking related to employee performance.

    The case is Does 1 Through 26 v. Meta Platforms, Inc., No. 3:26-cv-07122-WHO, filed July 13 in the Northern District of California. The court has denied the employees' request for a temporary restraining order, but it did not resolve the underlying claims. U.S. District Judge William Orrick found "serious questions going to the merits" and said discovery in arbitration would be needed to test Meta's account.

    That dispute is what makes the case useful. It shows the evidentiary problem employers will increasingly face when workforce decisions sit near performance systems, activity data, AI tools, dashboards, and human approvals. The central issue may be less about one identifiable algorithm than whether the employer can prove what did and did not affect the result.

    What The Employees Allege

    The complaint says Meta began notifying about ten percent of its workforce on May 20 that they had been selected for termination.

    According to the plaintiffs, managers who knew the employees' work did not assemble the termination list through individualized judgment. They allege that Meta used a group of internal tools and data sources that included:

    • "Metamate," described as an internal large-language-model assistant;
    • employee-trained "second brain" agents that ingested communications and work documents;
    • keystroke, screen-content, mouse, browser-history, and other activity data;
    • dashboards showing employee-level AI-token consumption;
    • productivity, output, performance, and calibration measures; and
    • algorithmically assisted rankings, including what the complaint calls an "AI-native" rating.

    Those details are allegations, not established findings. They still illustrate why a modern workforce case may be hard to explain through a conventional account of one supervisor making one decision.

    The plaintiffs' central theory is that the system rewarded signals employees could accumulate only while actively working. Someone on protected leave could not generate code commits, output volume, AI-tool usage, roadmap ownership, or similar measures at the same rate as an employee who was present throughout the measurement period.

    The complaint alleges that Meta failed to neutralize protected-leave periods, remove affected employees from the comparison group, or require an individualized review that accounted for leave and accommodations. The employees claim those omissions turned apparently neutral productivity signals into negative factors tied to protected activity or disability.

    The complaint brings claims under federal and state employment laws, including the Family and Medical Leave Act, the Americans with Disabilities Act, the Pregnancy Discrimination Act, and the Pregnant Workers Fairness Act. It also invokes laws in several states and the District of Columbia.

    What The Court Has Said So Far

    The July 17 temporary-restraining-order decision gives both sides something to point to.

    Meta submitted a declaration stating that human business leaders made the selections using criteria such as job profile, level, historical and recent performance ratings, tenure, location, job function, specialized skills, and organizational structure. The declaration said no plaintiff was selected because of leave, disability, or another protected characteristic and that AI made no selection decision.

    The employees submitted declarations describing their understanding of Meta's growing use of AI in performance reviews and internal employee classifications. But the judge noted that they were not present when the reduction-in-force decisions were made and did not yet have evidence rebutting Meta's direct account.

    Judge Orrick found that the employees had raised serious questions but had not shown a likelihood of success on the existing record. He denied emergency relief largely because most claimed harms, including lost employment, benefits, leave, and equity, could be addressed through damages or relief in arbitration.

    The order did identify a narrower concern. Four plaintiffs held Meta-sponsored employment visas, and the judge said the potential loss of immigration status likely could constitute irreparable harm. He directed Meta to submit declarations explaining how and why those four employees were selected. The preliminary-injunction hearing is scheduled for August 24.

    The order did not decide whether Meta used AI improperly or violated employment law. It framed the proof question: the employees suspect that AI-related systems affected the result; Meta says they did not; and the relevant records are largely controlled by Meta.

    The Hard Question Is How The Decision Was Made

    Companies often describe AI as advisory. A manager still approves the result, so the company may believe that a human remains responsible for the decision.

    That description does not resolve the legal or factual problem.

    If an algorithm determines which employees receive scrutiny, converts workplace activity into a score, sets a comparative ranking, or supplies the recommended list, the later human approval may carry less weight than the company assumes. The quality of the human review matters more than the existence of a final click.

    An employer defending this kind of case may need to show:

    • what systems and data affected the decision;
    • which metrics were calculated and over what period;
    • how leave, disability accommodations, and missing data were treated;
    • whether managers could change a recommendation;
    • what information managers saw before approving it;
    • how often managers overrode the system; and
    • whether anyone tested the process for distorted or discriminatory results.

    A human signature at the end of the process does not answer those questions.

    Measurement Windows Can Become Legal Risk

    The complaint focuses attention on a basic design choice: the measurement window.

    A productivity system can appear neutral while treating absence as poor performance. That risk grows when the system relies on volume measures such as messages sent, code committed, documents produced, hours active, or AI tokens consumed.

    The problem is not limited to formal leave. Disability accommodations may change how or when an employee works. Pregnancy-related restrictions may reduce certain kinds of activity. Caregiving leave can create gaps that a ranking system reads as lower output. A system trained on uninterrupted work histories may treat legally protected circumstances as performance signals unless the employer deliberately changes the design.

    Governance teams should therefore ask a more precise question than whether a model uses protected characteristics. They should ask whether the system uses proxies or measurement rules that systematically encode the effects of protected leave, disability, pregnancy, or accommodation.

    Employers Need A Decision Record, Not Just An AI Policy

    Most AI policies say that people must remain involved in consequential decisions. That is a useful principle, but it is not a litigation record.

    For workforce decisions, employers need documentation tied to the actual event. A defensible record should identify the system version, input fields, relevant dates, scoring logic, exclusions, adjustments, reviewers, overrides, and final reasons for each decision.

    That record should also explain how the employer handled protected leave and accommodations. If a measurement period overlapped with leave, the company should be able to show whether it adjusted the denominator, removed the affected period, used a different comparison, or excluded the metric.

    The same principle applies to vendors. A company may use a third-party model, but the employment decision remains the company's. Contract language should provide access to the documentation, testing information, logs, and technical support needed to investigate a challenged result.

    Discovery Will Reach Beyond The Final Layoff Spreadsheet

    The complaint also shows how quickly an employment dispute can become an AI-governance and data-preservation matter.

    Relevant evidence may include:

    • prompts and outputs from internal assistants;
    • model and scoring documentation;
    • employee-level dashboards;
    • activity-monitoring records;
    • calibration materials;
    • communications about metric selection;
    • bias, validation, and impact testing;
    • manager instructions and override records; and
    • records showing when employees requested leave or accommodations.

    Legal holds written for ordinary personnel files may miss much of that material. Some records may sit in analytics platforms, model logs, collaboration systems, or vendor environments with short retention periods.

    Employment counsel, privacy teams, and technical owners should decide in advance who can preserve those records and how quickly preservation can begin.

    What Companies Should Review Now

    Employers do not need to wait for a ruling in the Meta case to examine their own processes.

    Start with an inventory of every system that can affect selection for promotion, discipline, performance management, restructuring, or termination. Include systems described internally as analytics, productivity, workflow, or decision support. Labels do not determine whether a tool influences an employment decision.

    Then map the inputs. Look specifically for measures that fall when an employee is absent or working under an accommodation. Test whether protected leave changes an employee's score, rank, comparison group, or likelihood of additional review.

    Finally, inspect the human-review step. Reviewers need enough information and authority to identify a distorted recommendation. A process that asks a manager to approve hundreds of names without explaining the underlying data is not meaningful review.

    The Larger Lesson

    The Meta lawsuit may succeed, fail, or narrow as the employees pursue their claims in arbitration. Their allegations have not been proven, and Meta has submitted a direct factual denial.

    The governance problem exists either way. Employers are combining workplace monitoring, productivity analytics, internal AI assistants, performance ratings, and ranking systems. When those systems affect a termination decision, the company needs to reconstruct the path from raw data to final outcome.

    If AI helps build the layoff list, an employer should be ready to show what the system measured, what it ignored, who reviewed the result, and how legally protected circumstances were kept from becoming negative signals.

    Without that record, "a human made the final decision" may be a conclusion the evidence cannot support.

    Sources and Related Clearon Coverage

  • The EU’s Final Article 50 Guidance Is Here. The Omnibus Did Not Delay Transparency Duties.

    The EU’s Final Article 50 Guidance Is Here. The Omnibus Did Not Delay Transparency Duties.

    The last major excuse for waiting is gone.

    The European Commission has now adopted final Article 50 transparency guidelines. At nearly the same time, the EU's Digital Omnibus was published in the Official Journal and made parts of the AI Act's high-risk timetable final law.

    Those two developments belong in the same article because plenty of teams are going to misread them together.

    The easiest mistake now is to assume the Omnibus delayed the whole AI Act rollout. It did not. The amended high-risk dates are now final law, but the Article 50 transparency duties still apply on August 2, 2026.

    That means companies no longer need to guess whether practical Commission guidance will arrive before the deadline. It arrived. They also should stop telling themselves that the new Omnibus timing buys them more time on transparency. It does not.

    For broader tracking context, see Clearon's Laws, Bills & Regulations page.

    What Changed This Week

    Three separate EU developments now need to be read together.

    First, the Commission adopted final practical guidelines on Article 50 transparency obligations for providers and deployers of AI systems. The guidance covers direct AI interactions, machine-readable marking of AI-generated or AI-manipulated content, deepfake labelling, certain public-interest text disclosures, and notice duties for emotion-recognition and biometric-categorisation systems.

    Second, the Digital Omnibus was officially published as Regulation (EU) 2026/1744. That matters because it turns the revised high-risk timetable into final law instead of a politically agreed future change.

    Third, the EU also published Commission Implementing Regulation (EU) 2026/1755 on procedural arrangements for Commission evaluations of general-purpose AI models. That is not an Article 50 rule, but it shows the wider AI Act implementation machinery is moving from policy talk into formal instruments.

    The practical result is simple. The EU implementation picture is now clearer, not blurrier.

    What The Omnibus Actually Changed

    The Omnibus matters. It just does not matter in the way some summaries will imply.

    The new regulation changes parts of the AI Act's high-risk timetable. According to the official publication, the relevant Annex III high-risk regime now moves to December 2, 2027, and product-embedded high-risk systems move to August 2, 2028.

    That is real law now.

    But the Omnibus did not postpone Article 50. The transparency obligations still apply from August 2, 2026. If a company walks away from this week thinking "the EU delayed AI Act deadlines," that company may be calm about exactly the wrong deadline.

    This distinction matters because Article 50 sits in a very different lane from the high-risk regime. The high-risk rules are about system categories, lifecycle controls, and sector-specific obligations. Article 50 is about transparency in actual outputs and interactions. For many companies, Article 50 hits public-facing content and product workflows much sooner than the heavier high-risk framework ever will.

    Why The Final Guidelines Matter

    Until now, some teams could say they understood the direction of travel but were still waiting for final Commission guidance on scope and implementation.

    That position is much harder to defend now.

    The Commission has moved Article 50 guidance from pending to final. The guidance is still nonbinding. Article 50 itself remains the binding law. But final Commission guidance changes the planning posture in at least three ways.

    First, it narrows the room for pretending that core implementation questions are still too unsettled to begin workflow changes.

    Second, it gives legal and compliance teams a better basis for making near-term judgments about which products, interfaces, and publishing flows are in scope.

    Third, it raises the standard for companies that want to reject the Commission-backed path and rely on a custom approach instead. That choice is still available. It is just easier to scrutinize now.

    The earlier milestones already pointed in this direction. The Commission had published the transparency Code of Practice, said it adequately covers Articles 50(2), (4), and (5), and publicly identified signatories to the broader GPAI Code structure. The final guidelines now add the missing implementation layer many organizations said they were waiting for.

    The Rule Is Binding. The Guidance Is Not. That Distinction Still Matters.

    This is where companies can still trip over their own summaries.

    The legal obligation comes from Article 50. The final guidelines do not replace the statute and do not create a new binding act. They are implementation guidance.

    The Code of Practice is different again. It remains voluntary even after the Commission's adequacy assessment and public signatory list.

    So there are three separate layers:

    • Article 50 is binding law.
    • The final guidelines are nonbinding Commission guidance.
    • The transparency Code is a voluntary compliance path.

    That separation matters because teams need to know what they must do, what the Commission recommends, and what route they may choose to use as evidence of compliance.

    It also matters for anyone writing internal updates. If a business memo says "the Commission finalized Article 50 rules," it risks flattening together the law, the guidance, and the Code in a way that creates confusion later.

    What Companies Should Be Doing Right Now

    The final guidelines do not eliminate every edge case. They do make it harder to justify delay in the parts of the work that were always operational.

    That work starts with inventory.

    Companies should identify which products and workflows may trigger Article 50 analysis. That includes customer-facing AI systems, media-generation tools, marketing and communications pipelines, newsroom or publishing processes, synthetic audio and video workflows, public-facing text generation, and interfaces where a user may need to be told they are interacting with AI.

    Then comes role mapping.

    Many organizations will be both providers and deployers depending on the product or workflow. That cannot be solved once at the company level and forgotten. It has to be mapped feature by feature and channel by channel.

    Then comes scope mapping.

    Teams need working rules for when content qualifies as AI-generated or AI-manipulated, when it becomes a deepfake, when text is published to inform the public on a matter of public interest, and when direct AI interaction notices are required.

    Then comes control testing.

    The key question is not whether a label can be drafted. It is whether the notice, marker, metadata, or disclosure actually survives the channels where people encounter the content. Web pages, mobile surfaces, PDFs, screenshots, syndicated content, reposted clips, social snippets, image exports, and partner distribution all deserve testing.

    Then comes evidence.

    If a company is ever asked what it did before August 2, it should be able to show role assignments, workflow decisions, scope calls, implementation dates, exception handling, and testing results. A last-minute label pasted onto content with no decision trail behind it is weak compliance hygiene.

    Where The Hard Questions Still Sit

    The public conversation around Article 50 still overfocuses on labels.

    The harder questions are mostly underneath the label:

    • Who decides when a piece of content is in scope?
    • Who owns the distinction between provider and deployer in mixed workflows?
    • How will machine-readable marking behave when content is clipped, embedded, reformatted, or redistributed?
    • What counts as enough disclosure when AI-generated text is part of a broader edited publication?
    • How will product, legal, trust and safety, editorial, and communications teams avoid giving different answers to the same question?

    The final guidelines help. They do not remove the need for judgment.

    That is why the next two weeks matter more than the next abstract policy debate. Most organizations do not need another conceptual conversation about transparency. They need ownership, workflow decisions, and testing.

    Why The New GPAI Evaluation Rule Still Belongs In The Background

    The new implementing regulation on evaluations of general-purpose AI models is not the headline for most readers of this article.

    It still matters.

    It shows that the EU is not only publishing speeches, FAQs, and voluntary frameworks. It is also putting binding procedural instruments in place for the Commission's evaluation and enforcement architecture.

    That broader context should affect how companies read Article 50. Even though Article 50 is about transparency rather than GPAI model evaluations, both developments point the same way: the implementation phase is now real enough to change legal and product behavior, not just policy slide decks.

    A Better Internal Message Than “The EU Delayed Things”

    If you need a one-line summary for management, this is the better one:

    The EU clarified and formalized more of the AI Act this week, but it did not delay the Article 50 transparency duties that matter on August 2.

    That framing is closer to the truth than the broader and sloppier claim that the EU "pushed back AI Act deadlines."

    Some deadlines did move. This one did not.

    That matters because Article 50 is likely to hit public-facing workflows sooner than many teams expect. It is not mainly a frontier-model issue. It is a publishing, product, disclosure, and recordkeeping issue.

    Bottom Line

    The final Article 50 guidance is here.

    The Omnibus is now final law.

    Neither development gives companies a reason to delay transparency work.

    The opposite is true. The Commission has made the implementation picture clearer, and the new Omnibus publication removes one source of confusion while creating another for anyone who reads it carelessly. The high-risk timetable changed. The Article 50 date did not.

    If teams are still waiting for the right moment to move Article 50 from policy discussion into operational compliance, this was that moment.

    Sources

    Sources and Related Clearon Coverage

  • Why I Built a State AI Companion Chatbot Law Guide

    Why I Built a State AI Companion Chatbot Law Guide

    I started looking more closely at Hawaii’s new conversational-AI law because it seemed familiar.

    Act 248 requires AI disclosures, suicide and self-harm protocols, protections for minor account holders, and annual reports to the state Behavioral Health Administration. Violations can be treated as unfair or deceptive practices.

    California, New York, Oregon, Washington, Connecticut, Colorado, Idaho, Iowa, Nebraska, Georgia, and Rhode Island have enacted laws that reach parts of the same product category. Once those statutes are placed next to one another, the overlap is obvious. So are the differences.

    I could not find a useful way to explain that in a short state update. So I built a State AI Companion and Conversational Chatbot Law Guide for Clearon.

    A State Count Does Not Tell You What To Build

    “Similar laws” is a fair description. Product and legal teams still need the differences before they can decide what to build.

    One state may require recurring disclosures. Another may focus on the start of the interaction. Some regulate crisis referrals for every user. Others add detailed restrictions for minors involving sexual content, emotional dependence, reward systems, secrecy, isolation, or spending pressure.

    The reports go to different places. Hawaii uses its Behavioral Health Administration. California uses its Office of Suicide Prevention. Rhode Island requires reports to the Attorney General. Oregon has a separate reporting structure.

    The remedies differ too. Some statutes rely on state consumer-protection enforcement. Oregon provides a private action for ascertainable harm. California includes a separate limited civil remedy. Idaho and Nebraska say their laws do not create a private right of action.

    Those choices affect product design, recordkeeping, contracts, and litigation risk.

    What The Guide Covers

    The guide compares enacted laws in twelve jurisdictions that directly regulate companion or conversational AI:

    • California
    • Colorado
    • Connecticut
    • Georgia
    • Hawaii
    • Idaho
    • Iowa
    • Nebraska
    • New York
    • Oregon
    • Rhode Island
    • Washington

    For each jurisdiction, the guide identifies the law and operative date, then compares disclosure, crisis response, protections for minors, reporting, and enforcement.

    The guide keeps related laws in a separate section. Broader children’s online-safety statutes, therapy-bot restrictions, and narrowly targeted criminal provisions may belong in the same risk review, but they do not regulate the same products in the same way.

    Pending bills stay in a separate section. Legislative passage is not enactment, and a proposal does not create a current compliance duty.

    The Repeated Requirements

    The statutes keep returning to four practical questions.

    Does the user know this is AI? A notice may be required at the start of an interaction, during a long session, or more often when a minor is involved.

    What happens when a user expresses suicidal thoughts or an intent to self-harm? The answer has to work inside the product. It also has to be tested and documented.

    What changes for minors? The newer laws reach the conversation and the engagement design. They address sexual content, simulated dependence, isolation from trusted adults, rewards, and emotional pressure to keep using the product.

    Can the company prove what happened? Annual reports, Attorney General inquiries, and private claims all depend on records. A company may need to show which notice appeared, how the system handled a crisis signal, and which safeguards were active for a minor account.

    Hawaii Shows Why A Multistate Map Is Necessary

    Act 248 sits near the center of this group. It combines disclosure, crisis protocols, minor protections, reporting, and consumer-protection enforcement. It still falls short as a national template.

    A company could satisfy Hawaii’s reporting route and miss California’s reporting details. It could comply with one state’s disclosure language and miss another state’s frequency requirement. It could maintain a general minor-safety policy without addressing Washington’s or Idaho’s more specific engagement restrictions.

    I think a control matrix is more useful than twelve isolated memos. Each duty can be assigned to a product owner and matched with an effective date, a technical or operational control, and evidence that the control works.

    This Will Need Maintenance

    The guide is dated and was last reviewed July 29, 2026.

    Several laws have 2027 operative dates. Colorado rulemaking is still developing. New York has a separate minor-safety bill that passed both chambers but had not been confirmed as enacted when the guide was prepared. Other states are considering their own measures.

    I drew a firm line between enacted duties and pending proposals. A state will move into the main table only after enactment can be confirmed through an official source.

    Blending bills, signed laws, effective requirements, investigations, and enforcement findings produces a misleading picture of what companies must do now.

    Companion chatbot regulation has become a multistate compliance issue.

    The statutes share a basic structure: nonhuman notice, crisis response, protections for minors, reporting, and enforcement. The legal work is in the differences.

    Read the new State AI Companion and Conversational Chatbot Law Guide for the comparison table, source links, and practical review questions.

    Sources