Category: Litigation & Enforcement

Court orders, litigation developments, copyright disputes, privilege decisions, enforcement, and sanctions involving AI.

  • Anthropic Wins A Permanent Injunction On The 3252 Track, But The FASCSA Fight Is Still Live

    Anthropic Wins A Permanent Injunction On The 3252 Track, But The FASCSA Fight Is Still Live

    Anthropic just turned its March preliminary-injunction win into a full merits victory in the Northern District of California.

    Judge Rita Lin permanently enjoined the participating government defendants from enforcing the challenged measures in Anthropic's Northern District of California case and vacated the specific designation and directive actions identified in the order. But the ruling resolves the 10 U.S.C. Section 3252 track, not the separate FASCSA track.

    Commentary often treats the Anthropic supply-chain-risk dispute as a single case. It is not. Anthropic has been fighting two different supply-chain-risk designations under two different statutes in two different courts. This ruling is a sweeping loss for the government on the California path. It is not, by itself, the end of the Washington path.

    What Judge Lin Just Did

    Judge Lin's August 27 opinion and final-relief order turn the preliminary-injunction win into a merits victory for Anthropic.

    First, the court held that the government's actions amounted to unlawful retaliation against Anthropic for protected speech. The final-relief order expressly declares that the challenged actions violate the First Amendment because they are "unlawful retaliation against Anthropic for constitutionally protected expressive activities." The opinion adds the broader warning: "The empty invocation of national security is not a blank check to punish and retaliate against government critics."

    Second, the court held that Anthropic was denied the process the Constitution required before being publicly branded and cut off in this way. That due-process theme had already appeared in the March preliminary-injunction ruling, and the final-relief order now carries it through expressly.

    Third, and most important for procurement lawyers, Judge Lin concluded that Anthropic does not meet the statutory definition of a supply chain risk on the record before the court. The opinion says that "[a]n IT vendor does not become a potential adversary of the United States whenever it asks probing questions or stubbornly insists on particular contracting terms, even if doing so causes DoW to doubt its trustworthiness." That is not just a procedural criticism. It goes to the substance of the government's theory under Section 3252.

    The government's position was never simply that it did not want to buy Claude. It was free to stop buying Claude. The much more aggressive move was using national-security-flavored supply-chain machinery to treat Anthropic as if it were the kind of sabotage or subversion threat the statute was built to address. Judge Lin rejected that move in direct terms.

    Why The 3252 Point Matters

    Section 3252 is not a generic "we do not trust this vendor" statute.

    Clearon's earlier Anthropic article walked through the preliminary-injunction ruling, where Judge Lin had already signaled deep skepticism that Anthropic's insistence on two usage red lines could turn it into a statutory supply-chain threat. The merits ruling confirms that conclusion. The opinion explains that Section 3252 was built to address "sabotage or subversion" by "foreign intelligence, terrorists, or other hostile elements," not a domestic vendor's public disagreement with the government's preferred AI-use terms.

    If a frontier-model vendor can be labeled a supply-chain risk whenever it publicly criticizes the government's preferred uses or refuses one set of contract terms, then "supply chain risk" stops meaning sabotage or subversion and starts meaning policy defiance. Judge Lin rejected that stretch directly.

    For AI companies, that is a meaningful line. It suggests that refusing to permit certain uses, even in a sensitive government setting, does not by itself permit the government to move from ordinary procurement discretion to a reputationally destructive national-security designation.

    This Does Not Resolve The FASCSA Case

    That does not mean Anthropic is fully out of danger.

    The California ruling concerns the Section 3252 path and the related Presidential and Hegseth directives challenged in the Northern District of California. The separate D.C. Circuit case concerns a different designation under 41 U.S.C. Section 4713, part of the Federal Acquisition Supply Chain Security Act, or FASCSA.

    Those two tracks overlap in business effect, but they are not interchangeable as law.

    Judge Lin's ruling does not automatically erase the FASCSA designation. The D.C. Circuit case is still pending. CourtListener's D.C. Circuit materials show that the court denied Anthropic's emergency stay request in April, heard oral argument on May 19, 2026, later consolidated No. 26-1162 with No. 26-1049 after Anthropic filed a protective petition following the Secretary's June 3 reaffirmation, and then received Anthropic's August 28 Rule 28(j) letter invoking Judge Lin's ruling along with the government's September 3 response. As of this check, there is still no merits disposition reflected in the materials I could verify during this run.

    The Ninth Circuit posture matters too. Judge Lin's opinion notes that the government's appeal from the March preliminary injunction was filed in the Ninth Circuit but then stayed at the parties' mutual request pending a ruling from the D.C. Circuit in the related case. So the California and Washington tracks are now intertwined not just strategically, but procedurally.

    If you are advising a company that sells into or around the defense market, the takeaway is not "Anthropic won everywhere." It is "Anthropic won decisively on one statutory path, while the other path remains live."

    Why The Two Cases Still Matter Together

    Even though the statutes differ, the proceedings remain connected in practice.

    The operational question is broader than either caption: how much freedom does the government have to punish or isolate an AI vendor that refuses certain military or surveillance uses?

    The California decision pushes hard in one direction. It says the government cannot take a contract dispute, wrap it in national-security rhetoric, and convert it into retaliation for protected speech under a statute that does not fit the facts.

    The D.C. Circuit case leaves more uncertainty in place. The stay denial did not resolve the merits, but it did allow the FASCSA designation to remain operative while the petition proceeds. Judge Lin's ruling may still matter there as persuasive authority, and Anthropic is already pressing it that way, but the government is disputing any claim that the California decision automatically carries issue-preclusive force into the Section 4713 proceeding because the statutes, actions, and processes differ. That means the practical consequences inside the defense ecosystem do not disappear just because California ruled for Anthropic.

    That split matters for AI vendors that want defense business without giving the government unlimited control over product use. They now have better authority against an overbroad Section 3252 theory, but they still do not have a final appellate answer on the FASCSA route.

    It also matters for government contractors, integrators, investors, and boards. They still need to ask which statute is doing the work, which forum controls, and what the live restrictions actually reach. Sloppy summaries could cause companies either to overcomply or to assume a designation vanished when it did not.

    What Happens Next For The Government

    The most obvious next step is to seek Ninth Circuit review of Judge Lin's merits ruling, along with a request for a stay pending appeal. Judge Lin already denied the government's request for a seven-day administrative stay, so any broader effort to narrow or pause the California relief now has to proceed through the ordinary appellate-stay path.

    It may also try to argue for a more limited reading of the injunction or for partial relief tied to specific agencies or directives. The final-relief order leaves room for lawful procurement choices: it says the order does not require DoW to use Anthropic and does not prevent the government from transitioning to other AI providers so long as those actions comply with applicable statutes, regulations, and constitutional limits. But the ruling still amounts to a broad rejection of the theory that national security language can substitute for statutory fit and constitutional limits.

    Meanwhile, the government can continue litigating the D.C. Circuit case. In business terms, that may now be the more important active front, because it preserves the possibility that one supply-chain-risk designation could survive even after the California path failed.

    That does not mean the D.C. Circuit must come out differently on the merits. It only means the government still has a live forum in which to defend the FASCSA designation under a different statute, a different review path, and a different procedural posture.

    What Companies Should Watch Now

    Three follow-up questions matter most:

    1. Does the government seek an immediate stay pending appeal in the Ninth Circuit, and if so, does it get one?
    2. Does the government continue to lean on the D.C. Circuit case as its remaining live path for keeping pressure on Anthropic?
    3. How do agencies and contractors interpret the gap between the two rulings in day-to-day procurement decisions while the D.C. case remains unresolved?

    Bottom Line

    Anthropic just won a major merits ruling, and the easiest thing to blur is also the most important: this is the Section 3252 decision, not the FASCSA decision.

    Judge Lin held that Anthropic does not meet the statutory definition of a supply chain risk, that the government's actions retaliated against protected speech, and that the company was denied due process. That is a serious defeat for the government's California strategy and an important signal to other AI vendors that procurement pressure does not automatically become lawful once officials invoke national security.

    One more precision point matters. Anthropic did not win literally everything. Judge Lin rejected Anthropic's ultra vires claim, and the final-relief order also gives the government judgment as to certain non-participating defendants and certain Section 558 claims against specific agencies. But those partial defense wins do not alter the ruling's principal effect.

    The business story is still larger than one courtroom. The D.C. Circuit case remains live, the FASCSA designation still matters, and any serious assessment of Anthropic's position with government customers has to keep both tracks in view at the same time.

    Sources and Related Clearon Coverage

  • From a Stricken Filing to an $8,000 Fine: How Courts Calibrate Citation Failures

    From a Stricken Filing to an $8,000 Fine: How Courts Calibrate Citation Failures

    Three late-August federal orders are useful to read together because they show something easy to miss in the current discussion around AI-tainted filings.

    The issue is not just whether bad citations appeared in a filing.

    It is how courts sort out responsibility, procedure, candor, and remedy after that happens.

    The orders in Booker v. The Kroger Co., Adams v. Matrix Providers Inc., and In re Turgeon do not land in the same place. One involves admitted AI consultation and a direct sanctions order. One leaves AI causation unresolved while criticizing counsel's judgment and rule compliance. One involves a pro se debtor, no AI finding, and a stricken filing rather than a separate sanctions ruling. A fourth recent opinion, Snisko v. Cascade Funding Mortgage Trust HB4, adds another variation: a merits affirmance and a same-opinion show-cause order directed at counsel over allegedly fabricated quotations and misrepresentations. Read together, they show that even when AI is part of the background, the consequence still turns on human conduct and procedural posture.

    Booker: The Court Reached A Direct Rule 11 Sanctions Order

    Booker is the clearest of the three.

    In an August 28 Opinion and Order of Sanctions, Judge Steven D. Grimberg sanctioned plaintiff's counsel for using "fake or hallucinated case authorities" and for misrepresenting real authorities. The order also says counsel lied to the court about AI use.

    That candor point mattered.

    The court quoted its own standing order: lawyers may use whatever AI tools they like, but only human beings will be held responsible for the outcome. The order says counsel first denied using AI at the hearing, then later acknowledged that he had "consulted" AI tools. The court found that counsel had repeatedly lied to the court and used an "entirely disingenuous" explanation to minimize responsibility.

    The sanction was concrete and public. The court imposed $1,000 for each of four highlighted fake, false, or misleading authorities, then doubled that amount because of the lies to the court, for a total sanction of $8,000. It also ordered counsel to file documentation verifying the ethics and technology CLE training he said he had completed.

    The practical lesson is that citation failures can become materially more costly after the court concludes that counsel responded with evasion instead of candor, including by falsely denying AI use.

    Adams: The Court Criticized The Briefing, But The Remedy Was Narrower

    The August 27 order in Adams took a different path.

    Judge Charlotte N. Sweeney described serious problems in plaintiff's briefing, including a phantom citation to a nonexistent case, numerous inaccurate descriptions of case holdings, and repeated failures to support assertions with accurate record citations. The court also addressed counsel's explanation that Ricks v. Starbucks was included inadvertently during a family emergency while unnamed outside help and a paralegal assisted with finalizing the briefs.

    But the order stopped short of turning the whole episode into a sweeping AI sanctions opinion.

    The court expressly said it was unclear whether the briefing failures resulted from AI use or from "poor and unexacting legal judgment." Either way, the court found the conduct highly concerning. It also cited the Tenth Circuit's statement in Amarsingh v. Frontier Airlines that there is nothing inherently problematic about using GenAI in legal practice, while careless use can waste judicial resources and damage credibility.

    The court admonished Pearson over the citation failures. Its $1,000 monetary sanction, however, was framed around the courthouse-photography violation and repeated failure to follow local rules and practice standards, although the concluding sanction paragraph also cited Rule 11(c)(1). The order should not be read as assigning a $1,000 sanction specifically to the phantom citation.

    That is a useful distinction. A filing may contain AI-shaped defects without producing the kind of direct hallucination order that Booker delivered. Courts may instead fold the problem into a broader assessment of judgment, local-rule compliance, and lawyer conduct.

    Turgeon: The Court Struck The Filing And Focused On Case Management

    Turgeon is different again.

    The New Hampshire district court affirmed the bankruptcy court's dismissal of the debtor's Chapter 13 case. In recounting the record, the order explains that the bankruptcy judge questioned the debtor about "false, hallucinated case citations" in an objection to the trustee's motion to dismiss, found the citations inaccurate and misleading, and struck the objection.

    The opinion also notes that the debtor was given a chance to cure by filing an amended objection and did not do so.

    What matters here is what the court did not do. This was not a separate Rule 11 sanctions order. The district court did not treat the citation defects as a basis for dismissal. It held that the bankruptcy court could strike the objection under § 105(a), emphasized the two-week opportunity to amend, and rejected the due-process challenge after Turgeon failed to cure. The Chapter 13 dismissal rested on separate plan-filing and delay grounds.

    That makes Turgeon a reminder that citation problems do not always become standalone sanctions opinions. Sometimes they appear as part of a court's effort to manage the docket and police misleading filings without converting the dispute into a separate sanctions proceeding.

    Snisko: The Merits Can End And The Citation Fight Can Still Begin

    Snisko contributes a narrower but useful procedural point.

    In the same August 19 opinion that affirmed the bankruptcy court's abstention ruling, Judge Manish S. Shah separately ordered appellant's counsel to show cause why he should not be sanctioned for fabricated legal citations and other misrepresentations. The opinion said the brief was "replete with false quotations and erroneous statements of law," identified apparent quotations that do not appear in cited cases including In re Aguirre and In re Boughton, and said counsel "doubled down" in the reply after the defects had been flagged.

    The order does not make an express AI finding. That is part of why it matters. It shows that a court does not need to resolve how the errors were produced before opening a sanctions track. It also shows that citation risk can survive the merits, or in this case be embedded in the same opinion that resolves them.

    The Pattern Is Human Accountability, Not Tool Liability

    Taken together, the three orders tell a more useful story than a generic warning not to trust AI.

    They show that courts are still applying familiar legal ideas:

    • responsibility attaches to the signed filing;
    • candor after an error can materially affect sanction severity;
    • procedural posture can shape whether the outcome is a Rule 11 sanction, a local-rule sanction, a stricken filing, a same-opinion show-cause order, or some combination; and
    • the court does not need a grand theory of AI causation before acting.

    That is why the recent AI filing cases should not be read as a separate body of exotic law. They are mostly ordinary supervision, certification, and litigation-conduct rules applied to a new source of error at scale.

    What Law Firms Should Change

    The control problem is not just whether a tool generated a fake case name.

    It is whether the workflow catches:

    • nonexistent authorities;
    • real authorities used for false propositions;
    • quotations that do not appear in the source;
    • inaccurate record references;
    • misleading procedural narratives; and
    • bad post-error responses that make the situation worse.

    The second control point is escalation. Once a court or opposing party flags a possible hallucination or fake authority, the matter should leave ordinary drafting flow and move into a higher-review path led by a supervising lawyer. That follow-up needs independent source verification, a clean explanation of what happened, and absolute candor with the court.

    Booker shows what happens when that second step fails. Snisko shows that simply repeating the challenged position after notice can deepen the problem even before a sanctions amount is set. Booker also shows that a court may reserve whether further sanctions are warranted while requiring proof of the remedial training counsel says he has completed.

    Bottom Line

    The late-August orders do not create a single AI doctrine under Rule 11.

    They do show a stable principle.

    Courts still care most about the human choices around the filing: who signed it, who checked it, how the lawyer responded when the defects surfaced, and whether the court's rules were taken seriously. AI may explain how the error entered the draft. It does not replace the lawyer who owns the result.

    Sources and Related Clearon Coverage

  • DOJ Urges Court To Treat LLM Training as Fair Use in OpenAI Copyright Case

    DOJ Urges Court To Treat LLM Training as Fair Use in OpenAI Copyright Case

    On September 1, 2026, the United States filed a Statement of Interest in the consolidated OpenAI copyright litigation in the Southern District of New York, urging the court to reject arguments that training LLMs on copyrighted texts violates copyright law.

    That is a formal executive-branch litigation position, not a ruling, and it leaves acquisition and output questions aside.

    It is also more aggressive than a casual policy remark and narrower than the bluntest headlines make it sound.

    The government's filing does not say every use of copyrighted material by an AI company is lawful. It separates the pipeline into acquisition, training, and output, then says the United States is focused on whether the use of copyrighted works at the training stage constitutes fair use.

    That distinction is doing real work.

    What The Government Actually Asked The Court To Do

    The filing is a Statement of Interest under 28 U.S.C. § 517, not a merits ruling and not a government complaint against anyone. It is the executive branch telling Judge Sidney Stein how it thinks federal copyright law should be applied in this litigation.

    Its central ask is hard to miss. The brief says the United States has a strong interest in the court rejecting any argument that training LLMs on copyrighted texts violates copyright law.

    The government then frames LLM development as a staged process:

    • acquisition of data;
    • model training; and
    • model outputs.

    The brief says each stage may present distinct copyright questions. But the United States limits its own position to the training stage, defined as copying works in order to feed data into the model as learning material.

    That means the filing is best understood as an effort to establish a strong presumption for training-stage fair use while leaving acquisition and output practices for separate analysis.

    Why This Is More Than A Repackaged Talking Point

    The administration had already stated in its March 2026 National Policy Framework for Artificial Intelligence that training an LLM on copyrighted material, "in and of itself," does not violate copyright law. A July 2026 DOJ journal article also addressed the doctrine, but it expressly disclaimed that the authors' views necessarily reflected DOJ policy.

    This filing is different.

    It is a formal Department of Justice submission in pending federal litigation. It was submitted under a signature block listing Associate Attorney General Stanley Woodward Jr. and Civil Division Assistant Attorney General Brett Shumate, and signed by Senior Counsel Michael Weisbuch. That does not make it controlling law, but it does make it a real statement of the executive branch's litigation position in this case.

    So the legal significance is not that the issue is now settled. It is that a federal court now has before it an express government argument that OpenAI's training use is fair use and that courts should reject a rule generally making LLM training impermissible without licensing.

    The Fair-Use Theory The Government Is Pushing

    The brief leans heavily on the idea that copyright law must distinguish among uses rather than flatten every copy into the same category.

    That is why it emphasizes a use-by-use analysis and relies on cases like Authors Guild v. Google and Google v. Oracle America. The basic argument is familiar but now stated at full executive-branch volume: copying during training is transformative because it uses works as learning material to develop a model that recognizes patterns and relationships rather than to distribute the original works as a substitute library.

    The filing's language gets especially strong in its fourth-factor discussion. It says OpenAI's model training using New York Times articles is fair use and argues that the training copy does not serve as a substitute for the original or shrink protected market opportunities in the relevant copyright sense.

    That is a more aggressive proposition than merely saying the law is unsettled.

    The brief also frames a contrary rule as harmful to innovation, scientific progress, and U.S. competitiveness. It argues that broad copyright liability for training would hamper AI development under a misunderstanding of fair use doctrine.

    The Filing's Sharpest Move Is Its Attack On Kadrey

    The most consequential doctrinal section may be the government's critique of Kadrey v. Meta Platforms.

    The filing says the Kadrey court, "without the benefit of briefing," adopted an "indirect substitution" theory of "market dilution" based on the possibility that LLMs might create books competing with human-authored books. The government argues that this approach is untethered from the core copyright inquiry because it conflates training copies, which are not publicly accessible, with outputs, which may be accessible but will often lack substantial similarity.

    That matters because the fourth fair-use factor has become one of the main battlegrounds in AI copyright cases.

    If courts accept a broad market-dilution theory, many AI developers could face a much harder path on fair use even when their models are not outputting close substitutes for specific source works. If courts instead require a tighter connection between the challenged use and legally cognizable substitution, training-stage defendants get much more room.

    So the filing is not just defending OpenAI's posture in one case. It is trying to narrow one of the strongest emerging theories plaintiffs have used against AI training.

    The Government's Policy Case Is Broader Than Doctrine

    The filing also makes an overt policy argument about structure and competition.

    It says an erroneous ruling against fair use would hamper competition in the LLM market because only the largest technology companies might have the capital to pay universal licensing fees. It also says such fees would disproportionately benefit legacy media outlets because of the sheer volume of their written publications.

    Then the filing makes the point in blunter terms: it is not in the public interest for the largest technology companies to have an oligopoly on LLM training due to licensing entry barriers that function primarily as subsidies for old mainstream media companies.

    That argument will be attractive to many AI companies and many policymakers who worry about incumbency barriers.

    It is also not the whole story.

    In a footnote, the government says it takes no position on whether a licensing regime would actually be financially or logistically feasible. So the filing is clearly hostile to broad mandatory licensing as a legal consequence of the case, but it stops short of claiming to have solved the practical licensing debate.

    What The Filing Does Not Resolve

    This is where readers should slow down.

    The government did not ask the court to bless pirated acquisition or infringing outputs. The filing expressly separates those questions from the training-stage issue it wants resolved.

    That means several high-stakes questions remain open even if the court finds the filing persuasive:

    • how the copyrighted works were obtained;
    • whether retained libraries or other collection-stage conduct raises separate infringement problems;
    • whether RAG or output behavior can create substitution or substantial-similarity issues;
    • whether training on some categories of works presents different market-harm facts from others; and
    • whether courts will accept or reject broader theories of lost licensing markets.

    Those limits matter even more because the U.S. Copyright Office's May 2025 prepublication Part 3 report takes a more qualified approach.

    The Office says various uses of copyrighted works in AI training are likely to be transformative. But it immediately adds that the result depends on what works were used, from what source, for what purpose, and with what controls on the outputs. It also warns that making commercial use of vast troves of copyrighted works to produce expressive content that competes with them in existing markets, especially through illegal access, can go beyond established fair-use boundaries.

    That report predates this filing. DOJ addresses it directly in footnote 17, arguing that similar market-dilution reasoning deserves no deference and overlooks the required use-by-use analysis.

    That is not a direct rejection of DOJ's position. But it is a reminder that the government has advanced one strong reading of fair use, not the only plausible one, and the filing itself says the fair-use inquiry still turns on the specific facts and uses at issue in each case.

    Why This Matters Beyond OpenAI

    This filing lands in the middle of a larger litigation map that includes authors, publishers, answer-engine disputes, training-data fights, and increasingly explicit market-substitution theories.

    That broader setting matters because the filing is trying to influence not just one factual record but the legal frame that future courts may use.

    If Judge Stein embraces the government's approach, the training-stage fair-use defense gets a much firmer doctrinal platform in one of the most important AI copyright proceedings in the country. If he does not, the executive branch will still have shown the argument it wants courts to take seriously: separate training from acquisition and outputs, reject generalized market-dilution theories, and treat transformative training use as consistent with copyright's constitutional purpose.

    Either way, the filing gives courts and litigants a cleaner version of the pro-training position than they had before.

    Bottom Line

    DOJ did not tell a court that everything about AI companies' use of copyrighted material is lawful.

    It did something narrower and more important.

    It told the Southern District of New York that OpenAI's training use is fair use and that training LLMs on copyrighted texts should not, in general, be treated as copyright infringement. At the same time, it left acquisition and output questions for separate analysis and did not claim every training use in every case will necessarily come out the same way.

    The fight now is over whether courts will accept that carveout, and how sharply they will separate training from the acquisition and output questions DOJ left unresolved.

    Sources and Related Clearon Coverage

  • What IPWatchdog’s Video-Game AI Warning Reveals About State AI Laws

    What IPWatchdog’s Video-Game AI Warning Reveals About State AI Laws

    Gene Quinn's new IPWatchdog Unleashed article recounts his conversation with Bijou Mgbojikwe, senior policy counsel at the Entertainment Software Association, about a central scoping problem: laws aimed at harmful deepfakes can sweep together licensed digital replicas, fictional game content, and other materially different uses. Their discussion deserves direct attention, and Clearon's tracker shows why.

    Full credit to IPWatchdog, Gene Quinn, and Bijou Mgbojikwe. The article is worth reading in full, and the related podcast and YouTube versions are worth watching or listening to as well.

    The core point is simple and important. Lawmakers often talk about deepfakes, digital replicas, AI disclosures, and harmful deception as though they were one problem with one obvious fix. They are not.

    That matters because Clearon's tracker already shows several different regulatory models moving at once. Some are relatively narrow and tied to a concrete harm. Others use broader synthetic-media or deception concepts that become much harder to apply cleanly once they reach expressive content, fictional environments, or ordinary digital creativity.

    The IPWatchdog Point Deserves Serious Attention

    Gene Quinn's writeup of his conversation with Bijou Mgbojikwe frames the issue more carefully than much of the broader AI-regulation commentary does.

    The concern is not that lawmakers should ignore fraud, impersonation, child safety, or deceptive synthetic media. The concern is that a rule designed for one misuse case can spill outward if it defines the covered content too broadly or treats every realistic AI-generated output as though it presents the same risk.

    That is especially important for games and other expressive media. A law aimed at deceptive political media, nonconsensual sexual deepfakes, or misleading advertisements does not necessarily fit a fictional game world, a synthetic background character, a stylized voice clone used with rights clearance, or a digital replica embedded in a licensed creative work.

    Our Tracker Already Shows At Least Three Different Regulatory Models

    The current watchlist and published tracker notes show why this should not be treated as a single undifferentiated "AI content" category. The laws we track already fall into materially different buckets.

    1. Narrower disclosure rules tied to a specific context

    New York's synthetic-performer advertising law is the clearest example of a narrower approach.

    As tracked in Clearon's published coverage, New York now requires disclosure when advertisements include AI-generated performers. That is a targeted rule aimed at a concrete commercial context. It is more readily confined to an identifiable commercial context than a broad rule that treats any realistic synthetic character or voice as inherently suspect across every setting.

    This is the kind of example that supports the IPWatchdog point. A narrowly framed disclosure rule for advertising is very different from a generalized rule that could bleed into expressive media or product design.

    2. Broader anti-forgery and persona-protection measures

    Pennsylvania's Act 35 of 2025 and Ohio's pending HB 185 show a different lane.

    Pennsylvania's tracked law is a broader digital-forgery measure, not just an election-deepfake statute. Act 35 addresses digital forgery through an enacted criminal framework tied to statutory intent requirements. Ohio's HB 185, which remains pending, would separately revise persona-use law and prohibit certain unauthorized deepfake recordings. Both raise scoping questions, but they regulate different conduct through different legal mechanisms.

    That does not make them illegitimate. It does mean product teams, publishers, and counsel should ask harder scoping questions before assuming the rule cleanly maps to a game or creative-AI product:

    • Is the law keyed to deception, consent, and impersonation?
    • Does it distinguish commercial misuse from expressive use?
    • Does it turn on a real person's identity, or on synthetic realism more generally?
    • Does it leave room for licensed, parodic, or otherwise protected creative work?

    Those distinctions matter a great deal in games, where character design, voice synthesis, likeness licensing, machinima-style content, and user-generated creations can all sit near the line.

    3. Definition-heavy laws where carveouts and context do a lot of work

    The election-deepfake statutes we track are not video-game laws, but they are still useful cautionary examples.

    Clearon's comparison work already shows that California's AB 2655 and AB 2839 and New Mexico's HB 182 do not all solve the same problem in the same way. They use different combinations of prohibition language, disclosure mechanics, and satire/parody treatment.

    California's measures are enacted, but their current enforcement posture is materially constrained by federal-court rulings. New Mexico's enacted HB 182 is also the subject of pending constitutional litigation. They remain useful drafting examples, not interchangeable statements of currently enforceable law.

    That is the kind of drafting variation that can become decisive once a plaintiff argues that a law reaches protected expression more broadly than lawmakers intended. Even outside elections, the lesson carries over: if the operative definition is too blunt, the exceptions and carveouts end up doing enormous work, and courts may decide they do not do enough.

    For game publishers and digital-content companies, that is the real operational warning. The hardest laws are not always the ones with the harshest rhetoric. They are often the ones whose definitions, exceptions, and disclosure triggers do not map cleanly onto the actual product context.

    What Game and Creative-AI Companies Should Be Asking

    The practical question is not whether regulation is coming. It is what category of regulation a product is most likely to attract, and whether the legal theory behind that category actually matches the feature being built.

    Companies building or distributing AI-enabled creative tools, games, avatars, voice systems, or synthetic-character features should be able to answer:

    1. Is the main risk advertising deception, persona misuse, election content, consumer confusion, or some other category?
    2. Does the feature involve a real person's likeness, voice, or identifying traits?
    3. Is the output licensed, fictional, user-directed, editorial, or platform-distributed at scale?
    4. Would a required disclosure actually reduce a real risk, or would it simply create warning fatigue?
    5. If a law uses a broad synthetic-media definition, what part of the product would be exposed first?

    That is where the tracker becomes more useful than a generic AI-policy debate. The tracked laws show that states are already choosing different regulatory instincts depending on whether the perceived harm is fraud, identity appropriation, political deception, chatbot dependence, or unsafe decision-making.

    Read The IPWatchdog Piece And Watch The Episode

    This is one of those source pieces that deserves direct attention rather than only secondhand summary.

    If you care about how AI rules could land on games, digital replicas, creative tools, and software products built around expressive content, read Gene Quinn's article at IPWatchdog. Then watch or listen to the full IPWatchdog Unleashed conversation with Bijou Mgbojikwe through the podcast feed or the IPWatchdog YouTube channel.

    Quinn's article and Mgbojikwe's analysis ask the right scoping question: how do you target real harm without writing rules so broadly that they interfere with lawful creative work, protected speech, or normal product design?

    Bottom Line

    The regulatory pressure that IPWatchdog is describing is not theoretical. Clearon's tracker already shows it.

    Some laws are narrow and context-specific, like New York's advertising disclosure rule. Some are broader anti-forgery or persona-protection measures, like Pennsylvania's Act 35 and Ohio's pending HB 185. Others show how fast disclosure mechanics, prohibition language, and carveouts can become messy once lawmakers move from a headline harm to statutory text.

    For companies in games and expressive AI, the principal mistake is treating every rule that uses the word "deepfake," "replica," or "AI" as though it targets the same conduct. Product teams need to examine the covered harm, statutory elements, exceptions, and current enforcement posture.

    Sources and Related Clearon Coverage

  • Chatbot Conversation Governance Deserves Its Own Legal Review

    Chatbot Conversation Governance Deserves Its Own Legal Review

    A user deletes a chatbot conversation. What remains in safety logs, memory state, internal review copies, or downstream summaries, and who can still access it?

    If a dispute later arises, the answer may implicate privacy commitments, preservation duties, internal knowledge, and privilege.

    Current public sources do not establish that chatbot conversations are automatically discoverable or admissible, or that every provider faces the same litigation risk. They do show growing scrutiny of how conversational data is collected, retained, reviewed, described, and protected.

    Companies should treat that lifecycle as a distinct governance domain, not as ordinary product exhaust.

    What The Current Sources Actually Show

    The public record here is mixed, and the legal posture varies across sources. H.R. 9619 is a proposed federal bill, not enacted law. The FTC's companion-chatbot 6(b) inquiry is a special-report demand, not an enforcement action.

    Even so, the sources point in the same operational direction. The bill text, Congress.gov page, and Foushee materials show that retained chat logs, personal data, deletion rights, disclosures, safety assessments, and limits on certain chatbot uses are direct subjects of this legislative proposal. The FTC inquiry shows federal interest in records about testing, harms, monetization, disclosures, and sensitive user data in conversational systems.

    Together, they show that conversation history is no longer just a background technical feature. It can become relevant to questions about privacy, safety, design, disclosures, and recordkeeping.

    The Main Legal Categories Should Stay Distinct

    One reason this topic gets muddled is that several different legal concepts get collapsed into the phrase "chat logs."

    Companies should separate at least five questions:

    1. Retention

    What conversational data is actually stored, in what form, for how long, and with what links to account identity, memory state, attachments, moderation events, or downstream summaries?

    2. User Rights And Deletion

    What does the company mean when it says a user can delete chat history? Does deletion remove only the user-facing history, or also backend records, training queues, safety logs, memory features, and internal review copies?

    3. Internal Access And Knowledge

    Who inside the company can review conversations, under what criteria, with what logging, and for what purpose? A stored interaction does not automatically prove the company had actionable knowledge of it. Knowledge questions may turn on whether and how the material was reviewed, flagged, escalated, or monitored.

    4. Preservation And Legal Holds

    Ordinary retention schedules are not the same thing as litigation preservation. Once a dispute, investigation, or reasonably anticipated claim appears, counsel may need to decide whether certain conversational records, audit logs, or related system data should be preserved. That does not justify indiscriminate overretention of everything by default.

    5. Discovery, Admissibility, And Privilege

    A conversation may be requested in discovery without ultimately being admitted into evidence. Different questions govern relevance, proportionality, authentication, hearsay, admissibility, confidentiality, and privilege. Those issues should not be blurred together.

    Treating all five categories as one undifferentiated "records" problem leads to bad policy and bad legal advice.

    Where Governance Pressure Shows Up

    Conversation data deserves its own legal review because it combines several risks in one place.

    • users may disclose personal, intimate, financial, health, employment, or legally sensitive information;
    • the model may respond with advice, warnings, refusals, or unsafe output that later matters;
    • the system may generate summaries, memory state, moderation events, or escalation records tied to the exchange;
    • the company may make public claims about privacy, safety, or deletion that users understand more broadly than the actual product design supports; and
    • legal teams may later need to explain what was stored, who could see it, and what happened after a risky interaction occurred.

    That mix creates practical governance pressure. Companies may be asked questions they cannot answer cleanly:

    • what categories of conversation data are retained;
    • whether and how minors or other vulnerable users use the product;
    • what the company tells users about deletion, review, and reuse;
    • whether risky conversations trigger moderation, escalation, or human review;
    • how long supporting logs and summaries persist after a user deletes a chat;
    • whether marketing claims about privacy or supportiveness match the actual workflow; and
    • whether counsel can distinguish ordinary retention from a triggered legal hold.

    The same pressure reaches enterprise tools as well as public consumer chatbots. Internal copilots, customer-service assistants, HR tools, and workflow bots can all create conversation records that later matter in employment disputes, compliance reviews, internal investigations, trade-secret disputes, or privilege fights.

    Companies with consumer-facing or enterprise chatbot systems should be able to map:

    1. the full conversation-data lifecycle, including prompts, outputs, metadata, attachments, memory features, moderation events, and summaries;
    2. the difference between user-visible deletion and backend retention;
    3. the conditions for internal review, safety escalation, and access logging;
    4. how minors, self-harm issues, health issues, financial vulnerability, or professionally sensitive requests are handled;
    5. how legal holds would attach to chatbot data if a dispute arises;
    6. what public-facing privacy and safety claims depend on those workflows; and
    7. where privilege or confidentiality issues may arise for enterprise or internal-use deployments.

    That list is not a claim that every company must retain more data. In some cases, the better legal and operational answer may be to retain less, narrow access, shorten default storage periods, clarify deletion language, or segment especially sensitive conversational features from broader product analytics.

    Bottom Line

    Chatbot conversations are not automatically discoverable or admissible, and the cited bill and FTC inquiry do not create a universal legal rule. They do expose the same operational pressure point: can the company explain what it retains, what deletion means, who can access the records, and when a legal hold changes ordinary retention?

    The right response may be less collection, shorter retention, narrower access, or clearer disclosures, not more data by default. What matters is that those choices are deliberate, documented, and consistent with what the company tells its users.

    Sources and Related Clearon Coverage

  • Congress Is Starting to Sketch a Federal Rulebook for AI Chatbots

    Congress Is Starting to Sketch a Federal Rulebook for AI Chatbots

    Congress has not enacted a comprehensive federal law specific to consumer AI chatbots. But lawmakers are no longer speaking about chatbot risk only in general terms.

    On August 5, the Senate Commerce Committee ordered the CHATBOT Act favorably reported with an amendment in the nature of a substitute.

    By itself, that move does not create any legal obligation. The bill is still only a proposal.

    The bill now sits inside a clearer cluster of federal proposals. The introduced version of the CHATBOT Act focuses on family accounts, parental tools, and child-safety controls. The GUARD Act takes a different lane, using age verification and a ban on minors' access for defined AI companions, while applying disclosure duties and targeted criminal prohibitions more broadly to covered chatbots.

    A separate House bill, H.R. 9619, is framed in its official title around privacy and security for AI chatbot providers, although sponsor materials describe a broader proposal.

    Together, the proposals concentrate on three recurring concerns:

    • minors and parental oversight;
    • harmful chatbot interactions and companion access by minors; and
    • privacy and security obligations for consumer-facing AI systems.

    The News Hook Is Real, But It Is Not The Whole Story

    The immediate development is the CHATBOT Act.

    Congress.gov records show that S. 4407 was introduced on April 28, 2026. On August 5, the Senate Commerce, Science, and Transportation Committee ordered it favorably reported with an amendment in the nature of a substitute.

    Unlike a bill that has only been introduced, S. 4407 has received committee consideration and approval.

    One caveat is essential. As of August 27, the cited Congress.gov text page displays only the introduced version, not the committee substitute. Official Senate Commerce and Schiff materials confirm that the committee adopted a Cruz-Schatz-Curtis substitute, as modified, along with additional amendments, and describe some of the resulting provisions. The discussion below therefore distinguishes the introduced text from what committee and sponsor materials say about the committee-approved version.

    The introduced text would require family accounts when a covered entity knows a user is under 13. When the entity knows a user is 13 through 17, it would require direct notice to a parent and verifiable parental consent before the teen creates an account or profile. In practical terms, it makes account structure and parental controls part of the proposed safety regime rather than optional product settings.

    The larger story is not simply that another chatbot bill moved in Congress. It is that multiple proposals now address different parts of the same product-governance problem.

    Three Bills, Three Lanes

    The bills' differences reveal distinct regulatory instincts.

    The CHATBOT Act: Family Controls And Minor Access

    The introduced CHATBOT Act treats children's use of covered AI chatbots primarily as a family-account and parental-control problem.

    Its core move is not simply to warn users about AI. For known child users, it would require a family account with parental controls over privacy, account settings, time spent, interaction history, purchases, and other features. For known teen users, it would require parental consent, offer the parent a family-account option, and, if the parent declines that option, fix specified features at their most protective defaults.

    The policy choice is concrete: put controls into account architecture before use rather than rely only on disclosures after access begins.

    Official committee and sponsor materials indicate that the substitute goes beyond account structure. Senate Commerce Chairman Cruz's prepared remarks say the committee version would set the most protective design settings on teen accounts by default, require reasonable efforts to stop chatbots from presenting obscene material or facilitating suicidal ideation to minors, direct minors to crisis resources, and notify parents when a child or teen linked to a family account asks about suicide. Senator Schiff's post-markup release also describes regular disclosures that users are interacting with AI rather than a real person, a prohibition on materially assisting a minor in planning or attempting suicide, and a prohibition on providing obscene material to minors. Those descriptions remain subject to verification against the substitute text when it is published.

    The GUARD Act: Age Verification, Disclosure, And Targeted Prohibitions

    The GUARD Act sits nearby but is not the same bill.

    Congress.gov records show that S. 3062 was reported to the Senate with a substitute amendment on May 11, 2026, and placed on the Senate Legislative Calendar.

    The reported text would require account-based age verification for access to defined AI companions and prohibit minors from using them. Separate provisions would apply nonhuman and nonprofessional disclosure duties to publicly available AI chatbots generally. The text also would create criminal prohibitions for making an AI chatbot publicly available with knowledge or reckless disregard that it engages in specified sexual conduct involving minors or solicits, induces, or coerces minors toward suicide, nonsuicidal self-injury, or specified violence.

    That shifts from family account structure to a different regulatory toolkit:

    • verifying whether a user is an adult;
    • barring minors from covered AI companions;
    • disclosing that a chatbot is not human and does not provide specified professional services; and
    • tying criminal liability to specified conduct and a knowledge-or-reckless-disregard standard.

    This resembles state companion-chatbot models Clearon has tracked in New York, California, and Oregon. Across those laws, AI-identity disclosures and, in some jurisdictions, self-harm response protocols have become part of the legal architecture for certain relationship-like systems.

    H.R. 9619: Privacy And Security For Chatbot Providers

    The House bill, H.R. 9619, adds a third lane.

    Congress.gov records show that it was introduced on July 9, 2026, and referred to the House Energy and Commerce Committee. Its official title says it would require AI chatbot providers to provide data privacy and security.

    The official bill-status record does not yet provide introduced text. That still limits what can responsibly be said from the official congressional record alone about its precise coverage, duties, enforcement, or relationship to existing privacy law.

    Even at the title level, the bill adds privacy and security to a debate that might otherwise be framed only around outputs or child-safety warnings.

    Representative Valerie Foushee's July 9 press release identifies H.R. 9619 as the People-First Chatbot Act and describes a package broader than the official title alone. According to the release, the bill would include rights to access and delete retained chat logs and personal data; AI-identity disclosures; restrictions on implying that chatbot outputs are provided by, endorsed by, or equivalent to outputs from specified licensed professionals; monthly safety assessments for risks including suicide, emotional dependence, and compulsive use; warrant protection for law-enforcement access to chat logs; a right to request transfer to a human operator in customer-service interactions; and enforcement by the FTC, state attorneys general, and individuals through a private right of action.

    Because those details currently come from sponsor materials rather than an official posted bill text, they should be treated as strong but still secondary support for the bill's intended scope.

    The privacy lane matters because chatbot inputs can themselves contain unusually sensitive information, while persistent systems may retain conversation history and use it to personalize later interactions.

    If Congress continues down that path, privacy and security could become a distinct federal compliance lane for products built around persistent user interaction. The text of H.R. 9619 will be needed to assess how broad that lane actually is.

    The Common Pattern Is More Important Than The Bill Numbers

    The proposals differ in scope and mechanism. H.R. 9619 also cannot be fully evaluated from official text because Congress.gov has not posted it. Read together, the available texts and sponsor materials nevertheless reveal overlapping areas of congressional attention.

    The bills collectively put a set of basic questions on the table:

    • Who is using the chatbot?
    • What happens when the user is a minor?
    • What disclosures should the provider give?
    • What controls should exist before risky interactions occur?
    • What happens when the system is used in contexts involving self-harm, violence, or emotional vulnerability?
    • What data does the provider collect through chatbot interactions?
    • How is that data secured, retained, or used?

    Committee action on the CHATBOT Act does not predict Senate floor action. It does show that account controls and interaction-specific safeguards have moved beyond an introduced proposal into a committee-approved package.

    This Fits The Broader Regulatory Picture

    These federal bills do not appear in a vacuum.

    Clearon has already tracked a broader chatbot-safety pattern:

    • states are enacting companion-chatbot laws with disclosure and, in some cases, youth-safety duties;
    • the FTC has used its 6(b) authority to ask companion-chatbot companies about testing, harms, monetization, disclosures, and data practices; and
    • at least one state enforcement action is testing chatbot safety, warnings, and child-data practices under existing consumer-protection law.

    The FTC's companion-chatbot inquiry is especially useful context here. The agency asked about monetization, character development, testing, mitigation of negative impacts, disclosures, age restrictions, and the use or sharing of conversational data.

    Those are not the exact same mechanisms Congress is using in these bills.

    But they cover much of the same risk map.

    Federal legislators, state lawmakers, and regulators are focusing on a common set of concerns: youth access, disclosures, engagement design, harmful interactions, and conversational data.

    What This Means For Companies Right Now

    None of these federal bills is enacted law, so their proposed duties are not current federal requirements. That does not resolve what existing consumer-protection, privacy, child-safety, or other generally applicable law may require.

    Enactment is uncertain, but the bills can still serve as a forward-looking checklist of issues receiving legislative and regulatory attention.

    Consumer chatbot providers should already know:

    • whether their product is likely to be used by children or teens;
    • what account structure exists for minors and parents;
    • whether age gates are meaningful or easy to bypass;
    • what user-facing disclosures explain that the system is AI rather than human;
    • how the product handles self-harm, suicide, violence, or similar high-risk interactions;
    • what privacy and security controls protect conversational data;
    • what internal records support public safety claims; and
    • how product, legal, privacy, and trust-and-safety teams divide responsibility for those issues.

    Even without enactment, the proposals identify product choices that companies may need to explain to lawmakers, regulators, users, and parents.

    The Design Question Beneath The Bills

    These proposals reach beyond whether a single chatbot output was inaccurate or harmful. Their mechanisms operate at different product layers: account eligibility, parental controls, default settings, recurring disclosures, specified prohibited interactions, data practices, and safety testing.

    That shifts the compliance discussion upstream. The concrete questions include how a provider determines age, configures defaults, delivers notices, escalates high-risk interactions, handles conversation history, and documents safety claims. Lawmakers are examining not only what chatbots say, but how access, identity, safety, and data practices are built into the product.

    Bottom Line

    The August 5 committee action on the CHATBOT Act is the immediate development: the Senate Commerce Committee ordered the bill favorably reported with a substitute amendment. Definitive analysis of the committee-approved version will require the substitute text when it is published.

    The larger story is the emergence of a more recognizable federal chatbot-bill cluster.

    The introduced version of one bill emphasizes family accounts and parental controls, while committee and sponsor materials indicate the substitute also adds AI-disclosure, suicide-response, parental-notice, and obscene-material restrictions. The reported version of another emphasizes age verification, minor access, disclosures, and targeted prohibitions. A House bill's title identifies privacy and security, and sponsor materials describe a broader package of chat-log, disclosure, safety-assessment, and enforcement provisions, although its text is not yet available in the official record.

    None of that is binding law yet.

    Taken together, the proposals show that federal chatbot legislation is getting more specific. They do not establish what Congress will enact. They do show a possible layered approach organized around minors, specified harmful conduct, disclosures, privacy, and security rather than one sweeping AI statute.

    For companies building consumer-facing chatbots, the proposals provide a concrete set of governance questions to examine while federal rules remain unsettled.

    Sources

  • Anthropic’s Supply-Chain-Risk Fight Is Emerging as a First Amendment Test for AI Procurement

    Anthropic’s Supply-Chain-Risk Fight Is Emerging as a First Amendment Test for AI Procurement

    Anthropic helped supply AI tools to the U.S. defense establishment. Then a dispute over Anthropic’s usage limits, especially on lethal autonomous weapons and mass surveillance of Americans, escalated into something far more consequential than an ordinary contracting fight.

    The turning point was the government’s decision to brand Anthropic a "supply chain risk."

    This is not just a vendor-termination fight. It is emerging as a test of how far the government can use procurement and national-security tools before a court treats that response as retaliation for protected speech, a denial of fair process, or an unlawful use of procurement authority.

    The Backdrop Matters

    Anthropic was not an outsider to government AI work when this dispute started. In its March 26 preliminary-injunction order, the Northern District of California described a close working relationship between Anthropic and defense and intelligence users. The court noted that the Department awarded Anthropic a two-year agreement worth up to $200 million in July 2025 and was already using Claude Gov through partner platforms.

    One quick naming clarification: Executive Order 14347 authorized "Department of War" and "Secretary of War" as secondary titles, while statutory references to the Department of Defense and the Secretary of Defense remain controlling unless changed by law, so Judge Rita Lin’s order adopted the parties’ "Department of War" phrasing for consistency without changing the underlying statutory structure.

    What Triggered The Break

    According to Judge Lin’s order, the relationship fractured when the Department insisted it needed to use Anthropic’s models for "all lawful uses" without Anthropic’s usage restrictions. Anthropic agreed only with two exceptions: mass surveillance of Americans and lethal autonomous warfare.

    That disagreement, standing alone, would not necessarily make this a constitutional case. The district court was explicit on that point. The government remains free to stop using Claude and choose a different vendor.

    The legal problem, in the court’s telling, was what happened next.

    The order says the government went further through three distinct measures that should not be blurred together:

    • the President announced an all-agency ban on future Anthropic contracting;
    • Secretary Hegseth announced a broader boycott-style directive aimed at firms doing business with the military; and
    • the Department separately used formal supply-chain-risk machinery to designate Anthropic a "supply chain risk."

    That sequencing matters. The court treated the government’s freedom to stop buying from Anthropic as one thing, and these broader steps with reputational and market consequences as something else. The order also noted that the government later narrowed its position by saying the formal designation did not itself bar unrelated contractor use of Claude, which only reinforced how much the dispute turned on the scope and theory of the designation.

    Judge Lin wrote that these measures appeared designed to punish Anthropic rather than simply protect the government’s contracting interests.

    Why The March 26 Order Was Such A Big Deal

    The preliminary-injunction order is worth reading directly because the court was unusually plainspoken. But its significance goes beyond the First Amendment language that attracted the headlines.

    Judge Lin wrote that "[p]unishing Anthropic for bringing public scrutiny to the government’s contracting position is classic illegal First Amendment retaliation." She also wrote that "[n]othing in the governing statute supports the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government."

    Those are not final merits holdings. They are preliminary-injunction findings. But they are still significant because they show how sharply the court viewed the government’s theory on the existing record.

    The same order also rested on two other important pillars. First, the court found likely Fifth Amendment due-process problems in the way Anthropic was branded and restricted. Second, it found likely APA problems, including serious questions about whether the government had followed the procedures Congress tied to this kind of designation under 10 U.S.C. § 3252.

    That makes the March 26 ruling more interesting than a simple speech case. The order repeatedly distinguished between the government’s undisputed freedom to stop buying a product and its more aggressive effort to attach a national-security-style label with broader downstream consequences. The court illustrated the breadth of the separate Presidential and Hegseth directives with commonplace uses of Claude: an NEA website project and a defense contractor’s customer-service chatbot. That is where the case starts to feel less like vendor management and more like a fight over sovereign coercion.

    Where The Case Stands Now

    The injunction is not the end of the story.

    The CourtListener docket shows that Judge Lin entered both a reasoned order granting the preliminary injunction and a separate operative injunction on March 26, 2026. The opinion explains the court’s reasoning; the separate operative order blocks implementation or enforcement of the Presidential Directive, Hegseth Directive, and formal Supply Chain Designation pending final resolution or further order. The parties have since completed merits briefing, and the cross-motions for summary judgment were argued July 30 and taken under submission.

    Lawfare’s July 30 hearing diary reports that Judge Lin held a hearing on cross-motions for summary judgment and opened by saying the record appeared "largely the same" as it had at the preliminary-injunction stage, adding that she did not see additional evidence from the government improving its position and that "if anything it’s gotten worse." That is hearing coverage, not a written merits ruling, but it is still notable as a signal of the court’s concerns.

    The same Lawfare account also notes a parallel challenge in the D.C. Circuit under a different procurement statute, 41 U.S.C. § 4713. That is not merely the same dispute repackaged. It is a separate statutory track with its own posture and appellate consequences, which means readers should resist flattening everything into a single all-purpose Anthropic precedent.

    Why This Matters

    This case sharpens a question that reaches well beyond Anthropic.

    If an AI vendor sets usage limits for safety, legal, or civil-liberties reasons, how much room does the government have to respond through procurement pressure? One answer is easy: it can stop buying the product. The harder question is whether it can go beyond that and use supply-chain-risk machinery in ways a court might see as punitive, reputationally destructive, or speech-chilling.

    That is why this litigation matters to more than one company or one administration. It sits at the intersection of AI governance, procurement power, constitutional limits on retaliation, and the procedural guardrails Congress attached to national-security-style procurement designations.

    The government does have a theory here. In rough terms, it argues that a vendor supplying critical AI capabilities to defense users becomes a supply-chain concern if it reserves the right to withhold or constrain those capabilities in scenarios the government considers lawful and operationally necessary. The problem for the government, at least on the preliminary record, was not simply articulating that theory. It was substantiating it and connecting it legally to the authority Congress actually granted under § 3252.

    So the most interesting boundary in this case is not "buyer and regulator." It is ordinary contractor management versus sovereign coercion. On the current record, that is the line Judge Lin appears most concerned about.

    What To Watch Next

    The next developments worth watching are concrete ones:

    • whether Judge Lin’s eventual merits ruling keeps the same mix of First Amendment, due-process, and APA reasoning;
    • how the court treats the distinction between normal procurement discretion and punitive sovereign action;
    • what happens in the parallel D.C. Circuit track under the separate federal procurement statute; and
    • whether the government can produce a supply-chain-risk record that is both factually concrete and legally tied to the right statute.

    Those questions will likely tell readers more than the slogans around the dispute.

    Bottom Line

    The Anthropic case is now bigger than a fight over one AI contract.

    The most important issue is not whether the government had to keep using Claude. It did not. The more consequential issue is whether the government crossed a legal line when it escalated a contracting dispute into an adversary-style designation, a move the district court preliminarily concluded was likely unlawful under the First Amendment, the Due Process Clause, and the APA.

    That is why this remains one of the more consequential AI-law cases to watch, especially for readers trying to understand where procurement pressure ends and sovereign coercion begins.

    Sources

    Related Clearon Coverage

  • wikiHow v. OpenAI Could Become a Clearer Test of AI Answer Substitution

    wikiHow v. OpenAI Could Become a Clearer Test of AI Answer Substitution

    The newest copyright suit against OpenAI may matter less because it adds one more plaintiff and more because of what kind of plaintiff it is.

    wikiHow sued OpenAI in the Southern District of New York on August 21, alleging that OpenAI copied 11,211 wikiHow articles and infringed 1,211 registered copyrights. The complaint says OpenAI used that library "to build and operate ChatGPT," which it describes as a product that "supplies the substance of wikiHow's articles to readers who never arrive at wikiHow's pages." The filing also frames the alleged infringement across three channels: training-data copying, retrieval at runtime through RAG systems, and user-facing outputs.

    That combination makes this case worth watching.

    Many AI copyright cases already argue that model training used protected works without permission. The complaint here presses a more pointed practical theory too: OpenAI's systems allegedly use wikiHow content in ways that let ChatGPT answer the user's question instead of sending the user to the original instructional page.

    That is not yet a ruling. It is only a complaint-stage allegation. But it is a useful litigation development because it appears to sharpen the market-substitution question in a way some broader training suits do not.

    Why This Complaint Looks Different

    The complaint lands in a crowded field of AI copyright litigation. OpenAI is already facing claims from publishers, authors, and other rightsholders over model training and outputs.

    wikiHow's content, however, creates a slightly different frame.

    This is not just premium journalism, books, music, or images. It is a large library of practical how-to content built to answer specific user questions directly. If a chatbot gives the user a clean, useful answer to the same question, the substitution argument becomes easier to picture in everyday terms.

    That does not automatically make the legal claim stronger. It does make the economic theory easier to explain.

    If a chatbot supplies a sufficiently complete answer, a user may decide not to click through to the original article. In that sense, wikiHow could become a clearer test of alleged output-side competition than a complaint built mostly around the existence of training copies.

    The Copyright Issue Is Still Not Simple

    That is also why the case is interesting for the defense side.

    Instructional content sits in a legally awkward place. Copyright does not protect facts, systems, or methods as such. It protects original expression. For how-to material, that can make the boundary fight more visible.

    OpenAI's likely response, at least at a high level, is already familiar. Reuters reports that OpenAI says its models use publicly available data under fair use, which also considers whether the unlicensed use harms the market for the original work.

    The complaint makes the market-harm theory equally legible. If OpenAI used wikiHow content in ways that help generate answers that compete with the site, the market-harm question should not be treated as abstract.

    That means this case may force closer attention to a set of linked issues:

    • what exactly was copied during training;
    • how much of wikiHow's protectable expression, rather than uncopyrightable method or fact, appears in outputs;
    • whether those outputs can reasonably substitute for the original articles in the market; and
    • how courts should evaluate systems that answer the same practical question through a different interface.

    That still does not mean substitution alone would establish infringement. A system can compete with a source, summarize an idea, or answer the same practical question without necessarily infringing a copyright. The harder legal question is whether protected expression was copied or reproduced in a way the law recognizes, and how any resulting market harm should factor into the fair-use analysis.

    Why Clearon Readers Should Care

    For companies building or using generative AI systems, the important point is not just that another complaint was filed.

    The important point is the theory behind it.

    Some of the most useful future copyright disputes to watch may not be the ones that argue only that a model learned from protected material. They may be the ones that connect three things in one story:

    • identifiable source copying;
    • recognizable output behavior; and
    • a believable explanation for how the output threatens the source's market.

    Based on the complaint and the currently available reporting, wikiHow appears designed to tell that story in a relatively intuitive way.

    That matters beyond publishing. Any company building answer engines, support bots, research tools, workflow copilots, or domain-specific assistants should be watching how courts think about substitution theories when a system delivers useful task-oriented answers that may reduce a user's reason to visit the original source, especially where the plaintiff also alleges copying of protected expression and concrete fair-use market harm.

    What To Watch Next

    At this stage, the useful questions are procedural and factual before they are doctrinal.

    Watch for:

    • how the complaint's vicarious infringement and DMCA removal-of-CMI claims fare in motion practice or discovery;
    • whether wikiHow presses output examples aggressively or centers the case more on ingestion and training;
    • how OpenAI frames fair use for instructional content in particular;
    • whether the case stays a standalone S.D.N.Y. matter or becomes linked in some way to the broader OpenAI copyright cluster; and
    • whether the court treats market substitution in a chatbot setting as a concrete factual issue rather than a speculative theory.

    Those points may tell us more than the initial headlines.

    Bottom Line

    wikiHow v. OpenAI is still only a newly filed complaint. Nothing has been proven, and there is no ruling yet.

    But it looks like a potentially important complaint anyway.

    The reason is not just that wikiHow accuses OpenAI of training on its content. It is that wikiHow seems positioned to argue something narrower and more practical: OpenAI's systems allegedly use wikiHow material in ways that let ChatGPT answer the same how-to questions and compete with the original pages.

    If courts start engaging that theory seriously, this case could become a clearer test of AI answer substitution than another generalized training-data fight.

    Sources

    Sources and Related Clearon Coverage

  • Mobley v. Workday Shows the AI Hiring Fight Is Not Just About Employers

    Mobley v. Workday Shows the AI Hiring Fight Is Not Just About Employers

    The most important thing about Mobley v. Workday is not that a lawsuit against an AI hiring vendor exists. It is that the case keeps surviving key dismissal fights.

    In June, Reuters reported that Workday must continue defending California claims and a federal disability-discrimination theory tied to its AI-powered recruiting tools. That does not mean Workday has been found liable. It has not. The case is still active. But the June 22 order matters because it kept alive a version of the argument many vendors would rather avoid: a hiring-technology provider may not be able to end the case just by saying the employer made the final decision.

    That makes Mobley one of the clearest AI-employment cases to watch.

    For readers coming to this cold, the short arc matters. The case was filed in 2023. In 2024, Reuters reported that Judge Rita Lin allowed a federal theory to proceed on reasoning that Workday could potentially be treated as an employer covered by federal anti-discrimination law because it allegedly performed screening functions that its customers would otherwise perform themselves. In June 2026, Reuters then reported that Workday also had to keep defending California claims and a federal disability theory. So the current importance of Mobley is not one isolated ruling. It is a sequence of rulings refusing to let the case disappear early.

    What The Plaintiff Says Happened

    The plaintiff, Derek Mobley, alleges that Workday's screening tools helped exclude job applicants on unlawful grounds, including race, age, and disability. Reuters reported in 2024 that Mobley said he was rejected from more than 100 jobs with employers using Workday's platform.

    The theory is broader than one bad hiring decision. It is that the screening system itself may reproduce or amplify bias when employers use it across large numbers of applications.

    Workday denies that theory. Reuters reports that Workday says its recruiting tools do not make hiring decisions in California or anywhere else, that the technology looks at job qualifications rather than protected traits, and that it tests its products through a Responsible AI program.

    That is exactly why the case matters. The dispute is not just about whether bias exists. It is about where legal responsibility can sit when screening logic is supplied by a vendor but deployed inside an employer's hiring workflow.

    Why The June Ruling Matters

    The June 22 ruling is significant because it did not let the case collapse into a simple vendor-distance defense.

    According to Reuters, the court allowed claims to continue under California law and under a federal disability-discrimination theory. Earlier Reuters reporting had already described the case as a novel test of whether an AI screening vendor can face liability even though it is not the direct employer, and had tied that issue to the court's 2024 reasoning about Workday's alleged screening role.

    That does not answer the merits. It does answer something else that matters right now: the legal theory is serious enough to keep moving.

    For companies using AI in hiring, that is already a material development. A lot of governance planning still assumes the main legal risk sits with the employer and that the software provider is one step removed. Mobley is part of the reason that assumption looks less comfortable than it used to.

    The Real Legal Question Is About Functional Role

    The cleanest way to read Mobley is not as a referendum on AI in hiring generally.

    It is a case about functional role.

    If a vendor provides technology that meaningfully affects who gets screened out or moved forward, courts may look past formal labels and ask what role the system actually played in the hiring process.

    That question matters because modern hiring systems often do more than host applications. They can shape who gets surfaced, filtered, or routed to the next stage even when the employer remains the formal decision maker.

    Once the system starts doing that kind of work, the old line between "tool provider" and "decision maker" becomes harder to police with a simple contract definition.

    Why This Matters Beyond Workday

    Even if Workday ultimately wins, the case still tells employers and vendors where the pressure is building.

    The pressure points are familiar:

    • what data the system was trained on or calibrated against;
    • what traits or proxies may affect scoring and ranking;
    • whether customers can understand and audit the system's logic;
    • how bias testing is done and how much of it can be verified later;
    • what notice, review, or override rights exist in practice; and
    • who can reconstruct the path from application to rejection when a claim arrives.

    That list is not just for Workday.

    Any company buying or selling AI-assisted hiring technology should assume those questions may become discoverable facts rather than policy talking points.

    Why Clearon Readers Should Care

    Employment AI coverage often splits too neatly into two buckets.

    One bucket is compliance advice for employers. The other is product-risk advice for vendors.

    Mobley matters because it keeps blurring that line.

    The case suggests that a vendor cannot assume it is legally insulated just because a customer technically owns the hiring decision. It also suggests that an employer cannot assume responsibility sits neatly with the software maker if the system is embedded in the employer's own screening workflow.

    That means both sides need a stronger record.

    Employers need to know what the system actually does, what inputs it uses, what testing supports it, and how humans review outcomes. Vendors need to know how they describe the system, what documentation they can provide, what bias-testing evidence exists, and whether their product design makes the customer's review meaningful or merely ceremonial.

    What To Watch Next

    The next useful questions in Mobley are not abstract.

    Watch for:

    • how the pleadings and later evidence describe Workday's actual screening functionality;
    • whether disability, age, race, and other theories stay aligned or split procedurally;
    • how discovery fights over bias testing, model evaluation, and applicant data play out;
    • whether the court continues to treat Workday as potentially close enough to the hiring process to face anti-discrimination claims; and
    • whether the case produces a practical record about what responsible AI testing in hiring is supposed to look like.

    That last point may matter as much as the formal liability ruling.

    Bottom Line

    Mobley v. Workday does not prove that Workday discriminated, and it does not establish that every hiring vendor can be sued successfully under the same theory.

    But it does show something important already.

    The AI hiring fight is not staying confined to the employer alone. Courts are willing, at least at this stage and on the pleaded facts, to take seriously the argument that a vendor supplying the screening logic may remain in the case.

    For employers and vendors alike, that is enough reason to treat AI hiring documentation, testing, and review as litigation records rather than marketing language.

    Sources

    Sources and Related Clearon Coverage

  • Amazon v. Perplexity Is an Early Court Test for Agentic AI Under the CFAA

    Amazon v. Perplexity Is an Early Court Test for Agentic AI Under the CFAA

    The Ninth Circuit's August 4 decision in Amazon.com Services, LLC v. Perplexity AI, Inc. draws one of the first appellate lines around agentic AI and computer access law.

    The immediate holding is narrower than the headlines make it sound. The court vacated a preliminary injunction that had blocked Perplexity's AI-enabled browser assistant from interacting with Amazon on users' behalf. The panel said Amazon was unlikely to succeed, on the record before it, in showing that Perplexity itself "accessed" Amazon's computers within the meaning of the federal Computer Fraud and Abuse Act and California's parallel statute.

    That is not a general license for AI agents to operate on third-party platforms. The opinion instead suggests that, for purposes of the CFAA's access element, some user-directed AI activity may be treated as the customer's use of a tool rather than the tool provider's own entry into a platform's computers.

    What the Fight Was About

    Amazon's theory was straightforward. Perplexity's Assistant, an optional feature in its Comet browser, could use a customer's Amazon session to browse and carry out tasks on the user's behalf. Amazon said Perplexity lacked permission for that activity under the CFAA and California's Comprehensive Computer Data Access and Fraud Act. Central to the dispute was Perplexity's decision not to use a user-agent string that would identify the Assistant and allow Amazon to block it.

    The district court had granted Amazon a preliminary injunction in March. The Ninth Circuit vacated that order and sent the case back.

    The key question was easy to state and harder to answer: when a user tells an AI agent to act on a website, who is doing the "accessing" for computer fraud purposes?

    Why the Ninth Circuit Matters

    The Ninth Circuit answered that question narrowly, based on the technology and record before it.

    The panel concluded that the user accessed Amazon's computers with the Assistant's help. Perplexity's servers received browser screenshots and sent instructions back to the Assistant, but did not directly communicate with Amazon's servers. Those facts did not show that Perplexity itself had gained entry to Amazon's systems, the court reasoned.

    That reasoning matters because Amazon's CFAA claim required proof that Perplexity accessed a protected computer. The panel did not reach authorization or the statute's remaining elements, including its loss requirement.

    The same user-versus-provider question is likely to arise again as AI agents move from answering questions to logging in, navigating sites, filling forms, pulling account data, and initiating transactions.

    This Is Bigger Than One Shopping Dispute

    Amazon v. Perplexity does not resolve agentic AI access disputes. It shows courts beginning to decide how older computer access laws apply when software takes multiple steps at a user's direction rather than waiting for each click.

    That problem is not limited to e-commerce. The same legal tension can show up in:

    • enterprise automation tools that log into third-party services on behalf of employees;
    • consumer AI assistants that navigate password-protected sites;
    • browser-based agents that compare products, prices, or terms across platforms;
    • internal legal and compliance tools that automate retrieval from external systems; and
    • research workflows that rely on user-authorized scraping or session-based access.

    The Knight First Amendment Institute, joined by the ACLU and ACLU of Northern California, raised another concern in an amicus brief: reading the CFAA too broadly could chill journalism and public-interest research that depends on automated tools operating with user-provided access.

    The argument does not immunize researchers or AI vendors, but it shows why the stakes extend beyond this dispute.

    What Companies Should Take from It

    The safest reading is not "AI agents are fine now." It is that the technical path matters: who directs the tool, which computers communicate, where data goes, and how much control the provider exercises. Although user direction was important to the panel's access analysis, the opinion did not decide whether a user's permission would defeat a platform's authorization argument.

    For companies building agentic products, a few practical questions now look more important:

    • Is the agent acting with clear, documented user authorization?
    • Does the product rely on the user's own credentials and permissions, or does it bypass technical controls?
    • What signals does the system send to the platform about the nature of the interaction?
    • Does the workflow create separate data-use, contract, privacy, or state-law risk even if the CFAA theory weakens?
    • How much of the task is user-directed versus autonomously optimized by the vendor?

    For platforms, the decision shows the difficulty of a CFAA claim when the record depicts the user, rather than the tool provider, as entering the platform's systems. Contract claims, technical controls, API design, bot-detection systems, privacy arguments, and data-use restrictions may still matter.

    Why Clearon Readers Should Care

    This case sits at the intersection of AI product design, litigation risk, and platform governance.

    Agentic AI marketing often assumes that if a user can do something, an AI agent can do it without changing the legal analysis. The Ninth Circuit did not endorse that broad claim. It instead held that Amazon was unlikely, on the current record, to prove that Perplexity was the party that accessed its computers.

    That is an important early signal for legal teams reviewing AI assistants that operate inside customer accounts or interact with third-party services.

    Future disputes are therefore likely to turn on details: credentials, disclosure, technical barriers, autonomy, data handling, system architecture, and the relationship among the user, vendor, and platform.

    Bottom Line

    Amazon v. Perplexity is one of the first appellate opinions to test how the CFAA applies to agentic AI.

    The Ninth Circuit did not give AI agents blanket immunity. At the preliminary-injunction stage and on the record before it, the court held that Amazon was unlikely to show that Perplexity "accessed" Amazon's systems when the user accessed them with the Assistant's help.

    That is a meaningful development for AI companies, platforms, and in-house legal teams.

    The next question is whether other courts follow the same user-versus-tool framing, or whether different facts push them toward a narrower view of what agentic systems can do inside someone else's digital environment.

    Sources and Related Clearon Coverage