Tag: Legal Risk

  • Oregon Supreme Court’s First AI Hallucination Sanctions Show What Courts Punish Most

    Oregon Supreme Court’s First AI Hallucination Sanctions Show What Courts Punish Most

    The Oregon Supreme Court has issued its first sanctions orders involving court filings attributed to generative artificial intelligence. The significance is not a new AI-specific rule. It is that the court applied familiar duties of accuracy, reasonable inquiry, supervision, and candor to filings containing AI-generated errors.

    They also show that the response after an error is discovered can matter almost as much as the original filing.

    In one case, a self-represented litigant accepted responsibility, fully responded to the court, and received a $500 sanction with permission to submit a corrected filing. In the other, self-represented litigants acknowledged fabricated authorities but submitted more nonexistent cases less than 12 hours after the court's show-cause order. The court struck their filings and dismissed the proceeding.

    The lesson extends well beyond Oregon and beyond self-represented litigants. Courts across the country have imposed monetary sanctions, fee awards, dismissal, disqualification, practice suspensions, bar referrals, mandatory disclosures, and other remedies for filings containing fabricated or materially inaccurate authorities.

    Key Takeaways

    • *The Oregon Supreme Court sanctioned self-represented litigants, not lawyers.* The orders make clear that the obligation not to inject false authority into a proceeding applies to everyone who files.
    • *Courts are punishing the filing, not the mere use of AI.* The recurring issue is whether the signer verified that authorities exist, quotations are accurate, and cases support the propositions asserted.
    • *Candor changes the sanction analysis.* Prompt disclosure, correction, and acceptance of responsibility can mitigate sanctions. Repetition, concealment, blame shifting, and misleading explanations can sharply increase them.
    • *The signature and supervision duties are nondelegable.* Lawyers cannot avoid responsibility by pointing to an associate, contract lawyer, local counsel, vendor, internal AI tool, or firm policy.
    • *Financial penalties are only part of the risk.* Dismissal, disqualification, suspension, bar referral, and mandatory notice to clients and other courts can be more consequential than a fine.

    Oregon's Two New Orders

    The Oregon Supreme Court issued both orders on June 4, 2026, and announced them publicly the next day.

    Aldridge v. Tussing: Repeating the Error Led to Dismissal

    In Aldridge v. Tussing, the relators filed a petition for a writ of mandamus supported by nonexistent cases and fabricated quotations. The court ordered them to verify every citation under penalty of perjury, explain the errors, and show cause why sanctions should not be imposed.

    The relators acknowledged that fabricated authorities had been included and attributed the errors to a service called LegalAI. But less than 12 hours after receiving the show-cause order, they submitted another declaration containing at least four nonexistent cases.

    The court struck the petition and the show-cause response and dismissed the proceeding. Its explanation was direct: injecting false precedent undermines the integrity of a proceeding, and repeating the conduct in response to a show-cause order warrants a meaningful sanction.

    Witkin v. McGreevy: Acceptance of Responsibility Mitigated the Result

    In Witkin v. McGreevy, a self-represented respondent filed a response containing fictitious authorities and inaccurate legal arguments generated with AI. After receiving a show-cause order, the respondent addressed each fabricated authority, explained the AI use, and accepted responsibility.

    The court still struck the filing and imposed a stipulated $500 sanction. But it allowed the respondent to file a corrected response, provided that any revised filing certified that every cited, quoted, or paraphrased source of law had been verified to exist.

    The contrast is the point. Both filings contained false authority. The litigant who responded candidly and corrected course received a limited financial sanction and another opportunity to file. The litigants who repeated the misconduct after a direct warning lost the proceeding.

    Oregon Already Had a Six-Figure Warning for Lawyers

    The state-court orders arrived only months after a separate federal case from Oregon demonstrated how large the financial exposure can become.

    In Couvrette v. Wisnovsky, the U.S. District Court for the District of Oregon addressed summary-judgment briefing containing nonexistent cases and fabricated quotations. The court struck the briefing, dismissed the plaintiffs' claims with prejudice, imposed monetary sanctions, and awarded the opposing parties $94,704.38 in fees and costs directly resulting from the briefing.

    The March 2026 fee order allocated the award between lead counsel and local counsel. The local lawyer was ordered to pay 15% after the court found that he had failed to meaningfully participate despite serving as required local counsel for a lawyer admitted pro hac vice. The lead lawyer was ordered to pay the remaining 85%. The court also required local counsel to attach the sanctions order to future motions in which he sought to sponsor pro hac vice counsel in the district.

    Together with the court's earlier monetary sanctions, the financial consequences exceeded $110,000. More important, the case shows that local counsel and supervising lawyers cannot treat their role as providing a name, bar number, or signature while leaving the substance unchecked.

    The Sanctions Menu Is Expanding

    The early headline case was Mata v. Avianca. In 2023, the Southern District of New York imposed a $5,000 penalty after lawyers submitted fabricated cases and fake opinions generated by ChatGPT and continued to defend the material after its authenticity was questioned. The court also required notice to the client and to judges falsely identified as authors of the fabricated opinions.

    Since then, courts have used a much broader range of remedies:

    • *Sanctions for every signer:* In Wadsworth v. Walmart, the District of Wyoming imposed $5,000 in combined sanctions and revoked one lawyer's pro hac vice admission after a filing cited eight nonexistent cases. The court treated the duty to ensure a filing is supported by existing law as nondelegable.
    • *A $10,000 appellate sanction:* In Noland v. Land of the Free, L.P., the California Court of Appeal imposed $10,000 in sanctions after an appellate brief contained fabricated quotations and other inaccurate authority. The published opinion warned that lawyers must personally read and verify the authorities they cite.
    • *Disqualification and bar referrals instead of a fine:* In Johnson v. Dunn, the Northern District of Alabama publicly reprimanded and disqualified three lawyers, required broad distribution of the sanctions order, and referred the matter to licensing authorities. The court concluded that a fine and public embarrassment were insufficient deterrents.
    • *Suspension from appellate practice:* In Lnu v. Blanche, the Ninth Circuit imposed $2,500 sanctions on each of two lawyers, suspended both from practice before the circuit for six months, required notice to clients, opposing counsel, judges, and the lawyers' firm, and imposed a two-year AI-use disclosure and verification requirement. The court emphasized that the more serious discipline resulted from repeated failures of candor after the errors came to light.
    • *Both sides sanctioned:* In Withers v. City of Aberdeen, the Northern District of Mississippi sanctioned and removed all four lawyers after filings from both sides contained hallucinated authorities. The two out-of-state lawyers were also barred from appearing in the district for two years.

    These cases do not establish a uniform sanctions schedule. They show that courts are calibrating remedies to the conduct, the harm, the lawyer's role, prior warnings, remediation, and candor.

    What Courts Appear to Punish Most

    The orders point to several aggravating factors.

    Filing Without Reading the Authorities

    Checking whether a case name exists is not enough. Courts expect lawyers to read the authority and confirm that quotations are accurate, procedural posture is correctly described, and the case actually supports the proposition asserted.

    The Ninth Circuit drew a useful distinction between fabricated authorities and subtler inaccuracies. A fake case may be easy to detect. A real case mischaracterized by an AI tool may be more dangerous because it can survive a superficial citation check.

    Treating Signatures as Administrative

    Courts repeatedly reject the idea that a lawyer can lend a signature without assuming responsibility for the filing. That principle reaches supervising lawyers, local counsel, partners, and lawyers whose names appear in signature blocks even when they did not personally use AI.

    Repeating or Concealing the Problem

    An inaccurate filing creates a serious problem. Misleading the court about how it happened, replacing fake citations without disclosing the original problem, or submitting additional fabrications after a warning creates a larger one.

    The Oregon Supreme Court's two orders make the distinction unusually clear. So does the Ninth Circuit's order in Lnu, where the court said lesser sanctions might have been warranted if the lawyers had promptly disclosed the AI use and accepted responsibility.

    Relying on a Policy Without Enforcing It

    Having a written AI policy is not a defense when actual workflows allow unverified material to reach the court. Policies must identify who checks citations, quotations, propositions, facts, and record references before filing. They also need a clear escalation process when an error is discovered.

    What Litigation Teams Should Do Now

    For a practical pre-filing workflow, use Clearon's AI-Assisted Legal Filing Verification Checklist.

    • Require verification of every citation, quotation, factual assertion, and record reference against the original source before filing.
    • Make the signing lawyer responsible for confirming that verification occurred.
    • Apply the same controls to work prepared by associates, contract lawyers, local counsel, clients, vendors, and AI tools.
    • Preserve enough information about the drafting and verification process to explain it accurately if questioned.
    • When an error is discovered, notify the court and opposing counsel promptly, identify the nature and source of the error, and propose a concrete correction.
    • Do not describe a fabricated authority as a typographical error or silently swap in a different citation.
    • Train lawyers to detect mischaracterizations of real cases, not only nonexistent citations.
    • Treat show-cause orders as urgent risk events requiring independent review and senior oversight.

    Bottom Line

    The Oregon Supreme Court's first AI-related sanctions orders do not ban AI. They show how courts protect the integrity of filings when AI-assisted work reaches the docket without real verification.

    The technology may explain how a false citation appeared, but it does not change who is responsible for filing it. Courts are increasingly focused on three questions: Was the filing verified? Who accepted responsibility for it? What happened after the error was discovered?

    The emerging sanctions record suggests that the last question can determine whether the result is a correctable mistake, a monetary penalty, a lost case, or a career-level disciplinary problem.

    For the broader court-rule landscape, see Federal Court AI Orders Are Splitting Into Clear Patterns and Clearon's AI Litigation Practice Tracker.

    Sources

    Sources

  • Trump’s New AI Executive Order Turns Frontier Models Into a Cybersecurity Priority

    Trump’s New AI Executive Order Turns Frontier Models Into a Cybersecurity Priority

    President Donald Trump signed a new artificial intelligence executive order on June 2, 2026, and the center of gravity is clear: cybersecurity, critical infrastructure, and the most capable frontier models.

    The order, titled "Promoting Advanced Artificial Intelligence Innovation and Security," does not create a broad AI licensing regime. It expressly says it should not be read to authorize mandatory preclearance, licensing, or permitting for the release of new AI models. But it still gives the federal government a more formal role near the front end of model release: identifying high-capability frontier models and arranging early, secure access before those models are shared more widely with trusted partners.

    This is not a general-purpose AI rulebook. It is a national-security and cybersecurity order. Advanced AI is treated as both a defensive asset and a possible accelerant for cyber risk.

    What the Order Does

    Four pieces do most of the work.

    First, it directs federal cybersecurity leaders to prioritize AI-enabled cyber defense across national security systems, Department of War systems, and civilian federal government systems. Within 30 days, CISA, in consultation with OMB and other White House cyber and national-security officials, is directed to issue binding operational directives and other guidance where appropriate.

    Second, it creates an AI cybersecurity clearinghouse. Treasury, the Department of War through NSA, DHS through CISA, and the National Cyber Director are directed to form a voluntary clearinghouse with AI companies and critical-infrastructure operators. The goal is to coordinate vulnerability scanning, validation, remediation, and patch distribution.

    Third, it directs federal officials to develop a classified benchmarking process for advanced cyber capabilities in AI models. That process will help determine when an AI model should be treated as a "covered frontier model" under the order.

    Fourth, it calls for a voluntary framework under which AI developers can work with the federal government to determine whether models under development meet the covered-frontier-model threshold. Developers may then give the government secure access to covered models, with confidentiality, cybersecurity, insider-risk, intellectual-property, and nondisclosure protections, for up to 30 days before release to other trusted partners.

    That is the legal story for AI companies. The order does not say, "submit your model for approval." It says the federal government wants a structured way to spot advanced cyber capability, review certain models before broader trusted-partner release, and coordinate deployment where national cybersecurity interests are implicated.

    Why It Matters

    The order keeps the administration's pro-innovation posture, but it also shows where federal oversight is likely to harden first. Not around generalized consumer AI rules, at least not here. Around cybersecurity, national security, critical infrastructure, and model capability thresholds.

    That should get the attention of several groups.

    AI developers will need to assess whether their model-development processes can support secure government engagement without compromising trade secrets, release timelines, or customer commitments. Even a voluntary framework can become practically significant when major labs, cloud platforms, federal contractors, or critical-infrastructure vendors are involved.

    Federal contractors and regulated entities should watch the CISA and OMB guidance that follows. The order directs action on federal systems, but it also points to access for state and local authorities and operators of critical infrastructure, including rural hospitals, community banks, and local utilities. That suggests downstream cybersecurity expectations may reach beyond Washington.

    Legal and compliance teams should also pay attention to the documentation burden. If a model could plausibly fall within a classified benchmarking process, companies will want a defensible internal record of model capabilities, cyber-risk testing, access controls, deployment plans, and third-party release decisions.

    The Frontier-Model Piece

    "Covered frontier model" may be the most consequential phrase in the order.

    The order directs federal officials to build a classified benchmarking process to assess advanced cyber capabilities and identify the threshold for that designation. The designation decision is assigned to NSA leadership in consultation with the National Cyber Director, the Assistant to the President for Science and Technology, CISA, and Department of War representatives.

    That approach keeps the most sensitive capability assessment out of public view. It also means companies may never get a clean public checklist for what makes a model covered. They may instead be dealing with a government-facing process built around classified benchmarks, agency judgment, and secure communications with federal officials.

    From a legal-risk perspective, this creates several practical questions:

    • How will a company determine whether to initiate voluntary engagement?
    • What internal evidence should support the company's view that a model is or is not likely to meet the threshold?
    • How will pre-release access be governed contractually?
    • How will intellectual property, model weights, system prompts, evaluations, logs, and vulnerability findings be protected?
    • What happens if a company disagrees with the government's assessment?

    The order does not answer those questions. It starts the process that will create them.

    Not a Licensing Regime, But Not Nothing

    The anti-licensing language is not throwaway. It appears designed to reassure industry that the administration is not recreating a mandatory pre-release approval system for frontier AI.

    But legal teams should not mistake that reassurance for irrelevance. Voluntary frameworks can still shape market expectations, procurement preferences, liability arguments, insurance underwriting, and board-level risk controls. If the federal government creates a recognized process for secure early access and frontier-model cyber benchmarking, companies that ignore it may eventually have to explain why.

    That is especially true in sectors where AI models are deployed into cybersecurity products, vulnerability detection, incident response, financial services, health systems, utilities, or other sensitive environments.

    The Altman-Musk Divide

    The industry's early reaction shows why that anti-licensing language was probably necessary.

    OpenAI has publicly embraced the final order's basic structure. Sam Altman reportedly said the order "gets the balance right," and OpenAI's chief global affairs officer, Chris Lehane, framed the issue as one for democratic institutions, technical experts, and public stakeholders. That fits OpenAI's broader posture: accept government-informed safety testing and standards for high-capability systems, while resisting a regime that turns every major model release into a permission slip.

    Elon Musk and xAI appear to be in a different, more skeptical lane. Axios reported that Musk, along with Meta's Mark Zuckerberg and White House AI adviser David Sacks, spoke with President Trump before an earlier version of the order was delayed. The final version that emerged was narrower: voluntary rather than mandatory, built around a 30-day pre-release access window, and explicit that it does not authorize preclearance, licensing, or permitting for new AI models.

    That does not mean xAI is rejecting federal testing. In May, xAI, Google, and Microsoft agreed to give the federal AI Safety Institute, now CAISI, access to models for security testing before release. The better reading is narrower: xAI appears willing to participate in government model testing, while the Axios reporting suggests Musk was part of the industry pushback against a heavier pre-release review regime.

    For legal teams, that distinction is useful. The frontier labs are not simply dividing into "regulated" and "unregulated" camps. They are drawing boundaries around the legal character of the process: voluntary cooperation, safety benchmarking, and secure government access on one side; mandatory licensing, public approval gates, and open-ended release delays on the other.

    Enforcement Against AI-Enabled Cybercrime

    The order also directs the Attorney General to prioritize enforcement against people who use AI to unlawfully access or damage computer systems, steal data, or facilitate other crimes. It specifically references federal computer crime and fraud statutes, including 18 U.S.C. 1028, 1030, and 1343.

    That section is short, but it does some work. It frames AI-enabled cyber misuse as an enforcement priority rather than a wholly new legal category. The administration appears to be saying that existing criminal laws already reach many AI-assisted cyber offenses, and DOJ should treat AI use as a reason to prioritize those cases.

    Companies should read that as a controls issue. AI agents, autonomous scanning tools, security research workflows, and employee use of AI in technical environments all need clear authorization boundaries. A tool that accelerates defensive work can also create evidence problems if it is used the wrong way.

    What To Watch Next

    The next 30 to 60 days will tell us more than the headline did.

    CISA guidance and any binding operational directives will show how federal agencies are expected to use AI-enabled cyber tools and whether contractors will see new expectations in security programs. Treasury, NSA, DHS, and the National Cyber Director's clearinghouse work will show how much private-sector coordination the government can realistically achieve. The classified benchmarking process will determine whether "covered frontier model" becomes a narrow national-security category or a broader marker for advanced AI cyber capability.

    The order is not a comprehensive AI law. It is not a privacy law, a copyright law, or a civil-liability framework. It does show where federal AI governance may harden first: cybersecurity.

    For AI companies and the organizations that rely on them, the practical takeaway is direct: model capability, cybersecurity readiness, release governance, and critical-infrastructure impact now belong in the same review process.

    Editorial Notes

    Suggested dek: The June 2 order does not create a mandatory AI licensing system, but it does create a federal path for frontier-model cyber benchmarking, secure early access, and AI-enabled cyber defense.

    Suggested social: The new AI executive order is not a broad licensing regime. It is something more targeted: a cybersecurity and national-security framework for frontier-model capability, pre-release access, and critical infrastructure defense.

    Related follow-ons:

    • What AI companies should document before engaging with the voluntary frontier-model framework.
    • Why CISA's next AI guidance may matter more than the executive order itself.
    • How AI-enabled cybercrime enforcement could affect companies using autonomous agents.

    Sources

  • Disney v. Midjourney and the Broader Copyright Question for AI Users

    Disney v. Midjourney and the Broader Copyright Question for AI Users

    Disney v. Midjourney makes the AI copyright fight more concrete.

    The case is about training data, but it is also about outputs that allegedly look too much like famous protected characters and franchise imagery.

    What the case is actually about

    Disney, Universal, and affiliated rights holders sued Midjourney in federal court in Los Angeles on June 11, 2025.

    The case is:

    • Case: Disney Enterprises Inc. v. Midjourney Inc.
    • Court: C.D. Cal.
    • Docket: 2:25-cv-05275
    • Status: pending

    The studios' position is straightforward. They say Midjourney was built using copyrighted works and that the service can generate outputs that are too close to protected characters and expressive elements. The complaint reportedly includes example prompts and output images involving well-known properties, which is part of why the case landed so clearly in public discussion.

    Two examples from the complaint show why the output issue is getting so much attention:

    Cropped complaint comparison image showing an alleged Midjourney Homer Simpson output beside Disney reference images.
    Cropped complaint comparison image showing an alleged Midjourney Homer Simpson output beside Disney reference images. Source: Complaint, Disney Enterprises Inc. v. Midjourney Inc., No. 2:25-cv-05275 (C.D. Cal.), page 32.
    Cropped complaint comparison image showing an alleged Midjourney Minions output beside Universal reference images.
    Cropped complaint comparison image showing an alleged Midjourney Minions output beside Universal reference images. Source: Complaint, Disney Enterprises Inc. v. Midjourney Inc., No. 2:25-cv-05275 (C.D. Cal.), page 51.

    Midjourney’s likely response is also familiar. Training is not the same as republishing a work. Not every prompted image is substantially similar enough to infringe. And not every reference to a known character, franchise, or visual style cleanly collapses into liability for the platform.

    That is why this case matters. Both sides are arguing about where the legal line sits when a model produces commercially useful images that unmistakably evoke existing protected expression.

    Can businesses use Midjourney images commercially?

    Midjourney’s published guidance says customers generally own the images and videos they create and may use them commercially, subject to its terms and plan requirements. For businesses with more than $1 million in annual gross revenue, Midjourney says a Pro or Mega Plan is required for commercial use.

    That contractual permission is only one part of the analysis. It does not guarantee that a particular output is noninfringing, that the user owns every element in the output, or that the output qualifies for copyright protection. Midjourney’s terms provide the service and assets on an “as is” basis, disclaim a warranty of noninfringement, and place responsibility for using or redistributing assets on the customer.

    For business use, the practical controls should include:

    • confirming that the account and subscription plan permit the intended commercial use;
    • screening prompts and outputs for recognizable characters, logos, protected expression, and other third-party rights;
    • retaining records of prompts, source materials, edits, and human review;
    • requiring additional clearance before using AI-generated images in prominent campaigns, products, or customer deliverables; and
    • reviewing vendor terms regularly because platform rules and protections can change.

    Commercial-use permission from the platform answers whether Midjourney permits the use. It does not answer whether a rights holder may challenge it.

    Related Clearon AI analysis: OpenAI copyright MDL and data governance and AI-generated code and copyleft risk.

    The bigger issue

    For companies, the issue is not just whether Midjourney wins or loses.

    It is whether the business has decided what level of copyright and brand-adjacent risk it is actually willing to accept when employees use generative AI in public-facing work.

    Many legal teams are comfortable saying obvious character replication is out of bounds. The harder question is the gray zone. Is the company willing to rely on a fair use argument if a marketing image is styled to evoke Disney, South Park, or another highly recognizable visual world? Is it comfortable arguing that a prompt drew on a style, not a protected work? Is it willing to defend that position after publication, in a customer campaign, or in court?

    That is the governance issue this case sharpens. Companies need a view on where they are comfortable being aggressive, where they want to be conservative, and which arguments they are actually prepared to stand behind if challenged.

    They also need to account for contract risk, not just copyright doctrine. Most, if not all, major AI image providers put the user on the hook for at least some infringement risk tied to prompts, inputs, or outputs. Even when a vendor offers limited indemnity, it is often narrow and conditional. So a company deciding to operate in the gray zone may also be deciding that it, not the service provider, will carry much of the downstream claim risk.

    The Clearon AI takeaway

    Disney v. Midjourney turns AI copyright risk into a risk-allocation question for users, not just model developers.

    The practical lesson is less “never touch this” and more “decide, in advance, which copyright arguments your company is truly willing to own.”

    Sources

  • The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK's recent data-law changes matter for AI governance because they suggest a real break from the EU approach to automated decision-making.

    If you want the official legislation, the UK law is here: Data (Use and Access) Act 2025.

    Under section 80 of the Data (Use and Access) Act, the UK has replaced the old Article 22 framework with a more permissive structure: automated decision-making with safeguards, rather than a prohibition-first starting point.

    This is a real shift

    Under the classic Article 22 model, the analysis usually began with a restriction. The UK's newer approach is more operational and less categorical. The question becomes less "is this forbidden unless an exception applies?" and more "what safeguards, transparency, and review rights are required when this happens?"

    That may sound subtle, but it matters. It gives companies more room to deploy automated systems, while also increasing pressure to justify how those systems are used.

    What multinational teams should watch

    A lot of organizations still hope they can run one clean global policy for AI-enabled decision-making. The UK’s move makes that harder. If the EU and UK keep drifting apart here, legal teams may need separate assessments for profiling, scoring, and model-driven recommendations that affect individuals.

    That does not just affect flashy AI products. It can reach ordinary systems used in employment, insurance, financial services, fraud detection, customer eligibility, and prioritization workflows.

    The takeaway

    The UK is not abandoning regulation. It is choosing a different posture. A permission-with-safeguards model still requires governance, and in some ways it requires better governance because companies have more room to act.

    Cross-border AI compliance is starting to look less like one policy problem and more like jurisdiction management. That is the part legal teams should plan around now.

  • Illinois Is Turning AI in Employment Into a Notice and Recordkeeping Problem

    Illinois Is Turning AI in Employment Into a Notice and Recordkeeping Problem

    Illinois is becoming one of the clearest examples of where employment AI regulation is heading: notice, documentation, and practical scrutiny of how tools influence decisions.

    If you want the official bill history, Illinois’s law is here: HB 3773. The Illinois Department of Human Rights also has a direct summary page here: Artificial Intelligence in Employment.

    Recent draft rules from the Illinois Department of Human Rights would implement the state's newer restrictions on AI discrimination in employment. The bigger point is the compliance model taking shape around them.

    The trigger looks broad

    The reported standard is not limited to futuristic hiring bots. The rules would apply when AI is used “to influence or facilitate” covered employment decisions, including recruiting, hiring, promotion, discipline, discharge, training selection, and terms or conditions of employment.

    That deserves attention because the notice trigger may be broader than many employers expect. If AI is involved in screening resumes, targeting job ads, evaluating candidates, analyzing interviews, or helping shape employment outcomes, notice may be required even if the employer did not intend discrimination.

    Employment AI is becoming an operations issue

    The trend line is clear: employment AI law is moving away from “prove the tool caused unlawful bias first” and toward “tell people when the tool is in the process, document what it is doing, and be ready to defend the workflow.”

    That is why legal teams need a real inventory of where AI shows up in the employment stack, not just in one recruiting product. AI can appear in sourcing, ranking, interview analytics, assessments, chatbots, promotion systems, and workforce-monitoring features.

    The takeaway

    The answer is not to ban every automated feature. It is to map the tools, define which ones influence covered decisions, and decide where notice, contract review, testing, and documentation are required.

    Illinois is sending a simple message: if AI helps shape employment outcomes, silence is not a compliance strategy.

  • Connecticut’s SB 5 Shows How Far a State Can Push on AI Governance

    Connecticut’s SB 5 Shows How Far a State Can Push on AI Governance

    Connecticut has moved from “state to watch” to a state companies may actually need to operationalize against.

    If you want the official bill text, Connecticut’s latest substitute text is here: SB 5.

    On May 1, 2026, the legislature passed SB 5, a broad AI bill that would place Connecticut among the more aggressive state players in AI governance. The point is not just that another state acted. It is that Connecticut appears to be building a framework that spans multiple AI risk areas at once.

    What makes this state move worth watching

    A lot of state AI proposals focus on one slice of the problem, usually hiring tools, consumer protection, or deepfakes. Connecticut's approach is broader. It treats AI governance as a cross-functional legal problem rather than a niche product issue.

    That matters because it better reflects how organizations actually use AI. AI now touches hiring, customer communications, vendor tools, automated decisions, synthetic media, and internal workflows.

    The patchwork problem is getting harder

    SB 5 is also another reminder that federal law is not about to simplify the map. States are continuing to legislate, and they are doing it with different definitions, priorities, and enforcement models.

    That creates two practical tasks for legal teams. First, they need a real inventory of where AI shows up in the business. Second, they need a governance structure that can absorb state variation without rewriting the whole policy stack every time a legislature moves.

    The takeaway

    Connecticut’s bill may not become the national template by itself. But it does point toward the future: AI governance that looks more like privacy or employment compliance, meaning state-specific, operationally demanding, and hard to solve with one policy memo.

    Connecticut is not the whole story. But it is increasingly part of the real one.

  • Colorado Rewrites Its AI Law Before It Fully Takes Hold

    Colorado Rewrites Its AI Law Before It Fully Takes Hold

    Colorado's AI law is moving again before many companies have even finished mapping the original version.

    If you want the official text, the Colorado bill is here: SB26-189.

    In May 2026, lawmakers passed SB 26-189, a major rewrite of the state's earlier AI framework. The main shift is from regulating broadly defined “high-risk AI systems” to regulating automated decision-making technology, or ADMT, when it materially influences consequential decisions.

    What stands out is how directly the law targets decision environments legal teams already care about: employment, housing, lending, insurance, health care, education, and essential government services. The practical question is less about what a tool is called and more about how it is used when it affects a person in a meaningful way.

    The new focus is operational accountability

    The revised bill is set to take effect on January 1, 2027. That buys time, but it also makes the compliance direction clearer.

    Developers would need to give deployers technical documentation on intended uses, training data categories, limitations, and human-review instructions. Deployers would need to provide consumer notices and, after an adverse outcome, a plain-language explanation of the role the system played. Consumers would also have rights to seek correction of inaccurate data and meaningful human review.

    What legal teams should focus on

    This is especially important for employment and other high-impact workflows. Recruiting tools, ranking systems, interview-analysis products, and recommendation engines can all end up inside the regulatory frame if they materially influence decisions.

    That means the compliance question becomes more concrete: what is the system doing, who is relying on it, what notice is required, and what happens when someone challenges the outcome?

    The bigger lesson

    Colorado’s rewrite is a useful reminder that state AI compliance is still moving in real time. Static AI policies are going to age badly. Legal and compliance teams need a more flexible operating model that can absorb changing definitions, disclosure duties, and review rights across states.

    The takeaway is not that Colorado is backing away from AI regulation. It is that Colorado is trying to make its law more targeted and more workable. For companies using AI in consequential decisions, the safer question is not “do we use AI?” but “can we explain and defend how this system influenced the decision?”

  • Your AI Prompts May Not Be Privileged

    Your AI Prompts May Not Be Privileged

    Lawyers and business teams are increasingly using AI to think through legal and risk questions.

    That does not automatically make the prompt, output, or workflow privileged.

    The practical risk is simple: if people put sensitive legal analysis into the wrong AI environment, they may create a discoverable record instead of a protected one.

    This is a privilege, confidentiality, and workflow problem showing up in a new tool.

    The key practical point

    There is a major difference between:

    • a public or lightly controlled AI tool
    • and an enterprise environment with negotiated controls, restricted retention, and clear terms that do not permit your prompts or data to be used to train models for other users

    That distinction should be doing a lot of work in legal AI policy.

    If the tool is not enterprise-approved, if the data controls are unclear, or if the provider can use prompts to improve models for others, legal teams should assume the risk is much higher.

    What not to do

    • Do not paste live dispute facts, investigation details, board communications, draft legal theories, or regulator-response strategy into a casual AI tool.
    • Do not assume a prompt is protected just because it relates to legal advice.
    • Do not let employees use consumer AI tools for sensitive legal work without tool-specific approval.
    • Do not treat “internal” and “privileged” as if they mean the same thing.
    • Do not rely on vague vendor marketing about privacy or security. Check the actual enterprise terms, retention settings, training terms, and admin controls.

    What to do instead

    • Use an enterprise AI environment with contractual controls and settings that prevent your prompts and data from being used to train models for other customers or the public service.
    • Limit legal-use cases to approved tools and approved users.
    • Create a short list of off-limits prompt categories, including litigation strategy, privileged investigation facts, deal-sensitive issues, and regulator-response planning.
    • Require lawyer involvement when the purpose of the workflow is legal advice.
    • Know what records the tool keeps, where they are stored, who can export them, and how long they remain available.

    What recent cases make clear

    Recent attention to cases like United States v. Heppner has put a spotlight on a basic point many organizations still blur: a communication can feel private and still fail privilege requirements.

    In Heppner, Judge Rakoff held that AI-generated materials created through Claude were not protected by attorney-client privilege or the work-product doctrine because the defendant disclosed information to a third-party platform and the materials were not prepared by counsel or at counsel’s direction.

    Different cases can come out differently, and courts are not applying a one-line rule that all AI prompts are discoverable or all AI-assisted work loses protection.

    But that is not a reason for comfort. It is a reason to stop assuming the facts will break your way.

    A useful default rule

    If a prompt would be uncomfortable to hand to an opposing lawyer, regulator, or prosecutor later, it should not be casually entered into an unstructured AI workflow.

    That rule is not perfect, but it is much better than assuming “we were just using AI to think.”

    The takeaway for legal teams

    The real issue is not the model by itself. It is whether the workflow, tool, and contract structure are good enough to support sensitive legal use.

    Clearon AI’s recommendation is not to ban AI for legal work. It is to make sure legal AI use happens inside the right workflow.

    • approve an enterprise AI environment with terms and settings that protect sensitive prompts and do not allow them to train models for other users
    • block consumer or unapproved tools for privileged, litigation, investigation, and regulator-response work
    • limit sensitive legal prompting to approved users and defined use cases
    • give employees concrete do-and-don’t rules instead of vague policy language
    • treat prompt security, retention, and export controls as part of legal workflow design, not an afterthought

    In law, workflow mistakes have a nasty habit of becoming exhibits.

  • The EU AI Act Priorities Just Shifted Again

    The EU AI Act Priorities Just Shifted Again

    The EU AI Act story in 2026 is no longer about one looming deadline.

    It is about figuring out what moved, what did not, and where legal teams should spend compliance time first.

    “The AI Act was delayed” is too sloppy to be useful.

    Recent reporting indicates that the European Parliament and Council reached agreement on amendments that would postpone some major obligations, especially around high-risk AI uses and watermarking timing, while the European Commission also published draft guidance on transparency obligations that still begin this year.

    So the practical question is not whether the AI Act matters less. It is where the immediate compliance pressure now sits.

    It is what still appears to hit in 2026 and what can likely be sequenced later.

    The short version

    Here is the cleanest practical read based on current reporting:

    What did not move

    • core transparency obligations still appear set for August 2, 2026
    • disclosure expectations for AI systems that interact with people
    • related user-facing design and notice questions
    • the need to review where AI-generated or AI-manipulated content appears in products and workflows

    What moved later

    • AI-generated content transparency and some watermarking-related timing reportedly moves to December 2, 2026
    • Annex III high-risk AI systems reportedly move to December 2, 2027
    • Annex I product and product-safety high-risk AI systems reportedly move to August 2, 2028

    That does not mean companies can relax.

    It means they should stop treating every AI Act obligation as if it lands on the same day.

    What stayed on the 2026 calendar

    The biggest mistake legal teams can make here is hearing “delay” and translating it into “not urgent.”

    That would be a bad read.

    Even with the reported changes, core transparency obligations still appear positioned to matter starting August 2, 2026.

    For many organizations, that means focusing now on systems that interact directly with users and making sure disclosures are not buried in terms or documentation nobody reads.

    In plain English, companies should be asking:

    • Where are users directly interacting with AI systems?
    • Is the disclosure clear in the interface itself?
    • Are we treating different user groups appropriately?
    • Do any product flows involve AI-generated or AI-manipulated content that raises separate transparency issues?
    • Are product, legal, compliance, and design teams aligned on what the user actually sees?

    That is practical work. Not compliance cosplay.

    What legal teams should do now

    This is the moment for reprioritization, not celebration.

    A practical checklist:

    • map AI systems that directly interact with users
    • identify where AI-generated or AI-manipulated content appears
    • review interface-level disclosures instead of relying on buried policies
    • separate immediate 2026 transparency work from later high-risk build-out
    • revisit vendor diligence questions and contract language in light of the updated timing
    • give business teams a clearer timeline so “delay” does not become an excuse for doing nothing

    For in-house teams, this is also a communications problem.

    If the business hears only that the EU delayed the AI Act, the organization may under-resource work that still appears likely to happen this year.

    That misunderstanding can create more risk than the original deadline pressure.

    The bigger lesson

    The EU AI Act is becoming a sequencing challenge.

    That means the winning move for legal teams is not just knowing the rules. It is knowing the order in which the rules matter.

    That is what good AI governance looks like in practice.

    Not panic.
    Not delay theater.
    Just disciplined prioritization.

    The AI Act still matters in 2026.

    The real question now is which part of it is knocking first.

    One caution, though: because this area is moving through amendments, guidance, and implementation detail at the same time, legal teams should confirm the latest official timetable before treating any one summary as the final word.