Blog

  • PRG News Roundup, October 2, 2024

    News

    California has passed a bill mandating car manufacturer and vehicle connected services providers to develop software allowing drivers of vehicles to be notified and given the option to disable any person outside the vehicle trying to access their vehicle location. The legislation comes on the heels of news reports about abusers using connected cars to stalk their victims, highlighting victim’s inability to obtain efficient redressal.

    The much debated Safe and Secure Innovation for Frontier Artificial Intelligence Models Act has been passed by the California State Assembly. The Act seeks to guard against proliferation of deepfakes and similar other AI misuses. It requires developers to implement precautions before they train a sophisticated AI model such as implementing the capability to enact a full shutdown promptly, implementing and preserving a written safety and security protocol, etc.

    Neural data, i.e., data relating to the activity of the brain, is now classified as sensitive personal information under the California Consumer Privacy Act (CCPA). On September 30, 2024, the CCPA was amended to extend the protective umbrella of ‘sensitive personal information’, to information that is generated by measuring the activity of a consumer’s central or peripheral nervous system, and that is not inferred from non-neural information. The amendment is effective immediately.

    In a development that preserves childrens’ privacy as to sexual orientation, California governor has signed a bill prohibiting schools from outing transgender and gay students to their parents. The law overrides existing school board policies throughout the State which require staff to inform parents if their child starts using a name or pronoun that doesn’t match their sex assigned at birth.

    (Compiled by Student Fellow Nirali Sanghavi)

  • PRG News Roundup, September 25, 2024

    News

    Californians can now add their driver’s licenses and state IDs to their digital wallets on both
    Apple and Android devices. Other states – including Louisiana and Colorado – have rolled out
    their own digital IDs that can be used during traffic stops and other police interactions. Showing
    these IDs may waive privacy protections in interactions with law enforcement.

    LinkedIn revealed that it had been training its AI model on user data. Under its new privacy
    policy, LinkedIn now informs users that “we may use your personal data… [to] develop and train
    artificial intelligence (AI) models, develop, provide, and personalize our Services, and gain
    insights with the help of AI, automated systems, and inferences, so that our Services can be more
    relevant and useful to you and others.” Users can opt-out of future data collection, but not
    remove their information from past training datasets.

    Meta will not voluntarily join the EU’s AI Pact, a temporary measure before the AI Act comes
    into force in 2026.

    Telegram has tweaked its policies to be able to share more data with government authorities, in a
    reversal of longstanding policy

    The US Commission on Civil Rights issued a report on the civil rights implications of the federal
    use of Facial Recognition Technology. The report identified that there are no laws that expressly
    regulate the use of FRT or other AI by the federal government
    , and no constitutional provisions
    governing its use.

    (Compiled by Student Fellow Anthony Perrins)

  • PRG News Roundup, September 18, 2024

    News

    A study found that drivers are more likely to be distracted while using partial automation tech.

    OpenAI’s safety committee announced it will oversee security practices as an independent body.

    Instagram announced new privacy and parental controls for Instagram accounts of users under 18. It will port certain Instagram accounts to private by default “Teen Accounts”.

    A Politico piece describes how Andrew Kingman, outside counsel for the State Privacy and Security Coalition, has played a key role in shaping business-friendly data privacy laws across numerous states by lobbying against stricter regulations and promoting industry-favorable provisions.

    Exploding devices modified by Israel somewhere along the supply chain during manufacture or transit raise questions about the security of hardware.

    Events 

    Kate Crawford’s and Vladan Joler’s MoMA exhibit Anatomy of an AI System “analyzes the vast networks that underpin the “birth, life, and death” of a single Amazon Echo smart speaker, painstakingly compiling and condensing this huge volume of information into a detailed high-resolution diagram.” 

    The Privacy Research Group will be hosting the event “Surveillance, Geofence Warrants, and the Fourth Amendment: Recent Developments” in Furman Hall Room 120 from 1:30 to 2:30 pm on Tuesday, September 24th (in-person only). You can RSVP here. It’ll include a lecture by Albert Fox Cahn, a Q&A, and snacks & coffee. 

    On October 1, 2024, the AI(M) for the Future will feature six sessions, with options for both in-person and online attendance. Register here.

    The Engelberg Center has several events at NYU in the next week: a book launch event for the book Feminist Cyberlaw next Monday and a conference on the Hatch-Waxman Act next Thursday and Friday.

    (Compiled by Student Fellow Rebecca Kahn)

  • PRG News Roundup, April 3, 2024

    News

    The California Privacy Protection Agency issues a bulletin advising businesses to implement strong data minimization principles, including when processing consumer requests under the CCPA itself. [April 2]

    Google settles a class action lawsuit alleging it illegally stored data about users’ “incognito” browsing by agreeing to destroy billions of records and alter its tracking policies moving forward. [April 1]

    OpenAI announces — but does not release — a new “Voice Engine” model which can recreate a person’s voice based on only 15 seconds of audio. [March 29]

    OMB announces new guidance for federal agencies using AI, requiring agencies that cannot implement certain mandatory evaluation and monitoring safeguards by December 2024 to cease using AI systems until they can comply.

    The European Court of Justice rejects a request from Amazon to temporarily suspend the application of the Digital Services Act while the company litigates whether or not it is a “very large online platform” subject to the Act’s heightened requirements. [March 27]

    The Department of Justice and 16 states sue Apple for restricting competition by, among other things, artificially constraining messaging features between iPhones and Android devices and preventing third party developers from competing with Apple’s tap-to-pay digital wallet feature. [March 21]

    (Compiled by Student Fellow Micah Musser)

  • PRG News Roundup, March 27, 2024

    News

    Florida signed into law a social media ban for minors 13 and under, with 14-15 needing parental consent

    Portugal’s data regulator has ordered Worldcoin to stop collecting biometric data for 90 days, given concerns about unauthorized data collection from minors, as well as Worldcoin’s lack of consent or data deletion mechanism.

    The NTIA finishes up its public comment period on open-source AI models on 3/29.

    The FTC opened a new investigation into TikTok into alleged unfair and deceptive business practices as well as violations of the Children’s Online Privacy Protection Act.

    A man in Montana pleaded guilty earlier this month to wildlife trafficking charges as part of an effort to create cloned giant sheep hybrids.

    In its investigation of the 2020 SolarWinds cyberattack, the SEC is asking technology and telecom companies for internal communications as to how they handled the hack, prompting business pushback.

    Events

    Professor Strandburg is speaking on a panel as part of the Journal of Law & Business’s spring symposium, Artificial Intelligence and Antitrust: Global Regulatory Changes, from 6-8pm on 4/3.

    (Compiled by Student Fellow Stephanie Chen)

  • PRG News Roundup, March 6, 2024

    News

    The House of Representatives will be performing a Full Committee markup of H.R. 7521, the Protecting Americans’ Data from Foreign Adversaries Act on March 7, 2024. This is a response to privacy concerns in national security with sensitive data, including health data, about Americans traveling abroad being collected and sold, particularly to foreign adversaries. President Biden issued an Executive Order last week discussing steps being taken to protect Americans’ sensitive data from exploitation by foreign adversaries, including genetic and biometric information.

    The National Institute of Standards and Technology, responsible for promoting innovation and new technologies in the US, is struggling with funding. The agency is unable to do foundational work because it is so underfunded. President Biden’s AI Executive Order rests heavily on the NIST to oversee AI models and the data privacy and security of such models. The Washington Post article describes the NIST building as absolute decay, with black mold forcing an evacuation, leaks, and struggling technology.

    A bill introduced in Florida banning all minors under the age of 16, with or without parental consent, from addictive social media platforms was vetoed by Governor Ron DeSantis. Governor DeSantis previously seemed on board with the bill, having concerns about privacy for minors. Governor DeSantis is now believed to support a bill that would ban access for younger minors but allow access, with parental consent, for minors 14 and older.

    Google and Reddit came to an agreement allowing Google to use Reddit posts to train its AI in addition to other services. Reddit is then allowed to use Google’s AI model for its own site improvement. The $60 million deal set a precedent for tech companies to obtain data for AI models in the future. As part of the deal, Google must comply with Reddit’s privacy policy and fully delete data once a user has deleted a post, not allowing Google to keep shadow data.

    Germany is amending its Federal Data Protection Act. The amendment draft institutionalizes the German Data Protection Conference and aims to improve data protection law enforcement. The German press release states that there will additionally be legal certainty for consumer protective scoring, which has been developed with the Federal Ministry for the Environment and Consumer Protection.

    (Compiled by Student Fellow Paulina Andrews)

  • PRG News Roundup, February 28, 2024

    News
    On February 20, 2024, Nevada Attorney General Aaron Ford filed a motion to prevent Meta from providing end-to-end encryption on Messenger for users residing in the state who are under the age of eighteen. Since December 2023, Meta has made end-to-end encryption the default for all messages on Messenger. The AG has sought rapid hearing on the matter, citing the “extreme urgency” affecting the safety and well-being of minors in Nevada. Meta responded by noting the value of encryption in protecting communications and personal information.

    The Supreme Court heard a pair of cases (Moody v. NetChoice, LLC and NetChoice, LLC v. Paxton) on February 26, 2024. The Court appeared skeptical of laws in Florida and Texas that regulate how large social media companies exercise their editorial discretions over content moderation. The Court’s decision would have an enormous impact on the scope of the First Amendment and the nature of speech in the internet era.

    UnitedHealth, the nation’s largest insurer, was hit by a cyberattack on its unit—Change Healthcare, a division of Optum. The attack was discovered on February 21, 2024, and appeared to be a ransomware attack launched by a foreign nation-state actor. This latest attack foregrounded the vulnerability of healthcare data and private medical records, especially those of patients. The cyberattack disrupted UnitedHealth’s services with prescription drug orders and even affected the U.S. military overseas.

    Canada has introduced a new bill—the Online Harms Act—that requires social media platforms to remove posts exposing children to online abuse. The Canadian Parliament needs to vote on the bill, but the proposed Act aims to create a “digital safety commission” to regulate social media companies and offer more effective means to protect children online.

    President Biden issued an Executive Order on February 28, 2024, to protect the sensitive personal data of Americans. The Executive Order authorizes the Attorney General to “prevent the large-scale transfer of Americans’ personal data to countries of concern” and provides relevant safeguards. The “countries of concern” specified in the Order included China, Russia, Iran, North Korea, Cuba, and Venezuela. Such restrictions mark the first-ever broad prohibition on the sale of digital data by the U.S. to individual countries.

    Wendy’s has announced its plan to spend $20 million on more enhanced features, including dynamic pricing and digital menu boards that allow for a more flexible menu in stores. The company has further clarified that it will not use surge pricing, similar to that used by Uber, after its CEO Kirk Tanner’s comments to investors sparked commotion around the possibility of adopting this practice, which raises prices when the demand is highest.

    (Compiled by Student Fellow Stephanie Shim)

  • PRG News Roundup, February 22, 2024

    News 

    The Centers for Medicare & Medicaid Services (CMS) announced changes to the current research data request and access policies in the name of data security that will limit individual researchers’ access to data.

    The European Commission has opened investigations to assess whether TikTok has breached the Digital Services Act.

    Reddit has signed a contract to allow a company to train its AI Models on the platform’s content, ahead of its IPO.

    Signal is testing a beta version that hides user’s phone numbers and lets them pick a username instead.

    The European Court of Human Rights ruled that weakening end-to-end encryption presents a disproportionate risk of undermining human rights.

    Events

    Abrams Institute Conversations will host Yale Law Professor Jack Balkin to discuss the cases before the Supreme Court concerning the power of states to regulate content moderation on social media platforms. Monday, March 4 · 12 – 1:30pm EST

    Papers

    Researcher Access to Social Media Data: Lessons from Clinical Trial Data Sharing authored by Christopher Morten (Columbia Law School), Gabriel Nicholas (New York University School of Law) and Salome Viljoen (University of Michigan Law School; Harvard University). 

    (Compiled by Student Fellow Marina Garrote)

  • PRG News Roundup, February 7, 2024

    News

    Google agreed to a $350 million settlement over a lawsuit related to a security lapse that exposed Google Plus users’ data, amidst other legal challenges for privacy and competition law violations.

    The FTC has issued proposed settlements to ban the sale of sensitive geolocation data by data brokers, marking a significant step in addressing privacy concerns and emphasizing the need for informed consumer consent.

    Apple is reportedly considering acquiring the German AI startup Brighter AI to integrate its Precision Blur and Deep Natural Anonymisation technologies into the Vision Pro, aiming to enhance privacy by anonymizing faces and license plates in photos and videos.

    The EU requires large tech platforms like TikTok, X, and Facebook to identify AI-generated content to safeguard the upcoming European election against disinformation.

    Nightshade v1.0 ‘poisons’ AI models by embedding imperceptible pixel-level changes into images to prevent unauthorized use of artworks for AI training, with some critics labeling the tool as a form of ‘illegal’ hacking.

    A new report criticizes state privacy laws as being significantly weakened by the tech industry’s influence, with most states enacting ineffective legislation that fails to protect consumer data adequately or offer meaningful enforcement.

    After over two years of development, the EU’s Artificial Intelligence Act (AI Act) is nearing approval, with the latest text offering a final compromise on high-risk AI systems, General Purpose AI, and governance and enforcement mechanisms; however, critiques note that last-minute concessions may limit its protective potential, especially due to industry lobbying and the possibility of insufficient enforcement resources.

    An investigation into Microsoft’s design practices across Windows 10 and 11, Edge, and Bing reveals the company’s use of harmful design techniques—such as coercive, manipulative, and deceptive patterns—to push users towards using Edge browser, leading to potential consumer, social, and market harms. The report concludes that Microsoft’s practices distort user choice and undermine trust in technology, advocating for the cessation of these practices and regulatory intervention if necessary.

    A Nigerian man has been arrested and charged with various offenses, including child pornography and attempted extortion, following the suicide of a Canadian teen, who fell victim to an online sextortion scheme.

    US police departments are attempting to use facial recognition on 3D models of suspects’ faces generated from DNA evidence, despite concerns from civil liberties groups and experts who argue that this practice is based on unproven science and could lead to wrongful identification, as shown in a controversial case by the East Bay Regional Park District Police Department.

    Bumble has introduced an AI-powered feature called “Deception Detector” to its dating app, designed to identify and block fake profiles, scams, and spam, reducing member reports of such issues by 45% during initial testing and supporting a 95% success rate in blocking undesirable accounts. 

    Events

    The Workshop for Junior Scholars on March 11, 2024, at MIT Stata Center, organized by Aniket Kesari and Sarah Scheffler, aims to build a community and provide guidance for early-career individuals in Law and Computer Science. The half-day event includes panels on academic and non-academic careers, mentoring sessions, and discussions on conducting interdisciplinary research, followed by dinner. Registration is available online. It precedes another conference: ACM Symposium on Computer Science and Law (CSLAW 2024).

    There is an open application for a two-year residential postdoctoral program at Harvard Law School aimed at developing scholars early in their careers who have a primary interest in private law, including common law subjects and statutory areas like intellectual property. Selected from recent graduates, academics, and practitioners, Fellows focus on their research, contribute to the Project on the Foundations of Private Law, mentor students, present and attend workshops, help with events, and engage in blogging.

    (Compiled by Student Fellow Rebecca Kahn)

  • PRG News Roundup, January 31, 2024

    News

    Child access and privacy work are at the forefront of issues being addressed politically. On Wednesday, January 31, five CEOs from major tech companies, including Meta’s CEO Mark Zuckerberg and TikTok’s CEO Shou Zi Chew, testified at a Senate hearing about the protection of children from online sexual exploitation as congressional leaders explore how to tackle these issues.

    Additionally, the California Attorney General Rob Bonta introduced two bills, one privacy and one on social media. “The privacy bill, deemed the proposed Children’s Data Privacy Act, aims to amend the California Consumer Privacy Act to tighten youth coverage. The proposed Protecting Youth from Social Media Addiction Act focuses on measures to moderate content and limit luring features or techniques on social media platforms.”

    23 & Me’s stock price tumbled to the ground as they face a class action filed last week around a data breach specifically impacting Jewish and Chinese customers. 

    Court began to scrutinize using AI chatbots on legal briefings as an attorney Jae Lee “reports that she relied on a generative artificial intelligence tool, ChatGPT, to identify precedent that might support her arguments, and did not read or otherwise confirm the validity of the (non-existent) decision she cited.”

    TikTok continues to struggle in preventing the sharing of data with its Chinese parent company. TikTok is trying to show the U.S. lawmakers that its video sharing application is a safe form of social media through these limits in data sharing.

    OpenAI removed their blanket prohibition on military use of ChatGPT by deleting the text from their usage policy. The blanket ban on “military and welfare” has been removed from the policy but continues the policy on using the tool for “to harm yourself or others” and “develop or use weapons”. 

    Events

    As an organization focused on the intersection of law and artificial intelligence, LunchGPT’s first lunch is planned for Friday February 16 at 12 PM. If you are interested, please reach out to Kevin Fraizer with questions.

    Registration is now open for the 2024 ACM Symposium on Computer Science and Law, which will take place on March 12-13, 2024, at Boston University. The Symposium is a leading venue for cross-disciplinary scholarship at the intersection of computer science and law.

    (Compiled by Student Fellow Molly Pushner)