On July 23, 2025, the White House released America’s AI Action Plan, a comprehensive national strategy designed to strengthen the United States’ position in artificial intelligence through investment in innovation, infrastructure, and international diplomacy and security. The plan, issued in response to Executive Order 14179, reflects a pro-innovation approach to AI policy—one that aims to accelerate adoption while mitigating
Jackson Lewis
Jackson Lewis Blogs
Latest from Jackson Lewis
HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations
Earlier this year, North Dakota’s Governor signed HB 1127, which introduces new compliance obligations for financial corporations operating in North Dakota. This new law will take effect on August 1, 2025.
The law applies to certain “financial corporations.” Under the law, financial corporation means all entities regulated by the Department of Financial Institutions, excluding credit unions, as well as…
Reproductive Health Privacy in Flux: Texas Ruling vs. SCOTUS Limits
A Texas federal court just shook the foundation of HIPAA’s reproductive health privacy protections — but the Supreme Court may have the final word. In a sweeping decision, Judge Matthew Kacsmaryk vacated key provisions of the 2024 Reproductive Health Rule, stripping away national safeguards on disclosing reproductive health information. Yet, a recent SCOTUS ruling in Trump v. CASA, Inc. could rein in the…
The Potential For One Long Moratorium on AI Regulation
The federal budget bill titled One Big Beautiful Bill aims to unharness artificial intelligence (AI) development in the U.S. The current draft of the bill, which has passed the House, proposes a 10-year moratorium on the enforcement of AI-related legislation by states or other entities. Specifically, it restricts the regulation of AI models, systems,…
CCPA Compliance Reminder: Annual Update Requirement for Online Privacy Policies
For businesses subject to the California Consumer Privacy Act (CCPA), a compliance step often overlooked is the requirement to annually update the businesses online privacy policy. Under Cal. Civ. Code § 1798.130(a)(5), CCPA-covered businesses must among other things update their online privacy policies at least once every 12 months. Note that CCPA regulations establish content requirements for online privacy policies,…
Too Hot to Handle: Don’t Get Burned by Cal/OSHA’s Heat Rules
As summer temperatures rise across California, it’s a good time for employers to review their responsibilities under Cal/OSHA’s heat illness prevention standards. These rules apply to both outdoor and indoor workplaces and are designed to protect employees from heat-related illnesses and injury.
The outdoor heat illness prevention standards apply to all outdoor places of employment. For outdoor workplaces, employers must…
Texas Enacts Liability Shield From Punitive Damages for Certain Small Businesses That Adopt Cybersecurity Programs
On June 20, 2025, Texas Governor Greg Abbott signed SB 2610 into law, joining a growing number of states that aim to incentivize sound cybersecurity practices through legislative safe harbors. Modeled on laws in states like Ohio and Utah, the new Texas statute provides that certain businesses that “demonstrate[] that at the time of the breach the entity implemented and…
Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
Montana recently amended its privacy law through Senate Bill 297, effective October 1, 2025, strengthening consumer protections and requiring businesses to revisit their privacy policies that apply to citizens of Montana. Importantly, it lowered the threshold for applicability to persons and businesses who control or process the personal data of 25,000 or more consumers (previously 50,000), unless the controller…
The Growing Cyber Risks from AI — and How Organizations Can Fight Back
Artificial Intelligence (AI) is transforming businesses—automating tasks, powering analytics, and reshaping customer interactions. But like any powerful tool, AI is a double-edged sword. While some adopt AI for protection, attackers are using it to scale and intensify cybercrime. Here’s a high-level discussion at emerging AI-powered cyber risks in 2025—and steps organizations can take to defend.
AI-Generated Phishing & Social Engineering…
Different Country, Same Challenges: Lessons from a Breach That Could Have Been Prevented
A recent breach involving Indian fintech company Kirana Pro serves as a reminder to organizations worldwide: even the most sophisticated cybersecurity technology cannot make up for poor administrative data security hygiene.
According to a June 7 article in India Today, KiranaPro suffered a massive data wipe affecting critical business information and customer data. The company’s CEO believes the incident…