US privacy update: attorneys general pulse, AI, and more

Jonathan Joseph interviews Paul Singer, ex-enforcer with a U.S. State Attorney General Office.

  • AI GovernanceState Privacy LawsFTC Enforcement
  • Episode 23
  • August 16, 2023

Summary

This episode features Jonathan Joseph in conversation with Paul Singer, a former enforcer from a state Attorney General's office and partner at Kelley Drye, examining how state AGs are approaching enforcement of newly effective comprehensive privacy laws. Colorado and Connecticut are the first states under the microscope, and the message from both is consistent: enforcement will focus on clear, willful misconduct — companies that simply fail to provide required opt-out mechanisms or notice — rather than technical or inadvertent violations. A structural dynamic underlies this: state AGs communicate constantly with one another, exchanging priorities and enforcement approaches, which means patterns in one state quickly shape the posture of others. Resource constraints reinforce this prioritization, as every AG office has limited capacity and will direct it toward the most obvious, indefensible violations first. Artificial intelligence dominates the regulatory agenda, with Singer confirming it is at the forefront of every state AG's attention. The enforcement community's concern is not that AI creates wholly new problems, but that it risks amplifying biases already embedded in a company's data and decision-making — making pre-existing issues faster, more widespread, and harder to contain. Regulators are watching both what AI systems produce and what companies say about those systems. Overclaiming bias-free results while the underlying inputs remain biased is precisely the kind of representation that draws scrutiny. Transparency remains the governing principle: as AI adoption spreads, customers must understand that their data may be used in fundamentally different ways than before, and companies that communicate those changes clearly will generally be on sound footing under deceptive trade practice frameworks. Singer's closing advice centers on proactive public-private engagement. Companies adopting new technology should not wait for an investigation — they should approach enforcers early, explain what they are doing, and surface any concerns before they become enforcement targets. AG offices are meeting regularly and dedicating time at every session to AI, drawing on academia, business, and experts to build their understanding quickly. The practical implication is that regulators are learning fast, and organizations that engage transparently and early will be far better positioned than those that wait and react.

Transcript

**Jonathan:** Hey, Paul. How are you? Good to see you. **Paul:** Great. How are you doing, JJ? **Jonathan:** Good. Thanks. Hey, I really appreciate you doing this. I'm so excited about this. I know you've been an ex-enforcer. You've been in AG's office for twenty-plus years. One of the things that always gets traction for us and we just see a ton of interest on is what are the regulators thinking? What's next for them? How do they think about some of these issues we're approaching in privacy? So I appreciate the time today to talk about it. **Paul:** Absolutely. Look forward to our discussion. **Jonathan:** Yeah, awesome. Well, let's get started. How about we start with some specific AG offices, Colorado and Connecticut, given that they're so close to implementation? What's some of the inside baseball there? **Paul:** Yeah, I think it's great to start with them. Obviously, I think there's a lot of attention to those two states given their recent effective dates of their comprehensive state privacy laws. And frankly, they are two states that historically have been very active in the privacy space and have made it abundantly clear to the public that they intend to vigorously enforce their new laws. And so, you know, I think there's just inherently going to be a lot of focus on those states. You know, we recently had the great opportunity to talk to AG Weiser and sort of understand a little bit more about his priorities. And I think consistent with what we've heard out of Colorado since they went through the rulemaking process is largely, you know, they wanna look for obvious intentional misconduct, low hanging fruit, those kinds of violators, as opposed to perhaps the technical violations that may have been unintentional. I think they very much want to engage the business community and as they roll out their new law, really develop more of a dialogue for those types of entities to ensure compliance, but maybe not pick on people for technical violations. And, you know, AG Weiser has been very clear on that point for many months and sort of reiterated that since the effective date of their law. Connecticut, interestingly, I think is very similar despite not having a rulemaking process and quite as public an opportunity to engage with that office. I think they're looking at things very much the same way as Colorado, and it's important to remember that, one, states talk all the time, so the privacy players in this space are constantly in communication with one another. So they're taking reads and feeds off of each other as to exactly how they should implement these new laws. And two, every state AG office has limited resources and limited capacity to pursue these countless enforcement opportunities that come their way. And so I think you can expect that they're going to be looking for those that are clear, extreme, intentional violations to prioritize over more of the incidental issues as they come up. **Jonathan:** Yeah, Paul, actually remember that from the last time we talked, this idea of the state AGs, they talk, man, they call each other, they exchange ideas. Like sometimes we're operating in silos. **Paul:** Exactly, and I mean, this space in particular has historically been one where the AGs collaborate, and it makes sense because this is a space where it is constantly evolving, highly complicated. You know, there are such nuances to every state law as they're getting passed that without that kind of coordination, I think the AGs recognize that that would create chaos for the business community as well. And so it's in everybody's interest for those dialogues to occur. Frankly, I think there's opportunity to benefit and learn from one another that way. **Jonathan:** Gotcha. No, absolutely. So I wanted to ask you, what's a good example of the low hanging fruit here? Like the willful, intentional kind of flaunting of the laws? Is it the kind of stuff we see out of the FTC, BetterHelp and others? Is it that kind of stuff? **Paul:** I would expect that you're going to see just more blatant things where companies are simply just not providing users with opt-out possibilities, right? I mean like things that are just so glaringly on their face as you look at a company's data collection practices and that if they're not providing consumers notice and opt-out opportunities that are required by the law, I mean, are gonna immediately raise the kind of initial red flags. And remember, we're talking in the short term. This is where I think as these states gear up and ramp up enforcement, they're going to be focused on things that are that simple and that direct, where there's no real debate or question that you're violating the law. You either were intentionally engaging in that kind of misconduct or you were being willfully ignorant of the obligations that are imposed on you. **Jonathan:** Right. I don't know if there's a precedent for this in other industries, but for privacy as an example, it's so easy to check. Right? On your website, you weren't doing — **Paul:** Well, it is and it isn't, I guess you could say because, right, I think you could say that one, it's easy to check something like that if you provide the mechanism. Not so easy to know whether or not they're actually honoring your choice. Those are sort of two threshold questions, and that's why I sort of focus on the first one because you're right, that is super easy for someone as an enforcer to go in, review the practices of different companies and make that determination. It's not gonna be as easy for them to know what happens after you make that choice. And that's where I think they're gonna have to ramp up, engage with more of a dialogue with others, and frankly, rely on consumers and others coming forward to report what they're seeing in the marketplace. **Jonathan:** Yeah. What else? Generally, are there areas that the regulators are focused on? **Paul:** I mean, will not be a shock, but I will say AI is at the forefront of every state AG's mind right now. **Jonathan:** I just feel like no one's talking about AI. **Paul:** I know. I know. It's like everybody's just — yeah. I mean, it's funny because I feel like there's so much discussion happening publicly about how the technology is going to be implemented. You've seen sort of like the agreements that big tech have put in place with the White House on these general principles of ensuring there are some boundaries around responsible use of AI. I think what we've heard from the AG community is a little bit more granular and focused on some inherent issues that they have with the adoption of AI more broadly, and I think one of the key ones is ensuring that AI is used in a way that, to the best extent possible, it is bias free, and that the outputs that are generated from the use of AI are consistent with the kind of promises and representations that companies are making to their customers. And those are a little more complicated questions and issues because they fundamentally stem from the types of inputs that go into the various models themselves, and then how those models are then using those inputs and what kind of results they're producing at the end, right? And that, I think, takes a little bit more in-depth discussion and opportunity for them to learn about the technology to really understand what kinds of issues may present in the space. **Jonathan:** So there's a lot to unpack there, Paul. One of the things I've been wondering about is, let's just say it is a hypothetical company, and there's some bias there in how they make their decisions, not on purpose. It just happens that way. And then now you have AI on top of that. Are the regulators saying, hey, AI is our opportunity to fix that bias that you had already and maybe didn't even know about? Like, is that what we're doing here? Because it's not — AI is just working on the data you have if it's already biased. How do you help us think about that? **Paul:** Yeah. I mean, think from the enforcer's perspective, the concern is the opposite, right? The concern is that the AI is gonna somehow exacerbate the underlying issue that existed in the first place, right? And so if you already have bias in how you are dealing with your customers or in offering them different products or services, and then you're enhancing that bias through the use of AI. Again, to your point, JJ, it's not the technology that's creating it. It's the input that's creating it. It's the technology that may make it faster, more widespread, and become even more problematic to the enforcer. And so I think from their perspective, yeah, we recognize that they are trying to address problems that may already exist, but they may not really surface as critical issues until you're using technology that exacerbates it in this way. **Jonathan:** Got you. And then you made a point about representation. Also, don't say it's unbiased, right? If indeed there's a chance that it is, but also go back — I mean, it is a chance to go back and fix it. **Paul:** Absolutely. I mean, it should be an opportunity for everyone to take a pause and think about — you know, it's really outside the realm of AI. It's just how is any automated decision making happening within your company, and are there ways that it could be attacked both for what it's doing, like what kind of output it's generating, but also to your point, what are you saying about it to your customers? And, you know, that's really another key piece — as AI becomes adopted by more businesses and spread out more in the normal business community, I think making sure that customers understand that this technology is being adopted and being used, and now information related to you might be used in a whole different way to a whole different degree than you thought it was before. Again, the use of the data may not be problematic, but making sure you're transparent with your customers about how you're going to use that data has always been key to the regulator community, and I think this is just going to be another example of that. **Jonathan:** Yeah, it's funny, right? It's like AI hasn't necessarily changed a whole lot in terms of principles. When we heard Vudoya and others at the IAPP conference, it was transparency and accountability. In a lot of ways that hasn't changed. And it reminds me, Paul, I read a recent article where Google was saying, if your data is public, we can use it in our models. And it got me thinking, well, what if it's sensitive and personal and public? Are we carving it out? How do we think about that? What are we doing there? **Paul:** Like, what's — how do you think? I mean, it's tough. Right? Because, again, I think this is where transparency is key because users may not fully understand how public some of their data is. And that is where it becomes crucial, especially as you're adopting new technology to utilize that data, to make sure that they fully understand that, right? That, you know, not only is this data public, but it's data that may get used by some of these AI models that can start generating automated results and responses to you that are maybe different than what your initial expectations are. And so from an enforcer standpoint, I mean, frankly, I don't see this as very different than any new technology that rolls out. You have to take a pause and you have to think about what are your customers' expectations as they exist today, and how are those expectations going to change once this new technology is rolled out to them? And so if you are being transparent and clear — these are the differences — then you should generally be okay under a general deceptive trade practice theory. That's really the key, is making sure your customer base fully understands what's happening, how it affects them, what you're gonna do with that data, those kind of key crucial questions that you'd expect customers to ask. **Jonathan:** If we have time for a final question, how do the regulators stay on top of fast-changing technology? When I saw the FTC's little article on the hidden costs of pixel tracking, I thought, these guys get it. They're spot on or super technical. How do they do that in the context of AI? How did you do it when you were working for a — I mean, one, you depend on those private-public partnerships to help educate the enforcement community. **Paul:** That is so crucial, and it's something we tell clients all the time, is don't be afraid of an enforcer or regulator, quite the opposite. You should be proactively engaging them because as you're entering a new space and adopting new technology, you wanna make sure the enforcers are right there with you and understand what you're doing, how you're doing it, because if they have any questions or concerns, it's better to hear that on the front end than to wait until you're now the subject of an investigation, right? So I really strongly encourage that kind of public-private partnership. The other thing is that, you know, especially in the AG space, the AGs are meeting and talking all the time about these issues. That's what I was saying before about AI generally. The AGs meet on a very regular basis, and every single meeting in the last several months has had some panel or some open discussion about the adoption of AI, what it means to their constituents, and what kinds of things they as enforcers should be looking at. And so they're hearing from academia, they're hearing from experts, they're hearing from the business community in these forums that I think are really helping to shape their understanding. **Jonathan:** Well, I've a million questions, man, but we're just scratching the surface here. I really appreciate it. Hopefully, we get a chance to do this again. I want to ask you about how to balance innovation and regulation and all sorts of things, but I appreciate this little insight view, Paul. Thanks. **Paul:** Oh, absolutely. And happy to do it anytime. And it's a fun discussion and a great area to continue the dialogue.

Next step

See permissioning infrastructure in action

Walk through the platform with a Ketch architect, or launch the free CMP today.

Get Started Free

Get started in less than 5 min