In the summer of 2018,
]]>In the summer of 2018, California learned what happens when no one can hold internet providers accountable.
As the Mendocino Complex Fire, then the largest wildfire in California history, tore across the north of the state, Santa Clara County firefighters were called in to help. They relied on a mobile internet connection to coordinate the thousands of personnel and vehicles racing to contain the fire. In the middle of that emergency, Verizon throttled their connection down to an unusable trickle. Despite the firefighters' pleas, Verizon refused to restore full service unless they upgraded to a more expensive plan, forcing crews to fall back on personal phones to keep their systems running during a disaster.
California responded. In 2019, the legislature passed a law, enforced by the California Public Utilities Commission (CPUC), that prohibits mobile providers from throttling first responders during emergencies. It's part of a broader set of protections, including rules requiring providers to keep people connected during disasters.
Those protections exist for a reason: left to their own devices, internet providers have put profits over public safety before.
California is now being asked to sign away those protections for fourteen years.
In 2021, Congress created the Broadband Equity, Access, and Deployment (BEAD) program, a roughly $42 billion federal program to bring high-speed internet to places that still don't have it.
In July, the National Telecommunications and Information Administration (NTIA), the federal agency that distributes BEAD money, approved California's BEAD deployment plan. On August 31, it issued the award: $1.42 billion to connect about 270,000 homes and businesses.
Buried in the award's terms and conditions is a clause known as Condition 50. By signing the award, California would agree not to enforce its affordability, net neutrality, and public-safety protections against any internet service provider (ISP) that receives BEAD money.
It would be handcuffing itself for the next fourteen years.
Condition 50 isn't limited to the locations BEAD pays to connect. It covers any broadband service these ISPs offer anywhere in California, including their wireless services.
On top of that, California would have to write the same promise into its contract with every funded provider, handing each one its own contractual right to block enforcement.
Roughly 69% of California's BEAD funding flows to five large, national providers: Comcast ($400 million), AT&T ($331 million), Verizon/Frontier ($173 million), Amazon's Kuiper satellite service ($55 million), and SpaceX's Starlink ($22 million).
If California accepts the funding, three of the four major home-internet providers, two of the three major wireless carriers, and both major satellite providers would be shielded from enforcement of California’s consumer and public safety protections for the next fourteen years.
Condition 50 doesn't just block enforcement of today's rules. If California’s legislators or the CPUC added new disaster rules or affordability requirements, they couldn't enforce them against California's biggest broadband providers for well over a decade.
The grant goes to the State of California, and Condition 50 would bind the state itself, so the decision to accept it rests with Governor Newsom. The CPUC administers the BEAD program on the state's behalf. On September 17, the CPUC is scheduled to take a procedural vote ratifying the deployment plan NTIA approved in July.
But whether to accept the award on those terms or challenge Condition 50 in court is the governor's decision to make.
The firefighter law is just one of the protections at stake. Condition 50 covers three kinds California has built up over years: affordability, net neutrality, and public safety.
The affordability stakes alone are enormous.
When the CPUC approved Verizon’s acquisition of Frontier in January, it required the merged company to offer a $20-a-month plan to low-income Californians. An estimated 5.8 million households qualify, and eligible customers save up to $30 a month. Under Condition 50, California could no longer enforce that requirement, because Verizon is among the providers Condition 50 covers.
Net neutrality is the principle that your internet provider shouldn't get to pick winners and losers online: it can't block or slow the apps and sites you choose, or charge them for a faster lane to reach you. After the FCC repealed the federal net neutrality protections in 2017, California passed its own net neutrality law, which is widely regarded as the strongest in the country. The law showed its force as soon as it became enforceable: AT&T and Verizon promptly stopped exempting their own video apps from customers' data caps, a practice that had tilted the field against competitors.
That is how these protections mostly work. The credible threat of enforcement keeps providers in line without a regulator ever having to act. Condition 50 would remove that threat for fourteen years.
Public safety is the third protection at risk, and the need for it is growing. As climate change makes wildfires and other disasters more frequent, wireless networks have become a lifeline: for evacuation orders, for families trying to reach one another, for first responders like the Santa Clara crews. Whether those networks hold up when lives depend on them shouldn't be left to a internet provider's discretion.
The broadband market is consolidating quickly. Fewer providers mean fewer checks on prices and bad behavior, exactly when strong state protections matter most.
Federal protections won't fill the void. The federal Affordable Connectivity Program, which gave qualifying households $30 a month toward their broadband bills, ran out of money and ended in June 2024; roughly half of the 5.8 million eligible California households had signed up. Efforts in Congress to revive it have failed.
Meanwhile, the FCC's 2024 net neutrality rules were struck down by a federal court in January 2025, and the agency has neither the authority nor the will to police internet providers.
If California steps back, no one steps in.
Condition 50 is the result of a years-long campaign to escape California’s protections by the large phone and cable companies who are now getting BEAD funding.
Internet providers have been fighting California's net neutrality law for years, without success. They spent six million dollars lobbying the legislature to kill the law and even paid for robocalls falsely warning seniors that it would raise their phone bills. When they asked the courts to strike down the law, they lost three times: first at the district court, then at the federal court of appeals, and a third time when the full appeals court refused to rehear the case, with not a single judge voting to take it up.
Having lost in the Capitol and in court, the providers found another route: allies in the federal government willing to use broadband money as leverage to force California to give up these kinds of protections.
It's already working. In July 2025, a California lawmaker shelved a bill that would have required a $15 broadband plan for low-income households after federal officials warned it could cost the state its BEAD funding.
For the large phone and cable companies, Condition 50 is the prize: hundreds of millions of dollars, and fourteen years of freedom from the rules they couldn't defeat any other way.
About half of all eligible California households were enrolled in the federal Affordable Connectivity Program when it ended. If just one in five of these eligible households, or 20%, signed up for the Verizon/Frontier $20-a-month broadband plan (a deliberately conservative estimate), it would save low-income Californians roughly $4.2 billion over ten years. That's nearly three times the entire $1.42 billion in BEAD funding California would be accepting.
And that’s only the savings from a single plan.
California would be trading away billions in savings for its most vulnerable residents, plus its power to protect people during disasters and rein in ISP misbehavior, for a check worth a fraction of what it's giving up.
It’s a bad deal, and California should reject it.
California doesn't have to choose between connecting families and protecting them. California doesn’t have to reject the money to protect its laws; it can challenge Condition 50 in court and strip the condition from the grant.
A challenge would rest on solid legal ground.
Congress designed BEAD to get broadband built while making sure the providers who take the money follow the law: the statute directs states to ensure that funded providers can carry out their work “in compliance with all applicable Federal, State, and local laws,” while Condition 50 demands the opposite: that California promise not to enforce its own laws.
A federal agency can't use fine print in a grant to override what Congress wrote into the statute.
If California wins, it gets the full $1.42 billion without the condition, and can connect the 270,000 households without giving up its power to protect all Californians.
But timing is everything: California has to challenge the condition before it accepts the award.
Once the state signs, two things change: challenging Condition 50 becomes a lot harder. And enforcing any of the affected protections could prompt NTIA to cut off the BEAD money that hasn't yet been paid out.
The result: California would still have its protections on the books, but no regulator or attorney general would risk the state's broadband funding to enforce just one of them.
The CPUC's September 17 vote will draw attention, but by the CPUC's own account it merely ratifies California's plan; it doesn't accept Condition 50.
The decision that matters – whether to sign the agreement – is separate, and still ahead.
There's no need to rush it. Under BEAD's own rules, California has until the end of September to decide, and it can request another 30 days after that.
A fourteen-year commitment that trades away billions in savings and California's power to protect people in emergencies is not a decision to make against a self-imposed clock.
At a minimum, Governor Newsom should take the time the BEAD rules allow. Better still, he should refuse to sign away California's net neutrality, affordability, and public-safety protections and go to court to get the money the way Congress intended: with every state protection intact.
Professor Barbara van Schewick is a professor of law at Stanford University and the director of Stanford Law School’s Center for Internet and Society.
]]>I submitted a comment to the California State Bar's Standing Committee on Professional Responsibility and Conduct (COPRAC) on its proposed amendments to the attorney ethics rules related to AI. Given the growing epidemic of attorneys submitting AI-tainted filings in court (which I
]]>I submitted a comment to the California State Bar's Standing Committee on Professional Responsibility and Conduct (COPRAC) on its proposed amendments to the attorney ethics rules related to AI. Given the growing epidemic of attorneys submitting AI-tainted filings in court (which I wrote about here last fall), the proposed amendments would require attorneys (as part of the duty of competence) to stay abreast of the benefits and risks associated with AI, and would make clear (as part of the duty of candor) that attorneys have "the obligation to verify the accuracy and existence of cited authorities, including ensuring no cited authority is fabricated, misstated, or taken out of context, before submission to a tribunal, including any cited authorities generated or assisted by artificial intelligence or other technological tools." In my comments, I say that this is a good start, but that the duties of competence and candor should also address the potential for attorneys to be fooled by deepfakes and unwittingly offer them as evidence (or fail to challenge them when the other side tries to introduce them into evidence), a topic I first started writing about nearly seven years ago.
]]>Studies show the immense growth of AI. According to Stanford’s HAI, private investment in the AI sector has increased thirteenfold since 2014. Respondents indicating use of generative AI in at least one business function more than doubled – from 33% in 2023 to 71% in 2024. Microsoft indicates more than 80% of Fortune 500 companies are using AI agents or bots.
In non-AI contexts, prominent legal thinkers argue that regulatory certainty – otherwise known as the rule of law – is essential for capital market health. Without this, the rules of the road are uncertain, which is more likely to lead to unstable economic growth, as related by the Atlantic Council.
The same is true for AI applications. The difference is that AI can grow much faster, making the legal blanket even less relevant from yesterday’s application. From ownership to AI creations to the use of scraped info to train, numerous legal issues have arisen in recent years. Some of them have been decided in the U.S. Copyright ownership of AI creations is one indirectly decided by the U.S. Supreme Court. Other issues remain. Whether bot scraping is fair use is still not decided by the Court, although a lower federal court has decided the issue. Even though some important legal issues have been decided within the U.S., there can remain disagreement between jurisdictions.
This is just regulatory consistency. The other issue that remains is bandwidth of enforcement arms to handle the numerous civil and criminal issues that are implicated by AI use. It’s known in some circles as the “pacing problem.” These will, in all likelihood, arise with increased access to AI tools that can be used, to, among other things, create deep fakes to trick various stakeholders. In the pre-digital era, the courts had to deal with a phone spammer in Kansas. Now, the spammers are virtual and are often hard to identify.
For some, the inability of the law to keep up with AI proliferation is a good thing as there is no “regulatory capture.” Whereas for others, this means there are open holes in the regulatory tapestry that will lead to a weathering away of the rule of law. This can eventually decrease the size of the ballooning AI expansion.
]]>Below is the first portion of my testimony. It reviews the under-recognized value that I believe Section 230 is providing today, and argues that this value is easily recognized by comparison to non-Section-230 legal regimes including U.S. copyright law.
Thank you for the opportunity to appear at this hearing and discuss the legal backbone of today’s online speech environment: the law known as Section 230. [fn 1] Section 230 is widely maligned. But we should be realistic about the significant value it provides, and the harms that we would almost certainly face without it.
I speak today based on twenty-five years of experience in platform regulation as both a practicing lawyer and a legal scholar. For ten years, I experienced the impact of platform laws firsthand as counsel for Google, including as legal lead for web search. For another ten years at Stanford, I have studied and written about the practical and policy alternatives to Section 230 — including laws proposed or enacted around the world and here in the United States. Based on this experience, my take on Section 230 is much like Winston Churchill’s take on democracy:
Many forms of Government have been tried, and will be tried in this world of sin and woe. No one pretends that democracy is perfect or all-wise. Indeed it has been said that democracy is the worst form of Government except for all those other forms that have been tried from time to time[.]
Churchill was addressing the UK Parliament in 1947, with the horrors of World War II and the Holocaust fresh in memory. He did not speak lightly of sin, woe, or the imperfection of human governance. We should not speak lightly of the very real dangers in the world today, or of the Internet’s role in facilitating them. But Section 230, despite its flaws, has proven its value in achieving the very goals that will be discussed in this hearing. Experience here and in other countries illustrates the foreseeable damage threatened by many alternatives to Section 230.
Congress could repeal or amend Section 230, but two major things would not change. First, the U.S. Constitution protects the vast majority of the hate speech, disinformation, and other offensive or dangerous “lawful but awful” speech online. Lawmakers cannot tell platforms to remove online speech if they have no constitutional power to restrain that speech in the first place. The idea that eliminating Section 230 would make platforms liable for users’ constitutionally protected speech is simply false.
Congress could write a law to punish platforms for carrying defamation, fraud, obscenity, or other truly unlawful speech. But if laws like that go too far in incentivizing intermediaries to suppress legal expression, they can also violate the First Amendment. This is the lesson of Smith v. California, a 1959 Supreme Court case. The law at issue in that case imposed liability only bookstores — but, the Court noted, a “bookseller’s self-censorship, compelled by the State, would be a censorship affecting the whole public, hardly less virulent for being privately administered.” The whole public is affected by today’s platform regulations, too. Those laws must respect ordinary Internet users’ rights to receive and comment on news, share text messages and family vacation photos, read restaurant reviews on Yelp, and post book reviews on Amazon.
The second constraint on lawmakers’ options is practical. Well-intended regulations will succeed or fail based on what platforms and users actually do in response to changed legal rules. A law that aims to prevent violence but in fact incentivizes major platforms to prohibit all discussion of world events or politics is not a success — particularly if the same speakers simply migrate to other platforms and foment even more violence. Neither is a law that aims to protect political speech but in practice would turn every platform into an identical, unrestricted cacophony.
In the remainder of my testimony, I will discuss the important work that Section 230 is doing today, and question the likelihood that alternative proposals would yield better results. I will also distinguish viable approaches to regulating platforms’ “design” from approaches that are constitutionally suspect.
Every platform speech regulation, including Section 230, represents a prediction — and a gamble — about the real-world behavior of platforms and Internet users. Section 230’s prediction was based on what is now known as the “moderator’s dilemma.” Its drafters were motivated by two court rulings. Together, the rulings told nascent Internet platforms that attempting to moderate content would put them in an editorial role, with legal responsibility for users’ unlawful speech — but that they could avoid this risk by refusing to intervene, and tolerating all manner of unlawful or harmful posts. Section 230 was designed to avoid the resulting perverse incentives. It sought to encourage platforms to create and enforce editorial policies, and protect them from the very real risk that doing so would lead to liability.
Americans need not look far for evidence that Section 230’s prediction was correct. The law has produced an ecosystem of small, medium, and large platforms that can all afford to exist, and to adopt diverse approaches to content moderation, because they can't easily be sued out of existence. Comparing claims that are not immunized by Section 230 — federal crimes, intellectual property, trafficking, and prostitution — as well as foreign laws tells us a lot about the benefits Section 230 provides today.
The experience of the video hosting platform Vimeo illustrates the moderator’s dilemma in action. Vimeo employed content moderators in an effort to weed out both illegal uploaded content, such as obscenity, and content that violated the platform’s own rules, such as hate speech. That choice to moderate is precisely what Section 230 encourages. But because copyright law does not offer the same immunity, Vimeo was drawn into litigation for well over a decade about whether those moderators might have seen and recognized, but failed to remove, copyright-infringing content.
Vimeo has to date prevailed in court and survived the expense of litigation. Another smaller platform, Veoh, provides a more sobering example. Veoh and YouTube offered very similar services, and were sued on very similar copyright claims. Both ultimately won their cases, on nearly identical grounds. But being legally in the right was not enough to save Veoh. It went bankrupt in the process. YouTube, by contrast, was able to weather over $100 million in legal fees, and remains a behemoth today. Protection from devastating litigation costs, which accrue even in meritless lawsuits, is one of the most important benefits of Section 230. [fn 2]
Without Section 230, most platforms would have two safe courses to avoid liability for claims like defamation. They could moderate so thoroughly that only the blandest and least controversial material remains; or they could avoid moderation entirely and leave users to face the resulting glut of scams, pornography, dangerous diet advice, advocacy of violence, and more. This would not be an overall safer or better Internet than the one we have now.
Abundant evidence shows that under the “notice and takedown” systems established by many non-230 platform liability laws, platforms’ safest, cheapest, and easiest course is simply to honor every claim. This makes users’ online expression vulnerable to a “heckler’s veto,” and gives individuals, companies, and governments an avenue to silence speech simply by complaining about it.
Even under the U.S. Digital Millennium Copyright Act — a law that attempts to protect speakers by allowing for appeals, reinstatement of lawful content, and penalties against bad faith takedown demands — improper claims are extremely common, and far too often successful. Governments have used takedown demands to silence critical journalism and suppress video evidence of police brutality. Businesses have used them to target competitors. Activists and discredited scientists have used them to suppress inconvenient truths. Improper takedown claims are even more common under Europe’s Right to Be Forgotten laws. Among claims targeting 7.8 million webpages for removal from search results, Google reports that nearly half were legally invalid.
In theory, platforms should feel free to ignore complaints that target speech protected by the First Amendment. In practice, this is a pipe dream. Fighting is expensive, and platforms have little motivation to do it. They also often simply lack the information to know whether content is actually illegal. For example, they cannot know, and have little motivation to find out, whether allegedly defamatory news reporting about local political corruption is true or false. Even if platforms do have all the facts, the legality of speech often depends on complex doctrines like copyright fair use, or on nuanced, jurisdiction-specific precedent about who counts as a public figure in defamation cases. Litigating in the face of such uncertainty would be daunting even for more dedicated defenders of speech.
That mix of bad platform incentives and legal uncertainty would define a world without Section 230. In such a world, we should expect platforms to regularly yield to takedown demands regardless of their merits. When platforms are forced to litigate, we should not expect a clear body of rules to emerge. There are simply too many varying legal questions to resolve. Even beyond the First Amendment issues, every state offers its own wide variety of tort claims, and every platform presents slightly or significantly different facts against which those claims may be tested. The room for plaintiffs to argue that a new case is not governed by precedent would be vast.
Section 230 helps platforms resist improper pressure from the government, too. Without it, state and federal officials could credibly threaten retaliation through, for example, targeted use of agencies’ civil enforcement powers. Recent incidents in which broadcasters have yielded to what Chairman Cruz called “mafioso” tactics from FCC Chairman Brendan Carr illustrate the problem. Chairman Carr’s threats temporarily drove comedian Jimmy Kimmel off the air. When CBS declined to air Steven Colbert’s interview with Senate candidate James Talarico, the interview remained available on a Section-230-immunized platform, YouTube. The same dynamic could just as well arise with a liberal regulator and a conservative comedian or politician. As I tell my students, protecting lawful but unpopular speech from government “jawboning” is not a partisan issue. Everyone has reason to fear state power over their speech, whether under a current administration or a future one. History suggests that those who are societally marginalized or politically powerless are the likeliest victims of such abuse. It also suggests that when incumbents with close ties to and dependencies on government become too accommodating, it is the independent players who may show more spine. Section 230 is critical in allowing them to do so.
A persistent myth in policy discussions holds that Section 230 only protects the biggest platforms. Nothing could be farther from the truth. Today’s incumbents would survive the turbulence and uncertainty of a world without immunities. Their smaller competitors, like Veoh, very likely would not. This is the real backdrop when large incumbents “come to the table” and embrace changes to immunity. They are signaling that they can live with the consequences. If lawmakers want the Internet to evolve past its current state — if they want to constrain the power of today’s tech giants — the law must enable new and niche competitors to thrive.
Real-world defendants in Section 230 cases include newspapers, universities, libraries, employers, bloggers, and providers of spam protection and anti-fraud tools. They also include Internet infrastructure providers like domain name registrars. For the many smaller companies and non-profits the law protects, litigation costs remain daunting even with Section 230 in place. For early-stage startups, with a reported average $55,000 per month to cover all expenses, they may simply be insupportable. Section 230 gives the next generation of competitors a fighting chance against today’s giants.
[1] As Blake Reid explains, the law is technically Section 230 of the Communications Act of 1934.
[2] One study found that in 28% of cases in which platforms raised Section 230 defenses, courts found plaintiffs’ claims invalid and resolved the cases without needing to consider Section 230. Courts relied on Section 230 as the primary basis for ruling in only 42% of cases.
]]>On March 31, I gave a virtual guest lecture in Mailyn Fidler’s course “The Digital Fourth Amendment” at Harvard Law School. Prof. Fidler invited me to come talk about warrants to AI companies after she read my October 2025 blog post about a warrant issued to
]]>On March 31, I gave a virtual guest lecture in Mailyn Fidler’s course “The Digital Fourth Amendment” at Harvard Law School. Prof. Fidler invited me to come talk about warrants to AI companies after she read my October 2025 blog post about a warrant issued to OpenAI. As a sort of follow-up to that blog post, I’ve reproduced a portion of my lecture below (with some tweaks to better fit the blog post format).
AI models are used by hundreds of millions of people every day. They have replaced traditional search engines for many users, in addition to becoming companions that some people get very emotionally attached to. The larger the context window for a particular model – the more it can “remember” – the more useful it is to the user… and the more comprehensive the log the AI company is storing about someone’s life, creating a treasure trove for law enforcement. How should we think about AI chatbots and their providers for purposes of digital privacy law?
The SCA Requires a Warrant for AI Users’ Prompts and Models’ Responses
Georgetown Law professor Paul Ohm recently published a paper for Lawfare about the problems posed by reverse searches. In it, he notes that keyword searches and geofence warrants are the two main types of reverse searches right now, but that the list is likely to expand to include AI chatbots, given their popularity and the “gold mine of evidence” they contain about users. Ohm’s argument is that reverse searches probably aren’t authorized under the Stored Communications Act (SCA) and also likely violate the Fourth Amendment – a question on which the Supreme Court will very soon hear oral argument in a case called Chatrie.
Another Lawfare paper on the SCA, published the same day as Ohm’s, goes a bit further in discussing AI chatbots. Digital surveillance experts Rick Salgado and Stephanie Pell delve into the legislative history of the Electronic Communications Privacy Act (ECPA, of which the SCA is a part) to support their argument that “a search query or prompt to be processed by an AI service for text or image generation” qualifies as “contents of an electronic communication” for SCA purposes, “even if there is no second party or communicant .… The term does not require the involvement of some ‘other’ from whom it is sent or to whom it is conveyed.” Legislative history is also invoked to argue that AI companies should count as, at minimum, RCS providers (as other commentators have argued). Implicitly, I believe they’re arguing that AI companies count as ECS providers too.
To Salgado and Pell’s argument, I will add that there have been numerous ECPA cases involving transmissions between a user and a first-party server – also known as “visiting a website.” Your browser sends info to a server, the server sends data back; it’s a computer, not a human, on the other end of the transmission. For over 20 years, the courts have had zero trouble understanding those transmissions to be “electronic communications.” What counts as “content” has proved more divisive, but things like search queries users type into a search engine, or information users enter into a form provided by a website, have qualified as “contents.” Therefore, if you’re a user interacting with an AI chatbot on your phone or your laptop, those interactions seem very clearly to be “contents of electronic communications.” (Not just the user prompts; the AI’s response to a prompt, which may be text, an image, a video, or a combination thereof, is also straightforwardly “information concerning the substance, purport, or meaning of” an “electronic communication.”)
So: For SCA purposes, AI model prompts and responses are “contents of electronic communications,” and AI companies count as ECS and/or RCS providers.
The Federal Government Seems to Think So, Too
Does the federal government agree? Looking at the warrant to OpenAI that I wrote about last fall, I think it does. In the affidavit filed in support of the search warrant application, paragraph 4 says: “This Court has jurisdiction to issue the requested warrant because it is “a court of competent jurisdiction” as defined by 18 U.S.C. § 2711. See 18 U.S.C. §§ 2703(a), (b)(1)(A), & (c)(1)(A).”
Those citations are to the SCA: Section 2711 is the SCA’s definitions section; section 2703 deals with compelled disclosures to law enforcement of customer communications (both content and non-content information). 2703(a) is about “contents of wire or electronic communications in electronic storage”; 2703(b) is about “contents of wire or electronic communications in a remote computing service”; 2703(c) is about “records concerning [an] electronic communications service or remote computing service.”
These citations indicate to us that the government – or at least, the Special Agent with Homeland Security Investigations (HSI) making this affidavit – thinks of OpenAI as being subject to the SCA, and that the government thinks ChatGPT’s prompts and responses are contents of electronic communications in electronic storage. However, the affidavit is kind of cagey about whether the government considers OpenAI to be an ECS provider or an RCS provider; the affidavit simply tosses off a string citation to Section 2703(a), (b), and (c) all in a row. At minimum, the government seems to think OpenAI counts as either one or the other, and possibly both. (The distinction has long been critiqued as unworkable in the modern Internet age.)
That said, maybe I’m reading way too much into this language. It is entirely possible that the affiant just took his usual warrant affidavit template for stored communications (e.g., emails, cloud storage files) and copy-pasted the language into the OpenAI warrant application, without thinking about it too much. It’s also possible that, sitting in a field office up in Portland, Maine, the HSI agent here didn’t consult with any D.C.-based higher-ups. Agency leadership typically likes to have a say in whether to try out a novel type of legal process for electronic surveillance — such as a reverse prompt warrant to an AI company under the SCA. Perhaps boilerplate language in one paragraph of a warrant affidavit is too thin a reed to bear the weight I’m giving it.
Still, whatever the backstory, on the face of it this OpenAI warrant was sought under the SCA. Absent any other contextual information, we may as well treat that as a concession by the federal government that the SCA applies to AI companies, and that means “get a warrant.”
The latter conclusion is further bolstered by the fact that another part of the federal government, the Federal Bureau of Investigation (FBI), was recently revealed to have served a warrant to xAI and thereby gotten a suspect’s prompts to xAI’s Grok AI tool. (This was not a reverse warrant; unlike in the OpenAI case, the suspect’s identity was already known, so the FBI could specify whose account they wanted.) The warrant to xAI is sealed, so we don’t know what authority (i.e., the SCA) it invoked. Nevertheless, it is another indication that federal government policy when seeking AI user data is to get a warrant.
AI Companies Do, and Should, Stand Up for Users’ Privacy
Of course, they had little choice, really. OpenAI’s policy for government requests for user data says, “OpenAI US … only discloses requested user content to a law enforcement request in response to a valid warrant or equivalent.” That’s a standard requirement for tech companies to impose on government demands post-Warshak. (xAI’s policy is more ambiguous, requiring “appropriate legal process such as a subpoena, court order, or warrant.”)
It is important and meaningful that OpenAI has staked out this “get a warrant” position from the get-go, while the number of government demands for user data that it receives still remains shockingly minuscule for a company that counts more than one-tenth of the Earth’s population as weekly active users. As Harvard Law now-3L Jackie O’Neil wrote in her 2025 essay about geofence warrants (before the Supreme Court’s grant of cert in the Chatrie case on that topic):
While courts wrestle with options for sophisticated legal regulation of [reverse warrants], innovation outside of the criminal procedure context may be a stopgap. Technology companies wield ultimate control over [reverse] warrants’ efficacy. … Without means to compel … private companies to retain or organize their data, law enforcement agencies are at the mercy of large private companies with respect to [reverse warrants].
Put simply, AI companies already have a big role to play in protecting users’ digital privacy. AI tools like ChatGPT have become runaway successes with gargantuan user bases, long before the courts have had an opportunity to apply the niceties of ECPA definitions to them and the data they have about their users. Deciding in advance to demand a warrant for the troves of personal data they hold, and then communicating that policy to law enforcement and the public, is a way of setting norms and expectations, ensuring internal practice consistency, gaining public trust, and (hopefully) preempting government attempts at shenanigans.
Protecting User Privacy Means Saying “No” to Overbroad Reverse Prompt Warrants
What remains to be seen is whether OpenAI (and its brethren) will push back if and when shenanigans do happen. The warrant to OpenAI sought only one specific user’s account, but if OpenAI could locate one account that entered a particular prompt and got a particular response, that implies the ability to return a list of multiple accounts that entered a particular prompt (though this would violate its requirement that legal demands “unambiguously identify the user account(s) at issue”). Like I said in my original post, we don’t know OpenAI’s precise capabilities with regard to its gargantuan data stores, but they seem to be quite considerable.
AI companies should keep in mind that it’s in their interest, not just that of their users, not to let overbroad reverse prompt warrants become the new geofence warrants, whose constitutionality will soon be decided in Chatrie. Once Google started complying with them, geofence warrants ballooned to constitute over a quarter of all warrants Google received in the U.S. Eventually, Google changed how it stores user location data so that it couldn’t comply with those warrants anymore. There’s a lesson there for AI companies’ in-house counsel (many of whom came from Google, as it happens).
I am skeptical that the result in Chatrie, whatever it may be, will definitively settle the constitutionality of reverse warrants in the AI context to the satisfaction of all involved (including AI companies, their users, law enforcement, and judges). After all, following the Court’s last big digital Fourth Amendment decision in 2018, many lower courts elected to read the decision narrowly when considering other flavors of digital surveillance. And anyone to whom the Chatrie outcome proves unfavorable will have an incentive to split hairs.
We can anticipate litigation in the years to come over how Chatrie applies to AI. But that only makes it all the more important for AI companies to proactively adopt a robustly privacy-protective stance in the here and now. The major AI companies will rapidly become very powerful evidence intermediaries. We, the general public and the users of those companies, also have power. We can influence how the big AI companies respond to novel law enforcement demands. Consider how the number of downloads of Claude surged after Anthropic stood up to the Department of Defense over issues including the mass surveillance of Americans. That’s the kind of signal from users that’s hard for these companies to ignore. It wasn’t that long ago that it was in vogue for tech companies to loudly stand up for their users’ rights. It could become cool again. We can help make that happen.
]]>My answers are available here.
]]>My answers are available here.
]]>Thank you for your invitation. I’ll offer seven points.
First: American driving is dangerous.
Automated driving could help, if we’re careful about it. But people are dying today not because we’re careful about automated driving but, rather, because we’re
]]>Thank you for your invitation. I’ll offer seven points.
First: American driving is dangerous.
Automated driving could help, if we’re careful about it. But people are dying today not because we’re careful about automated driving but, rather, because we’re careless about road safety generally.
Other countries do care. Driving in the US is twice as deadly as in Canada and Australia. As a South Carolinian, I’m ten times more likely to die in a crash than my friends in the UK. Ten times.
These countries aren’t hiding some vast secret fleet of AVs. I can’t yet hail a robotaxi in London. But I can cross the street.
Second: Arrogance is careless.
AVs have tremendous potential. But believing they will be a panacea virtually guarantees they won’t, because that confidence blinds us to risks.
Many engineers working on AVs show humility. They talk with me about what’s hard, what went wrong, and what’s uncertain. They want to learn from local officials. I wish AV companies would show more of this humility in their PR.
Third: The best proxy for the safety of AVs is the trustworthiness of AV companies.
There are no “self-driving” or “driverless” cars. The companies that develop and deploy AVs are the drivers. This means that an AV is only as safe as the companies responsible for it. We can and should proactively assess their trustworthiness.
AVs won’t be perfect, but a company can still do right after its technology fails. It can explain what went wrong, how it’s addressing the actual harm, how it’s reducing future risks, and—critically—what it’s learned more broadly. We need more of this.
Doing right does not mean forcing victims into arbitrations, and it does not mean buying their silence and thereby misleading the public. These are betrayals of trust.
Fourth: Safety is a marriage, not a wedding.
Safety is a lifelong commitment that continues as long as an AV is on the road. It’s not just a one-time test or certification or checklist. A credible safety case must be a living document that is clearly supported, robustly interrogated, and routinely updated.
Vehicles placed on our roads stay there for decades and therefore need oversight for decades. NHTSA provides some of this oversight, and AVs will dramatically expand the scope of it. Yet both NHTSA and FMCSA are tiny, underresourced agencies with huge mandates.
Fifth: AVs are an especially visible part of a much broader discussion of AI.
As a society we’re likely to place many of our hopes and fears about AI generally on AVs specifically. The Transforming Transportation Advisory Committee, which I vice-chaired, addressed many of these issues, including employment, accessibility, sustainability in the face of climate change, privacy vis-à-vis both companies and governments, and fundamental questions of power. For each, we need clear policy goals and an iterative approach to achieving them.
Sixth: Local government has essential expertise.
Few appreciate how much local governments are subsidizing automated driving. First responders, for example, solve all kinds of problems, from waking up people in robotaxis to literally moving AVs that are stuck.
These local officials deserve our respect. They want the people who remotely assist AVs to be in the US. They need to know AVs will help rather than hurt their response to disasters. They want to be able to ticket AV companies for moving violations just as they would any other driver. They emphasize that every city is unique and AVs must operate accordingly.
Finally: We must empower, not disempower, our communities.
Preempting state and local authority would be profoundly short-sighted—and I say this as someone who believes strongly in the potential of AVs.
Many states want the federal government to lead on AV policy. But great leaders lead. Telling US DOT what to do (and providing the resources needed to do it) would help much more than telling states what not to do.
Preemption could create litigation rather than certainty. It could bar states from getting unsafe vehicles and unsafe drivers—human or otherwise—off the road.
Our AV industry started through federal research decades ago and then grew through our system of federalism. Brand America does have a serious credibility problem abroad, but preemption does not solve it.
In a scary time of technological change, we need to make sure that communities, and the people in them, have control and feel in control. We can deploy both technology and policy in a way that protects and empowers them.
Thank you.
]]>First, these jams – in which Waymo's vehicles appeared to come to a stop in intersections and active travel lanes – show exactly why:
1) I have been pushing for four years
]]>First, these jams – in which Waymo's vehicles appeared to come to a stop in intersections and active travel lanes – show exactly why:
1) I have been pushing for four years to add a floor to the concept of minimal risk condition (MRC) in SAE J3016. (Unfortunately, this term may soon change to mitigated risk condition.) As I wrote earlier this year, "I do not know what Waymo’s automated driving system does while awaiting the provision of remote assistance. If the system continues moving in a safe manner or achieves a minimal risk condition, then that system would be properly classified as level 4. If, however, the vehicle would simply pause in an active lane of traffic in a way that a human driver would not, then the more appropriate classification would arguably be level 3."
2) The US Department of Transportation's now-disbanded Transforming Transportation Advisory Committee (TTAC) recommended, in late 2024, "scenario planning, break-the-glass plans for emergencies and other contingencies," and "analysis of the resilience of relevant transport systems, including the implications of potential skill or labor loss for evacuations and other emergency situations."
3) Matt Wansley and I called for holistic emergency planning that accounts for drastic changes in actual driving environments, loss of communications, overwhelmed remote assistants and retrieval crews, AV-related roadway obstructions, and mass dependence on AVs. This planning needs to involve developers as well as regulators, especially the local officials who are often some of the best informed and yet least empowered actors in this field. (First responders in cities such as San Francisco and Austin are effectively subsidizing both the development and the operation of automated vehicles. This valuable public contribution deserves more recognition.)
Second, to speculate:
If all wireless communications were down because of the local power outage, then Waymo's robotaxis would have been entirely unable to receive the remote assistance they seem to need to deal with these unusual – but still foreseeable – roadway conditions. (I have not asked Waymo whether it has redundant communications through multiple cellular networks as well as through alternatives to cellular service.)
If Waymo's remote assistants were still able to communicate with Waymo's AVs, then it's possible that nothing the remote assistants could recommend was deemed acceptable by the AVs themselves. (This tricky "I'm sorry, Dave" question merits more attention than it has received in the context of automated driving.)
Alternatively or additionally, the explanation might lie in an issue I've observed in the broader automated driving industry: inadequate systems for managing (i.e., assessing, triaging, queuing, assigning, and reassigning) requests for remote assistance that exceed the capacity for remote assistance. A suboptimal approach could create spiraling delays even greater than what one might expect from insufficient capacity alone.
Striking in Saturday's images is how some robotaxis were blocking other robotaxis. (I have also experienced this.) Mitigating the resulting gridlock could require unblocking particular AVs before or in conjunction with others. This may be difficult under an approach to automated driving (including remote assistance) that treats each AV as independent rather than as part of a broader system.
[An update from Waymo's December 23rd blog post: "While the Waymo Driver is designed to handle dark traffic signals as four-way stops, it may occasionally request a confirmation check to ensure it makes the safest choice. While we successfully traversed more than 7,000 dark signals on Saturday, the outage created a concentrated spike in these requests. This created a backlog that, in some cases, led to response delays contributing to congestion on already-overwhelmed streets."]
Third, Waymo should improve its communications in an entirely different sense. In addressing Saturday's apparent traffic jams – as well as recent incidents in which Waymo's robotaxis struck and killed two pets, failed to stop for school buses, and failed to detect a stowaway in the trunk, among others – the company should be much more forthcoming. It should explain what specifically happened and why (including what it does not yet know), what steps it will take to understand and reduce the risk of broadly similar and otherwise analogous incidents in the future, and when and how it has actually implemented those steps.
In Waymo's case, this approach should involve giving some of the company's engineers and researchers a much more significant role in engaging with local communities and with the public at large – both by sharing and by listening. Waymo's impressive academic work deserves more recognition and discussion, and Waymo itself is in a good position to bridge this gap between its technical research and its public engagement generally.
]]>On December 11, 2025, President Trump signed an executive order (EO) that purports to deprive states of the ability to regulate artificial intelligence (AI) – to the modest extent possible given the limited power of EOs, which cannot require or forbid states to do anything.
]]>On December 11, 2025, President Trump signed an executive order (EO) that purports to deprive states of the ability to regulate artificial intelligence (AI) – to the modest extent possible given the limited power of EOs, which cannot require or forbid states to do anything. (Whether specific state AI laws will founder under other authorities, such as Section 230 or the First Amendment, is a separate question beyond the scope of this blog post.)
There is plenty to say about this EO, much of it unflattering (since it is very bad). However, one positive aspect is that the EO appears to tell the executive branch not to hassle states for cracking down on AI-generated child sex abuse material (AI-CSAM), the topic of dozens of state laws enacted in recent years. And because that “hands off” direction extends to online child safety more broadly, it looks like states will also be able to turn their attention to the red-hot topic of AI chatbots’ safety risks for children without drawing White House ire. (Again, a caveat that other authorities might still doom those state laws; also, laws purporting to protect children online are often terrible ideas, whether this administration approves of them or not.)
Section 8(a) of the EO tasks two senior administration officials with proposing a legislative recommendation for how to preempt state-level AI laws. There are significant changes to this section since the draft of the EO that leaked last month. Newly added is Section 8(b), which provides a list of carve-outs:
“(b) The legislative recommendation called for in subsection (a) of this section shall not propose preempting otherwise lawful State AI laws relating to:
(i) child safety protections;
(ii) AI compute and data center infrastructure, other than generally applicable permitting reforms;
(iii) State government procurement and use of AI; and
(iv) other topics as shall be determined.”
Nominally, Section 8(b) only modifies Section 8(a) – the legislative proposal for preempting state AI laws. Elsewhere in the EO, Section 3 requires the Attorney General to create an “AI Litigation Task Force (Task Force) whose sole responsibility shall be to challenge State AI laws inconsistent with” White House AI policy (namely, “to sustain and enhance the United States’ global AI dominance through a minimally burdensome national policy framework for AI”). Section 4 calls for the creation of a list of litigation targets, i.e., state AI laws that conflict with that policy; Section 5 directs the withholding of federal broadband funding from states unless they regulate AI the way the White House wants them to.
None of those sections contains the same limiting language that Section 8(b) imposes on 8(a). Nevertheless, I read that list of carve-outs as implicitly a statement of policy that carries over to the previous sections. That is, I find it highly unlikely that states’ AI-CSAM laws will be deemed to conflict with the EO’s stated policy (Section 4) or the federal FTC Act (Section 7), that the AI Litigation Task Force will sue all those states for having passed laws prohibiting AI-CSAM (Section 3), or that those laws will be implicated in the carrot/stick game of federal broadband funds (Section 5). This is for several reasons.
One, AI-CSAM prohibitions are perfectly consonant with the EO’s stated AI policy anyway. As said, that policy is “to sustain and enhance the United States’ global AI dominance through a minimally burdensome national policy framework for AI.” By and large, state AI-CSAM laws and bills target AI models’ outputs, not the models themselves. They will be enforced against the end user who creates and/or shares AI-CSAM using a generative AI tool, not the entities that provided the tool (though we are starting to see laws and bills targeting nudifier app services). Criminalizing AI-CSAM doesn’t hamper the business of OpenAI, Meta, Google, et al., nor the development of open-source models by nonprofits or academia.
In fact, federal government policy on AI-CSAM is already very clear. Congress passed, and the President signed, the TAKE IT DOWN Act earlier this year. The law outlaws nonconsensual deepfake pornography whether it depicts adults or minors, with both criminal and civil liability. Plus, using a computer to create CSAM of real kids has been a federal crime for almost three decades already, as I cover in this paper.
Second, for this administration to sue states to try to invalidate their child-protection laws is what seasoned political experts, in their specialized jargon, would call “a completely dumbfuck idea.” “Child safety” is already a sacrosanct topic, as I’ve learned from a decade working on tech policy. Invoking “child safety” tends to shut down nuanced discussion and rational thought, and it makes opposing even bad bills very difficult politically, as voicing concerns gets you called a pedophile. As one of the state legislative staffers interviewed for my recent AI-CSAM paper remarked, “Nobody objects to trying to protect children.”
There would be terrible optics to the Department of Justice (DOJ) going after states for CSAM- or other child safety-related laws. That would be true at any time, but it is particularly ill-advised now. The Epstein files (of which another batch are in the news today) have proven remarkably resilient as a topic preoccupying the American public, even among Trump’s own base. Even Trump loyalists in the GOP voted to release the files. The President’s approval rating is in the toilet. He is not going to tell Pam Bondi to give Gavin Newsom more ammo against him.
Third, executing the EO will require resource management. There are only so many federal government employees available to carry out the EO – especially since this administration has illegally fired so many federal workers and redirected so many others to helping kidnap nannies and gardeners, with a measurable impact on child safety investigations. Whoever works on implementing the EO will have only so many hours in the day, and with six different sections of the EO creating various workstreams, it’s possible some employees will end up on more than one. I assume the number of personnel carrying out the EO will be relatively modest, at least compared with the number tasked with immigration enforcement. Or redacting the Epstein files.
As said, there are dozens of states with AI-CSAM laws. And CSAM is just one topic; states are proposing and passing way more bills on AI besides that. For the federal government to challenge every state AI law simply does not scale. That means the carve-outs listed in Section 8(b) – which allows for “other topics as shall be determined” – are an operational necessity. It’s also why I think Section 8(b)’s list will, in practice, be read to apply to the previous sections too. The EO tasks various agencies and individuals with time-sensitive projects; as they plan their work, they can now deem the Section 8(b) topics out-of-scope. Whereas many states have “State AI laws relating to child safety protections,” far fewer have the kinds of big-picture AI governance laws, like those passed by Colorado and California, that are likely to be the highest-priority targets under this EO. The 8(b) carve-outs free up employees’ limited time and resources to focus on those priorities. (To be clear, I’m not saying I agree with the EO – only that triage is unavoidable for those tasked with implementing it.)
Finally, it bears noting that the wording of Section 8(b) exempts state AI laws relating to “child safety protections,” not AI-CSAM in particular. I suspect that this wording is intentionally broad so that it encompasses not just AI-CSAM legislation, but also other online child safety bills (in past, present, or future sessions) – of which there are a lot – that incidentally or explicitly cover AI, not just social media, gaming, and the like.
Child safety has been a predominant issue in the federal and state legislatures alike for several years running, and even if state laws addressing that topic might be “burdensome” on AI companies, it is a hard sell politically to let only AI companies get a hall pass from compliance. That’s why child safety was also a carve-out from some versions of a proposed federal legislative moratorium on state AI laws earlier this year. The House passed a moratorium (sans child safety exemption) in its version of the One Big Beautiful Bill Act, but the Senate ultimately removed it, prompting this small-beer simulacrum from the executive branch.
What’s more, AI chatbots are the latest, hottest topic in online child safety right now, following multiple high-profile cases of teen suicides allegedly related to chatbot interactions. States are already starting to enact legislation, and I believe AI chatbots will be as popular a legislative topic in the next few state legislative sessions as AI-CSAM was in the last few. After all, “Nobody objects to trying to protect children.”
To that end, the EO’s child-safety carve-out may operate as a limit on EO execution strategy – even though, again, it’s found only in Section 8, not other sections. In practice, I predict that the “child safety protections” language in Section 8(b) will be read by the AI Litigation Task Force, the Federal Trade Commission, et al. as an instruction not to get in states’ way as they start to regulate AI chatbots with respect to child safety, even if those regulations would otherwise be squarely in the EO’s sights. For example, Section 7 of the EO (evoking July’s “Woke AI” EO) frowns on “State laws that require AI models to alter their truthful outputs.” Technically, that would include, say, a bill that would prohibit chatbots from providing true information to under-18 users about how to make a noose, like ChatGPT allegedly gave to a teenager before his suicide. Under the EO’s child safety carve-out, the administration is not likely to challenge a bill like that (or a part of a bill, or the enforcement thereof by the state).
Lastly, to the extent that some states do meekly go along with this EO instead of standing up for themselves (I thought “states’ rights” were sacrosanct?), the child-safety carve-out also serves as a green light to the states. Even though the EO is plainly meant to scare them out of passing and enforcing new laws regulating AI, it’s a sign that they can pass AI laws governing CSAM, chatbots, and so on, and the administration won’t punish them for it.
In conclusion, attacking states’ right to regulate AI and protect their own residents is abhorrent. But there are more than 50 states and territories, and their legislatures seem determined to ensure that their constituents are benefited by AI, not harmed by it. Even GOP-led state governments are standing up against the new EO. And no wonder: not only do they have to protect their own right to govern, but also, they’re listening to their constituents’ desires. More AI regulation is what Americans want. This EO is not going to stop that from happening.
]]>My impulse to write this piece came from a question at a recent Conference, where I was speaking about AI training, fair use and EU text-and-data mining (TDM). During the Q&A, someone asked about the fresh decision of the Landgericht München I in
]]>My impulse to write this piece came from a question at a recent Conference, where I was speaking about AI training, fair use and EU text-and-data mining (TDM). During the Q&A, someone asked about the fresh decision of the Landgericht München I in GEMA v OpenAI (42 O 14139/24, 11 November 2025). I answered a bit too briskly that I did not think the case deserved the weight people were giving it: in my view, it misreads how machine learning works, mislabels memorisation as “reproduction”, and arrives at the wrong policy conclusion at exactly the wrong time.
Since then, media coverage, collecting-society press releases and early academic commentary have started to cast GEMA as a landmark for AI training in Europe. That, I think, is dangerous. So, this post tries to do what I have not had the time to do in the conference room: slow down, unpack what the Munich court actually did, and explain why it is a poor candidate for setting the legal frame for AI training in the EU.
Part 1 of this post will outline the decision and place it in the action workflow of large language models (LLMs), as well as explaining why treating training as “reproduction”, in the way GEMA suggests, is technically and doctrinally misguided. Part 2 will highlight the broader policy costs of that move - for innovation, for Europe’s position in AI, and for copyright’s own idea-expression architecture.
]]>“Micromobility” refers to a diverse set of transportation modes that, at least on the ground, fall somewhere between traveling by foot and traveling by car: “bicycles, scooters, electric-assist bicycles (e-bikes), electric scooters (e-scooters)
“Micromobility” refers to a diverse set of transportation modes that, at least on the ground, fall somewhere between traveling by foot and traveling by car: “bicycles, scooters, electric-assist bicycles (e-bikes), electric scooters (e-scooters), and other small, lightweight, wheeled conveyances.” Within this broad scope, micromobility policy often focuses specifically on vehicles that are partially or fully motorized or on shared systems of vehicles that are physically dispersed in a community and made available to users through an online platform.
The plethora of new terms—micromobility, mobility-as-a-service (MaaS), e-scooter, and so on—contributes to a myopic view that micromobility itself is novel. But these terms join many others, from “vulnerable road users” to “alternative modes,” in describing forms of mobility that have been literally and metaphorically at the margins of the US transportation system for well over a century.
Many of the vehicles themselves have an even longer history. In 1879, a local reporter lamented that a “woman pushing a baby carriage in front of her is as dangerous as seven roller-skaters and four velocipede riders combined.” In 1885, another prematurely declared that, “[t]o the credit of our people,” “the roller-skating craze is dying out.” By 1897, velocipedes had evolved into modern bicycles, and their riders—a “vast, modern, rapidly growing power”—were credited with electing Chicago’s new mayor. The bike afforded many people, and especially women, a freedom of movement that was never before available to them—and inspired contempt from others. The “cycling craze” was in full swing.
Yet “what had seemed like a revolution in 1890 had become an artifact of an earlier era by 1905.” Attention quickly shifted to motorized transport on the ground and, as the history of the Wright Cycle Company suggests, the sky. Although motorized scooters, including some of the electric variety, also made their debut, automobiles came to dominate US roads. (And the shared transport epitomized by the streetcar declined accordingly.)
This domination was not accidental. Automobile proponents successfully sought to transform streets from a place for people to a place for cars. Pedestrians became “jaywalkers.” Local car dealers spoke “of waging a campaign against the practice of children roller skating on the street.” What is now described as micromobility accordingly moved to the physical and policy margins. These modes have since been marked by two key tensions: competition with motor vehicles for space on the street, and competition among themselves for the remaining space at the curb and on the sidewalk—the literal and metaphoric margins of our streets.
These modes are numerous. On streets or on sidewalks, bicycles and roller skates have been joined by inline skates, skateboards, kick scooters, recumbent bicycles, party bikes, tricycles, pedicabs, go-karts, remote-controlled toy cars, shopping carts, Segways, hoverboards, mopeds, seated scooters, electric and electric-assist bicycles, dirt bikes, golf carts, neighborhood electric vehicles, autocycles, horse-drawn carriages, various types of farm equipment, a variety of mobility assistance devices, and now delivery robots—to name just a few. (And, while not “vehicles,” pets, livestock, and other animals are also present on streets and sidewalks.)
Jurisdictions in the United States have addressed these modes in a piecemeal fashion that has produced both internal and external inconsistencies. If they are expressly referenced, these modes are generally shoehorned into state vehicle codes that focus on conventional automobiles. (Indeed, some states codify their rules of the road—even those addressing pedestrians and bicycles—in a title on “motor vehicles.”)
States variously and discretely define bicycles and an assortment of motorized devices including electric bicycles, low-speed vehicles, golf carts, electric personal assistive mobility devices, electrically motorized boards, mopeds, motorized scooters, motor-driven cycles, motorcycles, “play vehicles,” “toy vehicles,” and—most recently—“personal delivery devices.”
Some of these categories are strikingly specific. For example, the category generally though not exclusively termed “electric personal assistive mobility devices” is the product of extensive lobbying by Segway. Accordingly, while definitions for these devices use generic language, they effectively describe only Segways. Later, many of the states that expressly regulated e-scooters created new e-scooter definitions rather than broaden their Segway definitions.
These various devices are not necessarily “motor vehicles”—or even “vehicles”—under state codes. Persons with physical disabilities using “wheelchairs and manually-powered mobility aids” and, in many cases, the motorized equivalents, are generally considered pedestrians. The legal classification of bicycles has occupied legal scholars for well over a century and has not produced consistent results.
In New York, a bicycle is not a “vehicle.” In Wisconsin, a bicycle (including an electric bicycle) is a “vehicle” but not a “motor vehicle,” a “motor bicycle” is both a “bicycle” and a “motor vehicle,” and a “snowmobile, an all-terrain vehicle, a utility terrain vehicle, an electric scooter, and an electric personal assistive mobility device” qualify as both a “vehicle” and “motor vehicle” “only for purposes made specifically applicable by statute.” In Oregon, an “electric personal assistive mobility device” is a vehicle (except when it isn’t) but not a motor vehicle (except when it is), and its user is treated as a bicyclist when on a roadway and as a pedestrian when on a sidewalk. (And Oregon also defines a “crosswalk” as a “portion of the roadway” rather than a portion of the sidewalk.)
These classifications are generally shortcuts for imposing substantive legal requirements. Federal law specifies that certain e-bikes are to be regulated by the Consumer Product Safety Commission (CPSC) rather than by the National Highway Traffic Safety Administration (NHTSA). Under state law, a motor vehicle (or its driver) might be subject to titling, registration, insurance, and licensing requirements that a mere device (or its user) would not be. (Language varies by state: New York, for example, uses the term “vehicle” to mean “motor vehicle.”)
Similarly, the rules of the road might apply differently to pedestrian, bicyclist, or motorist. In Wisconsin, for example, the rider of a bicycle or electric bicycle must follow all the rules of the road, including a small set of provisions specific to bicycles (which are “vehicles” but not “motor vehicles”), whereas the rider of an e-scooter must follow only 58 enumerated sections or subsections of the rules of the road—in each case unless a provision by its “express terms appl[ies] only to motor vehicles or” by its “very nature would have no application” to the device in question.
Whether explicitly or implicitly, these various provisions functionally determine whether and where a micromobility device may even be used. For example, at one point South Carolina regulators informally concluded that an e-scooter is a motor vehicle, must therefore be registered, yet cannot be registered, and therefore cannot be used on public roads, including crosswalks. (Conversely, for many years mopeds in the state escaped much of this regulation.)
Wisconsin expressly prohibits so-called “play vehicles”—“a coaster, skate board, roller skates, sled, toboggan, unicycle or toy vehicle upon which a person may ride” but not “in-line skates or electric scooters”—on roadways other than at crosswalks. (And so while both rollerbladers and rollerskaters are “vulnerable highway users,” only the latter are expressly barred from public roads.) Many states prohibit “obstructions” on roads. Philadelphia expressly prohibits “rid[ing] a scooter, roller skates, or skateboard” on any public sidewalk.
These examples suggest the panoply of ways that jurisdictions restrict micromobility on facilities held open to the public. (This wording is deliberate, as some state vehicle codes apply not only to public roads but to certain private roads and parking facilities.) Against a background presumption of legality, a given device might nonetheless be banned on sidewalks and crosswalks, on pedestrian plazas, on bike paths, on dedicated bike lanes, on roadway shoulders and curbsides, on neighborhood streets, on major roads, or on freeways—or, classically, “in the park.” Newer manifestations of micromobility are not fundamentally different than the varied modes that jurisdictions have excluded or marginally tolerated for decades.
]]>Earlier this week, the indefatigable Thomas Brewster at Forbes, a journalist who’s been covering the digital surveillance beat for years, reported on a search warrant to OpenAI seeking to unmask a particular ChatGPT user. Brewster says it’s “the first known
]]>Earlier this week, the indefatigable Thomas Brewster at Forbes, a journalist who’s been covering the digital surveillance beat for years, reported on a search warrant to OpenAI seeking to unmask a particular ChatGPT user. Brewster says it’s “the first known federal search warrant asking OpenAI for user data.” (Note the “known”: similar warrants might still be under seal like this one was until recently.) The warrant’s supporting affidavit describes a long-running child exploitation investigation into multiple dark web sites hosting child sex abuse material (CSAM), whose administrator the government sought to identify. (It has now arrested a suspect.)
So what’s the link between various dark web sites and OpenAI? Well, like 800 million other people, the sites’ administrator is allegedly a frequent ChatGPT user. As the affidavit describes, an agent from Homeland Security Investigations (HSI) had been chatting undercover with the admin, who described to the agent his ChatGPT usage, including specific prompts and partial or full responses. Based on that information, the government sought and obtained a warrant to OpenAI for (per Brewster) “various kinds of information on the person who entered the prompts, including details of other conversations they’d had with ChatGPT, names and addresses associated with the relevant accounts, as well as any payment data.” The affidavit includes two “unique, specific” prompts and the “unique responses” that ChatGPT generated. OpenAI apparently complied with the warrant in the form of an Excel spreadsheet of data. (We don’t know what’s in the spreadsheet.)
This warrant may be a first, but it’s not a surprise. User data is “if you keep it, they will come”: If a tech company stores data about its users, in a form the company can legibly access (i.e., not end-to-end encrypted, or E2EE), it will receive a government request for some user’s data eventually… and then for more users after that. And the more data the company stores, the richer the trove for investigators to tap into. (The day after his ChatGPT story, Brewster reported on how HSI used WhatsApp user data in an immigration-related investigation.) That’s why, as digital rights attorney Jen Lynch commented in the ChatGPT article, “it’s more important than ever for OpenAI and other AI companies to think about how to limit the amount of data they collect on their users.”
This warrant may be the first, but it won’t be the last. OpenAI’s transparency reports (each of which is a whopping one page long) say it got a total of 71 government requests for user data in the second half of 2024 (the latest reporting period available), after receiving only half that many in the first half of that year. That number is still small, but it will keep increasing, and this news is surely going to add to the load. Once word gets out that a company can provide various information about its users and will comply with valid legal process, other investigative agencies will follow suit, and the volume of requests goes way up.
That’s what happened with so-called “reverse warrants” to Google for keywords users entered into Google Search and for users’ location history in Google Maps. It got so bad that Google stopped storing Android users’ location history. The company also pushes back on at least some reverse keyword warrants.
Reverse warrants pose major constitutional problems because they’re inherently overbroad: they seek information on everybody who was in a particular place during a particular timeframe, or everybody who searched for a particular query. That flies in the face of the Fourth Amendment, as former federal magistrate judge Brian Owsley explains in a recent article in the Stanford Technology Law Review. As his opening says: “Traditional law enforcement warrants begin with a suspect and, supported by a finding of probable cause, seek additional evidence about that person. Keyword search warrants reverse this process.” The ChatGPT warrant news immediately raised concerns that a new chapter in the tawdry saga of reverse warrants has just begun, with OpenAI replacing Google as the main character.
True, as Lynch noted, this particular warrant looks properly scoped to seek information about one specific ChatGPT user, for whom the affidavit provided ample information to support probable cause linking that user to the CSAM sites. The warrant was not casting a dragnet for every unknown user who entered a query without any reason to suspect each of them individually, the way reverse keyword warrants do. This warrant also makes false positives highly unlikely by limiting the request to whichever account entered one specific prompt and received two specific and lengthy responses to prompts. That’s different from, say, a reverse keyword warrant for information on every person who googled a particular street address, which could cover a suspected arsonist but also anyone from party guests to a taxi driver to a pizza delivery guy.
Nevertheless, we should take this warrant to OpenAI as a harbinger of more to come. That this warrant application was properly scoped doesn’t mean the next one will be. And even if they’re all properly scoped, there are going to be more of them, and it’ll take some amount of work for OpenAI to deal with them. Therefore, here are some questions we should be asking about user data requests to OpenAI (and its ilk) going forward:
If OpenAI’s numbers are to be believed, one out of every ten people on Earth already uses ChatGPT at least once a week. In that sense, it’s remarkable that the volume of user data requests the company receives is as low as it is – and that it took this long for the first known reverse prompt warrant to arrive. As said, this one seems OK, but OpenAI needs to be ready for future ones to try to push the envelope. Navigating an increasing volume of requests from governments is a normal part of a startup tech company’s growth. But the larger its user base, the more important it is for the company to stand up for its users’ rights – and to do so vigorously straight out of the gate. Frankly, AI as a replacement for traditional web search has been disappointing enough already. We don’t need the AI version of superabundant unconstitutional reverse keyword search warrants too.
]]>It seems like every day brings another news story about a lawyer caught unwittingly submitting a court filing that cites nonexistent cases hallucinated by AI. The problem persists despite courts’ standing orders on the use of AI, formal opinions and continuing legal education
]]>It seems like every day brings another news story about a lawyer caught unwittingly submitting a court filing that cites nonexistent cases hallucinated by AI. The problem persists despite courts’ standing orders on the use of AI, formal opinions and continuing legal education (CLE) courses on ethical use of AI in law practice, and revelations that AI-powered legal research tools are more fallible than they purport to be.
Who are the attorneys submitting AI-tainted briefs? A recent 404 Media article about lawyers’ use of AI drew my attention to a database of AI Hallucination Cases compiled and maintained by Damien Charlotin, a French lawyer and scholar. Charlotin classifies the nature of the incident by various types of inaccuracies: fabricated cases, false quotes from or misrepresentations of real cases, or outdated invocations of cases that have been overturned. Besides helping the public understand how lawyers are getting tripped up by AI, Charlotin’s database also enables a better view of who is getting tripped up by AI.
Using the database, I analyzed 114 cases from U.S. courts where, according to either opposing counsel and/or the court’s own investigation, an attorney’s filing included inaccuracies that were suspected or shown to have been caused by the use of AI. I find that the vast majority of the law firms involved – 90% – are either solo practices or small firms. What’s more, in 56% of the cases, the AI hallucinations were attributed to the plaintiff’s counsel, compared with 31% to the defense. And, while most cases in the sample did not specify the AI tool used, of those that did, fully half involved some version of ChatGPT.
Methodology
I based my analysis on cases I downloaded in a .csv file from Charlotin’s database on October 9, 2025. The time period covers court orders issued from June 2023 (the month of the landmark order in Mata v. Avianca) through October 7, 2025.
[Note: October 9 was a Thursday; by the following Monday, when I began drafting this write-up, Charlotin had added three new matters involving pro se litigants (which I exclude from my analysis) as well as two updates on cases that were already in the database (and thus already in my sample), plus there was news coverage of an oral argument where an attorney was grilled about hallucinations in his briefing. I did not add that last matter, which had not yet yielded a written opinion at the time I wrote this, to my sample. This is all to give the reader some idea of just how frequently these incidents are happening and consequently to highlight that my sample should not be considered comprehensive – the data became outdated almost immediately.]
Charlotin has helpfully coded the data by a number of selectors including country. I restricted my download to the USA only. After importing the .csv file into Google Sheets, I then filtered by Party to include all cases involving a Federal Defender, Lawyer, and/or Paralegal. (Prosecutor is also an option in the database, but there were zero such cases in the USA for that time period.) This resulted in 117 cases, which fell to 114 after I excluded three cases from the sample (two cases that actually involved pro se litigants rather than lawyers and one duplicate case). (EDIT 10/17/25: Note that my choice to exclude cases tagged as Expert meant that my sample excluded some high-profile matters such as Concord v. Anthropic.)
I reviewed the court orders that Charlotin included for each database entry in order to determine which party was accused of submitting hallucinated citations and the name and law firm affiliation of the attorney(s) for that party. If that information was unavailable in the court order, I looked up the case docket in federal or state court records.
Most of the cases in the sample are typical adversarial matters where the parties can be classified as either plaintiff or defendant. For matters that fall outside that usual structure (such as bankruptcy cases), I created an “other” category. Where the court order came from an appellate case, I tried to classify the party as plaintiff or defendant as per the parties’ trial-court posture.
My data for the number of attorneys at each firm came from either the firm’s website or some other authoritative source (such as the NALP, Vault, or Law.com). I sometimes had to guess that an attorney was solo, typically where the attorney does not have a dedicated website and the firm name listed in court records, if any, is indicative of a solo practice (e.g., “Law Office of Jane Smith”).
For firm size, I have used the following bands: solo; 2-25; 26-100; 101-200; 201-500; 501-700; 701-1000; 1001+. These are the bands the NALP uses for its Directory of Legal Employers, except that it uses “1-25” as a band. I chose to split out solo attorneys as a separate category because I believe solo attorneys deserve recognition as a standalone group with unique characteristics that differentiate their practices from firms of 10 or 20 lawyers. I added a “government” category for the rare cases involving government attorneys (two: a public defender and attorneys for a county), but did not attempt to count how many attorneys were part of that particular government unit.
There may be errors in my data, thanks to having to guess about some things (such as whether someone is a solo practitioner) or relying on inaccurate or outdated sources (for example, third-party reporting on firm size). If you find an error, please email me (riana at stanford dot edu) and I’ll fix it and update this post.
The Party Submitting Hallucination-Tainted Filings Is Usually the Plaintiff
The plaintiff is more commonly the party allegedly responsible for submitting filings containing AI hallucinations. Out of 114 cases, 64 were attributed to the plaintiff (56.1%), compared with 35 to the defendant (30.7%). There were 15 “other” cases (13.2%): bankruptcy, family, probate, and tax court matters, agency matters, a habeas petition, and an attorney disciplinary proceeding. (The lawyer allegedly submitted filings with AI hallucinations during that disciplinary proceeding, not in an underlying case involving that lawyer like other disciplinary proceedings in the sample. Where the attorney was facing discipline for misusing AI while representing a client, I classified the lawyer according to the party they were representing in the underlying case.)
AI Hallucination Cases Overwhelmingly Involve Solo or Small Firms
Some of the 114 cases in the sample involved attorneys from more than one firm – for example, local counsel filing briefs drafted by a different firm. I counted each firm separately, except that if the court’s order faulted only one firm’s attorney, I did not count the other firm(s). The total number of firms (including government entities) was 129.
Solo practices and small firms represent the overwhelming majority of that number. Solos account for half (50.4%) and small firms of 2-25 lawyers for another 39.5%. Of the remaining 10% of firms, 3.1% are firms of 26-100 lawyers; 2.3% are firms of 201-500 lawyers; 1.6% are firms of 1001+ attorneys; 1.6% are government entities; and firms of either 101-200 or 501-700 lawyers each represent less than 1%. There were no cases involving firms of 701-1000 lawyers.
The number of firms in the sample with more than 25 lawyers is small enough to count on two AI-generated hands. Four have up to 100 lawyers: Ellis George, Hagens Berman Sobol Shapiro, Merlin Law Group, and Williams Kastner. Five have 101-700 lawyers: Butler Snow, Goldberg Segalla, Morrison Mahoney, Quintairos Prieto Wood & Boyer, and Spencer Fane. Two have more than 1000 attorneys: K&L Gates and Morgan & Morgan.
Five lawyers are implicated in more than one case in the sample. All are either solo practitioners or small-firm lawyers: solo Maren Miller Bam of Salus Law; Jane Watson of Watson & Norris (who was only admitted to the bar in 2024); Chris Kachouroff of McSweeney Cynkar & Kachouroff (who gained notoriety for appearing pantsless at a Zoom court hearing); solo Tyrone Blackburn (who got arrested for assault in June in connection with a different case of his); and William Panichi, a family-court attorney. While the first four allegedly misused AI in two separate cases, Panichi was called out in an astonishing four cases in one 30-day period; he has supposedly begun winding down his law practice and surrendering his license.
ChatGPT Was the Most Commonly Used AI Tool
Of the 114 cases in the sample, only 34 (30%) identified the specific AI tool(s) used by the attorneys. Some cases involved the use of more than one AI tool. OpenAI’s ChatGPT (any version, including in-house versions and the ChatGPT-powered app Ghostwriter Legal) was far and away the most common: it was implicated in fully half (18) of the 34 cases that specified a tool. Coming in a distant second were AI tools offered by Westlaw, followed by Anthropic’s Claude (any version), Microsoft Copilot, Google Gemini, and LexisNexis’s AI tools.
Discussion
This analysis confirms what many lawyers and judges may have suspected: that the archetype of misplaced reliance on AI in drafting court filings is a small or solo law practice using ChatGPT in a plaintiff’s-side representation.
Ultimately, the buck stops with the attorney to make sure that she can stand behind every word of every brief filed over her signature. But the 404 Media article that led me to Charlotin’s database paints a picture of how hard it is to live up to that obligation, particularly for solo or small-firm attorneys. Lawyers struggle with busy caseloads, the trustworthiness of their co-counsel, junior attorneys, and support staff, and personal issues (health problems, caregiving obligations, etc.) that compete with work for their time and attention. Of course, that was already true long before AI. Lawyers, even very good ones, have always made the occasional mistake or oversight in their work. AI tools have merely provided a new way to make those errors – while also promising a way out of the underlying issues that contribute to them, like time crunches and insufficient support. As the 404 Media article observed, “the legal industry is under great pressure to use AI.” To overworked attorneys at small law offices, these tools must seem like a godsend.
However, as the lawyers in this analysis learned the hard way, these tools are not reliable for their core purpose of accurate, comprehensive legal research results. Several of my Stanford colleagues are coauthors on a recent paper that investigated AI legal tools’ claims to be “hallucination-free” or to “eliminate” or “avoid” hallucinations. To the contrary, they found disturbingly high levels of hallucinations in all the tools they studied: OpenAI’s GPT-4, Lexis+ AI (offered by LexisNexis), Westlaw’s AI-Assisted Research, and Ask Practical Law AI (which, like Westlaw, is owned by Thomson Reuters). All of those companies are represented in the 34 cases analyzed above.
The incidents in Charlotin’s database illustrate the real-world impact of AI legal tools’ shortcomings – and not just on the lawyers, who end up humiliated and sanctioned for relying on tools they thought were reliable. AI-tainted legal briefs negatively affect those lawyers’ clients, who depend on them for high-quality representation, including in incredibly high-stakes matters such as criminal prosecutions or the termination of parental rights. They affect opposing counsel, who must waste their time tracking down nonexistent case citations. And they affect the courts, which are busy enough already without also having to police this new form of attorney ethics violations and take care not to let nonexistent cases cited by counsel creep into court opinions.
What Is To Be Done?
These cases keep happening at an alarming pace. Dozens of cases have been added to Charlotin’s database since the American Bar Association (ABA) issued its formal opinion warning about generative AI tools in July 2024. For all the news stories about lawyers caught flat-footed by these tools, clearly there are lawyers who never read them and subsequently become the headline of the next one. It may be that nothing will sufficiently penetrate lawyers’ consciousness about the pitfalls of relying on AI tools until every practicing lawyer is personally confronted with that knowledge through some combination of (1) every single type of court – federal, state, tribal, agency; civil, criminal, bankruptcy, family, probate, you name it – requiring every lawyer who appears in every case to file a declaration attesting that they understand and acknowledge the fallibility of AI tools and have educated all their staff as well, and (2) every single state bar (including D.C. and U.S. territories) imposing CLE requirements specifically about AI tools for legal research, like they now do for topics like substance abuse and elimination of bias.
Even then, there will be failures. Inevitably, some lawyers will dutifully certify that they understand that AI tools are unreliable, then file an AI-tainted brief anyway. But perhaps the incidence of lawyers sanctioned for unwittingly misusing AI will slacken with time and more pervasive awareness of AI’s perils. And hopefully AI legal research tools themselves will improve over time (as their paying customers surely expect them to) – though it is as unreasonable to expect perfection from them as from humans. “Trust, but verify” must remain the watchword.
With all that said, no amount of CLE courses and state bar ethics opinions will fix the problem I haven’t discussed until now: use of AI by pro se litigants. I wanted to figure out which lawyers were getting tripped up by AI, so I only analyzed U.S. cases involving lawyers or paralegals, for a sample of 114 cases. But in the .csv file I downloaded from Charlotin’s database, there are 160 cases involving a pro se litigant. That is: Pro se litigants account for the majority of the cases in the United States where a party submitted a court filing containing AI hallucinations. In a country where legal representation is unaffordable for most people, it is no wonder that pro se litigants are depending on free or low-cost AI tools. But it is a scandal that so many have been betrayed by them, to the detriment of the cases they are litigating all on their own.
Conclusion
This analysis speaks to both the urgent need for high-quality legal research tools in a legal profession dominated by small and solo practices, and the yawning gap between current AI tools’ actual and perceived reliability. In many cases in the analysis, the attorney had not understood that AI tools may produce inaccurate results. True, lawyers are ethically obligated to ensure the accuracy of their work product. But it is also incumbent upon the companies offering AI tools, especially those tailored specifically for legal research, not to oversell them or hide their shortcomings; that is, their marketing shouldn’t outgun their disclaimers. So long as these tools remain flawed without lawyers understanding that, AI tools for legal research threaten to be, not a timesaver, but a source of unnecessary extra work for lawyers and the courts.
]]>As the United States experiences its latest government shutdown, most of the daily operations of the federal government have ground to a halt. This includes much of the day-to-day work done by federal information technology and cybersecurity employees, including those at
]]>As the United States experiences its latest government shutdown, most of the daily operations of the federal government have ground to a halt. This includes much of the day-to-day work done by federal information technology and cybersecurity employees, including those at the nation’s leading civilian cybersecurity agency, the Cybersecurity and Infrastructure Security Agency.
CISA is among the entities that will see the deepest staffing reductions during the shutdown that began Oct. 1, 2025, according to Department of Homeland Security documentation. Only about one-third of its employees remain on the job after federal employees were furloughed. As if cybersecurity wasn’t challenging enough, fewer CISA employees are being asked to do more and more work protecting American cyberspace during the shutdown. And they’ll be working with the promise of getting paid for their efforts at some date in the future once the shutdown ends.
The current CISA situation is grim, from my vantage point as a cybersecurity researcher and former industry practitioner. The agency was already experiencing deep cuts to its staff and resources before the shutdown. And now, coinciding with the shutdown, a key law that enabled the agency to facilitate information-sharing with the private sector has expired.
Taken together, the cyberdefense agency is being hobbled at a time when the need for its services has never been greater, from the ongoing China-led Salt Typhoon attack on U.S. telecommunications networks to ransomware, data breaches and threats to infrastructure.
CISA was created in 2007 within the Department of Homeland Security. As its name implies, the agency is charged with digital security matters across the federal government. The agency also works with the companies that operate and secure the numerous critical infrastructure sectors of the American economy, such as phone networks, the electric grid and energy pipelines. Additionally, it helps state and local governments across the country secure their vulnerable networks and data.
CISA also publishes threat and vulnerability alerts for the government and cybersecurity community and engages with public and private stakeholders on best practices in response to emerging vulnerabilities. Prior to the recent expiration of the 2015 Cybersecurity Information Sharing Act, the agency also made it easier for organizations to share useful information with the government to help cybersecurity teams better protect their systems.
Embedded iFrameShutdown-mandated furloughs at the nation’s cybersecurity agency present an opportunity for malicious hackers.
The agency takes a nonpartisan approach to cybersecurity matters. However, some politicians have accused the agency of political bias for its work helping states protect their voting infrastructure from cyberattacks and external influence. Specifically, the agency was repeatedly maligned for calling the 2020 election the “most secure” in history. For some in elected office, this work on election security has tarnished CISA’s reputation and perhaps explains recent budgetary actions taken against the agency.
Since the Trump administration took office in January 2025, nearly 1,000 CISA employees have departed the agency through voluntary buyouts or deferred resignations. By the end of May 2025, nearly all of CISA’s senior leadership had resigned or had announced plans to do so.
For 2026, the president’s draft budget proposes to reduce CISA’s head count by nearly one-third, dramatically cutting staff from its risk management and stakeholder engagement divisions. Other cuts will significantly reduce the agency’s collaboration activities and funding for CISA’s various cybersecurity education and training programs.
Making the problem worse, the government shutdown began at the same time that Congress failed to renew the Cybersecurity Information Sharing Act. This law provided a legal shield that allowed companies and infrastructure operators to share timely and often sensitive information with CISA about the cyberattacks, vulnerabilities and incidents that they were encountering.
In the wake of the law’s expiration, prudent companies may consider restricting what information they share with the government. Without the indemnification provided by CISA, many companies will likely have their legal teams review any information to be shared with the government. And that takes time.
Unfortunately, adversaries do not reduce their attacks against the U.S. based on available federal cyber defense funding or the status of cybersecurity laws. In fact, malicious hackers often strike when their target’s guard is down.
Early in my career I had to work through a prolonged government shutdown. I’ve also participated in and developed assorted public-private information-sharing environments to exchange intelligence and analysis on cyber- and national security matters. And having been in the D.C. area for over 30 years, I’ve seen how government works. So I have a good idea of what’s needed to improve American cybersecurity. The following suggestions are a starting point.
First, Congress could ensure that critical security agencies such as CISA are immune from the threat of recurring federal government shutdowns. If it desired, Congress could set budgets for America’s security agencies on a biennial basis – as 16 states already do for their entire budgets.
In terms of cybersecurity funding, the White House’s proposed 2026 budget reduces research and education on cybersecurity. For example, the nation’s premiere federal cybersecurity scholarship program to recruit, educate and place future federal cybersecurity workers would be reduced by over 60%. Protecting this funding would allow CISA and the federal government to maintain the pipeline for a robust and capable cybersecurity workforce both today and into the future.
Companies could develop new or expand existing nongovernmental information-sharing networks that are not completely dependent on the government to facilitate or fund, such as the Cyber Threat Alliance or the Center for Internet Security. Cybersecurity relies on trust. But right now, the instability of the federal government makes it difficult to rely on any entity under its policy or funding influence, no matter how well time-tested and trusted. Regardless, without legal protections, the information-sharing utility of these services will be limited.
Cybersecurity risks remain even if the federal government shuts down. So this is another reminder that each of us is responsible for our own cybersecurity. Individual users should continue to remain vigilant, follow accepted best practices for cybersecurity and always be mindful about online risks.
It’s ironic that the federal government is shutting down, CISA is being eviscerated and the Cybersecurity Information Sharing Act has expired just as the country begins to observe national Cybersecurity Awareness Month – another collaborative public engagement activity that CISA promotes to help improve cybersecurity for all Americans.
Richard Forno, Teaching Professor of Computer Science and Electrical Engineering, and Associate Director, UMBC Cybersecurity Institute, University of Maryland, Baltimore County
This article is republished from The Conversation under a Creative Commons license. Read the original article.
]]>