The American Arbitration Association (AAA) has launched an AI Ambassador Program bringing together 37 attorneys from leading law firms to examine how artificial intelligence (AI) is reshaping disputes and dispute resolution. The group will develop practical resources for users, counsel, arbitrators, mediators, and other professionals, with an initial focus on AI-based evidence and arbitration procedure, AI-related disputes, automated transactions, digital assets, and algorithmic finance. The initiative reflects a growing reality: AI is changing not only the types of matters entering arbitration, but also the evidence, procedures, and decision-making tools used to resolve them.

The program builds on the AAA’s broader work in AI, including its support for the Legal Context Protocol (LCP), an open standard designed to create a reliable legal record for transactions conducted by autonomous software agents. As agents increasingly purchase services, commit funds, and accept terms without contemporaneous human review, traditional contracting records may be incomplete or inconsistent. LCP addresses that evidentiary gap by generating a cryptographic fingerprint of the governing terms and binding it to the related payment. The protocol does not dictate contractual terms or determine whether an agreement is enforceable. Instead, it makes the terms discoverable before a transaction and verifiable afterward, while allowing the parties to identify governing law and a preferred dispute-resolution process.

Taken together, the Ambassador Program and LCP point to the next phase of AI governance: building legal infrastructure alongside technical and payment infrastructure. Organizations exploring agentic commerce should consider how their systems identify applicable terms, document an agent’s authority, preserve transaction records, and account for disputes, audits, and regulatory inquiries. At machine speed and scale, a dependable record of who acted and what was agreed is not simply good recordkeeping, it is foundational to trust and enforceability.

In November 2025, the Department of Veterans Affairs entered into an agreement with Baylor Genetics to provide nationwide pharmacogenomic (PGx) and germline genetic testing services across the VA healthcare system. The partnership allowed VA providers to use advanced precision diagnostics to tailor treatment plans for conditions like post-traumatic stress disorder (PTSD) and depression, minimize side effects of medication, and screen for hereditary cancer risks. In doing so, Baylor Genetics processed lab samples and genetic insights for thousands of service members as part of this federal healthcare initiative.

On June 15, 2026, Baylor was the victim of a cyberattack, which compromised the sensitive health and personal information of over 30,000 veterans, including their names, dates of birth, lab results, medical testing details, health insurance information, and partial Social Security numbers. The VA has been working with Baylor to notify the affected individuals, and free credit-monitoring services are available for impacted veterans.

If you receive a breach notification letter, it is always worthwhile to follow the instructions in the letter and sign up for services offered.

Our clients are increasingly experiencing HR identity fraud—when an imposter (sometimes from a foreign adversary nation like North Korea) poses as a candidate for a remote job, often in the information technology space, in order to obtain access to company information or divert funds for a nefarious purpose.

The website Hypr recently issued its “first annual report analyzing hiring and employee fraud in 2026.” The 2026 State of HR Identity Fraud Report outlines the increase of hiring fraud and identifies that a shocking 98% of the 500 U.S. HR executives surveyed “have experienced candidate fraud firsthand.” The report examines how HR identity fraud is detected, how long it takes to identify it, and how to mitigate the risk through established processes.

While 90% of HR leaders have heightened concern over hiring fraud in the last two years, surprisingly, 68% of hiring fraud is discovered by a basic gut instinct—that is, when someone in the process felt something was “off,” as opposed to having established security controls in place.

The survey showed that 42% of cases are not caught pre-hire, and that “less than 3% are flagged the same day.” In addition, only a third are detected between one and three days, “45% require four to six days, and 20% go undetected for up to three weeks, averaging 5.73 days of unmonitored access.” This means that “by the time a red flag is raised, the fraudulent hire has already been provisioned with corporate credentials and internal network access.”

Part of the issue in failing to detect fraud is that there is no single point of supervision, as companies have outsourced a significant amount of work to vendors. “It’s a set of disconnected checks operating in silos. Because no single stage reliably stops candidate fraud, clearing an earlier stage offers no guarantee of identity assurance.” The internal team has specific obligations in the hiring process, and other functions are outsourced. This fragmentation allows threat actors to “infiltrate the onboarding process while accountability is transitioning between teams.”

The survey found that “42% of hiring fraud is detected only after employment begins. Among those post-hire cases, discovery takes an average of four to six days—by which point 98% of fraudulent hires have already been issued company credentials.” This means that the imposter had access to company data for a significant amount of time, which could include proprietary data, sensitive personal information, customer information or employee information. This unauthorized access requires an internal investigation and could lead to required notifications to individuals or customers.

The survey says that “24% of organizations spend one to three months resolving a single fake hire; while the rest lose one to three weeks. Almost no one clears an incident in under a week.”

The conclusion is “Most organizations already possess the core capabilities to solve this challenge. What remains missing is a unified, continuous owner for identity across the moments where HR, IT and Security currently hand it off to one another.” Reorganizing the hiring process to establish a single point of truth and responsibility for HR identity so threat actors can’t insert themselves into the hand-off process is worth serious consideration.

Survey results released in OneTrust’s 2026 AI-Ready Governance Report shows that employees are adopting AI tools more rapidly than company AI governance programs can keep up.

Although organizations indicated they were adopting governance programs to address the use of AI in their organizations, “Some organizations know agents are being used in parts of the business without consistent oversight. Others lack visibility into where and how agents are used.”

Consistent with other research “nearly half of respondents reported at least one incident during the past year in which AI systems or agents took unapproved actions.”

The message of the survey is that you are not alone in the journey to adopt an AI governance program for your organization. Concentrating on risk classification, understanding how employees are using AI, and developing a culture of safety and security while grappling with the rapid adoption of AI will help mitigate risk. The most important thing is to keep tackling it, and don’t get overwhelmed and give up. It is an ongoing, iterative process that will need regular assessment and fine tuning, so dig in and assemble a team committed to working on it for the long term.

Last fall, the University of North Carolina at Chapel Hill School of Law reportedly used ChatGPT, Claude, and Grok as jurors in a mock trial based on a real juvenile case. At the same time, AI-powered jury research platforms are entering the litigation consulting market, offering attorneys and claims professionals rapid assessments of liability, comparative fault, and potential damages.

These tools can provide valuable early insights. They may help legal teams test competing narratives, identify themes that resonate and flag arguments that could be poorly received, all faster and at a lower cost than traditional jury research. However, lawyers should distinguish reliability from validity. An AI simulation may consistently measure individual reactions to a case summary yet still fail to capture how an actual jury reaches a verdict. Real jurors discuss evidence, challenge each other’s assumptions, and revise their views through deliberation. Venue-specific attitudes and community norms also shape outcomes in ways that broad simulated populations may not reflect.

AI jury research is therefore best viewed as a screening tool rather than a substitute for focus groups, mock trials, or other interactive methods. It can inform early case assessment and help counsel decide where deeper research is warranted, but its polished percentages and damages ranges should not be mistaken for predictions of an actual verdict. For legal teams, the key question is not whether AI or traditional research is categorically better, it is whether the chosen method measures the issue that matters. When a case turns on contested evidence, group dynamics, and collective judgment, human deliberation remains central.

Manhattan District Attorney Alvin L. Bragg, Jr., announced on September 14, 2026, the “seizure of 12 domain names of illegal websites used for unlawfully disseminating, publishing, and selling non-consensual celebrity ‘deepfake’ videos.” According to the press release, the individuals under investigation:

[A]llegedly used artificial-intelligence (‘AI’) image and video creation tools to turn pre-existing photos and videos of approximately 1,200 real people into what appear to be hyper-realistic images and videos of those individuals engaging in sexual conduct. They then used these websites to disseminate, publish, and sell these videos and other similar non-consensual intimate imagery (‘NCII’).

In announcing the seizure, Bragg stated,

[Twelve hundred] individuals had their faces and bodies stolen and turned into illegal pornography on 12 different websites – without their knowledge or consent – and today, my Office is announcing that we have seized these websites pursuant to a court order. These horrific violations of privacy follow victims into their careers and personal lives and take an immense toll on emotional and mental wellbeing…Our investigations into these websites and similar operations are ongoing. If you have been a victim, I want you to know that we are here to help. Please contact our Cyber Crime Bureau at 212-335-9600.

This is encouraging news for victims, and I applaud DA Bragg for his effort to combat this horrible problem. If you have been a victim of a deep fake, call the Manhattan DA’s Office, or the consumer division of your Attorney General’s office, depending on where you live. If victims come forward and assert pressure to prosecute those disseminating deep fakes, perhaps a dent can be made to stop them from proliferating and harming victims.

Ransomware group ShinyHunters alleges on its online platform that it has compromised the Florida Department of Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and stole the DMV records of over 200,000 individuals. The threat actor posted a screenshot of Jeffrey Epstein’s DMV record as proof.

The DAVID records of drivers include their name, address, Social Security number, birthdate, driver’s license ID, and other information. ShinyHunters told BleepingComputer they “breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.” ShinyHunters no longer has access to the database and the “password-reset flaw used to compromise accounts is being patched.”

It is believed that ShinyHunters is “targeting other states’ DMV platforms using social engineering attacks.”This is a common strategy for ransomware groups—to concentrate on a particular industry and when they find a way to get into one, they use the same technique to attack others in the same industry.

State DMVs hold vast amounts of valuable personal information. State agencies should train their employees about social engineering attacks, how to identify them, and put robust security measures in place to protect this valuable information of its residents.

On August 26, 2026, LexisNexis won an important, but limited, victory in a proposed class action: a federal court refused to certify a class of people seeking damages for the company’s response to privacy requests which violated the Fair Credit Reporting Act (FCRA). The court did not decide whether LexisNexis had violated the FCRA, only deciding that the plaintiffs could not pursue their claims as the proposed class.

The facts began with Daniel’s Law, a New Jersey statute that protects the home addresses and personal telephone numbers of judges, prosecutors, police officers, certain other public officials, and their immediate family members. Covered individuals may ask a business to stop disclosing that information, and the business generally has ten days to comply.

Beginning in December 2023, thousands of covered individuals allegedly sent LexisNexis written requests to suppress their protected information. According to the plaintiffs, these were straightforward privacy requests, not requests to freeze their consumer files. Nevertheless, LexisNexis reportedly placed security freezes on approximately 18,607 files, maintaining that it could not redact the protected information from consumer reports without doing so.

Because a security freeze restricts access to a consumer report, it can affect banks, insurers, and others evaluating whether to provide credit or services. As a result, the plaintiffs alleged that the unrequested freezes violated the FCRA. However, their effort to proceed as a class ran into a proof problem. The record showed only 13 people had been denied insurance because of the freezes. For everyone else, the court would have needed individualized evidence showing that the person sought credit or services, the freeze blocked access to necessary information, and the blockage caused a denial. Those individual questions defeated the broader class, while a 13-person subclass was too small to satisfy Rule 23’s numerosity requirement.

For companies responding to statutory privacy requests, the decision illustrates how a request directed at specific information can implicate a broader consumer-reporting process. LexisNexis maintained that it could not remove the protected information from its consumer reports without placing a security freeze, and the court did not decide whether that approach violates the FCRA. The takeaway is less about prescribing a particular response and more about understanding how privacy workflows operate across connected systems. Companies should assess whether the mechanism used to honor a request changes access to a consumer report or related service and remember that a narrow request does not always have narrow effects.

California Senate Bill 690 is finally moving forward. The original bill would have broadly exempted disclosures made for a “commercial business purpose,” as defined under the California Consumer Privacy Act (CCPA), potentially eliminating many California Invasion of Privacy Act (CIPA) claims involving common website technologies. The amended version is narrower but could still offer meaningful relief to businesses facing the recent wave of CIPA litigation.

Under the amended bill, private plaintiffs could no longer bring claims under California Penal Code § 638.51 alleging that conduct on websites or online or mobile applications constitutes the unlawful use of a pen register or trap and trace device. Those claims could be brought only by the California Attorney General. The change would apply retroactively to certain pending lawsuits filed within the two years prior to the bill’s operative date. Plaintiffs could still pursue claims under § 631(a), although businesses often have stronger defenses to those claims, including consent and arguments that the information collected was not communication “content” or was not intercepted “in transit.”

SB 690 was approved unanimously by both the Assembly and Senate and has been sent to the Governor’s desk for signature, which must be completed by September 30, 2026. If enacted, it would take effect January 1, 2027. While it would not end CIPA website-tracking litigation, the bill signals legislative support for curbing private lawsuits based on increasingly common pen register and trap and trace theories. Businesses should continue monitoring the bill while reviewing their online tracking technologies, consent mechanisms, disclosures, and vendor relationships.

A recent article released by the Palo Alto Threat Research Center found that, between January and April 2026, a coordinated effort by threat actors was successful in launching vishing attacks using Microsoft Teams accounts to compromise companies across multiple industries.

The threat actor uses an external Teams account and creates a chat “using identities designed to mirror legitimate internal support units.” Usually these include names like help desk, IT support, or something else that makes the user believe the chat is coming from an internal IT support professional. The chat has a sense of urgency that something needs to be done on the user’s computer. The threat actors then call the victim and, if the user picks up, the scam commences. The threat actor then guides the employee through steps to allow remote control or to download malicious malware. If the caller doesn’t pick up, the threat actor calls back multiple times, scaring the user into believing it is urgent.

Once in the system, the threat actor has full control over the user’s access and can exfiltrate data, deploy ransomware, and start a ransomware attack.

Palo Alto has dubbed this attack as “Spring Ring.” It found that between January and April 2026, Spring Ring targeted many organizations across different industries, and more than 150 individual employees were called. In addition, this coordinated attack shows that threat actors are using legitimate tools to lull victims into believing the chats and calls are real.

It is crucial to be aware of the evolving nature of threats, including social engineering and the rise of vishing attacks, to understand that threat actors are using legitimate tools and to distrust any request for remote access to your computer. When in doubt, ignore the chat, and call your IT professional directly to a known number. If IT is really trying to get in touch with you, they will be very happy that you are calling them directly rather than falling victim to a vishing scheme.