← Carolina Clear Tech

Legal & Privacy Brief

2026-02-18

Listen to this brief (14:08)

Download MP3
Show Notes

Show Notes - 2026-02-18

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - 2026-02-18

Today: EPIC defended New York's surveillance pricing transparency law before the Second Circuit in National Retail Federation v. James, arguing the First Amendment does not bar states from requiring businesses to disclose algorithmic pricing based on personal data. Judge Rakoff of the Southern District of New York issued a written opinion holding that documents prepared using a consumer AI tool are not protected by attorney-client privilege, making AI-generated legal research discoverable in litigation. Wisconsin's age-verification bill S.B. 130 / A.B. 105 lost its VPN-blocking provision under pressure but still heads to Governor Evers with invasive identification requirements intact.


Litigation Updates

National Retail Federation v. James (2d Cir.) - Surveillance Pricing Transparency Law

EPIC filed an amicus brief in the Second Circuit Court of Appeals in National Retail Federation v. James, arguing that New York's surveillance pricing transparency law does not violate the First Amendment. The law requires businesses to disclose to consumers when pricing for goods and services is set using surveillance pricing, a practice in which companies use aggregated personal data including purchase history, location signals, behavioral profiles, and device identifiers to calculate individualized prices. The National Retail Federation is challenging the requirement as impermissible compelled speech. EPIC's brief counters that New York's consumer protection interest in pricing transparency justifies the disclosure mandate and that First Amendment analysis for commercial disclosure requirements differs substantially from speech restrictions. The Second Circuit's ruling will establish significant precedent for how far states can reach in requiring transparency around algorithmic consumer-facing systems.

United States v. Heppner (S.D.N.Y.) - Consumer AI Tool Outputs Not Protected by Attorney-Client Privilege

Judge Jed Rakoff of the Southern District of New York issued a written opinion on February 17, 2026, holding that documents defendant Bradley Heppner prepared using the consumer version of Claude for legal research are not protected by attorney-client privilege. The written opinion followed Rakoff's earlier bench ruling denying the privilege claim. The core legal issue is whether use of a consumer AI tool to conduct legal research constitutes a confidential communication with an attorney made for the purpose of obtaining legal advice. Rakoff held it does not. Documents generated through a consumer AI tool outside a formal attorney-client relationship are therefore discoverable in litigation. The practical effect is direct for any organization that uses commercial AI tools for compliance analysis, regulatory research, or legal memo drafting without routing that work through counsel: those outputs are available to opposing parties in discovery.

ECtHR - Green Alliance v. Bulgaria (Application No. 6580/22)

The European Court of Human Rights issued a decision in Green Alliance v. Bulgaria, Application No. 6580/22, catalogued on GDPRhub as a privacy law decision under the European Convention on Human Rights with GDPR-adjacent implications. The case originates from Bulgaria and was decided in early 2026; the full opinion is indexed on Bailii at ECHR/2026/30. Substantive opinion text was not available in the retrieved source content. Organizations with EU operations or EU data subjects should review the full opinion at the Bailii reference, as ECtHR privacy jurisprudence increasingly intersects with GDPR enforcement positions taken by national data protection authorities, particularly in cases involving civil society organizations, environmental advocacy groups, and organizational handling of member or supporter personal data.


Regulatory Guidance

12 AI-Discovered OpenSSL Zero-Days in January 27, 2026 Security Release

An AI system discovered and responsibly disclosed 12 new zero-day vulnerabilities in OpenSSL, all included in the January 27, 2026 OpenSSL security release. Ten of the 12 were assigned CVE-2025 identifiers; 2 received separate designations. The discoverer reported the vulnerabilities to the OpenSSL team during fall and winter 2025 under coordinated disclosure. The volume is significant: 12 zero-days from a single AI-assisted research cycle represents a material increase in disclosure velocity compared to historical OpenSSL release cadences.

The compliance implication is patch urgency. OpenSSL is a core dependency in virtually every enterprise software stack, web server, VPN appliance, load balancer, and security tool. Organizations that lack automated software composition analysis across their environments will not be able to quickly assess exposure. PCI DSS, HIPAA, SOC 2, and similar frameworks carry patching obligations tied to critical vulnerability disclosures; a release of this scope from a foundational cryptographic library triggers those obligations.


Policy Changes

Wisconsin S.B. 130 / A.B. 105 - Age Verification Bill Advances Without VPN Provision

Wisconsin's S.B. 130 / A.B. 105, which requires age verification for websites hosting content categorized as "harmful to minors," had its VPN-blocking provision removed before Senate passage following opposition from the EFF, security professionals, and industry stakeholders. The original bill required websites subject to the age-verification mandate to block users connecting via VPN. The EFF's letter to the Wisconsin Legislature identified this as technically unworkable: websites cannot reliably determine whether a VPN user is physically located in Wisconsin versus another state or country, so compliance would require over-broad blocking of commercial VPN IP ranges or restrictions on all Wisconsin user access to avoid liability. The VPN provision was stripped; the bill passed the State Assembly and awaited a Senate vote as of February 18, 2026, then proceeded toward Governor Tony Evers' desk. The EFF continues to oppose the bill in its remaining form.

The remaining requirements create substantial compliance obligations for website operators. The bill mandates invasive age verification using government IDs, financial information, or biometric identifiers before granting access to covered content. The bill's definition of "harmful to minors" extends beyond explicit adult material to content that merely describes sex or depicts human anatomy. This scope sweeps in medical information, health education, harm reduction content, and user-generated discussions on human biology, creating ambiguous compliance exposure for a wide range of website operators. Websites face a structural compliance dilemma: over-collect personal data to satisfy age verification, or restrict all Wisconsin user access to avoid liability.


Compliance Takeaways