Get tomorrow's brief in your inbox
Today: EPIC defended New York's surveillance pricing transparency law before the Second Circuit in National Retail Federation v. James, arguing the First Amendment does not bar states from requiring businesses to disclose algorithmic pricing based on personal data. Judge Rakoff of the Southern District of New York issued a written opinion holding that documents prepared using a consumer AI tool are not protected by attorney-client privilege, making AI-generated legal research discoverable in litigation. Wisconsin's age-verification bill S.B. 130 / A.B. 105 lost its VPN-blocking provision under pressure but still heads to Governor Evers with invasive identification requirements intact.
National Retail Federation v. James (2d Cir.) - Surveillance Pricing Transparency Law
EPIC filed an amicus brief in the Second Circuit Court of Appeals in National Retail Federation v. James, arguing that New York's surveillance pricing transparency law does not violate the First Amendment. The law requires businesses to disclose to consumers when pricing for goods and services is set using surveillance pricing, a practice in which companies use aggregated personal data including purchase history, location signals, behavioral profiles, and device identifiers to calculate individualized prices. The National Retail Federation is challenging the requirement as impermissible compelled speech. EPIC's brief counters that New York's consumer protection interest in pricing transparency justifies the disclosure mandate and that First Amendment analysis for commercial disclosure requirements differs substantially from speech restrictions. The Second Circuit's ruling will establish significant precedent for how far states can reach in requiring transparency around algorithmic consumer-facing systems.
United States v. Heppner (S.D.N.Y.) - Consumer AI Tool Outputs Not Protected by Attorney-Client Privilege
Judge Jed Rakoff of the Southern District of New York issued a written opinion on February 17, 2026, holding that documents defendant Bradley Heppner prepared using the consumer version of Claude for legal research are not protected by attorney-client privilege. The written opinion followed Rakoff's earlier bench ruling denying the privilege claim. The core legal issue is whether use of a consumer AI tool to conduct legal research constitutes a confidential communication with an attorney made for the purpose of obtaining legal advice. Rakoff held it does not. Documents generated through a consumer AI tool outside a formal attorney-client relationship are therefore discoverable in litigation. The practical effect is direct for any organization that uses commercial AI tools for compliance analysis, regulatory research, or legal memo drafting without routing that work through counsel: those outputs are available to opposing parties in discovery.
ECtHR - Green Alliance v. Bulgaria (Application No. 6580/22)
The European Court of Human Rights issued a decision in Green Alliance v. Bulgaria, Application No. 6580/22, catalogued on GDPRhub as a privacy law decision under the European Convention on Human Rights with GDPR-adjacent implications. The case originates from Bulgaria and was decided in early 2026; the full opinion is indexed on Bailii at ECHR/2026/30. Substantive opinion text was not available in the retrieved source content. Organizations with EU operations or EU data subjects should review the full opinion at the Bailii reference, as ECtHR privacy jurisprudence increasingly intersects with GDPR enforcement positions taken by national data protection authorities, particularly in cases involving civil society organizations, environmental advocacy groups, and organizational handling of member or supporter personal data.
12 AI-Discovered OpenSSL Zero-Days in January 27, 2026 Security Release
An AI system discovered and responsibly disclosed 12 new zero-day vulnerabilities in OpenSSL, all included in the January 27, 2026 OpenSSL security release. Ten of the 12 were assigned CVE-2025 identifiers; 2 received separate designations. The discoverer reported the vulnerabilities to the OpenSSL team during fall and winter 2025 under coordinated disclosure. The volume is significant: 12 zero-days from a single AI-assisted research cycle represents a material increase in disclosure velocity compared to historical OpenSSL release cadences.
The compliance implication is patch urgency. OpenSSL is a core dependency in virtually every enterprise software stack, web server, VPN appliance, load balancer, and security tool. Organizations that lack automated software composition analysis across their environments will not be able to quickly assess exposure. PCI DSS, HIPAA, SOC 2, and similar frameworks carry patching obligations tied to critical vulnerability disclosures; a release of this scope from a foundational cryptographic library triggers those obligations.
Wisconsin S.B. 130 / A.B. 105 - Age Verification Bill Advances Without VPN Provision
Wisconsin's S.B. 130 / A.B. 105, which requires age verification for websites hosting content categorized as "harmful to minors," had its VPN-blocking provision removed before Senate passage following opposition from the EFF, security professionals, and industry stakeholders. The original bill required websites subject to the age-verification mandate to block users connecting via VPN. The EFF's letter to the Wisconsin Legislature identified this as technically unworkable: websites cannot reliably determine whether a VPN user is physically located in Wisconsin versus another state or country, so compliance would require over-broad blocking of commercial VPN IP ranges or restrictions on all Wisconsin user access to avoid liability. The VPN provision was stripped; the bill passed the State Assembly and awaited a Senate vote as of February 18, 2026, then proceeded toward Governor Tony Evers' desk. The EFF continues to oppose the bill in its remaining form.
The remaining requirements create substantial compliance obligations for website operators. The bill mandates invasive age verification using government IDs, financial information, or biometric identifiers before granting access to covered content. The bill's definition of "harmful to minors" extends beyond explicit adult material to content that merely describes sex or depicts human anatomy. This scope sweeps in medical information, health education, harm reduction content, and user-generated discussions on human biology, creating ambiguous compliance exposure for a wide range of website operators. Websites face a structural compliance dilemma: over-collect personal data to satisfy age verification, or restrict all Wisconsin user access to avoid liability.
Patch the January 27, 2026 OpenSSL release now. Twelve AI-discovered zero-days, 10 with CVE-2025 identifiers, were patched in that release. Inventory all OpenSSL instances across your environment including third-party appliances. Document patching in your compliance records; this release triggers critical vulnerability patching obligations under PCI DSS, HIPAA, and SOC 2.
Restructure AI-assisted legal work through counsel. Judge Rakoff's written opinion in Heppner (S.D.N.Y.) establishes that consumer AI outputs are not attorney-client privileged and are discoverable. Route AI-generated legal analysis, compliance memos, and regulatory research through in-house or outside counsel. Document that structure with a written policy. Update litigation holds to treat AI-generated work product as discoverable material.
Audit algorithmic pricing for surveillance pricing exposure. The Second Circuit is weighing New York's disclosure requirement for surveillance pricing in National Retail Federation v. James. If your business uses data-driven or personalized pricing, document what personal data inputs drive pricing decisions and prepare consumer-facing disclosure language. Similar laws are advancing independently of this litigation.
Monitor Wisconsin S.B. 130 / A.B. 105 for Governor Evers' action. If signed, websites accessible to Wisconsin users hosting content within the bill's broad "harmful to minors" definition face age-verification requirements with significant personal data collection implications. Identify potentially covered content now and evaluate minimum-data-collection age verification options before a signing deadline triggers enforcement exposure.
Track ECtHR decisions through GDPRhub for EU data subject exposure. Green Alliance v. Bulgaria (Application No. 6580/22) and similar ECtHR privacy rulings shape GDPR enforcement postures at national DPAs across EU member states. Organizations with EU data subjects should include ECtHR jurisprudence in their compliance monitoring, not only formal GDPR enforcement actions from DPAs.