Get tomorrow's brief in your inbox
Today: The U.K. threatens tech executives with imprisonment for failing to remove nonconsensual intimate images within two days. Senator Chuck Grassley launches inquiry into Meta, Amazon, TikTok, and five other tech giants for submitting millions of deficient child exploitation reports to NCMEC. Avis data breach settlement offers up to $5,000 for documented losses.
U.K. Government Threatens Tech Executives With Imprisonment Over Intimate Images
The U.K. government formally submitted amendments to a crime bill that would allow imprisonment of tech executives who fail to remove nonconsensual intimate images published on their platforms. Communications regulator Ofcom is cracking down on the spread of these images following the Grok scandal, which led to millions of "nudified" images of women and children being circulated worldwide. The law mandates tech companies take down nonconsensual intimate images within two days or face fines, service blockage, and now imprisonment. In February, Prime Minister Keir Starmer called the mass distribution of such images a "national emergency." On January 13, Ofcom announced a probe of Grok's practices, owned by Elon Musk's xAI. Tech executives who commit the offense without a reasonable excuse could face imprisonment or fines, or both, marking a significant escalation from the February announcement that mentioned only fines and service blockage.
Florida Attorney General Investigates OpenAI Over ChatGPT Role in Mass Shooting
Florida Attorney General James Uthmeier announced an investigation into OpenAI's ChatGPT for potentially playing a role in a mass shooting at Florida State University. The family of one victim plans to sue OpenAI because the gunman allegedly constantly communicated with ChatGPT in the days leading to the shootings. A lawyer for the victim's family stated he has "reason to believe that ChatGPT may have advised the shooter how to commit these heinous crimes." Uthmeier said he plans to issue subpoenas in the coming days. OpenAI responded that more than 900 million people use ChatGPT each week and that the company builds ChatGPT to understand people's intent and respond in a safe and appropriate way. AI chatbots have allegedly played a role in multiple suicides and murders, including cases where ChatGPT reportedly encouraged self-harm in users with mental illness.
Senator Grassley Launches Inquiry Into Eight Tech Giants for Deficient CSAM Reporting
Senate Judiciary Committee chair Chuck Grassley (R-IA) launched a congressional inquiry into Meta, Amazon AI Services, TikTok, Snapchat, Discord, X.AI, Grindr, and Roblox for allegedly failing to supply adequate information to the National Center for Missing and Exploited Children (NCMEC) cyber tipline. The eight companies submitted more than 17 million reports of suspected online child exploitation in 2025, representing 81% of reports received through NCMEC's Cyber Tipline, but allegedly failed to provide location data and other information on users and suspects. NCMEC said the tech giants also failed to share CSAM in AI training and did not report "sadistic online exploitation targeting children." Meta turned over nearly 11 million reports but many allegedly contained "consistency and quality" issues. Amazon AI Services submitted more than 1.1 million tips but allegedly none could be acted upon because Amazon failed to provide location or suspect information. TikTok turned over 3.6 million reports but allegedly consistently reported incidents that did not relate to child exploitation. Grassley is compelling the eight tech firms to respond to NCMEC's charges and offer detailed reports on their plans to evolve their handling of cyber tips this year.
Avis Data Breach Class Action Settlement (Case No. 2:24-cv-09243)
Avis agreed to a class action settlement to resolve claims that it failed to prevent a 2024 data breach that compromised sensitive customer information, including credit card numbers and expiration dates. The data breach occurred between August 3 and August 6, 2024. Plaintiffs claim Avis failed to implement reasonable cybersecurity measures. Avis has not admitted wrongdoing but agreed to pay an undisclosed sum. Class members can receive up to $5,000 for documented, unreimbursed monetary losses resulting from the data breach occurring between August 3, 2024, and the settlement claim deadline of June 21, 2026. Class members who did not experience out-of-pocket losses can receive a cash payment distributed on a pro rata basis. The deadline for exclusion and objection is May 22, 2026. The final approval hearing is scheduled for July 28, 2026.
Washington Judge Narrows Amazon Alexa Class Action Over Secret Recordings
U.S. District Judge Robert S. Lasnik significantly narrowed a class action lawsuit accusing Amazon of secretly recording Alexa users' personal conversations. Judge Lasnik found that Amazon had disclosed the possibility of accidental device activations and that only some unregistered users had adequately alleged individual wiretap claims. The judge allowed some unregistered users' individual state and federal wiretap claims to proceed while dismissing plaintiffs' class allegations that Amazon engaged in unfair or deceptive conduct under the Washington Consumer Protection Act. The lawsuit claims Amazon violated state consumer protection laws by failing to disclose that Alexa-enabled devices are susceptible to "false wakes," in which they mistakenly detect other sounds as the wake word, and that they record a "split second of audio" before the wake word is spoken. Lasnik found the alleged conduct could not be considered unfair or deceptive because users were informed during the registration process about the existence of "false wakes," and plaintiffs failed to identify any misrepresentations by Amazon regarding how frequently this phenomenon occurs. The judge also found Amazon clearly and repeatedly disclosed that it retained audio, interactions, and other Alexa data and that it used the data to improve its services.
NFL Coach Brian Flores Petition on Arbitration Agreement Authority
Former Miami Dolphins head coach Brian Flores filed a racial discrimination lawsuit in 2022 against the NFL, Dolphins, New York Giants, and Denver Broncos, alleging his status as a Black man played a role in hiring and firing decisions. The NFL and teams moved to compel arbitration, contending that Flores accepted NFL Commissioner Roger Goodell's authority over employment disputes when he signed coaching contracts. In March 2023, a federal district judge compelled arbitration as to claims with specific employment contracts but did not compel arbitration of Flores' claims against the Broncos, Giants, Texans, and NFL. The U.S. Court of Appeals for the 2nd Circuit affirmed Flores' victory in August 2025, holding that the league's arbitration agreement was an arbitration agreement "in name only" and is unenforceable under the Federal Arbitration Act. The provision "fails to bear even a passing resemblance to traditional arbitral practice" by submitting Flores's statutory claims to the unilateral substantive and procedural discretion of the principal executive officer of one of his adverse parties, the NFL. In January, the three teams and NFL asked the Supreme Court to weigh in, contending the 2nd Circuit claimed an authority to subjectively determine whether an arbitration agreement is enforceable that it doesn't actually have.
San Mateo County PFAS Firefighter Gear Class Action (Case No. 3:26-cv-01654)
The County of San Mateo filed a class action lawsuit against 3M Company, DuPont De Nemours Inc., and 17 other companies claiming they manufactured and sold firefighter gear containing toxic and carcinogenic per- and polyfluoroalkyl substances (PFAS). The county claims the companies knew for decades about the dangers of PFAS but failed to warn firefighters and other public entities that purchased and used the gear. The county argues the companies conspired to cover up and conceal the risks of PFAS, which have been linked to cancer, immune system disorders, and other harmful health conditions. The county claims the companies' firefighter gear, including hoods, helmets, coats, pants, gloves, boots, and reflective tape, was treated with PFAS to make it water- and oil-repellent. The PFAS in the gear did not remain contained but rather leached, shed, crumbled, abraded, off-gassed, and migrated out of the gear, contaminating fire stations, fire trucks, equipment, property, and firefighters. The county wants to represent a nationwide class or California class of counties, cities, municipalities, fire districts, and other public or private entities that have purchased or paid for firefighter Turnout Gear that contained PFAS.
White House AI Framework Proposes Industry-Friendly Legislation
The White House released a comprehensive national framework for artificial intelligence (AI) on March 20, 2026, three months after calling for legislative recommendations in an executive order that sought to curb certain state AI laws. The framework proposes preemption of "cumbersome" state AI laws, limits on liability for developers, and an overall aversion to heavy federal regulations. The framework has received support from influential Republicans in Congress, including House Speaker Mike Johnson (R-La.) and Sen. Ted Cruz (R-Texas). Sen. Maria Cantwell (D-Wash.), ranking member of the Senate's commerce committee, said the framework "identifies key areas to address." The National AI Legislative Framework directs Congress to "prevent the United States government from coercing technology providers, including AI providers, to ban, compel, or alter content based on partisan or ideological agendas."
Section 702 FISA Reauthorization Faces Reform Pressure
Section 702 of the Foreign Intelligence Surveillance Act (FISA), which allows warrantless surveillance of Americans' communications with foreign persons overseas, is up for renewal. The Electronic Frontier Foundation (EFF) is urging Congress not to pass any bill that reauthorizes Section 702 without substantial reforms. Section 702 is marked by problems, loopholes, and compliance issues. The National Security Agency (NSA) collects full conversations being conducted by surveillance targets overseas and stores them, allowing the Federal Bureau of Investigation (FBI) to query and read the U.S. side of that communication without a warrant. People who have been spied on by this program will not know and have very few ways of finding out. EFF and other civil liberties advocates have been trying for years to ensure people know when data collected through Section 702 is used as evidence against them. The intelligence community and its defenders in Congress seem more interested in defending their rights to read private communications than in protecting privacy rights.
North Korean Hackers Use Six-Month Social Engineering Operation to Steal $280 Million from Drift
The Drift cryptocurrency platform published a post-mortem describing an extensive, months-long operation by North Korean hackers (UNC4736, also tracked as AppleJeus or Citrine Sleet) that culminated in the theft of more than $280 million. The operation began six months ago when Drift was approached at a cryptocurrency conference by members of a company claiming to focus on quantitative trading. The individuals who approached Drift were technically fluent, had deep knowledge of Drift, and had "verifiable professional backgrounds." The investigation revealed North Korean officials sought out Drift contributors at multiple major industry conferences in multiple countries over six months. The individuals who met them in person were not North Korean; the country's government allegedly used intermediaries to conduct face-to-face relationship building. The profiles used had fully constructed identities including employment histories, public-facing credentials, and professional networks. Drift officials created a Telegram group after their first meeting and had months of conversations around trading strategies. Drift officially onboarded the company in December 2025 and January 2026. The two sides continued to share information until April 1, when the $280 million theft was launched. The trading company scrubbed the entire Telegram chat with Drift after the exploit was launched. A contributor may have been compromised after copying a code repository shared by the trading firm. Another contributor was urged to download a TestFlight application that may have been malicious.
Trump Administration AI Policy Contradictions
The Trump administration's AI policy demonstrates contradictions between deregulation rhetoric and government control efforts. In March, the administration released its National AI Legislative Framework, directing Congress to prevent the United States government from coercing technology providers to ban, compel, or alter content based on partisan or ideological agendas. In February 2025, Vice President Vance endorsed a "deregulatory flavor" of AI policy. The administration released an AI Action Plan pledging to "dismantle unnecessary regulatory barriers" and "onerous regulation." Three days into his second term, President Trump revoked an Executive Order from President Biden which established government-wide effort to regulate AI. However, the administration demonstrates a contradictory impulse to control AI. Vice President Vance demanded that "AI must remain free from ideological bias." President Trump's AI Action Plan directed AI companies to design their models "to pursue objective truth rather than social engineering agendas." In July, President Trump issued an Executive Order on Preventing Woke AI in the Federal Government, prohibiting government procurement of AI models unless they are ideologically "neutral." In January, Secretary of Defense Hegseth issued a memo instructing the Department of Defense to "utilize models free from usage policy constraints" and banning the DoD from employing AI models which incorporate ideological "tuning." In late February, Hegseth threatened to cut ties with Anthropic unless the company allowed the military to use its AI for "all lawful purposes." When Anthropic refused, President Trump directed federal agencies to "IMMEDIATELY CEASE all use of Anthropic's technology."
Federal Court Blocks Nexstar-Tegna Merger Over Media Consolidation Concerns
Chief Judge Troy Nunley in U.S. District Court for the Eastern District of California issued a temporary restraining order blocking Nexstar's $6.2 billion purchase of Tegna from proceeding. FCC chair Brendan Carr illegally ignored remaining U.S. media consolidation laws to rubber stamp the merger. DirecTV filed suit saying consolidation in local broadcast TV will erode competition in the local broadcast TV sector, harming product quality, opinion diversity, and labor, while resulting in higher overall prices in exchange for worse product. Nexstar admits the merger will greatly increase its "scale" and "leverage," the ability to force its TV distribution customers to pay higher fees for local news, live sports, and other content. DirecTV alleges Nexstar will shut down local newsrooms in dozens of markets, reducing the amount, variety, and quality of local broadcast news. The deal would combine Nexstar's stable of more than 200 local stations with Tegna's 65 outlets in major markets nationwide, blowing past restrictions that no company can control more than 39 percent of households (the new combined company reaches 54.5 percent). The companies are also being sued by a coalition of eight attorneys general and consumer groups.