← Carolina Clear Tech

Legal & Privacy Brief

2026-06-03

Listen to this brief (26:26)

Download MP3
Show Notes

Show Notes - 2026-06-03

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - June 3, 2026

Today: The Supreme Court allowed Alabama to use a congressional map that lower courts found racially discriminatory, overturning district court findings of intentional race-based vote dilution. The White House released a scaled-back AI executive order requiring 30-day voluntary pre-release testing of frontier models, down from the previously proposed 90-day mandate. Red Hat pulled 32 packages downloaded 117,000 times weekly after attackers compromised a GitHub account to distribute credential-stealing malware through its software distribution pipeline.

Enforcement Actions

Teva Pharmaceuticals QVAR Antitrust Settlement

Teva Pharmaceuticals agreed to pay $35 million to resolve antitrust claims that it engaged in anticompetitive behavior to prevent generic competition for its QVAR asthma medication. The settlement addresses allegations that Teva used exclusionary tactics to maintain market dominance and keep prices artificially high for the respiratory drug.

Texas v. Meta - WhatsApp Encryption Deception Claims

Texas filed suit against Meta and WhatsApp alleging the companies deceptively marketed WhatsApp as a fully private messaging platform while allegedly maintaining access to users' communications. The state claims Meta violated the Texas Deceptive Trade Practices Act by representing end-to-end encryption as absolute while allegedly retaining technical capabilities to access message content.

Litigation Updates

Supreme Court Permits Alabama Redistricting Map Despite Discrimination Findings

The Supreme Court cleared Alabama to use a congressional map in the 2026 elections that lower courts found violated Section 2 of the Voting Rights Act and the Fourteenth Amendment through intentional race-based vote dilution. In a four-page unsigned order, the Court held that the district court's analysis departed from the Supreme Court's April 29 decision in Louisiana v. Callais, which made it harder for plaintiffs to prove Voting Rights Act violations. Justice Sotomayor dissented, joined by Justices Kagan and Jackson, arguing the majority "disregards both democratic values and the rule of law" and paves the way toward "a chaotic election." The lower court had found Alabama divided Black voters in the southern part of the state among three congressional districts, leaving them a minority in each, and ordered the state to use a map created by a court-appointed special master instead.

Supreme Court Death Penalty Trend: Oral Arguments vs. Emergency Docket

The Supreme Court continued a trend of siding with death row inmates in oral argument cases while denying emergency stay requests. In Whitton v. Dixon, the Court vacated an 11th Circuit opinion and remanded for additional proceedings after finding the circuit court improperly considered DNA evidence not presented to the jury. In Pitchford v. Cain, a 5-4 decision threw out the conviction and death sentence after finding the trial judge failed to properly analyze whether the prosecutor violated constitutional protections against racial discrimination in jury selection under Batson. However, the Court has denied over 75 emergency stay requests since July 2024 without noted dissent, even as 47 people were executed in 2025 (the highest total since 2009) and 14 have been executed in 2026. In Guerrero v. Busby, the Court granted Texas's request to vacate a 5th Circuit stay, clearing the way for execution hours later despite the inmate's claim of intellectual disability.

D.C. Circuit Blocks Transgender Military Ban as Unconstitutional Animus

The U.S. Court of Appeals for the D.C. Circuit ruled that Defense Secretary Pete Hegseth's policy removing transgender members of the military was fueled by unconstitutional animus and "the bare desire to harm a politically unpopular group." The three-judge panel divided over scope, opting in a 2-1 ruling authored by Judge Robert Wilkins to protect only the specific plaintiffs rather than issue a nationwide injunction, explicitly seeking to avoid running afoul of Supreme Court concerns about broad injunctive relief. The decision followed the Supreme Court's earlier lifting of a Washington state federal judge's nationwide order blocking the ban.

Amazon Subscribe & Save Deceptive Pricing Class Action

A class action lawsuit alleges Amazon misleads consumers into purchasing Subscribe & Save items through deceptive acts and omissions related to pricing. The complaint claims Amazon's subscription pricing model contains undisclosed terms or price manipulations that result in consumers paying more than advertised or receiving less value than represented.

Airborne Vitamin C Mislabeling Class Action

RB Health faces a class action alleging its Airborne supplements contain less vitamin C than advertised on product labels. The lawsuit claims the company violated state consumer protection laws and FDA labeling requirements by misrepresenting the actual dosage of the key ingredient consumers rely on for immune support claims.

Regulatory Guidance

White House AI Executive Order: 30-Day Voluntary Testing Framework

The White House released an AI executive order establishing a voluntary framework for government testing of frontier AI models within 30 days of public release, down from the previously proposed 90-day mandatory period. The order directs AI developers to collaborate with government to select "trusted partners" for classified critical infrastructure cybersecurity testing and cyber threat tracking. It mandates Treasury Department leadership of an AI cybersecurity clearinghouse to facilitate vulnerability scanning and patching prioritization across executive branch systems. The order explicitly states the framework should not be seen as authorizing "creation of a mandatory governmental licensing, preclearance, or permitting requirement" for AI model development or release. The revised order followed internal conflict with former AI czar David Sacks, who told the president industry was concerned the initial version would harm innovation and competitiveness with China. The order directs ONCD, CISA, and OMB to locate federal grant funding for advanced AI vulnerability detection. Industry had pushed for a 14-day review period.

Illinois Children's Social Media Safety Act Passed

The Illinois legislature passed HB 5511, the Children's Social Media Safety Act, which Governor JB Pritzker is expected to sign. The law requires strong default privacy settings for minors and mandates device-level age assurance. Devices must provide an interface at account setup for the primary user to self-report birth date or age, then with user consent share that age-range signal with online platforms to provide age-appropriate safeguards. The law prohibits addictive design features for minors, including addictive feeds and overnight push notifications. The provisions mirror EPIC's Model Age-Appropriate Design Code and represent a state-level response to platform failures to protect children online.

California AB 1856: Open Source Exemption, Expanded Age-Gating

California amended AB 1856 to exempt open-source operating systems from last year's AB 1043 age-bracketing requirements, but expanded age-gating mandates to web browsers and websites. The amendment defines "operating system provider" to exclude "a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software." However, the bill still requires browsers and websites to request and collect user ages, extending California's age verification regime beyond the original operating system and app store scope. EFF continues to oppose the expansion as unconstitutional barriers to accessing lawful speech, threats to anonymity, and pressure to collect sensitive user data. The amendment passed the Assembly 68-1 on May 28 and moves to the Senate.

Red Hat Software Supply Chain Compromise

Red Hat pulled 32 packages from its software distribution pipeline after attackers used a compromised GitHub account to distribute credential-stealing malware to developers. The packages were downloaded approximately 117,000 times weekly before removal. The attack used a variant of the Mini Shai-Hulud self-propagating worm whose source code was published May 12 by cybercriminal group TeamPCP, which announced a $1,000 contest on BreachForums for the largest supply chain attack using the code. The malware, renamed Miasma, differed only cosmetically from the TeamPCP original while retaining credential-stealing functionality. Red Hat stated "based on current findings, no actions from customers are required" but the incident joins a cascade of supply chain intrusions since September 2025, including attacks on LiteLLM (leading to Mercor breach), axios JavaScript library (attributed to North Korean hackers), GitHub itself (TeamPCP breach via malicious VS Code extension), and OpenAI employee devices (TanStack library compromise).

Commission Recommends $11 Billion Cyber Force

A commission by the Center for Strategic and International Studies and Foundation for Defense of Democracies recommended establishing a dedicated U.S. Cyber Force military branch costing up to $11 billion to start, with approximately 30,000 personnel (including 5,000 National Guard and up to 6,000 civilians). The report states the force could align with the Department of the Army or stand as its own department and would take 12-18 months to establish. The commission assumed presidential authorization and focused on implementation rather than debating necessity. Bipartisan frustration has grown over existing military branches' failure to provide U.S. Cyber Command with ready personnel. Sen. Kirsten Gillibrand (D-NY) indicated she will offer an amendment mirroring the recommendations during next week's closed-door Senate Armed Services Committee markup. The House Armed Services Committee takes up its draft Thursday. The fiscal 2025 defense bill also tasked the National Academies with a separate feasibility study expected to conclude in coming months.

Privacy Developments

UK ICO Draft Guidance on Automated Decision-Making

EPIC submitted feedback on the UK Information Commissioner's Office consultation addressing Articles 22A-22D of the UK GDPR on automated decision-making (ADM) and profiling. EPIC criticized the guidance for an overly narrow scope that only covers ADM with consequential effects and no meaningful human involvement, creating a loophole when human actors simply execute ADM conclusions. EPIC argued the guidance underestimates individual harm from contesting unfair decisions, noting people may lose access to housing or public benefits during appeals or miss irreversible opportunities like job positions filled during review. The guidance implies children's personal information may be used to influence their choices under certain conditions. EPIC stated "there are no conditions that make manipulating children acceptable. None." EPIC challenged the core assumption that ADMs make processes more efficient, effective, and fair, noting systems lack transparency and accountability compared to human decision-makers. EPIC asked what acceptable margin of error exists for life-changing machine decisions: "Is it one person unfairly incarcerated, denied work, or rejected from housing? Two?"

Norway and Sweden File Complaints Against Schibsted "Pay or Okay"

The Norwegian Consumer Council and noyb filed a complaint with the Norwegian Data Protection Authority against media publisher Schibsted for implementing "Pay or Okay" systems across its Nordic brands (TV4, Aftenposten, E24, VG, Aftonbladet). The practice forces users to choose between accepting personalized ad tracking or paying a premium to reject it. Industry data shows such systems produce consent rates around 99%, while studies indicate only 0.16% to 7% of people actually want to be tracked. Schibsted executive Fredric Karén confirmed to SVT that "studies show that if you allow this without demanding any form of payment in return, a great many users will decline." The Swedish IMY has received at least 56 complaints since Schibsted introduced the system in Sweden in March. noyb and NCC request the Norwegian DPA declare the practice illegal and issue a fine for the systemic violation. noyb lawyer Joakim Söderberg stated "profiteering from fundamental rights is not a legitimate business model in Europe."

EFF Defends DeFlock.me Against Flock Safety Trademark Threats

EFF is representing Will Freeman, creator of DeFlock.me, a website that reveals locations of tens of thousands of automated license plate reader (ALPR) cameras operated by police surveillance company Flock Safety. Freeman created the site to expose the dangers of ALPRs that collect location data on every vehicle and upload it to a massive nationwide police database. When Flock Safety sent legal threats citing trademark law, Freeman contacted EFF, which recognized the site as grassroots advocacy and criticism protected by the First Amendment. EFF lawyers helped Freeman fight back and Flock Safety withdrew its threats. Privacy advocates in cities nationwide are pressuring officials to block or end ALPR contracts and winning. Freeman stated "without [EFF], free speech would be only for those wealthy enough to defend themselves against billion dollar companies."

Russia Claims Foreign Intelligence Operation Against Officials' Phones

Russia's Federal Security Service (FSB) accused foreign intelligence services of a "large-scale operation" using malicious software on senior Russian officials' mobile devices to extract data, intercept communications, and conduct covert audio and video surveillance. The FSB alleged foreign services used "technical capabilities of major international IT corporations and mobile communication technologies" and claimed the operation enabled access to correspondence, phone calls, geolocation, contacts, and audio/video data. The FSB stated some targeted officials later appeared on U.S. and EU sanctions lists. The agency did not disclose the spyware name, infection method, or provide technical evidence. FSB distributed video to Russian media showing offices linked to Cloudflare and Fastly, though neither company was directly accused of participation. The allegations echo FSB's 2023 claim about Operation Triangulation, where the agency accused U.S. intelligence of using spyware to compromise thousands of Apple iPhones belonging to Russian officials. Apple rejected those allegations, stating it has "never worked with any government to insert a backdoor into any Apple product and never will."

Spain Arrests Hacker for Publishing Government Officials' Personal Data

Spanish National Police arrested an individual in Granada for allegedly leaking personal information of officials from the National Police, Civil Guard, Attorney General's Office, National Security Council, and Spain's National Cybersecurity Institute (INCIBE). Police described it as a large-scale disclosure of sensitive personal information posing threats to individuals and institutions. The data was posted on multiple internet platforms. Authorities warned such disclosures expose public officials to harassment, threats, extortion, and coordinated targeting campaigns. Police seized computer equipment and electronic devices for forensic analysis. The investigation seeks to determine whether others were involved in a broader network. The arrest follows a separate case months earlier where police arrested a 19-year-old accused of stealing and selling approximately 64 million personal records from nine companies. Authorities have not indicated whether the cases are connected.

Policy Changes

ONCD Institutional Weakness Exposed by AI Cyber Risks

Kevin Frazier examined how AI cyber threats are exposing weaknesses in the Office of the National Cyber Director (ONCD), which Congress created to coordinate U.S. cyber policy. Using the Trump administration's inconsistent responses to advanced AI models as a case study, Frazier argued Congress should strengthen ONCD's authority, resources, and coordinating role. The analysis found ONCD is not leveraging its cyber expertise to inform and coordinate the executive branch's response to emerging issues. AI models with sophisticated cyber capabilities are forcing the question of whether the federal government is prepared to help public and private actors anticipate and respond to risks those models create. The review indicates ONCD may not be fulfilling its intended purpose of cyber policy coordination.

Trump Administration "Indict-and-Invade" Legal Theory

Christopher Hardee argued the Trump administration is using the indictment of former Cuban President Raúl Castro to support a flawed legal theory allowing the U.S. to justify military intervention abroad as law enforcement operations. The approach mirrors the legal justification used for the Venezuela invasion, where U.S. Special Operations forces used an indictment against Nicolás Maduro to conduct a capture operation in Caracas in January. The New York Times reported the Castro charges "laid the grounds for potential action by the military to remove him from the country through a means similar to" the Maduro operation. Hardee argued the "indict-and-invade" theory is not only an absurd pretext but legally baseless, as the UN Charter binds the president and contains no law enforcement invasion exception.

Microsoft Threatens Security Researcher Over BitLocker Exploit

Microsoft threatened legal action against anonymous security researcher "Nightmare Eclipse" who published a series of significant security exploits against Windows, including one that breaks BitLocker encryption. The dispute involves recriminations traded between Microsoft and the researcher over responsible disclosure practices and the security of Windows encryption systems.

Compliance Takeaways