image

Articles

Artificial Intelligence and The Law: A year-end retrospective

Westlaw Today

  • Published On: April 6, 2026

Attorneys at Anderson Kill PC provide a month-by-month retrospective of key legal developments involving artificial intelligence in 2025, touching on copyright, data privacy, algorithmic bias, and federal preemption.

This year-end retrospective looks at key developments in artificial intelligence and the law during 2025 on a month-by-month basis. Each article is anchored to a specific event, litigation, or development from that month and uses it as a starting point to discuss the legal issues it raised and why they matter.

Together, the twelve articles capture how AI-related legal questions developed and grew over the course of the year, and identify the areas of law to keep an eye on in 2026.

January: AI washing: SEC action and litigation

In January 2025, a series of enforcement actions and lawsuits brought renewed attention to what has come to be known as "AI washing." "AI washing" occurs when a company represents its products or operations as "fueled" or "powered" by artificial intelligence, when in practice their work either does not utilize AI or utilizes AI only to a limited extent.

Companies choose to exaggerate their use of AI because it is widely viewed as attractive to investors and customers, and describing a business as AI-driven can make it appear more innovative or competitive than it actually is.1

The legal concern arises when those AI-related ideas move beyond enthusiastic concepts.

When a company starts to make specific representations about how a company operates, such as describing its services as automated or AI-driven when the underlying work is still performed largely by humans, or suggesting that AI has materially reduced labor costs or improved margins when it has not, those statements can violate federal securities laws.

AI claims can thus function like any other statements about a company's core business operations which must be accurate and must not mislead investors.

The first of the January AI washing cases was filed on January 6, 2025, when investors brought a securities class action against Innodata Inc.2
The complaint alleges that Innodata violated Section 10(b) of the Securities Exchange Act when it stated it developed its own proprietary AI technology, even though most of the "AI work" was actually being done by offshore manual human labor.

In response, Innodata moved to dismiss, arguing that its statements about AI were accurate, and that it described itself as a "data engineering company" which combined AI and human labor. In support of its motion, Innodata also informed the court that both the SEC and the Department of Justice had closed investigations into the company without taking enforcement action.

As of early 2026, the motion to dismiss remains undecided.3

Later in January, the Securities and Exchange Commission issued an administrative order involving Presto Automation, Inc., addressing alleged misstatements about the company's use of artificial intelligence.4

Presto allegedly did not disclose that it was using another company's AI technology and instead referenced it as their own. In its order, the SEC found that Presto had described its technology as proprietary and AI-driven in ways that overstated automation and understated the role of human involvement. The SEC, however, did not impose civil penalties.

February: The EU Artificial Intelligence Act

In February 2025, the first operative provisions of the EU Artificial Intelligence ("AI") Act became applicable, marking the beginning of the Act's phased implementation across the European Union. While the Act entered into force in August 2024, February was when its regulatory framework began to have legal effect, triggering the first compliance obligations for entities developing, deploying, or relying on AI systems that fall within its scope.

The EU AI Act is a first-of-its-kind, horizontal and harmonized regulatory framework governing artificial intelligence. In passing the Act, Parliament states its priority is to ensure that AI systems deployed across the EU are safe, transparent, traceable, non-discriminatory, and environmentally sustainable.

The Act applies to both public and private actors, inside and outside of the EU, so long as an AI system is placed on EU market or has an impact on individuals located within the EU.

The Act assigns primary responsibilities to two categories of actors: providers and deployers. Providers are individuals or organizations that develop an AI system or general-purpose AI model, or have one developed on their behalf, and place it on the market or put the AI system into service under their name or trademark.

Deployers are individuals or organizations that use AI systems. These classifications are significant because the Act imposes different obligations depending on the role an entity plays in the AI lifecycle.

The Act does not regulate all AI systems uniformly, but instead adopts a risk-based approach, dividing AI systems into four categories. The first category, "unacceptable risk," covers a narrow set of particularly harmful uses of AI that contravene EU values and fundamental rights and are therefore banned.

The second category, "high risk," includes AI systems that negatively affect safety or fundamental rights, either because they are used in regulated products under EU product safety legislation or because they fall within designated high-impact sectors such as critical infrastructure, education, employment, access to essential services, law enforcement, migration, and legal decision-making.

High-risk AI systems are subject to significant regulatory obligations prior to being placed on the market and throughout their use. Providers are required to implement quality management systems, conduct assessments, and establish post-market monitoring processes.

Deployers are required to implement human oversight, maintain system logs, report serious incidents, and, in certain contexts, conduct fundamental rights impact assessments before first use.

The remaining categories include limited-risk AI systems, such as chatbots and deepfake technologies, which are subject primarily to transparency obligations, and minimal-risk AI systems, which remain largely unregulated beyond general product safety requirements.

For violations of the Act, the EU has established tiered penalty structures tied to the type of infringement and global annual turnover, with reduced thresholds for small and medium-sized enterprises.

February 2025 thus marked the point at which the EU AI Act began operating as a live regulatory regime, with phased compliance obligations now formally in effect and additional requirements scheduled to come online in the months and years ahead.

March: Copyright, human ownership, and AI

Conversation in March focused on an old question with a new twist: Can a work without a human author receive copyright protection?

While courts have faced versions of this issue before in the context of animals5 or natural forces,6 a federal appellate court was presented with its first opportunity to address the question in the context of works generated by artificial intelligence.

On March 18, 2025, in Thaler v. Perlmutter, the U.S. Court of Appeals for the District of Columbia Circuit upheld the U.S. Copyright Office's denial of a copyright registration for an artwork generated entirely by an artificial intelligence system.7 Affirming the district court, the court held that copyright registration under the Copyright Act requires human authorship, and that a work created without any human author does not qualify for protection.

The case arose from the plaintiff's attempt to register a visual artwork that he asserted was created autonomously by an artificial intelligence system plaintiff developed, known as the "Creativity Machine." In his copyright application, Thaler identified the AI system as the sole author of the work and listed himself only as the owner of the output.

The U.S. Copyright Office denied the application on the ground that the work lacked human authorship. In affirming the denial of the application, the D.C. Circuit framed its analysis as a straightforward application of existing copyright law.

The court emphasized that the Copyright Act repeatedly assumes the existence of a human author. The court also relied on longstanding copyright principles treating machines as tools of human creativity rather than as creators in their own right.

Interestingly, Thaler v. Perlmutter may not have answered the most important pending question concerning AI and copyright. If a work is created entirely by an AI system and is merely generated in response to a prompt supplied by a human, does that level of human involvement satisfy the originality and authorship requirements of the Copyright Act?

By focusing on a case in which the AI was listed as the sole author on the application, the court avoided confronting how copyright law should treat AI-generated works where a human claims authorship even though the work was created nearly entirely by an AI.

Had Thaler instead made himself the author on the copyright application, the D.C. Circuit may have taken an approach more similar to Burrow-Giles Lithographic v. Sarony, where the Supreme Court first gave copyright protection to photographs, even though photography is a mechanical process.

The Burrow-Giles Court reasoned in favor of copyright because the photographer still must arrange, direct, and pose the subject of the photograph. Whether an AI prompter is deemed to be like a photographer, and is thus granted copyright protection for their AI-generated works, is yet to be seen.

April: The trouble with training data

April raised a different copyright question involving generative AI: whether the use of copyrighted works as training data violates the rights of copyright owners under the Copyright Act. By this point in 2025, multiple lawsuits across the country were presenting variations of this question, often paired with allegations of direct and contributory copyright infringement based on the use of training data.

"Training data" refers to the material used to teach a generative AI system how to produce text, images, or other content. For large language models, that material often includes books, news articles, websites, images, and other human-generated works, many of which are protected by copyright.

During training, the AI is given access to this data so it can analyze it, identify patterns and relationships, and adjust internal parameters that change how it generates new outputs. Once trained, the system can produce new content that mimics features of the underlying training data without (hypothetically) reproducing any single source verbatim.

April brought with it an example of how utilization of copyrighted training data can lead to litigation. In New York Times Co. v. Microsoft Corp., the New York Times, and other newspapers, filed suit against Microsoft (creator of Copilot) and OpenAI (creator of ChatGPT) for direct and contributory copyright infringement (among other causes of action).

The news organizations allege that Microsoft and OpenAI train their models using content from the internet, including copyrighted content from their news websites. The data is then used to inform the AI's responses to user queries, which may result in models "regurgitating" large portions of the news organizations' content.8 The court declined to dismiss the plaintiffs' direct or contributory copyright infringement claims.

April also saw procedural consolidation of these disputes in In re OpenAI, Inc., Copyright Infringement Litigation.9 The litigation consists of twelve actions pending in the Northern District of California and the Southern District of New York, brought by different categories of plaintiffs, including authors, news organizations, and other content creators.

Although the separate claims varied, each action alleged that OpenAI and related defendants used copyrighted works without authorization to train large language models underlying generative AI products, such as ChatGPT. The Panel concluded that they shared common factual questions concerning how large language models are trained and what copyrighted materials were included in training datasets.

The question of copyrighted training data and the affirmative defense of fair use was also tackled in two similar cases in California.10 With both judges in the Northern District of California finding that AI is likely transformative enough to constitute fair use, although "transformativeness" is not the only factor in a fair use analysis.
May: Biometric privacy in the age of AI

On May 12, 2025, the Northern District of Illinois approved a final class settlement in In re Clearview AI, Inc., Consumer Privacy Litigation, resolving long-running claims that the company unlawfully collected and used biometric data en masse.11 The approval of that settlement marked a significant milestone in the litigation surrounding the harms caused by AI-powered biometrics.

Both artificial intelligence and advanced biometric systems have rapidly evolved from hypothetical, far-off technologies to ubiquitous, commonplace tools. Biometric technologies measure and analyze unique human characteristics, including facial geometry, fingerprints, voice patterns, and other personal identifiers.

Artificial intelligence has expanded the capabilities of these systems by allowing them to process vast datasets, identify patterns, and improve accuracy over time. As a result, biometric tools are now widely used across industries, including law enforcement, security, employment, and consumer-facing technology.

As use of these technologies has expanded, litigation has followed. Much of that litigation has been brought under biometric-specific statutes, most notably the Illinois Biometric Information Privacy Act ("BIPA"), which imposes requirements regarding notice, consent, retention, and disclosure of biometric identifiers.

Unlike many privacy laws, BIPA provides a private right of action and statutory damages, making it a particularly powerful vehicle for class action litigation involving biometric data.

The Clearview litigation presents a case study of the risks associated with using AI-powered biometrics. Plaintiffs alleged that Clearview scraped billions of images from social media platforms and other publicly available sources to build a facial-recognition database marketed to law enforcement and private companies, without obtaining the consent required by BIPA.

The consolidated actions, originally filed in 2020, alleged violations of BIPA, unjust enrichment, and related claims, and sought relief on behalf of individuals whose biometric data was allegedly collected and used without authorization. The $52 million settlement, approved in May 2025, resolved claims involving millions of photographs and imposed restrictions on Clearview's future business practices.

Clearview is not an isolated case. Courts have continued to entertain biometric privacy claims involving AI-driven technologies in a variety of contexts, including facial-recognition tools used by employers, retailers, and technology companies. May of 2025 merely showed that biometric privacy litigation remains an area of extreme risk for companies.

The approval of the Clearview settlement demonstrated both the longevity of these cases and the potential exposure associated with large-scale biometric data practices. Companies deploying AI-powered biometric systems should be mindful that litigation risk can arise not only from how biometric data is used, but also from how it is collected, stored, and commercialized, and that compliance obligations may attach even where data is sourced from publicly available materials.

June: The continued rise of state legislation

In June 2025, the momentum of state AI legislation continued to grow, as more states advanced and enacted legislation addressing the development and use of AI. For instance, on June 11, 2025, Texas enacted the Texas Responsible Artificial Intelligence Governance Act, which establishes categorical limits on how AI systems can be developed or deployed.

The Act prohibits the use of AI systems designed to intentionally promote or facilitate physical harm or criminal conduct, intentionally infringe upon Constitutional rights, or unlawfully discriminate against a protected class. It also prohibits the use and deployment of AI systems created to generate or disseminate child sexual abuse material or unlawful deepfake images and videos.

But Texas was not the only state to propose and enact AI legislation last year. 2025 marked a significant year for AI legislation across all 50 states.

In September 2025, California Governor Gavin Newson signed the California Transparency in Frontier Artificial Intelligence Act, the first law in the nation to focus specifically on AI transparency and safety. The Act targets developers of advanced "frontier" AI systems, especially large developers.

Specifically, the Act requires large frontier developers to implement and publish safety and governance frameworks explaining how they assess and mitigate catastrophic risks associated with their products. It also mandates reporting of critical safety incidents to the state and requires developers to adopt whistleblower protections for employees who raise concerns about catastrophic risks and violations of the law.
New York followed suit with a similar (but weaker) law, enacting the Responsible AI Safety and Education Act in December.

In April, Montana enacted the Right to Compute Act, introducing an AI regulation that affirms the right to own and use computational technology. But it also requires that any regulation of AI be "demonstrably necessary and narrowly tailored to fulfill a compelling government interest in public health or safety."

Oddly, this test mimics the strict scrutiny test for infringing upon free speech. Meaning any law passed that would limit someone's access to an AI system would have to pass strict scrutiny.

States have also focused on regulating AI in healthcare and insurance. For example, Maryland enacted House Bill 820 on May 20, 2025, to govern AI use in health insurance utilization review.

The law requires that when health insurance carriers, pharmacy benefit managers, and private review agents use AI in utilization review, the technology bases its determinations on an enrollee's individual medical history, the clinical circumstances presented by the requesting provider, and other relevant clinical information.

It further prohibits AI from replacing the role of a healthcare provider, requires disclosure of whether AI was used in adverse decisions, and allows for inspection of AI tools by the Maryland Insurance Commission.

The wave of state AI legislation in 2025 reflects a rapid push to regulate AI as federal regulations seem increasingly unlikely and as AI becomes an ever-present fixture in daily life.

July: Bias and discrimination

July 2025 saw increased concerns about bias and discrimination in artificial intelligence systems in the consumer context. As AI tools become more often used in day-to-day decision-making, discussion has become focused on whether these tools will merely replicate or amplify historical patterns of discrimination.

Artificial intelligence tools originally developed for predictive policing have found new applications in the private sphere.

Originally, predictive policing systems were designed to forecast crime across geographic areas using historical incident data. Now, retailers have adapted similar approaches within the environment of brick-and-mortar stores, deploying computer vision systems, facial recognition, and behavioral analytics to identify customers who may pose elevated theft risks.

These systems represent a significant shift away from traditional loss prevention methods, which relied primarily on physical deterrents such as security guards or surveillance cameras.

Modern predictive loss prevention systems typically rely on ceiling-mounted cameras and other sensor data that feed into algorithms supposedly capable of identifying individuals, tracking products, and interpreting customer behavior.

These systems may flag conduct such as item concealment, missed scans at self-checkout, or exits without payment, and generate real-time alerts or risk scores. Those alerts can influence immediate decisions by store employees, including whether to approach a customer, or detention of a suspected thief.

Critiques of these systems have raised serious concerns about disparate impact.

AI models trained on historical loss prevention data, such as prior apprehensions, trespass notices, or employee incident reports, will reflect the patterns present in that data. If certain groups were historically scrutinized or detained at higher rates, the AI system may replicate or intensify those disparities. Over time, this feedback loop can embed bias into an AI system's operation, even in the absence of intentional discrimination.

These dynamics create potential exposure under federal and state civil rights laws, which prohibit practices that result in discriminatory effects on protected classes regardless of intent.

Identity matching features may also implicate state privacy and biometric statutes, particularly where facial recognition or appearance-based tracking is involved. In addition, false arrest and false imprisonment claims may arise when AI alerts are treated as sufficient grounds for detention without independent verification.

As AI increasingly shapes the interactions between customers and employees, courts and regulators are likely to scrutinize not only how these systems are designed, but how the systems are impacting these relationships. The growing use of predictive AI in retail environments illustrates how discrimination risks can emerge even when systems are adopted for ostensibly neutral purposes.

August: The dangers of AI chatbots

August 2025 brought a court case with a concerning fact pattern that raises important questions about the safety of AI in the hands of minors. In Raine v. OpenAI, Inc.,12 the parents of a sixteen-year-old allege that OpenAI's ChatGPT product directly contributed to their son's death.

The complaint describes how the child developed a relationship with a chatbot and used the program as an outlet for emotional distress and suicidal ideation. According to the plaintiffs, the program's responses not only validated these thoughts but also provided explicit, technical information regarding suicide methods.

Raine was one of three major lawsuits to emerge during the past year in which plaintiffs argue that an AI chatbot was directly responsible for the death of a minor.13

An AI chatbot is a computer program designed to simulate human conversation through text-based communication with users. These programs can impersonate celebrities, historical figures, or fictional characters. Some platforms even allow users to create custom characters.

These chatbots create the impression that users are conversing with a real individual. Through repeated interactions, chatbots learn language patterns, retain information about users, and generate responses in natural, human-like language. This replication of human connection can become dangerous when adequate safeguards are not in place, particularly for vulnerable populations such as youth and individuals experiencing mental illness.

Garcia v. Character Technologies, Inc.14 helped lay the groundwork for litigation like Raine and other cases concerning the dangers of AI chatbots.

In Garcia, Plaintiff alleged that Character.AI caused her fourteen-year-old son to form an emotional attachment to the program, ultimately leading to his death by suicide.

The complaint described how Character. AI engaged in sexual conversations with the boy and professed love for him, knowing that he was only fourteen years old. When the child confided in the chatbot about his depression and suicidal ideations, the program told the child to "come home," failing to suggest that the child seek real-world help. Soon after, the child committed suicide.

Several months later, Peralta v. Character Technologies, Inc.15 raised similar claims. In that case, the parents of a thirteen-year-old girl alleged that Character.AI engaged in manipulative conversations with their daughter, encouraging her to engage in self-harm and actively isolating her from her family, ultimately creating the conditions for her to take her own life.

The emergence of litigation against AI chatbot developers reflects growing concern over the real-world consequences of this technology.

As cases such as Raine, Garcia, and Peralta demonstrate, the capacity of chatbots to form emotional bonds with users, particularly minors and other vulnerable populations, raises serious questions about the adequacy of existing safeguards. It should be noted that following the drafting of this article, many of these cases were settled in mediation.

September: The impact of AI on the court system

2025 saw the court system flooded with hallucinated citations and fake evidence with no end in sight. While courts have attempted to stem the tide with new rules on the use of AI for attorneys and pro se litigants, that seems to have had little impact on the number of filings containing fake case citations and AI-generated legalese.

In September, we saw two cases that highlighted the severity of attorneys using artificial intelligence in court filings:
In Puerto Rico Soccer League NFP, Corp. v. Federacion Puertorriquena de Futbol,16 in response to various motions by Defendants, Plaintiffs submitted four filings.

Defendants sought leave to reply to these four motions, and in their replies claimed that Plaintiffs had made multiple citation errors and alleged that they had used generative artificial intelligence to write these motions.

The Court conducted an independent review and found that Plaintiffs' motions contained multiple citations that were incorrect, did not contain the quotes or content cited to, and referenced cases that cannot be located and thus presumably do not exist. The Court issued its order finding that sanctions were warranted against Plaintiffs.

The Court ordered Plaintiffs' counsel to pay the attorneys' fees incurred by Defendants in relation to Plaintiffs' filings. Counsel was eventually ordered to pay Defendants $24,492.10 in attorneys' fees and costs.

In September, this was the highest sanction recorded against an attorney for the use of AI, however, in our estimation, this record was beaten with a record AI sanction of $60,000 in December.

In Mendones v. Cushman and Wakefield, Inc.,17 the Court found that Plaintiffs intentionally submitted false testimony to the Court in connection with their motion for summary judgment. The Court, attentive to the issue of improper use of generative AI, went through a detailed analysis of the evidentiary submissions.

First, the Court found that Plaintiffs submitted "deepfake" exhibits that were the products of generative artificial intelligence and did not capture the actual speech and images of individuals. Second, the Court further found that other exhibits were the products of AI or, at least, were materially altered. When Plaintiffs presented the Court with metadata, the court did not find this to be reliable or credible.

The Court declined to order a monetary sanction and instead found that dismissal of the case was warranted. The Court reasoned that a "terminating sanction serves the appropriate remedial effect of denying Plaintiffs — and other litigants seeking to make use of GenAI to submit video testimonials — of the ability to further prosecute this action after violating the Court's and the Defendants' trust so egregiously."

While these cases were notable entries in September, they were not the only entries in September.18

October: Artificial intelligence and insurance

By October 2025, it had become clear that artificial intelligence was no longer a hypothetical risk for insurance companies and policyholders, but an inevitable one. The question that followed was not whether AI-related claims would arise, but how insurance policies would respond when they did.

As AI becomes integrated in everyday business operations, companies can face claims ties to AI-driven errors, bias, and misuse. Those claims can range from allegations of discrimination to defamation, or from data privacy violations to securities violations. While the technology giving rise to those claims may look new, the theories of liability are generally not. In most cases, AI-related disputes look familiar, alleging negligence, various torts, or statutory violations.

Businesses may assume that AI-related claims fall into a coverage gap because it is new technology. However, as stated, the actual claims arising from AI are not novel. In practice, most insurance policies in effect during 2025 were drafted without any reference to artificial intelligence at all.

Where policy language does not expressly exclude AI-related conduct, coverage thus turns on traditional questions, such as whether the alleged harm falls within a covered insuring agreement and whether any exclusions apply. In many instances, AI-related liabilities fit comfortably within existing insurance policies.

Technology errors and omissions insurance, for example, is designed to respond to claims arising from failures of technology products or services. Where an AI system produces incorrect outputs, or fails to perform as advertised, those allegations often mirror claims that have long been covered under tech E&O policies.

Similarly, cyber insurance may respond when AI systems expose personal data, facilitate unauthorized access, or trigger regulatory investigations stemming from data security incidents. Most cyber policies in effect during 2025 do not contain AI-specific exclusions.

At the same time, 2025 saw a growing effort by insurance companies to introduce AI-specific endorsements, supposedly expanding coverage for certain AI-related incidents. Others explored broader exclusions aimed at carving AI risks out of existing policies. New standalone products also emerged for hypothetical AI risk protection.

These developments should not suggest that existing insurance has suddenly become inadequate to cover AI-related risks. Most coverage disputes in this area still turn on familiar issues, the same causes of action, the same policy language, and the same exclusions.

For policyholders, the key takeaway from 2025 was not that AI risks are uninsured, but that coverage depends on policy language that was often drafted before AI became commonplace. As insurance companies continue to introduce policy language, specifically AI exclusions or endorsements, that landscape may change. But in 2025, silence in insurance policies likely meant coverage, not exclusion.

November: Antitrust and algorithmic collusion

November found its focus on a set of antitrust claims involving algorithmic pricing tools. Specifically, can the use of shared pricing software and pooled data support allegations of coordination among competitors under the Sherman Act?

This question was presented directly in the multidistrict litigation concerning RealPage's revenue management software. In In re RealPage, Inc., Rental Software Antitrust Litigation (No. II),19 renters allege that competing landlords unlawfully fixed prices by delegating rent-setting decisions to a common algorithm supplied by RealPage.

According to the complaints, participating landlords provided RealPage with detailed, non-public information, including current rents, occupancy levels, concessions, and lease terms. RealPage pooled that data with similar information from competing landlords operating in the same markets and used it to generate unit-specific pricing recommendations designed to maximize rental revenue.

The plaintiffs alleged that RealPage's system went beyond providing generalized market insights. Instead, they claimed it functioned as a centralized mechanism for coordinating prices, with landlords knowingly submitting competitively sensitive data, understanding that their competitors were doing the same, and then adhering to the software's recommended rents.

The complaints further alleged that RealPage monitored compliance with its pricing recommendations and discouraged deviations, reinforcing the alleged coordination. Defendants argued that these allegations described lawful parallel conduct and independent decision-making, emphasizing that landlords retained discretion over whether to accept pricing recommendations.

They also contended that the use of pricing software, even when widely adopted, does not itself establish an agreement among competitors.

On November 21, 2025, the court issued a consolidated opinion resolving multiple motions to dismiss. The court denied the motion to dismiss the multifamily housing claims, holding that plaintiffs plausibly alleged a horizontal conspiracy facilitated through RealPage's software.
At the same time, the court granted the motion to dismiss the student housing claims, finding that those plaintiffs failed to plead sufficient facts showing the exchange of non-public information or a conscious commitment to a common pricing scheme.

In reaching those conclusions, the court emphasized that, at the pleading stage, delegating pricing decisions to a shared algorithm fed by pooled competitor data can support an inference of agreement, even absent direct communications among competitors.

Other recent algorithmic pricing cases illustrate the boundaries of these theories. In Duffy v. Yardi Systems, Inc., a court similarly allowed antitrust claims to proceed where plaintiffs alleged that landlords knowingly shared non-public pricing data through a common pricing platform and collectively adhered to algorithmic rent recommendations.

December: The pending question of federal preemption

President Trump has made federal preemption of state AI laws a priority of his administration's AI policy.

However, thus far, Republicans' attempts to secure federal preemption of state AI regulations has been unsuccessful. At the same time, during the 2025 legislative session, all 50 states, Puerto Rico, the Virgin Islands, and Washington D.C., have introduced AI related legislation. And many states have actually enacted broad protections for their citizens.

In an effort to quell the tide of state legislation, on December 11, 2025, President Trump signed an executive order entitled "Ensuring A National Policy Framework for Artificial Intelligence" (the "EO").
The purpose of the EO is to allow United States AI companies to be free to innovate without "cumbersome" regulations and, as per the EO, state-by-state regulation by definition creates a patchwork of 50 different regulatory regimes that makes compliance more challenging, particularly for start-ups.

The EO attempts to preempt state regulation in three ways: first, through litigation; second, by withholding federal funding; and third, by creating and passing new legislation.

First, the EO seeks to preempt state laws through litigation. The EO tasked the Attorney General to establish an AI litigation task force within 30 days of the date of the EO to challenge state AI laws which are inconsistent with the EO.

The Task Force is charged with challenging state laws which: (1) unconstitutionally regulate interstate commerce, (2) are preempted by existing federal regulation, (3) the Secretary of Commerce has identified as onerous laws such as laws that require AI models to alter their truthful outputs or that compel AI developers or deployers to disclose or report information in a manner that would violate the First Amendment.

Second, executive departments and agencies shall assess their discretionary grant programs and determine whether agencies may condition grants on states either (1) not enacting an AI law that conflicts with the policy of the EO or (2) for those states that have enacted such laws, to enter a binding agreement with the relevant agency not to enforce any such laws during the performance period in which it receives the discretionary funding.

In addition, within 90 days of the date of the EO, the Chairman of the FTC shall issue a Policy Notice specifying the conditions under which states may be eligible for remaining funding.

Third, the Special Advisor for AI and Crypto and the Assistant to the President for Science and Technology shall jointly prepare a legislative recommendation establishing a uniform Federal policy framework for AI that preempts State AI laws that conflict with the EO.

The EO also provides a carve out for state AI laws relating to: (1) child safety protections; (2) AI compute and data center infrastructure; (3) state government procurement and use of AI; and (4) other topics as shall be determined.

While the EO seeks to clear a path for the preemption of state laws, there still appears to be strong bipartisan pushback against such. In addition, executive orders cannot override Congress' power to pass laws or override federal laws and statutes. Therefore, one can expect a lengthy battle between states and the federal government over AI.

 

Notes:
1 See, e.g., U.S. Securities and Exchange Commission, SEC Chair Gary Gensler on AI Washing, YOUTUBE (Mar. 18, 2024).; see also Press Release, SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence, SEC (Mar. 18, 2024).
2 D'Agostino v. Innodata Inc., No. 2:24-cv-00971 (D.N.J. Jan. 6, 2025).
3 See also Sarria v. Telus International (CDA), Inc., No. 1:25-cv-00889 (S.D.N.Y. Jan. 30, 2025).
4 In the Matter of Presto Automation Inc., SEC Administrative Proceeding Matter: No. 3-22413 (Jan. 14, 2025).
5 See Naruto v. Slater, 888 F.3d 418 (9th Cir. 2018) (holding that a monkey cannot own a copyright in an image.
6 See Kelley v. Chicago Park District, 635 F.3d 290 (7th Cir. 2011) (flower garden found not to be copyrightable.
7 Thaler v. Perlmutter, 130 F.4th 1039 (D.C. Cir. 2025), cert. denied.
8 New York Times Co. v. Microsoft Corp., 777 F. Supp. 3d 283 (S.D.N.Y. 2025).
9 776 F. Supp. 3d 1352 (U.S. Jud. Pan. Mult. Lit. 2025).
10 See, e.g., Bartz v. Anthropic PBC, 787 F. Supp. 3d 1007 (N.D. Cal. 2025); Kadrey v. Meta Platforms, Inc., 788 F. Supp. 3d 1026 (N.D. Cal. 2025).
11 (N.D. Ill. May 12, 2025).
12 No. CGC-25-628528 (Cal. Super. Ct. San Francisco Cnty.).
13 See also Peralta v. Character Technologies, Inc., No. 1:25-cv02907 (D. Colo.); Garcia v. Character Techs., Inc., No. 6:24-CV-1903 (M.D. Fla.).
14 No. 6:24-CV-1903 (M.D. Fla.).
15 No. 1:25-cv-02907 (D. Colo.).
16 No. CV 23- 1203 (RAM), , at *1 (D.P.R. Sept. 23, 2025).
17 No. 23CV028772 (Cal. Super. Ct. Sept. 9, 2025).
18 See, e.g., Pelishek v. City of Sheboygan, No. 23-CV-1048, (E.D. Wis. Sept. 18, 2025); Ebem v. Bondi, No. 1:24-CV-148-H-BU, (N.D. Tex. Sept. 15, 2025); T.M. v. M.M., 268 N.E.3d 869, fn. 2 (Ind. App. Sept. 24, 2025).
19 709 F. Supp. 3d 478 (M.D. Tenn.).

By Jamie O'Neill, Esq., Seán McCabe, Esq., Abigail Damsky, Esq., and Kennedy Aldrich, Esq., Anderson Kill PC

 

Read this article on Westlaw Today

Related People
image
Kennedy Aldrich
View Moreimage
image
Abigail Damsky
View Moreimage
image
Seán McCabe
View Moreimage
image
Jamie O’Neill
View Moreimage
Related Practice Areas

© Copyright 2026 by Anderson Kill P.C. ClickySoft - WordPress Development Company