On June 2, 2026, Connecticut Governor Ned Lamont signed Senate Bill 5 into law, designated as Public Act 26-15 and also known as the Connecticut Artificial Intelligence Responsibility and Transparency Act (the “CART Act” or “Act”).1 The CART Act is among the most comprehensive state AI laws enacted to date, creating distinct obligations for employment-related automated decision tools, consumer chatbots, frontier-model developers, generative-AI provenance, and online platforms used by minors, while also addressing AI applications in healthcare through targeted carveouts and innovation initiatives.
Continue Reading Connecticut Enacts Sweeping AI Law Covering Employment, Healthcare, and Online SafetyHealthcare
Colorado Scales Back AI Law, with Targeted Implications for Health Care
- S.B. 26-189, Concerning the Use of Automated Decision-Making Technology in Consequential Decisions, and, in Connection Therewith, Making an Appropriation (Colo. 2026) (to be codified at Colo. Rev. Stat. §§ 6-1-1701 to 1709) (effective Jan. 1, 2027), https://leg.colorado.gov/bill_files/116489/download. ↩︎
- S.B. 24-205, Consumer Protections for Artificial Intelligence, 74th Gen. Assemb., Reg. Sess. (Colo. 2024), https://leg.colorado.gov/bill_files/47770/download. ↩︎
- President Trump’s December 2025 Executive Order criticized state AI laws as a “patchwork of 50 different regulatory regimes” and cited Colorado’s algorithmic-discrimination law as an example. Exec. Order No. 14,365, Ensuring a National Policy Framework for Artificial Intelligence, 90 Fed. Reg. 58,499 (Dec. 16, 2025), https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence; Fact Sheet: President Donald J. Trump Ensures a National Policy Framework for Artificial Intelligence, White House (Dec. 11, 2025), https://www.whitehouse.gov/fact-sheets/2025/12/fact-sheet-president-donald-j-trump-ensures-a-national-policy-framework-for-artificial-intelligence/. ↩︎
- In the signing statement for the 2024 AI Act, Governor Polis expressed that he signed SB 24-205 “with reservations,” warning that it imposed a complex compliance regime, risked a state law patchwork that could hamper innovation and competition, and needed refinement before taking effect. Letter from Jared S. Polis, Governor of Colo., to Members of the Colo. Gen. Assemb. (May 17, 2024). https://drive.google.com/file/d/1i2cA3IG93VViNbzXu9LPgbTrZGqhyRgM/view. Governor Polis convened a Colorado AI Policy Work Group to develop a revised policy framework, producing the 2026 Act. See Press Release, Office of Governor Jared Polis, Colorado Artificial Intelligence Policy Workgroup Delivers Unanimous Support for Revised Policy Framework (Mar. 17, 2026), http://governorsoffice.colorado.gov/governor/news/colorado-artificial-intelligence-policy-workgroup-delivers-unanimous-support-revised-policy; see also S.B. 26-189, 75th Gen. Assemb., Reg. Sess. (Colo. 2026), https://leg.colorado.gov/bills/sb26-189. ↩︎
…
Continue Reading Colorado Scales Back AI Law, with Targeted Implications for Health Care
Supreme Court Reinforces Donor Privacy Protections, Permitting Immediate Federal Court Challenge to State Subpoena
On April 29, 2026, the United States Supreme Court issued a unanimous opinion in First Choice Women’s Resource Centers, Inc. v. Davenport, where it held that a nonprofit suffered an injury to its First Amendment right of association when it was subpoenaed by a state attorney general to produce donor information, including donor identities.1 Justice Gorsuch, writing for the Court, held that the nonprofit petitioner could challenge the subpoena in federal court without first waiting for a state court to compel compliance.
Continue Reading Supreme Court Reinforces Donor Privacy Protections, Permitting Immediate Federal Court Challenge to State SubpoenaThe European Data Protection Board Releases New Guidelines on the Processing of Personal Data for Scientific Research
For almost a decade, the scientific research provisions of the General Data Protection Regulation (GDPR) have lacked authoritative, European Union (EU)-wide interpretation, leaving sponsors of clinical trials and research institutions alike to navigate a patchwork of national implementing laws. A 2019 study commissioned by the European Data Protection Board (EDPB) — the body comprising EU national data protection authorities — confirmed significant divergence among EU Member States, and interim guidance published in 2021 by the EDPB highlighted — but left unresolved — several key GDPR compliance issues facing organisations in the life sciences industry. In the years since, the COVID-19 pandemic and the United Kingdom’s post-Brexit departure from the EU framework have only sharpened the need for more specific guidance. Ropes & Gray attorneys co-authored an article published in Science magazine in October 2020 that provided a summary of the complexity in this space and potential solutions.
Continue Reading The European Data Protection Board Releases New Guidelines on the Processing of Personal Data for Scientific ResearchThe White House Legislative Recommendations: National Policy Framework for Artificial Intelligence and Federal Preemption of State AI Laws
On March 20, 2026, the White House released its National Policy Framework for Artificial Intelligence (“Framework”), outlining legislative recommendations for Congress to establish a unified federal approach to AI regulation. The Framework builds on prior executive actions, including the December 2025 Executive Order (the “Executive Order”) and the Trump administration’s “America’s AI Action Plan,” and it proposes that Congress adopt legislation broadly preempting state AI laws deemed to impose “undue burdens.” This alert summarizes the Framework’s key provisions, analyzes their potential impact on state laws, and highlights considerations for healthcare and life sciences stakeholders navigating the evolving regulatory landscape. While the Framework does not itself change the current legal status of the Executive Order, it signals increased policy focus and may prompt further agency action.
Continue Reading The White House Legislative Recommendations: National Policy Framework for Artificial Intelligence and Federal Preemption of State AI LawsHHS OCR Announces Civil Enforcement Program for Confidentiality of Substance Use Disorder Patient Records
On February 13, 2026, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced its civil enforcement program to implement the updates to the Substance Use Disorder (“SUD”) confidentiality provisions of the regulation at 42 CFR Part 2 (“Part 2”).1 The new enforcement program became effective February 16, 2026, in accordance with the deadline set by the 2024 Final Rule modifying Part 2 (“2024 Final Rule”).
Continue Reading HHS OCR Announces Civil Enforcement Program for Confidentiality of Substance Use Disorder Patient RecordsNew York’s Health Information Privacy Act Aims to Strictly Regulate Consumer Health Data
On January 22, 2025, the New York State Assembly and Senate rapidly passed the wide-ranging New York Health Information Privacy Act. If not vetoed by Governor Kathy Hochul, NY HIPA would be the fourth enacted state consumer health data privacy law, following the Washington My Health My Data Act, Nevada SB 370 and the…
Biden Administration Finalizes Its Last Changes To Health Data Interoperability and Information Blocking Regulations
In December 2024, the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (“ASTP/ONC”) within the U.S. Department of Health and Human Services (“HHS”) published two final rules that establish health data interoperability and information blocking regulations (the “New HTI Final Rules”).
The New HTI Final Rules will affect Trusted Exchange…
A Flurry of Healthcare Sector Cybersecurity Regulatory Developments in 2024
2024 was a record year for cyberattacks in the healthcare sector. According to the Breach Portal maintained by the U.S. Department of Health and Human Services (“HHS”) Office of Civil Rights (“OCR”), to date this year, there have been more than 530 breaches of protected health information (“PHI”) affecting 500 or more individuals. 2024 also the saw the largest known breach of PHI at a HIPAA-regulated entity: Russia-linked cybercrime organization, BlackCat/ALPHV executed a ransomware attack on Change Healthcare, Inc., the payment processor owned by UnitedHealth, which affected the records of more than 100 million individuals.
Continue Reading A Flurry of Healthcare Sector Cybersecurity Regulatory Developments in 2024New York State Adopts New Cybersecurity Program and Incident Reporting Requirements for Hospitals
On October 2, 2024, the New York State Department of Health (“NYSDOH”) finalized and adopted new hospital cybersecurity regulations. Effective immediately, hospitals in New York State are required to report to NYSDOH as promptly as possible, but not later than 72 hours after, determining that a cybersecurity incident has occurred. A cybersecurity incident is an…