A task force formed by the European Union’s data protection enforcers has released preliminary conclusions on how the EU’s data protection rules apply to OpenAI’s chatbot, ChatGPT. The task force remains undecided on critical legal issues, such as the lawfulness and fairness of OpenAI’s data processing. This lack of clarity leaves OpenAI facing regulatory risks and potential penalties under the GDPR. Despite complaints about violations of the GDPR, OpenAI may continue business as usual without clear guidance from EU data protection enforcers.
Colorado has enacted new right-to-repair laws, requiring device manufacturers to make it easier for consumers and independent businesses to repair electronic devices. The law covers a wide range of consumer electronic devices and prohibits manufacturers from using “parts pairing.” Compliance is required by January 1st, 2026, for devices manufactured on or after July 1st, 2021.
Think Congress can’t pass privacy laws? The U.S. government has passed a new privacy law specifically designed to protect the privacy of affluent jet owners, but it has failed to pass an internet-era privacy law or regulate data brokers. The new law passed in the FAA reauthorization bill allows private jet owners to censor travel details and claim confidentiality for “safety or security” reasons.
In a follow-up, Steve Kramer, the political consultant who admitted to deepfaking Joe Biden’s voice in a robocall during the New Hampshire Democratic primary, has been indicted in New Hampshire and fined $6 million by the Federal Communications Commission. The charges include voter suppression and impersonation of a candidate. The FCC also fined a telecom company allegedly involved in the call an additional $2 million.
Let’s be patient, the Europeans do eventually get there. That said, I want to focus a moment back on Congress. It’s easy to fall into the trap of assuming there will be no action. That isn’t the case. It’s just priorities.

