Dechert Cyber Bits
Issue 103 - September 24, 2026
Key Developments in Cybersecurity, Privacy & AI
Catch Dechert at IAPP Privacy. Security. Risk. + AI Governance Global 2026!
Will you be at IAPP PSR in Seattle on October 8-9? Partners Ben Sadun and J.J. Jones will speak on "Privacy Programs on Trial and Incident Response Under Fire" on Tuesday, October 8 at 11:30 a.m. If you'll be in Seattle, come by to say hello to Ben and J.J.
FTC Rescinds Obsolete Health App Breach Notification Guidance
The Federal Trade Commission (“FTC”) has rescinded a Biden-era policy statement that interpreted the Health Breach Notification Rule (“HBNR”) to cover health apps and connected devices that collect consumer health information, including fitness trackers (“Policy Statement”). Under the Policy Statement, a breach of consumers’ personal health records by such apps or devices would trigger a notification obligation under the HBNR to affected consumers and the FTC. At the time the Policy Statement was issued, the HBNR had never been enforced in its decade-long existence. Following the Policy Statement, the FTC brought actions against several digital health companies alleging violations of the HBNR. The FTC later revised the HBNR itself to extend to health apps and connected devices (“2024 HBNR Updates”).
In its action rescinding the Policy Statement, the FTC noted that the Policy Statement had been superseded by the 2024 HBNR Updates, and that the Policy Statement had been “contentious at the time of issuance” and of “minimal benefit,” citing dissents made by Commissioners at the time. The FTC also cited President Trump’s January 2025 executive order directing federal agencies to eliminate unnecessary rules and reduce complicated federal regulation, including a specific instruction to curb reliance on sub-regulatory guidance such as policy statements.
Takeaway: Because the FTC has not announced any decision to reverse the 2024 HBNR Updates, health apps and connected devices remain subject to HBNR requirements. Still, companies may fairly read the Commission’s recent rescission of the Biden-era Policy Statement as an indication that this FTC is less likely to actively enforce the HBNR against health apps and connected devices.
European Commission Designates ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act
On August 31, 2026, the European Commission (“Commission”) designated ChatGPT as a Very Large Online Search Engine ("VLOSE") and Reddit and Roblox as Very Large Online Platforms ("VLOPs") under the Digital Services Act ("DSA"). All three companies had reported average monthly EU user numbers above the 45 million threshold that triggers designation under the DSA. What sets the ChatGPT designation apart is the theory behind it: rather than treating the chatbot solely as a platform, the Commission concluded that ChatGPT’s ability to respond to user prompts by searching the web is, on its own, sufficient for it to function as an online search engine within the meaning of the DSA.
A four-month compliance period is now running for all three companies: by January 2027, each must comply with the increased obligations that come with VLOP and VLOSE status, including identifying and mitigating systemic risks arising from their platforms. The designations also give the Commission expanded, direct investigative authority over the mechanics of the respective services. Notably, day-to-day oversight will not sit with the Commission alone: Ireland's Coimisiun na Mean (Ireland’s Independent Media Regulator), will have oversight over ChatGPT and Reddit, and the Netherlands' Authority for Consumers and Markets will have oversight in relation to Roblox.
Takeaway: This marks the first time the Commission has designated a generative AI chatbot as a VLOSE and indicates that the Commission views a service responding to prompts by searching the web as being sufficient to qualify that service as an online search engine under the DSA. We expect the Commission will apply a similar approach in assessing the status of other AI assistants with comparable functionality. Businesses operating AI-powered services with an EU user base are advised to assess whether they are approaching the 45 million monthly user threshold that triggers DSA designation, and plan accordingly.
California Governor Signs Over a Dozen Bills Addressing Online Safety for Minors
On September 10, 2026, California Governor Gavin Newsom signed over a dozen bills addressing online safety for children and minors under 18, including a comprehensive framework regulating AI companion chatbots bills and bills banning addictive features for children under 16.
SB 1119, known as Adam’s Law, directs operators of companion chatbots that interact with users under the age of 18 in California to perform comprehensive annual risk assessments that evaluate “covered harms” (such as privacy issues, and physical, psychological and/or emotional harm) associated with the chatbot. Operators must also maintain crisis response protocols for their products, implement default parental controls, prohibit the chatbot from engaging in certain harmful conduct, and not use a minor’s engagement with the chatbot to serve targeted ads. SB 1119 also requires operators to submit to biennial independent third-party child safety audits by January 1, 2029. Audit summaries will need to be posted to the operator’s website and submitted to the California Attorney General. Public prosecutors can bring civil enforcement actions under the law for up to $5,000 per affected child (for negligent violations) and up to $15,000 per child for intentional violations. The law also contains a private right of action.
AB 1709 prohibits social media platforms from implementing potentially addictive features (such as autoplay, unlimited scrolling and personalized feeds) for users under 16. Notably, the California Attorney General may add to the list of impermissible features over time. AB 1709 imposes penalties of up to $50,000 per minor for knowing violations and up to $25,000 per negligent violation and can be enforced by the California Attorney General or local public prosecutors. AB 1709 does not include a private right of action.
Takeaway: The package of laws signed by Governor Newsom represent the most sweeping and hard-hitting approach to minors’ safety online by a regulator to date. Companies offering chatbots and other online services to minors under 18 in California will want to promptly review their obligations under these new laws. We anticipate compliance will have significant impact on user experience and product development and design, including the need to implement age verification checks for children under 16 in some cases.
Cybersecurity Mishaps Carry FCA Price Tags, DOJ’s Honeywell Enforcement Shows
On September 1, 2026, the U.S. Department of Justice (“DOJ”) announced that Honeywell Aerospace (“Honeywell”), an aerospace supplier to government and commercial customers, agreed to pay over $2 million to resolve allegations that a business unit failed to meet cybersecurity requirements tied to a Department of Defense (“DOD”) contract. The allegations, which started with a whistleblower qui tam complaint, alleged that, for one of its networks, Honeywell fell short of the National Institute of Standards and Technology’s (“NIST”) Special Publication 800-171 controls, which are required to safeguard Controlled Unclassified Information (“CUI”) residing on nonfederal systems. These controls are implemented in government contracts through the DOD’s Cybersecurity Maturity Model Certification (“CMMC”) program.
Honeywell joins a growing list of contractors facing False Claims Act (“FCA”) exposure over alleged cybersecurity gaps. The DOJ recovered over $52 million in cybersecurity-related FCA actions in fiscal year 2025 alone.
As part of the settlement, Honeywell did not admit wrongdoing, and issued the following statement: “Honeywell Aerospace has been and remains committed to a robust and fully compliant cybersecurity program that protects our networks and our customers. Honeywell Aerospace complies with all applicable cybersecurity requirements and laws and its contractual and regulatory obligations.”
Takeaway: Cybersecurity compliance is emerging as a distinct area of potential exposure under the FCA, as the DOJ’s latest settlement shows. Although the DOD has paused full implementation of the CMMC program, existing contractual requirements to implement cybersecurity controls are still in effect, and the DOJ’s settlements indicate that the agency views them as legitimate hooks for potential FCA liability.
Dechert Tidbits
Florida AG Pushes to Make AI Companies Criminally Liable for Chatbot-Assisted Crimes
The Florida Attorney General proposed legislation that would hold companies criminally responsible when AI chatbots they own, control, or distribute participate in a crime, with penalties including heavy fines, victim payments, and court-ordered monitorship. The proposal follows the Florida AG’s civil suit against OpenAI and CEO Sam Altman over the FSU mass shooting, in which the shooter allegedly used ChatGPT to plan the attack, plus an expanded criminal investigation covering a separate double homicide involving another ChatGPT user.
CalPrivacy Flags Data Broker Reporting Gaps
On September 3, 2026, the California Privacy Protection Agency ("CalPrivacy") issued Enforcement Advisory No. 2026-01, warning data brokers that providing inaccurate information in their annual Delete Act registration (in addition to simply failing to annually register) can trigger a fine of $200 for each day that the incorrect information appears in the registry (“Advisory”). CalPrivacy warned that the Delete Act does not distinguish unintentional mistakes from intentional misrepresentation. The Advisory follows more than a dozen registration-related enforcement actions CalPrivacy has brought against data brokers since November 2024.
AI Risk Management Toolkit: Guidance published by the UK Department for Science, Innovation and Technology (DSIT)
DSIT published an AI Risk Management Toolkit to help organizations involved in designing, procuring, and deploying AI-enabled products identify and manage AI-related risks throughout a system's lifecycle (“Toolkit”). Building on the government's existing Orange Book risk management framework, the Toolkit provides a risk assessment guide, critical risk-identification questions, a workbook for tracking identified risks and treatment actions and a monitoring dashboard spanning financial, legal and regulatory, transparency, fairness and accountability categories. Though designed for UK government departments, the Toolkit offers a useful practical reference point for any organization looking to structure its own AI governance and risk assessment processes.
Please note that where a “Takeaway” is missing from one of our
blurbs, it is likely because one of the parties involved is a client of the
firm or otherwise has an interest in the matter.
In 2025 and 2026, Dechert’s Cyber, Privacy & AI team achieved top individual and group rankings in The Legal 500 and Chambers USA. Global Chair and Partner Brenda Sharton, a Law360 MVP, and Partner Ben Sadun, a Law360 Rising Star, were recognized for their leadership and contributions to the team’s achievements. The team was also recognized in Law.com’s “Litigators of the Week” column for its recent victory for Flo Health, a matter that showcased the team’s strategic excellence. Thank you to our clients for entrusting us with the types of matters that led to these recognitions.
Recent News and Publications
- Committed Capital Cyber Risk in Transactions Podcast – Brenda Sharton, J.J. Jones (September 3, 2026)
- Srsly Risky Biz: Supreme Court Undermines Section 702 - Risky.Biz (July 9, 2026)
- Governor Newsom’s AI Executive Order: What Employers Need to Know - Dechert OnPoint (June 4, 2026)
- AI Cyberattacks Call for Company Preparation to Limit Fallout - Bloomberg Law (March 31, 2026)
- Dechert Adds Former Microsoft Cybersecurity Counsel J.J. Jones as Partner - CyberTech Insights (March 11, 2026)
- Wake Up Call: Simpson Thacher misses appeal deadline - Bloomberg Law (March 11, 2026)
- Microsoft Cybersecurity Legal Official Jones Exits for Dechert - Bloomberg Law (March 10, 2026)
- Dechert Appoints J.J. Jones as Partner - CityBiz (March 10, 2026)
- Dechert Continues Lateral Hiring Momentum with Addition of Cybersecurity, Privacy and AI Expert J.J. Jones PR Newswire (March 10, 2026)
- Dechert Lands Ex-Microsoft, Google Atty In San Francisco – Law360 (March 10, 2026)
- Cybersecurity & Privacy Group Of The Year: Dechert – Law360 (February 2026)
- Law360's Practice Group of the Year for Cybersecurity & Privacy – Law360 (January 2026)
- MVP: Dechert’s Brenda Sharton – Law360 (November 2025)
- Litigator of the Week Runners-Up and Shout-Outs – Law.com (August 8, 2025)
- 2025 Rising Star: Dechert's Benjamin Sadun – Law360 (July 21, 2025)
-
- Brenda Sharton Q&A (Profiles in Diversity Journal Q4 2024 "All Colors, All Leaders" issue)
- Disclosing Personal Data to Non-EU Authorities - GDPR Guidance Published (Dechert OnPoint published December 18, 2024)
- MVP: Dechert's Brenda Sharton - (Law360 October 10, 2024)
- Brantley et al. v. Prisma Labs, Inc. (Global Legal Chronicle published August 31, 2024)
- Law360's Legal Lions of The Week (Law360 published August 9, 2024)
- Lensa AI App Creator Shakes Ill. Biometric Privacy Suit (Law360 published August 6, 2024)
- Prisma Labs Skirts BIPA Suit Over Training of Its AI Photo App (Bloomberg Law published August 6, 2024)
- A New UK Labour Government: A Fresh Approach to AI Regulation (Dechert OnPoint published July 9, 2024)
- The EU AI Act: An Overview (Dechert OnPoint published May 13, 2024)
- Tribunal Overturns UK ICO’s Enforcement Action Against Clearview AI (Dechert OnPoint published November 8, 2023)
- 5 Takeaways from ICO's Biometric Recognition Guidance (Published in Law360, October 18, 2023)
- Bridge Over Troubled Data Flows: UK-US Data Bridge Approved (Dechert OnPoint published September 22, 2023)
- US-EU Plan On AI Illustrates Differing Opinions On Regulation (Published in Law360, August 2, 2023)
- SEC Final Rule Exempts ABS Issuers from New Cybersecurity Disclosure and Reporting Requirements (Dechert OnPoint published August 16, 2023)
- SEC Finalizes Cybersecurity Disclosure Rules for Public Companies (Dechert OnPoint published August 7, 2023)
- Ready. Set. Flow: Green Light from the Commission for EU-U.S. Data Privacy Framework (Dechert OnPoint published July 11, 2023)
- EU General Court Examines Data Anonymisation and Pseudonymisation (Dechert OnPoint published May 25, 2023)
- SEC Proposes New Cybersecurity Risk Management Rule for Various Market Entities (Dechert OnPoint published May 10, 2023)
- Artificial Intelligence: Legal and Regulatory Issues for Financial Institutions (Dechert OnPoint published April 26, 2023)
- BioDech | A Global Life Sciences Broadcast Series - What Every Life Sciences Company Needs to Know About Cybersecurity
- The group was named 2022 Law360 Practice Group of the Year.
- Winner of the International Association of Privacy Professionals (“IAPP”) Legal Innovation Award for the Americas for 2022, for its work with client Flo Health, Inc., the world’s leading women’s health App on its “Anonymous Mode” feature in the wake of the Dobbs decision by the U.S. Supreme Court.
- Recognized as a 2022 “Standout” by London’s Financial Times in a legal innovation award for the Americas in the category of “Innovation in Enabling Business Resilience.”
- Exploiting Public Health Data for R&D: UK Progresses Secure Data Environments (Dechert OnPoint published July 20, 2023)
- EU Data and Digital Drive: 10 Things to Know About the Digital Services Act (Dechert OnPoint published February 17, 2023) By: Paul Kavanagh, Dr. Olaf Fasshauer, and Madeleine White.
- Your Company’s Data Is for Sale on the Dark Web. Should you Buy it Back? (Published in the Harvard Business Review January 4, 2023) By: Brenda Sharton.
- Brenda Sharton and Steven Rabitz quoted in Plan Sponsors Have Myriad Responsibilities to Protect Against Cyberthreats (Published in PLANSPONSOR December 22, 2022).
- English High Court Maintains Claimant’s Anonymity in Cyberattack Case (Dechert OnPoint published December 19, 2022) By: Paul Kavanagh, Brenda Sharton, Dylan Balbirnie, and Anita Hodea.
- The entry into force of the Digital Markets Act kicks off new era of digital regulation in Europe (Dechert OnPoint published October 25, 2022), by members of the Dechert antitrust practice.
- Brenda Sharton was named a 2022 Law360 MVP for Cybersecurity & Privacy.
- Brenda Sharton was recognized as one of Massachusetts Lawyers Weekly's Go To Cybersecurity/Data Privacy Lawyers for 2022 (Published in Mass. Lawyers Weekly October 31st issue)
- Practice leaders Brenda Sharton and Karen Neuman are discussed in Litigation Leaders: Dechert’s Cathy Botticelli and Jonathan Streeter on Counseling Clients With an Eye Toward Avoiding Litigation (Published in Law.com August 15, 2022).
- Brenda Sharton quoted in Why hackers are able to steal billions of dollars worth of cryptocurrency (Published in the Washington Post August 11, 2022).
- FDA Medical Device Cyber Guidance Protects Patients, Cos. (Published in Law360 June 9, 2022) By: Brenda Sharton, Emily Van Tuyl, and Kathleen Fay
- Olaf Fasshauer was ranked in the 2022 publication of German’s daily newspaper Handelsblatt (in cooperation with Best Lawyers) as best lawyers in Germany for Data Security and Privacy Law
- Brenda Sharton presented at the WSJ Pro Cyber Forum (June 1, 2022).
- Brenda Sharton was a moderator on the panel, "The Digital Transformation of Customer Experience" at the LendIt Fintech Conference (May 25, 2022).
- Ranked by The Legal 500 US – Media, Technology and Telecoms: Cyber Law (including Data Privacy and Data Protection). Brenda Sharton was named a Leading Lawyer and Hilary Bonaccorsi was named a Rising Star.
- Brenda Sharton named to Cybersecurity Docket’s Incident Response 40 2021 list.
- Dubai data protection authority plans to launch international privacy risk index and update international data transfer mechanisms (Dechert OnPoint published May 5, 2022) By: Paul Kavanagh and Dylan Balbirnie.
- Brenda Sharton quoted in Global Data Review article, "SEC proposes 4-day breach reporting rule" (April 26, 2022).
- CJEU rules on private copying exception to storage in the cloud (Dechert OnPoint published April 11, 2022) By: Paul Kavanagh and Nathan Smith.
- SEC Proposes New and Amended Cybersecurity Rules for Public Companies (Dechert OnPoint published March 17, 2022) By: Timothy Blank, Kevin Cahill, Brenda Sharton and Daniel Murdock.
- Brenda Sharton was quoted in the Law360 article, “Congress Seizes On Incident Reports In Fighting Cyberattacks” (March 16, 2022).
- 4 Takeaways For Asset Managers From SEC's Cyber Rule Plan (Published in Law360 on March 10, 2022) By: Kevin Cahill and Hilary Bonaccorsi.
- California Privacy Protection Agency Signals Delay for Final CPRA Rules & California AG Conducts CCPA Investigative Sweep (Dechert Newsflash published February 25, 2022) By: Karen Neuman, Hilary Bonaccorsi, Bailey E. Dervishi.
- SEC Proposes New Cybersecurity Rules for SEC Registered Advisers and Funds (Dechert OnPoint published February 23, 2022) By: Kevin Cahill, Timothy Blank, Brenda Sharton, Hilary Bonaccorsi, Colleen Hespeler and Bailey Dervishi.
Content Editors
Hilary Bonaccorsi, Aurelien Martinot, Austin Mooney, Laura Rossi, Morgan Shields, Lydia Speight
Partner Committee Editors
Dechert Cyber Bits Partner Committee
Brenda R. Sharton
Partner, Global Chair, Cyber, Privacy and AI
Boston
brenda.sharton@dechert.com
Hilary Bonaccorsi
Partner
Charlotte
hilary.bonaccorsi@dechert.com
Timothy C. Blank
Senior Counsel
Boston
timothy.blank@dechert.com
Kevin F. Cahill
Partner
Los Angeles
kevin.cahill@dechert.com
Dr. Olaf Fasshauer
National Partner
Munich
olaf.fasshauer@dechert.com
J.J. Jones
Partner
Washington, D.C.
jakarra.jones@dechert.com
Paul Kavanagh
Partner
London
paul.kavanagh@dechert.com
Austin Mooney
Partner
Washington, DC
austin.mooney@dechert.com
Laura Rossi
Partner
Luxembourg
laura.rossi@dechert.com
Benjamin Sadun
Partner
Los Angeles
benjamin.sadun@dechert.com
Dechert’s global Cyber, Privacy and AI practice provides a multidisciplinary, integrated approach to clients’ privacy and cybersecurity needs. Our practice is top ranked by The Legal 500 and our partners are well-known thought leaders and sought after advisors in the space with unparalleled expertise and experience. Our litigation team provides pre-breach counseling and handles all aspects of data breach investigations as well as the defense of government regulatory enforcement actions and class action litigation for clients across a broad spectrum of industries. We have handled over a thousand data breach investigations of all types including nation states, ransom/cyber extortion, vendor/supply chain, DDoS, brought by threat actors of all types, from nation-state threat actors to organized crime to insiders. We also represent clients holistically through the entire life cycle of issues, providing sophisticated, solution oriented advice to clients and counseling on cutting edge data-driven products and services including for trend forecasting, personalized content and targeted advertising across sectors on such key laws as the CCPA, CPRA and state consumer privacy laws, Section 5 of the FTC Act; the EU/UK GDPR, e-Privacy Directive, and cross-border data transfers. We also conduct privacy and cybersecurity diligence for mergers and acquisitions, financings, corporate transactions, and securities offerings.
-
- Issue 102 - September 3, 2026
- Issue 101 - August 20, 2026
- Issue 100 - August 6, 2026
- Issue 99 - July 23, 2026
- Issue 98 - June 25, 2026
- Issue 97 - June 11, 2026
- Issue 96 - May 21, 2026
- Issue 95 - May 7, 2026
- Issue 94 - April 23, 2026
- IAPP Edition - April 9, 2026
- Issue 93 - March 26, 2026
- Issue 92 - March 12, 2026
- Issue 91 - February 26, 2026
- Issue 90 - February 12, 2026
- Issue 89 - January 29, 2026
- Issue 88 - January 15, 2026
- 2026 Crystal Ball Edition - December 30, 2025
-
- Issue 87 - December 11, 2025
- Issue 86 - November 20, 2025
- Issue 85 - November 5, 2025
- Issue 84 - October 23, 2025
- Issue 83 - October 9, 2025
- Issue 82 - September 25, 2025
- Issue 81 - August 21, 2025
- Issue 80 - August 7, 2025
- Issue 79 - July 24, 2025
- Issue 78 - June 26, 2025
- Issue 77 - June 12, 2025
- Issue 76 - May 15, 2025
- Issue 75 - May 1, 2025
- Issue 74 - April 10, 2025
- Issue 73 - March 27, 2025
- Issue 72 - March 13, 2025
- Issue 71 - February 27, 2025
- Issue 70 - February 13, 2025
- Issue 69 - January 30, 2025
- Issue 68 - January 16, 2025
- 2025 Crystal Ball Edition - January 2025
-
- Issue 67 - December 12, 2024
- Issue 66 - November 21, 2024
- Issue 65 - November 7, 2024
- Issue 64 - October 24, 2024
- Issue 63 - October 10, 2024
- Issue 62 - September 26, 2024
- Issue 61 - September 12, 2024
- Issue 60 - August 15, 2024
- Issue 59 - August 1, 2024
- Issue 58 - July 18, 2024
- Issue 57 - June 27, 2024
- Issue 56 - June 13, 2024
- Issue 55 - May 23, 2024
- Issue 54 - May 2, 2024
- Issue 53 - April 18, 2024
- Issue 52 - March 28, 2024
- Issue 51 - March 14, 2024
- Issue 50 - February 29, 2024
- Issue 49 - February 19, 2024
- Issue 48 - February 1, 2024
- Issue 47 - January 18, 2024
- 2024 Crystal Ball Edition - January 5, 2024
-
- Issue 46 - December 14, 2023
- Issue 45 - November 16, 2023
- Issue 44 - November 2, 2023
- Issue 43 - October 19, 2023
- Issue 42 - October 5, 2023
- Issue 41 - September 21, 2023
- Issue 40 - August 31, 2023
- Issue 39 - August 17, 2023
- Issue 38 - August 3, 2023
- Issue 37 - July 20, 2023
- Issue 36 - June 29, 2023
- Issue 35 - June 15, 2023
- Issue 34 - May 25, 2023
- Issue 33 - May 11, 2023
- Issue 32 - April 27, 2023
- Issue 31 - March 30, 2023
- Issue 30 - March 16, 2023
- Issue 29 - March 2, 2023
- Issue 28 - February 16, 2023
- Issue 27 - February 2, 2023
- Issue 26 - January 19, 2023
-
- Issue 25 - December 15, 2022
- Issue 24 - November 10, 2022
- Issue 23 - October 27, 2022
- Issue 22 - October 12, 2022
- Issue 21 - September 29, 2022
- Issue 20 - September 15, 2022
- Issue 19 - August 18, 2022
- Issue 18 - August 3, 2022
- Issue 17 - July 21, 2022
- Issue 16 - June 23, 2022
- Issue 15 - June 10, 2022
- Issue 14 - May 26, 2022
- Issue 13 - May 12, 2022
- Issue 12 - April 28, 2022
- Issue 11 - April 7, 2022
- Issue 10 - March 24, 2022
- Issue 9 - March 10, 2022
- Issue 8 - February 24, 2022
- Issue 7 - February 10, 2022
- Issue 6 - January 27, 2022
- Issue 5 - January 13, 2022
-
- Issue 4 - December 9, 2021
- Issue 3 - November 18, 2021
- Issue 2 - November 4, 2021
- Issue 1 - October 21, 2021