Dechert Cyber Bits

Issue 103 - September 24, 2026

Key Developments in Cybersecurity, Privacy & AI


Catch Dechert at IAPP Privacy. Security. Risk. + AI Governance Global 2026!

Will you be at IAPP PSR in Seattle on October 8-9? Partners Ben Sadun and J.J. Jones will speak on "Privacy Programs on Trial and Incident Response Under Fire" on Tuesday, October 8 at 11:30 a.m. If you'll be in Seattle, come by to say hello to Ben and J.J. 


FTC Rescinds Obsolete Health App Breach Notification Guidance

The Federal Trade Commission (“FTC”) has rescinded a Biden-era policy statement that interpreted the Health Breach Notification Rule (“HBNR”) to cover health apps and connected devices that collect consumer health information, including fitness trackers (“Policy Statement”). Under the Policy Statement, a breach of consumers’ personal health records by such apps or devices would trigger a notification obligation under the HBNR to affected consumers and the FTC. At the time the Policy Statement was issued, the HBNR had never been enforced in its decade-long existence. Following the Policy Statement, the FTC brought actions against several digital health companies alleging violations of the HBNR. The FTC later revised the HBNR itself to extend to health apps and connected devices (“2024 HBNR Updates”). 

In its action rescinding the Policy Statement, the FTC noted that the Policy Statement had been superseded by the 2024 HBNR Updates, and that the Policy Statement had been “contentious at the time of issuance” and of “minimal benefit,” citing dissents made by Commissioners at the time. The FTC also cited President Trump’s January 2025 executive order directing federal agencies to eliminate unnecessary rules and reduce complicated federal regulation, including a specific instruction to curb reliance on sub-regulatory guidance such as policy statements.

Takeaway: Because the FTC has not announced any decision to reverse the 2024 HBNR Updates, health apps and connected devices remain subject to HBNR requirements. Still, companies may fairly read the Commission’s recent rescission of the Biden-era Policy Statement as an indication that this FTC is less likely to actively enforce the HBNR against health apps and connected devices.


European Commission Designates ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act 

On August 31, 2026, the European Commission (“Commission”) designated ChatGPT as a Very Large Online Search Engine ("VLOSE") and Reddit and Roblox as Very Large Online Platforms ("VLOPs") under the Digital Services Act ("DSA"). All three companies had reported average monthly EU user numbers above the 45 million threshold that triggers designation under the DSA. What sets the ChatGPT designation apart is the theory behind it: rather than treating the chatbot solely as a platform, the Commission concluded that ChatGPT’s ability to respond to user prompts by searching the web is, on its own, sufficient for it to function as an online search engine within the meaning of the DSA.

A four-month compliance period is now running for all three companies: by January 2027, each must comply with the increased obligations that come with VLOP and VLOSE status, including identifying and mitigating systemic risks arising from their platforms. The designations also give the Commission expanded, direct investigative authority over the mechanics of the respective services. Notably, day-to-day oversight will not sit with the Commission alone: Ireland's Coimisiun na Mean (Ireland’s Independent Media Regulator), will have oversight over ChatGPT and Reddit, and the Netherlands' Authority for Consumers and Markets will have oversight in relation to Roblox.

Takeaway: This marks the first time the Commission has designated a generative AI chatbot as a VLOSE and indicates that the Commission views a service responding to prompts by searching the web as being sufficient to qualify that service as an online search engine under the DSA. We expect the Commission will apply a similar approach in assessing the status of other AI assistants with comparable functionality. Businesses operating AI-powered services with an EU user base are advised to assess whether they are approaching the 45 million monthly user threshold that triggers DSA designation, and plan accordingly.

 


gears

California Governor Signs Over a Dozen Bills Addressing Online Safety for Minors

On September 10, 2026, California Governor Gavin Newsom signed over a dozen bills addressing online safety for children and minors under 18, including a comprehensive framework regulating AI companion chatbots bills and bills banning addictive features for children under 16.

SB 1119, known as Adam’s Law, directs operators of companion chatbots that interact with users under the age of 18 in California to perform comprehensive annual risk assessments that evaluate “covered harms” (such as privacy issues, and physical, psychological and/or emotional harm) associated with the chatbot. Operators must also maintain crisis response protocols for their products, implement default parental controls, prohibit the chatbot from engaging in certain harmful conduct, and not use a minor’s engagement with the chatbot to serve targeted ads. SB 1119 also requires operators to submit to biennial independent third-party child safety audits by January 1, 2029. Audit summaries will need to be posted to the operator’s website and submitted to the California Attorney General. Public prosecutors can bring civil enforcement actions under the law for up to $5,000 per affected child (for negligent violations) and up to $15,000 per child for intentional violations. The law also contains a private right of action.

AB 1709 prohibits social media platforms from implementing potentially addictive features (such as autoplay, unlimited scrolling and personalized feeds) for users under 16. Notably, the California Attorney General may add to the list of impermissible features over time. AB 1709 imposes penalties of up to $50,000 per minor for knowing violations and up to $25,000 per negligent violation and can be enforced by the California Attorney General or local public prosecutors. AB 1709 does not include a private right of action.

Takeaway: The package of laws signed by Governor Newsom represent the most sweeping and hard-hitting approach to minors’ safety online by a regulator to date. Companies offering chatbots and other online services to minors under 18 in California will want to promptly review their obligations under these new laws. We anticipate compliance will have significant impact on user experience and product development and design, including the need to implement age verification checks for children under 16 in some cases.

 


gears

Cybersecurity Mishaps Carry FCA Price Tags, DOJ’s Honeywell Enforcement Shows 

On September 1, 2026, the U.S. Department of Justice (“DOJ”) announced that Honeywell Aerospace (“Honeywell”), an aerospace supplier to government and commercial customers, agreed to pay over $2 million to resolve allegations that a business unit failed to meet cybersecurity requirements tied to a Department of Defense (“DOD”) contract. The allegations, which started with a whistleblower qui tam complaint, alleged that, for one of its networks, Honeywell fell short of the National Institute of Standards and Technology’s (“NIST”) Special Publication 800-171 controls, which are required to safeguard Controlled Unclassified Information (“CUI”) residing on nonfederal systems. These controls are implemented in government contracts through the DOD’s Cybersecurity Maturity Model Certification (“CMMC”) program.

Honeywell joins a growing list of contractors facing False Claims Act (“FCA”) exposure over alleged cybersecurity gaps. The DOJ recovered over $52 million in cybersecurity-related FCA actions in fiscal year 2025 alone.

As part of the settlement, Honeywell did not admit wrongdoing, and issued the following statement: “Honeywell Aerospace has been and remains committed to a robust and fully compliant cybersecurity program that protects our networks and our customers. Honeywell Aerospace complies with all applicable cybersecurity requirements and laws and its contractual and regulatory obligations.”

Takeaway: Cybersecurity compliance is emerging as a distinct area of potential exposure under the FCA, as the DOJ’s latest settlement shows. Although the DOD has paused full implementation of the CMMC program, existing contractual requirements to implement cybersecurity controls are still in effect, and the DOJ’s settlements indicate that the agency views them as legitimate hooks for potential FCA liability.


gears

Dechert Tidbits 

Florida AG Pushes to Make AI Companies Criminally Liable for Chatbot-Assisted Crimes

The Florida Attorney General proposed legislation that would hold companies criminally responsible when AI chatbots they own, control, or distribute participate in a crime, with penalties including heavy fines, victim payments, and court-ordered monitorship. The proposal follows the Florida AG’s civil suit against OpenAI and CEO Sam Altman over the FSU mass shooting, in which the shooter allegedly used ChatGPT to plan the attack, plus an expanded criminal investigation covering a separate double homicide involving another ChatGPT user.

CalPrivacy Flags Data Broker Reporting Gaps

On September 3, 2026, the California Privacy Protection Agency ("CalPrivacy") issued Enforcement Advisory No. 2026-01, warning data brokers that providing inaccurate information in their annual Delete Act registration (in addition to simply failing to annually register) can trigger a fine of $200 for each day that the incorrect information appears in the registry (“Advisory”). CalPrivacy warned that the Delete Act does not distinguish unintentional mistakes from intentional misrepresentation. The Advisory follows more than a dozen registration-related enforcement actions CalPrivacy has brought against data brokers since November 2024.

AI Risk Management Toolkit: Guidance published by the UK Department for Science, Innovation and Technology (DSIT)

DSIT published an AI Risk Management Toolkit to help organizations involved in designing, procuring, and deploying AI-enabled products identify and manage AI-related risks throughout a system's lifecycle (“Toolkit”). Building on the government's existing Orange Book risk management framework, the Toolkit provides a risk assessment guide, critical risk-identification questions, a workbook for tracking identified risks and treatment actions and a monitoring dashboard spanning financial, legal and regulatory, transparency, fairness and accountability categories. Though designed for UK government departments, the Toolkit offers a useful practical reference point for any organization looking to structure its own AI governance and risk assessment processes.

 


Please note that where a “Takeaway” is missing from one of our
blurbs, it is likely because one of the parties involved is a client of the
firm or otherwise has an interest in the matter.  


In 2025 and 2026, Dechert’s Cyber, Privacy & AI team achieved top individual and group rankings in The Legal 500 and Chambers USA. Global Chair and Partner Brenda Sharton, a Law360 MVP, and Partner Ben Sadun, a Law360 Rising Star, were recognized for their leadership and contributions to the team’s achievements. The team was also recognized in Law.com’s “Litigators of the Week” column for its recent victory for Flo Health, a matter that showcased the team’s strategic excellence. Thank you to our clients for entrusting us with the types of matters that led to these recognitions.




Dechert Cyber Bits Partner Committee


Dechert’s global Cyber, Privacy and AI practice provides a multidisciplinary, integrated approach to clients’ privacy and cybersecurity needs. Our practice is top ranked by The Legal 500 and our partners are well-known thought leaders and sought after advisors in the space with unparalleled expertise and experience. Our litigation team provides pre-breach counseling and handles all aspects of data breach investigations as well as the defense of government regulatory enforcement actions and class action litigation for clients across a broad spectrum of industries. We have handled over a thousand data breach investigations of all types including nation states, ransom/cyber extortion, vendor/supply chain, DDoS, brought by threat actors of all types, from nation-state threat actors to organized crime to insiders. We also represent clients holistically through the entire life cycle of issues, providing sophisticated, solution oriented advice to clients and counseling on cutting edge data-driven products and services including for trend forecasting, personalized content and targeted advertising across sectors on such key laws as the CCPA, CPRA and state consumer privacy laws, Section 5 of the FTC Act; the EU/UK GDPR, e-Privacy Directive, and cross-border data transfers. We also conduct privacy and cybersecurity diligence for mergers and acquisitions, financings, corporate transactions, and securities offerings.

View Previous Issues