Photo of Erik Dullea

Erik Dullea

As head of Husch Blackwell’s Cybersecurity practice group, Erik assists clients in all aspects of cybersecurity and information security compliance and data breach response. Erik previously served as the acting deputy associate general counsel for the National Security Agency’s cybersecurity practice group before returning to the firm in 2023.

Key point: The rapid advancement of generative artificial intelligence (AI) facilitates the creation of highly realistic digital replicas of an individual’s image, voice, or other likeness, fueling disputes over unauthorized deepfakes, synthetic voices, and AI-generated impersonations that federal legislation might address.

Key point: On August 11, 2026, the Colorado Attorney General’s Office released draft regulations and a notice of proposed rulemaking to implement the state’s new Automated Decision-Making Technology (ADMT) Act, extending obligations to midstream developers, proposing detailed standards for when AI “materially influences” a decision, what post-adverse-outcome disclosures must contain, and what “meaningful human review” requires. Businesses operating in Colorado should review the draft rules now and consider submitting comments before the October 26, 2026 hearing.

Key point: Colorado and Connecticut recently enacted laws regulating employers’ use of AI and automated decision-making tools in employment decisions—with notice obligations, anti-discrimination requirements, and civil penalties that will require employers operating in these states to reassess their AI-driven HR practices now. Meanwhile, Illinois paused its rulemaking efforts on the circumstances under which notice of the use of AI is required.

Key Point: Several states have enacted their own ‘mini-TCPA’ laws—state-level variants of the federal Telephone Consumer Protection Act (TCPA) that impose additional restrictions on telemarketing—and the past year has brought notable enforcement and legislative developments at both the federal and state levels.

Key point: CISA’s virtual town hall meetings for CIRCIA rulemaking have been rescheduled for June 15-18, 2026.

On May 26, 2026, CISA announced the dates for the rescheduled CIRCIA rulemaking town hall meetings between June 15-18, 2026. The agency’s use of town halls is discretionary and is not mandated within the federal rulemaking process. CISA canceled the original events because of the DHS funding impasse, and the new meetings will be held virtually as described in the table below.

Key point: 2026 may be a pivotal year for organizations to monitor cyber incident reporting requirements—the voluntary sharing allowed under CISA 2015 remains available, but only through September, and regulations delineating who and how mandatory reporting requirements are managed under CIRCIA are coming.

A recent ruling by the Southern District Court of New York sets a historical precedent for the use of generative AI platforms in the legal profession. The court found that a client’s prompts to a generative AI system and documents generated by AI to share with counsel are not protected by the attorney-client privilege or

Key point: Historically, civilian‑agency contractors who handled Controlled Unclassified Information (CUI) enjoyed an informal compliance environment, with a requirement to adhere to NIST SP 800‑171 often framed as self‑attestation. That world is now decisively over, with the GSA following a path similar, but not identical, to the DoD’s CMMC requirements.