Skip to main content
Legislation

The Current

The Current #11 — Nobody Has to Warn You First Anymore

State privacy cure periods have closed and the regulators now coordinate — plus the CISA 2015 expiry, Comcast's $117.5M patch-gap settlement, and where AI hiring liability actually moved.

Charles Redding, Founder, DLegendDigital7 min read

Four items, one thread: for years most of what could go wrong at your company came with a warning shot first — a regulator's letter, a grace period, a federal shield if you spoke up. Three of those are gone or going, and the fourth was never coming from where people thought. Enforcement isn't growing. It's changing hands.

Your Privacy Grace Period Expired — and the Regulators Started Comparing Notes#

For three years, most state privacy laws came with a right to cure: get a regulator's letter, fix it inside thirty days, matter closed, no penalty. A lot of companies quietly let that window become the plan. It has now closed in Connecticut, Colorado, Delaware, Oregon, Montana and Tennessee, with Minnesota's sunsetting later this year. Indiana and Kentucky went the other way and made theirs permanent — so the map is genuinely uneven.

Meanwhile the enforcers stopped working alone. On August 4, 2026 Vermont became at least the ninth member of the Consortium of Privacy Regulators. Last September four of them ran a joint sweep on the same day against businesses ignoring browser opt-out signals. And on May 8, 2026 California's AG, district attorneys and the state privacy agency together announced a $12.75 million settlement with General Motors and OnStar over selling connected-vehicle location data — the largest penalty under the state's privacy law, and the first built on data minimization, which needs no breach and no broken opt-out. It asks only whether you collected more than your stated purpose required.

Two things are live now with no future date attached: the expired cure periods, and the rule that a data protection assessment must be done before high-risk processing starts — a precondition, not a deadline you can miss. Full breakdown in this cycle's blog post below.

The Federal Shield for Sharing Threat Intel Expires September 30#

The Cybersecurity Information Sharing Act of 2015 — the law giving companies liability protection and FOIA exemptions when they share cyber threat indicators with the government and each other — is scheduled to lapse on September 30, 2026. Congress extended it there in February, after it had already sunset once in September 2025 and spent roughly six weeks genuinely expired.

We know what a lapse looks like, because we just lived through one. Sharing didn't stop, but counsel at a lot of companies had to re-examine whether a shared indicator was now FOIA-able, or usable against them by a regulator later. The result was hesitation at exactly the moment speed matters.

If your security team is in an ISAC (an industry threat-sharing group) or any government program, ask counsel one question before October: what changes about what we share if the protections lapse again? In September that's a conversation. In October it's a scramble.

$117.5 Million for a Five-Day Patch Gap#

Comcast settled the Xfinity data breach class action for $117.5 million, covering roughly 31.6 million notified customers. The claim window closed August 14, 2026.

The detail worth sitting with is the timeline. Attackers got in between October 16 and 19, 2023 through Citrix Bleed (CVE-2023-4966), a flaw in Citrix NetScaler. Citrix published the fix on October 10 — five days before the intrusion began.

That's the whole story: not a zero-day, not a sophisticated adversary, not a missing control. A patch existed, and the gap between "available" and "applied" was five days on an internet-facing appliance. Three years later that gap is worth nine figures.

Pull your list of internet-facing appliances — VPN concentrators, load balancers, gateways — and find out honestly how fast you patch one when a fix drops. Not your policy's answer; your last three actual instances. If it's longer than a week, you now have a dollar figure to attach to that in your next budget conversation.

The Federal AI-Hiring Enforcer Stepped Back. The Liability Didn't.#

The EEOC has withdrawn its AI technical-assistance documents and stepped back from disparate-impact enforcement. You could read that as pressure coming off employers who use AI to screen candidates. It isn't.

Title VII still bars selection procedures that create unjustified adverse impact — the statute didn't change, only the agency's posture. State AI hiring laws keep arriving. And liability is widening, not narrowing: vendors can be held responsible under ordinary agency principles when they exercise control over employment decisions or act on the employer's behalf. Cases against AI hiring vendors over algorithmic bias are in the courts now.

The exposure didn't disappear when the federal guidance did — it moved to private plaintiffs and to your vendor contract. If you screen candidates with any automated tool, read the indemnification language in that agreement this month and ask the vendor what bias testing they run and whether they'll share results. A vendor who won't answer in writing is telling you where the risk will sit.

One Level Deeper: There Are Three Doors, and You've Only Been Watching One#

Here's the pattern behind these four items, which the blog doesn't cover because it stays inside the regulatory lane. Enforcement reaches you through three doors, and most compliance programs face only the first.

Door one is the regulator. Predictable, procedural, announces itself, historically came with a cure window. This is what your compliance calendar is built around.

Door two is the private plaintiff. No warning, no cure period, no threshold to argue about. Comcast's $117.5 million came through this door, and California's chatbot law built a private right of action right into the statute. It doesn't wait for an agency to finish hiring.

Door three is your counterparty. The customer's vendor questionnaire, the security addendum, the indemnification clause. This one often moves first, because contracts get renegotiated faster than statutes get written.

The exercise takes ten minutes: name your top three compliance investments this year and ask which door each defends. If all three answer "door one," you've built for the slowest and most forgiving one. GM came through door one. Comcast came through door two. AI hiring is arriving through door three. Same control failures, three arrival paths — and only one sends a letter first.

How This Impacts Your Organization#

The principle doesn't change with company size: the assumption that something official warns you before it costs you is weaker than it was. What changes is which door reaches you first, how much slack you have when it opens, and where your leverage sits.

Large Enterprises (1,000+ employees)

Your real risk is organizational: each door is watched by a different function. Legal tracks regulators, litigation tracks plaintiffs, procurement handles counterparty questionnaires — and they rarely compare notes, so the same control gap gets assessed three times with no shared answer. Your leverage is that you can mandate one source of truth. This quarter, take one control area — data retention, given the GM minimization theory — and produce a single answer that satisfies all three doors, owned by one named person. Also settle before October whether a CISA 2015 lapse changes your sharing posture, or that call gets made ad hoc by whoever is on the bridge.

Mid-Size Organizations (100–999 employees)

You feel this fastest, because the cure period was doing more work for you than for anyone else — "launch it, fix it if someone writes" was a rational use of scarce attention when the statute offered a second chance. It doesn't anymore. The overcorrection to avoid: standing up a privacy or AI governance program in response. You don't have the staff, and it won't touch the actual defects. Three moves, no platform team needed: test your own opt-out end to end and follow the data into every downstream system; get real patch latency on your internet-facing appliances from your last three instances; read the liability clause in any AI screening contract before renewal.

Small & Growing Organizations (under 100 employees)

Honest counsel: two of these four probably don't reach you. You're likely below the thresholds of most state privacy laws — Texas is the outlier with essentially none — and probably not in a formal threat-sharing program. Don't buy anything off this issue. What does reach you is doors two and three, and both are cheap. Make sure that when someone asks you to delete their data, it actually gets deleted everywhere — not just in the first system you thought of. And if you use any tool to screen applicants, ask the vendor in writing what bias testing they do. That costs an email and tells you whether you're carrying someone else's risk.

  1. Your Privacy Grace Period Expired — and Now the Regulators Compare Notes (companion blog post) — dlegenddigital.com/blog
  2. Vermont joins the Consortium of Privacy Regulators — ago.vermont.gov
  3. California AG + CPPA $12.75M GM/OnStar settlement — oag.ca.gov
  4. First CCPA data-minimization enforcement action — akingump.com
  5. Congress extends CISA 2015 through September 2026 — hunton.com
  6. Navigating the expiration of CISA's legal protections — aoshearman.com
  7. Comcast $117.5M data breach settlement — inquirer.com
  8. Citrix Bleed (CVE-2023-4966) advisory — cisa.gov
  9. AI in hiring: 2026 developments and vendor liability — akerman.com

Four stories, three doors, one thread: in most of these cases the warning shot was never a legal right — it was a habit, and habits are being retired. The fix isn't a bigger compliance program. It's knowing which door each of your controls faces, and being honest about the two you haven't watched.

On the blog this cycle: Your Privacy Grace Period Expired — and Now the Regulators Compare Notes — what closed, what's genuinely not urgent until 2027, and the seven things worth doing Monday.

Hit reply and tell me what you're wrestling with — I read every one.

— Charles Redding, Founder, DLegendDigital

Paired long-form

Your Privacy Grace Period Expired — and Now the Regulators Compare Notes

For three years state privacy law came with a 30-day window to fix whatever a regulator found, and a lot of companies quietly made that window the plan. It closed in most of the states that actually enforce - right as those regulators started running joint sweeps.

Read the full article

The Current

Get the next one before anyone else.

Twice a month. ~5 min read. No spam, no upsells buried in footnotes.

Free. Unsubscribe any time.

More issues

Full archive →