01
Creator Economy
NO FAKES Act Reintroduced May 21 — Civil Society Flags Overreach as Senate Markup Looms
On May 21, 2026, Senators Blackburn, Coons, Tillis, and Klobuchar formally reintroduced the NO FAKES Act (Nurture Originals, Foster Art, and Keep Entertainment Safe), alongside companion House sponsors. The bill creates a federal right of publicity covering AI-generated voice and likeness replicas, with a 70-year post-mortem term — a provision civil liberties organizations including Public Knowledge immediately flagged as tilted heavily toward the entertainment industry. The bill's lack of explicit protections against debt-related seizure of likeness rights and an unbalanced counternotice framework drew sharp criticism in a joint letter to the Senate Judiciary Committee filed the same week. This version places platforms on direct collision course with Section 230 immunity doctrine through explicit platform liability provisions.
Why This Matters for Your Clients
Talent, creators, production companies, and influencer-adjacent brands need to assess what a federal likeness right — with 70-year post-mortem protection — would mean for existing AI tool agreements, contract language, and licensing structures before Senate Judiciary moves to markup. New York's own synthetic performer disclosure law (S.8420-A) takes effect June 9, 2026, creating a two-layer compliance obligation in the near term regardless of NO FAKES' final fate.
Watch For
Senate Judiciary markup schedule following reintroduction; whether the 70-year post-mortem term is negotiated down; SAG-AFTRA and RIAA coalition responses; and New York brand/agency penalties beginning June 9, 2026 ($1,000–$5,000 per violation).
02
AI Governance
Take It Down Act Went Live May 19 — FTC Issues Second Warning Wave; 48-Hour Takedown Clock Now Running
The Take It Down Act (TIDA) became enforceable on May 19, 2026, exactly one year after President Trump signed it. The federal law criminalizes the publication of non-consensual intimate imagery (NCII) — including AI-generated deepfakes — and requires covered platforms to remove flagged content within 48 hours of a valid takedown request. On May 20, 2026, the FTC issued a second round of compliance warning letters to a dozen platforms still missing required appeal and removal processes. For media, ad-tech, and creator clients, the practical risk is not only direct liability: platforms under compliance pressure are now deploying aggressive automated filters that are flagging lawful creative content — satire, commentary, fan fiction, legitimate editorial imagery — as NCII, with no realistic 48-hour review window for false positives.
Why This Matters for Your Clients
Content creators, production companies, and platforms hosting user-generated content now face active FTC oversight, not just prospective rule-making. The over-removal risk is real: the EFF flagged during passage that the 48-hour window incentivizes automated takedowns of legal content. Any client whose content touches intimate portrayal, AI-generated imagery, or likeness simulation should audit their platform agreements and content moderation appeal rights now.
Watch For
First FTC enforcement action or consent order under TIDA; platform AI filter false-positive litigation; whether the FTC's "reasonable efforts to identify identical copies" standard gets formally interpreted; and any parallel state-level NCII enforcement in New York or California using TIDA as a floor.
03
IP & Copyright
OpenAI MDL: SDNY Orders "Multimodal Data Sources" Document Review — Depositions of Altman & Nadella Confirmed
In In re: OpenAI, Inc. Copyright Infringement Litigation (25-MD-3143, SDNY), Magistrate Judge Ona T. Wang issued a May 12, 2026 order directing OpenAI to submit its "Multimodal Data Sources" project document for in camera review, with briefing due by May 15–19. The MDL — which consolidates 12+ copyright cases from news organizations and authors — already has depositions of Sam Altman, Greg Brockman, and Microsoft CEO Satya Nadella on record. Courts are forcing full disclosure of OpenAI's internal characterization of training data practices, which could directly determine whether its commercial training model qualifies as "fair use" under the fourth Campbell factor. Simultaneously, a federal court in April 2026 ruled that music generated primarily by AI — even when curated by a human producer — lacks the "substantial human authorship" required for copyright registration.
Why This Matters for Your Clients
Clients producing AI-assisted music, visual content, marketing material, or licensed IP need an ownership analysis before they license, assign, or litigate. The April 2026 AI music ruling — combined with the Supreme Court's March 2026 refusal to hear Thaler v. Perlmutter — means the human authorship floor is now locked at the federal level. California's AB 412 (AI Copyright Transparency Act), currently in Assembly committees as of May 2026, would impose per-day damages if AI developers don't disclose use of specific copyrighted works — directly affecting any California creator or studio.
Watch For
SDNY ruling on OpenAI's "Multimodal Data Sources" protective order; whether discovery reveals internal commercial characterization of training data (fourth Campbell factor); Anthropic's $1.5B settlement with authors potentially finalizing; CA AB 412 Assembly committee votes this summer; and the Third Circuit fair-use appeal in Ross Intelligence v. Thomson Reuters.
04
Startup & Corporate
New York AI Transparency Bill Passed Legislature — SEC "AI Washing" Enforcement Pattern Intensifies
On March 9, 2026, New York Assembly Bill A3411B passed the state senate and was sent to Governor Hochul. If signed, it will require all owners, licensees, and operators of generative AI systems to display a clear and conspicuous interface notice that AI outputs may be inaccurate — with civil penalties of $1,000 per violation, 90 days after signature. This follows a sweeping 2026 wave of New York AI transparency statutes covering algorithmic pricing disclosure, companion chatbot oversight, and synthetic performer labeling. Meanwhile, the SEC continues its post-Delphia/Global Predictions pattern: the Division of Corporation Finance is issuing AI comment letters and treating any material overstatement of AI capabilities in registration statements, fundraising decks, or public disclosures as potential securities fraud — a risk Morgan Lewis flagged in April 2026 as intensifying for growth-stage companies with no comprehensive federal AI statute to provide safe harbor.
Why This Matters for Your Clients
Growth-stage AI and tech companies preparing for fundraising rounds in New York must audit user-facing AI disclosures and investor materials simultaneously. The New York $1,000/violation penalty is per incident — a single non-compliant SaaS product with thousands of daily users creates compounding exposure fast. On the SEC side, any growth company describing "AI-powered" capabilities in pitch materials or annual reports must ensure those descriptions match actual deployed functionality, or risk investigation before a banker, auditor, or regulator forces it.
Watch For
Governor Hochul's signature on A3411B and the 90-day effective date; SEC Division of Corporation Finance AI comment letters targeting growth-stage filings; and whether the Trump AI Litigation Task Force formally challenges New York's state-level AI disclosure patchwork under federal preemption doctrine.
05
Cyber & Cross-Border
Cybersecurity Enters Client Exposure Territory — California CPRA Audit Rules Live; Cross-Border AI Data Risk Now Client-Facing
Effective January 1, 2026, California's CPRA cybersecurity audit rules and automated decision-making technology (ADMT) regulations became enforceable, with staggered executive certification deadlines beginning in 2028. These rules require businesses processing personal data through AI — including content recommendation engines, marketing personalization, and influencer analytics platforms — to conduct formal privacy impact assessments and cybersecurity audits. For cross-border operations, this intersects directly with a new layer of risk: the EU AI Act's prohibited and high-risk system provisions are now in a phased rollout (prohibited practices banned since February 2025; high-risk rules from August 2026), while China amended its Cybersecurity Law effective January 1, 2026 to explicitly regulate AI development with fines up to 10 million yuan. For creative clients with international licensing, streaming, or brand partnerships, the cross-border data flow triggered by AI training, AI-generated content distribution, and synthetic performer usage now creates simultaneous California, EU, and Chinese regulatory exposure.
Why This Matters for Your Clients
A client in music, fashion, or media with a streaming catalog distributed globally — or an AI tool vendor with a California user base — now has at minimum three jurisdictional cybersecurity and AI governance obligations running in parallel. The practical entry point for most clients is vendor due diligence: reviewing AI tool agreements, data processing addenda, and whether their SaaS stack has mapped CPRA's ADMT rules. Cross-border licensing agreements involving AI-generated content may also need governing law updates now that China's amended Cybersecurity Law explicitly covers AI outputs.
Watch For
California CPPA enforcement actions under the new ADMT rules; first multistate AG coordination action on cross-border AI data practices; EU AI Act high-risk system requirements taking effect August 2026; and whether California's DROP (Data Removal & Opt-Out Platform) data broker registry expansion — live August 1, 2026 — captures AI model training data vendors.