About
California

California

Tracking California legal and regulatory developments.

9 entries in Tech Counsel Tracker

LawSnap Briefing Updated May 25, 2026

State of play.

  • Newsom has shifted California's AI posture from government risk management to labor-market intervention. The May 21 executive order directs four state agencies to study AI-driven layoffs and skills gaps, develop WARN Act amendment recommendations, and examine worker-ownership models — signaling that employment-side AI regulation is the next legislative frontier .
  • CCPA compliance obligations are expanding into routine operational practices. The CPPA's updated regulations require written risk assessments for processing activities posing "significant risk" to consumer privacy, with obligations for new covered processing beginning in 2026 — and call recording combined with analytics, AI tools, or profiling now falls within scope .
  • The Musk v. OpenAI jury has returned a verdict rejecting the founding-agreement claims, signaling judicial reluctance to enforce informal nonprofit governance commitments against organizational evolution toward commercial structures .
  • Cal/OSHA successor liability doctrine is clarified but incompletely defined. The "substantial continuity" test binds acquirers to predecessor citation history — including repeat-violation penalty exposure — but courts have not resolved how strictly the standard applies across different restructuring types .
  • For counsel advising employers, technology companies, entertainment IP clients, or healthcare operators with California operations, the practical baseline is a multi-front compliance environment: CCPA risk-assessment obligations for call recording and employee data, AI workforce disruption rulemaking, Cal/OSHA successor liability in M&A, CIPA litigation exposure, and active AI copyright and hiring-tool litigation are all simultaneously live.

Where things stand.

  • CCPA risk-assessment obligations now reach call recording. The CPPA's phased regulations require documented risk assessments for processing posing "significant risk"; call recordings combined with analytics, AI, or profiling trigger the requirement, but the agency has not yet issued specific guidance on which practices cross the threshold — leaving businesses to apply a balancing test without a clear safe harbor .
  • CCPA employee data protections are in active rulemaking. The CPPA solicited public comments on potential updates to employee privacy notice requirements; the employment exemption expired January 1, 2023, and a 2023 AG enforcement sweep established baseline compliance expectations .
  • CIPA digital wiretapping litigation has reached a structural inflection point. More than 4,000 lawsuits and arbitrations target website tracking technologies; federal courts are split on whether CIPA's pen register framework applies; the California Court of Appeal's forthcoming ruling in Variety Media will determine whether CIPA or the CCPA framework governs — a binary outcome with major exposure implications for any company running standard web analytics .
  • Cal/OSHA successor liability follows the "substantial continuity" test. A corporate reorganization, name change, or asset sale does not automatically shield a new entity from inheriting predecessor citation history; Cal/OSHA bears the burden of proof, and misidentification of the employer entity remains a viable appellate defense; repeat-violation penalties make the determination high-stakes in M&A and facility consolidations .
  • The AG's CPOM enforcement posture has hardened. AG Bonta's unsolicited amicus brief in Art Center Holdings argues that MSO succession agreements granting unilateral physician-replacement rights violate CPOM even when unexercised; expanded injunctive enforcement authority against PE-backed platforms remains active .
  • The Federal Circuit has reinforced the patent-trade secret boundary under California's UTSA. Patent disclosures irrevocably place information in the public domain, foreclosing trade secret claims on the same subject matter; a surgical instrument list sent by email without confidentiality markings also failed for insufficient secrecy measures .
  • Right of publicity and false endorsement claims are an active litigation category in California. The Dua Lipa v. Samsung complaint layers copyright ownership, California right of publicity, and Lanham Act false endorsement over a single manipulated backstage photograph used on consumer product packaging — testing consent, licensing chain, and damages allocation across multiple theories simultaneously .
  • AI copyright doctrine is being shaped in California federal courts. Anthropic's transformative fair use argument for Claude training data is pending; the Bartz v. Anthropic $1.5 billion settlement with over 100,000 authors and rights holders has a fairness hearing scheduled in San Francisco federal court .
  • AI hiring tool vendor liability is in active litigation. Mobley v. Workday has a certified ADEA class with viable disparate impact claims against the tool vendor; how indemnification provisions in vendor contracts allocate exposure between platform developers and deploying employers remains unresolved .
  • California's absolute noncompete ban applies extraterritorially. Business and Professional Code § 16600.5 voids noncompetes regardless of where signed or which state's law the agreement selects; choice-of-law provisions have not reliably resolved the conflict in litigation .
  • SB 553 workplace violence prevention enforcement is entering its active phase. The two-year anniversary of the law's effective date arrives July 2026; mandatory annual retraining and plan reviews are now required, and Cal/OSHA inspections are increasingly likely .

Latest developments.

Active questions and open splits.

  • What WARN Act and severance obligations will California impose on AI-driven workforce reductions? Newsom's executive order directs agencies to examine WARN Act amendments and severance requirements, but no specific thresholds, timelines, or enforcement mechanisms have been defined — employers cannot yet calibrate compliance posture for AI-driven headcount decisions .
  • Which call-recording practices cross the CCPA "significant risk" threshold? The CPPA has not issued specific guidance on when call recordings trigger the risk-assessment obligation; businesses must apply a balancing test without a clear safe harbor, creating material compliance risk for contact centers, healthcare, and financial services operations .
  • CIPA scope: pen register statute or CCPA compliance pathway? The California Court of Appeal's ruling in Variety Media will resolve whether cookies and tracking pixels trigger CIPA's warrant requirement or fall under the CCPA's clearer compliance framework — a binary outcome affecting every company with a California-facing website .
  • CPOM enforcement: categorical ban on succession rights vs. fact-specific control analysis. AG Bonta's position in Art Center Holdings — that any unexercised MSO replacement right violates CPOM — conflicts with calls for an actual-control analysis; the Court of Appeal's resolution will determine whether existing MSO agreements across California require immediate restructuring .
  • Cal/OSHA successor liability: how strictly does "substantial continuity" apply across restructuring types? Courts have not resolved the standard's application to different corporate restructurings, acquisitions, and contract transitions — leaving acquirers uncertain about inherited citation exposure and repeat-violation penalty risk until the agency or courts provide clearer guidance .
  • AI training data fair use doctrine. Anthropic's transformative fair use argument in California federal court, alongside the Bartz settlement, will shape whether large-scale ingestion of copyrighted works for model training is defensible without licensing — a question with industry-wide implications regardless of which company prevails .
  • AI hiring tool liability: vendor vs. employer exposure allocation. Mobley v. Workday has a certified ADEA class with viable disparate impact claims against the tool vendor; how indemnification provisions in vendor contracts allocate exposure between platform developers and deploying employers is unresolved .

What to watch.

  • Agency recommendations from Newsom's AI workforce executive order — the first agency outputs will define the scope of potential WARN Act amendments and severance requirements, setting the compliance baseline for employers using AI-driven workforce tools .
  • CPPA guidance on call-recording risk-assessment thresholds — specific agency direction on which practices cross into "significant risk" territory will determine whether contact center, healthcare, and financial services operations require immediate compliance restructuring .
  • California Court of Appeal ruling in Variety Media CIPA case — outcome determines whether businesses face CIPA's warrant-requirement exposure or the CCPA compliance pathway for standard web analytics, with immediate implications for the 4,000+ pending suits .
  • Bartz v. Anthropic fairness hearing outcome in San Francisco federal court — approval or rejection sets the damages benchmark for AI copyright disputes and signals how courts will treat training data acquisition going forward .
  • California Court of Appeal decision in Art Center Holdings — the ruling on MSO succession agreements will either validate or require restructuring of PE-backed physician practice platforms statewide .
  • Post-verdict proceedings in Musk v. OpenAI — any post-trial filings, regulatory follow-on, or shareholder challenges will clarify whether the jury verdict fully insulates OpenAI's governance structure or leaves residual exposure .

9 Contributing Entries

Apple sues OpenAI and two ex-employees for stealing trade secrets to build AI hardware

Apple sued OpenAI and two former Apple employees on Friday, July 10, 2026, in the U.S. District Court for the Northern District of California, alleging coordinated theft of trade secrets to accelerate OpenAI's consumer hardware development. The complaint names Chang Liu and Tang Tan as defendants and accuses OpenAI of orchestrating a campaign to recruit Apple staff and extract confidential project information, including technical drawings and component specifications. Apple alleges that Tan, while still employed there, used insider knowledge of confidential projects to extract proprietary information from job candidates during OpenAI interviews before his departure.

Apple sues OpenAI, alleging coordinated trade secret theft for AI hardware

On July 10, 2026, Apple filed a federal lawsuit in the Northern District of California against OpenAI, former Apple executives Tang Tan and Chang Liu, and io Products, LLC, alleging a coordinated scheme to steal trade secrets and accelerate OpenAI's entry into consumer hardware. The complaint accuses OpenAI of systematically acquiring confidential Apple information—including product designs, manufacturing processes, and supply chain strategies for the iPhone, Apple Watch, and MacBook—to build competing AI devices.

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based law firm, faces two proposed class-action lawsuits over a data breach that exposed sensitive information on 57,554 current, former, and prospective clients. The breach occurred in May 2026 when a cybercriminal impersonated the firm's IT department and convinced an attorney to upload client files to an external Google Drive account. The exposed data includes names, Social Security numbers, addresses, dates of birth, driver's license numbers, passport numbers, medical records, and health insurance information. Blank Rome announced the breach to affected clients on June 26, 2026—nearly a month after the incident occurred. The firm stated it will "aggressively defend" against the suits and claims they lack merit.

26 Meta Employees Sue Company Over AI-Driven Layoffs Targeting Disabled and Leaved Workers

Twenty-six current and former Meta employees filed a federal lawsuit Monday in the U.S. Northern District Court of California alleging the company used artificial intelligence systems to systematically target workers with disabilities or those on protected medical, parental, or family leave during its May 2024 mass layoff. The plaintiffs claim Meta replaced managerial discretion with AI-driven metrics—including productivity scores, keystroke monitoring, and AI token consumption data—to generate termination lists, effectively penalizing employees for approved absences. The complaint names specific tools including Metamate, Meta's internal AI assistant, and employee-built monitoring dashboards that allegedly recorded absences as "disengagement" and suppressed performance ratings. One plaintiff was terminated while on approved pre-birth leave; another alleges a manager discouraged medical leave by warning that leadership would "definitely" fire them if they took it.

12 State AGs Sue to Block $110B Paramount-Warner Bros. Discovery Merger

On July 13, 2026, a coalition of 12 state attorneys general filed a federal antitrust lawsuit challenging Paramount Skydance Corporation's $110 billion acquisition of Warner Bros. Discovery. Led by California Attorney General Rob Bonta and joined by officials from Minnesota, Oregon, and nine other states, the plaintiffs argue the merger violates the Clayton Act by eliminating competition between two of Hollywood's five major film distributors and cable operators. The states contend the deal would raise movie ticket and cable prices, reduce employment in the entertainment sector, and diminish consumer choice in news and entertainment programming.

Federal Judge Denies Meta's Summary Judgment, Allowing NJ Youth Mental Health Trial to Proceed

A federal judge in California has denied Meta Platforms' motion for summary judgment, clearing the way for a multistate lawsuit over youth mental health to proceed to trial in August 2026. The ruling, issued June 29 by the U.S. District Court for the Northern District of California, rejects Meta's attempt to have the case dismissed and confirms that the attorneys general's claims have sufficient legal merit to survive pretrial scrutiny.

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based national law firm, faces a proposed class action lawsuit alleging it failed to protect sensitive client data after a May 2026 social-engineering attack compromised information on over 57,000 individuals. An unauthorized third party impersonated IT staff and tricked a Blank Rome attorney into uploading confidential files to an external Google Drive account, exposing names, Social Security numbers, and potentially financial and medical records. The lawsuit names Blank Rome as defendant and alleges violations of common law, industry standards, the Federal Trade Commission Act, and HIPAA due to inadequate cybersecurity safeguards and delayed notification.

Scientology Seeks CA Supreme Court Review Over Boies Schiller AI Citation Errors

The Church of Scientology International has petitioned the California Supreme Court to review an appellate court's decision not to sanction Boies Schiller Flexner LLP over citation errors in a brief filed during a harassment and retaliation suit. The errors—mischaracterized authorities and a completely fabricated case—were generated by artificial intelligence. Partner John Kucera acknowledged failing to verify the AI-generated citations and sought to withdraw the brief, but the lower court denied the request. The appellate court subsequently declined to impose monetary sanctions, prompting Scientology's legal team to escalate to the state's highest court.

mail Subscribe to California email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap