
Loading summary
A
This podcast is brought to you by audiohook, the leading independent audio dsp. Audiohook has direct publisher integrations into all major podcast and streaming radio platforms, providing 40% more inventory than what could be accessed in omnichannel DSPs. What's more, audiobook has full transcripts on more than 90% of all podcast inventory, enabling advanced contextual targeting and brand suitability. Audio Hook is so confident that in addition to CPM buys, they offer the industry's only pay for performance option, where brands can scale audio and podcasting with peace of mind mind knowing they are only paying for outcomes. Visit audiohook.com to learn more. That's audiohook.com.
B
Welcome to the Monopoly Report the Monopoly Report is dedicated to chronicling and analyzing the impact of antitrust and other regulations on the global advertising economy. Alan I'm Alan Chappelle. I'd like you to imagine something for a moment. Your company being mentioned on a future episode of one of the most popular podcasts in the digital media space, with your products and services being talked about by me. Alan Chappelle that would be pretty cool, wouldn't it? If you're interested in sponsoring the monopoly report, visit Market now on to today's topic. There are 19 separate states that have enacted comprehensive privacy laws and a bunch of different states that are starting to regulate on AI. I'd imagine that we'll see even more states in 2026 and continued clashes between the states and the federal government, which seems to increasingly be looking to preempt state efforts to regulate on AI. This week my guest is Coben Zweifel Keegan. Coben is the Managing Director of the IAPP International association of Privacy Professionals in Washington, dc. Through this role, Coban works to integrate the diverse voices of privacy professionals into the evolving tech policy conversation, engaging with business representatives, civil society, congressional leaders, and federal government stakeholders. Coben's writing for the IAPP newsletter has become a must read for privacy and other regulatory pros. Coban is a great person to talk about emerging trends at the state level when it comes to regulation, including regulation in the ad space. So let's get to it. Hey Colvin, thanks for coming on the pod. How are you?
C
I'm doing pretty good. How are you doing, Alan?
B
I'm doing fantastic. We're spending the rest of the summer or the last remaining days in the summer out in the Bay Area in Sausalito, which is sort of has been a second home for me for the last 15 or so years.
C
That's awesome. I'm jealous. I'm just here in D.C. and it's actually getting a little bit fallish out there. It's starting to cool down a bit. So it's been. It's been pretty hot, but not so much anymore.
B
So let's dive in. So historically, one of the number one questions that I've received, at least from the US business community is, you know, what are the chances of a federal privacy law being passed this year? But the far more interesting discussions around privacy and AI and consumer protection are currently taking place at the state level. So before we get into the substance of what's happening at the state level, let's talk a bit about the culture and key drivers. You know, the obvious one is that there's a vacuum left by congressional inaction. But I'm curious, is there anything else that might be driving the states to act?
C
Yeah, I think one big driver is really just that consumers want these laws. That we keep seeing consumers, as technologies evolve, catching up and wanting to have at least some sort of reflection of protections. Consumer protections, data rights, in theory, kind of in a democracy. Right. We want to see what the people want put into practice, at least sometimes. In the US we call them consumers, in the eu, we call them data subjects. I think both take a little bit of life out of remembering that these are people who exist in the world and want. And they all have varying levels of interest in privacy overall. But often I think there's a strong interest in avoiding digital surveillance. And I think that has been a big part of the push. I think it's not by accident that we saw the first state comprehensive consumer privacy law occur because of the threat of a ballot initiative, which would have been a popular mechanism to get that into law, and California, and since then it's been spreading. So I do think that's one factor. You're right that congressional inaction is another. I think the states waited quite a long time just to see if Congress would step in and pass a comprehensive consumer privacy law. The states haven't been waiting when it comes to AI, and I'm sure we can talk about that a little bit more. By now they figured out that Congress is probably not going to move as fast as the states can. So the timeline has been a lot different on AI governance than we saw on privacy. But especially once states start comparing themselves to each other, comparing the protections they're providing to consumers, you start to see the legislative action speed up. And that's been a big driver for sure.
B
I probably spent at least the first decade of my Career sort of pushing back on what I would characterize as the tinfoil hat view, where a lot of the harms were ethereal, were hard to demonstrate, and as a result, those voices that may have had concerns were easier to dismiss. And what's really happened over the last, we'll say, five to seven years is that you now have tangible harms. Stuff is starting to break, and people, people, not data subjects or consumers, but people are starting to get hurt. And so on some level, the state action, at least in my view, is driven from. They're looking out there and they're seeing people hurt.
C
Yeah, I think that's true. And you see that in a bunch of different contexts, but certainly around a lot of the same kind of sensitive areas that we talk about in privacy when it comes to sensitive data. So location information, health information, as technology has evolved to be able to make more powerful inferences about people and to be able to. And is more intrinsic to our lives. And there's sensors everywhere. I think we do see a continuing increase of the possible risks, and then sometimes those are being brought to bear on individuals for sure.
B
So prior to 2018, the ballot initiative that you just talked about in California, that. That ultimately led to the CCPA state action, and I'm probably oversimplifying here a bit, but state action was mostly limited to what I might call activist AGs. You had Elliot Spitzer back in, what, 2004 and 2005, to a lesser extent, Kamala Harris in California around 2015. But federal inaction on privacy goes back a long way. And so how do you explain what's taken place at the state level? It's just, you know, you kind of alluded to this a minute ago. I mean, they were sort of waiting and waiting. What ultimately made the states decide to. To jump in now?
C
Yeah, I think there was that whole period of time where states were waiting to see. And there was a lot of. There has been discussions at the federal level for well over a decade, probably two decades now, on various types of Internet regulation, including privacy restrictions. And I don't want to give too much credit to California, but I think it is. That is kind of where the spark finally struck. And we had seen some grassroots advocacy and other. And lots of bills in various places. But it was California that we finally saw a law passed under the threat of the ballot initiative, under that kind of major pressure from the grassroots advocacy that was happening. And since then, yeah, legislators do have a tendency to kind of innovate and experiment. And we've seen the discussion evolve over the past five or six years through a lot of legislative cycles in a bunch of different states. And I see it as a national conversation. Mostly this is all happening in kind of the same policy conversation. The states are watching each other. The same stakeholders are showing up at the state legislatures all over the country. And you can kind of track the genealogy of these bills as they've evolved through Washington state, where there was a lot of the first innovations that became the kind of template for the other states that passed privacy laws, even though Washington never managed to pass theirs.
B
Well, they came back with the fury when they did pass something, though.
C
They did. They've. Yeah, they certainly passed something. And it's certainly powerful for what it covers, that's for sure. Yeah, for me, that's kind of one big part of that is just the. That it's all part of one big policy conversation. And often it's the same stakeholders that would have been engaging at the federal level have been turning to the states because that's where the action's happening.
B
Yeah, and. And you know, it's easy to forget California sort of led the way for a long time. What was it, 2005 when they passed the first data breach notification law? California actually is one of the reasons I got into the privacy space, because I was in the email marketing space in 2003 and there was a opt in consent law coming down from Florida. I'm just right from California that everybody was sort of freaking out about and all of that fear, uncertainty and doubt coming through the email space. And ultimately it was preempted by can spam. But I said, you know what, there's something to this privacy thing. And that's actually when I decided to put out my shingle.
C
I mean, California also led with calapa, which is that was the basis for. You mentioned Kamala Harris's actions. And yeah, that really helped to push for companies to have privacy policies, which then enabled the Federal Trade Commission to have more robust enforcement for deception. Because once you're forced to put your practices down on paper, it's a little bit easier to accidentally or on purpose say something wrong and deceive consumers.
B
So what are some of the key themes coming from the states? What are the areas of focus that you're seeing?
C
Yeah, that's a great question. And I think I'd like to focus a lot on the enforcement side in the conversation because I think that's where we've been seeing a lot of the newest lessons from privacy, not so much from what legislators are passing and the newest bills. But what we're seeing and how attorneys general are actually enforcing these laws. And over the past couple of years, we're actually seeing all of these laws come online. We have 19 comprehensive consumer privacy laws across the states now. And I think all but three of those are now in effect. And all those states have empowered their attorneys general to bring actions against companies. And we see a wide variety of kind of, of resources put towards that. States are definitely used to engaging on consumer protection enforcement. And so this is usually being built into that unit within an AG's office. But some states have provided the AG with specific funding to enforce these laws, whereas other states haven't. So usually in the states that don't have the funding, you don't see, you only see a couple of dedicated staffers of dedicated lawyers who are going after companies in this area. Like one, one and a half is maybe the average, maybe two. But some states have actually given millions of dollars to the to units to actually build a robust enforcement strategy. And so that's why we see states like Texas. That's one of the main reasons we see states like Texas and California, which has two enforcers, and now most recently Minnesota, which we haven't seen any actions from, but they just came online. That's one of the big reasons we kind of see more activity from those folks. But you asked about themes and kind of what are the big areas of focus for those enforcers? I guess I'll highlight three. We can kind of go through them if you like, I think. Sure. We already talked briefly about sensitive data, and I think location data in particular is always going to be a focus area for enforcers because it is something that people perceive as very sensitive, very intrinsic to their lives. And now we have these trackers all the time that show where we are. The other two that I'll highlight and we'll go through them one at a time. Health, I think is a good one to focus on because we did just see a big health enforcement action in California and then automated decision making. I'll also talk about, because even though we haven't seen a ton of enforcement on that front, that one's more of a big theme on the legislative side and that touches on this AI issues and kind of why they're so focused around privacy. So yeah, first on location, but Texas started to focus on and has been a big theme of its first year has been the auto industry, which for a long time wasn't the subject of a lot of regulatory scrutiny. And as cars have gotten smarter and there's more and more sensors in cars. We've also seen integrations from car companies that potentially share information with insurance companies. So the location story in Texas is actually also a story about third party sharing and insurance and inferences used to help insurance companies manage risk profiles of consumers of drivers. And so Texas sued rather than negotiate with these companies, Texas decided to directly sue General Motors and Allstate and Allstate subsidiary Arity. Both of those matters are related to this type of data collection and making of driver scores. And Texas has alleged that the consumers really aren't aware of this, even if it's maybe disclosed in initial paperwork, and that it's a very invasive thing that consumers should don't necessarily expect their cars to be reporting on how risky they are as drivers.
B
Yeah, and this sort of gets to my earlier point, which is things that were talked about 10, 15 years ago. I remember John Lebowitz, when he was at the FTC was, was literally railing about the potential in the ad space for using data for insurance eligibility decisions. And most of us at the time were like, sir, nobody is doing that. That would be crazy for anybody to do that. And now, lo and behold, 15 years later, that exact fear has come to fruition. And so crazy is the new black, I guess. And something like somebody where you point to, you'd say that's never going to happen. Well, it turns out a lot of those fears are really coming to fruition. I feel like I owe an apology to Joe Tooru over at, over at UPenn because I think in retrospect he was right.
C
It's funny how that happens. Yeah, I mean, I think a big portion of consumer protection laws is based on consumer expectations. And that's kind of a double edged sword. And we still see how much that matters both in this insurance context and also in this Healthline case that I'll talk about. But it's a double edged sword because we expectations shift and as we get used to stuff, as we get used to certain types of tracking and things, maybe the ball moves a little bit and then maybe companies feel a little more comfortable doing the next thing to monetize.
B
So one of the things that's made the great state privacy experiment relatively palatable from the business community. And by the way, I know that palatability is not the goal of people creating these laws, but the thing that's made it less of a huge deal is that there's been a level of consistency across the various state rule sets. You know, there isn't a ton of variance at least as it applies to the ad space. And I'm curious, do you think that's going to change? Because a lot of states are going back for second and third time to revamp their laws. Do you think that we're going to look back in two or three years and there's going to be a, a wide variance in terms of, you know, what California requires versus what New Jersey requires?
C
Yeah. Those are funny examples to use. Yeah.
B
Well, they both have rulemaking, right.
C
They relate to each other. Yeah. It relates to the answer, for sure. You're previewing the answer. Yeah. I think overall, like you said, these laws are very similar to each other. California is a bit of an outlier. The others share a lot of common genes, and we are seeing states continue to want to innovate and expand on those. They like being the laboratories of democracy. They like shifting and coming up with new things. There's a lot of changes legislatively in terms of broadening of the definition of personal data and how we think about different types of sensitive personal data, but overall, they're really similar. Yes. This year we didn't actually see in this, in this legislative cycle in 2025, we didn't see any state pass a new comprehensive consumer privacy law, but instead we saw a number of states, a number of the earliest states, go back to the drawing board and revise their laws. A lot of those revisions were in keeping with other states. So it's not necessarily innovating beyond what we've already seen. Like Connecticut kind of. If you look at Connecticut's amendments, they're really a kind of a hodgepodge of some of the innovations that have shown up in other states like Maryland and Minnesota. And the legislature kind of picked and chose some, some ways to make their law even better. But yeah, I think in rulemaking, as you previewed, I do think we're starting to see some deviations. California just finalized their automated decision making rules. Those do differ from the Colorado regulations on automated decision making. New Jersey has draft rules, and I know industry has been very plugged into that draft. And I'm sure New Jersey will be sifting through a lot of comments from various stakeholders because what I've heard from industry is just that a lot of the rules are different, are outliers compared with what's expected and interpretations from states. And so we'll see. I don't know what New Jersey's final rules will look like, but I do think we are seeing these differences take place that sometimes do have operational impacts.
B
Yeah. The thing that comes to mind for me is the more variance there is. And then if some state does something, you know, that, that comes off as draconian, either in how they're enforcing the law or in the rule set that they're creating. You know, sooner or later that's going to create an impetus for a federal preempting, you know, privacy law. Now, that hasn't happened yet for a whole bunch of reasons, but it does feel like that's moved from unlikely to improbable. I don't know if that's even a step in the direction towards federal preemption of something, but it does feel like that might be starting to shift. Do you agree? Disagree?
C
It's hard to. Yeah. That goes back to your, your initial question that you didn't actually ask of when will we see a federal privacy law? Because we've gotten tired of asking and answering that question. There's still a lot of interest from Congress to pass something. It's always just comes down to the question of what it would look like. And there are a lot of, there's a lot of activity happening even now. So I don't want to say that it's impossible, but we, we've all gotten a little chilled on the idea that maybe that would one day happen. And it, maybe it does play out the way we saw data breach laws play out right there. We, everyone predicted that we would one day have like that because there would be variations and there are a lot of variations in data breach laws in terms of the number of days you have to respond and all of the other intricacies of reporting for data breaches. But it never panned out. Right. We never saw a preemptive federal law, and now we have 50 plus data breach rules across the states. Maybe that's the way we'll go. I think if a state came along that was even stronger on remedies like, or on process, if there was a, for example, if there was a very strong private right of action that a state actually passed, that might be a big enough spark to still get Congress to act on preemption. But yeah, right now in the Commerce Committee in the House, they're working on a partisan draft legislation, a Republican version of a comprehensive consumer privacy law, which probably will look a lot like the states. And that is expected, I think, this fall at some point to see what that draft might look like. They're just trying to get all their ducks in a row for, for what a Republican version of that looks like, which is helpful for the overall picture of of how this might one day be negotiated to have a final law.
B
Well, it feels like they've bifurcated things a bit. So previously the discussion was, will they come up with a federal privacy law, and will that privacy law preempt state law? And they've sort of removed the. They seem to be talking about preemption more and more now, almost outside of the confines of whether or not they will actually choose to create a rule set both as it applies to privacy and AI. I mean, that big, beautiful bill was step one. Right. And then they started tying or tried to tie federal funding to, you know, state action in certain areas. And it's hard to regulate AI without also regulating privacy, I guess, is my point.
C
Yeah, I see what you mean. They're definitely related and overlapping policy areas. AI policy is a very broad area. It covers every committee on the Hill, and there's all sorts of possible activity across the economy on AI guardrails. What we end up focusing on as the type of lawyers that we are is the consumer protection kind of the stuff. The stuff that's going to impact commercial systems, the. The stuff that will protect consumers. And yes, this year we have a very different approach from the Republican side, and they're the ones in power on AI regulation broadly and including on the kind of AI governance, consumer protection side. Very hands off, very deregulatory. And that includes this moratorium idea, which is not quite preemption, because you can't preempt something with nothing. And they know that, and they don't quite know exactly what they would do in terms of an overall structure for AI governance, because it is complex, it does cover the whole economy, and there's a lot of different types of AI systems out there. So instead you have this moratorium idea. It is related to privacy because a lot of the activity we see already covering AI systems in law is from the privacy world because of these automated decision making rules that we have in some states. The Colorado AI act is an extension of those automated decision making rules. That's one of the main drivers of AI law, and it was explicitly brought into that. The drafting of the language for the moratorium explicitly included not just AI laws, but anything that covers automated decision making systems. So it was explicitly appearing to target those parts of privacy. But I would caveat that with saying that there's not the same emphasis on deregulation of privacy at the federal level. I think if there were, when we do see a bill from the Republican side, it won't say we shouldn't have privacy laws. It would, it would be a version of the state laws that we already have.
B
So I had recently, and this is sort of on the same topic, I had recently posted what I thought was sort of a tongue in cheek article predicting a federal privacy law. And mostly I was reacting to what I thought was a great New York Times piece by Mike Isaac and Kashmir Hill about Spotify's privacy settings and how some hacker managed to publish a list of music listens of a bunch of lawmakers and other policymakers. But it reminded me of the 1987 confirmation hearings of Robert Bork where somebody had published A list of Mr. Bork's video rental history and that rent really freaked out lawmakers out to the point where they attempted to prohibit this from ever, ever happening again to them via the Video Privacy Protection Act. So I don't know if you're going to be willing to play with me on this, but what makes you think that these Panama playlists referenced in that New York Times article wouldn't result in a similar level of congressional cya?
C
Well, I have to say first that your article was definitely it was going around the group chats we people were some people were not taking it as tongue in cheek. I as soon as I opened it and read it more closely I was like oh yeah, he's messing with us here a little bit. But I definitely see your point that when it hits home for people is when they and especially legislators, when these things hit home, it spurs them to action. We've actually seen this isn't as fun of an example, but we've seen the killings in Minnesota spur the discussions on both at the congressional level and then in Minnesota when their law was going into effect but also at the congressional level. We've heard that come up again and again in ongoing privacy discussions because that was definitely noticeable to lawmakers that this person used data brokers and people search websites to be able to figure out where they actually live. So that was certainly felt closely to them. But I don't know. So if that I guess the question is like if that won't spur action, I don't know that people's music histories will. It does seem like some lawmakers have taken it in stride more than others. There was it became a bit of a meme and a discussion topic on various social media websites where people would were riffing off of the like the in in Florida, I guess the governor was saying that his playlist had been incorrectly identified but he liked some of the songs but he added other songs to the list that he would have. Would have been listening to. So yeah, I think to your point though, yeah, that when it does hit home, sometimes it spurs action. I think there might be something different when it comes to the pornographic tendencies that were revealed in the, in the video rental history that maybe doesn't show up in our music listening habits.
B
Well, but the point I was making, and again, a little tongue in cheek here was that like somebody could be outed via their music taste potentially. There's. I actually think though, overall, if one was looking to set up an ad targeting business, music interests would be just a fantastic proxy for where somebody is and what somebody is thinking and what mood they're in at that particular time. But the distinction between music interests and video rentals to me seemed really thin. And, and as I was thinking about this, the big distinction really is that 30 years later, we are so anesthetized to what 30 years ago would have seemed like. We wildly invasive activities. And today those are taken in stride. And we, we can debate as privacy professionals whether that's a good thing or a bad thing. But it is the thing, I think.
C
Yeah. And I think there's blurring of lines between yeah on all levels there, both on the types of entertainment that we're consuming because we have all different types of modalities where we're experiencing audio and video content and we've seen some effort to try to figure out what the lines of the VPPA is even. Right. Does that apply to Netflix? Can people sue you under. Based on a claim that any video embedded in your. In your browser is revealing your video habits? And. But then there's also kind of new modalities, right. Where immersive technologies maybe we don't. There's going to be merging of different types of content and entertainment feeds that maybe these old ideas and old regulatory structures don't necessarily apply to. So I do think, yeah, that that's our job as tech policy people always is to continue to figure out how we analogize the stories but to these new, new technologies and, and help people understand how they actually impact their lives.
B
And this sort of leads to the challenges around having a private right of action to enforce certain laws because boy, class action claimants tend to be really creative. And you've now convinced multiple judges that a website that happens to be playing a video is a videotape manufacturing company. That's like hard, hard, you know, legal precedent at this point. And so that ends up being one of the challenges, I think, with, with respect to, you know, setting up private right of Actions within. And really the core of why a large part of the business community is not in favor of a private right of action.
C
Yeah, that's a good point. Is that we see those rights continue to be creatively expanded. And although I think if there was a explicit black letter, private right of action for some of these privacy laws, you'd see those efforts pushed towards that direction instead of the very creative litigating that we see. But certainly I think there would be, the business community is probably right that there would be a lot more, there would be many more lawsuits if we had that, that kind of a private right of action in one of these laws. So yeah, I agree that's an ongoing debate. But you're totally right that you end up with rules that maybe don't directly conform to how things used to be. But sometimes that's necessary because technologies have shifted. And if the real, if what we're trying to protect is the entertainment that people like, people's entertainment interests, maybe those decisions make sense. Although now we have these odd distinctions between like video and audio, as you.
B
Mentioned, I think that some of the state level AI laws are in contrast to some of the state privacy efforts. And what I mean by that is that like the privacy efforts have been then reasonably effective, but the AI efforts I think thus far have been less so. And maybe that's just because they're still getting out of the gate and there's still a lot of discussion and definition. I don't mean to disparage any particular effort, but like, what states, in your view, have, you know, the most interesting overall approach to creating a rule set for AI thus far?
C
Yeah, that's a good question. We, and I think you're right in how you're framing this. Some of it is just maturity in terms of the policy discussion because privacy has been around for a long time. It's a very, comparatively, it's a concrete kind of a discrete set of standards and rules. We kind of understand what the practice of privacy looks like in terms of the mechanisms that are at play, the kinds of levers we can pull around people's personal data to protect it. With AI, as I talked about before, it's a much broader policy area. But even if we're just talking about kind of AI governance, internal governance structures, which looks a lot like some of the same mechanisms we see in privacy, there's a lot of discussion about what is reasonable, what should companies be doing, both developers and deployers, to make sure that their systems are responsibly designed and that they provide relevant choices or rights to consumers when needed. We still don't necessarily know what all of those rights and choices or mechanisms should be. What kind of red teaming should we be doing? How much is enough when we think about guardrails for some of these systems. So that's part of why it's a bit of a mess. It's also a mess because of the different, the wide variety of AI systems out there. We have generative AI which has kind of sparked this entire craze and this big bubble of policy commentary that we're currently in.
B
That's not the only bubble, by the way.
C
Yeah.
B
Sorry, didn't mean to interrupt.
C
No, no problem. Yeah, that's very true. And I mean we always see these, there are always policy moments and right now we're in the generative AI moment, but we were in a crypto moment for a while and I'm sure we'll be in a quantum moment eventually. But for now, yeah, everything is generative AI both in policy and in the economy. Apparently we've now become totally invested in this new technology. But that's not the only type of AI out there. And I think often what we end up with when legislators go to move on this is that they realize that it's hard to define AI. There's a lot of systems at play that are already out there. And so we get this other. One of the big categories of AI legislation is automated decision making legislation. And that's probably the one that has had the most traction, both sectorally in places like in areas like employment law, but also in the kind of cross sectoral push that we've seen. Colorado and Texas both have laws at least touching on this. Texas's law is a bit of a grab bag, but it's kind of applying civil rights protections to AI systems. If AI systems are used to make decisions or otherwise impact people. We also see lots of bills about kind of basic consumer protections for individuals, like transparency over, if you're talking to a chatbot, things like that, which I would argue is probably already illegal. It already something that's covered by consumer protection law, but we don't need to get into that. And then there's foundation model legislation I think is one of the other big themes. And that's the one that is steadfastly opposed by industry and creates a whole lot of hullabaloo every time states try to regulate the actual development of these big models that we've seen that in California we've seen lots of pushback and we don't have a. We don't have a law in place that's touching on that, even though the EU does have some rules and restrictions in its EU AI act that apply to the developer side. Anyway, Colorado just went through a big attempt to potentially revise its act, and that has not happened. It's not passed. But I think Colorado probably leads at least when we focus on that automated decision making segment of AI standards. It's the most kind of fully formed set of standards that cover automated decision making and it builds on the existing privacy, privacy law and regulations that touch on that in Colorado as well.
B
So this has been a fantastic conversation. I really appreciate you coming on cobe. And I've got one more question for you. What are your predictions over the next 18 months in terms of and privacy regulation, either at the state level or if you want to go, you know, big and bold, go for it.
C
Yeah. Some of my colleagues in the policy world try to avoid making predictions, but we'll just, we'll just go for it.
B
This deregulation, I never allowed myself to worry about being wrong at the expense of a good sound bite.
C
Exactly. It's better to say something and then. And hope that it's at least half right in the future. Yeah. The deregulatory moment that we're in isn't going to fade very quickly, but at the same time, we are seeing a lot of media attention, a lot of consumer attention to AI harms. You just had a big lawsuit yesterday from parents talking about a chatbot that they allege contributed to their son's suicide. Those kinds of stories keep showing up. And I think that level of engagement and the kind of, the, the emotional undertones that are picking up in consumer relationships with AI systems really is, is probably going to come back and to legislators, either at the state level or the federal level. That's one of the big themes that we see from, or one of the big talking points, I guess, from local legislators is that they're in touch with their constituents and their constituents are worried about this stuff. And that's part of why they want to pass laws like the Colorado AI act, which has seen similar bills in Texas and Connecticut and California and to some extent in other states as well. So I think those two things are somewhat in conflict. But there's also this idea of trying to get harmony between them. Right. If we're innovating and building these AI systems that people will actually use, consumers have to trust that the systems are responsibly built and aren't going to result in harms. And so somewhere in that mix we might find some more innovations of what the actual regulatory solutions might be. That battle between developers and employers keeps playing out and figuring out where the responsibility lies is going to be really difficult. Other predictions we'll see we'll see some bills at the federal level. We will see the House Commerce Committee is working hard. The Senate as well are they're both deeply engaged on privacy. On kids safety, we'll probably see a new version of COSA and of the comprehensive consumer privacy bill of some kind. But I certainly won't predict that anything is going to pass because it doesn't seem like that's very easy to do these days. They'll need to first start by funding the government and things like that. So that's always, it's always a challenge to predict that tech policy legislation will pass. But next term at the state level, definitely more of the same. Right. Continuing engagement on these issues. More privacy laws passing most likely, or at least another cycle of talking about them, even adjusting laws like we've seen this term. And then on AI I think there's also this question of whether states respond to this moratorium idea by doubling down on their work on AI by feeling a little slighted by Congress saying maybe they don't want states to act in this area. That might have the perverse effect of seeing even more laws. And I've heard some legislators very strongly arguing that they want to do more now. So we'll see what that looks like next year. But I yeah, this definitely going to be busy.
B
I, I think that doubling down is just as likely to see more energy towards preemption.
C
But I guess we'll see both porque no los dos. But I mean yeah. And we the moratorium idea in Congress is also not going away. It will almost certainly return, especially in those places where there's no requirement for Democratic support. So the next time we have a must pass piece of legislation to get a budget done or when we go back into budget reconciliation next year, most likely we might see these same things come up. And yeah, we'll see. I don't know if there's a bit of disagreement on the Republican side about whether that kind of preempting states on that issue makes sense. But it's a strongly held belief among the committee chairs that they want to make that happen. So it's definitely not going anywhere.
B
Well, thanks for your thoughts. Coban Coben Zweiful Keegan I would encourage my audience to read religiously your writings for the International association of Privacy professionals. The IAPP stuff you've done has been fantastic and for me is a must read. So thank you so much for coming on the show.
C
Thank you so much for having me and for reading. I really appreciate it.
B
That was a great conversation. A couple of themes Number one, Copenhagen seems very bullish on the states continuing to lead on privacy, AI and consumer protection, noting that the states are starting to, in effect, compete with and build upon each other's ideas. While I think that's true, I'm of the mind that you're going to see more federal efforts to preempt or rein in state regulatory efforts. The Big Beautiful bill will not be the last attempt for Congress to restrict state action. There's some irony here in that, given the GOP's historical push for state rights in terms of state privacy and AI themes, Coban emphasized health, precise location, and automated decision making, which would include profiling. I've been pretty vocal on the perils of health and precise location models in the ad space. Number three, Coleman emphasized enforcement at the state level and it's certainly true that we're starting to see a bunch of states and I'm looking at you, Texas. Certain states are beginning to really flex their muscles when it comes to enforcement. One under discussed component of state level enforcement is that some states are beginning to hire outside law firms to assist them in ways that the FTC and the DOJ and other federal agencies have never been allowed to do. Bringing in outside law firms is going to have a significant impact on the type of cases brought, and the fines imposed for violations are likely to increase significantly. And lastly, Covid and I riffed a bit on the likelihood of a federal privacy law and why we're both a bit weary of being asked the question repeatedly over the past 20 years. We also talked a bit about a recent article I wrote in the Chappelle substack, commenting on the recent New York Times story about some hacker exposing the Spotify listening habits of lawmakers and policymakers. I compared that to the publication of Supreme Court nominee and antitrust celebrity Robert Bork's videotape rentals back in 1987 and how that mini scandal resulted in the Congressional CYA known as the Video Privacy Protection Act. I'll link to my substack in the description of this episode. Overall, this was a fun discussion and thanks very much for listening.
A
Thank you for listening to the Market podcast. New episodes come out every Friday and an insightful vendor interview is published each Monday. You can subscribe to our library of hundreds of executive interviews at marketecture tv. You can also sign up for free for our weekly newsletter with my original strategic insights on the week's news at News Market Architecture tv. And if you're feeling social, we operate a vibrant Slack community that you can apply to join@adtechgod.com.
Host: Alan Chapell
Guest: Cobun Zweifel-Keegan, Managing Director, IAPP
Date: September 3, 2025
This episode delves deeply into the evolving landscape of U.S. state regulation of privacy and artificial intelligence (AI) in the absence of comprehensive federal action. Alan Chapell and guest Cobun Zweifel-Keegan discuss the factors driving states to innovate new privacy laws, key enforcement and legislative trends, and the growing patchwork of state approaches to regulating both data privacy and AI. The conversation explores how and why states are becoming laboratories for tech regulation and the implications for businesses, individuals, and future federal action.
Timestamps: 03:00–08:55
Consumer Demand & Federal Inaction
Tangible Harms Now Evident
Timestamps: 06:47–10:29
California’s Pioneering Role
Activist AGs in Early Privacy Battles
Timestamps: 10:29–15:25
Key Enforcement Areas
Resource Disparities Among States
Unexpected Consistency (so far)
Timestamps: 15:57–22:05
States Begin to Diverge in Rulemaking
Will this Push Federal Preemption?
Timestamps: 22:05–25:00
Timestamps: 24:03–30:20
Analogies and Media Moments
Normalization of ‘Invasive’ Practices
Private Right of Action Debates
Timestamps: 30:20–34:47
Privacy vs AI Legislative Effectiveness
Foundational Model Regulation
Timestamps: 34:47–39:36
Persistent State Leadership
Federal Action Still Unlikely
Alan closes by highlighting Cobun’s insights and recommending he be read “religiously” for all privacy professionals (39:19). He emphasizes the continuing trend of state leadership but sees growing momentum—and political irony—in renewed federal preemption efforts.
End of Summary