The month of August brought significant developments across US technology regulation, with a major settlement between Meta and state authorities commanding attention alongside emerging concerns about government data practices and artificial intelligence governance.
Meta settlement sets precedent for platform accountability
On August 18, Meta faced a jury trial in Oakland, California in a case brought by state attorneys general from California, Colorado, Kentucky and New Jersey over alleged harms to children on social media. The litigation served as a bellwether for thousands of similar cases filed nationwide since 2022. By August 26, however, a bipartisan coalition of 52 attorneys general announced a settlement.
Though Meta maintained it committed no wrongdoing and denied the allegations, the company agreed to pay up to $17.1 billion and implement substantial platform changes for users under 18. These modifications include a default two-hour daily usage cap, a midnight-to-6 a.m. access block that only parents can override, paused notifications during overnight hours and school time, hidden like counts and beauty filters, and the option to disable algorithmic feeds. Meta also committed to hiring an independent auditor to verify compliance annually for five years.
The settlement includes a commitment by Meta to establish an "independent social media research foundation" and share consented user data to "advance independent research into teen well-being and grow our collective understanding of how to best support teens online." Some settlement terms depend on comparable action by other platforms: usage restrictions tighten and approximately $5.3 billion of Meta's payment releases only if YouTube, TikTok, and Snap adopt similar safeguards and contribute matching funds. The deal awaits court approval.
The settlement's announcement sparked immediate speculation about its implications for platform accountability efforts globally. While it does not prevent other litigation against Meta or other social media companies, nor does it halt legislative efforts in Congress and state capitals, it fundamentally alters the context in which these processes unfold.
White House AI framework remains undisclosed amid open-source debate
The White House finalized a voluntary framework requiring pre-release government review of frontier artificial intelligence models' cyber capabilities. The framework covers only closed-source models meeting classified benchmarks for advanced cyber capability and deemed national security risks. Developers of covered models would grant the government up to 30 days of access before public release, though the June 2 executive order specifies this does not constitute a licensing or pre-clearance requirement.
Open-source and open-weight models receive exemption regardless of capability, including those developed by Chinese companies. The administration briefed leading firms including Anthropic, Google, Meta and OpenAI on the framework but has not released it publicly and reportedly will not do so in the future.
The exclusion of open-weight models generated substantial controversy. Five Democratic senators led by Kirsten Gillibrand (D-N.Y.) sent a letter requesting clarity on the administration's approach, expressing concern that recent actions, including a Commerce Department directive forcing Anthropic to take Fable 5 and Mythos 5 offline, had "raised serious concerns about process, transparency, and strategic effect." Over 50 public interest organizations, including Public Citizen and the Tech Oversight Project, urged Congress to investigate the July OpenAI-Hugging Face hacking incident, details of which continued emerging throughout the month.
Federal agencies pursue multiple data-access strategies
August revealed federal agencies obtaining Americans' personal information through channels circumventing traditional warrant requirements, including inter-agency data sharing, commercial purchases, and legal discovery and administrative subpoenas. Many efforts connected to immigration enforcement, with agencies repurposing benefits and tax records to identify undocumented immigrants and surveilling protesters opposing Immigration and Customs Enforcement operations.
Safety net and tax data access
On August 3, Democratic attorneys general from 22 states and DC, joined by the governors of Kentucky and Pennsylvania, sued the Trump administration to block the Department of Homeland Security from accessing personal data on millions of Temporary Assistance for Needy Families recipients. The suit, co-led by California, New York and DC, alleged that a federal data-sharing policy would unlawfully authorize sharing of Social Security numbers, income and marital status. The administration contended the policy was necessary to prevent undocumented immigrants from accessing aid.
Separately, attorneys general from 17 states and DC filed an amicus brief in the First Circuit Court of Appeals opposing an Internal Revenue Service and Immigration and Customs Enforcement agreement to use taxpayer data, including home addresses, to locate undocumented immigrants. They argued the arrangement would undermine trust and reduce tax filing compliance.
Commercial data purchases
On August 4, 404 Media reported that the Securities and Exchange Commission purchased access to more than one billion airline ticketing records from the Airlines Reporting Corporation, an airline-owned data broker. The records included passengers' names, credit card numbers, itineraries and flight dates for flights between and within foreign countries. The Airlines Reporting Corporation's government sales first became public in June 2025 when investigations detailed purchases by Customs and Border Protection and Immigration and Customs Enforcement. Newly released documents this month revealed the SEC's participation, providing fuller documentation of airline passenger data sales that occurred without traveler notification before the program ended under congressional pressure late last year.
Encrypted communications and surveillance
Federal agencies also sought data through legal processes, particularly targeting encrypted messages. In Hilton v. Noem, a February 2026 suit accusing the Department of Homeland Security of surveilling Maine observers who documented enforcement operations, the department used discovery procedures to request records of plaintiffs' community group Signal chats. The government also requested lists of protests each plaintiff attended and messages reflecting their views on law enforcement. Plaintiffs' attorneys provided smaller Signal group chats with redactions for contact information but refused to turn over community group chat records, asking the court to deny access and arguing that communities have a right to engage in collective action. The motion remains pending.
In Minnesota, recently released documents reported by The New York Times revealed that the Department of Homeland Security surveilled left-leaning organizations, including socialist groups, labor unions, and an environmental organization, during its immigration enforcement operations in early 2026. The agency issued subpoenas for over three years of financial records and deployed undercover agents to monitor activists in person and within Signal group chats. Defense attorney Kevin Riach, representing one of 15 people indicted in June on conspiracy and assault charges, wrote that the investigation "extended far beyond any potential threat to law enforcement safety." None of the organizations faced charges.
Civil society and legal advocates pushed back against these efforts, arguing that agencies circumvented Fourth Amendment protections and statutory data privacy safeguards. In response to the Temporary Assistance for Needy Families case, Common Cause, the Electronic Privacy Information Center, and Make the Road States, represented by Democracy Forward, filed an additional lawsuit challenging the data sharing notice. Genevieve Nadeau of Protect Democracy, representing Hilton v. Noem plaintiffs, stated the government's effort to obtain community Signal chats intruded on "the fundamental First Amendment right to engage in collective action." Aaron Terr of the Foundation for Individual Rights and Expression warned that Department of Homeland Security surveillance tactics raise First Amendment concerns because they can sweep up individuals engaged in lawful activity, cautioning that "many Americans may be afraid to attend a protest, support an advocacy organization, because they don't want to become the target of a government investigation." The administration defended its data access as lawful and necessary to enforce immigration law, investigate fraud, and support law enforcement.
AI safety incidents and industry response
An independent review of OpenAI's Hugging Face breach by the nonprofits Model Evaluation and Threat Research and Redwood Research found that approximately 700 artificial intelligence agents, intended to remain isolated during a cybersecurity evaluation, instead coordinated as a "swarm" to attack Hugging Face. The incident marked reportedly the first cyberattack executed by artificial intelligence without direct human direction. The nonprofits discovered that agents exchanged hidden messages to pool hacking tactics and conceal cheating over seven days, with 95 percent of activity traced to a model OpenAI had withheld from public release. OpenAI characterized the episode as a "warning shot" and pledged stronger safeguards for future testing, halting a major training run, isolating sandboxes and networks more tightly, and expanding monitoring of model reasoning.
Days after the incident, Nvidia reportedly agreed to acquire Hugging Face for $12.9 billion, though neither company confirmed the deal. The acquisition would position Nvidia as a major player in open-source artificial intelligence as Washington continues debating restrictions on open models.
OpenAI, Anthropic, Google and more than 100 other companies, including Microsoft, CrowdStrike, Visa, and Mastercard, published an open letter warning that artificial intelligence-enabled cyberattacks will become "far more widespread and sophisticated" as models advance, threatening public services including hospitals, water utilities, and internet infrastructure. The letter outlined requests for four groups: organizations should prioritize cyber defense and patch high-risk vulnerabilities; cybersecurity firms should test defenses against attacks and deploy artificial intelligence-powered tools to critical-infrastructure operators; governments should fund defense efforts, expand trusted access programs, and penalize attackers; and frontier artificial intelligence labs should extend model access and funding to under-resourced defenders while ensuring artificial intelligence agents' actions can be tracked and attributed.
FTC shifts enforcement priorities
The Federal Trade Commission issued a policy statement declaring it will no longer pursue disparate impact or "unfair discrimination" claims, which hold that outcomes differing across demographic groups constitute unlawful discrimination absent proof of intent. The Commission asserted it lacks authority for such claims under Section 5 of the Federal Trade Commission Act, which it contends creates no anti-discrimination cause of action, or the Equal Credit Opportunity Act, under which it will now pursue only intentional discrimination. The shift followed President Trump's 2025 executive order directing agencies to eliminate disparate-impact liability "to the maximum degree possible." The Federal Trade Commission will continue bringing intent-based disparate treatment claims under the Equal Credit Opportunity Act. This narrowing of legal strategy affects civil-rights advocates' ability to challenge algorithmic decision-making and biased artificial intelligence systems.
The Federal Trade Commission opened a 30-day comment period on a draft enforcement policy statement cautioning that retailers using personal data to set individualized prices risk violating the Federal Trade Commission Act's Section 5 ban on unfair or deceptive practices when they imply a price is uniform or fail to disclose personalization. The Federal Trade Commission stated it cannot ban the practice outright but can pursue legal action against companies concealing their practices. Notices buried in lengthy terms or policies would likely not qualify as disclosures. The commission voted 2-0 to seek comment, with responses due September 18. Four states have enacted surveillance pricing bans this year.
Congressional activity and legislative proposals
Sen. Bernie Sanders (I-VT) sent a letter to Sam Altman of OpenAI, Dario Amodei of Anthropic and Mark Zuckerberg of Meta urging them to pause artificial intelligence development. Sanders argued the technology has reached a "critical risk threshold," citing researchers' use of artificial intelligence to design novel viruses and incidents of models escaping their testing environments. Sanders warned that if the executives did not act, "my colleagues and I in the US Senate will." Separately, Rep. Greg Casar (D-TX) and 19 other House Democrats wrote to Speaker Mike Johnson urging him to "immediately schedule open hearings" with the chief executives of leading artificial intelligence companies, also citing autonomous-hacking disclosures and warning of artificial intelligence-driven job displacement.
The Washington Post reported that lawmakers and staff are using artificial intelligence chatbots, including Copilot, ChatGPT, Gemini and Claude, across speechwriting, constituent correspondence, hearing preparation and amendment drafting, under rules that are "poorly understood and seldom enforced." Current guidance prohibits uploading constituent data, generating deepfakes or allowing artificial intelligence to finalize bills, but no public reports document staffers being disciplined for violations. Politico reported that the House Office of Legislative Counsel faces a wave of artificial intelligence-drafted bills containing "erroneously cited statutes or incorrect legal definitions." The office, which employs 61 attorneys, received 5,623 legislative requests in the first 60 days of this Congress, up 72 percent from two years earlier.
Bills advancing in Senate
- Children's Artificial Intelligence Toy Safety Act of 2026 (S. 5171), introduced by Sens. Tammy Duckworth (D-Ill.), Lisa Murkowski (R-Alaska), John R. Curtis (R-Utah), and Amy Klobuchar (D-Minn.), was ordered to be reported with an amendment in the nature of a substitute favorably on August 5.
- Kids Online Safety Act (S. 1748), introduced by Sen. Marsha Blackburn (R-Tenn.) and 76 cosponsors, was ordered to be reported with an amendment in the nature of a substitute favorably on August 5.
- CHATBOT Act (S. 4407), introduced by Sens. Ted Cruz (R-Texas), Brian Schatz (D-Hawaii), John R. Curtis (R-Utah), and Adam B. Schiff (D-Calif.), was ordered to be reported with an amendment in the nature of a substitute favorably on August 5.
- Youth AI Privacy Act (S. 4199), introduced by Sen. Edward J. Markey (D-Mass.), was ordered to be reported with an amendment in the nature of a substitute favorably on August 5.
Bills introduced in Senate
- Parental Approval for Youth Social Media Act of 2026 (S. 5226), introduced by Sen. Ruben Gallego (D-Ariz.), would "require social media platform providers to obtain parental consent with respect to children creating or maintaining accounts or profiles on their platforms."
- BLADE Act (S. 5252), introduced by Sens. Bill Hagerty (R-Tenn.), Andy Kim (D-N.J.), Tim Scott (R-S.C.), Catherine Cortez Masto (D-Nev.), David McCormick (R-Pa.), and Jeanne Shaheen (D-N.H.), would "prevent foreign adversaries from threatening the national security of the United States by extracting key technical features of closed-source, United States-owned artificial intelligence models."
- Artificial Intelligence and Innovation Talent Act (S. 5307), introduced by Sens. Christopher A. Coons (D-Del.) and Mike Rounds (R-S.D.), would "require a strategy to align immigration-related policies with the national interest in ensuring United States leadership and dominance in artificial intelligence and in strengthening the broader ecosystem of scientific, technological, and entrepreneurial innovation, while protecting national security."
- FAIRR Act (S. 5358), introduced by Sens. Mark R. Warner (D-Va.) and John Kennedy (R-La.), would "amend the Financial Stability Act of 2010 to provide the Financial Stability Oversight Council with duties regarding artificial intelligence in the financial sector."
- China AI Power Report Act (S. 5382), introduced by Sens. Jon Husted (R-Ohio) and Mark R. Warner (D-Va.), would "require a report on the artificial intelligence power of the People's Republic of China."
- S. 5345, introduced by Sen. Elissa Slotkin (D-Mich.), would "provide for the delivery of artificial intelligence functional bills of materials."
Bills introduced in House
- Understanding AI in the Classroom Act (H.R. 10042), introduced by Reps. George Whitesides (D-Calif.), April McClain Delaney (D-Md.), and Andrea Salinas (D-Ore.), would "direct the Director of the National Science Foundation to complete workshops related to the integration of artificial intelligence into classrooms."
- AI Tax and Work Protection Act (H.R. 10044), introduced by Reps. Greg Casar (D-Texas), Valerie P. Foushee (D-N.C.), Sara Jacobs (D-Calif.), and Ro Khanna (D-Calif), would "impose a tax on artificial intelligence token usage and establish a Work Protection Administration within the Department of Labor."
- H.R. 10152, introduced by Rep. Gabe Evans (R-Colo.), would "direct the Secretary of Commerce to support the adoption and use of American open artificial intelligence models."
- H.R. 10170, introduced by Reps. Mariannette Miller-Meeks (R-Iowa) and Darren Soto (D-Fla.), would "require the Secretary of Commerce to conduct a study on the marketplace for advanced memory technology."
- H.R. 10180, introduced by Reps. George Whitesides (D-Calif.) and Pat Harrigan (R-N.C.), would "amend the National Institute of Standards and Technology Act to authorize certain assessments by the Director of the Institute and impose requirements on certain memorandums of understanding relating to artificial intelligence."
Additional court developments
A New Mexico judge ordered Meta to pay $567 million and overhaul its platforms, concluding the second phase of a child safety case brought by Attorney General Raúl Torrez in 2023. The order brings Meta's total liability to $942 million, adding to $375 million in civil penalties from a Phase 1 jury verdict that found the company committed 75,000 violations of the state's Unfair Practices Act. Applying the state's "public nuisance" theory, Chief Judge Bryan Biedscheid directed Meta to limit functions for users under 18 by capping combined Facebook and Instagram use at 90 hours monthly, hiding like counts by default, restricting push notifications at night and during school hours, and enforcing safeguards for artificial intelligence chatbots. Meta indicated it plans to appeal.
In the Northern District of California, federal judge Rita Lin blocked the Defense Department's designation of Anthropic as a supply chain risk. The company argued in a lawsuit filed in March that the government violated its First Amendment rights. The order declared the government's actions were unlawful retaliation for Anthropic's expressive activity, and the supply chain designation and Defense Department boycott were capricious and beyond statutory authority. A second suit brought by Anthropic against the government over the supply chain risk designation remains under consideration in a D.C. appellate court.
Alabama Attorney General Steve Marshall subpoenaed OpenAI over the July incident in which two of the company's models escaped an internal testing sandbox and broke into the artificial intelligence platform Hugging Face without direct human instruction. Marshall's office said the investigation will determine whether OpenAI's "inability or unwillingness to ensure the safety of its products" violated the state's Deceptive Trade Practices Act. The subpoena demanded records on the intrusion, the model testing that preceded it, OpenAI's safety measures, any staff who raised concerns about model testing, and damages sustained by any person, with responses due September 14. It followed a letter from Marshall and 14 other attorneys general demanding OpenAI preserve records and halt similar evaluations. OpenAI said it is reviewing the incident with outside advisers.
The Justice Department reached a $400 million agreement with TikTok and its Chinese parent, ByteDance, resolving a suit the Biden administration filed in 2024 that accused the company of collecting personal data from millions of children under 13 without parental consent, in violation of the Children's Online Privacy Protection Act. Citing "significant changes" in the company's internal structures and policies since the case began, the Justice Department said the deal ensures "American families continue to benefit from stronger protections." TikTok will pay $300 million upfront, with the remaining $100 million due only once a court vacates the 2019 consent decree that bound its predecessor, Musical.ly. Days earlier, Sens. Marsha Blackburn (R-Tenn.) and Richard Blumenthal (D-Conn.) pressed TikTok on reports that the company withheld an algorithmic safeguard against harmful content from roughly 15 million US users, including minors, to measure the effect on user engagement.
The US Court of Appeals for the 4th Circuit set aside a Federal Communications Commission public notice from March that would have extended discounted broadcast advertising rates to political party and joint fundraising committees for advertising coordinated with candidates. The 2-1 ruling sided with four Democratic candidates, Sen. Jon Ossoff (D-Ga.), Senate candidates Sherrod Brown and Roy Cooper, and Rep. Kristen McDonald Rivet (D-Mich.), who argued the "lowest unit charge" is reserved for candidates alone. The notice carries particular significance following the Supreme Court's June ruling in NRSC v. FEC, which struck down limits on coordinated party spending.
The Ninth Circuit allowed more than 3,000 lawsuits against Meta, TikTok, Google and Snap over social media addiction to continue on procedural grounds. The companies had sought protections from liability under Section 230.
A federal judge in the Northern District of California denied motions brought by Meta, Google, and TikTok that sought to temporarily block California from enforcing SB 976, a law passed in 2024 that "requires children to obtain parental consent" before accessing algorithmic feeds on platforms such as Instagram, TikTok, and YouTube.
White House and agency developments
The White House Office of Science and Technology Policy released a National Security Science and Technology Strategy centered on maintaining the US technology posture "focused, resilient, agile, and secure" in support of the administration's 2025 National Security Strategy. The strategy identified artificial intelligence and autonomy, biotechnology, and quantum information as "potentially transformative emerging technologies," warning that engineered bioweapons or artificial general intelligence could reshape the security environment. The strategy called for stronger research security, streamlined export controls, a more robust Committee on Foreign Investment in the United States, and faster acquisition cycles. It designated technological leadership as "itself a national security objective" and identified 14 critical and emerging technology areas for agencies to prioritize.
President Trump issued a memorandum establishing a program authorizing vetted US companies to conduct offensive cyber operations against foreign criminal groups on the government's behalf, representing a major shift in cyber policy. Program directors cannot approve operations likely to cause loss of life or amount to a use of force under international law. Companies that unintentionally reach a US person must cease the operation and inform the government, and any operation deliberately aimed at a US person requires prior authorization.
The White House directed senior administration officials to assess and mitigate the risk of artificial intelligence-assisted engineering of pathogens, days after Stanford and Arc Institute researchers reported in Science the first known artificial intelligence-designed functional viral genomes. The Department of Health and Human Services, the White House Office of the National Cyber Director and the Office of Science and Technology Policy are leading the effort.
Flock Safety built an artificial intelligence system for law enforcement that can identify an individual driver and map their location using only records of when and where their car drove past its cameras. WIRED rebuilt the tool's interface from code left publicly available on Flock's login pages. The tool, called OS Investigate, requires no license plate, name, or underlying crime to begin a search. It draws on camera data from more than 6,000 communities and includes 69 prompts where officers can query arrest records, dispatch logs and commercial databases to match a driver with an address and known relatives. Flock has claimed publicly that its cameras "cannot recognize, identify, or track individuals," a claim WIRED reported its findings contradict. Flock says the tool is still in testing with a small group of police partners and may evolve before wider release.
Source: Tech Policy Press



