August 2026: State Regulators Seize the Quiet Season
State regulators finalize regulations, conduct audits, and start rulemaking while Congress preps for what's ahead.
It’s August: the month DC tech policy folks are supposed to get a brief reprieve as Congress heads into recess, and most state legislative sessions have concluded for the year. It’s been a while since “August recess” actually meant a quiet month. But it is relatively less busy, and in that spirit, this edition is slightly more abridged than the usual full debrief/policy analysis of each development.
That said, “quiet” doesn’t necessarily mean idle. The team and I spent last week at the National Conference of State Legislatures (NCSL) Annual Conference, where tech policy programming, significantly around AI, dominated the agenda for the first time. It’s a clear sign the state tech policy conversation is continuing to expand beyond the usual players, as tech itself becomes an election issue in its own right — and, increasingly, a source of friction. As expected, lawmakers were focused on chatbots, youth online safety, and data brokerage. But tech policy conversations generally carried an undercurrent of real frustration between legislators and industry representatives — not a new dynamic, but one that feels uniquely tense heading into an election year.
This Issue: focuses on a few significant regulatory developments during this legislative quiet month and what’s coming, including:
New York’s finalized SAFE for Kids Act rules;
CalPrivacy’s announcement of the first compliance audit;
An upcoming Senate markup on kids online safety and AI;
Key active bills in Massachusetts and California; and
Vermont’s AADC rulemaking.
Martin Johnson Heade (1859), “Approaching Thunderstorm.” This object’s media is free and in the public domain. A fitting image for a month that feels slower: the calm holds for now, but the horizon shows what lies on the other side of recess.
1. New York Issues Final Implementing Regulations on SAFE for Kids Act
On July 28, New York Governor Hochul and Attorney General James announced the final implementing rules for the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, a 2024 law restricting social media platforms from providing “addictive” feeds to minors without verifiable parental consent (VPC). Under the law, the attorney general was tasked with promulgating regulations on age assurance, VPC, and any other rules necessary to effectuate the law's provisions.
Some important components of the final implementing rules include:
Certified Age Assurance: When a covered operator lacks actual knowledge that a user is a minor, it must apply an age assurance method that complies with Section 700.4 — which prescribes specific certification standards that include requirements and benchmarks for documentation, accuracy, data processing, security, and testing.
VPC: To obtain verifiable parental consent for a minor's use of a covered platform, operators must identify the parent's age through the certified age assurance process, use a method reasonably calculated to confirm the individual is the minor's parent, and account for parental privacy, safety, and the risk of circumvention or fraud. Consent obtained under COPPA also satisfies this requirement, so long as notice specific to this law is provided.
While Governor Hochul has signed and finalized the SAFE for Kids Act rules, as well as the “Safe By Design Act” in the budget bill, three other consumer tech proposals await her signature, veto, or chapter amendment: S 9051 (companion chatbots), S 9408 (chatbots in toys), and S9269 (consumer health).
2. CalPrivacy Begins First Privacy Compliance Audit
The California Privacy Protection Agency (CPPA) announced it has opened its first formal compliance audit, targeting gig economy platforms’ compliance with the California Consumer Privacy Act (CCPA) and specifically whether these companies are honoring consumers’ rights to access and control their personal information. According to the agency, the new Audits Division, led by Sabrina Ross (a longtime industry governance professional who will be joining FPF’s Privacy Executives Summit in October), is separate from the Enforcement Division, though audit findings may lead to enforcement referrals in appropriate circumstances. While little is specified in the announcement, a few things stand out:
Application to Workers and Contractors: California’s privacy law is unique in extending beyond consumers to employees. The CPPA’s announcement specifies that the audit will examine whether both consumers and workers, including independent contractors who make up the majority of gig platform workers, can access what information is collected about them, how it’s used, and with whom it’s shared, all within the required 45-day response window. The audit will also assess whether responses are complete and whether consumer control mechanisms are functioning properly.
This focus tracks with the agency's stated priority on consumer rights functionality, as well as its forthcoming rulemaking on employee data later this year.
Compliance Audit: Not to be confused with a technical performance audit, this “audit” evaluates compliance under the CCPA, not the security or functionality of their systems. Under 11 CCR § 7304, CalPrivacy may examine business practices directly, without needing a prior complaint or settlement (a somewhat notable shift from the complaint and investigation-driven enforcement model previously utilized by CalPrivacy). The announcement comes just one month after Illinois enacted the first-ever compliance audit requirement under its new frontier model law — together suggesting compliance audits may be emerging as a new regulatory lever for privacy and AI alike.
The audit also may double as fact-gathering recon for CalPrivacy’s broader pre-rulemaking activities on data broker audits, employee data, notices and disclosures, reducing friction in the exercise of privacy rights, and opt-out preference signals. The next board meeting is scheduled for August 6th and 7th to discuss opt-out preference signals.
3. Senate Confirms Rumored Markup on Kids Online Safety and AI
This Wednesday, the Senate Committee on Commerce, Science, and Transportation will host a markup of five key pieces of legislation: S. 737 (SCREEN Act), S 1748 (Kids Online Safety Act - KOSA), S 4199 (Youth AI Privacy Act), S 4407 (CHATBOT Act), and S 5171 (Children’s AI Toy Safety Act). The markup follows the House’s passage of the Kids Internet and Digital Safety (KIDS) Act, which similarly bundled KOSA, the SCREEN Act, and AI chatbot safeguards (the SAFE Bots Act). Notably absent from the Senate’s slate, though, are COPPA 2.0 and a federal data broker registry, which were important components of the House package. However, text for most of the five Senate bills isn’t yet public, so it’s not yet fully clear (or public) how this Senate package compares to the House one.
The key divergences to watch, though, are duty of care and preemption. The House dropped KOSA's "duty of care" standard entirely, while the Senate's previous version retained one — whether it survives markup, alongside how the two chambers reconcile their preemption approaches, will be the questions that likely matter most.
4. AI, Social Media, Privacy Bills Pass Chamber in Massachusetts and California
Though most state sessions have wound down, the Massachusetts and California state legislatures are keeping folks busy with a significant number of active bills on AI, social media, and data privacy. Key bills that have passed at least one chamber and are worth watching include:
California
Chatbots: SB-1119 / AB-2023 would build on the state’s existing companion chatbot law (SB 243) by expanding substantive requirements toward child-specific design, advertising, parental controls, and independent compliance audits.
Employment: S 947 would prohibit certain uses of automated decision systems in employment. It is the successor to SB 7, vetoed by Governor Newsom last year.
Wearable Privacy: SB 1130 would prohibit the manufacture or sale of wearable recording devices without a recording light or alert, and prohibit use of those devices in places of business where there is a reasonable expectation of privacy.
Social Media Liability: AB 2 would establish heightened penalties under existing tort law for negligence by large social media platforms.
Massachusetts
Comprehensive Privacy: S 2619 would create a WPA-style comprehensive consumer privacy law. The bill is currently in conference committee attempting to reconcile the House and Senate versions, with each taking different approaches to data minimization.
Social Media Safety Bill: S3164 would regulate the “addictive” design of social media platforms for minors.
Though Massachusetts also has two frontier model proposals (S 3178 and H 5527) that have garnered attention, neither has advanced easily. Sources suggest the bills' differing approaches to independent compliance audit requirements may be unlikely to be reconciled in conference committee.
5. Vermont Initiates Rulemaking on Age-Appropriate Design Code
Last week, Vermont Attorney General Clark announced proposed rules for the state’s Age Appropriate Design Code (AADC). Enacted last year, the Vermont AADC (S 69) imposes a duty of care, age assurance, transparency, and design requirements on businesses offering online products and services accessible to minors. The law tasks the attorney general with adopting rules on how businesses must conduct age assurance, and what counts as a design practice that leads to compulsive use or impairs user autonomy.
For age assurance, the proposed rules require businesses to individually assess which age assurance method or technique to use based on a set of case-specific factors, following a "graduated escalation" approach tied to how intrusive the method is. Whatever method a business chooses must be evaluated for accuracy and error rates, limited to collecting only the data strictly necessary for age assurance, and paired with an appeals process for users. For design practices, the other proposed rules clarify aspects around heightened risk of harm, personalized media practices, and which factors determine compulsive use and autonomy. The rules also give illustrative examples of prohibited practices, such as continuous media feeds, circumvention tactics, and engagement-based notifications.
Public timing details are limited, but sources indicate the comment period closes October 2, with public hearings expected sometime in late September ahead of that deadline.
That’s all for now, thank you for reading. See you in September!
The Algorithmic Update is a monthly newsletter highlighting key legislative, regulatory, and legal developments in privacy, AI, and tech policy. FPF members receive weekly legislative updates with deeper analysis and tracking, as well as member-exclusive resources—learn more here or contact membership@fpf.org.
Tatiana Rice is the Senior Director of Legislation at the Future of Privacy Forum (FPF). Key thanks to Jordan Francis, Daniel Hales, and Justine Gluck.


