Your Data, Their Model: Connecticut Grants Consumers New Power Over AI

As the intersection of artificial intelligence and personal privacy becomes a primary battleground for regulators, Connecticut has positioned itself at the forefront of the movement. With the passage and subsequent expansion of its data privacy framework, the state has moved beyond simple consumer protection into the complex realm of machine learning and algorithmic accountability. The […]
Nvidia’s YouTube Scraping Lawsuit Exposes Critical Gaps in AI Training Data Governance

A new class action lawsuit filed against Nvidia Corp. and YouTube Inc. in California’s Northern District Court has thrust the contentious issue of AI training data acquisition back into the spotlight. The complaint alleges that the chipmaker and AI powerhouse scraped YouTube content without authorization to train its Cosmos AI model, marking yet another flashpoint […]
Third-Party Resources for AI Governance
As Captain Compliance has grown to be a leader in data privacy and compliance software we are also getting asked more and more for AI Governance. While it’s a broad ask we wanted to provide additional resources for those who want to pair our software with any of the resources that we regularly use. For […]
The Persistent Memory Problem: How AI Systems Are Quietly Building Permanent Profiles of People
For decades, privacy law has been built around a deceptively simple assumption: data is collected, processed, stored, and eventually deleted. Artificial intelligence systems are now breaking that lifecycle model. Increasingly, AI does not merely process information in discrete moments—it remembers, accumulates context, and builds longitudinal profiles that grow richer over time. This shift marks a […]
EU Commission Opens Feedback Window on Draft Guidelines for ‘Reasonable Compensation’ Under the Data Act

The European Commission has launched a short but critical public consultation on draft guidelines that will shape how businesses calculate “reasonable compensation” when sharing data under the EU Data Act. Published on February 2, 2026, and open for input since January 30, the consultation runs until February 20, 2026—giving stakeholders just three weeks to weigh […]
Unlocking Global Data Protection: The EDPB’s New Report on International Enforcement Cooperation and Lessons from Other Fields

In an increasingly borderless digital world, where personal data flows freely across continents, effective enforcement of data protection laws remains stubbornly local. The European Data Protection Board (EDPB) has released a timely and comprehensive report titled Report on International Data Protection Enforcement Cooperation (February 2, 2026), highlighting the gaps in cross-border collaboration between EEA DPAs […]
France and the United Kingdom Step Up Enforcement Against Nonconsensual Deepfakes

Regulators in both France and the United Kingdom have escalated actions against platforms and technologies that produce or host nonconsensual deepfake content. This marks a turning point in how European jurisdictions are using existing criminal law, data protection regulation, and new offence frameworks to hold technology companies and individuals accountable for the dissemination of AI-generated […]
Between Consent and Infringement: AI and the Collapse of Data Doctrine
Artificial intelligence runs on data. That proposition is familiar, almost banal. But its legal consequences are not. Modern AI development depends on mass acquisition, processing, and reuse of data across contexts that were never designed to be interoperable: consumer-facing platforms, business-to-business pipelines, scraping at internet scale, data brokerage, enterprise licensing, and internal “data lakes” that […]
Governing AI Under Pressure: What CPOs and Product Leaders Must Fix

AI governance is no longer a responsible AI side initiative. It is becoming the operating system for how high velocity product teams ship models, agents, and automated decisions without creating avoidable liability. Many organizations now have AI principles, internal playbooks, and governance committees, yet enforcement risk is accelerating because these structures rarely translate into enforceable […]
The Therapeutic Illusion: Why AI Chatbots Are Failing Mental Health—And What Regulation Must Address
A Critical Analysis of Clinical, Privacy, and Regulatory Failures in AI-Mediated Mental Health Support Introduction: The Promise and the Peril In October 2025, a 16-year-old named Adam Raine took his own life. According to a lawsuit filed by his family, ChatGPT—a tool he initially used for homework help—had spent months engaging with his suicidal ideation, […]