This update highlights key legislative and regulatory developments in the second quarter of 2026 related to artificial intelligence (“AI”), connected and automated vehicles (“CAVs”), and Internet of Things (“IoT”).

I. Federal AI Legislative Developments

In the second quarter, members of Congress introduced several AI bills related to chatbots, digital replicas, nonconsensual AI-generated imagery, and AI standards. While the path to enactment remains unclear, these efforts demonstrate that there continues to be significant bipartisan interest in Congress in regulating AI. The bills are important data points for the conversation, particularly since they are likely to be reintroduced in some form in the next legislative session. The bills focus on several key themes:

  • Chatbots. In both the House and Senate,lawmakers are pursuing legislation to regulate chatbots that interact with minors.
    • The House passed the KIDS Act (H.R. 7757), a legislative package that includes a revised SAFE BOTs Act, which would establish requirements intended to safeguard minors interacting with chatbots. The bill combines portions of the Kids Online Safety Act, COPPA 2.0, the Safe Messaging for Kids Act, the SPY Kids Act, the Safer GAMING Act, the SAFE Bots Act, and other youth safety proposals.
    • In the Senate, the GUARD Act (S. 3062), which has been reported out of committee, would establish age-verification and other requirements for chatbots. More recently, Sen. John Curtis (R-UT) and Sen. Adam Schiff (D-CA) introduced the SAFE KIDS Act (S. 4855), which would require certain AI systems to implement age estimation and independent audits for chatbots.
  • Digital Replicas. Several legislative proposals have focused on the use of AI to create digital replicas. For instance, the NO FAKES Act of 2026 (S. 4591) would grant individuals a licensable property right in their voice and visual likeness and create a private right of action for unauthorized uses, subject to certain exceptions. This bill has been reported out of the Senate Judiciary Committee and now awaits full Senate floor action.
  • Nonconsensual AI-Generated Intimate Imagery. Following enactment of the TAKE IT DOWN Act (S. 146) in April 2025, lawmakers continue to introduce legislation addressing nonconsensual intimate imagery. For example, the CONSENT Act (S. 4695/H.R. 9155), a bipartisan bill introduced in both the House and the Senate, would create a private right of action against individuals who transmit unsolicited intimate visual depictions.
  • Content Labeling. The bipartisan Spot the Fakes Act (H.R. 9578) would task the FTC and NIST to create standards for how to display labels in AI-generated content metadata, and the Voluntary Consumer AI Disclosure Pilot Act (H.R. 9439) would direct NIST to establish a pilot program and develop voluntary disclosure standards regarding private-sector use of AI systems. Additionally, the AI Labeling Act (S. 4915) is a bipartisan proposal to impose visible labeling requirements on AI-generated videos, audio, and images, among other disclosure requirements.

II. Federal AI Executive Branch Developments

In the second quarter of 2026, the executive branch employed several approaches to pursue its AI agenda. For example:

  • White House: On June 2, 2026, after postponing the signing on May 21 amid industry concerns, President Trump signed an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security.” The Executive Order will establish a framework for secure development of frontier AI models and an “AI cybersecurity clearinghouse” to facilitate vulnerability coordination and remediation, among other initiatives. The Executive Order was quickly followed by National Security Presidential Memorandum 11, published on June 5, 2026, which directs the military, intelligence agencies, and related federal departments to accelerate the adoption of AI for national security applications.
  • Department of Justice: On April 24, 2026, the DOJ’s AI litigation task force intervened in xAI’s lawsuit to invalidate the Colorado AI Act (SB 24-205). DOJ’s complaint focused on the Fourteenth Amendment’s Equal Protection Clause, targeting the law’s disparate-impact requirements and its carve-out for algorithms designed to advance “diversity.” On April 27, 2026, the court stayed enforcement of the Act (which was, in any event, subsequently repealed and replaced on May 14, 2026, as discussed further below).
  • NIST: On May 5, 2026, the National Institute of Standards and Technology (“NIST”), through its Center for AI Standards and Innovation (“CAISI”), announced new agreements with Google DeepMind, Microsoft, and xAI. Under the agreements, these developers will allow CAISI to access certain of their models for pre-deployment evaluations and targeted research to better assess frontier AI capabilities and advance the state of AI security.

III. State AI Legislative Developments

State lawmakers advanced a large volume of AI bills in the last quarter, and at least 35 AI-related bills have been enacted. The enacted and/or passed frameworks focus on several key themes:

  • Frontier Model Oversight: Multiple states passed bills designed to regulate frontier model developers and create oversight and transparency mechanisms, and two of these bills were enacted into law. Illinois enacted S.B. 315, which creates public safety disclosure and reporting requirements, similar to those in New York and California for frontier developers, with a third-party audit requirement. Additionally, Connecticut enacted S.B. 5, an omnibus AI law that would (among other things) require large frontier model developers to establish employee reporting procedures for certain public health or safety risks and create employee reporting protections for all frontier model developers.
  • Automated Decision-making Technology (ADMT) in Employment: A number of state frameworks advanced that focus on AI or ADMT use in the employment context. For example, Colorado repealed the original Colorado AI Act (SB 24-205) and enacted a revised Colorado AI Act, which focuses primarily on disclosure, recordkeeping, and consumer notice requirements for developers and deployers of ADMT that is used to “materially influence a consequential decision.” Newly enacted Connecticut S.B. 5 creates notice requirements for deployers of “automated employment-related decision technology” and requires developers to provide deployers with the information needed to comply with those notice obligations.
  • Chatbot Safety: Multiple states enacted AI chatbot safety bills, including Connecticut (S.B. 5), Colorado (H.B. 1263), Georgia (S.B. 540), and Tennessee (S.B. 1700). Notably, some of these laws require AI companion chatbot operators to estimate the age of users and implement specific safeguards for minor users.
  • Transparency: New York A6578, if signed by the governor, will require generative AI model developers to post certain training data information on their website and give employees notice of when their data is used to train an AI model starting January 2027. This bill resembles California AB 2013, which went into effect earlier this year, but unlike AB 2013, it includes a separate section on disclosures of employee data for training.
  • Health Insurance & Healthcare: States continue to focus on regulating the use of AI for health insurance and healthcare. For example, Alabama and Georgia enacted laws prohibiting the use of AI by health insurers to make adverse decisions, including health insurance coverage decisions, without sufficient human review. Additionally, Colorado (H.B. 1195) and Nebraska (LB 525) enacted laws prohibiting or restricting the use of AI to provide mental healthcare services.

IV. Connected & Automated Vehicles Developments

The second quarter of 2026 brought continued activity related to CAV legislation, enforcement, and regulation. For example:

  • State Regulatory Action: On April 28, California’s Department of Motor Vehicles (the DMV) finalized updated regulations governing testing and deployment of AVs in the state. The regulations introduce significant new safety and oversight requirements, and expand California’s AV framework to include heavy-duty vehicles over 10,000 pounds, which had previously been excluded.
  • Federal Legislative Activity: In late May, the House Transportation and Infrastructure Committee approved the bipartisan BUILD America 250 Act, a surface transportation reauthorization bill that includes several autonomous trucking provisions. The bill would establish a federal regulatory framework for autonomous commercial motor vehicles, would codify safety case and incident reporting requirements, and would require human operators for otherwise autonomous school buses and vehicles transporting hazardous materials.
  • NHTSA: On June 26, NHTSA proposed amendments to FMVSS 135, which sets requirements for brake system performance in light vehicles. The proposal is a step toward deploying purpose-built autonomous vehicles: it removes requirements for hand- or foot-operated brake controls for vehicles designed never to be operated by a human. All vehicles subject to the standard, including autonomous vehicles, would still need to meet the same stopping distance performance criteria currently mandated by the rule.
  • UN Global Technical Regulation: For the last five years, the United Nations Working Party on Automated/Autonomous and Connected Vehicles has been preparing a draft Global Technical Regulation (GTR) for ADS-equipped vehicles. The draft GTR is intended to harmonize international autonomous vehicle performance requirements and assessment methods. On June 24, 2026, WP.29 announced that it had approved the GTR, as well as amendments to approximately 90 other UN regulations intended to address their applicability to driverless vehicles. The United States delegation supported adoption, as did China, the EU, Japan, Canada, and the UK. This vote does not mean that the GTR will have the force of law in the United States. NHTSA will still need to initiate rulemaking, a lengthy and uncertain process. NHTSA issued a brief statement regarding the approval, which was positive but lacked specificity as to the agency’s plans for adoption.

V. Internet of Things Developments

There were a few notable developments in the second quarter of 2026 pertaining to the Internet of Things, including:

  • GUARD Act. Rep. John Moolenaar (R-MI), Rep. Jay Obernolte (R-CA), and Rep. Jennifer McClellan (D-VA) introduced the bipartisan Guarding the U.S. Against Adversarial Robotics Dominance (GUARD) Act, which would require national security agencies to review humanoid and quadruped robots produced by China and other foreign adversaries for national security risks. Products determined to present unacceptable national security risks would be placed on the FCC’s “Covered List,” prohibiting them from the U.S. market. The legislation reflects concerns that Chinese robotics firms could flood the U.S. market with heavily subsidized robots while creating surveillance, cybersecurity, and supply chain vulnerabilities within American infrastructure.
  • FCC Cyber Trust Mark: New Lead Administrator Named. The FCC named ioXt Alliance as Lead Administrator of the Cyber Trust Mark IoT labeling program on April 13, 2026. The Cyber Trust Mark is a voluntary cybersecurity labeling program for wireless consumer Internet of Things (IoT) products. The FCC has indicated there will be additional intermediary steps before the program is ready to accept product applications, and is also reviewing public input from its Further Notice of Proposed Rulemaking regarding potential additional national security disclosures.

We will continue to update you on meaningful developments in these quarterly updates and across our blogs. Please also stay tuned for our upcoming quarterly video briefings on AI developments!

Photo of Jennifer Johnson Jennifer Johnson

Jennifer Johnson is a partner specializing in communications, media and technology matters who serves as Co-Chair of Covington’s Technology Industry Group and its global and multi-disciplinary Artificial Intelligence (AI) and Internet of Things (IoT) Groups. She represents and advises technology companies, content distributors…

Jennifer Johnson is a partner specializing in communications, media and technology matters who serves as Co-Chair of Covington’s Technology Industry Group and its global and multi-disciplinary Artificial Intelligence (AI) and Internet of Things (IoT) Groups. She represents and advises technology companies, content distributors, television companies, trade associations, and other entities on a wide range of media and technology matters. Jennifer has three decades of experience advising clients in the communications, media and technology sectors, and has held leadership roles in these practices for more than twenty years. On technology issues, she collaborates with Covington’s global, multi-disciplinary team to assist companies navigating the complex statutory and regulatory constructs surrounding this evolving area, including product counseling and technology transactions related to connected and autonomous vehicles, internet connected devices, artificial intelligence, smart ecosystems, and other IoT products and services. Jennifer serves on the Board of Editors of The Journal of Robotics, Artificial Intelligence & Law.

Jennifer assists clients in developing and pursuing strategic business and policy objectives before the Federal Communications Commission (FCC) and Congress and through transactions and other business arrangements. She regularly advises clients on FCC regulatory matters and advocates frequently before the FCC. Jennifer has extensive experience negotiating content acquisition and distribution agreements for media and technology companies, including program distribution agreements, network affiliation and other program rights agreements, and agreements providing for the aggregation and distribution of content on over-the-top app-based platforms. She also assists investment clients in structuring, evaluating, and pursuing potential investments in media and technology companies.

Photo of Nicholas Xenakis Nicholas Xenakis

Nick Xenakis draws on his Capitol Hill and legal experience to provide public policy and crisis management counsel to clients in a range of industries.

Nick assists clients in developing and implementing policy solutions to litigation and regulatory matters, including on issues involving…

Nick Xenakis draws on his Capitol Hill and legal experience to provide public policy and crisis management counsel to clients in a range of industries.

Nick assists clients in developing and implementing policy solutions to litigation and regulatory matters, including on issues involving antitrust, artificial intelligence, bankruptcy, criminal justice, financial services, immigration, intellectual property, life sciences, national security, and technology. He also represents companies and individuals in investigations before U.S. Senate and House Committees.

Nick previously served as General Counsel for the U.S. Senate Judiciary Committee, where he managed committee staff and directed legislative efforts. He also participated in key judicial and Cabinet confirmations, including of Attorneys General and Supreme Court Justices. Before his time on Capitol Hill, Nick served as an attorney with the Federal Public Defender’s Office for the Eastern District of Virginia.

Photo of Jayne Ponder Jayne Ponder

Jayne Ponder provides strategic advice to national and multinational companies across industries on existing and emerging data privacy, cybersecurity, and artificial intelligence laws and regulations.

Jayne’s practice focuses on helping clients launch and improve products and services that involve laws governing data privacy…

Jayne Ponder provides strategic advice to national and multinational companies across industries on existing and emerging data privacy, cybersecurity, and artificial intelligence laws and regulations.

Jayne’s practice focuses on helping clients launch and improve products and services that involve laws governing data privacy, artificial intelligence, sensitive data and biometrics, marketing and online advertising, connected devices, and social media. For example, Jayne regularly advises clients on the California Consumer Privacy Act, Colorado AI Act, and the developing patchwork of U.S. state data privacy and artificial intelligence laws. She advises clients on drafting consumer notices, designing consent flows and consumer choices, drafting and negotiating commercial terms, building consumer rights processes, and undertaking data protection impact assessments. In addition, she routinely partners with clients on the development of risk-based privacy and artificial intelligence governance programs that reflect the dynamic regulatory environment and incorporate practical mitigation measures.

Jayne routinely represents clients in enforcement actions brought by the Federal Trade Commission and state attorneys general, particularly in areas related to data privacy, artificial intelligence, advertising, and cybersecurity. Additionally, she helps clients to advance advocacy in rulemaking processes led by federal and state regulators on data privacy, cybersecurity, and artificial intelligence topics.

As part of her practice, Jayne also advises companies on cybersecurity incident preparedness and response, including by drafting, revising, and testing incident response plans, conducting cybersecurity gap assessments, engaging vendors, and analyzing obligations under breach notification laws following an incident.

Jayne maintains an active pro bono practice, including assisting small and nonprofit entities with data privacy topics and elder estate planning.

Photo of Micah Telegen Micah Telegen

Micah Telegen represents clients in complex investigations and enforcement actions, including in the automotive and consumer product industries. He frequently advises clients on compliance with the Motor Vehicle Safety Act, the Consumer Product Safety Act, and other federal safety laws and regulations. Micah…

Micah Telegen represents clients in complex investigations and enforcement actions, including in the automotive and consumer product industries. He frequently advises clients on compliance with the Motor Vehicle Safety Act, the Consumer Product Safety Act, and other federal safety laws and regulations. Micah also regularly advises clients facing regulatory challenges related to emerging technologies in the automotive industry, including connected and autonomous vehicles. He also maintains an active pro bono practice and has experience litigating on behalf of criminal defendants and tenants facing eviction.

Photo of Rosie Moss Rosie Moss

Rosie Moss is an associate in the firm’s Washington, DC office. She is a member of the Data Privacy and Cybersecurity Practice Group and the Technology and Communications Regulation Practice Group.

Rosie advises clients on a wide range of data privacy and technology…

Rosie Moss is an associate in the firm’s Washington, DC office. She is a member of the Data Privacy and Cybersecurity Practice Group and the Technology and Communications Regulation Practice Group.

Rosie advises clients on a wide range of data privacy and technology regulatory issues, including emerging artificial intelligence compliance matters. She assists clients in complying with federal and state privacy laws and Federal Communications Commission (FCC) regulations. Rosie also maintains an active pro bono practice.

Photo of Evan Chiacchiaro Evan Chiacchiaro

Evan Chiacchiaro is an associate in the firm’s Washington, DC office and member of the Technology and Communications Regulation Practice Group.

Evan advises clients on a range of technology regulatory issues, including emerging artificial intelligence compliance matters and compliance with Federal Communications Commission…

Evan Chiacchiaro is an associate in the firm’s Washington, DC office and member of the Technology and Communications Regulation Practice Group.

Evan advises clients on a range of technology regulatory issues, including emerging artificial intelligence compliance matters and compliance with Federal Communications Commission (FCC) regulations. Evan also maintains an active pro bono practice focused on civil rights.

Photo of Irene Kim Irene Kim

Irene Kim is an associate in the firm’s Washington, DC office, where she is a member of the Privacy and Cybersecurity and Advertising and Consumer Protection Investigations practice groups. She advises clients on a broad range of issues, including U.S. state and federal…

Irene Kim is an associate in the firm’s Washington, DC office, where she is a member of the Privacy and Cybersecurity and Advertising and Consumer Protection Investigations practice groups. She advises clients on a broad range of issues, including U.S. state and federal AI legislation, comprehensive state privacy laws, and regulatory compliance matters.

Photo of Clare Mathias Clare Mathias

Clare Mathias is an associate in the firm’s Boston office. She is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Clare advises clients on a wide range of privacy and health care issues, including compliance…

Clare Mathias is an associate in the firm’s Boston office. She is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Clare advises clients on a wide range of privacy and health care issues, including compliance with federal health care regulations and U.S. state and federal privacy laws.

Clare also maintains an active pro-bono practice.