I’ve curated a list of recent works on privacy, AI, and tech that will be worth your time checking out. I didn’t have time to sum up the papers, so I’m pasting the abstracts in full.
Privacy
Nikolas Guggenberger, The Platform-Property Paradox, 29 Stan. Tech. L. Rev. 286 (2026)
Abstract:
In digital markets, the essential functions of property turn against each other. Common law property divides the world into mine, yours, and others’ by excluding non-owners. This exclusion strategy generally serves three essential functions in economic ordering: internalizing externalities by channeling positive and negative effects on third parties back to the owner; creating modularity by dividing the world into manageable chunks; and promoting liberty by enabling private control over resources. These functions usually work in harmony. As this Article shows, not so in the digital platform economy
Digital networks create enormous value by facilitating communication, transactions, and knowledge production–value that grows exponentially as more people participate. Through property-like entitlements, law enables platforms like Amazon, Google, and Facebook to exclude others from these networks and thereby capture that exponential value. This legal architecture encloses digital networks just as law once enclosed common meadows. The resulting control over digital networks disproportionately benefits incumbents. Paradoxically, this Article argues, property’s internalization function captures value so effectively that it fuels industrial concentration. Rather than creating modularity, this concentration amplifies systemic complexity and interdependence; instead of promoting liberty, it entrenches economic dependence, centralizes control, and breeds oligarchy.
This Article reveals property design as a central and underappreciated driver of platform dominance, one amenable to legal correction. While scholarly and policy responses to economic concentration have largely emphasized antitrust enforcement and sector-specific regulation, this Article foregrounds the upstream design of property entitlements. The Article challenges the classical prescription that property should maximize internalization of externalities. When platforms internalize network effects under that logic, the result is industrial concentration with deep structural harms to modularity and liberty. Reconciling property’s essential functions thus requires curtailing property-like entitlements, expanding the digital commons, and recalibrating the remaining protections.
Mason R. Clark, It Takes a Village (to Raise Children’s Privacy), 29 Chap. L. Rev. 495 (2026)
Abstract:
Raising children is an expensive and (mostly) rewarding commitment. Many parents, guardians, and caregivers are willing to invest in indestructible car seats, private schools, and organic, farm-fresh, wholegrain, low-sugar, dye-free, naturally flavored foods. Is it reasonable to ask them to invest in children’s privacy? Surely companies can’t expect parents to stand guard at the edge of a digital playground they never built and never (knowingly) agreed to let their children enter.
The digital age has profoundly reshaped children’s privacy. It is hard to imagine listening to a podcast or scrolling on a social media platform without being bombarded by reports, rants, and reels about the unprecedented privacy risks children face online. Most federal and state privacy laws have failed to provide a comprehensive framework for safeguarding children’s digital privacy. Scholars in this area have proposed legislative and regulatory reform and critiqued corporate malfeasance. This Article suggests it is time to reimagine the pay-for-privacy (PFP) model—an often-discredited model in which users pay for enhanced privacy protections—as a potential solution to minimize children’s privacy risks.
This Article makes three arguments. Part II suggests parents are the primary gatekeepers of children’s online privacy, and can responsibly manage their child’s digital footprints (with some help). It also acknowledges deceptive corporate privacy practices and explores the pitfalls of PFP models. Part III argues companies are well-positioned to provide detailed reports to parents about their child’s data and design childcentric privacy protections using revenue from a PFP model. Part IV then claims that the Federal Trade Commission (FTC) may have the expertise and the momentum to moderate between parents and companies in a PFP model.
Like the adage “it takes a village to raise a child,” it takes a village to ensure children’s privacy. As caregivers consider essential costs to raising children, this Article argues privacy may be one of those costs. PFP models, with appropriate oversight and equity, can enhance parental engagement and incentivize corporate accountability to foster a more private digital environment for children.
Kenneth A. Bamberger & Ella Corren, Untangling Privacy and Competition, 111 Iowa L. Rev. 1331 (2026)
Abstract:
This Article argues that competition law, contrary to the hopes of policymakers and scholars that it offers a powerful tool to combat privacy harms, operates as an anti-privacy framework. Far from a means to address widespread surveillance by market-dominant platforms and other data-intensive firms that monetize the collection and analysis of personal information, competition law’s analysis systematically privileges corporate interests at the expense of consumer protection.
This analysis proceeds in two parts. First, the Article identifies the specific competition law concerns raised in recent regulatory enforcement actions and private litigation involving Big Tech, as well as leading scholarship, regarding the ways in which large technology firms secure, enhance, and exploit market power through collection and use of personal data. It then provides an analytic framework that identifies circumstances in which competition concerns align with privacy concerns, pointing in the same regulatory and logical direction, and other circumstances in which those two sets of concerns misalign: where remedies for one might harm the other. Our framework untangles these two sets of concerns and reveals that a majority of competition arguments misalign with privacy. In some misalignment scenarios competition concerns are merely orthogonal to those of privacy, but there is every reason to expect that privacy will be harmed rather than promoted. In others, competition and privacy directly conflict, meaning that promoting competition directly degrades privacy.
Second, the Article reveals two fundamental analytic errors that regulators, courts, and commentators make about privacy in a market setting. These errors dictate privacy-destroying outcomes, even in the instances in which privacy and competition concerns do align.
In the first error, regulators adopt a cramped understanding of the right to privacy as either a superficial concept limited to issues like consent, consumer choice, or data security, or as a means to broader economic goals rather than an essential value on its own terms. Thus, they fail to comprehend privacy as freedom from surveillance. In the second error, competition regulators prioritize markets for surveillance over markets for privacy, either through an agnosticism regarding the substance of the market and a resulting choice to promote the more lucrative and thriving market for surveillance; or through a conceptual confusion between surveillance and privacy markets that obscures the surveillance market’s privacy harms.
These errors combine, we show, in a harsh outcome: that privacy concerns are credited in competition analysis only when doing so promotes the health and competitiveness of privacy-eviscerating surveillance markets. The resulting regulatory imbalance ultimately reinforces the dominance of surveillance-driven business models at the expense of consumer and civil rights.
This analysis underscores the conclusion that privacy cannot be effectively regulated through the back door of competition. Rather, the market for personal data should be regulated directly, as we do in other contexts plagued by market failures and harmful underlying behaviors.
Alex Chemerinsky, The First Amendment Right to Privacy, 109 Marq. L. Rev. 1297 (2026)
The First Amendment is often considered to be in tension with privacy. This Article is about the contexts in which it is not.
Although freedom of speech can pose challenges for privacy governance, privacy is a core First Amendment value. Many important First Amendment decisions were motivated more by intuitions about privacy than any other interest. For each primary First Amendment liberty—the rights to speak, listen, associate, and practice religion—the Supreme Court has recognized not only a substantive liberty but also the right to exercise it privately.
But although expressive privacy is an important First Amendment value, it remains underrecognized, undertheorized, and underprotected. Privacy interests that are dispositive in some cases are rejected, with little explanation, in others. For example, in two decisions from the October 2024 Term—Free Speech Coalition v. Paxton and Mahmoud v. Taylor—the Court substantially revised the First Amendment privacy doctrine without even acknowledging the central role of privacy in its analysis. The result is a jurisprudence that is inconsistent and that inadequately protects privacy and speech.
This Article argues three things: descriptively, that there is a First Amendment right to privacy; normatively, that there should be a First Amendment right to privacy; and, prescriptively, that the First Amendment right to privacy should be expanded in the interest of doctrinal consistency and greater fidelity to privacy’s role as a First Amendment value.
A. Michael Froomkin, Putting the Brakes on a No-Drive List (2026)
Abstract:
The constitutional right to domestic travel, though often called fundamental, is doctrinally unstable and full of exceptions-a vulnerability that could enable an oppressive new “No-Drive” list modeled on the No-Fly list, barring designated individuals from driving or riding as passengers, across (or within) state lines.
The No-Fly list rests on four premises transferable to driving: that the activity is a privilege, not a right; that special circumstances justify restricting people never charged or convicted; that government can identify targets through secretive processes; and that limited administrative review satisfies due process. Since driving is already legally treated as a privilege, this doctrinal groundwork exists. Meanwhile, license plate readers, facial recognition, GPS tracking, and pervasive surveillance make such a scheme technically feasible where it once wasn’t.
A No-Drive list could be implemented via congressional authorization, emergency powers, or immigration authority, with rhetoric labeling political opponents “domestic terrorists” supplying a ready justification-echoing the No-Fly list’s rationale, and made increasingly practical by expanding surveillance infrastructure.
Such a list would face even stronger moral, political, and economic objections than the No-Fly list. Freedom of movement is central to personal liberty and dignity; restricting it would harm democratic participation, chill association, enable authoritarian control, disrupt labor markets and resource allocation, and undermine competitive federalism. Strict scrutiny, due process and statutory claims offer legal challenges, especially against passenger prohibitions-which would effectively block interstate traveland surveillance-based enforcement raises Fourth Amendment concerns. Still, the travel right’s underlying fragility leaves its judicial invalidation uncertain.
Preventing this outcome requires recognizing freedom of movement as a foundational structural guarantee, not a mere exception-riddled instrumental right-lest it become a tool for authoritarian control over those labeled “domestic terrorists,” a category the Trump administration has applied to peaceful protesters and political adversaries.
Daniel Epps, Justifying the Fourth Amendment, 79 Vand. L. Rev. 1 (2026)
Abstract:
Why does the Fourth Amendment belong in the Constitution? This question is not whether society should impose some legal restraints on government searches and seizures. Rather, why should such protections reside in our national charter, superior to other forms of law and insulated from change via ordinary majoritarian political processes? Despite major disputes about the Fourth Amendment’s content, Fourth Amendment theorists rarely ask this question. Almost all agree that the Fourth Amendment’s constitutional protections are critically important—even if no one can agree exactly what those protections are.
This Article seeks a justification for the Fourth Amendment—the reason why search-and-seizure protections deserve to be enshrined in supreme and entrenched constitutional law. While this question might seem beside the point, identifying a justification for the Fourth Amendment should be seen as a critical step in choosing a theory of the Fourth Amendment’s meaning. Yet whether understood as freezing in place specific substantive rules, a broader value like privacy, or an institutional allocation of power, the reason to constitutionalize such a guarantee is surprisingly elusive.
After canvassing all potential justifications for the Fourth Amendment as constitutional law, this Article finds that many are unappealing or unpersuasive; those that survive rest on uneasy premises. That conclusion poses a challenge to Fourth Amendment theorists, who must explain why their reading merits constitutional status. More generally, searching for the Fourth Amendment’s justification reveals how criminal procedure scholars can learn from constitutional theory. That investigation also deepens our understanding of constitutional interpretation and the very notion of constitutionalism itself.
Barry Friedman, Policing Agency Data Trusts (2026)
Abstract:
Policing agencies are indiscriminately collecting, retaining, and using vast quantities of personal data from people who are suspected of no unlawful conduct whatsoever. This has caused expressions of concern or caution from many quarters, including—notably—the Director of National Intelligence (DNI). In a declassified report, the Office of the DNI stated that massive amounts of data are being collected “on nearly everyone that is of a type and level of sensitivity . . . that could be used to cause harm to an individual’s reputation, emotional well-being, or physical safety.”
This practice of universal data collection presents a conundrum. As many have argued, it poses the risk of serious harms: violations of personal privacy and security, erroneous targeting of innocent individuals, racial bias, and even the threat that the data will fall in the hands of hackers or authoritarian leaders. At the same time, those who favor such collection maintain that the data, properly used and analyzed, holds out hope of enhancing public safety by locating serious law violators and preventing dangerous threats.
This Article offers up a novel solution to the conundrum posed by the collection, retention, and use of personal data: policing agency data trusts. Data trusts are a new form of legal instrument that allow data creators to instruct trustees on how their data may be used; the trustees ensure in turn the data is used in no other ways. There now is a small but growing body of literature—and even some experimentation—explaining how data trusts could be employed in the context of commercial data uses.
This Article turns the idea of data trusts to the problem of policing agency indiscriminate collection, retention, and use of personal data. Data that is collected would be held outside policing agency hands. Those agencies could query the collected data only according to legislative authorization and regulations established by independent data trustees. Requests would be vetted through data stewards, and only those requests consistent with governing law and the data trust rules would be permitted. Further, use of the data would not be limited to law enforcement. Rather, the data would be available to others to query—including defense counsel, and researchers who study policing and public safety. These data trusts would allow capturing any benefits of collection, while minimizing or mitigating entirely the harms and assuring a degree of democratic accountability.
Bennett Capers, We, the Watchers, 2026 Wis. L. Rev. 251 (2026)
Abstract:
A man’s home is his castle, the expression goes. It is a place where he can retreat from intrusion or prying eyes, including from the state, at least without a warrant or extenuating circumstances. At least this is what we tell ourselves.
This Essay shows the falsity of this belief. A man’s home may still be his castle, but his castle may as well be made of glass. The state has entered the home. And we, too, have become watchers.
Technology
Jack M. Balkin, Technology and Constitutional Rot (2026)
Abstract:
Technological change affects the Constitution not only by creating new problems of constitutional interpretation, but also by changing the distribution of economic and political power. New technologies alter what governments and private actors can know, control, predict, and accomplish. When constitutional institutions fail to adapt, large shifts in power and control can lead to constitutional rot: the process by which a democratic republic becomes less democratic and less republican over time. The United States has suffered from increasing constitutional rot over the past four decades; rapid technological change has made the rot worse.
Our Second Gilded Age has many similarities to the technological and economic upheavals of the First Gilded Age, which was also a period of constitutional decay. We now live in the Algorithmic Society, where public and private decision making increasingly depend on algorithms, artificial intelligence, platforms, large-scale data collection and digital surveillance. The Algorithmic Society produces an Algorithmic State, including a National Surveillance State organized around prediction and prevention. These changes disproportionately strengthen the executive branch, weaken Congress, limit practical judicial oversight, and increase government’s dependence on powerful private firms and privately-owned technological infrastructure.
Large global technology companies increasingly exercise governing power over communications, commerce, national security, access to information, and public debate. As a result, government and technology firms engage in repeated attempts at mutual co-optation, blurring traditional distinctions between public and private power. Digital platforms reshape the public sphere through an attention economy that weakens knowledge, intensifies political polarization, and erodes trust. These changes exacerbate four central features of constitutional rot: growing wealth inequality, political polarization, loss of trust, and policy disasters.
Despite these dire circumstances, the United States has recovered from periods of constitutional rot before. The First Gilded Age gave way to the reforms of the Progressive Era and the New Deal. Today constitutional renewal involves a different set of reforms: new digital privacy laws and new antitrust, civil-rights, and due-process protections. Renewal means reconstructing and improving the knowledge institutions that underwrite our democracy. It requires structural changes that better allow Congress to check and oversee the executive branch. And it requires reforms that secure and strengthen our system of democratic representation.
Ari Ezra Waldman, Challenging Technical Expertise, 106 B. U. L. Rev. 451 (2026)
Abstract:
This Article explores an underlying assumption of much law and technology scholarship and policy—namely, that technical expertise is necessary for technology policymaking. This assumption is so embedded in tech policy and scholarship that many scholars and policymakers take it for granted. This Article changes that. It surfaces the three implicit rationales for integrating technical expertise into tech policymaking (and a fourth if we include no rationale at all!): the unique nature of digital technologies, the capability of technical expertise to enable governance of those technologies, and the affinities between certain technical and legal values. Although these arguments are repeated often, only a few withstand scrutiny. This does not mean that there is no role for technical know-how in this space. Nor does it mean that the opposites of expertise—namely, willful ignorance or raw power—are the only other or best options. The goals of this Article are to bring nuance and precision where there have been only generalities. It seeks to identify the conditions in which technical expertise can actually make better policy and regulations in the public interest. To that end, I identify three such conditions: where technical complexity both impedes regulation and is scrutable to experts, where government regulators need to evaluate scrutable technical claims for legal compliance, and where the interests of experts align with the public interest.
Elettra Bietti & Anne Bellon, Technological Capture (forthcoming 2027)
Abstract:
Public institutions, regulatory agencies, and government officials are increasingly captured by and dependent on tech platforms and AI companies. These companies’ asymmetric control over information and digital infrastructures gives them a privileged and novel ability to shape law and regulation, which is currently poorly understood.
Classic accounts of corporate influence and regulatory capture have painted a reductive picture of corporate power and influence in liberal democracies. While some of these accounts’ original goals were to limit corporate influence on government, they have broadly promoted corrosive approaches to tech regulation that allowed Big Tech to grow in size and influence. Our approach consists of turning dominant theories of corporate capture on their head to make better sense of tech power in the information age.
We define technological capture as the loose assemblage of techno-informational modes of influence that tech platform companies rely on to shape laws and regulatory proceedings. After describing technological capture and its plural and overlapping manifestations in tech law and policy, we lay out three strategies that governments and institutions can put in place to counter tech influence. These are (a) to strengthen regulators’ technical capacity, (b) to design enforcement mechanisms more responsive to dynamic innovation markets, and (c) to diffuse platforms’ power by tapping into their networked structures.
AI
Daryl Lim, Polyphonic AI Regulation, 32 Geo. Mason L. Rev. 745 (2026)
Abstract:
This Article will advance a polyphonic framework for regulating generative artificial intelligence (“AI”) by integrating four legal regimes—antitrust, copyright, the right of publicity, and information privacy—thereby offering a distinct normative perspective on AI’s impact. As generative AI systems reshape markets, the appropriate doctrines deriving from these legal regimes must neither converge artificially nor operate in silos. Instead, this Article will argue for regulatory pluralism that preserves each doctrine’s integrity while fostering coordinated governance.
Part I will examine how generative AI reshapes competition across the AI “stack” from infrastructure to applications, raising concerns about vertical integration, interoperability, and exclusionary conduct. It will analyze enforcement strategies and countervailing narratives, emphasizing the need for layered, context-sensitive antitrust scrutiny that respects dynamic efficiency. Part II will turn to copyright law, focusing on transformative use, market harm, and emerging licensing practices. The Part will also propose adopting analytical tools from antitrust, such as market substitution tests, to improve fair use analysis. Part III will address identity-based harms and data commodification by arguing for a new data right. Drawing from the right of publicity and information privacy law, it will propose a bifurcated framework distinguishing between personality-based and behavioral control claims to restore individual autonomy in AI training and deployment. The Article will conclude with a call for structured regulatory coordination. Through cross-agency collaboration, regulatory sandboxes, and interoperable standards, polyphonic regulation offers a principled, pluralistic path forward, one capable of promoting innovation while preserving dignity, competition, and democratic accountability in the age of generative AI.
Sylvia Lu, Regulating AI Harms, 78 Fla. L. Rev. 323 (2026)
Abstract:
In recent years, the rapid expansion of artificial intelligence (AI) innovations has led to a rise in AI harms—harms emerging from AI applications that threaten civil rights and fundamental interests. A facial recognition system for improving criminal detection wrongly collected sensitive personal data and flagged racial minorities as shoplifters. A risk prediction algorithm adopted to identify patients denied medical treatment to Black individuals with poor health conditions. A social media algorithm intended to boost social engagement exacerbated addictive behavior and mental illness in teenagers. These harms are becoming increasingly ubiquitous. Yet they often manifest in small and intangible forms, enabling them to aggregate while eluding legal oversight. Imperceptibly and cumulatively, AI harms affect millions to billions of individuals.
This Article argues that AI regulation should be grounded in the legal conception of AI harms. To that end, it constructs a legal typology identifying four categories of AI harms: eroding privacy, undermining autonomy, diminishing equality, and impairing safety. Additionally, it identifies two principal aggravating factors–accountability paucity and algorithmic opacity–that obstruct these seemingly minor harms from correction. This Article then applies this legal conception to a comparative analysis of regulatory frameworks in the United States, the European Union, and Japan. Despite their differing philosophies, these regulatory examples either overlook certain categories of harms or fail to consider their cumulative effects, thereby allowing harmful AI practices to escape oversight.
Drawing on these findings, this Article proposes a harm-centric framework consisting of three foundational legal interventions: AI Harm Assessments, Individual AI Rights, and AI Harm Disclosures. These interventions mitigate AI harms by addressing the aggravating factors that enable them to persist and accumulate. Taken as a whole, this legal conception of AI harms provides a normative basis for identifying legally cognizable AI harms, designing legal interventions to address them, and advancing harm-centric AI regulation while supporting AI innovation.
Jerry Kang & Paul Ohm, The Architecture of Disclaim: AI, Implicit Bias, and their (Un)predictable Convergence (2026)
Abstract:
Artificial intelligence and the human mind share a decisionmaking architecture, and antidiscrimination law is built for neither. In both, a producing layer encodes the statistical regularities of an unequal world and shapes the inputs a decision runs on, while an avowing layer deliberates, explains, and sincerely denies discriminatory intent — without being able to observe the processing beneath it. We name this the architecture of disclaim, and we show it is functionally isomorphic across silicon and carbon. Recent computer-science studies of large language models are echoing, sometimes measure for measure, a half-century of implicit bias research on human brains. The parallels are not cosmetic. Models and brains exhibit similar bias effects, with similar resistance to correction. Alignment training and diversity training fail in the same way and for the same reason: each updates what a system says without retraining what it computes. Asked whether it discriminated, either system answers confidently — and the answer is sincere and wrong.
The architecture defeats the law’s existing toolkit, cluster by cluster. Consciousness (purposeful discrimination) fails because the avowing layer answers honestly. Cause (but-for causation) fails because race travels in a bundle of proxies that no counterfactual can isolate, so the test can convict but never acquit. Consequence (disparate impact) comes closest — it never asks about anyone’s interior — but it arrives statutorily confined, constitutionally imperiled, and missing an accepted account of why its disparities matter.
A fourth cluster survives. Conduct asks not what the actor intended, observed, or can counterfactually prove, but what it should have done. Two legal traditions are building toward it right now, neither aware of the other. AI governance has converged on assessment, audit, and reasonable response; implicit bias law has replaced Batson’s futile hunt for purposeful intent with an epistemically upgraded objective observer. Two construction crews are working with one blueprint. The convergence is not coincidence — it is the signature of the same architecture asserting itself across different substrates — and naming it makes an exchange possible, because each side holds what the other is missing. AI governance holds ex ante duties that attach before any contested decision. Implicit bias law holds the epistemic content without which a reasonableness benchmark is an empty vessel.
The exchange composes a new standard: the responsible person — an actor charged with what the science of decisional systems has established, bound by ex ante duties before the decision, and judged on that same knowledge after it. Because the standard interrogates no interior and demands no counterfactual, it reaches the firm whose managers consult a frontier model persistently, informally, and mid-discretion — which is what every firm may be becoming, and what every substrate-specific regime misses. What to do? Judges can begin through evidentiary rulings alone. Legislators can finish, enacting ex ante obligations calibrated to what minds and machines can and cannot do. Two decades ago, one of us asked why we tolerate from our organically grown black boxes what we would never tolerate from synthetic ones. We shouldn’t. The architecture of disclaim means that neither minds nor machines can simply avow their way to fairness — but the law can now hold both to becoming what they claim to be.
Margot E. Kaminski & Andrew D. Selbst, AI and the Doctrine of Speakerless Speech (2026)
Abstract:
What makes speech “speech” for purposes of the First Amendment? Although the Supreme Court has developed elaborate doctrines governing when speech may be regulated, it has never squarely confronted a more fundamental question: whether constitutional speech requires the existence of a human speaker. That question has become unavoidable with the rise of generative artificial intelligence. Large language models routinely produce text, images, and videos that resemble ordinary expression while lacking any obvious connection to a human communicative act. The resulting debate has focused mostly on whether these outputs should receive First Amendment protection. This Article argues that the prior question is one of constitutional coverage.
This Article identifies and reconstructs what we call the doctrine of speakerless speech—a previously unrecognized strand of First Amendment doctrine that becomes visible once courts confront expression lacking a connection to a human speaker. Examining the First Amendment’s coverage doctrine alongside Citizens United v. FEC, Moody v. NetChoice, and related cases, we show that disputes over corporations, algorithmic curation, expressive conduct, and now generative AI all confront the same underlying constitutional problem: if expression appears without a connection to a human speaker, what makes it speech for First Amendment purposes? Read together, these cases reveal that the Court has increasingly understood First Amendment coverage to turn not simply on the presence of words, images, or familiar expressive media, but on their connection to human communicative intent.
This account changes the terms of the debate over AI and the First Amendment. Existing scholarship has divided over whether AI outputs should receive First Amendment coverage. Some scholars argue that outputs resembling traditional speech should be categorically covered; others contend that machine-generated outputs cannot be speech because machines neither speak nor possess constitutional rights. We argue that both approaches miss the central doctrinal development. The Supreme Court’s recent cases neither compel categorical protection nor categorical exclusion. Instead, they point toward a factual inquiry into the relationship between a particular AI output and a human’s intent to communicate.
The Article makes three contributions. First, it identifies and reconstructs the doctrine of speakerless speech across cases that have never before been understood as part of a common body of law. Second, it offers the first sustained account of Moody v. NetChoice as a foundational decision about the constitutional boundaries of speech itself, rather than merely a case about social media platforms. Third, it provides a framework for evaluating the growing body of litigation involving generative AI and other algorithmic systems, showing why constitutional protection should turn on the nexus between AI outputs and human expressive intent rather than on categorical assumptions about either machines or media. In doing so, the Article offers a unified account of First Amendment coverage at precisely the moment that artificial intelligence has made the concept of a human speaker no longer inevitable.
Woodrow Hartzog, Neil Richards, Ryan Durrie, & Jordan Francis, Against AI Half Measures, 78 Fla. L. Rev. 1 (2026)
Abstract:
So far, U.S. consumer protection policy for artificial intelligence (AI) accountability has largely consisted of industry-led approaches such as encouraging transparency, mitigating bias, promoting principles of ethics, and empowering people. These approaches are vital, but they are only half measures. To bring AI within the rule of law, lawmakers must start drawing substantive lines.
In this Article, we identify four AI regulatory approaches to consumer, data, and democratic harms as half measures. First, transparency does not produce accountability on its own. Second, while mitigating bias in AI systems is critical, even unbiased systems are a threat to the vulnerable. Third, while “AI ethics” are important, they are a poor substitute for laws. Finally, empowering people in their individual choices misses the larger questions about the distribution of power and collective well-being.
Instead of these half measures, we recommend that lawmakers reject the idea that AI systems are neutral and inevitable. When lawmakers go straight to putting up half-hearted guardrails, they fail to ask the existential question about whether some AI systems should exist at all. To avoid the mistakes of the past, lawmakers must make the hard calls. “AI Half Measures” will certainly not be enough.
* * * *
Daniel J. Solove is the Bernard Professor of Intellectual Property and Technology Law at the George Washington University Law School. He is the founder of TeachPrivacy, a company that provides workforce privacy, cybersecurity security, and AI training to companies and organizations around the world. He is the author of 10+ books and 100+ articles.
You can follow his events, writings, training, cartoons, and resources by subscribing to his free weekly newsletter.
Subscribe to Solove’s Free Substack
A supplement to Solove’s regular newsletter with more in-depth discussions