Several recent developments are shaping the landscape of privacy, AI, and employment law. This quarter’s legal and information governance update examines new U.S. consumer privacy laws in Alabama, Louisiana, and Oklahoma; a recent change in Colorado’s revised AI law; EU AI Act implementation guidance and member-state enforcement scope; and California employment laws affecting human resource recordkeeping.
Continue reading to become informed of these new laws and regulations from across the globe and empower yourself with the information you need to do your job as efficiently and confidently as possible.
Throughout the update, we’ve included notations in italics, where applicable, if the regulatory updates have been added to our IG and retention management software, Access Unify® | Lifecycle, as a courtesy to active clients.
Recently, signs of life started emerging in the consumer and data privacy legislative arena. After an unusually quiet year for privacy legislation in 2025, three states, Alabama, Louisiana, and Oklahoma, will add their distinctiveness—or lack of it—to the fragmented framework of data privacy legislation in the United States of America.
The Alabama Personal Data Protection Act, taking effect May 1, 2027, applies to controllers and processors doing business in Alabama or targeting Alabama residents if they control or process personal data of more than 25,000 consumers, excluding payment-transaction data, or derive more than 25% of gross revenue from selling personal data. The Alabama regulation is notable for its relatively low coverage threshold when compared with older state laws. Alabama is not considered an outlier, but its threshold makes it potentially relevant to smaller organizations than the 100,000-consumer thresholds common in earlier state privacy statutes.
Cited in Access Unify® | Lifecycle as Alabama House Bill 351 §§ 5, 7 & 10
The Louisiana Data Privacy Act, taking effect January 1, 2027, looks more like a hybrid of the Virginia-style privacy model and California’s business-threshold approach. It applies to businesses meeting one of several thresholds, including more than $25 million in annual gross revenue; buying, receiving, selling, or sharing personal information of 75,000 or more consumers, households, or devices; or deriving at least 50% of annual revenue from selling personal information.
Cited in Access Unify® | Lifecycle as LA. REV. STAT. ANN. §§ 51:1780.3, 1780.4 &1780.5
The Oklahoma Consumer Data Privacy Act, taking effect January 1, 2027, is closer to the mainstream Virginia/Colorado model. It applies to entities that conduct business in the state or target state residents and either process personal data of at least 100,000 consumers or process data of at least 25,000 consumers while deriving more than 50% of gross revenue from personal-data sales.
Cited in Access Unify® | Lifecycle as OKLA. STAT. ANN. tit 75A, §§ 301, 302, 306, 309, 312 & 320
These laws expand the existing patchwork of obligations to more states, but they differ most significantly in their applicability to organizations either by revenue or total consumers data being managed. Businesses with a mature privacy compliance program will recognize the familiar architecture of these new laws. Looking ahead, I will be watching Massachusetts and Pennsylvania for their chance at joining the growing number of states with consumer and data privacy protections in 2026.
In addition, while it isn’t a new comprehensive piece of legislation as covered above, California had privacy relevant regulations go into effect on January 1, 2026. California businesses subject to the California Privacy Regulations must pay close attention to new record retention obligations for privacy risk assessments and cybersecurity audits.
Under CAL. CODE REGS. Title 11, § 7155(c), a business must retain each risk assessment related to processing activities, including both original and updated versions, for as long as the relevant processing continues or for five years after the assessment is completed, whichever period is longer.
Cited in Access Unify® | Lifecycle as CAL. CODE REGS. Title 11, § 7155
Separately, CAL. CODE REGS. Title 11, § 7122(g) requires both the business and the auditor to retain all documents relevant to each cybersecurity audit for at least five years after the audit is completed. Together, these provisions underscore California’s increasing emphasis on documentation, accountability, and long-term compliance in privacy and cybersecurity governance.
Cited in Access Unify® | Lifecycle as CAL. CODE REGS. Title 11, § 7122
U.S. AI regulation in 2026 is still state led. The federal government has issued AI policy, agency guidance, executive directives, and proposed frameworks, but Congress has not yet enacted a comprehensive national AI statute that clearly governs private-sector AI use across employment, records, consumer data, automated decision-making, and system accountability. In that vacuum, states can move faster, using their traditional authority over those areas of concern.
Colorado is an excellent example of state flexibility and agility as it completed a reset of its first-in-the-nation AI law this year, before the original framework fully took effect, by repealing and reenacting the law with amendments. Colorado replaces the broader “high-risk AI” framework with a narrower regime focused on automated decision-making technology (ADMT) used in consequential decisions. The main compliance obligations begin January 1, 2027, and the law centers on practical accountability measures. Developers must provide technical documentation to deployers, organizations using covered ADMT must give consumer notices and post-adverse-outcome disclosures, and consumers receive rights to access relevant personal data, correct factually inaccurate data, and request meaningful human review and reconsideration. Businesses must retain compliance records for at least three years, and the Colorado attorney general enjoys rulemaking and enforcement authority which prevents any private right of action.
Cited in Access Unify® | Lifecycle as COLO. REV. STAT. § 6-1-1702 & 1703
The EU AI Act is now moving from framework to implementation. The core of AI obligation remains as Regulation (EU) 2024/1689, the Artificial Intelligence Act, which entered into force on August 1, 2024, and has a phased application; prohibited practices and AI literacy began in 2025, general-purpose AI rules began in 2025, and most rules will apply beginning August 2, 2026.
The most important 2026 implementation materials are guidance and codes of practice. The Commission’s Guidelines on general-purpose AI models clarify the scope of GPAI obligations, open-source treatment, model modification, notifications, serious-incident reporting, and public summaries of training content. The General-Purpose AI Code of Practice provides voluntary commitments for transparency, copyright, and safety/security, including model documentation and systemic-risk practices. The Commission also published the final Code of Practice on marking and labelling AI-generated content on June 10, 2026, aimed at helping providers and deployers meet EU AI Act Article 50 transparency obligations for chatbots, deepfakes, and AI-generated or AI-manipulated content.
While the EU methodically and purposefully rolls out the expanding framework for the EU AI Act, the clearest records retention duties remain in the AI Act, not in the rollout guidance documents. Those obligations still include a 10-year retention for the technical documentation, quality management system documentation, and declarations of conformity. A 6-month obligation applies for automatically generated high-risk AI system logs under the control of providers and deployers.
Cited in Access Unify® | Lifecycle as Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, Arts. 11, 17, 18, 19, 22, 23, 26
At the member-state level, progress is uneven because while the AI Act sets the regulatory requirements, member states must create the enforcement structures, authorities, and penalties within their respective jurisdictions. Below is a snapshot of member states that have already put national AI laws in place. Other member states are at different stages of drafting legislation and building authority structures.
| Denmark | Law No. 467 of 14 May 2025 | Act on supplementary provisions to the Regulation on Artificial Intelligence. |
| Finland | Act 1377/2025 | Act on the Supervision of Certain Artificial Intelligence Systems |
| Hungary | Act LXXV of 2025 | Implementation of the European Union Regulation on Artificial Intelligence in Hungary |
| Government Decree No. 344/2025 (X.31) | Implementation of the EU Artificial Intelligence Regulation | |
| Ireland | S.I. No. 366/2025 | European Union (Artificial Intelligence) (Designation) Regulations 2025 |
| Italy | Law No. 132/2025 | Provisions and delegation of powers to the Government regarding artificial intelligence |
| Lithuania | Law No. XIII-1414 | Law on Technology and Innovation |
| Law No. X-614 | Law on Information Society Services | |
| Malta | Legal Notice 226 of 2025 | Artificial Intelligence Regulations |
| Legal Notice 227 of 2025 | Data-protection legislation | |
| Slovenia | ZIUDHPUI | Act on the Implementation of the EU Regulation on Harmonised Rules on Artificial Intelligence |
Recent amendments to California’s employment law underscore why employers should keep close watch on the state’s legislative calendar—even targeted changes can create new recordkeeping, notice, and data governance obligations.
California SB513 took effect January 1, 2026, and expands access by employees or their representatives to personnel records, including education and training records when employers maintain them. The statute requires those records to include the employee’s name, training provider, training duration and date, core competencies, and any resulting certification or qualification. The amendment preserves the requirement to make personnel records available for inspection or copying within statutory timeframes and to retain personnel records for at least three years after termination.
Cited in Access Unify® | Lifecycle as CAL. LAB. CODE § 1198.5
California SB464, signed in late 2025 and goes into effect in January 2027, requires covered private employers and labor contractors to ensure demographic information gathered for pay data reporting is collected and stored separately from personnel records.
Cited in Access Unify® | Lifecycle as CAL. GOV’T. CODE § 12999
California SB294, also signed in late 2025, went into effect January 1, 2026. The Workplace Know Your Rights Act requires employers to provide specified rights notices and to keep records of compliance for three years, including the date each notice was provided or sent.
Cited in Access Unify® | Lifecycle as CAL. LAB. CODE § 1553
To learn more about how to address records retention, data privacy and security requirements more efficiently, request a call with an Access expert, or request a product demonstration of Access Unify® | Lifecycle.
Share