Alston & Bird Consumer Finance Blog

Bank Regulatory

Expansion of New York’s Community Reinvestment Act Via New Regulation

Last week, the New York State Department of Financial Services (DFS) announced a new regulation designed to ensure that licensed nonbank mortgage bankers in New York (“mortgage lenders”) meet the needs of the communities they serve in the state, particularly low- and moderate-income (LMI) neighborhoods and borrowers. Under New York law, “low-income” means income that is less than 50% of the area median income, in the case of an individual, or a median family income that is less than 50% of the area median income, in the case of a geography. Further, “moderate-income” means income that is at least 50% and less than 80% of the area median income, in the case of an individual, or a median family income that is at least 50% and less than 80% of the area median income, in the case of a geography.

By way of background, in November 2021, New York amended the state’s Community Reinvestment Act (CRA), which at the time mirrored the federal Community Reinvestment Act, to expand coverage to New York state-licensed mortgage bankers. This made New York the third state (after Illinois and Massachusetts) to pursue such action.

The new regulation, effective July 7, 2026, takes things further by imposing following parameters and requirements on mortgage lenders as set forth below.

Origination Threshold

Non-depository mortgage bankers that have made at least 200 HMDA-reportable originations in the preceding year are subject to performance evaluation under the new regulation and will receive a rating of Outstanding, Satisfactory, Needs Improvement, or Substantial noncompliance.

No Branches, No Problem

A mortgage banker with one or more branches within the state must delineate one or more branch-based assessment areas for evaluating performance. However, “branchless” lenders will be evaluated based on where they do a substantial portion of their business. Specifically, the lender must delineate a lending-based assessment area in each MSA or nonmetropolitan area in which it originated, in each of the two preceding calendar years, at least 100 mortgage loans outside of any branch-based assessment areas.

Performance Tests

The regulation imposes a lending test and service test on non-bank mortgage lenders, to arrive at a performance rating. Notably, the DFS, when reviewing a mortgage lender’s change of control, branch, or other application, will consider the mortgage lender’s record of CRA performance.

  • Lending test. The lending test assesses how well mortgage bankers serve all borrowers and neighborhoods within their assessment areas, particularly LMI communities. The lending test considers the geographic distribution of loans in LMI tracts and to LMI borrowers. In addition, the lending test considers the lender’s innovative and flexible lending practices, carried out safely and soundly, to meet the needs of these communities.
  • Service test. The service test evaluates whether mortgage lenders offer programs and services that promote community development. Unlike banks, however, mortgage bankers will not be required to make community development investments or grants, recognizing the differences in how these institutions operate. Nevertheless, mortgage lenders will be evaluated on the extent and innovativeness of their community development services, qualified investments, community outreach, marketing, and educational programs; each of which are defined terms under the regulation.

Discrimination and Other Illegal Credit Practices

The evaluation of a mortgage banker’s performance in meeting the credit needs of the community is adversely affected by evidence of discriminatory or other illegal credit practices in any geography by the mortgage lender, including violations of (1) Section 5 of the FTC Act, (2) Section 8 of RESPA, (3) TILA’s right of rescission, (4) HOEPA or New York’s high cost lending law, or (5) ECOA, Fair Housing Act or section 296-a of New York Executive Law.

Given the above, New York-licensed mortgage lenders should prepare for these CRA obligations by conducting preliminary analysis of their lending in LMI census tracts and to LMI borrowers, to ensure that both marketing efforts and loan product offerings are meeting the needs of these communities. While federal redlining enforcement may currently be deprioritized, state-level CRA inquiries and investigations are likely to ramp up. Alston & Bird is able to assist mortgage lenders with proactive efforts to ensure compliance with New York’s CRA law.

Commercial Financing Disclosure Requirements and Exemptions

What Happened

In a development that has not attracted sufficient industry attention, eleven commercial financing laws enacted to date require providers of certain types of commercial financing to disclose key terms to small businesses and other covered entities before a transaction is consummated. These requirements apply to providers of commercial financing transactions that are in amounts below certain thresholds, such as sales-based financing, closed-end and open-end commercial loans, factoring transactions, lease financing, accounts receivable purchases, and asset-based lending arrangements.

Why It Is Important

This post summarizes the salient elements of the of these eleven state laws that have been enacted to date in California, Connecticut, Florida, Georgia, Kansas, Louisiana, Missouri, New York, Texas, Utah, and Virginia, respectively, including a brief description of the coverage of the statutes as well as the notable exemptions and applicable disclosure and registration requirements. Some of these statutes also impose registration requirements upon lenders, and all of them subject violators to substantial penalties.

California

The California disclosure requirements took effect on December 9, 2022. With respect to California’s law, persons providing commercial financing (including small business loans and merchant cash advances) to recipients “whose business is principally directed or managed from California” are required to provide recipients with consumer-like disclosures, after the California Department of Financial Protection and Innovation issued final regulations in June 2022 to implement the California Commercial Financing Disclosure Law (“CCFDL”). Commercial financing providers are required to disclose to the recipient at the time of extending a specific commercial financing offer specified information relating to the transaction and to obtain the recipient’s signature on that disclosure before consummating the commercial financing transaction. The CCFDL exempts, among others, regulated depository institutions (banks, credit unions, etc.), transactions greater than $500,000 and real estate-secured commercial loans or financings. The California law otherwise applies to, among other things, commercial loans, certain commercial open-end plans, factoring, merchant cash advances, and commercial asset-based lending. Under the California law “provider” is primarily limited to entities that extend offers of commercial financing, such as lender/originators, but also includes a non-bank partner in a marketplace lending arrangement who facilitates the arrangement of financing through a financial institution.

Connecticut

On June 28, 2023, Connecticut enacted “An Act Requiring Certain Financing Disclosures,” which requires (1) providers offering “sales-based financing” (a/k/a revenue-based financing) in amounts of $250,000 or less to provide specified disclosures to applicants; and (2) mandates that providers offering sales-based financing register annually with the Connecticut Department of Banking starting by October 1, 2024. The Connecticut law authorizes the state banking commissioner to adopt promulgating regulations, and the law took effect on July 1, 2023. The Connecticut law applies to providers of commercial financings and defines “provider” as “a person who extends a specific offer of commercial financing to a recipient and includes, unless otherwise exempt … a commercial financing broker.” “Commercial financing” means any extension of sales-based financing by a provider not exceeding $250,000. Under the statute, “sales-based financing” is a “transaction that is repaid by the recipient to the provider over time” (1) as a percentage of sales or revenue, in which the payment amount may increase or decrease according to the recipient’s sales or revenue, or (2) according to a fixed payment mechanism that provides for a reconciliation process that adjusts the payment to an amount that is a percentage of sales or revenue. Notably, the Connecticut law exempts the following entities and transactions: banks, bank holding companies, credit unions, and their subsidiaries and affiliates; entities providing no more than five commercial financing transactions in a 12-month period; real estate-secured loans; leases; purchase money obligations; technology service providers acting for an exempt entity as long as they do not have an interest in the entity’s program; transactions of $50,000 or more to motor vehicle dealers or rental companies; transactions offered in connection with the sale of a product that the person manufactures, licenses, or distributes.

Florida

Effective July 1, 2023, Florida enacted the Florida Commercial Financing Disclosure Law, which requires covered providers to furnish consumer-oriented disclosures to businesses for certain commercial non-real estate secured financing transactions exceeding $500,000. The Florida law applies to providers of commercial financing transactions and defines “provider” as a “person who consummates more than five commercial financings” in Florida during any calendar year. “Commercial financing transactions” include commercial loans, open-end lines of credit, and accounts receivable purchase transactions. The Florida law exempts the following entities and transactions: federally insured depository institutions, their subsidiaries, affiliates, and holding companies; licensed money transmitters; real estate-secured loans; loans exceeding $500,000; leases; and certain purchase money transactions. All financings made on or after January 1, 2024, must comply with this requirement.

Georgia

Effective January 1, 2024, Georgia amended its Fair Business Practices Act to require certain providers of commercial financings of $500,000 or less to furnish TILA-like disclosures to small-business borrowers before the consummation of the transactions. Transactions greater than $500,000 are exempt from the disclosure requirements. The Georgia law defines “provider” as “a person who consummates more than five commercial financing transactions” in Georgia during any calendar year, including participants in commercial purpose marketplace lending arrangements. “Commercial financing transactions” include both closed-end and open-end commercial loans as well as accounts receivable purchase transactions but do not include real estate-secured transactions. The Georgia law exempts federally insured depository institutions and their subsidiaries, affiliates, and holding companies; Georgia-licensed money transmitters; captive finance companies; and institutions regulated by the federal Farm Credit Act. Purchase money obligations are also exempt.

Kansas

The Kansas Commercial Financing Disclosure Act, which took effect July 1, 2024, applies to “commercial financing transactions” of $500,000 or less, defined to include any commercial loan, commercial open-end credit plan, lines of credit, and accounts receivable purchase transaction, with a business located in Kansas. A provider subject to the Kansas Act must disclose the following to the recipient of financing before, or at the time of, consummation: total amount of funds provided to the recipient; total amount of funds disbursed to the recipient; total of payments made to the provider; total dollar cost of financing for the recipient; manner, frequency and amount of each payment (or estimates if these terms may vary, along with the provider’s methodology for calculating variable payments and circumstances where payments may vary); and prepayment costs or discounts.

Louisiana

Effective August 1, 2025, Louisiana law requires provides of “revenue-based financing transactions,” defined as “an agreement under which a person engaged in a commercial enterprise sells or agrees to forward a percentage of sales, revenue, or income, and the person’s payment obligation increases and decreases according to the volume of sales made or revenue or income received,” to provide written disclosures to recipients of financing. Notably, Louisiana’s law is the first state commercial financing disclosure law that does not exempt any types of entities or transactions, regardless of dollar amount.

Missouri

Missouri Senate Bill 1359, which includes provisions for commercial lending disclosures, went into effect on February 28, 2025. The Missouri law prescribes that several disclosures be made for commercial financing transactions and applies to “providers” of commercial financing transactions, defined as a “person who consummates more than five commercial financings” to a business located in Missouri in any calendar year. “Commercial financing transactions” include any unsecured and secured commercial loan, accounts receivable purchase transaction, commercial open-end credit plan or each to the extent the transaction is a business purpose transaction. Exemptions from the Missouri law include the following entities and transactions: a depository institution or a subsidiary or affiliate; a service corporation to a depository institution that is owned and controlled by same and regulated by a federal banking agency; a lender regulated by the federal Farm Credit Act; real estate-secured loans; a lease; a licensed money transmitter; loans exceeding $500,000; and certain purchase money transactions. This law also contains a registration requirement for brokers.

New York

The New York Commercial Financing Disclosure Law (“NYCFDL”) took effect August 1, 2023, and is substantially similar to the California requirements. It requires “providers” of commercial credit to provide Truth-in-Lending Act-like disclosures to applicants at the time it extends a specific offer of the commercial financing in amounts of $2,500,000 or less. “Providers” include both lenders and brokers. The NYCFDL applies to closed end financing, open-end financing, sales-based financing, including merchant cash advances and factoring transactions. The NYCFDL provides a de minimis exemption, “for any person or provider who makes no more than five commercial financing transactions in [New York] in a twelve-month period.” Further, “Financial institutions”, which include banks, and certain other chartered depository institutions authorized to conduct business in New York, are also exempt from the new commercial loan disclosure law, but the subsidiaries or affiliates of such exempt financial institutions are not exempt. Commercial financings over $2,500,000 are exempt from the law as are transactions secured by real property. The obligation to provide disclosures apply if the financing recipient’s business is “principally directed or managed from New York.”

Texas

On May 28, 2025, the Texas legislature passed a “commercial sales-based financing” bill, known as House Bill 700, and Governor Greg Abbott signed the bill into law on June 20, 2025. Among other things, the Texas law requires disclosure of sales-based financing terms to recipients, and, starting December 31, 2026, registration for all sales-based financing providers and brokers with the Texas Office of Consumer Credit Commissioner. Registrants must renew their registrations annually by January 31. The legislation exempts from its requirements the following entities: banks (specifically including out-of-state banks) and their subsidiaries and affiliates, certain companies that provide tech services to exempt entities, lenders regulated under the Farm Credit Act, real property secured sales-based financing, true (operating) leases, and certain commercial sales-based financing agreement or commercial open-end credit plan of $50,000 or more. Financings greater than $1 million are exempt from the disclosure requirement. Unlike any other current state law, the Texas law also contains a provision prohibiting sales-based financing providers and brokers from establishing a mechanism for automatically debiting a recipient’s deposit account unless the provider or broker holds a validly perfected security interest in the recipient’s account under the Texas UCC, with a first priority against the claims of all other persons. Most provisions of the law became effective on September 1, 2025, except for the provider and broker registration requirement.

The Texas legislation, while part of a growing trend of augmented state regulation of commercial non-real estate secured commercial financing, is far more burdensome than other similar state laws enacted to date.

Utah

Effective January 1, 2023, the Utah law requires providers to register with the Utah Department of Financial Institutions and maintain such registration annually. Further, prior to consummation of the commercial financing, providers must, among other things, disclose to recipients: (i) the total amount of funds provided to the business; (ii) the total amount of funds disbursed to the business; (iii) the total amount paid to the provider under the financing; (iv) the manner, frequency and amount of each payment (or if the amount of each payment may vary, the manner, frequency and estimated amount of the initial payment); (v) information regarding prepayment of the financing; and (vi) the amount the provider paid to the broker, if applicable. The Utah law does not apply to consumer purpose transactions, real estate-secured transactions or transactions with loan amounts greater than $1 million—or if the provider makes five or fewer Utah commercial financings in any calendar year.

Virginia

The Virginia law, which took effect on July 22, 2022, includes some of the same type of disclosure requirements that other states discussed above have adopted, but it is limited to sales-based financing. Notably, the Virginia law requires sales-based financing providers to make disclosures of the financing terms on a prescribed form at the time the provider offers sales-based financing to a recipient—and requires them to register with the Virginia State Corporation Commission. The law exempts sales-based financings in amounts over $500,000 and contains a de minimis exemption for a person that enters into no more than five “sales-based financing” transactions in any 12-month period.

What to Do Now

It is anticipated that other states will enact similar laws in the future that will impact small balance commercial lending. Lenders must either comply with these nettlesome laws or structure their transaction to avoid triggering them.

Privacy, Cyber & Data Strategy Advisory | How AI Is Changing the Incident Response Landscape: What GCs Need to Know

Originally published January 6, 2026 on the Alston & Bird website.

Executive Summary

Our Privacy, Cyber & Data Strategy Team examines the profound implications of the evolution of AI-driven cyberattacks and offers practical steps general counsel can take to proactively defend against them.

  • Vibe hacking—AI’s ability to work autonomously—eliminates threat actors’ need for technical expertise or large teams to conduct complex attacks
  • Game-changing polymorphic malware and “just-in-time” AI-driven code regeneration can defeat traditional defenses
  • General counsel can update their companies’ own AI systems and ensure third-party AI vendors have the latest security

The cyber-threat landscape has always evolved rapidly, but the emergence and weaponization of artificial intelligence (AI)—particularly generative AI (GenAI)—by threat actors represents a seismic shift that cannot be ignored. Just one year ago, we wrote about the early stages of adversaries using AI to automate and customize cyberattacks, primarily to improve phishing campaigns, develop deepfakes, and refine their tactics, techniques, and procedures. Over the past year, threat actors have significantly escalated their use of AI, moving from “vibe hacking”—the use of agentic AI systems that can reason, plan, and act autonomously as both technical consultants and active operators of cyberattacks—to unprecedented integration and autonomy of AI throughout the attack life cycle.

If that were not enough, we are now starting to see polymorphic malware and “just-in-time” AI-driven code regeneration, which are true game changers. Polymorphic malware powered by AI can continuously rewrite its own code in real time, defeating traditional signature-based detection and even heuristic analysis. Compounding these risks are cyberattacks targeting AI systems themselves, such as prompt injection attacks that manipulate the reasoning layer of AI models and often leave no meaningful forensic trail. This creates significant limitations for conventional forensic tools and logging frameworks, which were never designed to capture the internal logic of autonomous AI agents.

The Evolution of AI in Cyberattacks: From Phishing Emails and Deepfakes to Fully Automated AI-Powered Cyberattacks

Initially, threat actors used AI to enhance phishing campaigns—improving grammar, tone, and personalization to increase success rates. Attackers soon leveraged AI to create convincing deepfakes for social engineering and fraud. By mid-2025, vibe hacking emerged as hackers began to use and code agentic AI systems not just to be assistants in an attack but as autonomous operators capable of executing complex, multistep cyberattacks. Today, organizations face fully automated AI-powered attacks with minimal human oversight.

This shift is driven by several factors:

  • An evolution of AI to be able to execute nearly every stage of an attack.
  • The maturing underground marketplace for illicit AI tools.
  • AI’s ability to complete cyberattacks faster than before.
  • Elimination of the need for hackers with deep technical expertise or large teams with specific expertise to conduct complex cyberattacks.

Vibe hacking is threat actors’ use of agentic AI systems as technical consultants and active operators of cyberattacks. In practice, AI agents like Claude Code are no longer just assisting attackers; they are executing multistep operations independently, from reconnaissance and credential harvesting to data exfiltration and ransom note generation. This evolution lowers the barrier to entry for sophisticated cybercrime and enables lone actors to conduct campaigns that previously required coordinated teams.

Cybercriminals took this to the next level in the last quarter of 2025. Highly sophisticated threat actors, including a Chinese state-sponsored group (designated by Anthropic as GTG-1002), demonstrated “unprecedented integration and autonomy of AI throughout the attack lifecycle.” GTG-1002 coordinated targeted attacks against approximately 30 entities, with several confirmed compromises.

Claude Code was manipulated to autonomously execute 80%–90% of an attack—reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration. Humans primarily assumed a strategic oversight role, initiating the campaign and intervening at critical decision points. Anthropic indicated this marked the first documented case of agentic AI successfully obtaining access to confirmed high-value targets for intelligence collection.

While these attacks were highly sophisticated, limitations remain. In the Anthropic-reported attacks, AI tools occasionally hallucinated data, misidentified credentials, and flagged publicly available information as sensitive. These errors, however, can be corrected with minimal human oversight, rapidly shrinking the limitations to fully autonomous attacks.

Accelerated speed of AI-powered cyberattacks

AI has dramatically shortened the time required to execute a cyberattack from start to finish. In fact, a defining characteristic of AI-powered attacks is the ability to gather and analyze data efficiently. AI tools not only speed up the research phase of a cyberattack but also improve the accuracy and completeness of a threat actor’s analysis of data.

Anthropic’s November 2025 report illustrates how AI compresses every stage of the attack life cycle:

  • Reconnaissance. AI agents can automate reconnaissance tasks, scanning thousands of endpoints, cataloging systems, mapping infrastructure, identifying exposed services, and analyzing authentication mechanisms quickly. Tasks that once required weeks of manual effort can now be completed in hours.
  • Vulnerability Discovery. AI systems can autonomously test for misconfigurations, weak credentials, and exploitable flaws using adaptive scripts that evolve based on real-time feedback.
  • Exploitation and Lateral Movement. Agentic AI can sequentially leverage multiple vulnerabilities without human intervention, moving across networks and escalating privileges with minimal oversight.
  • Credential Harvesting and Data Analysis. AI accelerates credential cracking and can parse massive datasets for sensitive information at machine speed, enabling attackers to identify and prioritize high-value assets instantly.
  • Exfiltration and Monetization. AI orchestrates stealthy data exfiltration while simultaneously generating ransom notes or negotiating scripts tailored to victims.

This level of automation is not theoretical—it has already been observed in real-world campaigns. The ability to compress what was once a multiweek operation into a matter of hours or days is a paradigm shift in cyber-risk.

Lowering the barrier to entry

AI has erased the need for hackers to have extensive technical expertise. Threat actors who previously lacked the skills to execute complex attacks can now simulate professional competence through AI assistance. For example, North Korea’s IT remote worker scheme has been transformed by AI, enabling operatives to pass interviews, maintain engineering roles, and deliver work product without formal training. Beyond nation-state actors, AI empowers individual cybercriminals to accomplish what once required entire teams. Developing ransomware, identifying targets, and making strategic and tactical decisions around exploitation and monetization of stolen data can now be performed with the assistance of AI and a single individual overseeing the operation.

AI-Powered Polymorphic Malware and Code Regeneration

In its November 2025 AI Threat Tracker report, Google’s Threat Intelligence Group (GTIG) highlighted a shift from threat actors leveraging AI just for productivity gain to threat actors deploying novel AI-enabled malware in active operations. This can be seen in the growing use of just-in-time (JIT) code regeneration, allowing attackers to dynamically rewrite malicious code during execution, making detection and static analysis extremely difficult. GTIG emphasized that this capability enables malware to adapt to defensive measures in real time, reducing the effectiveness of traditional signature-based detection.

While GTIG focused on JIT regeneration, other sources, including Anthropic and independent threat researchers, have documented the rise of AI-powered polymorphic malware—malicious code that continuously mutates its structure to evade detection. Emerging strains such as PROMPTFLUX demonstrate how attackers use large language models (LLMs) to adjust code in malware so it can evolve dynamically and remain stealthy almost indefinitely.

The implications are profound: AI-driven polymorphism and JIT regeneration reduce the cost and complexity of maintaining stealth, making advanced malware accessible to less-skilled actors. Combined with AI’s ability to orchestrate reconnaissance, exploitation, and exfiltration, this trend alters the landscape for enterprise security.

Cyberattacks on AI Systems and Investigation Gaps

Cyberattacks against AI systems are introducing new challenges for forensic investigations and for understanding what happened and why. Even with the right security such as endpoint detection and response software and robust traditional monitoring and logging in place, there may be significant gaps when investigating AI-driven attacks.

One of the most concerning examples is a prompt injection attack, which targets AI systems by embedding malicious instructions inside what appears to be normal input. For instance, an attacker might hide a command such as “delete all logs” within a seemingly benign request. Because LLMs cannot reliably distinguish between trusted commands and untrusted data, the AI may execute these instructions without question. This creates a fundamental problem both for securing the AI system itself and for forensically investigating these attacks.

Conventional investigations rely heavily on system-level logs—detailed records that explain what happened within an operating system or application—that allow investigators to reconstruct the timeline of an attack, identify actions taken, and determine which systems were compromised. However, prompt injection attacks occur inside the AI’s reasoning layer, not at the operating system level. If the AI is instructed to erase or alter logs, investigators may only see the outcome (e.g., data exfiltration or deletion) without any record of the causal chain or how the outcome occurred.

In other words, the “why” behind the action is missing because the attack exploits the AI’s cognitive process rather than the system’s technical process. Forensic teams cannot rely on the old playbook—they likely need new methods such as monitoring AI interactions, auditing prompts, and implementing specialized AI audit trails to reconstruct the reasoning chain.

Practical Tips and Actionable Steps

As AI-driven cyber-threats accelerate, general counsel (GCs) play a critical role in shaping governance, risk management, and legal response strategies.

  1. Update Incident Response Procedures for AI-Powered Cyberattacks. AI-driven attacks occur at unprecedented speed and often outpace traditional response timelines. Companies should consider updating incident response procedures to explicitly address these threats. Organizations should also consider incorporating scenarios involving AI-powered attacks, such as polymorphic malware and prompt injection, into tabletop exercises to test readiness and identify gaps. These exercises provide valuable insights into how an AI-driven incident might unfold and help better prepare the organization to respond to the unique nature of AI-driven attacks.
  2. Investigate AI-Powered Cyberattacks—Protect Privilege and Ensure Vendor Expertise. AI-powered attacks introduce new types of evidence—such as prompt logs, model outputs, and reasoning steps—that traditional forensic processes do not capture. GCs should structure investigations to preserve attorney-client privilege for AI-related forensic evidence. Given the new types of forensic evidence, companies may also want to verify that their preferred third-party forensic firms maintain the necessary expertise.
  3. Audit AI Inputs. Where feasible and appropriate, organizations should consider regularly auditing AI inputs to fine-tune the AI system to detect and block malicious or misleading prompts before they trigger harmful actions. Auditing reduces the risk of unauthorized activity and provides transparency into how AI systems interpret and act on sensitive information. Reviewing prompts and outputs enables companies to identify misuse patterns; it also strengthens controls and ensures accountability in AI-driven decision-making.
  4. Revisit Vendor Management and Contracts. AI introduces risks that traditional vendor agreements do not fully address. Companies should consider contractual provisions that require vendors to monitor AI systems for misuse, such as prompt injection attacks, and maintain detailed audit trails of prompts and outputs for forensic investigations. Companies should consider including provisions that mandate compliance with emerging AI regulations in vendor agreements to ensure vendors meet evolving legal and security standards.
  5. Review Governance and Oversight. GCs can be an advocate for an AI risk governance framework that aligns with regulatory expectations and industry standards. Board-level reporting should include AI-specific threat trends and mitigation strategies. This helps with leadership visibility and accountability for AI-related risks.
  6. Monitor Regulatory and Liability Developments. Stay ahead of emerging AI regulations and assess potential liability exposure for AI misuse or compromised AI systems. This will allow GCs to advise leadership on compliance obligations and risk mitigation strategies.

Ransomware Fusion Center

Stay ahead of evolving ransomware threats with Alston & Bird’s Ransomware Fusion Center. Our Privacy, Cyber & Data Strategy Team offers comprehensive resources and expert guidance to help your organization prepare for and respond to ransomware incidents. Visit Alston & Bird’s Ransomware Fusion Center to learn more and access our tools.


If you have any questions, or would like additional information, please contact one of the attorneys on our Privacy, Cyber & Data Strategy team.

You can subscribe to future advisories and other Alston & Bird publications by completing our publications subscription form.


President Trump Signs Executive Order Aiming to Curb State AI Regulation

Originally published December 18, 2025 (source).

Executive Summary

President Trump issued an Executive Order aimed at discouraging state artificial intelligence (AI) regulation through federal agency action and funding conditions, without directly preempting state law. Our Privacy, Cyber & Data Strategy Team discusses the resulting uncertainty and what businesses should watch as agencies begin implementing the Order.

  • The Order relies on indirect federal measures, not express preemption, to constrain state AI regulation
  • State laws addressing AI outputs, disclosures, and alleged bias may face increased scrutiny
  • Businesses should continue complying with applicable state AI laws while monitoring federal agency actions

On December 11, 2025, following several unsuccessful congressional attempts to pass a statutory moratorium on state-level artificial intelligence (AI) regulation, President Trump signed an Executive Order that seeks to limit states’ ability to regulate AI under their existing legal frameworks, and to deter them from passing new AI laws. Per the Order, the Trump Administration sees the United States in an AI arms race with adversaries, which it seeks to win—and argues that burdensome state-level AI regulation could impede American innovation, competitiveness, and national security in this effort. The Order also takes the position that a state-by-state AI regulation “patchwork” adds challenging compliance burdens, mandates ideological bias within models, and impermissibly regulates beyond state borders.

The Order seeks to encourage a “minimally burdensome national policy framework for AI” through a variety of measures. Given that an Executive Order applies only to federal agencies, this may raise a key gating question: How, if at all, can an Executive Order impact the effectiveness of state law or the state lawmaking process? However, the Order does not purport to preempt state law. Instead, it adopts various indirect measures—to be implemented by federal agencies—intended to encourage states not to enforce or pass overly burdensome AI regulation, or to penalize them if they do. It also asks certain agencies to use their existing authorities in ways that may preempt state AI laws.

Summary of the Order

The Order takes several actions in pursuit of its goal of a “minimally burdensome” regulatory framework for AI. These broadly fit into two categories. First, the Order establishes a framework through which the Trump Administration can challenge state AI laws or incentivize states not to pass or enforce AI laws. Second, the Order instructs certain agencies to implement policies that the Administration hopes may preempt state AI laws.

Key actions established by the Order include:

  • DOJ AI Litigation Task Force. The Order directs Attorney General Pam Bondi to create an “AI Litigation Task Force” within the Department of Justice DOJ). Its task is to challenge state AI laws inconsistent with the Administration’s policy, or with the goal of “global AI dominance” by the U.S. It remains unclear on what specific AI statutes and regulations would be challenged, or on what basis they would be challenged. The Order’s language seems to give the DOJ broad discretion.
  • Evaluation of “Onerous” State AI Laws. The Order directs Secretary of Commerce Howard Lutnick to publish a report identifying “onerous” existing state AI laws. Per the Order, laws will be deemed onerous if they (1) require AI models to alter truthful outputs; or (2) require AI developers or deployers to engage in impermissible compelled speech or otherwise “disclose or report information in a manner that violates the First Amendment or any other provision of the Constitution.”
  • Restrictions on Broadband Funding. The Order also directs the Department of Commerce (DOC) to issue a policy notice tying states’ receipt of federal broadband funding to their “onerous AI” practices. Specifically, the DOC is directed to specify the conditions under which states that pass “onerous” AI legislation are ineligible for federal broadband funding. This is conceptually similar to the AI moratoria previously proposed in Congress; these tied a state’s receipt of federal broadband funding to a prohibition on it regulating AI. The Order maintains the tie between broadband funding and restrictions on AI regulation, but the tie will now be based on a DOC policy statement, along with a DOC finding that a state is engaged in “onerous” AI regulation. The Order suggests that any state the DOC identifies in its report on “onerous state AI laws” may be deemed ineligible for federal broadband funding.
  • Restrictions on Other Discretionary Spending. Other executive departments and agencies are ordered to assess their discretionary grant programs to determine whether they can condition discretionary funding on states not passing AI laws. For states that have already passed AI laws, agencies are instructed to try to enter into binding agreements with the states that tie receipt of discretionary funding to a commitment not to enforce the AI laws. In these efforts, federal agencies must work together with Special Advisor for AI and Crypto David Sacks.
  • Agency-Created Preemption. The Order directs the Federal Communications Commission to draft a federal reporting and disclosure standard to preempt conflicting state laws that regulate AI. It also directs the Federal Trade Commission (FTC) to publish a policy statement outlining how the FTC Act’s prohibition on unfair and deceptive trade practices preempts any state laws that require alterations to the truthful outputs of AI models. It remains to be seen whether these policy statements could in fact have preemptive effect.

Analysis of Impact on State AI Laws

The Order does not define what constitutes “minimally burdensome” or “onerous” AI regulation, giving wide interpretive discretion to the various agencies within the Administration empowered to enforce the Order (and leaving uncertainty for affected businesses). However, it gives clues on the types of AI laws that the Administration is likely to prioritize in any future actions.

First, the Order takes aim at state AI laws that require models to “alter their truthful outputs.” The Order explicitly calls out the Colorado AI Act and its provisions banning “algorithmic discrimination.” The Order takes the position that it—and similar laws— may induce AI models to produce “false results in order to avoid a ‘differential treatment or impact’ on protected groups.” Although not named in the Order, similar state AI laws banning algorithmic discrimination or bias, such as Illinois’s HB 3773, or new California privacy regulations on “automated decisionmaking technology,” may also be in the crosshairs.

The Order explicitly references state AI laws that require disclosure or reporting of information in violation of the First Amendment or other constitutional provisions. As an example of a law that may be targeted, California recently passed the Transparency in Frontier AI Act, which is a first-in-the-nation “frontier” AI regulation requiring developers of powerful AI models to publish a safety framework and report certain safety incidents to regulators. This law and similar legislation that imposes significant safety obligations on, or requires publication or disclosure of information by, frontier model developers (e.g., New York’s Responsible AI Safety & Education (RAISE) Act) and other AI companies may be targets of the Order.

In citing the First Amendment as a potential bar to such statutes, the Trump Administration may be thinking of prior constitutional challenges on “compelled speech” grounds. One example was a successful challenge to California’s Age-Appropriate Design Code, which required companies that provide digital services “likely to be accessed by minors” to draft detailed “data protection impact assessments” (DPIAs) and produce them to regulators upon request. The Ninth Circuit found the DPIAs were unconstitutional compelled speech and also deputized businesses to become “censors for the state.”

The Order’s broad, discretionary language casts a wide net of uncertainty over what state AI laws the Administration may challenge under the Order. For example, the AI Litigation Task Force is directed to sue states with AI laws “on grounds that such laws unconstitutionally regulate interstate commerce, are preempted by existing Federal regulations, or are otherwise unlawful in the Attorney General’s judgment.” This type of language gives wide discretion to the Administration to enforce the Order. At the same time, in its legislative recommendation provision, the Order expressly excludes laws that relate to children’s safety, AI computing and data center infrastructure, and state government procurement and use of AI, which suggests these types of laws may not be targeted.

Reactions and Legal Challenges

The Order has been praised by various industry groups, such as the Consumer Technology Association, while also receiving pushback from advocacy groups like the American Civil Liberties Union. It remains to be seen whether the Order will face legal challenges, or whether these will be reserved for the agency actions it requires, such as a DOC policy restricting federal broadband funding to states that pass “onerous” AI laws—or an FTC policy statement stating that states cannot use their UDAP statutes on AI.

The Order also calls on Congress to establish a single “minimally burdensome national standard” and tasks Sacks and Assistant to the President for Science and Technology Michael Kratsios with creating a proposed federal AI statute—including its preemption provisions. Congressional action would ameliorate many of the legal concerns that stem from a broad unilateral executive action; however, there is increased skepticism on federal deregulation of AI from Republicans, both on Capitol Hill and in state governments.

What Should Businesses Do?

Governors in California, Colorado, and New York issued statements indicating the Order will not stop them from passing, or enforcing, their local AI statutes and regulations. The DOC’s report on “onerous” AI will not be issued until spring 2026, and it has no effect on its own; any impact on the effectiveness of AI statutes will require challenges by the DOJ, agreements between states and executive agencies, or similar resolutions with significant lead times. Businesses should continue endeavoring to comply with AI laws, rules, and regulations that may apply to their operations.

We will continue to monitor developments arising from the Order, including any legal challenges and the complex state AI law landscape. Please contact our team if you have questions about the impact of the Order or the applicability of state AI laws to your company.

Ransomware Fusion Center

Stay ahead of evolving ransomware threats with Alston & Bird’s Ransomware Fusion Center. Our Privacy, Cyber & Data Strategy Team offers comprehensive resources and expert guidance to help your organization prepare for and respond to ransomware incidents. Visit Alston & Bird’s Ransomware Fusion Center to learn more and access our tools.

Executive Order, Action & Proclamation Task Force

Alston & Bird’s multidisciplinary Executive Order, Action & Proclamation Task Force advises clients on the business and legal implications of President Trump’s Executive Orders.

Learn more about administrative actions on our tracker.


If you have any questions, or would like additional information, please contact one of the attorneys on our Privacy, Cyber & Data Strategy team.

You can subscribe to future advisories and other Alston & Bird publications by completing our publications subscription form.


FAPA Is Here to Stay: Understanding the NY Court of Appeals’ Retroactivity Ruling and Its Impact on Foreclosures

On November 25, 2025, the New York Court of Appeals—the highest court in the state of New York—issued a decision in Article 13, LLC v. LaSalle National Bank Association, holding that New York’s Foreclosure Abuse Prevention Act (FAPA) applies retroactively to all foreclosure actions in which a final judgment of foreclosure and sale has not been enforced.

What Happened?

In December 2022, New York enacted FAPA to close a perceived loophole under prior case law that allowed the holders of mortgage notes to reset the statute of limitations on foreclosure. Previously, a noteholder could show that that the mortgage was not validly accelerated, or was voluntarily deaccelerated, which would reset the statute of limitations. Under FAPA, however, parties are estopped from asserting that an invalid acceleration or voluntary deacceleration reset the statute of limitations.

Two years before FAPA was enacted, Article 13 LLC—a junior mortgage holder on a property—brought a quiet title action before a federal district court seeking to cancel a senior mortgage as time-barred under the statute of limitations. Relying on pre-FAPA case law, the holder of the senior mortgage argued the statute of limitations had not run because the mortgage had not been validly accelerated. Mid-litigation, New York enacted FAPA, and the district court held that FAPA estopped the senior mortgage holder from making this argument.

The case went on appeal to the U.S. Court of Appeals for the Second Circuit, which certified the question of whether FAPA applied retroactively to the New York Court of Appeals. Based on FAPA’s plain language, the New York Court of Appeals first held that FAPA applies retroactively, at least for foreclosure actions in which a final judgment or foreclosure and sale has not been enforced. It then held that the retroactive application of FAPA does not violate substantive or procedural due process under New York’s constitution. The Court explained that retroactive application does not offend due process because it does not impair the vested rights of holders, which in the typical situation, are aware for years of the invalid acceleration and have every opportunity to take timely action to enforce their rights.

Why is it Important?

The New York Court of Appeal’s decision is significant because in cases where a prior foreclosure action was commenced (triggering the statute of limitations) but later discontinued without an express judicial determination that acceleration was invalid, lenders are now estopped from reviving the loan after the limitations period has expired. This puts an end to an old practice and represents a major shift in the mortgage foreclosure industry.

For mortgage servicers, this means that before proceeding with a foreclosure, they must first evaluate aged or delinquent loans to reassess whether pursuing foreclosure is viable. This is particularly true when prior foreclosures have been voluntarily discontinued, dismissed, or left dormant. Attempting to re-file may now lead to outright dismissal under FAPA.

For participants in the secondary market, it is now important to employ heightened diligence to determine whether mortgages held in trust are still enforceable. Mortgages or entire portfolios that were previously viewed as recoverable through renewed foreclosure actions may now be worth only their collateral value or even nothing at all.

What Do You Need to Do?

Mortgage servicers should review their foreclosure strategies, including their allocation of litigation resources, as time-barred loans may require alternative resolution strategies such as settlements or charge-offs.

Meanwhile, RMBS trusts and other holders of distressed mortgage portfolios should consider whether to audit their portfolio to identify mortgages with prior foreclosure actions that may now be time barred under FAPA. Or, in the case that they are junior lienholders, they should consider whether they can leverage FAPA in quiet title actions to cancel more senior mortgages that are now time-barred.