‘Trust issue’ means states will keep regulating privacy, lawmaker says

Tatiana Maksimova via Getty Images
Opponents of state action have called for Congress to pass a national data privacy law, which has been unsuccessful so far. Residents are scared of tech and AI and want help, a Virginia delegate argued.
In early June, a House subcommittee held another hearing about another proposed federal data privacy law to provide national standards and preempt the numerous state laws on the subject.
But since then, all has gone quiet once again on data privacy as Congress lurches towards the midterm elections in November and other issues have taken precedence. Meanwhile, states are continuing to legislate on data privacy, especially as worries about artificial intelligence remain high.
And that lawmaking on privacy will continue, one state representative said last week, especially as they are hearing from constituents about their anxieties over technology while Congress does nothing.
“A lot of what we're hearing about is AI and job impacts, the environmental impacts of the training and running of the AI models then just sort of these products themselves,” Virginia Del. Kirk McPike said during a panel discussion at the Augmented and Virtual Reality Policy Conference last week. “There's a trust issue.”
Virginia’s own comprehensive privacy law went into effect in 2023 after being passed in 2021. It is one of several state laws that provides residents with various rights in how their personal data is collected and used, and gives them the ability to request records of data held by companies. The Virginia Attorney General’s Office enforces the law, but there is no right of private action.
That law and others come as elected officials have struggled to regulate various new innovations and technologies. McPike drew a comparison with social media platforms, which have been shown to cause numerous harms, especially to young people, prompting state lawmakers in particular to try and implement safeguards.
“I think that if a lot of these AI tools had emerged in the late 2000s when the last big thing to come out of the tech industry was the internet and the iPhone, that some of this would have been received in an open-minded way,” McPike said. “But right now, it's coming into the world in an era where the last major things to come out of the tech industry that impacted people's day-to-day lives and ways they felt were things like social media, which seemed fun when it started and then turned horrifying.”
Despite those concerns, business groups and others have continued to warn about a fragmented policy landscape that drives up compliance costs. During the panel, Jordan Crenshaw, senior vice president of the U.S. Chamber of Commerce’s Technology Engagement Center, said that fragmentation “ultimately shows up as a tax on innovation.”
Crenshaw did praise Virginia’s privacy law and called it a “great model for the country.” But at the same time, he warned, “other states don't get it right.”
“We understand there's some great state models out there, but we also want to make sure that we're not subjecting small businesses to those bad state models that could put them behind,” he said, noting that the physical and time costs for compliance can weigh heavily on small businesses.
Regulating privacy may take something of a back seat to regulating artificial intelligence, which is something that many states have at least attempted, despite threats of preemption by the federal government. But the lessons from Colorado, which tried to comprehensively regulate AI only to revise its legislation and push back its effective date for further revisions, weigh heavily and may help guide what happens next.
“I think what we see now are states taking much more targeted approaches,” said Meghan Pensyl, director of policy at the Business Software Alliance, during the panel discussion. “We're not seeing the broad comprehensive frameworks get enacted at the state level because that's really difficult. Instead, we're seeing a lot of legislation being enacted with respect to particular technologies, whether it's companion chat bots or frontier models.”
Similar to privacy laws, a lack of national regulations on AI and preemption of state laws will create a “void that cannot be sustained,” McPike warned. And Pensyl urged state lawmakers to work together across jurisdictional lines where possible, as they could “develop models that create harmonization.”
“I think you're going to continue to see more efforts by states to engage with this issue until there is some clear leadership at the federal level setting at least a baseline in terms of what interactions with models are allowable at what age levels,” he said.




