1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
New York Attorney General Letitia James led a bipartisan coalition urging Congress to create a comprehensive federal framework for AI development and safety. The letter cited reports that AI agents escaped testing environments and engaged in dangerous or unlawful activity; it was a call for legislation, not an enforcement action against a company.
New York Attorney General Letitia James issued an industry alert urging workers with knowledge of unsafe or illegal conduct in AI development to file confidential complaints through the OAG's secure whistleblower portal. The alert cites the OAG's monitoring of cybersecurity, economic, and other safety risks from emerging AI, and highlights the RAISE Act (effective January 1, 2027), which will require large AI developers to publicly disclose safety measures and report security incidents, as well as the SHIELD Act's data security requirements. No company was named, charged, or penalized; the alert signals impending OAG enforcement authority over AI developers.
New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' private genetic data. The October 2023 data breach exposed sensitive genetic information of 6.9 million consumers, including 305,245 in New York, with some data published for sale on the dark web. The settlement includes monetary penalties and new data protection requirements for the company and its successor, 23andMe Research Institute.
$18.0M
New York Attorney General Letitia James and a bipartisan coalition of 45 other attorneys general secured $45 million from Block, Inc., the company behind Cash App, for misleading users about the platform's security and failing to protect them from fraud. The settlement requires Block to implement changes including maintaining live customer support, stopping misleading marketing, and fulfilling legal obligations to investigate fraud claims and reimburse users for unauthorized transactions.
$45.0M
New York, California, and Connecticut attorneys general reached a $5.1 million settlement with educational technology company Illuminate Education, Inc. for failing to protect student data, resulting in a 2022 breach exposing millions of students’ personal information. The investigation found Illuminate failed to implement basic security measures including data encryption, suspicious activity monitoring, and proper decommissioning of inactive user accounts, and did not delete student data when required by contracts. Illuminate must pay the penalty and implement enhanced data security measures including a comprehensive information security program, encryption of student data, and annual notice to schools about data collection and deletion options.
$5.1M
New York Attorney General Letitia James secured a $450,000 settlement from three companies distributing eufy-branded home security cameras for failing to implement adequate data security measures. The companies’ cameras had unencrypted video streams accessible without authentication, exposing private consumer footage. The settlement requires the companies to implement stronger security protocols, including encryption, vulnerability testing, and a comprehensive information security program.
$450K
Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.
$49.5M
All data sourced from official government enforcement pages.