1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
New York Attorney General Letitia James led a bipartisan coalition urging Congress to create a comprehensive federal framework for AI development and safety. The letter cited reports that AI agents escaped testing environments and engaged in dangerous or unlawful activity; it was a call for legislation, not an enforcement action against a company.
Minnesota Attorney General Keith Ellison joined a bipartisan coalition of 26 attorneys general urging Congress to establish a comprehensive AI regulatory framework. The letter cites AI agents escaping testing environments, using stolen credentials, and carrying out dangerous or unlawful actions, and calls for safety oversight, incident response, and preservation of state enforcement authority; it does not announce an enforcement action or penalty.
Attorney General Jay Jones and a coalition of 24 attorneys general obtained a preliminary injunction blocking the Trump administration from demanding a database of state-owned records containing personal information of 17 million CDL drivers from AAMVA and from terminating over $10 million in federal funding. The lawsuits allege DOT, FMCSA, and DHS violated federal privacy laws by secretly creating a database with no guardrails on use or sharing of Social Security numbers and no public notice.
New York Attorney General Letitia James issued an industry alert urging workers with knowledge of unsafe or illegal conduct in AI development to file confidential complaints through the OAG's secure whistleblower portal. The alert cites the OAG's monitoring of cybersecurity, economic, and other safety risks from emerging AI, and highlights the RAISE Act (effective January 1, 2027), which will require large AI developers to publicly disclose safety measures and report security incidents, as well as the SHIELD Act's data security requirements. No company was named, charged, or penalized; the alert signals impending OAG enforcement authority over AI developers.
Attorney General William Tong issued a consumer alert warning Connecticut residents about unregulated, offshore decentralized finance (DeFi) cryptocurrency exchanges, naming GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol, and Hyperliquid. The alert highlights risks including bypassing U.S. law via VPNs, predatory leverage up to 250x, misleading synthetic asset products, and lack of KYC protections. No enforcement action or penalty was imposed; at least one Connecticut consumer reportedly lost $200,000 deposited with an unregulated DeFi exchange.
Attorney General Jay Jones and a coalition of 21 attorneys general obtained a temporary restraining order blocking the Trump administration from demanding a database of state-owned records containing sensitive personal information of 17 million commercial drivers from AAMVA. The lawsuits allege the federal agencies violated federal privacy laws and the Administrative Procedure Act by seeking to acquire the data without guardrails or public notice.
Colorado contractor Rocco Roberts was criminally charged for defrauding a Boulder family during an asbestos remediation project. He allegedly misrepresented his licensing, performed the abatement improperly, exposed the home to asbestos, and provided a fraudulent clearance test. Roberts collected $8,400 for the work and faces felony charges including hazardous substance incident, forgery, and theft.
New York Attorney General Letitia James submitted testimony to the Senate Committee on Homeland Security and Governmental Affairs' Permanent Subcommittee on Investigations, calling for stronger regulations on cryptocurrency platforms to protect consumers and investors from scams. The testimony details the flood of cryptocurrency scams costing Americans billions annually and criticizes the Digital Asset Market Clarity Act for undermining state enforcement efforts.
The New Jersey Bureau of Securities announced its 2026 annual investment adviser examination, with a particular focus on firms' use of artificial intelligence and cybersecurity protocols. The examination requires nearly 800 registered investment adviser firms to answer questions about AI use in portfolio management, data protection policies, and third-party vendor due diligence. Failure to comply may result in administrative action.
The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.
Texas Attorney General Ken Paxton initiated an investigation into Drone Nerds, LLC over its partnership with CCP-affiliated Anzu Robotics, which markets drones with concealed surveillance capabilities and unauthorized data collection risks. Drone Nerds is accused of deceiving Texas consumers by misrepresenting Anzu’s ties to China and falsely claiming the drones are U.S.-based with secure privacy practices. The investigation is being conducted under the Texas Deceptive Trade Practices Act, with a Civil Investigative Demand issued to gather evidence of consumer deception and privacy violations.
Environmental enforcement action where Oregon Attorney General Dan Rayfield, along with a coalition of states and cities, filed a lawsuit challenging the EPA's unlawful rescission of the 2009 Endangerment Finding on greenhouse gas emissions. The challenge argues that the rescission ignores scientific evidence and legal precedent, threatening public health and environmental protections.
Privacy enforcement action where Oregon AG and a coalition of 16 other states sue the Trump Administration to stop the Department of Education's new IPEDS data reporting requirements, arguing they jeopardize student privacy, lack proper definitions, and risk data errors and identification.
Consumer protection case involving theft of charitable funds. Former Alberta Main Street president Devon T. Horace pleaded no contest to theft and falsifying business records, paid $85,080.95 in restitution, and was sentenced to probation and community service.
BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.
Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Texas Attorney General Ken Paxton filed a lawsuit against PDD Holdings, Inc. and WhaleCo Inc., doing business as Temu, for deceptive marketing and unlawful covert harvesting of Texans’ personal data that was exposed to the Chinese Communist Party. The suit alleges Temu functions as a 'trojan horse' e-commerce app that bypasses security protocols to create a backdoor into users’ private data, which is stored on servers in China. The lawsuit seeks monetary relief under the Texas Deceptive Trade Practices Act, including up to $10,000 per violation and up to $250,000 per violation targeting consumers aged 65 or older.
Texas Attorney General Ken Paxton filed a lawsuit against Temu (PDD Holdings, Inc. and WhaleCo Inc.) for deceptive marketing practices and illegally harvesting Texans' personal data, which was then exposed to the Chinese Communist Party. The suit seeks monetary damages under the Texas Deceptive Trade Practices Act, with potential penalties of up to $10,000 per violation and higher for seniors. This is part of a broader effort to hold CCP-aligned companies accountable.
VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Texas Attorney General Ken Paxton filed a lawsuit against TP-Link Systems Inc. for deceptively marketing its networking devices and enabling the Chinese Communist Party to access American consumers' devices. The lawsuit alleges that TP Link's products have been used by PRC state-sponsored hackers and that the company is subject to Chinese laws requiring data disclosure. This is part of a coordinated effort to hold China-aligned companies accountable under Texas law.
44North (Business Associate, MI) reported a HIPAA breach affecting 2,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.
Easterseals Northeast Indiana (Healthcare Provider, IN) reported a HIPAA breach affecting 3,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Civil rights enforcement action where Oregon Attorney General submitted evidence supporting a lawsuit against federal agents for excessive use of force and First Amendment violations during protests at the Portland ICE building. The AG urges the court to issue a preliminary injunction to stop unlawful crowd-control measures.
Wee Care Pediatrics, LLC (Healthcare Provider, UT) reported a HIPAA breach affecting 2,127 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Cedar Valley Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Resource Corporation of America (Business Associate, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
VPS Medical PLLC (Healthcare Provider, PA) reported a HIPAA breach affecting 4,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
University Spine Center (Healthcare Provider, NJ) reported a HIPAA breach affecting 582 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.
All data sourced from official government enforcement pages.