Reflex Cyber Risk Management™ solution

Cyber and technology
A litigious blast from the past:
how vintage wiretap laws are fueling a new AI privacy wave
A person in a suit typing on a laptop with digital icons representing law, AI, and security above the keyboard.

In our ongoing series, we present expert knowledge from our exclusive cyber risk management partner network. In this first installment, Ben Goodman, CEO of CyRisk, discusses the evolution of privacy litigation in the digital age, the role of artificial intelligence (AI), and steps brokers can take to support their cyber clients.

Privacy law in the United States did not begin with the internet. The framework brokers are now wrestling with traces back to the Cold War. In 1967, against a backdrop of expanding federal surveillance and growing public unease about wiretaps, California passed the California Invasion of Privacy Act (CIPA). That same year, the Supreme Court decided Katz v. United States1, establishing that the Fourth Amendment protects people rather than places. The federal Wiretap Act followed in 1968. These statutes were written for rotary phones and reel-to-reel tapes, but they shared a foundational premise: A person on either end of a communication has the right to know who else is listening.

That premise sat largely undisturbed for decades. The Electronic Communications Privacy Act of 1986 updated wiretap law for digital transmissions. The Fair Credit Reporting Act (FCRA), Health Insurance Portability and Accountability Act (HIPAA), Children’s Online Privacy Protection Act (COPPA), and a patchwork of state laws addressed specific data types. None of it anticipated a world in which every page load could trigger a silent transfer of user data to a third party. None of it anticipated machine learning systems that could identify, profile, and microtarget an individual from digital fragments that, by themselves, look anonymous. And none of that early legislation ever envisioned a data broker industry that would generate between $300 billion and $400 billion each year.

Plaintiffs’ attorneys figured this out before most defendants did. Beginning around 2022, we started to see class action lawyers reapplying and expanding the intent of the old wiretap statutes and asking a simple question: If a tracking pixel intercepts a website visitor’s communications with the site owner and transmits the content to Meta, Google, or TikTok, is that really any different from a third party tapping a phone line? Courts have increasingly said no, it is not. CIPA’s $5,000 per violation statutory damages, multiplied across millions of visitors, have turned ordinary website analytics into nine-figure exposures. Many of these disputes have been characterized as shakedown lawsuits that impact small businesses, community nonprofits, schools, healthcare providers, and local governments who are dragged into expensive legal fights that center around a statute that never contemplated governing website configurations. 

The targets have expanded with the technology. Camplisson et al. v. Adidas America, Inc. tested whether tracking pixels qualify as “pen registers” and “trap and trace” devices under CIPA § 638.512. Frasco v. Flo Health, Inc. applied the same logic to a software development kit (SDK) that captured reproductive health inputs and sent them to Meta in real time3. AI notetakers that join meetings without all-party consent are the next wave with suits against Otter.ai, Fireflies.ai, Microsoft, and others working their way through the courts. Some of these class action suits are alleging Biometric Information Privacy Act (BIPA) violations, as voiceprints are considered biometric data. Session replay tools, device fingerprinting, and chatbot transcripts that are quietly fed back into model training have also been targeted.

Generative AI brings every one of these issues into sharper focus. Models trained on scraped personal data raise wrongful collection questions at the input layer. Models that output personalized advertising, employment screening, or pricing decisions raise discrimination and microtargeting questions at the output layer. A separate trap has opened around privilege. In the U.S. v. Heppner ruling, the court found that exchanges between counsel and a general purpose large language model (LLM) did not carry attorney-client privilege. If a client’s defense team uses an AI tool to draft strategy or summarize evidence, that work product can become discoverable.

For brokers, the practical issue is that most clients still think of cyber insurance as a breach product. Certainly, this is the headline benefit, but as we all know, the coverage offered by most cyber policies is significantly broader. The most litigated exposure today often has nothing to do with a breach. It is the chatbot the marketing team installed last quarter, the SDK embedded in the mobile app, the analytics pixel on the checkout page, the notetaker quietly transcribing client meetings. None of those involve an intruder. All of them can produce regulatory actions and/or class action lawsuits.

With all this in mind, below are a few specific items brokers can put in front of clients now to protect themselves from these wiretapping lawsuits — recognizing that the clients who are being targeted with these wiretapping lawsuits likely need added guidance. Separately, the California legislature is focusing on a legislative fix that is designed to prevent plaintiff’s attorneys from misusing and expanding the 1967 wire-tapping law and to stop this litigation from being initiated.

Protecting insureds from lawsuits

Current inventory of trackers with consent mechanism

Raise the consent bar

Treat AI vendors as a distinct procurement category

Document human-in-the-loop process

Separate coverages

  1. Ask the client to produce a current inventory of every pixel, SDK, and third-party tracker in production on internet-facing web properties, with the consent mechanism associated with each. If they cannot produce it quickly and easily, that itself should be a real concern. The reality is, marketing and product teams routinely add tags without legal review. Run a CyRisk Privacy Scan to reveal what is actually firing on the client’s web properties.
  2. Raise the consent bar. Courts have made clear that a privacy policy linked in a footer is not notice. Affirmative, conspicuous consent, a clickwrap box checked before the tracking fires, is the defensible posture. Cookie banners that allow tracking to begin while the user reads them do not count. And make sure your client has verified that user choices are being honored and that trackers are not firing after consent is withheld.
  3. Treat AI vendors as a distinct procurement category. The standard SaaS agreement does not cover the AI issues. Encourage clients to insist on specific contractual provisions: clear data ownership of inputs and outputs, an explicit prohibition on using customer data to train derived models, and liability caps set at a meaningful multiple of contract value. Uncapped indemnities flowing the wrong way are an underwriting red flag.
  4. Push clients to document a human-in-the-loop (HITL) process for any AI output that drives a consequential decision. Hiring, pricing, claims, credit, and clinical contexts all qualify. Documenting these processes along with real transparency in the decision-making process will make the difference between a defensible record and a regulatory finding.
  5. Separate the coverage conversation. Wrongful collection sits in cyber. AI performance failures, including hallucinations, model regressions, and agentic actions that cause financial harm, sit in tech E&O. A client running an AI-heavy operation with only one is underinsured, and the gap usually shows up at the worst possible moment.

The throughline from 1967 to now is one of expanded privacy risk. The technology has changed, and the law is being misapplied to ensnare businesses. Until there is a legislative fix, brokers who can guide clients with specific operational and contractual direction will help their clients stay out of that trap.

1Katz v. United States, 389 U.S. 347 (1967). 22025 WL 3228949 (S.D. Cal. Nov. 18, 2025). 3No. 3:21-cv-00757-JD (N.D. Cal. 2025). Disclaimer: The views, thoughts, and opinions expressed in this article belong solely to the individual experts interviewed and do not necessarily reflect the official policy, position, or endorsement of Munich Re Specialty. This content is provided for informational and educational purposes only. Cyber risk landscapes evolve rapidly; readers should not rely on this information as a substitute for professional legal, technical, or financial consultation tailored to their specific organizational needs.
Ben Goodman is the founder and CEO of CyRisk Inc., where he leads the development of cyber, privacy, and AI risk analytics solutions used by insurance companies and their policyholders, drawing on more than 25 years of experience in technology strategy, risk management, cybersecurity, and compliance. A recognized thought leader on emerging risk, he has served on leading actuarial and industry panels, published award-winning work on cyber risk, and regularly advises insurers and corporate executives on managing technology-driven threats and opportunities.  
Ben Goodman
© tbd

1 of

Munich Re Specialty – North America’s Reflex™ Cyber Risk Management solution

Our experts

Steve Pacheco
Steve Pacheco
US Head of Cyber & Tech E&O
Worldwide
Munich Re Specialty – North America
Quinn Barbeito
Quinn Barbeito
Underwriter, Cyber Northeast
Munich Re Specialty – North America
Munich Re Specialty – North America products and services are offered by and provided through insurance companies and producers/surplus lines brokers that are eligible or licensed in accordance with the laws and regulations of individual jurisdictions. Products and services are not available in every, and may vary by, jurisdiction. The information provided on this site is intended as general information only and does not constitute an offer to sell or a solicitation to purchase insurance or non-insurance products and services. Please be aware that the insurance policy and not any information provided on this site will form the contract between the parties thereto, and will govern in all cases. Munich Re Specialty – North America’s insurance products and services in the United States, Canada, and the United Kingdom are underwritten and provided by or through one or more of the insurers, producers/surplus lines brokers that are members of the Munich Re Group identified below. Each company is financially responsible only for insurance policies it has issued.
    Track image

    0:00
    0:00