Reflex Cyber Risk Management™ solution
how vintage wiretap laws are fueling a new AI privacy wave

In our ongoing series, we present expert knowledge from our exclusive cyber risk management partner network. In this first installment, Ben Goodman, CEO of CyRisk, discusses the evolution of privacy litigation in the digital age, the role of artificial intelligence (AI), and steps brokers can take to support their cyber clients.
Privacy law in the United States did not begin with the internet. The framework brokers are now wrestling with traces back to the Cold War. In 1967, against a backdrop of expanding federal surveillance and growing public unease about wiretaps, California passed the California Invasion of Privacy Act (CIPA). That same year, the Supreme Court decided Katz v. United States1, establishing that the Fourth Amendment protects people rather than places. The federal Wiretap Act followed in 1968. These statutes were written for rotary phones and reel-to-reel tapes, but they shared a foundational premise: A person on either end of a communication has the right to know who else is listening.
That premise sat largely undisturbed for decades. The Electronic Communications Privacy Act of 1986 updated wiretap law for digital transmissions. The Fair Credit Reporting Act (FCRA), Health Insurance Portability and Accountability Act (HIPAA), Children’s Online Privacy Protection Act (COPPA), and a patchwork of state laws addressed specific data types. None of it anticipated a world in which every page load could trigger a silent transfer of user data to a third party. None of it anticipated machine learning systems that could identify, profile, and microtarget an individual from digital fragments that, by themselves, look anonymous. And none of that early legislation ever envisioned a data broker industry that would generate between $300 billion and $400 billion each year.
Plaintiffs’ attorneys figured this out before most defendants did. Beginning around 2022, we started to see class action lawyers reapplying and expanding the intent of the old wiretap statutes and asking a simple question: If a tracking pixel intercepts a website visitor’s communications with the site owner and transmits the content to Meta, Google, or TikTok, is that really any different from a third party tapping a phone line? Courts have increasingly said no, it is not. CIPA’s $5,000 per violation statutory damages, multiplied across millions of visitors, have turned ordinary website analytics into nine-figure exposures. Many of these disputes have been characterized as shakedown lawsuits that impact small businesses, community nonprofits, schools, healthcare providers, and local governments who are dragged into expensive legal fights that center around a statute that never contemplated governing website configurations.
The targets have expanded with the technology. Camplisson et al. v. Adidas America, Inc. tested whether tracking pixels qualify as “pen registers” and “trap and trace” devices under CIPA § 638.512. Frasco v. Flo Health, Inc. applied the same logic to a software development kit (SDK) that captured reproductive health inputs and sent them to Meta in real time3. AI notetakers that join meetings without all-party consent are the next wave with suits against Otter.ai, Fireflies.ai, Microsoft, and others working their way through the courts. Some of these class action suits are alleging Biometric Information Privacy Act (BIPA) violations, as voiceprints are considered biometric data. Session replay tools, device fingerprinting, and chatbot transcripts that are quietly fed back into model training have also been targeted.
Generative AI brings every one of these issues into sharper focus. Models trained on scraped personal data raise wrongful collection questions at the input layer. Models that output personalized advertising, employment screening, or pricing decisions raise discrimination and microtargeting questions at the output layer. A separate trap has opened around privilege. In the U.S. v. Heppner ruling, the court found that exchanges between counsel and a general purpose large language model (LLM) did not carry attorney-client privilege. If a client’s defense team uses an AI tool to draft strategy or summarize evidence, that work product can become discoverable.
For brokers, the practical issue is that most clients still think of cyber insurance as a breach product. Certainly, this is the headline benefit, but as we all know, the coverage offered by most cyber policies is significantly broader. The most litigated exposure today often has nothing to do with a breach. It is the chatbot the marketing team installed last quarter, the SDK embedded in the mobile app, the analytics pixel on the checkout page, the notetaker quietly transcribing client meetings. None of those involve an intruder. All of them can produce regulatory actions and/or class action lawsuits.
With all this in mind, below are a few specific items brokers can put in front of clients now to protect themselves from these wiretapping lawsuits — recognizing that the clients who are being targeted with these wiretapping lawsuits likely need added guidance. Separately, the California legislature is focusing on a legislative fix that is designed to prevent plaintiff’s attorneys from misusing and expanding the 1967 wire-tapping law and to stop this litigation from being initiated.
Protecting insureds from lawsuits
Current inventory of trackers with consent mechanism
Raise the consent bar
Treat AI vendors as a distinct procurement category
Document human-in-the-loop process
Separate coverages
- Ask the client to produce a current inventory of every pixel, SDK, and third-party tracker in production on internet-facing web properties, with the consent mechanism associated with each. If they cannot produce it quickly and easily, that itself should be a real concern. The reality is, marketing and product teams routinely add tags without legal review. Run a CyRisk Privacy Scan to reveal what is actually firing on the client’s web properties.
- Raise the consent bar. Courts have made clear that a privacy policy linked in a footer is not notice. Affirmative, conspicuous consent, a clickwrap box checked before the tracking fires, is the defensible posture. Cookie banners that allow tracking to begin while the user reads them do not count. And make sure your client has verified that user choices are being honored and that trackers are not firing after consent is withheld.
- Treat AI vendors as a distinct procurement category. The standard SaaS agreement does not cover the AI issues. Encourage clients to insist on specific contractual provisions: clear data ownership of inputs and outputs, an explicit prohibition on using customer data to train derived models, and liability caps set at a meaningful multiple of contract value. Uncapped indemnities flowing the wrong way are an underwriting red flag.
- Push clients to document a human-in-the-loop (HITL) process for any AI output that drives a consequential decision. Hiring, pricing, claims, credit, and clinical contexts all qualify. Documenting these processes along with real transparency in the decision-making process will make the difference between a defensible record and a regulatory finding.
- Separate the coverage conversation. Wrongful collection sits in cyber. AI performance failures, including hallucinations, model regressions, and agentic actions that cause financial harm, sit in tech E&O. A client running an AI-heavy operation with only one is underinsured, and the gap usually shows up at the worst possible moment.
The throughline from 1967 to now is one of expanded privacy risk. The technology has changed, and the law is being misapplied to ensnare businesses. Until there is a legislative fix, brokers who can guide clients with specific operational and contractual direction will help their clients stay out of that trap.
Munich Re Specialty – North America’s Reflex™ Cyber Risk Management solution
Our experts
