Morrison Foerster’s State and Local Government Task Force is pleased to provide our quarterly newsletter summarizing noteworthy developments from state attorneys general (“State AGs”), local government agencies, and legislative bodies across the country, with links to primary sources. This quarter’s topics include the following:
1. State AGs Escalate Jurisdictional Fight over Sports Prediction Markets
2. State AGs Push FCC to Strengthen Know-Your-Customer Rules for Voice Service Providers
3. Texas AG Sues Netflix Over Alleged Collection and Monetization of User Data
4. New York Legislature Passes Bill Banning Surveillance Pricing
5. California Launches Consumer-Focused Cabinet Agency Under Rohit Chopra
On April 30, 2026, a bipartisan coalition of 41 State AGs [1] argued to the Commodity Futures Trading Commission (CFTC) that states should have exclusive authority to regulate sports-related event contracts. Specifically, the State AGs filed a formal comment with the CFTC’s rulemaking process, claiming that prediction-market platforms offer contracts on game outcomes, point spreads, and player statistics that essentially function as unregulated sportsbooks and that regulation of such activity falls within the states’ traditional authority over gambling.
The State AGs asserted that by treating sports-event contracts as federally regulated financial products, platforms could bypass state licensing, age restrictions, responsible-gaming safeguards, consumer protections, and tax requirements. The State AGs asked the CFTC to recognize that sports-related contracts constitute entertainment-based gambling rather than instruments for managing commercial or financial risk and to preserve state authority to regulate or prohibit them.
Notwithstanding the CFTC’s proposed framework in June 2026 for evaluating its jurisdiction over event contracts involving gaming and other activities, New York Attorney General Letitia James sued KalshiEX, LLC (“Kalshi”) on July 31, 2026, alleging that the platform operated an illegal, unlicensed gambling business and made sports wagering available to New Yorkers below the state’s legal gambling age of 21. The suit seeks an order halting the alleged conduct and imposing civil penalties, forfeiture of gains, and restitution. On August 11, 2026, the CFTC—citing its exclusive jurisdiction over designated contract markets granted by the Commodity Exchange Act (CEA)[2]—ordered Kalshi to continue operating under normal conditions, notwithstanding the New York AG’s lawsuit. In separate ongoing litigation, a Washington state court issued an amended preliminary injunction blocking Kalshi from offering event contracts in many prediction market categories, including sports and holding that “the CEA does not preempt Washington State gambling law.”
These developments reflect an increasingly direct conflict between federal regulation of event contracts and state gambling enforcement. Prediction-market operators and companies partnering with those platforms should consult with counsel to assess compliance with applicable state gambling, licensing, and consumer-protection laws in each jurisdiction where their products are accessible.
On July 27, 2026, a coalition of 50 State AGs submitted reply comments urging the Federal Communications Commission (FCC) to strengthen “Know-Your-Customer” (KYC) requirements for originating voice service providers. The State AGs characterized originating providers as the principal gatekeepers to the U.S. communications network and argued that stronger customer-screening requirements could prevent illegal calls from entering the network. According to the coalition, Americans received more than 29.6 billion scam robocalls and text messages and lost nearly $2 billion to related scams in 2025.
The filing builds on earlier multistate efforts to strengthen the FCC’s anti-robocall framework. As discussed in our Q1 2025 newsletter, a bipartisan coalition of 47 State AGs previously supported reforms to the FCC’s Robocall Mitigation Database intended to improve the accuracy of providers’ filings and make it more difficult for bad actors to exploit deficient or misleading database entries. The latest comments move the State AGs’ focus further upstream—from ensuring the accuracy of regulatory filings to requiring substantive due diligence when providers onboard and retain customers. Originating providers therefore should expect continued scrutiny of their customer-verification procedures, documentation of customers’ anticipated calling activity, ongoing traffic monitoring, and responses to indicators of potentially unlawful calls.
On May 11, 2026, Texas Attorney General Ken Paxton sued Netflix, Inc. under the Texas Deceptive Trade Practices Act (DTPA), alleging that the company collected and monetized Texans’ personal data without adequate knowledge or consent. The complaint alleges that Netflix tracked viewing habits, preferences, devices, household networks, application usage, and other behavioral information associated with adult accounts and children’s profiles.
The Texas AG further alleges in its lawsuit that Netflix disclosed user information to commercial data brokers and advertising-technology companies, which could combine it with data from other sources to create consumer profiles. The lawsuit also challenges autoplay and other platform features as intentionally designed to increase engagement and data collection, particularly among younger users. As a remedy, the lawsuit seeks an order stopping the alleged collection and disclosure, requiring Netflix to disable autoplay by default on children’s profiles, and imposing civil penalties and other injunctive relief.
This matter highlights the Texas AG’s continued enforcement campaign targeting the collection, use, disclosure, and security of consumer data, including data generated by entertainment and communications products. Companies (especially those with products or platforms accessible to minors) should review whether product interfaces, privacy notices, consent mechanisms, and public claims accurately describe actual data flows and platform-design practices.
In early June 2026, the New York State Legislature passed the One Fair Price Act (S.8623B/A.9349B), which prohibits surveillance pricing, and was signed into law by Governor Kathy Hochul on June 17, 2026. The bill defines surveillance pricing as using personal data in an algorithm to offer different prices to different consumers for the same goods or services.
The law, which will go into effect in December 2026, prohibits entities and service providers from setting or adjusting a reference price or consumer price using surveillance pricing. It also prohibits collecting, using, selling, retaining, sharing for valuable consideration, or disclosing personal data for the purpose of facilitating surveillance pricing. The legislation does not prohibit dynamic pricing based on nonpersonal factors.
The law will be enforced by the New York AG and authorizes that office to seek injunctive relief, restitution, and damages, as well as civil penalties of up to $5,000 for a first violation and $20,000 for each subsequent violation.
The law reflects growing state scrutiny of algorithmic pricing and the use of consumer data in commercial decision-making. Businesses that use pricing vendors, personalization tools, loyalty programs, or consumer profiles should identify the data inputs used to set reference prices and discounts and assess whether service-provider arrangements could expose them to liability under the new restrictions.
On July 1, 2026, California Governor Gavin Newsom swore in former Consumer Financial Protection Bureau Director Rohit Chopra as the inaugural secretary of the newly established Business and Consumer Services Agency (BCSA). The cabinet-level agency was created through a government reorganization and is intended to improve coordination and enforcement across sectors, including financial services, health care, real estate, retail, hospitality, agriculture, and higher education.
Chopra previously served as Director of the Consumer Financial Protection Bureau (CFPB) from 2021 to 2025 and as a Commissioner of the Federal Trade Commission. The Newsom administration expressly framed the BCSA as a state-level backstop in light of its view that federal consumer-protection activity has receded. Subsequently, on August 5, 2026, the Newsom administration appointed Jennifer Song as Deputy Secretary and Special Counsel for Enforcement at BCSA. Song previously served as Advisor and Counsel to Director Chopra at the CFPB from 2021 to 2025.
This new agency and these key new appointments may facilitate more coordinated investigations and enforcement across California agencies with overlapping jurisdiction in areas such as financial products, professional licensing, privacy, health care, and technology, including, for example, the Department of Financial Protection and Innovation and the California Privacy Protection Agency. Companies operating in California should monitor BCSA’s activities and prepare for consumer protection matters that involve multiple departments or combine licensing, supervisory, and enforcement approaches.
On July 27, 2026, New York AG Letitia James submitted written testimony to the U.S. Senate Committee on Homeland Security and Governmental Affairs’ Permanent Subcommittee on Investigations urging Congress to impose stronger safeguards on cryptocurrency platforms. Attorney General James also criticized the proposed Digital Asset Market CLARITY Act, arguing that certain provisions would preempt state regulation and restrict state and local authorities’ ability to investigate cryptocurrency fraud and hold platforms accountable. According to the testimony, cryptocurrency-related complaints to the New York Attorney General have tripled over the past three years and reported cryptocurrency scam losses in New York have totaled nearly $500 million over the past five years.
Attorney General James pressed Congress to require cryptocurrency platforms to comply with anti-money-laundering, know-your-customer, and cybersecurity requirements; monitor transactions for manipulation and other anomalous activity; and prevent untraceable cryptocurrency, including assets routed through money-laundering mixers, from being converted into U.S. dollars. She also called for legislation preserving the application of existing state money-transmission, commodities, and securities laws and imposing financial liability on platforms and intermediaries that fail to protect consumers from fraud, similar to the liability framework under the Electronic Fund Transfer Act.
The New York AG’s testimony reflects New York’s resistance to federal legislation that would displace state consumer-protection and financial-enforcement authority. It also signals that the New York AG is likely to continue scrutinizing cryptocurrency companies’ fraud controls, transaction-monitoring systems, cybersecurity practices, and protections for customers who lose funds through scams, regardless of whether Congress establishes a new federal regulatory framework.
[1] The signatories were the Attorneys General of Alabama, Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, the District of Columbia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Nebraska, Nevada, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Utah, Vermont, Virginia, and Wisconsin.
[2] 7 U.S.C. § 2(a)(1)(A).