View as Webpage

Volume 7, Issue 7

Welcome


Welcome to our seventh issue of 2026 of Decoded -- our technology law insights e-newsletter.


In this issue, we bring you a variety of technology topics, including artificial intelligence and ROI; utilizing mobile apps as medical devices; Coca-Cola's ransomware issue and ransomware's ecosystem; incorporating cyber risk; Apple's biometrics case; the impact of diesel engines on a Virginia data center; and data centers and their rules and regulations, including how the EPA has weighed in on the issue.


We are very pleased to announce that Eric W. Iskra will begin his one-year term as Chair of the American Bar Association’s Section of Labor and Employment Law on August 1. His election to one of the ABA’s most prominent leadership positions is a testament to his thoughtful leadership abilities, his legal acumen, and his career-long dedication to advancing the practice of labor and employment law. Congratulations! Click here to learn more.



As always, thank you for reading.


Nicholas P. Mooney II, Co-Editor of Decoded; Chair of Spilman's Technology Practice Group; Co-Chair of the Cybersecurity & Data Protection Practice Group; and Co-Chair of the Artificial Intelligence Law Practice Group


and


Alexander L. Turner, Co-Editor of Decoded and Co-Chair of the Cybersecurity & Data Protection Practice Group

AI ROI is Rising, but Not Where Companies Expected

“Enterprises reported that AI is helping them find business insights and interact with customers, but not necessarily save money or time, an SAP survey found.”

 

Why this is important: Most organizations are expanding their use of artificial intelligence but continue to struggle with measuring its return on investment, according to a new SAP study conducted with Oxford Economics. Based on a survey of 2,600 executives across 13 countries, the report found that 69 percent of respondents are satisfied with the ROI of their AI initiatives. However, nearly as many executives remain unconvinced that their AI deployments are delivering their full potential, reflecting the ongoing difficulty of defining and quantifying AI’s business value.

 

Rather than producing the greatest gains through cost reduction or productivity improvements, AI is delivering its strongest benefits by helping employees generate insights, make better decisions and improve customer interactions. While efficiency gains remain an important objective, organizations increasingly recognize that AI’s value often comes through enhanced decision-making and business processes rather than direct cost savings.

 

AI adoption continues to accelerate. On average, organizations now use AI to assist with 30 percent of their tasks, up from approximately one-quarter last year, and respondents expect that figure to reach 48 percent within the next two years. Despite this growth, relatively few companies have deployed AI across entire business processes and most organizations remain focused on isolated or task-specific applications.

 

Investment in AI is also rising rapidly. U.S. companies surveyed reported spending an average of $37.2 million on AI this year and expect that investment to increase by 46 percent over the next two years. They reported generating an average of $9.9 million in ROI this year and anticipate that figure will grow to $26.5 million as deployments mature and become more integrated.

 

The study concludes that long-term AI success will depend not only on increased investment but also on strong governance, high-quality data, workforce skills and board-level understanding of AI. Organizations that strategically prioritize AI initiatives capable of transforming core business processes, while carefully measuring outcomes and managing resources, are expected to achieve the strongest returns as AI adoption continues to mature. --- Shane P. Riley

As Mobile Apps Become Medical Devices, Security Becomes Patient Safety

“A recent report from Zscaler shows that the healthcare industry experienced a 224% increase in mobile attacks last year, and a 2025 Ponemon Institute survey showed that insecure mobile healthcare apps are the top cybersecurity concern in the industry (cited by 55% of respondents).”

 

Why this is important: As mobile health (mHealth) apps increasingly function as medical devices, cybersecurity is becoming a core patient safety issue rather than just an IT concern. The global mobile healthcare app market is projected to grow from $114.2 billion in 2024 to more than $1 trillion by 2030, driven by telehealth, AI-enabled health tools, remote monitoring, patient portals, and wellness applications. The explosive market growth is driven by (1) expansion of hybrid and remote care models, especially for underserved and rural communities; (2) advances in AI-powered mobile health technologies for chronic disease management and patient engagement; and (3) growing consumer preference for managing appointments, prescriptions, and medical records through mobile apps. But with mHealth app growth comes increasing cybersecurity risks. Over the previous year, there has been a reported 224 percent increase in mobile attacks against the healthcare sector, but the need and the use of these applications is only going to increase over time, especially in rural communities. Healthcare organizations and developers should treat mobile app security as a fundamental patient safety requirement, integrating strong security practices throughout the software lifecycle rather than adding them as an afterthought. The Federal Trade Commission (FTC) also recommends that mHealth applications be designed with security in mind from the outset, with appropriate security measures testing prior to launch. --- Jennifer A. Baker

Ransomware Attack Forces Coca-Cola to Suspend US Production at Dairy Unit

“The beverage company is still working to determine the full scope of the breach at its Fairlife business.”

 

Why this is important: Coca-Cola disclosed on July 16 that a ransomware attack forced its Fairlife dairy unit to suspend production at its U.S. facilities. The company said it was still working to determine the full scope of the attack and its impact on the business, though it stated the incident had not affected product quality or safety. The Anubis ransomware group later claimed credit, listing Coca-Cola and Fairlife on its leak site and claiming to have stolen 1 TB of confidential data, then threatening to publish it unless a ransom was paid.

 

By July 27, Coca-Cola confirmed that the incident involved the taking of certain data, though it has not shared further detail on what was affected, and said a majority of production had resumed at its four U.S. facilities. The company added that based on available information, it does not believe the incident is likely to have a material impact on its financial results.

 

This incident is a reminder that ransomware risk extends well beyond IT downtime. A production halt at a major manufacturer shows how quickly an attack can disrupt physical operations and supply chains, not just data systems, and the confirmed data theft raises the usual chain of obligations: breach notification, regulatory disclosure, and downstream contract and vendor exposure.

 

Clients in manufacturing, food and beverage, or any operations dependent on connected production systems should treat this as a prompt to revisit incident response plans that account for both operational and data impact, and to confirm cyber insurance and vendor contracts address business interruption alongside data breach costs. --- James E. Dunlap, Chief Information Officer, Spilman Thomas & Battle

Ransomware Ecosystem Grows, but ‘Four-Headed Monster’ Dominates

“AI is helping hackers, a new report finds, but mostly by automating very human behaviors.”

 

Why this is important: The number of ransomware attacks is rising quarter over quarter in 2026. The news may not be unexpected, but it nonetheless is concerning. While the number of ransomware attacks continues to climb, they aren’t being carried out by an equally increasing number of groups. The number of threat actor groups is increasing. However, in Q2 2026, 40 percent of all attacks were carried out by the few most prolific groups. Qilin, The Gentlemen, Akira, and DragonForce comprise what one commentator calls the “four-headed monster” of high-volume ransomware groups. 

 

These groups are employing AI in their attacks, but they’re using it in mundane ways. While some have been expecting to see AI-based attacks become the norm, reality is playing out differently. Threat actor groups are using AI to handle repeatable tasks, like reviewing the massive troves of data they’ve stolen. They’re using AI exactly like we do, to quickly review and summarize large quantities of information. This means the groups can quickly understand exactly what data they have and, based on what the AI agent reports, negotiate a ransom from an informed position. --- Nicholas P. Mooney II

US Enterprises Incorporate Cyber Risk into Larger Strategic Focus

“The rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact.”

 

Why this is important: Growing adoption of artificial intelligence and cloud technologies is prompting large enterprises to fundamentally rethink how they manage business risk, with cybersecurity increasingly viewed as a strategic business function rather than solely an IT responsibility. According to industry experts, organizations are embedding cyber risk considerations into AI initiatives, digital transformation efforts and broader technology investments, recognizing that strong security practices enable innovation while reducing enterprise risk.

 

As a result, CISO/CIOs are taking on more influential roles, working closely with executive leadership and corporate boards to integrate cybersecurity into overarching business strategy and governance. The shift reflects growing recognition that cyber resilience is essential to operational and financial performance.

 

Regulators and financial analysts are reinforcing this trend. S&P recently warned that weak cybersecurity governance could negatively affect corporate credit ratings, while U.K. authorities have urged business leaders to incorporate cyber risk into enterprise-wide decision-making amid a rising number of attacks targeting critical infrastructure. Together, these developments underscore that cybersecurity is no longer simply a technical concern but a core element of corporate governance, risk management and long-term business strategy. --- Shane P. Riley

Apple Hit With Illinois Biometric Privacy Suit Over Eye Scans

“Still, the company never separately discloses that the same process also involves scanning the eyes at a much more granular level.”

 

Why this is important: We’ve previously reported on many lawsuits brought in Illinois under its Biometric Information Privacy Act. Now, Apple is facing one. In this lawsuit, the plaintiff claims that Apple’s Face ID system secretly captures detailed scans of users' irises and retinas without the written consent required under BIPA. While Apple is arguing that it discloses to customers that it captures facial geometry with its Face ID system, the plaintiff claims that it never separately discloses that it scans the eyes at a much more granular level and that obtaining permission to collect one category of biometric data does not automatically extend to a different type of data. Not surprisingly, the plaintiff is pursuing this lawsuit as a potential class action. If you have any questions about facial recognition software or this new lawsuit against Apple, contact Spilman’s Cybersecurity & Data Protection Practice Group. --- Nicholas P. Mooney II

Virginia couldn't Stop Sterling Data Center's 24-Hour Diesel Generator Use, Regulator Says

“Loudoun County Supervisor is calling for new laws after an emergency at the Vantage VA2 campus, amid debate over public health impacts of data center pollution.”

 

Why this is important: In Sterling, Virginia, the WUSA9 investigation examines growing concerns about air pollution from a Vantage Data Centers facility in Loudoun County’s “Data Center Alley,” home to the world’s largest concentration of data centers. Vantage VA2 operates from eight on-site natural gas turbines, backed by dozens of diesel generators, rather than relying on the electric grid. This has prompted concerns about continuous emissions near residential neighborhoods.

 

A health-impact study commissioned by the Piedmont Environmental Council has put a focus on how Virginia should regulate this new type of data center infrastructure. Conflict arises between environmental advocates, who argue that on-site fossil-fuel-powered data centers could pose significant health risks to nearby communities, and state regulators, who contend that the available evidence does not support the severity of those projected impacts and that more direct monitoring is needed.

 

The study estimated that emissions of fine particulate matter (PM2.5) from the facility's permitted operations could contribute to respiratory and cardiovascular disease, premature deaths over time, and $53 million to $99 million per year in estimated health-related damages if the facility operates at its permitted emission levels. Residents describe quality-of-life concerns including air quality and increased and persistent noise from the turbines, adding to concerns about living near the facility.

 

Virginia's Department of Environmental Quality (DEQ) later reviewed the analysis and argued that it likely overstates the impacts. DEQ said the study assumes maximum permitted emissions, relies on modeling approaches the agency does not consider appropriate for this purpose, and does not fully account for local monitoring data, which, according to the DEQ, indicates cleaner air than the study suggests.

 

The issue has broader implications. The controversy reflects a larger challenge in Northern Virginia where rapid data center growth is outpacing available electrical infrastructure. Some developers are proposing or using on-site fossil-fuel generation to avoid years-long waits for grid connections, raising questions about permitting, public health, and local land-use policy. Virginia regulators have since begun a dedicated air-monitoring study across Data Center Alley to gather more data. --- Jennifer A. Baker

To Regulate or Not to Regulate: The Data Center Paradox

By Matthew J. Wisniewski, Summer Associate and Barry A. Naum


Many believe that the booming data center industry presents a great opportunity for America to be the leader in cutting-edge artificial intelligence innovation; however, potential environmental hazards along with enormous energy demands (and possible increased energy costs) have raised concerns. Numerous stakeholders, including state legislatures and the data centers themselves, are actively working to address these concerns. With Federal regulations recently rolled back, state government officials are now in a position to impose regulations on data centers. But self-regulation may be a more practical, efficient, and long-term solution.


Click here to read the entire article.

EPA Steps Back from AI Data Center Regulations 

“The U.S. Environmental Protection Agency has gone on record to say that it will not set any standards or regulations for new data centers and instead wants to leave it up to states and communities to regulate them.”

 

Why this is important: By stating that it will not set any regulations for AI data centers, the Environmental Protection Agency (EPA) is leaving data center regulations to the states and potentially even local governments. With this decision, the EPA also proposed to leave out the public conversation on new minor clean air pollution permits (for entities emitting less than 100 tons of pollutant per year) that are often needed by data centers using various fossil fuels for power.

 

While the EPA stepping away from data center regulations may seem disastrous, leaving decisions regarding data centers to state and local governments can result in better tailored decisions for the areas that data centers are looking to call home. Some states have passed laws that are favorable for data centers to attempt to attract them to bring more income to their economies. For example, throughout the past several years, Virginia has welcomed data centers with favorable laws that make it less costly for data centers to operate in Virginia, resulting in Virginia containing a record-high concentration of data centers. Similarly, West Virginia has used favorable legislation to target data centers to move to the state, using its High Impact Data Center program promising low zoning and environmental restrictions to attract several planned data centers. On the contrary, leaving decisions regarding the regulation of data centers can also prevent data centers from coming to certain states. For example, New York passed a statewide moratorium on all new data center permits, effectively stopping any new data centers from moving to the state.

 

The EPA also has created a potential workaround for data centers by proposing to remove the option of public comment for minor air pollution permits. This gives data centers the chance to stack minor air pollution permits for their power sources, which could lead to less oversight but the same amount of pollution that would constitute a major permit. --- Andrew B. Komorowski, Summer Associate

Severe Weather and Increasing Risk for Data Center Construction

“AI-driven hyperscale data centers are facing new risks and challenges that extend beyond power shortages and chip supply, according to a new report from Zurich North America.”

 

Why this is important: There have been many articles addressing the high costs, areas of skilled labor shortages, critical material shortages, absence of nearby water resources, and high load energy needs related to data center construction. As if those issues were not enough for data center developers, designers, engineers and contractors to analyze in deciding where to site and construct new data centers, there is another significant challenge that must be evaluated: severe weather events. A new report by a well-known insurer for parties involved in significant construction projects – Zurich North America – identified “6 critical questions to enable a resilient buildout.” In the report, Zurich points to severe weather as the largest source of U.S. losses among its insured builders over the past three years, accounting for 32 percent of losses among its insured data center portfolio (followed by fire and equipment damage). Construction projects in Texas, Tennessee, Wisconsin and Ohio, which are outside the “traditional markets” for data center construction, also raise the risk of tornado, hail and wind damage. Careful planning in the planning, design, and contracting phases of the project to address severe weather hazards, the impact on the job, and relevant risk allocation among the parties can help minimize legal disputes over who is responsible for the inevitable damage that may arise on a data center construction project.

 

If you are working on the development, design or construction of a data center project, please contact our Construction Practice Group or members of our Data Center Team. --- Stephanie U. Eaton

Can Virtual Reality and AI Help Construction Workers Avoid Accidents?

“A Texas A&M researcher is studying whether immersive simulations can help prevent workers from becoming desensitized to jobsite hazards.”

 

Why this is important: Construction can be a dangerous profession. Good contractors know that to minimize worksite accidents, thorough safety training and daily briefs are required. But as construction projects become more and more complex, and previously unknown hazards present themselves, the types of safety training previously implemented – with written maps, diagrams, safety procedures and protocols, PowerPoints or even video – may not identify all hazards in a way that those working among them can appreciate. In an effort to evaluate whether construction workers – particularly those who are desensitized to potential hazardous conditions on their jobsites – will appreciate the dangers through the use of AI and virtual reality tools, researchers at Texas A&M are putting theories to the test. Yes, this would be safety training at a new level. 

 

Consider how, over time, construction workers hear so many alarms, constantly see traffic and equipment moving all around them, and are familiar with known hazards on a job site, that they become desensitized to potential hazards. This is very prevalent on transportation projects where, in a span of 10 years, there were 1,800 fatalities and 167,000 non-fatal injuries caused when vehicles and/or heavy equipment hit workers. The Texas A&M researchers developed a virtual reality roadway construction scene through which workers needed to navigate. During the simulation, researchers studied the workers’ biological responses to what they saw and heard. Armed with information, the researchers then observed the workers who had the virtual reality training when those workers returned to the field, to see if this new type of safety training was impactful. The researchers observed behavior changes among the virtual reality-trained workers, who were more vigilant and attentive to their surroundings than they had been previously. 

 

While this new type of safety training is not readily available yet, the researchers are working on an AI-powered augmented reality system that will be designed to replicate actual jobsites based upon photographs taken of the work area. The AI model interfaces with the potential hazards depicted in the photos (and potentially video). From this information, the AI model can create site-specific safety scenarios through the augmented reality interface. Therefore, the safety training goes from generic to specific, and is more relevant and relatable to workers on their jobsite. 

 

We are interested in whether any of your companies have implemented or are considering implementing AI-generated or VR training for your jobsites, and if so, how have you seen improvements in worker safety? Please let us know by contacting our Construction Practice Group. --- Stephanie U. Eaton

X Share This Email
LinkedIn Share This Email

This is an attorney advertisement. Your receipt and/or use of this material does not constitute or create an attorney-client relationship between you and Spilman Thomas & Battle, PLLC or any attorney associated with the firm. This e-mail publication is distributed with the understanding that the author, publisher and distributor are not rendering legal or other professional advice on specific facts or matters and, accordingly, assume no liability whatsoever in connection with its use.



Responsible Attorney: Michael J. Basile, 800-967-8251