Key Takeaways: Colorado Attorney General Phil Weiser on Trends in Technology Policy and Enforcement
Fenwick recently hosted a conversation with Colorado Attorney General Phil Weiser, moderated by Fenwick partner Jonathan Lenzner and counsel Anna Uhls. Weiser has served as Colorado’s attorney general since 2019, overseeing a portfolio that includes many issues critical to the tech sector, including consumer protection, antitrust, AI regulations, child safety, and data privacy. He previously served in the U.S. Department of Justice’s Antitrust Division and in the White House as a senior advisor on technology and innovation at the National Economic Council, and he founded the Silicon Flatirons Center for Law, Technology, and Entrepreneurship.
The discussion covered increased state enforcement in the tech sector, with a focus on antitrust, online safety, consumer protection, and Colorado’s nation-leading approach to regulating data privacy and artificial intelligence. Below are key takeaways from the conversation.
1. State AGs are increasing enforcement activity in areas where federal agencies are receding.
Weiser repeatedly framed states as a necessary enforcement backstop where he and other state attorneys general believe federal agencies are not enforcing laws consistently, for example with data privacy, AI, antitrust, and online harms.
Our takeaway: Companies should not expect federal retrenchment to reduce overall enforcement risk. State AGs, particularly coordinated multistate coalitions, remain a significant enforcement threat.
2. Protection of children online will continue to be an area of high-priority tech enforcement.
Weiser highlighted recent national social media litigation and identified addictive design features, COPPA issues, and notification and engagement mechanisms as areas of concern for regulators. Weiser said that congressional inaction has prompted states to take the lead in regulating online harms to children. Although he expects legal challenges under the First Amendment and § 230, he expressed confidence in the states’ legal position.
Our takeaway: Online child safety will continue to be a bipartisan priority for state AGs across the country, with a focus on consumer-facing tech companies and addictive design theories.
3. Multistate antitrust coalitions are becoming more independent from DOJ.
Perhaps the most striking antitrust point was Weiser’s discussion of the Live Nation/Ticketmaster litigation. He described DOJ’s settlement as an unprecedented breach of trust with the states, who were co-plaintiffs with the DOJ on the case, and stated that states are now prepared to litigate major antitrust cases on their own if necessary. He also noted states are actively expanding antitrust capacity because the traditional assumption of federal leadership can no longer be relied upon.
Our takeaway: The traditional playbook of focusing primarily on DOJ or FTC engagement may no longer be sufficient. State coalitions may continue aggressively even if federal agencies change course.
4. Colorado’s first-in-the-nation AI law is a cautionary tale.
One of the more noteworthy moments was Weiser’s candid criticism of Colorado’s first AI law (he said his office did not play a role in passing the law), which, in his opinion, improperly imposed obligations on AI deployers rather than focusing on entities creating risks and damaged Colorado’s reputation as a tech-friendly state. He expressly rejected the idea that AI will remain unregulated, calling a lack of oversight “ahistorical.” Weiser expects meaningful governance and oversight to emerge, although he acknowledged uncertainty regarding frontier-model risks and liability frameworks.
Our takeaway: Weiser appears to favor AI governance targeted at developers and creators of high-risk systems rather than broad obligations on ordinary enterprise users of AI.
5. He favors federal privacy legislation, but only with state enforcement authority.
In a discussion about the challenges facing companies navigating a patchwork of numerous state privacy laws, Weiser expressed support for a federal privacy law that preempts state laws, provided that state AGs retain authority to enforce it.
Our takeaway: Rather than viewing federal and state authority as competing alternatives, some influential AGs are advocating for consistent federal standards enforced vigorously by the states.
6. Highly prescriptive rules and regulations don’t work with rapidly evolving technologies.
Weiser emphasized that regulators should be cautious about relying on highly prescriptive rules for rapidly evolving technologies. He suggested that while detailed regulatory requirements may work in areas where technology changes slowly, a more flexible, principles-based approach is often necessary when dealing with dynamic technologies because rigid rules may quickly become outdated.
Throughout the discussion, Weiser contrasted Colorado’s privacy law with aspects of the original AI law he views as flawed. He repeatedly praised:
- Principle-based regulation
- Outcome-focused obligations
- Enforcement after the fact
- Avoiding burdens on startups and smaller companies
Our takeaway: When engaging with regulators like Weiser, companies developing or working with emerging and fast-developing new technologies may want to consider emphasizing risk management processes, governance structures, accountability mechanisms, and practical safeguards that reflect a more principles-based framework that focuses on outcomes and responsible conduct.
7. He sees blockchain as legitimate but expects strong anti-fraud controls.
On crypto and blockchain, Weiser struck a relatively balanced tone, calling blockchain an exciting foundational technology but emphasizing that regulators will target fraud and expect companies to implement responsible controls and oversight mechanisms.
Our takeaway: The message was not anti-crypto; it was that firms need credible compliance and anti-fraud programs.