In a decision with potential far-reaching consequences, the Seventh Circuit Court of Appeals recently affirmed dismissal of a putative class action related to unwanted text messages under the Telephone Consumer Protection Act (“TCPA”), finding that text messages do not equal calls and are therefore not covered by section 227(c)(5) of the TCPA (Steidinger v. Blackstone Medical Services, No. 25-2398 (7th Cir. July 14, 2026)).
The Seventh Circuit’s decision ultimately conflicts with decisions from other circuit courts and could result in the U.S. Supreme Court deciding the issue once and for all.
What Happened?
Plaintiffs received numerous marketing text messages from the defendant, even after they asked it to stop (or added themselves to the Do-Not-Call Registry). In response, they filed a putative class action under the TCPA.
The defendant then moved to dismiss and argued that 47 U.S.C. § 227(c)(5), the provision on which the plaintiffs’ claims for relief were based, only creates a private right of action for phone calls, not text messages.
The district court agreed, dismissed the TCPA claims, and declined to exercise supplemental jurisdiction over the plaintiffs’ state law claims. The plaintiffs then appealed.
Based on Plain Meaning, a Text Message Does Not Equal a Telephone Call
On appeal, the Seventh Circuit Court of Appeals affirmed the district court’s decision and found that a text message is not a telephone call for purposes of § 227(c)(5) of the TCPA. That section provides for a private right of action for any person “who has received more than one telephone call within any 12-month period by or on behalf of the same entity in violation of the regulations prescribed under this subsection.”
As the court noted, it is undisputed that a “telephone call” could not have included text messages when the TCPA was enacted in 1991; the first text message was not sent until the next year. So the court looked into what “telephone call” meant back in 1991.
Because the TCPA does not define the term, the court looked to contemporaneous dictionary definitions. As the court noted, in 1991, “a telephone was ‘[a]n instrument for reproducing sounds at a distance.” Because text messages do not reproduce sounds, they did not meet the definition of a telephone call back in 1991.
The Plaintiffs’ Arguments
The court also concluded that the provisions surrounding § 227(c)(5) provided further support for this plain reading of the term telephone call. For example, §§ 227(c)(3) and (4) relate to creating a national database for individuals to object to receiving “telephone solicitations,” a term specifically defined to include more than telephone calls. The court found it telling that Congress used two different terms within the same statutory scheme and rejected the plaintiffs’ argument that those different terms should not be given different meanings.
The plaintiffs, however, rejected that conclusion and raised a number of policy-related arguments that the court rejected outright.
The plaintiffs contended that the term telephone call should be read broadly to encompass text messages; otherwise, “the TCPA’s protections will become increasingly ineffectual as new technologies emerge.” But the court found that the “march of technology” alone was insufficient to ignore the plain meaning of the statute.
Next, the plaintiffs argued that decisions by the Supreme Court and other circuits undermine the defendants’ argument. This, too, was rejected. The Seventh Circuit found that the Supreme Court cases relied upon by the plaintiffs never actually decided what the term “call” meant, noting that the parties never argued that issue, and it rejected the other circuit courts’ decisions on that same basis.
The Court also rejected the plaintiffs’ plea to consider the Federal Communications Commission’s interpretation of the term “call,” noting that under recent Supreme Court precedent, it is no longer bound to defer to the agency’s determination.
Finally, the Court rejected the plaintiffs’ public policy arguments, noting that “the plaintiffs’ policy arguments and broad invocation of the TCPA’s remedial nature ‘cannot overcome the clear commands of [§ 227(c)(5)’s] text and the statutory context.’”
What Does It Mean?
The Seventh Circuit’s ruling is binding on Illinois, Indiana, and Wisconsin, and it means that TCPA class actions under § 227(c)(5) for unwanted marketing text messages in those states are effectively dead. But this decision is only binding in the Seventh Circuit, meaning that other courts could rule differently on the issue. Furthermore, the FCC retains the ability to regulate unwanted text messages under the TCPA.
Attorneys are problem solvers, often tasked with ensuring safe adoption of emerging technologies in real time. With our added duty of competence, we must always advocate for thoughtful implementation, even when there’s a temptation to save time or costs through automation. The magic problem-solving skills of legal work come through a competent human in the mix, not artificial intelligence or any other tool.
As a Gen X attorney, I’ve seen technology evolve from typewriters to tablets and can consider new AI automations with the benefit of lived experience. AI is not the “set it and forget it” solution to automating “simple” legal work. No matter how much pressure in-house counsel is under to reduce costs, automate, and prioritize speed in contracts, using AI without involving human judgment does the opposite. It increases costs due to mistakes, missed clauses, and renegotiations after someone signs onto an impossible promise tangled in “boilerplate” wording.
AI automations are the next tool attorneys will learn to use, implement, and perfect, just as we’ve done for generations moving from quill and ink, through the beloved early word processor WordPerfect, to the variety of digital tools used in practice today. AI tools are not magic, but with innovative attorneys at the helm, incorporating knowledge and experience into the process while thoughtfully crafting improvements, they are remarkably effective at scaling the creation of clear, cost-effective, and commercially aware agreements. As with any legal technology, our tools are most valuable to clients when attorneys are responsible for the substance of our creations.
Why Context Requires a Human
I remember the joyful power of using the “reveal codes” function in WordPerfect, and how it enhanced our new computer skills. Revealing the underlying format is an ideal example of what technology can do to empower and improve the quality of attorney work. Today we can use AI to perform a “reveal” function across all types of contracts, uncovering their structures and paving the way to make adjustments at scale with speed. Automated review of repeat contracts does not, of course, eliminate the need for a human attorney’s experience and knowledge.
The gains of automation don’t fall out of thin air. Smart gains require human attorneys who are familiar with the deal, the client, the counterparties, and any third-party beneficiaries, as well as the tricky ways contracts operate when they are treated as routine or unimportant. When a backdoor standstill is slipped into a simple deal nondisclosure agreement (NDA), an automation might not pick up the ambiguity-turned-land-mine. An experienced, detail-oriented human review will find the dangerous one-word addition of “negotiated” to a standard use restriction (you will only use X for a transaction regarding Y) and discuss the risk of “negotiated” slipped in before “transaction” with a business in a way that a computer can’t. It’s the attorney who turns insight into quality and action for clients, not the tool.
Checking Our Work, Avoiding the Foot Fault
As a later-in-life law student, I took my 1L writing classes in my thirties with professors who regaled us with tales of the halcyon days of learning to Shepardize by hand, sharing horror stories of classmates stealing a key reference from the library when they needed it most. By that time, though, we were learning not only how to find those tomes among the stacks but also how to use LexisNexis, Bloomberg, and WestLaw: ubiquitous tools in today’s practice of law.
Along with learning the foundations of the legal profession, we were taught to use current innovations to become more agile, not to avoid our duty to check those citations each time. Current advancements require the same duty to check our work. This May, the Florida Supreme Court issued an instruction reiterating what we know: innovations don’t replace attorney responsibility. In Florida (and I expect many states to follow), an attorney’s representation to the court is the accuracy of our work, including existing and accurately cited sources, not a disclosure or certification of what tool was used.
Because our duty of competence is not removed by our use of technology, AI automations included, attorneys must always check our work. Instead of slowing things down, AI can help boost the volume of our work, leaving time for careful citation checks in the same timeline it previously took to create the product to begin with. Another use of AI is searching past agreements and finding how often and in what form the counterparty agreed to wording your client needs. With AI, we don’t have to invent the wheel or delay the process to search vast troves of past agreements; we can utilize its enhanced search and summary capabilities to inform and improve our output.
When, Not If, Automation Falls Short
A May 2026 article in The New Yorker surveyed college professors about the push-and-pull of AI use on college campuses. One professor, Daniel Silver at the University of Toronto, discussed showing students that the C-grade “replacement-level work” that AI produces is the floor. Students must still learn how to think and create something better than the identifiably bland output of a large language model.
The same issue affects the use of AI tools in our profession. The first draft spit out by a large language model is not the quality of legal work we are expected to produce, nor the work a competent attorney would be comfortable presenting as their own, even the ever-maligned “first-year.”
In the rush to utilize AI automations, those of us in the transactional contract space have already seen such C-level replacement work come into our inboxes, sometimes in an email “signed” by an automation itself. Automations don’t capture the nuances of a commercial relationship in drafts or emails, despite the relationship often being equally important as the outcome of an early-stage NDA or engagement letter. A human in the mix who knows how to balance relationships and risk improves timing and success by reaching out with a quick phone call, confirming the counterparty’s intent, and sending back a finalized contract reflecting positions acceptable to everyone.
The benefits of AI to a law firm are not outputs to replace thought, innovation, or competence. Instead, AI is a particularly promising tool, allowing thoughtful attorneys to organize and monitor complex problems across discovery, depositions, governance, and reporting.
The Gordian Knot AI Can’t Untangle
As attorneys, our clients hire us to solve their problems, no matter the size or the complexity, and regardless of whether it’s ever been seen before. Trust like this—clients bringing us their Gordian knots to unweave—is why our profession requires competence, honesty, and a clear path of responsibility for our actions. These guiding principles have allowed attorneys to be leaders in AI adoption, within our firms and in partnership with our in-house clients. We are trusted to use our experience and thoughtfulness to implement the next big thing without dropping the proverbial balls of competence, honesty, and responsibility.
Those core values for attorneys are why humans will not be replaced by large language models: Our craft requires a human in the loop. Tools help attorneys synthesize and organize data, so we support our clients efficiently and build both the details and big picture needed to make the most important decisions. AI tools can find and summarize, but not decide, so attorneys are well placed to use those summaries and searches to expand the information available to compliance teams and provide the advice our clients count on.
With AI, our clients will benefit from information learned from the last fifty or five hundred contracts that have been through the same queue, but only if they can also depend on humans applying context and detail for today’s deal. An experienced attorney knows why a particular commercial term matters to sales, why checking citations for hallucinations and other mistakes (before filing) matters to courts, or why the deposition answers of the CFO and CIO should be checked against one another. Clients will not and should not rely on a C-minus draft or on automated review, but they can benefit from the knowledge gained from prior experience when that knowledge is funneled through attorney sign-off.
The Road Ahead
Pretending the next generation of attorneys will only learn by doing it our way is a recipe for stagnation. At the same time, our clients deserve our expert skills enhanced by AI tools, not replaced by them. Luckily for us, our profession is already constantly adapting to the ever-shifting landscape of legislation, markets moving at warp speed, and clients who rely on us to understand established law and find innovative theories to move their ideas in the world. Buoyed by our foundational duties of competence, honesty, and responsibility—attorney innovators will lead on AI, too. Even as the competence and honesty of AI tools’ outputs improve incrementally, our responsibility is the core reason why the most successful adoptions of AI include human involvement. Attorney skills and foresight identify mistakes, right the ship, and approve the final work product before our work is touched by a client or a court.
Attorneys have always used tools, from pen and paper through word processors and digital research repositories. As long as we maintain human oversight, AI is simply the next tool in our belt, not the Sword of Damocles.
This article previews a Showcase CLE program at the American Bar Association Business Law Section’s upcoming Fall Meeting in Chicago, Illinois. Register now to attend the program, “Data Centers: Issues of National Infrastructure, State Investment, and Local Sustainability,” on Thursday, September 3, 2026, 12:00–1:30 p.m. CT.
Data centers have gained popular attention in the United States of late, amid an expansion of data center development fueled by the artificial intelligence boom. Many residents and local officials in communities abutting data centers—whether proposed, under construction, or in operation—have risen up in opposition, voicing their concerns about strains on the local electricity grid and depletion of clean water sources, frustration with nuisances such as heat and noise, and skepticism about whether data center projects’ promises of jobs and economic prospects to the community are justified and real.
We depend on data centers every day. When we text, email, and use generative AI tools, the data we transmit and consume fly through various data centers. Data centers use electricity to power the transmission and manipulation of data and typically use water (some use air-based systems) to cool the components and equipment that heat up as they process data. With increasing adoption of AI, data centers’ electricity usage is expected to accelerate. Hence, it would appear that though all of us benefit from data centers from anywhere, the communities hosting the data centers may be asked to shoulder a disproportionate share of the burden and externalities.
That apparent benefit-burden mismatch led me to propose the upcoming Showcase Program on data centers at the ABA Business Law Section Fall Meeting 2026 in Chicago, titled Data Centers: Issue of National Infrastructure, State Investment, and Local Sustainability. Through conversations with the panelists and members of the Section’s Community Economic Development Committee, as well as my own research, the working thesis I have developed is that durable data center development should preserve meaningful self-determination for host communities. A conscientious business lawyer engaged in or wanting to engage in data center development—whether as deal counsel, policy strategist, or community advocate—can help manifest that principle in contracts, processes, and community engagement.
Such an approach is a particularly helpful lodestar today when conversations around data centers have shifted significantly and continue to be in flux. For example, as the world’s largest data center market, northern Virginia remains the mature-market benchmark for the industry, and the state’s retail sales-and-use tax exemption was an important player in that growth. However, in March, a Virginia appellate court affirmed that the rezoning approvals for a major proposal, Prince William Digital Gateway, were void because of defective public notice, resulting in the cancellation of what reportedly would have been the world’s largest data center project. Texas—another incentive-driven market—appeared to respond to the popular opposition when Governor Greg Abbott directed the Public Utility Commission of Texas and the Electric Reliability Council of Texas to audit certain projects and to make available to the public important information about the projects, such as receipt of public financial assistance, power and water demand, and measures to reduce neighborhood impact.
Other questions persist. How will the Trump administration’s energy policy coexist with data center’s increasing demand for power? What will happen to the sprawling data center facilities should we no longer need such large footprints, whether due to technology advances or changes to our data consumption patterns? What will happen if the operator or the tenant leaves, and the facilities stop operation altogether?
The Showcase Program will help attendees to make sense of these developments, participate in the conversation, and leave with practical questions for our professional lives. The panel brings together a leading professor, a data center developer executive immersed in responsible data center development, and lawyers with deep knowledge from transactional, financing, and tax perspectives. We will ask how multifaceted influences and concerns can be aligned to support host-community agency.
During the session, the panelists will explain what data centers are and what they do; examine the legal and political considerations that shape data center development, including tax incentives and financing; and discuss how business lawyers can help catalyze host communities’ meaningful exercise of self-determination. We hope to offer concrete takeaways for lawyers in different roles and generate lively conversations. I hope you will join us.
This article previews a Showcase CLE program at the American Bar Association Business Law Section’s upcoming Fall Meeting in Chicago, Illinois. Register now to attend the program, “When the Alarm Sounds: Boardroom Crisis Management in Real Time,” on Wednesday, September 2, 2026, 12:00–1:30 p.m. CT.
Corporate crises rarely arrive at a convenient time, in a neat package, or with a complete set of facts. Lawyers cannot control when the alarm sounds. A ransomware attack locks key systems before dawn. A whistleblower complaint alleges executive misconduct on the eve of an earnings call. A regulator sends an urgent inquiry that suggests the government already knows more than the company does. A financial restatement threatens market confidence, investor relations, and board credibility all at once.
In those moments, lawyers (both outside counsel and in-house counsel) are asked to do far more than answer legal questions. They must help a company think clearly under extreme pressure—and do so in a way that holds up to real-time and post-hoc scrutiny from regulators and judges. They must also help directors and officers identify problems, preserve privilege, and satisfy fiduciary duties, all without creating new legal or ethical problems of their own along the way. The first hours matter, but so do the decisions made in the days, weeks, and months that follow.
When the Boardroom Becomes a Crisis Command Center
When a serious crisis emerges, one of the very first questions is who should take charge. The answer can be surprisingly hard to pin down. Management often has operational control and access to information, but the board may have independent oversight obligations, particularly when the allegations involve senior leadership, internal controls, financial reporting, regulatory compliance, or enterprise risk management.
The board’s role often has to be worked out in real time, and counsel needs to be ready for it. Should the full board handle this directly, or does it call for a special committee and independent counsel? Whatever the answer, directors need enough information—properly documented—to know when to defer to management and when to take a harder stance. These decisions can shape the company’s legal position, affect privilege, and determine whether later scrutiny views the company’s actions as thoughtful governance or reactive damage control.
Preserving Privilege While Finding the Facts
Internal investigations are often central to corporate crisis response. But an investigation that is poorly structured at the outset can create avoidable risk. Counsel must consider (1) who the client is; (2) who is directing the investigation; (3) who should conduct interviews; (4) how documents should be collected; (5) how findings should be reported; and (6) whether any report should be written, oral, privileged, or shared with third parties.
To complicate matters, there is a practical tension between learning the facts quickly and preserving legal protections. In a crisis, business leaders want answers immediately. Regulators may expect cooperation. Auditors, insurers, lenders, investors, and counterparties may demand information. Employees may be anxious or confused. The media may ask questions before the company has completed its own review. Lawyers must help the company gather reliable information without sacrificing privilege, waiving protections unnecessarily, or creating a record that is inaccurate, incomplete, or damaging.
Communications, Candor, and Control
Every corporate crisis is also a communications crisis. Silence can create suspicion, but premature statements may create liability. Public companies may face disclosure obligations. Regulated entities may have reporting duties. Private companies have their own audiences to manage, from employees and customers to lenders and business partners. And in nearly every significant crisis, someone will be watching: regulators, plaintiffs’ lawyers, the media, competitors, stockholders, consumers, and/or the court of public opinion.
Shaping communications that are accurate, disciplined, and consistent with the company’s legal obligations is its own kind of advocacy. That does not mean turning lawyers into public relations professionals. It means understanding how communications strategy, litigation risk, regulatory exposure, and corporate governance intersect. Counsel must also be sensitive to the danger of inconsistent messaging. What the company tells employees should not undermine what it tells regulators. What it says publicly should not conflict with what the board has been told privately. What appears in a press release may later appear in a complaint, deposition, enforcement action, or judicial opinion. Good crisis management requires coordination, judgment, and restraint.
Ethics in the Pressure Cooker
Crisis conditions can magnify ethical risk. Lawyers may face difficult questions about organizational representation, conflicts, confidentiality, reporting obligations, document preservation, witness communications, and interactions with government agencies. In-house counsel may be asked to serve simultaneously as legal adviser, business strategist, investigator, and institutional memory. Outside counsel may be asked to move quickly while still maintaining independence and professional judgment. But many fundamental and difficult questions arise quickly:
Whom does counsel represent?
What happens when the interests of the company and individual executives diverge?
How should counsel communicate with employees during internal interviews?
What must be done to preserve documents and electronically stored information?
When does zealous advocacy become obstruction, overstatement, or concealment?
These issues matter not only to corporate lawyers but also to judges and government lawyers who later evaluate whether a company acted responsibly. A crisis response that is ethical, organized, and well-documented can affect regulatory credibility, settlement posture, judicial perception, and litigation outcomes.
A Practical Framework for the Full Life Cycle of a Crisis
Crises tend to unfold in phases, but the planning for them has to happen long before any crisis exists. What counsel needs is a practical framework for advising boards and companies through the full life cycle of a corporate crisis. This framework must be built well in advance, not improvised under pressure.
The first phase is preparation, which includes refining governance structures, setting escalation protocols, drafting crisis playbooks, addressing privilege issues, training incident response teams, and educating the board, long before any of it is actually needed. That groundwork pays off in the first critical hours, when counsel must help identify the problem, convene the right decision-makers, preserve evidence, retain necessary advisers, and control communications.
From there, the response widens: internal investigations, regulatory engagement, public disclosures, employee communications, insurance coordination, remediation, litigation strategy, and board oversight, often running at the same time.
And once the immediate crisis passes, the work is not finished. Counsel must turn to identifying lessons learned, effectuating governance reforms, implementing compliance improvements, and, where needed, the slower work of rebuilding trust.
Conclusion
Corporate crises test institutions. They also test the lawyers and public relations professionals who serve those institutions, often before key audiences—boards, regulators, judges, juries—who will judge the process as closely as the outcome.
When the alarm sounds, the lawyer’s role is not simply to say what the law requires. It is to help the organization make careful decisions under intense pressure, protect the integrity of the process, and guide the client from the first frantic phone call to whatever resolution eventually follows. The lawyers who do this well are usually the ones who did the unglamorous work months or years earlier—the playbook, the trained team, the privilege protocols already worked out—long before anyone could have guessed which crisis would actually occur.
Program attendees will leave with guidance on the following:
How to organize the first forty-five minutes to an hour after a crisis is identified.
How to determine who should lead and who should be informed.
How to preserve privilege while gathering facts.
How to navigate legal ethical dilemmas.
How to coordinate legal and communications strategies without increasing liability.
How to advise boards through difficult governance decisions under time pressure.
How to recognize common mistakes that often worsen a crisis.
The ABA Business Law Section is hosting its Fall Meeting in Chicago on September 2–4, 2026, at the Hyatt Regency Chicago. This event brings together legal professionals from around the world and offers 50+ CLE programs, networking receptions, practice group committee meetings, and ticketed dinners. With so many events happening at once, choosing which CLEs, receptions, and dinners to attend can be challenging, especially for in-house counsel. To assist, the Business Law Section’s In-House Counsel Committee has created the guide below, curated for in-house counsel attending the ABA Business Law Section’s Fall Meeting in Chicago this September.
ABA Business Law Section Fall Meeting: The In-House Counsel Track
This track presents one path through the conference for in-house counsel, but please note that there are other programs of interest, including others co-sponsored by the In-House Counsel Committee. Refer to the Fall Meeting agenda for details.
Bolded programs are presented by the In-House Counsel Committee.
Wednesday, September 2, 2026
Time (CT)
Program
Type
Location
Presented By
8:00 AM
Enterprise Risk Management 3 M’s: Mapping, Managing and Mitigating Risk Tools for Legal Advisors
CLE
Grand Hall K, Ballroom Level, East Tower
In‑House Counsel Committee
12:00 PM
Showcase Program: When the Alarm Sounds: Boardroom Crisis Management in Real Time
CLE
Grand B, Ballroom Level, East Tower
Business Law Section
2:00 PM
GCs Beyond the Corporation: Ethical Risks, Roles, and Realities
Mandatory Compliance: U.S. ESG Laws and Regulations Every Company Must Know
CLE
Grand Hall G, Ballroom Level, East Tower
Corporate Sustainability Law Committee
11:00 AM
In‑House Counsel Committee Meeting
Meeting
Randolph 2, Concourse Level, East Tower
In‑House Counsel Committee
12:00 PM
Showcase Program: Data Centers: Issues of National Infrastructure, State Investment, and Local Sustainability
CLE
Grand B, Ballroom Level, East Tower
Business Law Section
2:00 PM
Proactive Strategies for Mitigating the Risk of Nuclear Verdicts
CLE
Grand Hall G, Ballroom Level, East Tower
In‑House Counsel Committee
4:00 PM
AI in the Boardroom: Governing Risk, Accountability, and the “Black Box”
CLE
Grand Hall J, Ballroom Level, East Tower
In‑House Counsel Committee
5:00 PM
In‑House Counsel Reception
Special Reception
Plaza Ballroom, Lobby Level, East Tower
In‑House Counsel Committee
6:00 PM
Diversity Networking Reception
Special Reception
Crystal BC, Lobby Level, West Tower
Diversity, Equity, and Inclusion Committee
Friday, September 4, 2026
Time (CT)
Program
Type
Location
Presented By
8:00 AM
Navigating Payments Compliance: MTL/MSB Frameworks, Nacha and Network Rules, and Bank-Fintech Regulatory Strategies
CLE
Grand Hall J, Ballroom Level, East Tower
Banking Law Committee
The ABA Business Law Section’s Fall Meeting is a great place to network, learn, and explore a new city. It is especially valuable for in-house counsel to learn new practice areas, meet potential outside counsel, and network with fellow in-house counsel. We look forward to seeing you there!
Business lawyers, both internal and external counsel, occupy an important leadership role in the ongoing evolution of organization governance built on “checks and balances.” Further, business lawyers can contribute to carrying the concept of “checks and balances” and “transparency” down through the organization, thereby benefitting the entire organization. As is set out here, business lawyers can contribute to the leadership of their organizations—legal and otherwise—by encouraging the discussion of and aiding in the implementation of the appropriate checks and balances within a transparent environment. Business lawyers can lead by exploration and examination, and thoughtful inquiry without dictating. That exploration and examination can reach to all levels in an organization.
Leadership Through Governance
A good starting position for the business lawyer is to keep in mind what has been set out by recognized authorities. There are three to whom we have often turned and continue to turn:
Retired Delaware Supreme Court Chief Justice E. Norman Veasey, in his Pennsylvania Law Review article of May 2005, stated that stockholders should have the right to expect that “the board of directors will actually direct and monitor the management of the company, including strategic business plans and fundamental structural changes.”[1]
Further to the point that directors have management as well as oversight responsibilities, then–Delaware Chancery Court Chancellor William B. Chandler stated in his 2005 opinion in the Disney shareowner derivative suit, “Delaware law is clear that the business and affairs of a corporation are managed by or under the direction of its board of directors. The business judgment rule serves to protect and promote the role of the board as the ultimate manager of the corporation.”[2]
In a discussion of internal controls and director responsibilities on the Federal Reserve website, the Fed describes a board’s responsibility to create and enforce prudent policies and practices with the following statement: “Directors are placed in a position of trust by the bank’s shareholders, and both statutes and common law place responsibility for the affairs of a bank firmly and squarely on the board of directors. The board of directors of a bank should delegate the day-to-day routine of conducting the bank’s business to its officers and employees, but the board cannot delegate its responsibility for the consequences of unsound or imprudent policies and practices.”[3]
These well-recognized authorities provide a basis for the business lawyer to interact with, not dictate to, other members of senior management and the board who are accountable for addressing these responsibilities. The task is not simple; business lawyers and their clients, be they organizations, boards, or senior management, are seeking to address expectations for enhanced oversight and governance and face many challenges.
Not to address the intertwined set of governance, oversight, and management responsibilities can be catastrophic, as occurred in the Wells Fargo fake accounts scandal of the late 2010s and the Boeing crashes of 2018 and 2019. There was criticism of all of the Wells Fargo directors by the Board of Governors of the Federal Reserve based on their lack of performance, followed by a procession of director departures including the chair/CEO and the lead director.[4] And in the 2021 In re The Boeing Company Derivative Litigation decision,[5] Delaware Chancery Court Vice Chancellor Zurn set out a balanced, but scathing, review of the Boeing board’s actions and lack thereof with respect to the loss of 346 passenger lives in two Boeing 737 Max crashes and other safety lapses.[6] Regarding Boeing, U.S. District Judge Reed O’Connor said that “Boeing’s crime may properly be considered the deadliest corporate crime in U.S. history.”[7]
Economists have long recognized that the division of labor of a firm is unique to each firm at each point in time. Similarly, there is no single standard and no single metric for what constitutes effective governance—no sole best practice, no “one size fits all” approach to follow. But there are the fundamental issues of governance, oversight, and management to be addressed.[8]
Governance, oversight, and management are necessarily both organization-specific and time-specific. Models and practices are useful sources of information to consider in designing governance-oversight-management structures, but what is required in an organization will inevitably change over time, sometimes unexpectedly and rapidly in response to a crisis or other change in circumstances.[9]
These factors position the business lawyer to employ an approach of exploration and examination to promote thoughtful inquiry. It is the authors’ view that the business lawyer brings to this examination and exploration the critical role of checks and balances and the importance of transparency.
Checks and Balances
The concept of checks and balances in corporate governance is not new. In the March 2002 issue of The CPA Journal, five senior executives (three large public companies, one large private company, and a large public-private organization), including one of these authors, authored an op-ed titled “From ‘Tone at the Top’ to ‘Checks and Balances.’”[10]
Shortly afterward, a senior executive from the Securities & Exchange Commission relayed its concurrence with the position taken in the op-ed regarding checks and balances.
Not long afterwards, writing in the Wall Street Journal in 2004, Paul Volcker, former chair of the Federal Reserve, and Arthur Levitt Jr., former chair of the SEC, were direct on the need for checks and balances: “Two years ago this summer, Congress passed the Sarbanes-Oxley Act, the most far-reaching corporate reform legislation in 60 years, with the support of all but three members of Congress who voted. It was a moment of rare bipartisan action in response to the breakdown in corporate checks and balances that cost investors hundreds of billions of dollars in losses.”[11]
Note that no mention was made of “tone at the top.”
Economics and political history have long pointed to the value of checks and balances. Volcker and Levitt locked their value in place.
Going Forward
The ABA Business Law Section understands well the benefits to an organization from effective business lawyer involvement and guidance, and recently joined with the three authors here and a colleague in publishing the book Corporate Governance: Understanding the Board-Management Relationship (2024).[12]
The business lawyer cannot only raise the issues of “checks and balances” and “transparency” but, within the context of those issues, needs to focus on questions of stress testing the organization, the adequacy and effectiveness of internal reporting, the monitoring of cash flows, the usefulness of an executive committee of the board, and other questions, doing so from the position of an involved insider opening and maintaining a dialogue on these and other matters.
An important avenue exists for the business lawyer to offer valuable legal leadership via maintaining an organization’s focus in general, and in addressing governance, oversight, and management issues throughout the organization.
Business Roundtable, in its updated Principles of Corporate Governance 2016, sets out: “No one approach to corporate governance may be right for all companies, and Business Roundtable does not prescribe or endorse any particular option, leaving that to the considered judgment of boards, management and shareholders. Accordingly, each company should look to these principles as a guide in developing the structures, practices and processes that are appropriate in light of its needs and circumstances.” ↑
James N. Clark, R. Hartwell Gardner, H. Stephen Grace Jr., John E. Haupert, & Robert S. Roath, From ‘Tone at the Top’ to ‘Checks and Balances,’CPA J. (Mar. 2002). ↑
Every day, personal data is bought, sold, and traded online by companies most people have never heard of, often for purposes they never explicitly agreed to. Consumers typically don’t know it’s happening. And the businesses operating websites are also often in the dark as to how some data-collection technologies work in practice. Up until now, there have been few legal avenues for better understanding and addressing these potential harms.
That’s changing. Today, artificial intelligence is helping legal teams pull back the curtain on how companies that buy and sell consumer information online—often called data brokers—access and use that data. That same technology is also helping organizations that operate online understand whether their data privacy policies and practices are actually effective. And it’s helping consumers’ attorneys spot and address entities on all sides of consumer data exchanges that fail to protect data privacy.
Staying up to date on all the ways consumer data can be misused (whether intentionally or not, and whether by the organization itself or an external partner) is time-consuming and challenging. Yet businesses operating online likely can’t avoid interacting with external partners, such as data brokers, that seek to access their consumer data. Therefore, they must be aware of the potential privacy risks those organizations introduce so they can better manage them. Here’s what you need to know.
The shifting landscape of consumer data privacy litigation
Data privacy litigation has historically focused on website owners that collect personal digital data, such as health information, financial details, browsing activity, location, and communications, without consent. This can happen when operators add third-party tracking technologies, such as cookies and pixels, to their websites.
Pixels collect and transmit user data so websites can better understand who a user is and what actions they might take.
Cookies store data on a user’s computer, allowing websites to identify the user and provide a targeted experience based on past online behavior.
These trackers shape how individuals experience the internet. The information can be intercepted by third-party technology providers who use it to customize advertising and other online experiences to each individual based on the interests they have demonstrated.
Courts increasingly view the practice of intercepting and disclosing this type of consumer behavior data without proper consent as a potential wiretap violation.
Wiretap claims against medical websites, in particular, have historically dominated this area of plaintiff litigation. But as the category evolves, a new kind of case is emerging for firms seeking to protect consumer data through the courts. Instead of focusing on consumer-facing companies, plaintiffs are bringing claims against organizations whose trackers collect consumer information in the background of those websites and profit from it (often without explicit consent and in violation of data privacy statutes) using the Electronic Communications Privacy Act (“ECPA”).
These more recent cases go beyond the tech giants that have historically faced class action lawsuits (e.g., Google and Facebook) and look at other players in the adtech pipeline. These entities are typically registered data brokers that operate within the real-time bidding (“RTB”) infrastructure, which precisely targets ads to individual users based on the information collected about them. These cases turn largely on the collection of users’ browsing history, persistent digital identifiers, and communications to build identity profiles for advertising.
At the same time, states have begun implementing laws to put parameters around how these companies can collect and use consumer information, but these laws are generally not enforceable through private litigation.
Key developments driving potential claims against data brokers include the following:
The emergence of positive case law on the privacy harm of profiling users in this way (discussed below)
The potential impact on consumer data privacy is significant. A congressional committee found that, over the last decade, just four data breaches involving major data brokers cost U.S. consumers more than $20 billion in losses related to identity theft. That’s a mere snapshot of the likely harm caused by poor data privacy protections. The growing use of AI across business sectors is raising even more concerns about the security of personal data online. In a recent IBM survey, 97 percent of organizations reported an AI-related security incident and lacked proper data access controls.
Darrow data shows an emergence in this category of data privacy cases. Darrow analyzed a subset of consumer data privacy class actions filed directly in federal courts in the first quarter of 2026 involving allegations of website-based tracking. Of the 128 cases identified, over 10 percent targeted advertising technology and data vendors directly rather than the website operators hosting the tracking technology. Prior to 2026, cases advancing wiretap and pen register claims directly against these kinds of advertising-technology vendors were far less common. In 2025, Darrow observed only a handful of similar cases being filed in federal court compared to a surge of website-operator wiretap cases.
Technology vendors make up a growing share of ECPA class actions.
Federal data-privacy class actions involving allegations of website-based tracking. Source: Darrow
Cases shaping consumer data broker privacy litigation today
Several recent cases and settlements are beginning to establish precedent, indicating paths forward for future privacy cases focused on actions by data brokers and ad tech vendors.
In both cases, the Northern District of California allowed plaintiffs’ claims to move forward based on allegations that the companies’ practices of monitoring and collecting data on users’ web browsing activity, combining that data with information from other sources, and using it to build unique profiles that track individuals’ activity across the internet could violate California and federal wiretap laws. In doing so, the courts rejected the argument that collecting data for profit, rather than for surveillance, was sufficient to avoid federal wiretap claims.
In two recent cases, the Northern District of California found a privacy injury arising from the collection of IP addresses, device and browser information, digital “fingerprint” information, and the URLs of online pages, which were used to profile users. The court rejected defendants’ arguments that the “pseudonymization” of data precluded liability. These cases reinforce that programmatic advertising vendors may be held liable under both wiretap and California Invasion of Privacy Act pen-register laws for the type of tracking and identity-resolution conduct.
Other notable cases indicate potential outcomes as more claims work through the courts.
Oracle agreed to pay $115 million in 2024 to settle a lawsuit alleging that the company sold consumer profiles containing a wide range of personal information to marketers directly and through an Oracle product that helps companies personalize their online marketing. Oracle also had to agree to limits on how it collects user information online going forward.
The Federal Trade Commission will closely watch data broker Kochava after they reached a settlement earlier this year requiring Kochava to revise how it collects, uses, discloses, and disposes of user location data, following the resolution of a class action lawsuit over its disclosure of location data from sensitive venues, including health care facilities, jails, and schools. Kochava agreed to a class settlement in 2025 providing injunctive relief and approximately $1.5 million in attorneys’ fees and expenses, saying it lacked sufficient funds and insurance coverage to pay significant class-wide damages.
These types of orders and settlements are just the beginning as these cases continue to mature. However, several issues remain in bringing these claims that businesses and consumers should consider.
Challenges to advancing data broker privacy claims
While data broker and adtech vendor privacy claims are growing in number, there are several hurdles to bringing forward these claims, from clearly defining the class to proving harm on technology platforms that are constantly changing.
Understanding which companies introduce the risk. Identifying the specific intermediaries that buy and sell consumer data collected on a given website can be challenging. Consider that in California alone, more than five hundred companies have registered with the state as data brokers—a figure that likely does not capture all the companies processing consumer data across the United States.
Identifying class members. Because these companies operate in the background, data privacy advocates have historically lacked visibility into the volume and type of consumer data they have accessed. Even when that information is known, classes can be difficult to define if class members used numerous websites with these hidden tracking technologies at different points in time. However, technical analysis used in discovery can help ascertain class members and provide the basis for defining common classes with similar privacy harms. Businesses implicated by these claims will have to consider what individual data they have retained and how any data elements were derived.
Proving harm or consent. Different legal theories exist about what counts as a privacy harm and what level of consent is required when being tracked online. Another recent decision from the Northern District of California, In re Meta Android Privacy Litigation, highlights two competing theories of consent.
Broad consent: This theory posits that if an app or website’s privacy policy discloses the collection and sharing of users’ data, even in general terms, then acceptance of that policy counts as consent to having their information tracked and shared. Under this theory, reasonable users would understand that their online data is generally being collected, and thus consent, even where the precise contours of that collection are not stated.
Narrow consent: This theory holds that users must be informed of the specific ways in which their information is tracked and shared, meaning they can agree to some usage but not others—particularly if those others rely, as they did in the In re Meta Android Privacy Litigation case, on knowledge of the platform’s technical architecture that a user would not reasonably be expected to understand. Whether a reasonable user would understand and consent to the collection would be determined based on the specific context.
In this decision, which examined how Meta accessed Android users’ data, the court found that users might agree to basic tracking but not to a more nuanced, hidden process that runs counter to their expectations of online data privacy. The court emphasized that consent goes beyond the four corners of the privacy policy and is dependent on the circumstances.
Four signals shaping consumer data broker privacy risk
With the arrival of AI, legal teams now have the ability to identify and address potential harm more quickly. This allows them to map their digital exposures and make changes to swiftly mitigate their organization’s risk or take steps to secure remedies for consumers—all before privacy violations escalate.
Here are four factors poised to shape the risk landscape around consumer data privacy, and how AI can help organizations better understand what’s at risk and address it accordingly.
How AI can help: Legal teams can use AI to review public disclosures, such as government contracting data, to identify arrangements with data brokers that suggest improper data collection and use. Companies should pay attention to these signals and look for similar agreements that might be putting them at risk.
2. More receptive courts
Courts are warming to the idea that consumers shouldn’t be profiled and tracked without their consent in commercial settings. That means more cases across a wide range of sectors are entering discovery. There, legal teams can watch and learn which practices are most likely to trigger liability. Consider the landmark litigation against Facebook over how it tracked user activity on non-Facebook websites, in which the U.S. Court of Appeals for the Ninth Circuit held in 2020 that users had standing for their privacy harms and that the company violated wiretap laws. Although this case was settled, the ruling helped to shape dozens of subsequent cases.
How AI can help: As litigation in this sector continues to grow, AI can be used to scan cases and identify potential patterns that could help legal teams more efficiently identify, and therefore mitigate, other areas of potential harm.
3. An impactful target
Data brokers built their business model around the ability to access and sell consumer data. What’s more, unlike the massive platforms on which that data is accessed, these entities are usually undisclosed to consumers while profiting from data aggregation at scale—leaving them with fewer defenses and giving advocates a privacy harm narrative that courts understand.
How AI can help: Public marketing materials from data brokers and other adtech vendors are rife with claims about the types of data they collect and how comprehensive their data collection is. Legal teams can use AI to analyze tracking behavior across websites and flag inconsistencies between actual practices and privacy policies, as well as discrepancies between the data broker’s privacy policy and the website’s privacy policy where it collects data.
4. State privacy laws and litigation trends
Organizations that collect consumer data must navigate a growing patchwork of compliance rules, as many states have passed comprehensive data privacy laws in recent years. As regulations increase, consumer data privacy benefits from greater transparency, disclosure, and the setting of thresholds for violations, even though most of these laws do not provide a private right of action. States such as California with stricter privacy laws are also frequent venues for federal class action litigation.
How AI can help: AI enables legal teams to track data brokers’ behavior at scale and better understand what data is being collected, where, and when.
Top states for federal online-tracking class actions filed in Q1 2026
Federal data-privacy class actions involving allegations of website-based tracking. Source: Darrow
The future of consumer data broker privacy risk
With the emergence of AI, identification of data privacy violations is shifting from reactive methods (in response to a data breach or government enforcement action) to proactive ones (by identifying where trackers are used and determining whether they comply with consent laws).
Litigation will likely continue to rise, but companies and consumers can take steps to better understand how data brokers access data and how that access is (or isn’t) reflected in the privacy policies they ask customers to accept. At the same time, privacy advocates will likely continue to unearth privacy violations caused by data brokers at scale.
With this new depth of insight, legal teams have the clarity and foresight needed to flag and address signals of data privacy risk to not only protect consumer data today but also shape how consumer data is tracked and shared online for decades to come.
Many people believe the American dream of owning a home is becoming further and further out of reach. Market data paints a striking picture. As home prices rapidly rose in the wake of the COVID-19 pandemic, increases in median income failed to keep pace. Whereas a market standard is that homeownership costs generally should not exceed a 30 percent share of income, Federal Reserve Bank of Atlanta data suggests that the median household income share of median homeownership costs is now approximately 43 percent. The contributing drivers have ebbed and flowed: high interest rates on mortgage loans peaked as a key affordability factor in 2023, but rates have begun moderating, with Freddie Mac reporting in its Primary Mortgage Market Survey in July 2026 a 6.55 percent weekly average, 0.20 percentage points down from a fifty-two-week high. However, the S&P Cotality Case-Shiller U.S. National Home Price Index continues to climb.
The rise in home price appreciation is significantly driven by an imbalance of supply. Data published by the Joint Center for Housing Studies of Harvard University shows that home inventories for sale have modestly risen since the pandemic, but recent upticks in inventory are partially attributable to average time on the market for sale increasing as well. In any event, existing home inventory for sale remains below pre-pandemic levels. New housing starts likewise have increased modestly but not above the levels prior to the 2008 financial crisis. At the same time, current homeowners are staying in their homes longer. Redfin data placed the average time U.S. homeowners stay in their homes at 12 years in 2025, almost double the length before the financial crisis of 6.5 years. Furthermore, homeowner turnover (i.e., home sales per 1,000 homes) measured only 2.77 percent, one of the lowest levels since the mid-1990s. Factors contributing to longer tenure and lower turnover may include home price affordability, retaining lower interests on existing mortgage loans, and economic uncertainty.
Existing housing policy is likely driving these trends and can also be tailored to address them. For example, in California, Proposition 13 amended the state constitution to limit year-over-year increases in property taxes, and for nearly fifty years, these increases have not kept pace with the market value of the properties. Instead, Proposition 13 generally limits reassessment to the time a home sells, creating an incentive for established homeowners to stay. This is consistent with observed homeowner tenure patterns; whereas the national average homeowner tenure is about twelve years, California’s average is about twenty years. On the other hand, numerous proposals have aimed to combat supply-side housing constraints, including the Trump administration’s executive order to prevent “large institutional investors” from acquiring single-family homes, efforts to “upzone” existing neighborhoods to allow for more density, local neighborhood stabilization programs to address blight, and housing subsidized through nonprofit community land trusts and low-income housing tax credits.
The housing finance industry and agencies are also addressing affordability through demand-side affordability products. The proposal that has gotten the most public attention in the last year has been the Trump administration’s fifty-year fixed rate mortgage. Although the true affordability of a fifty-year mortgage product can be scrutinized, lenders and government agencies have other tools to make homeownership more affordable. These include assumable mortgages securing FHA (Federal Housing Administration), VA (U.S. Department of Veterans Affairs), and other loans that need not be paid off at sale; loans that have low down payment requirements (such as the Fannie Mae HomeReady program) or no down payment (such as VA and U.S. Department of Agriculture loans); down payment assistance grants such as those offered by Federal Home Loan Banks and local nonprofits; and “piggyback” second mortgage programs (such as the Freddie Mac Affordable Seconds program) that allow borrowers to take a first mortgage at a loan to value ratio low enough to avoid private mortgage insurance and a simultaneous second mortgage to fund a portion of the down payment.
There are potential policy-based solutions to address both supply- and demand-related challenges in housing affordability, including the expansive reforms in the 21st Century ROAD to Housing Act enacted in July 2026. While these reforms will take time to implement, the Act includes initiatives to study and expand access to small-dollar mortgage loans, raise awareness of federally backed programs like VA lending, increase housing supply, and support public welfare investments in affordable housing. On the other hand, existing law also includes guardrails to limit features that might potentially harm borrowers. These guardrails include the requirement that creditors assess borrowers’ ability to repay their mortgage loans. Many lenders comply with the ability-to-repay rules by originating only so-called “qualified mortgages,” which cannot include features such as negative amortization, interest-only payments, balloon payments, terms in excess of thirty years, or points and fees in excess of 3 percent of the loan amount. Furthermore, both the Home Ownership and Equity Protection Act and the Dodd-Frank Wall Street Reform and Consumer Protection Act include additional restrictions on “higher-priced mortgage loans” and “high-cost mortgages.”
Another consideration is whether affordability products are offered where they are needed most. Federal and state credit and housing discrimination laws, such as the Equal Credit Opportunity Act and the Fair Housing Act, are designed not just to increase access to credit but also to prevent predatory lending affecting protected classes. Key exceptions include special purpose credit programs (“SPCPs”), which historically could be targeted to benefit certain identified classes who might not otherwise obtain credit on favorable terms and have previously been applied to make housing more affordable. Recent rulemaking by the Consumer Financial Protection Bureau, however, limits SPCPs as an option for certain protected classes. And for banks that are subject to the Community Reinvestment Act, their penetration into low- and moderate-income neighborhoods through home lending, community development investments in housing-related programs, and flexible and innovative products all contribute to the evaluation of whether they are meeting the needs of their communities. Affordable housing is poised to remain at the forefront of policy debate for years to come.
This article is related to a CLE program that took place during the ABA Business Law Section’s 2026 Spring Meeting. The panelists have diverse viewpoints, so not all opinions expressed here are attributable to all panelists. To learn more about this topic, listen to a recording of the program, free for members.
Litigation funding involves someone (a dedicated litigation funder, a hedge or private equity fund, or a private party) handing over funds to a lawyer, a plaintiff, or both. In a sense, the funder is making a bet on the eventual success of the litigation. The money is almost invariably offered on a nonrecourse basis, so if the litigation is a bust, the plaintiff or lawyer does not owe the funder anything.
In the early days of litigation funding, plaintiffs were the usual recipients of these funds. They still can be today, either alone or in concert with their lawyer. In the latter case, both plaintiff and lawyer might obtain funding together. However, in recent years, lawyers and law firms, including some very large firms that you might not think of as typical plaintiff lawyers, have emerged as some of the biggest consumers of litigation funding.
The funder may be betting on a single case from which the lawyer anticipates a healthy contingent fee. Alternatively, the funder may be investing in a whole bevy of cases that the law firm has underway. They may all be similar or related cases, or they could be unrelated cases. The funder gets additional spreading of its risk in these so-called portfolio funding transactions.
Loan, Sale, or Prepaid Forward Sale
How are these transactions taxed? To answer, one first should look at the documents. You cannot assess how a transaction will be taxed without seeing the underlying documentation. Some transactions, albeit a minority, are documented as nonrecourse loans. The funder loans money, and the lawyer must repay it plus a healthy amount of interest if the case is successful.
If the documents support treating the arrangement as a loan for tax purposes, the loan proceeds are not income to the lawyer. However, the tax treatment that both the funder and the lawyer receive from a loan is generally disadvantageous. This is one major reason that few transactions are documented as loans. A transaction could be documented as a current purchase and sale of an interest in the case, but that too is uncommon, because of the poor tax treatment to one or both sides.
Instead, for at least the last fifteen years, litigation funding transactions have typically been documented with prepaid forward purchase agreements (“PFPAs”) rather than via loan or sale agreements. The PFPA is not a debt instrument and has no interest payments, and given its terms, it is impossible to tell how much the plaintiff or lawyer contracting with the funder will ultimately pay. This is one reason that the litigation funding industry uses PFPAs, which are a form of variable prepaid forward contract.
The tax authorities say that a taxpayer who receives an advance payment of the purchase price of property under a properly structured PFPA is not taxable on receipt of the advance payment. Instead, the transaction is held open until the contract is settled. The IRS approved this treatment in Revenue Ruling 2003-7, consistent with the fundamental principle that gross income includes gains derived from dealings in property, not gross sale proceeds, per Section 61(a)(3) of the tax code.
In a litigation funding contract involving a law firm, the funder makes one or more cash advances to the law firm. The advances are in exchange for the law firm’s promise to sell the funder a variable portion of the attorney fees and costs that the law firm hopes to receive under its contingent fee agreement with its client.
Single-Case Funding
The PFPA may relate to the law firm’s representation of a single client in a single case. The law firm agrees to sell the funder a variable portion of whatever tangible or intangible property it recovers from its representation of that particular client in that single case. The law firm’s right to payment does not accrue until the case is resolved, whether by settlement or by a nonappealable final judgment.
Once the law firm’s payment right accrues, two things happen. First, the law firm should report its recovery as compensation in accordance with its method of accounting. The basic tax principle that compensation income is taxed when earned is unaffected by whether the law firm has made a side bet with a funder.
Second, the accrual of the law firm’s payment right entitles the funder to a portion of the recovery under the PFPA. When the law firm settles its obligation, the PFPA provides that the law firm’s payment terminates the parties’ rights and obligations under the contract. When the PFPA is terminated, the law firm calculates and reports its gain or loss under the contract.
This is generally equal to the difference between (1) the advances the law firm received and the sum of the law firm’s payments to the funder and (2) the law firm’s basis in the PFPA. Section 1234A of the tax code requires taxpayers to report capital gain or loss from certain terminations of sale contracts. However, because the property that is the subject of the sale is the law firm’s right to fees, the law firm’s gain or loss is ordinary gain or loss under the substitute-for-ordinary-income doctrine, consistent with United States v. Midland–Ross Corp., 381 U.S. 54 (1965).
Hence, the resolution of the case should result in the law firm reporting ordinary compensation income equal to the gross amount of its recovery, and ordinary gain or loss from the termination of the PFPA. In that way, the law firm is paying tax only on the funds that it gets to keep from the case, not on the amount it owes the funder.
Portfolio Funding
In a portfolio funding transaction, the law firm enters into a single PFPA requiring it to sell the funder a portion of its recoveries from multiple cases. The PFPA requires the law firm to make payments to the funder whenever any case in the portfolio is resolved as specified in the contract. A taxpayer who sells a collection of assets should generally treat the transaction as a collection of separate sales, rather than as the sale of a single asset, consistent with Williams v. McGowan, 152 F.2d 570 (2d Cir. 1945).
Applying this principle to portfolio funding, the law firm should generally report the results of settling its obligations with respect to any particular case in the year that case is resolved. To calculate the law firm’s gain or loss, an appropriate portion of the funder’s advances should be allocated to the case in question as the amount realized in that sale.
Novoselsky Case
This tax case does not apply in this context, but its notoriety makes it worth a few paragraphs. Novoselsky, TC Memo. 2020-68, was a 2020 Tax Court case that caused some people to worry that it could apply to commercial litigation funding. The case involved a lawyer’s do-it-yourself loans from interested parties that have no bearing on commercial litigation funding.
Novoselsky tried to borrow money on a nonrecourse basis using self-drafted “litigation support agreements.” His agreements were so poorly written that the IRS argued—and the Tax Court held—that they failed to create debt for tax purposes, so he had to report the payments he received in his income. Novoselsky even argued that the payments should be classified as nontaxable gifts or amounts he received in trust.
Not surprisingly, the Tax Court sided with the IRS. The case has no application to properly drafted litigation funding documents. The case did not discuss prepaid forward contracts.
Conclusion
Litigation is expensive and involves uncertainty. For clients and lawyers, litigation funding can help to reduce risk, albeit with a cost of funding that is usually commensurate with the degree of risk the funder is taking on. From a tax viewpoint, most recipients of funds want to delay the event of taxation, and to be sure that when they pay taxes, they are paying taxes on their net recoveries, not on any of the money that is being paid to the funder.
Properly structured, the unique prepaid forward purchase agreements typical in this context can achieve both goals. Funders like them too because the lawyers and plaintiffs they deal with want and expect these agreements, and because of the tax advantages that the funders and their investors can often achieve.
Consumer fraud is often described as a compliance issue, a consumer protection problem, or a law enforcement priority. Those descriptions are accurate, but they can make the problem sound abstract. Several government agencies, as well as nonprofits, in the United States educate, inform, and track consumer fraud, including the Federal Trade Commission (“FTC”), which maintains a Consumer Sentinel Network, a database of fraud reports made directly to the FTC as well as reports made to law enforcement agencies and the Better Business Bureau. This secure data is made available to law enforcement. An aggregated data file called the Consumer Sentinel Network Data Book (“Consumer Sentinel”) is published yearly containing fraud reports by type, state, consumer, etc., making the harm more concrete: consumers reported more than $12.5 billion in fraud losses in 2024 (the most recent year for which a data book has been released), and the Consumer Sentinel Network received 6.5 million reports across fraud, identity theft, and other consumer protection categories.[1] The data is especially useful for business lawyers because it shows where consumer-facing representations, digital contact methods, and payment pathways meet measurable financial harm.
This article uses the FTC’s public Consumer Sentinel data files to look at deceptive marketing and consumer fraud through a business-law lens.[2] The central point is simple: deceptive marketing is not limited to false advertising copy. In a digital marketplace, the consumer’s path to loss can begin with a social media message, website, app, phone call, email, text, or online advertisement. The legal risk is not only whether the first statement was misleading but also whether the full consumer pathway predictably moved people from contact to payment.
The Complaint Categories Show the Breadth of Consumer-Facing Risk
As shown in figure 1 below, the largest Consumer Sentinel report category is credit bureaus and information furnishers, with more than 1.35 million reports. Identity theft follows with more than 1.13 million reports, and imposter scams account for 845,806 reports. Online shopping and negative reviews, banks and lenders, debt collection, auto-related complaints, internet services, business and job opportunities, and credit cards round out the top ten categories. Those categories are not all “marketing” in the narrow advertising-law sense. But many involve the same basic commercial problem: consumers receive information, form trust, act on a representation, and sometimes suffer financial harm. The data shows that consumer protection risk appears across credit reporting, identity misuse, online purchasing, financial services, debt collection, job opportunities, and consumer credit.
Figure 1. Top 10 Consumer Sentinel Report Categories by Number of Reports, 2024
Credit bureaus and information furnishers, identity theft, and imposter scams were the top categories of Consumer Sentinel fraud reports in 2024.
The legal hook is familiar. Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful.[3] The FTC’s deception framework focuses on whether a representation, omission, or practice is likely to mislead consumers acting reasonably under the circumstances and whether it is material.[4] Consumer Sentinel data does not prove that every report is unlawful, but it helps identify areas where consumer-facing practices generate enough friction or harm to deserve legal attention.
Payment Method Is Where the Loss Becomes Real
As shown in figure 2 below, in 2024, bank transfers or payments accounted for approximately $2.089 billion in reported losses, the largest payment category in the dataset. Cryptocurrency followed at approximately $1.417 billion. Payment apps and services accounted for approximately $391 million; cash, $308 million; wire transfers, $287 million; credit cards, $275 million; checks, $225 million; gift cards or reload cards, $212 million; debit cards, $180 million; and money orders, $51 million.
Figure 2. Reported Consumer Fraud Losses by Payment Method, 2024
Bank transfers or payments and cryptocurrency were the payment methods for the vast majority of consumer fraud losses in 2024 Consumer Sentinel data.
This ranking should matter to lawyers advising companies, platforms, financial institutions, fintech providers, and payment intermediaries. Consumer protection analysis often begins with the front end of the transaction: what was said, what was omitted, and whether the overall impression was misleading. The payment data shows that the back end of the transaction is just as important. Once money moves through a bank transfer, cryptocurrency transfer, wire transfer, payment app, or similar mechanism, recovery can be difficult.
The FTC has separately reported that consumers in 2024 lost more money to scams paid through bank transfers or cryptocurrency than through all other payment methods combined.[5] If a consumer-facing pathway uses urgency, impersonation, scarcity, or fear to move a person toward a hard-to-reverse payment method, the risk is not merely reputational; it becomes a financial-harm problem with legal consequences.
The Marketing Channel Is Often the Entry Point
The contact-method chart, shown in figure 3, brings the marketing side into focus. Social media was associated with approximately $1.858 billion in reported losses, the highest amount among the listed contact methods. Websites or apps accounted for approximately $976 million; phone calls, $948 million; emails, $502 million; text messages, $470 million; online ads or pop-ups, $246 million; and mail, $90 million. The “other” category accounted for approximately $1.072 billion.
Deceptive marketing is nearly as old as marketing itself. The familiar image of the traveling snake-oil salesman reflects a long-standing form of commercial opportunism: taking advantage of limited information, consumer trust, urgency, or the difficulty of verifying a claim before a purchase is made. The basic strategy has not disappeared, but the delivery methods have changed. What once occurred through personal demonstrations, printed advertisements, or door-to-door sales can now be carried out through social media, websites, apps, text messages, and other digital channels.
From a marketing perspective, opportunism helps explain how legitimate tools of persuasion can be redirected toward deception. Scarcity, social proof, authority, personalization, and urgency can help consumers evaluate legitimate products, but they can also be used to discourage careful review or accelerate payment before a claim can be verified. Digital platforms increase the potential scale of that conduct by allowing a deceptive message to reach large numbers of consumers quickly, at relatively low cost, and with increasingly precise targeting.
Figure 3. Reported Consumer Fraud Losses by Contact Method, 2024
Social media was the contact method for almost $1.86 billion in consumer fraud losses in 2024, the highest amount of any contact method by far.
These numbers show that modern consumer fraud often begins in ordinary marketing environments. Cialdini’s Principles of Influence[6]describe several methods of influence widely used in the marketing environment, including reciprocity, social proof, and scarcity, that, while not necessarily illegal, do capitalize on consumers’ use of heuristics or mental shortcuts, resulting in purchasing decisions less than beneficial.
Other theories in the areas of cognition, decision-making, psychology, and sociology also help explain why consumers engage in faulty decision-making and fall prey to fraudulent activities. Social media, apps, websites, emails, texts, and online ads are not merely communication tools; they are consumer access points. A deceptive message on social media may not look like a traditional advertisement. A fake website may mimic a legitimate business. A text message may imply urgency. A phone call may create fear. Each channel can move a consumer closer to a financial decision.
That point aligns with the FTC’s concern over digital “dark patterns,” which the agency has described as design practices that can trick or manipulate consumers into buying products or services or giving up personal information.[7]Consumer Sentinel data does not measure dark patterns directly, but it supports the same broader concern: digital design, contact channels, and consumer decision-making cannot be separated from the legal analysis of deception.
The Harm Is Not Limited to One Age Group
The age data shown in figure 4 complicates the simple narrative that consumer fraud is only a problem for one demographic group. Reported losses were highest among consumers ages sixty to sixty-nine, at approximately $1.18 billion. Consumers ages fifty to fifty-nine reported approximately $1.006 billion in losses, followed by ages forty to forty-nine, approximately $971 million; ages seventy to seventy-nine, approximately $887 million; ages thirty to thirty-nine, approximately $810 million; ages twenty to twenty-nine, approximately $430 million; ages eighty and over, approximately $319 million; and ages nineteen and under, approximately $55 million.
Figure 4. Reported Consumer Fraud Losses by Age Group, 2024
Consumer fraud is a problem for all age groups, with consumers in age groups 30–39 to 70–79 all reporting over $800 million in losses in 2024.
The chart does not prove why loss levels differ by age group. It may reflect differences in assets, savings, reporting behavior, channel exposure, scam type, or willingness to engage with certain communications. Still, the pattern is useful. It suggests that consumer education and compliance controls should not be generic. The warning needed for a twenty-five-year-old using payment apps and social media may not be the same warning needed for a sixty-five-year-old responding to a bank message, investment offer, technical support contact, or government imposter communication.
Geography Can Help Target Enforcement and Compliance
The state chart, shown in figure 5 below, shows the largest reported fraud losses in California, Texas, Florida, New York, Arizona, Illinois, New Jersey, Washington, Virginia, and Georgia. California alone accounted for approximately $1.679 billion in reported fraud losses. Texas reported approximately $898 million; Florida, approximately $866 million; and New York, approximately $534 million.
Figure 5. Top 10 States by Total Reported Consumer Fraud Losses, 2024
California, Texas, and Florida, the states with the largest populations, were the states with the most total reported consumer fraud losses in 2024.
Large states will naturally show large aggregate losses, so Table 1 below details per capita total fraud losses for each of the top ten aggregate state losses. State attorneys general, consumer protection offices, financial institutions, and national companies can use geographic data to decide where education, monitoring, and enforcement resources may be most needed. For corporate counsel, geographic concentration can be an issue-spotting tool. If a product, campaign, platform feature, or payment pathway generates disproportionate complaints or losses in a state, that pattern should trigger review.
Table 1: Per Capita Reported Fraud Losses in States with Largest Aggregate Losses, 2024
Consumer Sentinel data supports a simple framework for evaluating deceptive marketing and consumer fraud risk. First, ask how the consumer was reached. Second, ask what representation or impression was created. Third, ask how payment was requested or processed. Fourth, ask which consumers appear most exposed. Fifth, ask where the losses are concentrated. Those questions move the analysis from isolated advertising review to a broader review of the consumer journey.
This approach is useful because a social media message, website, app screen, text, phone call, or online ad may be only one part of the transaction. The more important question may be whether the full pathway creates foreseeable financial harm. That pathway can include the claim, the timing, the call to action, the payment method, the consumer segment, and the post-payment recovery process.
For corporate counsel, the lesson is operational. Advertising review, user-experience review, payment-risk review, complaint monitoring, and fraud prevention should not be separate silos. If the same consumer journey creates marketing conversion, payment movement, and complaint risk, it should be reviewed as one legal and business process. Consumer Sentinel data gives lawyers a way to explain that point to boards and executives in concrete terms: risk can be measured in reports, dollars, channels, payment methods, age groups, and states.
Conclusion
The most useful insight from the 2024 Consumer Sentinel data is not simply that consumer fraud exists—it is that the harm can be mapped in a way that business lawyers understand. The contact method shows how the consumer enters the funnel. The payment method shows how the loss occurs. The age and state data show who and where the harm affects. The report categories show the parts of the marketplace where consumer trust is breaking down.
That makes deceptive marketing a business law problem as much as a consumer protection problem. It involves legal representations, platform design, payment systems, compliance controls, customer trust, and measurable financial loss. The data does not establish liability in any individual case, but it does provide an early warning system. Public complaint data can help lawyers and businesses see where consumer-facing conduct is most likely to produce financial harm—and where compliance attention should go before the next enforcement action, lawsuit, or reputational crisis.
Fed. Trade Comm’n, Consumer Sentinel Network Data Book 2024 (2025). The FTC states that the 2024 data book is based on unverified reports filed by consumers, not a consumer survey. ↑
Id. data files (CSV files). The figures in this article are based on author analysis of the public data files. ↑
Annual Estimates of the Resident Population for the United States, Regions, States, District of Columbia, and Puerto Rico: April 1, 2020 to July 1, 2024 (NST-EST2024-POP), in Vintage 2024 National and State Population Estimates, U.S. Census Bureau (Dec. 2024). ↑
Connect with a global network of over 30,000 business law professionals