The Innovation Attorney Podcast

The Innovation Attorney

The Innovation Attorney is a publication about the intersection of venture capital, technology, public policy and law. theinnovationattorney.substack.com

  1. Jul 29

    Shifting the Burden: AI Vendor Indemnification for Training Data

    Indemnification clauses covering training data, not just model output, are the specific language shifting AI copyright liability to vendors, a shift exposed by the $1.5 billion Bartz v. Anthropic settlement of August 2025. Anthropic’s commercial terms define a covered Customer Claim to include the data Anthropic used to train the model, not merely the output the model produces. Google’s Generative AI Indemnified Services terms take the same two pronged approach, indemnifying both the training data and the output. OpenAI’s Copyright Shield and Microsoft’s Customer Copyright Commitment, by contrast, are written to reach only the output a customer generates, leaving open who bears a claim aimed at the underlying training corpus itself. Three cases decided or advanced in the past twelve months turned training data indemnification from a boilerplate footnote into the line item that can determine whether a seed stage company survives a copyright claim it did not create. Anthropic agreed to pay $1.5 billion to settle Bartz v. Anthropic in August 2025, covering the piracy based downloading of copyrighted books before August 25, 2025, but that settlement does not touch claims arising from Anthropic’s later conduct or from Claude’s generated output. Music publishers led by Concord Music Group filed a second amended complaint against Anthropic in the Northern District of California on July 22, 2026, covering more than 20,000 songs and seeking over $3 billion, with BMG filing its own suit in March 2026 over 493 compositions. The New York Times’ case against Microsoft and OpenAI remains pending before Judge Sidney Stein in the Southern District of New York, with the court ordering the production of 20 million anonymized ChatGPT logs in 2026. In redlining commercial AI licensing agreements this year, the fastest movement from a vendor’s legal team has not come from asking for a higher indemnification cap. It has come from inserting the word training into the defined term Claim. A vendor’s outside counsel will negotiate over dollar figures for a week and concede that single word in an afternoon, because the word costs the vendor nothing until a rights holder actually sues, at which point it decides who pays. what specific language shifts training data liability to the vendor The operative shift happens inside the definition of the covered claim, not in the marketing name attached to the indemnification program. Anthropic’s commercial terms define a Customer Claim as a third party claim alleging that the customer’s use of the Services, including data Anthropic used to train a model that is part of the Services, or Outputs generated through authorized use, violates a third party’s patent, trade secret, trademark, or copyright. Google’s Generative AI Indemnified Services terms indemnify separately against an allegation that Google’s use of data to train the underlying model infringes intellectual property rights and against a claim that the generated output infringes those rights. OpenAI’s enterprise terms indemnify claims arising from the Services but explicitly exclude customer content, customer applications, and combinations with third party products, leaving open whether a claim aimed squarely at the pretraining corpus falls inside or outside that promise. Microsoft’s Customer Copyright Commitment, extended to Copilot Studio as of June 1, 2025, protects the output of Copilot products and the Azure OpenAI Service, conditioned on the customer not tampering with safety systems and implementing required mitigations, but the commitment is written around what the model produces, not what data built it. Only Anthropic and Google currently write training data into the indemnified claim itself, a distinction that separates two of the four major foundation model vendors from OpenAI and Microsoft on the single clause most likely to decide a copyright suit. why the liability cap decides what the indemnity is actually worth An indemnification promise subject to a general limitation of liability, typically capped at the fees a customer paid in the preceding twelve months, is a rounding error against a claim of the size Concord Music Group has filed against Anthropic. Market practice in negotiated enterprise AI agreements carves intellectual property indemnification, including training data indemnification, out of the general liability cap entirely, or sets a separate and materially higher supplemental cap for that category alone. A founder who accepts a vendor’s indemnification language without confirming it sits outside the general cap has negotiated a promise that a plaintiff’s damages model will outrun before the ink dries. The same exclusions recur across every major vendor’s indemnity: modification of the service or output, combination with third party technology, input the customer itself supplied, and use of an output the customer knew or should have known was infringing, so the value of the promise depends as much on what voids it as on what it covers. Sophisticated investors have started asking this question directly during diligence: does the company’s core foundation model vendor indemnify training data claims, and is that indemnity carved out of the general liability cap. An unindemnified company bears the full cost of defending a claim like the one Concord Music Group brought against Anthropic, a fact that shows up on a term sheet as increased risk weighting long before it shows up on a balance sheet as a settlement payment. The vendors that built the largest foundation models have now shown, through Anthropic’s Customer Claim definition and Google’s two pronged Generative AI Indemnified Services terms, that indemnifying training data is commercially survivable. A founder negotiating with a vendor whose terms stop at output alone now has a market benchmark to cite, not just a request to make. Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc.’s rejection of fair use for a training corpus built into a directly competing product is the fact pattern to watch as the New York Times’ case against Microsoft and OpenAI proceeds, since a ruling against the vendors there would reset the price every foundation model company charges for standing behind its own training data. Read my full analysis here: https://theinnovationattorney.com/blog/ This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit theinnovationattorney.substack.com/subscribe

  2. Jul 29

    Closing the Series A IP Gap: Founder Code, AI Assistants, and Chain of Title

    A Series A term sheet stalls when diligence counsel finds GPL code an AI assistant pulled from public repositories central to the nine billion dollar Doe v. GitHub copyright suit. The same clause that decides code provenance also decides who owns the invention: a present tense assignment signed at incorporation controls, a promise to assign later does not. Both defects are curable before the term sheet is signed. Neither is curable after. Two failure patterns account for nearly every intellectual property defect found in a Series A closing. The first involves code an AI coding assistant wrote, where the model’s training corpus included repositories carrying the General Public License or another copyleft term. The second involves code a founder wrote before the Delaware corporation existed, where the assignment agreement uses the wrong verb tense or never gets executed at all. Neither defect requires bad intent. Both require the founder to run the audit before the investor’s counsel does. What Triggers A GPL Disclosure Obligation In AI Generated Code An open source license attaches its disclosure obligation at the moment the code is distributed, not at the moment it is written. The General Public License, Version 3, triggers its disclosure obligation only at distribution; the Affero variant extends that obligation to network accessible software, which describes almost every software as a service product built today. Doe v. GitHub, Inc., filed in the Northern District of California on November 3, 2022, tests whether an AI coding assistant’s output can carry the license terms of its training data forward into a new codebase without the author ever knowing the terms exist. The presiding judge dismissed twenty of twenty two claims, including the claim under the Digital Millennium Copyright Act’s copyright management information provision, but the open source license violation and breach of contract claims survived and moved to the Ninth Circuit on an interlocutory appeal filed September 27, 2024, with nine billion dollars in statutory damages at stake. A dependency scan run today, using a tool such as FOSSA, Black Duck, or Snyk, catches the same copyleft fingerprint the Ninth Circuit is being asked to rule on, months or years before a court says what the rule actually is. Why The Wording Of An Assignment Clause Decides Who Owns Pre Incorporation Code Copyright law assumes an independent author owns the code that author writes, and a founder who built a product before the company existed was, as a matter of law, an independent author. Under 17 U.S.C. Section 101, an independent contractor’s work qualifies as a work made for hire only if it falls into one of nine enumerated categories, and software is not one of them. The code stays the founder’s personal property until a written assignment moves it, and the certificate of incorporation filed under Delaware General Corporation Law Section 102 does not perform that transfer by itself. The verb tense in that assignment then decides the outcome if a dispute ever reaches a court. Board of Trustees of the Leland Stanford Junior University v. Roche Molecular Systems, Inc., 563 U.S. 776 (2011), holds that a present tense assignment defeats an earlier promise to assign, because title vests first in the inventor and moves only when an actual assignment, not a promise, takes effect. A founder who once signed an employer’s invention assignment agreement carries a second risk: California Labor Code Section 2870, and the six other state statutes built on the same model, protect an employee’s invention only when it was built entirely on personal time, without the employer’s equipment, and unrelated to the employer’s actual or reasonably anticipated business, a protection that narrows sharply the moment the startup’s product resembles the former employer’s own line of business. What A Founder Should Do Before Opening A Data Room Three steps close both gaps before a term sheet exists. Run a dependency scan across every repository, including any code an AI coding assistant helped write, and resolve every copyleft flagged component before the data room opens. Confirm that every founder and every early contributor signed a present tense assignment, not a promise to assign, and attach a prior inventions schedule naming anything built before the company existed. Where a founder’s prior employer operated in the same product line, document a clean room development record showing the code was rebuilt independently, because that record is the strongest answer available once a former employer’s counsel starts asking questions. Series A counsel checks all three items in the first week of diligence, and a completed record turns what could be a repriced term sheet into a closed exhibit. Neither defect is a drafting problem that gets cheaper with time. A dependency scan run the week before a term sheet is signed finds the same license conflict a scan would have found a year earlier, except now it competes with a closing calendar instead of an afternoon of engineering time. Read my full analysis here: https://theinnovationattorney.com/blog/ This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit theinnovationattorney.substack.com/subscribe

  3. Jul 29

    Securing the Stack: How Founders Clear IP Gaps Before Series A Diligence

    In March 2024, the Securities and Exchange Commission fined two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., a combined 310,000 dollars for telling investors their artificial intelligence did more than it actually did. Two years later, that enforcement logic has moved from the asset management industry into the venture capital term sheet. A founder who cannot document what a third-party large language model vendor does with customer data, which state privacy statutes apply to that data, and what the board actually reviewed before relying on artificial intelligence now faces the same category of scrutiny a public company faces from the Commission’s Enforcement Division. The mechanism is simple once traced to its source. Section 17(a) of the Securities Act of 1933 and Rule 10b-5 under the Securities Exchange Act of 1934 make a false statement about a product’s artificial intelligence fraud, whether the security is a public share or a Regulation D private placement sold under Rule 506(b) or 506(c). The Commission’s Enforcement Division built a Cyber and Emerging Technologies Unit in February 2025 specifically to read artificial intelligence disclosures inside Forms 10-K, 10-Q, and 8-K, and the North American Securities Administrators Association named artificial intelligence marketing claims a 2026 examination priority for state registered advisers. None of that authority is limited to companies that have already gone public. It reaches the representations a founder makes in a subscription agreement the same day the wire arrives. How does a third-party large language model vendor create diligence risk The answer sits in two documents most founders have never read closely: the vendor’s Data Processing Addendum and its training exclusion policy. OpenAI does not use API or Enterprise data to train its models by default. Anthropic reduced API log retention from thirty days to seven days as of September 14, 2025, and deletes inputs and outputs automatically unless a customer negotiates a longer window through its own Data Processing Addendum. Both vendors offer a zero data retention agreement to qualifying enterprise customers, removing stored inputs beyond what abuse screening requires. A startup that cannot produce a signed Data Processing Addendum, a documented training exclusion election, and a written record of its retention window is handing a diligence team an open item, and diligence teams in 2026 are trained to find it. The Federal Trade Commission’s settlement with DoNotPay, a 193,000 dollar final order approved in February 2025 over an AI product marketed as performing to the standard of a licensed attorney without substantiating testing, and its separate 18 million dollar stipulated judgment against Air AI, show what happens when a company’s public claims about its artificial intelligence outrun what it can prove. Both actions rested on Section 5 of the Federal Trade Commission Act, the same statute that reaches a startup’s own claims about its vendor relationship. Which state privacy statutes actually apply to a startup’s customer base Twenty states had comprehensive consumer privacy statutes in effect at some point during 2026. Indiana, Kentucky, and Rhode Island took effect January 1, 2026, and Connecticut, Arkansas, and Utah added amendments effective July 1, 2026. California added its own layer on top of the existing California Consumer Privacy Act: the Privacy Protection Agency finalized rules on automated decisionmaking technology, risk assessments, and cybersecurity audits effective January 1, 2026, phased by revenue through April 1, 2030 for the smallest covered businesses. Colorado’s approach to artificial intelligence specifically has changed twice since 2024. Senate Bill 24-205 was set to take effect February 1, 2026. Colorado’s governor signed Senate Bill 25B-004 in August 2025, moving that date to June 30, 2026, then signed Senate Bill 26-189 in May 2026, replacing the original statute with a new artificial intelligence law effective January 1, 2027. A data map naming every applicable state, the threshold that triggers coverage, and a completed risk assessment for any automated decisionmaking use is now standard diligence, not an artifact investors expect a company to build after signing. What board records satisfy Delaware’s oversight duty for artificial intelligence Delaware’s Court of Chancery, applying the duty recognized in In re Caremark International Inc. Derivative Litigation, extended director oversight obligations to cybersecurity risk in 2025 for any company that stores consumer data or depends on digital infrastructure. A director does not need to understand how a transformer model produces an output. The board needs to show it received regular briefings on how the company relies on artificial intelligence and what could go wrong. On December 4, 2025, the Commission’s own Investor Advisory Committee recommended that companies disclose how they define artificial intelligence, what oversight mechanism the board uses, and what material effects that use has produced. That recommendation targets public companies, but it is already shaping what venture investors expect to see in board minutes at private companies preparing to raise. A board package that shows the company mapped its uses of artificial intelligence, measured the associated risk, assigned management responsibility, and kept the board briefed, consistent with the four functions of the National Institute of Standards and Technology’s AI Risk Management Framework, gives investor’s counsel something concrete if a Caremark claim ever follows the round. The founders who close rounds fastest in 2026 are not necessarily the ones with the strongest product demonstration. They are the ones who can hand a data room three things without delay: an executed vendor Data Processing Addendum, a state by state privacy map, and board minutes that show artificial intelligence reliance was actually discussed before the company relied on it. Read my full analysis here: https://theinnovationattorney.com/blog/ This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit theinnovationattorney.substack.com/subscribe

  4. Jul 29

    The Founder’s Guide to Reverse Vesting and Company Buybacks

    Institutional investors are treating a written founder vesting schedule with a one year cliff, tracking NVCA Investor Rights Agreement Section 5.3, as a condition to closing a priced round in 2026. A lead investor’s term sheet increasingly lists a signed restricted stock purchase agreement among the conditions to closing rather than as a side letter to negotiate after the wire lands. Founders who never documented vesting, or whose shares fully vested years before this round, are the ones asking what specific reverse vesting and company buyback language a term sheet will require before a lead investor signs. The question surfaces at an inconvenient moment. By the time a term sheet reaches signature, the company has already negotiated valuation, board composition, and protective provisions. Vesting shows up in the conditions to closing section almost as an afterthought, yet it is often the single item standing between a signed term sheet and a closed round, because the lead investor’s counsel will not release funds until every founder has executed the restricted stock purchase agreement the term sheet references. How the standard schedule works NVCA Investor Rights Agreement Section 5.3 supplies the template most lead investors hand to portfolio companies: vesting over forty eight months, with nothing vesting during the first twelve. Twenty five percent vests on the cliff date, and the remaining seventy five percent vests monthly over the following three years. When a founder incorporated without documenting a vesting schedule, this is the schedule the round will impose retroactively, dated to a vesting commencement date the parties negotiate, often the company’s original incorporation date or the date the founder began working full time. What the repurchase right actually says Reverse vesting issues a founder’s full share grant up front and then gives the company a contractual right, not an automatic forfeiture, to repurchase the unvested portion if the founder departs before the shares vest. Delaware General Corporation Law Section 160 supplies the corporate authority for that repurchase, subject to the rule that a company cannot buy back its own stock if doing so impairs capital. The 2023 amendments to Section 160 clarified how the resulting treasury shares may later be resold under Section 153, a detail that matters when a company wants to reissue repurchased founder shares to a replacement executive rather than retire them. The restricted stock purchase agreement itself fixes the repurchase price, commonly the lower of original issue price or fair market value, and a repurchase window, commonly ninety days from termination, during which the board must act or the option lapses. Does the cliff apply to shares already earned This is the specific ambiguity founders are running into. Where a founder already vested shares under an earlier grant and is only placing new or unvested shares onto a schedule at the priced round, a fresh one year cliff is hard to justify on the merits: the founder has already demonstrated the staying power a cliff exists to test. SaaStr founder Jason Lemkin has taken exactly this position in practitioner commentary, arguing that reverse vesting at a financing generally should not carry a new cliff for founders who are already committed. Some lead investors propose the NVCA cliff language anyway, as a matter of drafting convenience rather than a considered position on a founder who already has three years of history behind the company. That gap between boilerplate and rationale is precisely where a founder’s counsel should redline. Credit for time served, and what happens without it When a term sheet requires revesting, it typically places some or all of a founder’s previously vested shares back onto a new schedule as of closing. Founders routinely negotiate credit for time already served, so that only a portion, often twenty five to fifty percent of total founder shares, goes back onto the new schedule rather than the full grant. None of this happens automatically. A term sheet silent on credit for time served will be read by the lead investor’s counsel as requiring full revesting from zero, because silence favors the drafting party’s default position, not the founder’s expectation. The tax deadline that follows the signature A founder who signs a new restricted stock purchase agreement covering shares subject to company repurchase faces a substantial risk of forfeiture under Internal Revenue Code Section 83(c), and with it a firm thirty day deadline under Section 83(b) to elect to be taxed at grant rather than as the shares vest. The Internal Revenue Service introduced Form 15620 in November 2024 as the first official form for this election, and added an online filing option in 2025. Courts have consistently declined to excuse a late filing under Section 83(b), so the thirty day clock needs to be calendared from the date the new restricted stock purchase agreement is signed, not from the date the round closes, a distinction that has cost founders their election in past financings. The counterweight founders negotiate in return Founders typically negotiate double trigger acceleration alongside reverse vesting: unvested shares accelerate, often in full, only if the company experiences a change of control and the founder is then terminated without cause or resigns for good reason within a defined window, commonly twelve months, after that change of control. Roughly eighty five to ninety percent of Series A and later stage term sheets in 2026 include some form of double trigger acceleration for the founding chief executive. A founder signing a fresh reverse vesting schedule at closing without also negotiating double trigger acceleration is accepting the restriction without the protection that has become standard alongside it. In three decades of counseling companies through priced rounds, the redline that most often gets missed is not the vesting percentage. It is the silence on credit for time served and the absence of an explicit carve out for the one year cliff on shares a founder already earned. Those two gaps cost founders equity quietly, long after the term sheet is signed and forgotten. Read my full analysis here: https://theinnovationattorney.com/unlocking-venture-financing-founder-vesting-buybacks-and-tax-compliance/ This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit theinnovationattorney.substack.com/subscribe

  5. Jul 28

    Restarting the Nuclear Fuel Cycle

    Tennessee, Utah, Oklahoma, Louisiana, and Idaho have each signed a non binding agreement with the Department of Energy to host a Nuclear Lifecycle Innovation Campus, a facility combining uranium enrichment, fuel fabrication, spent fuel research, and waste storage on one site. The Department expects to narrow the five contenders to three finalists before the end of 2026. Utilities that have spent nearly three decades collecting Judgment Fund damages for spent fuel the federal government was contractually obligated to remove starting in 1998 are watching closely, because the plan asks Congress to grant authority two federal appeals court rulings already said the Nuclear Regulatory Commission does not have. The spent fuel problem is older than most of the reactors producing it today. Congress passed the Nuclear Waste Policy Act in 1982, funded by a fee of one mill per kilowatt hour on every unit of nuclear electricity generated, and directed the Department of Energy to open a permanent repository by 1998. In 1987, Congress narrowed the search to a single site, Yucca Mountain, Nevada, and in 2002 it overrode Nevada’s formal objection to complete the designation. The site never opened. Funding for its licensing process ended in 2011, and roughly one hundred thousand metric tons of spent commercial fuel now sit in pools and dry casks at more than seventy reactor locations across the country, growing by about two thousand metric tons a year. Distributing the function across five willing states is a reasonable departure from four decades of trying to force a single site through litigation. Oak Ridge, Tennessee, and Idaho National Laboratory each carry existing federal nuclear infrastructure and a trained workforce that a green field site would lack, and the Department’s new Center for Spent Fuel Research at Idaho National Laboratory, announced in January 2026, gives the plan a research foundation rather than a blank page. The remaining obstacle is not geology or willingness. It is statutory authority. In 2024, the Fifth Circuit Court of Appeals vacated Nuclear Regulatory Commission licenses for consolidated interim storage facilities in Texas and in Lea County, New Mexico, ruling that neither the Atomic Energy Act nor the Nuclear Waste Policy Act gives the Commission power to license privately owned storage away from a reactor or a federal repository. Holtec International, the New Mexico licensee, withdrew its project in 2025 after the Supreme Court resolved a related challenge on procedural grounds without reaching that statutory question. Every state agreement signed this year is non binding until Congress supplies the authority those courts said the agency lacks. Three environmental risks apply to consolidated storage: transportation accidents, cask or container failure, and handling errors, and most already have a demonstrated safeguard elsewhere in the federal system. Transport casks must survive a thirty foot drop, a thirty minute fire, and submersion under Nuclear Regulatory Commission rules at 10 CFR Part 71, and the agency’s own risk studies rate the probability of a radiological release during shipment as very low. Storage has one clear cautionary tale. On February 14, 2014, a drum of transuranic waste at the Waste Isolation Pilot Plant near Carlsbad, New Mexico, ruptured after technicians packed it with an organic absorbent instead of the mineral based material its chemical profile required, producing a reaction that blew off the lid and contaminated about thirty five percent of the underground disposal area. The facility closed for nearly three years, and direct cleanup ran to roughly five hundred million dollars. Investigators traced the rupture to a packaging procedure rather than to any flaw in the salt formation, which performed as designed, and it produced a permanent fix: the Environmental Protection Agency and the New Mexico Environment Department now require overhauled waste characterization at every generator site before a single drum ships. Any new campus inherits that same regulatory model, plus dry cask designs the NRC projects will remain safe for more than a century. The reprocessing question has a simpler answer than most people expect. The United States does not recycle spent fuel commercially because of a decision made in 1977, not because the chemistry is impossible. That year, following a Ford Foundation study warning that separated plutonium from commercial reprocessing could hasten weapons proliferation, the federal government deferred reprocessing indefinitely and canceled the Clinch River Breeder Reactor program. A later administration lifted the formal ban in 1981, but by then a 2003 Harvard Belfer Center analysis had already shown what utilities suspected: reprocessing only becomes cheaper than direct disposal once uranium prices exceed roughly three hundred sixty dollars per kilogram, a level the market has rarely reached. France chose differently and has recycled fuel at La Hague since 1966, recovering plutonium that its Melox plant turns into mixed oxide fuel supplying about ten percent of French nuclear electricity. Reprocessing still leaves high level waste that needs its own repository, a French project called Cigeo, so the French approach shrinks the disposal problem without solving it entirely. Current federal research favors pyroprocessing and electrorefining over the plutonium separating methods France uses, because those techniques keep plutonium mixed with other actinides rather than isolating it. A 2026 study led by Oklo with Argonne and Idaho National Laboratory found that waste from an electrorefining process is compatible with deep borehole disposal, placing waste as far as five kilometers underground, an option still years from commercial use but no longer purely theoretical. The five state plan will succeed or fail on a single fact that has nothing to do with geology, chemistry, or engineering: whether Congress passes the authority two federal appeals courts have already said the executive branch does not have on its own. Utilities holding more than thirty four billion dollars in accumulated damages claims have every reason to push that legislation forward, and investors pricing new reactor construction into any of these five states should be pricing that legislative outcome first. Read my full analysis here: https://theinnovationattorney.com/blog/ This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit theinnovationattorney.substack.com/subscribe

  6. Jul 28

    The Duress PIN Dilemma: Federal Prosecution and the Digital Border

    Federal prosecutors in the Northern District of Georgia charged Samuel Tunick under 18 U.S.C. Section 2232(a) in November 2025, the first known application of that destruction of property statute to a phone’s self triggered data wipe. Tunick had entered a duress PIN built into GrapheneOS while Customs and Border Protection agents held his phone at Hartsfield-Jackson Atlanta International Airport, and the device erased its contents instead of opening. He faces up to five years in prison for using a security feature he did not build, under a statute written for smugglers who dumped contraband overboard. The stop happened on January 24, 2025, as Tunick returned from a trip to the Dominican Republic. Agents pulled him into secondary inspection, told him a warrant was not required, and asked him to open his phone. Court filings describe what happened next. The screen went blank, flashed several times, and the phone appeared to restart. Agents seized the device anyway and released Tunick a short time later. His attorneys say the agents cited a search for child exploitation material without evidence to support it, and that the real interest was Tunick’s association with Defend the Atlanta Forest, the movement opposing the Atlanta Public Safety Training Center. What is a duress PIN and how does GrapheneOS implement it A duress PIN is a second passcode that does not open the phone. Entering it instead destroys the cryptographic keys protecting the phone’s encrypted data, an action indistinguishable from the outside from an ordinary restart. GrapheneOS built the feature without a confirmation prompt or any visible warning, so a person entering the code under pressure gives no sign of what the code actually does. In drafting incident response policies for hardware clients, the recurring gap is not the encryption itself. It is the absence of a plan for what happens when a device is seized, a gap this case now shows can carry criminal exposure rather than only a data loss. Does the border search exception let agents search a phone without suspicion In the Eleventh Circuit, yes. The border search exception traces to United States v. Ramsey, 431 U.S. 606 (1977), and gives the government authority to search people and property at the border without a warrant or individualized suspicion. Circuits disagree on how far that authority extends to phones. The Ninth Circuit required reasonable suspicion for a forensic search in United States v. Cotterman, calling it a computer strip search. The Fourth Circuit required individualized suspicion of a transnational offense in United States v. Kolsuz. The Eleventh Circuit rejected both positions in United States v. Touset, holding that a forensic search of a phone needs no more suspicion than a search of a suitcase. Because Tunick’s case sits in the Northern District of Georgia, Touset controls. In July 2026, the Fourth Circuit added United States v. Belmonte Cardozo, holding that even a manual phone search is routine and needs no suspicion, while the Electronic Frontier Foundation and the National Association of Criminal Defense Lawyers keep pressing appellate courts for a probable cause and warrant standard. Can the government force you to reveal your phone passcode No. The Fifth Amendment privilege against self incrimination protects a traveler from being forced to disclose a memorized passcode, under the act of production doctrine from Fisher v. United States, 425 U.S. 391 (1976). The Eleventh Circuit applied that doctrine to encrypted devices directly in a 2012 ruling, In re Grand Jury Subpoena Duces Tecum, finding that compelled decryption can violate the privilege unless the government already knows the person can access the device. Tunick was never asked to explain a key. He entered a code. That single fact is where the case’s novelty begins. Agents got a code, and the code they got was engineered to protect data rather than expose it. Is a data wipe destruction of property under Section 2232(a) That is the statutory question the court still has to answer. Section 2232(a) punishes destroying, damaging, wasting, disposing of, or otherwise taking action against property to prevent the government from taking lawful custody of it. Every prior prosecution under the statute involved a physical object: narcotics thrown from a boat, a vessel scuttled to avoid forfeiture, paper records burned during a raid. Tunick’s phone was never damaged. The government has physical custody of it right now. Defense counsel will argue that data is not the kind of property Section 2232(a) contemplates. Prosecutors will argue that the statute’s language covers any action taken to defeat the government’s authority over the object of a search, regardless of whether the object is physical or digital. Why do Tunick’s attorneys call this a selective prosecution Because the stated reason for the search does not match, in their telling, the reason agents actually cared about Tunick. Under United States v. Armstrong, 517 U.S. 456 (1996), a defendant claiming selective prosecution must show that similarly situated people were treated differently and that the decision to search or charge him was driven by an improper purpose. Tunick’s team argues the improper purpose here was his connection to Defend the Atlanta Forest. A ruling on the suppression motion is expected later in 2026. The ruling will decide more than one case. It will tell millions of travelers who run privacy hardened phones whether that choice creates criminal exposure the moment they cross a border. It will also test whether a decades old statute, written for smugglers and physical contraband, extends to a line of code that erases a key. Read my full analysis here: https://theinnovationattorney.com/wiping-data-at-the-border-5th-amendment-limits-and-criminal-exposure/ This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit theinnovationattorney.substack.com/subscribe

About

The Innovation Attorney is a publication about the intersection of venture capital, technology, public policy and law. theinnovationattorney.substack.com