Alert 03.18.26
New California AI Laws Are Here: Is Your Business Ready?
From pricing algorithms to data transparency, California’s new laws continue to solidify its reputation as the forerunner in regulating development and deployment of AI.
Shruti Bhutani Arora leads the Global Consumer Protection team at Pillsbury. She is a leading regulatory defense and compliance advisor at the intersection of consumer protection, data protection, cybersecurity, artificial intelligence, and national security-related data regulation.
Shruti represents technology companies, health tech and fintech platforms, gaming companies, ad tech businesses, digital media companies, and data center operators in complex, high-stakes matters involving regulatory scrutiny, enforcement risk and emerging technology governance. She delivers strategic, business-aligned counsel that enables innovation while mitigating enforcement, regulatory, and reputational exposure.
View More
Consumer Protection & Regulatory Defense
Shruti advises companies on compliance with federal and state consumer protection laws and represents clients in high-stakes investigations and enforcement actions before the Federal Trade Commission (FTC) and state attorneys general. Her work includes responding to civil investigative demands, subpoenas and enforcement proceedings involving digital platforms, advertising practices, subscription models, data-driven products and emerging technologies.
She counsels clients on advertising substantiation, endorsements and influencer marketing, social media campaigns, negative option and subscription programs, automatic renewals, ad targeting practices, media buying arrangements, and promotional marketing initiatives, including raffles, sweepstakes and contests. She works closely with clients to structure consumer-facing programs that withstand regulatory scrutiny while preserving commercial objectives.
Data Protection, Privacy & Governance
Shruti advises companies on data protection, privacy compliance, governance and regulatory defense across the evolving landscape of U.S. state comprehensive privacy laws and related regulatory regimes. She represents clients in regulatory investigations and enforcement actions involving privacy, data governance and cross-border data practices, including matters before the FTC and state attorneys general.
Her work spans biometric privacy laws, employee privacy laws, protections for minors’ data, social media regulation, cross-border data transfers, and sector-specific compliance frameworks. She designs and implements enterprise-wide privacy and governance programs and develops defensible compliance strategies that withstand regulatory scrutiny.
Shruti advises health tech companies on compliance with the Health Insurance Portability and Accountability Act (HIPAA), including privacy, security and breach notification requirements governing protected health information (PHI). She assists clients in preparing for and responding to HIPAA audits and investigations, strengthening compliance controls, and mitigating enforcement exposure. She counsels fintech and financial services companies on compliance with the Gramm-Leach-Bliley Act (GLBA), financial privacy obligations, and safeguarding requirements. Her work enables clients to operationalize defensible compliance frameworks across consumer data, sensitive personal data, financial information, health data, and infrastructure-related data environments.
She also advises companies on compliance with the U.S. Department of Justice’s Data Security Program (DSP) rule and related national security-driven data restrictions. Her work includes restricted transaction analysis, cross-border data transfer risk assessments, vendor and counterparty diligence, and implementation of operational safeguards addressing sensitive personal data and foreign access concerns.
Cybersecurity & Incident Response
Shruti advises companies on cybersecurity risk management, preparedness and breach response. She conducts tabletop exercises and incident response simulations to test escalation protocols, executive coordination and regulatory reporting obligations.
In the event of a security incident, she guides clients through forensic coordination, legal risk assessment, breach notification analysis under state, federal and sector-specific laws, and preparation of required notices to regulators and affected individuals. She also advises on regulatory engagement and communications strategies to mitigate enforcement and reputational exposure.
Artificial Intelligence
Shruti advises companies across the AI lifecycle, from model developers to deployers of AI systems, on governance, risk management and regulatory compliance. She counsels clients on the design, development, testing, and deployment of AI systems, including large language models, machine learning models, agentic AI tools and MCP servers used in both consumer-facing and employment contexts.
She also helps organizations design and implement practical compliance strategies, which include AI impact assessments, governance framework design, transparency and accountability measures, and integration of data protection and security safeguards from product conception through launch.
Shruti closely monitors legislative and regulatory developments in artificial intelligence and helps companies anticipate and operationalize emerging statutory and regulatory requirements.
View More
Speaking Engagements
View More
Education
J.D., University of Utah College of Law, 2014
LL.M., Intellectual Property, The George Washington University Law School, 2008
B.A./LL.B., Army Institute of Law, 2007
Admissions
California
Florida
Languages
Hindi
Punjabi