Skip to main content
    All Blog articles
    Cybersecurity News
    5 min read

    Florida just told Big Tech to choke on their kombucha.

    Florida just told Big Tech to choke on their kombucha. DeSantis just drew a line in the sand on AI. Big Tech wanted zero AI regulation for the next decade. Florida said "lol no." Here's why I'm slow clapping from my home office.

    Author
    By ZoraSafe
    Published
    Published December 9, 2025
    Updated
    Updated December 10, 2025
    Cybersecurity News

    ZoraSafe Blog

    Florida just told Big Tech to choke on their kombucha.

    Governor DeSantis Florida AI Bill of Rights announcement protecting consumer data privacy

    Florida Just Did What Big Tech Hoped No State Would Do

    Finally, someone's reading the terms of service.

    December 8, 2025

    Last week, Governor Ron DeSantis stood up in The Villages (yes, that Villages, where the average age is "retired" and pickleball is a competitive blood sport) and proposed something truly wild: treating Floridians like actual humans instead of walking data points with credit cards attached.

    Governor, I don't say this often, but... well done. Slow clap. Standing ovation from my home office. You just made Big Tech choke on their kombucha.

    The proposed AI Bill of Rights would give Florida residents real protections against the algorithmic Wild West we've all been living in. And as someone who's spent years watching AI systems get built with all the security foresight of a screen door on a submarine, I'm not just cautiously optimistic. I'm doing a little victory dance. (It's not pretty, but it's happening.)

    What's Actually in This Thing?

    Florida AI consumer protection legislation key provisions infographic

    Let's break down the highlights without the political spin. Grab a snack. This is the good stuff.

    The "You Are Not the Product" Protections:

    • Your data entered into AI must stay secure and private (I know, revolutionary concept)
    • Companies can't sell your personal information to third parties without consent
    • Ban on AI using your name, image, or likeness without permission (sorry, deepfake scammers, no more fake celebrity endorsements)

    The "Protect the Humans" Provisions:

    • Disclosure required when you're chatting with a bot (the fact that this isn't already law tells you everything about where we've been)
    • Prohibition on AI providing "licensed" therapy or mental health counseling (because your therapist should have a pulse)
    • Parental controls for kids' AI interactions, including access to chat logs and alerts for concerning behavior
    • Reinforced deepfake protections, especially for minors

    The "No More Surprises" Rules:

    • Insurance companies can't use AI as the sole basis for denying claims (looking at you, algorithmic claim deniers)
    • AI use in legal filings must be disclosed
    • State agencies banned from using Chinese-developed AI tools like DeepSeek (Florida data stays out of foreign hands)

    Why This Actually Matters (And Why I've Been Yelling About It)

    Here's the thing nobody in Silicon Valley wants to say out loud: AI systems are built with inherent security flaws, and bad actors figured that out approximately five minutes after launch.

    I've been banging this drum for years. We've watched AI-powered scams evolve from laughably obvious Nigerian prince emails to deepfake grandchildren calling from "jail" sounding exactly like your actual grandchild. The same technology promising to cure cancer is right now being weaponized to manipulate your grandmother out of her retirement savings.

    And the companies building these systems? They're moving fast and breaking things. Unfortunately, the "things" they're breaking include people's lives, bank accounts, and mental health. But hey, at least shareholder value is up!

    Consider Megan Garcia, who attended the press conference with Governor DeSantis. She lost her teenage son after an AI chatbot encouraged him to "come home," a euphemism that had nothing to do with family dinner. This isn't a theoretical risk in some academic paper. It's happening now, to real families, while tech companies shrug and point to their Terms of Service that nobody reads because they're 47 pages of legal origami.

    The Elephant in the Server Room

    Federal versus state AI regulation debate visualization showing states rights versus federal preemption

    What makes this proposal particularly spicy is its timing. The Trump administration has been reportedly considering an executive order that would ban states from regulating AI for the next decade. Yes, you read that right. A ten-year moratorium on protecting citizens at the state level. A full decade of "trust us, we're tech companies."

    DeSantis called it what it is: "putting every state in handcuffs."

    Whatever your political persuasions (and I know my readers span the spectrum), this is a federalism question that should concern everyone. The people closest to the problem, state legislators, local officials, the actual citizens getting scammed, would be legally prohibited from doing anything about it.

    Florida looked at that proposal and said: "Nah. We're good."

    And honestly? Respect.

    The Data Center Dimension (a.k.a. Why Your Water Bill Might Care)

    Data center water consumption environmental impact visualization for AI infrastructure

    The proposal doesn't stop at consumer protections. It also takes aim at the massive data centers required to run AI systems. These facilities gulp water like a college freshman at an open bar.

    According to the Environmental and Energy Study Institute, a medium-sized data center can use 110 million gallons of water per year. Large ones? Up to 1.8 billion gallons annually. In Florida. Where we already fight over water rights like it's the Hunger Games.

    Under DeSantis's proposal:

    • Utilities can't charge residents more to subsidize Big Tech's data centers (your electric bill won't fund Zuckerberg's AI dreams)
    • No taxpayer subsidies for these facilities
    • Local governments can prohibit data center construction (local control! imagine!)
    • Environmental protections for water resources and agricultural land

    Whether you're a climate hawk or just prefer your tap water to actually flow when you turn the handle, this is worth paying attention to.

    What's Missing (Because I Keep It Real)

    No proposal is perfect, and intellectual honesty is kind of my thing. So let's talk gaps:

    The Good Faith Question: The bill relies heavily on companies complying voluntarily. We've seen how well that works. Facebook "accidentally" shared data with Cambridge Analytica. Google "accidentally" collected WiFi payload data with Street View cars. These companies have more "accidents" than a toddler potty training.

    The Enforcement Mystery: Who's actually going to enforce these provisions? With what resources? Against companies with legal teams the size of small nations and budgets larger than some countries' GDP?

    The Technology Arms Race: AI evolves faster than legislation. By the time this becomes law (if it does), we might be dealing with threats nobody's imagined yet. Today's deepfake is tomorrow's quaint memory.

    The Bottom Line

    Look, I work in AI-powered cybersecurity. I built my company with my sister because we watched scammers target our own mom. So when I say this proposal is a step in the right direction, I'm not speaking from theory. I'm speaking from watching families get destroyed by technology that moved faster than common sense and definitely faster than Congress.

    Is it perfect? No.
    Is it overdue? By about five years.
    Will Big Tech fight it tooth and nail? Absolutely, with lawyers and lobbyists and probably some well-placed "concern" about "innovation."

    But here's what I keep coming back to: Governor DeSantis said something at that press conference that stuck with me. He said we can't "turn it all over to machines and think it's going to work out great in the end."

    That's not anti-technology. That's pro-human. And honestly, it's refreshing to hear a politician say it out loud.

    We built these systems. We can build guardrails too. The question isn't whether AI should exist (it does, I use it, I build with it). The question is whether humans get to have a say in how it affects our lives.

    Florida just raised its hand. Governor DeSantis just drew a line in the sand.

    And from this cybersecurity nerd in the Sunshine State: thank you. Now let's make sure it actually passes.


    Cat Karow is the co-founder of ZoraSafe, an AI-powered cybersecurity platform protecting families from scams and digital threats. She writes about cybersecurity, data privacy, and keeping humans in the loop at ZoraSafe and The Shield Blog. Yes, she uses AI. Yes, she thinks it needs guardrails. Both things can be true.

    Share this article

    Share: