The AI Law Report — Issue 001 | 7 August 2026
The Law Begins to Test AI’s Boundaries
Global developments from the courts, regulators and public authorities
Issue 001 | Friday 7 August 2026
Published by AI Policies UK
This Week
This is the first edition of The AI Law Report. It draws together developments captured through our monitoring between 25 July and 7 August 2026. Subsequent editions will run Friday to Friday.
The period produced an unusually broad spread of activity. Three courts allowed AI-related claims past their first serious procedural test: the Delaware Superior Court refused to dismiss a defamation claim against Google over chatbot outputs, the Third Circuit revived antitrust litigation concerning AI-assisted hotel pricing, and the Southern District of New York allowed most of Reddit's data-scraping claim against Perplexity and several intermediaries to proceed. In Munich, a first-instance court found that the AI music service Suno had no right to process songs represented by the German collecting society GEMA, and ordered disclosure of revenue so that damages can be assessed.
The Ninth Circuit moved in the other direction, vacating the preliminary injunction that had restrained Perplexity's shopping agent from operating on Amazon, on the preliminary view that the users rather than the AI company were the parties accessing Amazon's systems.
On the regulatory side, 2 August was the principal commencement date. The EU AI Act's transparency provisions became applicable and enforcement machinery was stood up; California's AI Transparency Act became operative for large generative-AI providers on the same day. Germany's BaFin acquired express powers over AI use by banks and insurers on 29 July, and the MHRA published the findings of the second phase of its AI medical-device sandbox.
Two courts in Connecticut sanctioned lawyers for AI-generated citation errors, one of them after an express written warning at the outset of the case.
Finally, the Australian Attorney-General asked the Privacy Commissioner to give priority consideration to the privacy implications of AI-enabled smart glasses. No investigation has been opened and no finding has been made, but the referral is recorded here because it is exactly the kind of early-stage development this publication exists to track.
Courts & Litigation
Delaware court refuses to dismiss defamation claim over Google chatbot outputs
Jurisdiction: United States — Delaware
Court: Superior Court of the State of Delaware (Judge Meghan A. Adams)
Case: Robert Starbuck v Google LLC, C.A. No. N25C-10-211 MAA
Area: Defamation · Generative AI · Publisher liability
Stage: Motion to dismiss denied · Date: 24 July 2026 · Confidence: High
What happened. Robert Starbuck alleges that Google's Bard, Gemini and Gemma systems repeatedly generated false statements about him, including that he had been accused of sexual assault, had been convicted of criminal conduct, and had associations with a prominent white supremacist. He says he notified Google from December 2023 onwards, and again through its legal department in 2025, but that the outputs continued.
Google's motion to dismiss was denied in its entirety. The court held that third-party publication had been sufficiently pleaded, and declined to decide the effect of Google's inaccuracy disclaimers without evidence of their wording, prominence and presentation. On actual malice, which Starbuck must ultimately establish to the clear and convincing standard as a public figure, the court found it reasonably conceivable that repeated notifications could support the necessary inference, and was unwilling to assume without evidence that Google's legal department was organisationally separate from those responsible for managing AI output risk. The court also declined to strike an allegation that Google's AI had itself stated it was engineered to defame Starbuck, while expressly not holding that a chatbot's account of its own programming can establish corporate intent.
The underlying question. Whether an AI developer can be liable as the publisher of defamatory model outputs, and what a claimant must show about an organisation's internal knowledge to establish the state of mind defamation law requires. The allegations have not been tested. Nothing has been decided about their truth or about Google's responsibility.
What happens next. The case proceeds to discovery.
UK MP asks High Court to require model-level restrictions on Grok
Jurisdiction: England and Wales
Court: High Court of Justice, London
Case: Jess Asato MP v xAI
Area: Misuse of private information · Data protection · Non-consensual intimate imagery · Injunctive relief
Stage: Claim filed; no defence filed at time of reporting · Date: Reported 28 July 2026 · Confidence: High
What happened. The Labour MP Jess Asato has brought a claim arising from manipulated and sexualised images of her generated through Grok, including a video depicting her being drugged and prepared for sexual assault. Her case is that the harm was enabled by choices made in the system's design and training. Filings cited in reporting indicate that Grok's internal instructions prohibited assistance with clearly criminal activity while also stating that the system had no restrictions on certain adult sexual, offensive, violent or fictional content.
The notable feature is the remedy. Asato is seeking an order requiring xAI to introduce effective and permanent technical measures preventing Grok from generating non-consensual sexualised images of her, rather than damages or the removal of particular images.
The underlying question. Whether existing privacy and data-protection causes of action reach the design of a generative system rather than only its published outputs, and whether an English court will order a developer to alter model behaviour on an ongoing basis. A related question is how responsibility is divided where the model contributes abusive detail beyond what a user requested.
What happens next. xAI's response is awaited. No substantive hearing date has been reported.
Bombay High Court grants leave in deepfake claim against platforms
Jurisdiction: India
Court: Bombay High Court (Justice Abhay Ahuja)
Case: Nitin Gadkari v Meta, X, Google and unknown persons
Area: Deepfakes · Defamation · Intermediary responsibility · Territorial jurisdiction
Stage: Leave granted to institute the suit · Date: Order reported 28 July 2026 · Confidence: Medium-high — the order and hearing date are consistently reported, but the pleadings and full order text were not located through an official judgment source
What happened. India's road transport and highways minister alleges that deepfake and AI-generated posts falsely portrayed him as personally responsible for the country's ethanol-blended-fuel programme and claimed that he and his family profited from it. The proposed defendants include Meta, X, Google and unidentified individuals said to have created or circulated the material.
Because part of the alleged cause of action arose outside the court's territorial jurisdiction, Gadkari sought permission under Clause XII of the Letters Patent to bring the suit in Bombay. Justice Ahuja granted that permission. The court has not considered whether the material is defamatory or whether the platforms bear any responsibility.
The underlying question. How territorial jurisdiction is established where synthetic content is generated in one place, hosted in another and causes reputational harm in several, and what duties intermediaries owe once notified of AI-generated material making serious factual allegations about an identifiable person.
What happens next. A hearing on the requested permanent injunction was listed for 5 August 2026. No report of the outcome was located within this monitoring period.
Third Circuit revives antitrust claim over AI-assisted hotel pricing
Jurisdiction: United States — federal
Court: US Court of Appeals for the Third Circuit
Case: Cornish-Adebiyi and others v Caesars Entertainment and others
Area: Competition · Algorithmic pricing · Information sharing · Consumer protection
Stage: Dismissal reversed; proposed class action remitted · Date: 29 July 2026 · Confidence: High
What happened. Casino customers allege that major Atlantic City hotel and casino operators supplied commercially sensitive information, including real-time room prices and occupancy data, to Cendyn's Rainmaker revenue-management platform, which used AI-assisted algorithms to generate pricing recommendations for participating hotels. The claimants say the shared platform enabled competitors to align prices without communicating directly. A district judge dismissed the claim in October 2024 on the basis that the complaint did not adequately explain how the operators used one another's information once it had reached Cendyn.
The Third Circuit reversed, holding the allegations sufficient to proceed and observing that AI software may facilitate coordination by allowing competitors to align prices and share information without direct communication. The ruling establishes nothing about whether any defendant broke the law; it establishes that the alleged arrangement is plausible enough to warrant discovery. The decision diverges from an August 2025 Ninth Circuit ruling dismissing a comparable claim concerning Nevada casino hotels.
The underlying question. Whether the use of a common algorithmic pricing platform can support an inference of concerted action under federal antitrust law in the absence of direct communication between competitors.
What happens next. The case returns to the district court for further proceedings and discovery.
Munich court finds Suno infringed copyright in GEMA-represented works
Jurisdiction: Germany
Court: Munich Regional Court
Case: GEMA v Suno
Area: Copyright · Model training · Generative music · Damages
Stage: First-instance judgment; appeal available · Date: 31 July 2026 · Confidence: High
What happened. The German collecting society GEMA brought proceedings against the AI music company Suno concerning the processing of protected songs, including works associated with artists such as Alphaville, without the required licences. The court ruled that Suno did not have the right to process the protected works represented by GEMA, and ordered the company to disclose the revenue derived from the unlawful activity so that damages can be calculated. The quantum has not been determined.
Suno has said it disagrees with the decision and is considering its options, including an appeal.
The underlying question. Whether the ingestion, analysis or reproduction of copyrighted works in the course of developing and operating a generative system engages exclusive copyright rights.
What happens next. Damages remain to be assessed. An appeal is available and Suno has indicated it is under consideration. This is a first-instance decision in one jurisdiction and does not settle the European position.
SDNY allows most of Reddit's scraping claim against Perplexity to proceed
Jurisdiction: United States
Court: US District Court for the Southern District of New York (Judge Paul A. Engelmayer)
Case: Reddit Inc. v SerpApi LLC and others, No. 1:25-cv-08736
Area: Data scraping · Access controls · AI training data · Conspiracy
Stage: Motion to dismiss largely denied · Date: Late July 2026 · Confidence: High
What happened. Reddit alleges that Perplexity AI and several data-scraping companies, including SerpApi, Oxylabs and AWMProxy, obtained Reddit content without permission for use in Perplexity's AI-powered search service, circumventing technical and contractual restrictions on automated access. Reddit licenses its content to some AI companies, including Google and OpenAI, and says Perplexity had no comparable licence.
Judge Engelmayer rejected most of the attempt to dismiss. Reddit may continue to pursue claims that the defendants unlawfully circumvented protective measures to obtain content for AI use, and the court held that Reddit has standing to sue in respect of alleged misuse of its users' content. Some secondary claims were dismissed. No finding of liability has been made.
The underlying question. Whether content that is publicly viewable is thereby freely available for automated extraction and AI ingestion, and whether a downstream AI company can be liable where data reaches it through scraping intermediaries rather than through its own access to the source platform. The claim rests substantially on Reddit's position as platform operator and on its access controls, rather than solely on ownership of the underlying posts.
What happens next. Discovery proceeds.
Ninth Circuit vacates injunction against Perplexity's shopping agent
Jurisdiction: United States — federal
Court: US Court of Appeals for the Ninth Circuit
Case: Amazon.com Services LLC v Perplexity AI, Inc., No. 26-1444
Area: Agentic AI · Computer access · Platform rights · User authorisation
Stage: Preliminary injunction vacated; litigation continues in N.D. Cal. · Date: 4 August 2026 · Confidence: High
What happened. Perplexity's Comet browser includes an AI shopping agent able to log into a user's online accounts, browse products and place orders. Amazon sued in November 2025, relying principally on the Computer Fraud and Abuse Act, and obtained a preliminary injunction in March 2026 preventing the agent operating on Amazon.
The Ninth Circuit vacated that injunction, holding that Amazon had not shown it was likely to succeed on the CFAA claim because, on the evidence available at this stage, it was the users rather than Perplexity who accessed Amazon. The agent acted on the instructions of authenticated Amazon customers using their own accounts, and the court declined to treat Perplexity as the statutory accessor merely because its software performed the technical steps. The decision does not determine that Perplexity acted lawfully. Amazon has said it disagrees and is evaluating its next steps.
The underlying question. When a user instructs an AI agent to act within an account the user is entitled to use, who is the party that "accesses" the platform's computer for the purposes of computer-misuse legislation. This appears to be the first US federal appellate decision addressing the point directly.
What happens next. The substantive litigation continues in the Northern District of California.
Four defendants plead guilty in Minnesota Medicaid fraud involving ChatGPT-fabricated records
Jurisdiction: United States — District of Minnesota
Authorities: US District Court, District of Minnesota; Department of Justice; FBI; IRS Criminal Investigation; HHS Office of Inspector General
Case: Prosecutions concerning Brilliant Minds Services LLC; defendants Moktar Hassan Aden, Mustafa Dayib Ali, Khalid Ahmed Dayib and Abdifitah Mohamud Mohamed
Area: Criminal fraud · Healthcare · Fabricated documentary evidence
Stage: Guilty pleas entered; sentencing outstanding · Date: Pleas 7–23 July 2026; announced 24 July 2026 · Confidence: High
What happened. The defendants operated Brilliant Minds Services LLC as a provider under Minnesota's now-defunct Housing Stabilization Services Medicaid programme. They enrolled around 350 people and claimed reimbursement for housing-support services that were either not provided or substantially inflated. When insurers sought supporting records, the defendants used ChatGPT to fabricate documentation making the services appear genuine. The admitted fraud involved approximately $2.2 million in Medicaid payments between April 2022 and April 2025. All four have pleaded guilty to one count of wire fraud, each facing a statutory maximum of 20 years.
The underlying question. The offence is wire fraud and not an AI-specific crime. The development is recorded here because of the role AI played: not in originating the fraud but in retrospectively manufacturing an apparently coherent documentary history once the claims came under scrutiny. The Department of Justice has described the use of AI to further healthcare fraud as a growing enforcement concern.
What happens next. Sentencing dates have not been fixed.
xAI challenges Minnesota law restricting image "nudification"
Jurisdiction: United States — Minnesota
Court: Federal court, Minnesota
Area: Non-consensual intimate imagery · Freedom of expression · Provider-level duties
Stage: Claim filed · Date: 27 July 2026 · Confidence: Medium-high — the filing and its central argument are consistently reported; the pleadings were not reviewed directly
What happened. xAI filed a federal challenge to a Minnesota statute due to take effect on 1 August 2026, which restricts services allowing users to alter or generate images depicting the intimate body parts of identifiable individuals. Reporting indicates the law exposes providers to penalties of up to $500,000 per generation or alteration. xAI argues the provision is an overbroad, content-based restriction contrary to the First Amendment, and says it already prohibits users from generating non-consensual sexualised images.
The underlying question. Whether a state may restrict what an AI system is technically capable of producing, as distinct from penalising harmful use after it occurs.
What happens next. No hearing date identified within this period.
Professional Regulation & Court Sanctions
Two decisions in Connecticut during the period concerned lawyers filing material containing AI-generated citation errors. They are reported together because they arise in the same jurisdiction within days of each other, but they are separate matters.
Connecticut Supreme Court sanctions lawyer and firm over ChatGPT-altered citations
Jurisdiction: Connecticut, United States
Court: Connecticut Supreme Court
Cases: TOV Realty, LLC v Angel Suarez and others, SC 21183; Kosel Equity, LLC v Mark MacGregor and others, SC 21184
Area: Professional competence · Supervision · Hallucinated authorities · Confidentiality
Stage: Final sanctions order · Date: 31 July 2026, reported 3–4 August · Confidence: High
What happened. Attorney Ian Gottlieb conducted his research through LexisNexis and verified the quotations and authorities in his drafts. He then passed those drafts through ChatGPT to improve their organisation and writing. The system added new authorities and altered existing citations. Neither Gottlieb nor the colleagues reviewing the documents rechecked the citations before filing. Approximately seven erroneous or unverified citations appeared across the applications and later briefs. The legal propositions themselves remained substantively established, which contributed to the alterations going unnoticed.
The court found negligence rather than any attempt to deceive. Gottlieb accepted responsibility and admitted a breach of the professional duty of competence. The court ordered continuing legal education in ethics and law-office management including three hours specifically on generative AI, and notification to other jurisdictions in which he is admitted. Responsibility was attributed to the firm as well as the individual, on the basis that other partners reviewed the filings and the firm lacked appropriate AI policies and procedures.
The court also stated that competence in using generative AI includes understanding the implications for privilege, confidentiality and work product, particularly where a publicly accessible platform is used. It did not decide that privilege had been waived in these cases.
The underlying question. Whether verification carried out before a document is passed through an AI editing tool discharges the duty of competence in respect of the document eventually filed.
Federal judge imposes $3,500 sanction after express pre-briefing warning
Jurisdiction: United States — District of Connecticut
Court: US District Court for the District of Connecticut (Judge Vernon D. Oliver)
Case: Barteca Intermediate Holdings, LLC and Barteca Holdings, LLC v tacobarn Newtown LLC and tacobarn Greenwich LLC, No. 3:26-cv-00250
Area: Hallucinated authorities · Rule 11 · Candour to the court
Stage: Sanctions imposed; trademark litigation continues · Date: 5 August 2026 · Confidence: High as to the sanction and procedural history; medium-high as to the detail of the lawyer's AI workflow, as the full order was not available through an openly accessible official source
What happened. Defence lawyer Hilary B. Miller filed two motions containing inaccurate authorities and fabricated or materially incorrect quotations presented as coming from decided cases. On 19 February 2026, the day the litigation was filed, Judge Oliver had issued a case-specific notice warning parties and counsel that AI-generated propositions and authorities must be independently verified. In June the court ordered Miller to show cause. On 5 August it imposed a $3,500 sanction.
The underlying question. What sanction is appropriate where a lawyer files AI-affected material after receiving express written notice from the court identifying that precise failure mode.
What happens next. The underlying trademark proceedings continue. The sanction does not affect the merits.
Regulators & Enforcement
EU AI Act transparency obligations become applicable and enforcement machinery begins
Jurisdiction: European Union
Authorities: European Commission, EU AI Office and Member State competent authorities
Instrument: Regulation (EU) 2024/1689 (EU AI Act), Article 50 and related provisions
Area: Generative AI · Synthetic content · Chatbots · Deepfakes · General-purpose AI
Stage: Guidance published; enforcement channels launched 31 July; rules applicable from 2 August · Date: Late July to 2 August 2026 · Confidence: High
What happened. Three connected steps occurred within the period. The Commission published final guidelines on the Article 50 transparency obligations, prepared with Member States, the AI Board and other stakeholders following public consultation. On 31 July it announced that the AI Office and national authorities would begin enforcing the next applicable stage of the Act, and identified operational reporting channels through which suspected non-compliance can be raised, including by downstream providers of general-purpose models. On 2 August the relevant provisions became applicable.
In substance, providers must design directly interactive systems so that individuals are informed they are dealing with AI, and providers of generative systems must apply machine-readable marking capable of supporting detection of AI-generated or manipulated content. Deployers have disclosure obligations in specified circumstances including deepfakes and certain AI-generated text on matters of public interest. Organisations not adhering to the voluntary transparency code must demonstrate compliance by an alternative and equivalently adequate route; the Commission has published a list of more than 180 signatories to that code.
One point of accuracy matters here. Not all high-risk obligations commenced on 2 August. Following the AI Omnibus amendments, obligations for certain high-risk systems in areas including employment, education, biometrics, migration and critical infrastructure apply from 2 December 2027, with a further tranche from 2 August 2028. It would be inaccurate to describe all EU AI Act high-risk obligations as presently enforceable.
The underlying question. How the transparency duties apply across the value chain, in particular where responsibility sits between a model provider, a deployer and an intermediary, and what constitutes an equivalently adequate alternative to the voluntary code.
What happens next. No named infringement proceedings were identified during the period. Enforcement capacity is now in place and reporting channels are open.
California AI Transparency Act becomes operative
Jurisdiction: California, United States
Enforcement: California Attorney General, city attorneys and county counsel
Instrument: California AI Transparency Act, SB 942 as amended by AB 853
Area: Synthetic-content provenance · Deepfakes · Consumer protection · Model licensing
Stage: Statutory obligations operative · Date: 2 August 2026 · Confidence: High
What happened. The Act applies to providers of publicly accessible generative-AI systems with more than one million monthly users or visitors in California, and became operative on 2 August following amendment by AB 853.
Covered providers must make available a free, publicly accessible AI-detection tool allowing content or a URL to be checked against their system, returning system provenance information while avoiding disclosure of personal provenance data, and supporting API access. Providers must offer users a manifest disclosure — a clear and conspicuous indication that content is AI-generated — and must include a latent disclosure embedded in qualifying image, video or audio content using widely accepted standards, designed to be permanent or exceptionally difficult to remove where technically feasible. Where a provider knows that a licensee has modified a licensed system so that it can no longer generate the required disclosures, the licence must be revoked within the statutory period.
Violations attract civil penalties of $5,000 per violation. Injunctive relief is available in specified circumstances involving third-party licensees.
The underlying question. How a person, platform or investigator can determine whether apparently authentic media was generated or altered by a particular system. The Act places design and provenance duties on large providers rather than only on those who publish synthetic content.
What happens next. No enforcement action has been announced.
BaFin acquires supervisory powers over AI use by banks and insurers
Jurisdiction: Germany
Regulator: Federal Financial Supervisory Authority (BaFin)
Area: Financial services · Insurance · Creditworthiness assessment · Discrimination · Transparency
Stage: Statutory powers in force · Date: 29 July 2026 · Confidence: High
What happened. German legislation expanding BaFin's mandate entered into force on 29 July, allowing the regulator to supervise compliance with AI requirements across banks and insurers and to impose fines. Its stated areas of attention include creditworthiness assessment, transparency, discriminatory outcomes and prohibited practices involving sensitive personal information. BaFin President Mark Branson said the regulator would seek to ensure fair access to financial services and prevent discrimination arising from AI use. No enforcement decision against a named institution has been announced.
The underlying question. The development gives a sector regulator direct responsibility for examining AI systems as a distinct supervisory concern, rather than only through general financial and data-protection law.
What happens next. Supervisory activity begins. No named proceedings identified.
MHRA publishes Phase 2 findings from its AI medical-device sandbox
Jurisdiction: United Kingdom
Regulator: Medicines and Healthcare products Regulatory Agency
Document: AI Airlock Sandbox Phase 2 Programme Report
Area: Healthcare · Medical devices · Generative AI · Human oversight · Post-market surveillance
Stage: Sandbox findings and recommendations; not formal statutory guidance · Date: 27 July 2026 · Confidence: High as to substance; medium-high as to precise timing, as GOV.UK records the date but not the time
What happened. Phase 2 of the AI Airlock ran from April 2025 to March 2026 and examined how an AI system's intended purpose is defined and maintained, how iterative change is managed through predetermined change-control plans and post-market surveillance, and how AI-powered in-vitro diagnostics should be evaluated.
Three findings are of wider interest. First, the report states that human-in-the-loop arrangements may become less effective over time as clinicians grow familiar with a system and apply less scrutiny to its outputs, so oversight must be monitored as a changing condition rather than assumed as a fixed control. Second, LLM-based products without active guardrails may begin performing functions outside their specified purpose through model behaviour alone — a system intended to structure clinical information could begin influencing diagnosis or prioritisation without any authorised redesign. Third, the MHRA distinguishes statistically detectable performance change from clinically significant change, and says surveillance thresholds should be tied to clinical consequence.
The report is expressly a sandbox report rather than MHRA guidance. There is no enforcement decision against any company.
The underlying question. Whether a medical-device framework built around relatively static products can adequately govern systems whose behaviour and clinical influence may change after deployment.
What happens next. The findings will inform future policy, the National Commission into the Regulation of AI in Healthcare, and the design of Phase 3.
Government & Public Authorities
Australian Attorney-General refers smart-glasses privacy concerns to the Privacy Commissioner
Jurisdiction: Australia
Authorities: Attorney-General Michelle Rowland; Office of the Australian Information Commissioner; Privacy Commissioner Carly Kind
Area: Privacy · Biometric data · Facial recognition · Wearable AI · Consent
Stage: Government referral and regulatory prioritisation; no investigation opened, no determination made · Date: 6–7 August 2026 · Confidence: High as to the referral and statements; medium as to what process will follow
What happened. The Attorney-General wrote to the Privacy Commissioner asking the OAIC to give priority consideration to the privacy implications of smart glasses. The letter follows the increasing availability of inexpensive camera-equipped glasses and of more sophisticated products combining cameras, microphones, AI assistants and potentially biometric or facial-recognition capability. Rowland highlighted the difficulty people may have in knowing they are being recorded, and the potential for disproportionate effects on women and children.
The government has not directed the OAIC, which is independent, to reach any particular conclusion. Separately, Commissioner Kind warned publicly that widespread adoption could fundamentally alter ordinary interpersonal privacy and may require consideration of new laws.
The underlying question. Australia's Privacy Act generally regulates businesses and government agencies rather than the purely personal activity of individuals. That creates a potential gap where one person wears a device capable of continuously recording others, while a technology company subsequently receives, stores, analyses or processes what is captured. Commissioner Kind has noted that where a company receives personal information collected through surveillance wearables, existing obligations can apply to that company. Australia already treats biometric information used for automated verification or identification as sensitive, and previous OAIC facial-recognition determinations have emphasised necessity, proportionality, transparency and consent.
What happens next. No formal investigation has been announced. Whether the OAIC opens one, issues guidance, or recommends legislative change is not yet known. This should not be reported as an enforcement action.
Related AI Policies UK resource AI Wearables Risk Policy, first published 2026.
UK opens Legal Services Advisory AI Growth Lab
Jurisdiction: United Kingdom
Authorities: Department for Business, Innovation, Science and Trade; Legal Services Board; Solicitors Regulation Authority; Council for Licensed Conveyancers; Information Commissioner's Office
Document: Advisory AI Growth Lab: Legal Services
Area: Legal services · Professional regulation · Data protection · Consumer protection · Access to justice
Stage: Applications opened; no regulatory decisions or exemptions · Date: 3 August 2026 · Confidence: High
What happened. The government launched an advisory AI sandbox focused initially on legal services, intended to help law firms, LawTech businesses, AI developers and public bodies understand how existing rules apply to AI-enabled products. Applications close on 27 September 2026, and selected participants will receive up to nine months of regulatory engagement. Applications are reviewed jointly by the participating regulators, so applicants need not identify the correct regulator in advance.
The programme is limited to questions capable of being addressed under existing frameworks. It cannot amend legislation, create exemptions or remove obligations, and participation does not constitute approval, authorisation or endorsement.
The underlying question. A single legal AI product may simultaneously engage professional regulation, data protection, consumer protection and the reserved-activities framework, each with a different responsible regulator.
What happens next. Applications remain open until 27 September 2026. Lessons are to be shared in aggregated and anonymised form where appropriate.
UK government says binding regulation of advanced models remains available
Jurisdiction: United Kingdom
Authority: UK government; statement by AI Minister Kanishka Narayan
Area: Frontier-model safety · Pre-deployment testing · Regulatory policy
Stage: Policy statement; no consultation, bill or binding rule announced · Date: Reported 3–4 August 2026 · Confidence: High that the statement was made; low as to any prediction about legislation
What happened. The AI Minister said the government would consider regulating advanced AI models if the present voluntary arrangements no longer provided sufficient public protection. Under those arrangements, major developers give the AI Security Institute access to frontier models for capability and risk assessment before deployment. The government continues to rely principally on existing sector regulators rather than a dedicated horizontal AI regulator.
The underlying question. This is not a new legal obligation and should not be read as an announced legislative programme. Its significance is that the continuation of voluntary oversight has been explicitly linked to whether it produces adequate protective outcomes.
What happens next. No consultation or draft legislation has been announced.
China publishes draft cyberbullying law covering AI-generated abuse
Jurisdiction: People's Republic of China
Regulator: Cyberspace Administration of China
Area: Online safety · AI-generated abuse · Platform responsibility · Identity verification
Stage: Draft legislation open for consultation · Date: Published 29–30 July 2026; consultation closes 28 August 2026 · Confidence: High as to the published proposal; medium as to its final form
What happened. The cyberspace regulator released draft legislation addressing online bullying, including content generated or distributed using AI. The proposal would apply to activity within China and to overseas organisations or individuals targeting the country. Proposed platform duties extend beyond removing reported content to identifying and tracing the use of AI in generating or spreading abusive material, with additional obligations concerning identity verification and instant-messaging functions. Schools would be required to include anti-cyberbullying material in their curricula. Proposed sanctions apply to online service providers in breach.
The underlying question. How responsibility should be assigned where AI systems contribute to the creation, alteration, amplification or circulation of abusive content, rather than only to its original authorship.
What happens next. Consultation closes on 28 August 2026. These are proposals, not law.
Developments to Watch
Ireland — High Court Practice Direction HC 142. A practice direction on the use of generative AI in civil proceedings was issued on 29 July 2026 and takes effect on 1 September 2026. It will be covered when it comes into operation.
Alabama — State Bar AI ethics guidance. Guidance issued on 23 July 2026, immediately before this reporting period, states that lawyers remain responsible for AI-assisted work, must verify citations against authoritative legal databases, should prefer enterprise or closed systems for confidential information, and cannot bill for hypothetical hours saved by AI, though they may charge for actual review, correction and professional judgment. It acknowledges unresolved privilege risks where client information is entered into AI systems. Recorded here as a baseline.
United States — privilege and work product in AI prompts. Commentary published on 24 July 2026 synthesised several federal decisions on whether AI prompts and outputs attract privilege or work-product protection, including Tremblay v OpenAI, Concord Music Group v Anthropic, United States v Heppner, Warner v Gilbarco, Morgan v V2Xand Conservation Law Foundation v Shell Oil. The pattern reported is that courts are applying conventional privilege, work-product and waiver doctrines to the particular workflow rather than treating prompts as categorically protected or categorically discoverable, with outcomes turning on who created the prompt, at whose direction, on what platform, and whether the output was relied upon. We have not independently reviewed each underlying ruling; the Conservation Law Foundation order was stayed pending review and its authority is correspondingly limited. Noted as an emerging line of authority rather than a decided development.
Western Australia — judicial commentary. Chief Justice Peter Quinlan of the Supreme Court of Western Australia delivered a lecture titled "What the Machine Doesn't Know: Humanity and Artificial Intelligence" in Sydney on 6 August 2026. The event is confirmed, but no reliable transcript or authoritative account of the remarks was located within this period, so no propositions are attributed to him here.
United States — OpenAI and IYO settlement. OpenAI, Io Products and the wearable-technology company IYO informed the Northern District of California in late July that they had settled IYO's trademark claim in principle, and requested a short pause to finalise terms. Terms were not disclosed.
Editorial note
The AI Law Report is an independent editorial publication from AI Policies UK bringing together significant judicial, regulatory and public-authority developments involving artificial intelligence. It reports developments for information and educational purposes and does not provide legal advice or predict legal outcomes. Where possible, reporting is verified against judgments, filings, regulatory publications and other primary sources.
Where primary documentation could not be located, this is stated in the relevant entry.
Next edition: Friday 14 August 2026.