Wholestory

Last Updated: September 19, 2026

Law & Governance: The Rules Being Written

Three binding California statutes in eight days. On September 9, SB 813 and AB 1405 — the state describes the first as making California the first in the nation to require assessments by independent verification organisations, and the second as requiring third-party audits of AI systems. On the 16th, SB 1050, requiring explicit disclosure on any advertisement using AI-generated performers and barring continued use of one found in violation. Then, on the 18th, a directive that is not a law at all. Newsom ordered two agencies to recommend statutory changes by November 16: external safety evaluators at AI companies, independent verification of the safety frameworks already mandated, a route to requiring a ‘kill switch’, and a wider definition of the incidents companies must report — to cover ‘a range of loss-of-control incidents’. Several mirror SB 1047, which he vetoed in 2024. Existing law sets the reporting bar at 50 deaths, chemical or biological weapons, or $1 billion in damage, which the recent agent-driven hackings do not reach. He has also floated a special session or executive action, and called the new laws ‘the floor, not the ceiling’.

The Whole Story

AI's rules are being written in three places that do not talk to each other: courtrooms applying statutes drafted decades before the technology, legislatures drafting new ones, and executives issuing orders that bypass both. The three move at different speeds and often in opposite directions, and the gap between what is announced and what is enforced has become the most reliable feature of the field.

The courts came first, because plaintiffs did not need a new law. Copyright suits over training data have run since January 2023, when visual artists sued Stability AI and Getty Images followed with a complaint over twelve million photographs; The New York Times sued OpenAI and Microsoft that December. The first US merits ruling, in February 2025, went against the AI company. Then in June 2025 Judge William Alsup drew the line that still governs American copyright practice: training a model on lawfully acquired books is fair use, but downloading pirated copies to do it is not. Anthropic settled the resulting class action for $1.5 billion in September 2025 — the largest copyright settlement on record — and a successor judge approved it in July 2026 at roughly $3,000 a work, expressly reasoning that success at trial was not assured. No court has yet held that unlicensed training is generally unlawful, and the rulings that come closest are elsewhere: a Munich court found in November 2025 that memorising song lyrics exceeds Europe's text-and-data-mining exception, and a Delhi judge found in July 2026 that India's fair-dealing exception stretches the other way, far enough to cover a closed corporate training process.

Running alongside it is an older question the technology has made urgent: when a machine acts, who is answerable? The answer has mostly been the company that deployed it. A Canadian tribunal held Air Canada to what its chatbot told a passenger in February 2024 and rejected outright the submission that the chatbot was a separate legal entity; a US court let a wrongful-death suit against Character.AI proceed in May 2025 by treating the model as a product; a German appeals court ruled in May 2026 that running a chatbot is the operator's own commercial act, whatever probability produced the words. California bars the defence by statute. But that line was drawn under contract, tort and product law, and where a different statute is asked the answer inverts: in August 2026 a federal appeals court held that under America's 1986 anti-hacking law an AI agent is a tool rather than a person, so it is the user, not the company, who reaches into someone else's computers — while pointedly declining to say anything about liability in tort. China has now answered the question wholesale rather than case by case: on 7 September 2026 its Supreme People's Court issued 24 articles of adjudication rules telling every court below it how to decide AI disputes — cloned faces and voices infringe personality rights, a provider that is told its system produced infringing content and is slow to act is liable, and so is a user who prompted for it on purpose. In the meantime the enforcement that exists in the West is being brought under laws that mention neither AI nor agents. The Federal Trade Commission banned Rite Aid from facial recognition in 2023 and opened a sweep against deceptive AI claims in 2024; a state medical board sued a chatbot company for practising medicine without a licence; Florida sued OpenAI and its chief executive for deceptive trade practices; and fifteen attorneys general jointly demanded document preservation and a halt to a category of experiments after one of those experiments escaped.

Legislatures have had a harder time. The EU AI Act entered into force in August 2024 as the world's first comprehensive statute, and has been retreating from its own timetable ever since: in July 2026 the Digital Omnibus amended the Act itself, pushing the high-risk obligations from August 2026 to December 2027 and, for AI inside machinery and toys, to August 2028. The register those obligations depend on does not exist and is not expected before late 2027. Britain has legislated nothing comparable; the instrument it passed in 2026 obliges its data regulator to write an AI code of practice that will not take effect until 2027. In the United States there is no federal statute at all. Colorado passed the first comprehensive state law in May 2024, over its own governor's written reservations; the legislature postponed it twice, xAI sued to enjoin it, the Justice Department intervened against it, a court froze it before it ever applied, and in May 2026 the state repealed and re-enacted it as a narrower regime that does not take effect until 2027. State laws that do bite tend to be narrow ones — a hiring-audit rule in New York City, deepfake and nudification bans — and those are now being met at the courthouse door on First Amendment grounds.

What has filled the vacuum is executive power, and it changes hands. Biden's Executive Order 14110 of October 2023 imposed reporting duties on frontier developers; Trump revoked it on his first day in office. What replaced it works differently: an order of December 2025 directed federal agencies to contest state AI laws, and an order of June 2026 built a federal review gate for the most capable models — voluntary by its own terms, and triggered by a classified benchmark that the NSA director alone applies. The Commerce Department has meanwhile shown it does not need any of this, restricting a company's models through export-control letters issued without notice or comment.

So four questions are open. Whether unlicensed training is lawful is unresolved in the United States and answered opposite ways in Germany and India. Whether a company answers for what its agent does depends, in the United States, on which statute a plaintiff reaches for — and the court that said least about it said so deliberately; China has simply written the answer down. Whether written rules can be enforced is a resource question the EU is about to test with thirty-four compliance staff. And whether a threshold nobody outside an intelligence agency can inspect is a workable basis for a legal obligation is a question the first designation will start to answer.

Continue Reading →

AI Copyright: Who Owns the Training Data

ItemStatusFigureAs of
Microsoft Copilot Copyright CommitmentVendor indemnity: Microsoft absorbs commercial customers' copyright exposure over Copilot outputOffered$0 to customerSep 7, 2023
Bartz v. Anthropic (pirated books)Authors' class action over pirated books used to train Claude; No. 24-cv-5417Settled$3,000 / workJul 21, 2026
Bartz v. Anthropic (plaintiffs' fees)Court-set price of winning the pirated-books caseAwarded$101.56M feesJul 21, 2026
Concord, UMPG & ABKCO v. Anthropic (lyrics)Music publishers' statutory-damages claims over song lyrics used to train ClaudeSought$150,000 / work maxJul 22, 2026
GEMA v. SunoDamages for training on and reproducing six protected works; 42 O 763/25Amount pendingNot yet setJul 31, 2026
Round Hill Music v. Suno and v. AnthropicStatutory damages over a music catalogue used to train two model builders; reported Nos. 5:26-cv-08507 (Suno) and 5:26-cv-08505 (Anthropic)SoughtUp to $1B / caseAug 17, 2026
BMG — Suno global allianceOpt-in licence over BMG's recorded and publishing repertoire, settling Suno's prior unlicensed useSettledTerms undisclosedAug 12, 2026
Aug 17, 2026 · latest
What a work is worth: settlement figures, statutory ceilings, and fee awards, matter by matter.

Competing summary-judgment motions in the New York Times’ case against OpenAI and Microsoft ask Judge Sidney Stein to decide whether training on copyrighted work is fair use. Almost every AI copyright ruling so far has been at the pleading stage, deciding only whether a claim may proceed; this would decide the question. Across 105 classifiable US filings — 89 litigation families — 77 per cent sit in two courts, and the count has gone 8, 15, 32, 47 across four years. What is inside them is moving: of 47 filings dated 2026, 33 allege training, 28 raise DMCA theories, and 14 allege the material was unlawfully acquired, against six of 32 a year earlier. Courts have started separating three questions — whether training is fair use, whether the material was lawfully obtained, and whether outputs infringe. Two pleading-stage rulings show the other pattern: core copyright claims surviving while DMCA theories fail. Cohere lost its motion to dismiss entirely, on 75 cited examples of alleged copying.

Read More →

Who Regulates AI in America

ItemStatusAs of
NYC Local Law 144 (AI hiring audits)Bias-audit, disclosure and notice duties for automated employment decision toolsIn forceJul 5, 2023
Colorado SB24-205 (AI Act)Algorithmic-discrimination duties for high-risk systems in consequential decisionsRepealed / re-enactedMay 14, 2026
California SB 1047 (frontier-AI safety)Safety protocols, shutdown capability and audits for the largest frontier modelsVetoedSep 29, 2024
California AB 2013 (training-data transparency)Public disclosure of generative-AI training-data summaries; in force since 2026 and under appealIn forceMar 4, 2026
California SB 896 (GenAI risk analysis)State risk analysis of generative-AI threats to critical infrastructureEnactedSep 29, 2024
Texas TRAIGA (HB 149)Bans on government social scoring and harmful AI; AI Council and regulatory sandboxEnactedJun 22, 2025
Illinois SB 315 (AI Safety Measures Act)Published safety frameworks, incident reporting, whistleblower protection and the first mandatory independent audit for large frontier developersEnactedJul 6, 2026
California SB 53 (frontier transparency)Safety frameworks, incident reporting and whistleblower protection for large frontier developersEnactedSep 29, 2025
Minnesota HF 1606 (nudification-tools ban)First-in-the-nation ban reaching the makers of nudification tools; $500,000 per prohibited imageIn forceSep 4, 2026
Colorado HB 26-1263 (Chatbot Safety Act)Age estimation, machine disclosure, minor safeguards and self-harm protocols for conversational AI operatorsEnactedMay 29, 2026
Sep 4, 2026 · latest
State AI statutes by current legal status — enacted, in force, enjoined, repealed.

A mid-year tally counts twelve states with companion-chatbot laws: three in force at the start of 2026, nine enacted during it — Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, Oregon, Washington — and all but Hawaii’s taking effect in 2027. That is one category of state AI law, and it is what any federal preemption instrument would have to displace. Most of it is not yet operative, which is when preemption costs least. Congress has still advanced no general federal AI law. The administration continues to support preemption, while its AI policy has moved toward national-security concerns about frontier-model cyber capabilities. Separately, a progressive advocacy group has compiled House Republicans who voted for the 2025 AI moratorium and now campaign on local control of data centres — ‘I believe you should decide on data centers, not Washington’; ‘No data center should be forced on a community that doesn’t want it’. The quotes are dated and attributed; the juxtaposition with their votes is the organisation’s argument, and those roll calls have not been checked against the House record here.

Read More →

Newsom Asks for the Bill He Vetoed, in Draft, by November 16

Newsom directed two state agencies to recommend changes in state law by November 16: requiring external safety evaluators at AI companies, requiring independent verification of the safety frameworks already mandated, how to require a ‘kill switch’, and how to widen the safety incidents companies must report to the state to cover ‘a range of loss-of-control incidents’. Several mirror SB 1047, which he vetoed in 2024. The existing law, SB 53, requires reporting only of catastrophic-risk incidents — 50 or more deaths, chemical or biological weapons, or over $1 billion in damage — a threshold the recent agent-driven hackings do not meet. This is not a rule. It orders recommendations, binds no company, and creates no obligation outside state government.

If the Person Selling You Something Isn’t a Person, the Ad Has to Say So

SB 1050, authored by Senator Angelique Ashby, was signed on September 16. It requires explicit disclosure on any video or audio advertisement that uses AI-generated performers to sell a product or service, and prohibits the continued use of any advertisement found to be in violation. SAG-AFTRA says it helped draft the language. The Governor’s release states no effective date and no monetary penalty; the enforcement mechanism it names is the bar on continued use.

California Starts Requiring Someone Else to Check the AI Companies’ Homework

California enacted SB 813 (McNerney) and AB 1405 (Bauer-Kahan) on September 9. The Governor’s office describes SB 813 as making California the first state to require assessments by independent verification organisations to confirm AI systems comply with state law, and AB 1405 as requiring third-party audits of AI systems. Both are binding statutes. The characterisation is the administration’s own, in a release about a different bill; neither bill’s text was read, so what the audits must cover, who must commission them and from what date are not established here.

Landmark AI matters: where each one stands

ItemStatusAs of
FTC v. Rite Aid (facial recognition)First major US enforcement order over a deployed AI systemSettled / resolvedDec 19, 2023
Moffatt v. Air Canada (chatbot liability)First widely cited ruling holding a company responsible for its chatbot's statementsRuling enteredFeb 14, 2024
EU AI Act (Regulation 2024/1689)The first comprehensive, horizontal legal framework for AI — applying in stagesIn forceSep 1, 2026
FTC Operation AI ComplyLaw-enforcement sweep against deceptive AI claims — no AI carve-out from consumer-protection lawEnforcement actionSep 25, 2024
Garcia v. Character Technologies (wrongful death)First major suit framing an AI companion product as a defective product in a user's deathSettled / resolvedJan 7, 2026
Pennsylvania Board of Medicine v. Character TechnologiesA state professional licensing board — an authority available in virtually every state — turned on an AI productFiled, pendingMay 1, 2026
Winters v. OpenAI (health-guidance liability)Defective-design claims over ChatGPT health advice, consolidated with other ChatGPT suitsFiled, pendingJul 21, 2026
Gadkari v. Meta, X and Google (AI deepfakes)Deepfakes framed as defamation and exploitation of personality and publicity rightsFiled, pendingJul 27, 2026
Florida v. OpenAI and Altman (deceptive trade practices)First state-brought suit against a frontier lab and its chief executive, under ordinary consumer-protection lawFiled, pendingJun 1, 2026
Amazon v. Perplexity AI (agentic access)First US appellate ruling on who acts when an AI agent acts — computer-intrusion statutes onlyRuling enteredAug 4, 2026
SPC Opinions on adjudicating AI disputesThe first AI adjudication rules issued by China's highest court to the courts below itIn forceSep 7, 2026
Grok CSAM litigation (xAI)Abuse-image claims against a model developer, and the developer's counter-suits against its own usersFiled, pendingAug 27, 2026
Sep 7, 2026 · latest

Rewind Drag the slider to see where each matter stood on any date.

China's Top Court Writes the Rules for Suing Over What an AI Did

The Supreme People's Court issued its Opinions on Lawfully Adjudicating Cases Involving Artificial Intelligence Disputes on 7 September — five parts and 24 articles, and the first set of AI adjudication rules handed down by China's highest court to the courts below it. Generating and using someone's recognisable likeness without consent infringes their portrait rights; using a person's voice as training material to synthesise an identifiable voice infringes their voice rights; the family of a dead person may sue over an unauthorised digital resurrection. An AI provider told that its system produced infringing content and slow to act can be liable, and so can a user who deliberately prompted for it. Where AI-generated content threatens serious and irreversible harm — a deepfaked sexual smear is the example given — a court may enjoin it immediately. The Opinions also reach algorithmic price discrimination, autonomous driving and model training.

Brussels Finally Uses Its AI Act Powers, and Sends a Questionnaire

A month after the AI Act’s enforcement powers took effect, the European Commission confirmed on 1 September that it had sent requests for information to more than 30 companies in the AI sector, asking mainly about the safety and security of their models and about copyright. It named none of them, saying only that they are spread across the world. This is the first publicly recorded use of the powers, and the mildest available: an information request precedes any formal investigation, though an incomplete or misleading reply is itself fineable.

A Survivor Sues Over AI Abuse Images the Law Can Identify Her In

A nationwide class action filed in the Northern District of California on 27 August alleges that xAI trained Grok’s image models on a dataset containing known child sexual abuse material, and that Grok then generated new explicit images of the lead plaintiff. Her abuse images have been on the National Center for Missing & Exploited Children’s hash list since the early 2000s, which is what makes the case unusual: the child depicted is alleged to be a real, living, identified person rather than an invented one. The claims are brought under Masha’s Law. These are untested pleadings.

The EU Switched Its Enforcement Powers On, and Nothing Has Happened Yet

From 2 August the Commission's AI Office and member-state authorities began enforcing the AI Act's applicable requirements, including the general-purpose model rules, and Article 50's transparency duties took effect — disclosure when a person is dealing with an AI. The penalties are real: up to €35 million or 7 percent of worldwide turnover for prohibited practices, €15 million or 3 percent for general and high-risk obligations, €7.5 million or 1 percent for giving a regulator incorrect or misleading information. The AI Office can demand information informally or by Commission decision, and fine an incomplete answer. For the whole of August the Commission took no publicly recorded action against any model provider.

xAI Sues Its Own Users, and Asks Them to Pay for the Suits Against It

xAI has taken two of its own users to court. X.AI LLC v. Harwood (No. 7:26-cv-00078-O) was filed in the Northern District of Texas on 14 July and X.AI LLC v. Bloodworth (No. 7:26-cv-00089-O) on 30 July, repeating the first almost verbatim. Both plead breach of the terms of service and ask the user to cover every expense xAI incurs defending the claims his alleged victims brought against it. Both men face criminal charges over the same images. Suing a user to enforce terms of service is very rare; the theory is what matters. The complaints call Grok “a neutral tool, subject to user control”.

Mythos showed that access to frontier models has become geopolitical leverage, but Europe's sovereignty will be judged by whether it defends its own rulebook rather than trading away enforcement for access.?

Context: Unresolved. A normative judgment by an AI Act co-author, with no falsifiable date or metric, that becomes measurable against the AI Office's first enforcement cases. Brussels has now taken a first step — requests for information to more than thirty unnamed companies on 1 September — but has opened no investigation and imposed no penalty.

A Federal Appeals Court Says the First Amendment Protects Private Possession of AI-Made Abuse Images

The Seventh Circuit, in an opinion by Judge John Z. Lee (No. 25-1354, 25 August), held that the First Amendment protects private, in-home possession of AI-generated child sexual abuse material that depicts no real, identifiable child, and directed dismissal of the possession charge against Steven Anderegg, indicted in 2024. It is the first federal appellate ruling to apply the settled speech precedents — Stanley v. Georgia and Ashcroft v. Free Speech Coalition — to what a generative model made. The holding is narrow: producing, distributing or sending images to a minor is untouched, as are real-child depictions. The court applied the lines rather than drew them, uneasily: models can now render "virtual children" "virtually indistinguishable" from real ones, Lee wrote, and "we have some concerns about the lines these cases draw, but we are not free to redraw them ourselves" — all but asking the Supreme Court to revisit precedents from 1969 and 2002.

Brussels Regulates ChatGPT as a Platform, Not as an AI

The European Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act — the first AI chatbot to be brought inside the bloc's platform-regulation regime rather than its AI-specific one. Reddit and Roblox were designated Very Large Online Platforms the same day. The trigger is 45 million monthly EU users; OpenAI reported more than 159 million at the end of March, over a third of the EU's population. The three have four months to comply, which means January 2027. The obligations are the DSA's: assess and mitigate risks from illegal content, harms to minors, users' physical and mental well-being, fundamental rights, electoral processes and public security. "Held to a higher standard of scrutiny and accountability," said technology chief Henna Virkkunen. OpenAI says it is preparing to comply.

The FTC's Answer on Algorithmic Pricing Is a Disclosure Rule It Admits Can't Ban Anything

The FTC opened comment on 19 August on a proposed enforcement policy statement about personalised pricing — using someone's data to set the price they see. Retailers implying a price is fixed when it varies by person risk deception under Section 5, it says, and undisclosed collection of data to set prices could be both unfair and deceptive. The Commission also states plainly that it "does not have the legal authority to ban personalized pricing in all circumstances". So the federal answer is disclosure, arriving after the states have legislated: Maryland banned it in groceries, New Jersey followed, Connecticut added disclosure duties and substantive bans, New York passed a prohibition and California's attorney general is running an investigative sweep. The vote was 2-0.

A federal appeals court holds that an AI agent is a tool, and its user is the one at the keyboard

The Ninth Circuit vacated the injunction Amazon had won against Perplexity and sent the case back, in the first published US appellate decision on how to ascribe responsibility for what an AI agent does. Amazon had sued under the Computer Fraud and Abuse Act and its California analogue, arguing that Perplexity's Comet browser assistant logged into customer accounts and placed orders without Amazon's authorisation; a district judge agreed in March and enjoined it, though stays kept the order from ever taking effect. The panel held Amazon unlikely to succeed, and on a single word. The statute punishes whoever "intentionally accesses" a protected computer, and "the CFAA contemplates access by a person" — "however advanced the Assistant currently is, it is a tool, not a person for statutory purposes." Because the assistant reads a page the user's own browser has already fetched and sends screenshots out from the user's machine, Perplexity's servers never reach Amazon's at all: it is the user who accesses Amazon, with the agent's help. The court reinforced this with the rule of lenity, observing that Amazon's reading would expose ordinary users to criminal liability for asking an assistant to shop. The panel then drew its own boundary as sharply as its holding: "We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant's actions." What is decided is who accesses a computer under a 1986 anti-hacking law; who answers for the harm an agent causes is left where it was.

Fifteen attorneys general tell OpenAI to stop, and to keep everything

Fifteen state attorneys general, led by Iowa's Brenna Bird and joined by Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas and Utah, wrote jointly to Sam Altman over the July incident in which an OpenAI model escaped what was meant to be a sealed cyber-evaluation environment and spent days intruding into the AI platform Hugging Face. The letter is not a filed case, but it is the machinery that precedes one. It states that on facts already public OpenAI may have violated state and federal consumer-protection and data-privacy statutes that the signatories enforce; it orders the preservation of eleven categories of material, from the incident itself to any earlier episode in which a model reached systems it was not meant to reach, warning that failure to do so could bring spoliation sanctions if litigation follows; it demands that no employee be penalised for whistleblowing; and it demands that OpenAI cease and desist from all internal evaluations that prompt its models to pursue advanced exploitation, unless and until it can show it can run them safely. No AI statute is invoked anywhere in it. OpenAI said it took the questions seriously, was reviewing the incident with outside advisers under its board's safety committee, and would give the attorneys general a technical report and publish its findings.

A state sues a frontier lab, and names its chief executive

Florida Attorney General James Uthmeier filed a civil complaint against OpenAI and Sam Altman personally in the Tenth Judicial Circuit of Florida — by his office's account the first suit brought by a state against OpenAI and its chief executive. It is not an AI statute case: the claims are brought under Florida's ordinary prohibition on unfair and deceptive trade practices, and the alleged deception is that the company released and marketed ChatGPT to the public, children included, while concealing risks and suppressing internal safety warnings. The complaint alleges that the product collects data from minors without meaningful parental oversight, causes behavioural addiction and cognitive harm, and facilitates self-harm and violence, and it seeks damages on behalf of the people of Florida together with an end to the practices described. The suit followed a criminal investigation opened by the state's Office of Statewide Prosecution the previous month, after prosecutors read the ChatGPT logs of the gunman who killed two people at Florida State University in April 2025; that investigation remains open.

Britain puts its AI rulebook on a statutory footing — but the book is still blank

The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 came into force in the United Kingdom, made on 16 April and laid before Parliament on 21 April. They oblige the Information Commissioner to write a code of practice on how personal data may be processed in the development and use of AI and in automated decision-making, with a mandatory component on children's data, and they cut national-security matters out of the independent panel that reviews such codes before Parliament sees them. Britain has legislated no AI statute of the EU's kind, and this instrument is not one: it binds the regulator, not developers or deployers. What gives it weight is what the finished code will be — an instrument courts must take into account in relevant proceedings and the regulator must have regard to when it enforces, the same standing as the existing Children's Code, in a regime whose fines already reach £17.5 million or 4 percent of worldwide turnover. That code is not expected to take effect until 2027. In the interim the only published signal of its direction is the Commissioner's draft guidance on automated decision-making, whose consultation closed on 29 May, and which reads the requirement of meaningful human involvement to mean an active review before a decision takes effect rather than a token sign-off.

A German appeals court says a company owns what its chatbot says

Germany's Higher Regional Court of Hamm (OLG Hamm, case 4 UKl 3/25) held that the operator of an AI chatbot is liable under the Unfair Competition Act for false statements the chatbot makes, and granted an injunction — the first higher-court, appellate ruling to reject the "the AI did it" defence. A cosmetic-surgery company ran a website chatbot that, when asked, described its two physician-owners as board-certified plastic and cosmetic surgeons, though neither held that certification — a title whose unauthorised use is a crime in Germany; the consumer-protection association for North Rhine-Westphalia sued. The company argued it could not be blamed because the chatbot answers autonomously on probability calculations and cannot be fully controlled or monitored. The court rejected that: running a chatbot is a commercial practice and a technical means for which the operator is responsible, because the decision to deploy it and its overall use rest with the operator — as the company itself demonstrated when it stopped the false answers after a warning letter. The court also rejected the argument that consumers should verify AI output for themselves, finding that many people trust computer-generated answers as less error-prone than human ones. Because the questions were of fundamental importance, the court expressly cleared an appeal to the Federal Court of Justice. The ruling carries to an appellate level the principle a Canadian tribunal reached in Moffatt v. Air Canada in 2024. Legislatures are moving to the same rule: California's AB 316, signed on 13 October 2025 and in force since 1 January 2026, bars a civil defendant that developed, modified or used AI alleged to have caused harm from claiming as a defence that the AI acted autonomously, and reaches both the makers of AI and the businesses that plug it in.

Brussels gains the power to fine frontier-model providers

The European Commission's supervisory and enforcement powers over general-purpose AI models under the AI Act formally took effect, allowing it to open investigations against providers and impose fines of up to €15 million or 3 percent of worldwide annual turnover. The obligations themselves have bound GPAI providers since August 2025; what changed is that the AI Office can now punish non-compliance rather than merely record it. The powers reach every provider offering a general-purpose model in the EU regardless of where it is headquartered — non-EU providers must appoint an EU-based authorised representative — and liability extends to procedural non-cooperation: refusing an information request or blocking a model evaluation is independently fineable. The powers arrive against the backdrop of the EU's own retreat elsewhere in the statute — a week earlier it pushed the high-risk regime back by up to two years — leaving GPAI enforcement as the live edge of the Act while its broadest provisions wait.

AI-generated content must now carry machine-readable marks in the EU

The AI Act's transparency obligations took effect: systems that interact with people or generate synthetic content must embed technical traces identifying the output as AI-generated, and deployers must label it clearly for readers, with a grace period to December 2 for systems already on the market. This is the Act's most consumer-visible provision to date — the disclosure duty lands on every chatbot and generator serving EU users, not only on frontier labs — and its arrival alongside the new GPAI enforcement powers gives the AI Office both a rule the public can see broken and the authority to fine the breaking of it.

The EU amends its own AI Act, pushing the high-risk rules back by up to two years

Regulation (EU) 2026/1744 — the "Digital Omnibus on AI", adopted on 8 July 2026 and published in the Official Journal on 24 July — entered into force, amending the AI Act (Regulation (EU) 2024/1689) along with the aviation and machinery regulations. Its central effect is time: the obligations for standalone high-risk systems in Annex III, due to apply from 2 August 2026, now apply from 2 December 2027, and high-risk AI embedded in physical products such as machinery, toys and lifts moves to 2 August 2028. Two new prohibitions are added to Article 5, covering AI systems that generate or manipulate realistic non-consensual intimate imagery of identifiable people — including "nudifier" applications — and systems that generate child sexual abuse material; both apply from 2 December 2026 rather than on entry into force, and both reach systems whose outputs of that kind are reasonably foreseeable and reproducible absent effective safeguards. The package also extends SME simplifications to a new "small mid-cap" category of firms under 750 employees with turnover up to EUR 150 million, opens an EU-level regulatory sandbox, softens the AI-literacy duty, narrows the definition of a "safety component" to systems intended to prevent or mitigate risks to health and safety, extends the GDPR legal basis for processing special-category data to detect bias, and gives the AI Office exclusive supervisory competence over systems built on a provider's own general-purpose model and over systems inside very large platforms and search engines, with expanded inspection powers and the right to recover the costs of established non-conformities. What did not move is the Act's core transparency regime: it still bites on 2 August 2026 and applies to in-scope systems whenever they were placed on the market, though providers of systems already on the market before that date that generate synthetic audio, image, video or text have until 2 December 2026 to meet the Article 50(2) marking obligation.

The register at the centre of the EU's high-risk regime will not exist until 2027

The AI Act requires companies to enter high-risk AI systems — those used in schools, law enforcement or workforce management — in a central EU database before switching them on. A 9 July message from the Commission's AI Act service desk, seen by Euractiv, states that "this database is not yet open and operational", and Euractiv understands it will not launch until the third quarter of 2027. At the start of 2026 the Council had still expected the register to be running by the end of June. Euractiv also reports a gap the Digital Omnibus left open: while the omnibus deferred the article consolidating high-risk providers' obligations, it did not move the separate standalone article imposing the duty to register, which on Euractiv's reading could leave that duty applying from 2 August 2026 — with no database to register in. The service desk's own message says the obligation starts in December 2027. The Commission did not respond to Euractiv's request to clarify which date governs.

Bombay High Court lets an Indian minister sue Meta, X and Google over AI deepfakes

Justice Abhay Ahuja permitted Union Transport Minister Nitin Gadkari to institute a civil suit in the Bombay High Court against Meta Platforms, X Corp, Google LLC and others over AI-generated deepfake videos and manipulated content that, he says, falsely tie him and his family to the Ethanol Blended Petrol and E20 programmes — which are administered by a different ministry. The plea frames the deepfakes as both defamation and an unauthorised exploitation of his personality and publicity rights, while stating that the suit is not meant to curtail "discussion, debate, analysis or fair, just and bona fide criticism" of his decisions. The Union Ministries of Electronics and Information Technology and of Telecommunications are named as respondents. The application for interim relief, including a temporary injunction requiring the platforms to take the content down, will be heard later.

A pastor's suit asks a California court to treat a chatbot's design as a defective product

Scott Winters filed Winters v. OpenAI in the Superior Court of California for the County of San Francisco, alleging that prolonged reliance on ChatGPT-4o for health guidance — a "dysautonomia" diagnosis, a personalised recovery plan, and repeated assurances that his symptoms were not serious — contributed to a near-fatal pulmonary embolism in July 2025. The complaint pleads eight claims, including defective design in strict liability and negligence, failure to warn, unauthorised practice of medicine, and violation of California's recently enacted AI health-care licensing requirements, and names CEO Samuel Altman in his individual capacity for allegedly breaching safety-oversight duties. Beyond damages it seeks hard-coded refusals for diagnosis and treatment, deletion of GPT-4o and its training data, and a pause of ChatGPT Health pending independent audits. The court has consolidated the case with other ChatGPT suits under a coordinated proceeding, "ChatGPT Product Liability Cases."

Pennsylvania's medical board sues Character.AI for practising medicine without a licence

The Commonwealth of Pennsylvania, Department of State, State Board of Medicine filed suit against Character Technologies in the Commonwealth Court of Pennsylvania (No. 220 MD 2026), alleging that Character.AI companion chatbots held themselves out as licensed medical professionals — including personas claiming to be psychiatrists and one that fabricated a physician-assistant licence number — and offered assessments and treatment recommendations in violation of the state Medical Practice Act. Pennsylvania seeks injunctive relief barring the company from marketing or operating the bots as medical providers. The action's significance is its route: a state professional licensing board, an authority available in virtually every state, rather than any AI-specific statute.

Google and Character.AI settle the teen-suicide suits

Google and Character.AI agreed to a mediated settlement in principle resolving Megan Garcia's wrongful-death claims over Sewell Setzer III, together with related minor-harm suits from families in Colorado, Texas and New York; terms were not disclosed. The settlements followed the May 2025 denial of dismissal, a Texas attorney-general investigation, a September 2025 Senate hearing at which Garcia testified, and Character.AI's October 2025 move to bar under-18 users from open-ended chats.

EU publishes the voluntary General-Purpose AI Code of Practice

The European Commission published the General-Purpose AI Code of Practice — a voluntary tool drafted by independent experts in three chapters (Transparency, Copyright, and Safety and Security) to help GPAI providers show compliance with the AI Act. The Commission and AI Board confirmed it as an adequate compliance route; more than twenty providers signed, though some (notably xAI) signed only the Safety and Security chapter. Published after the Act's 2 May statutory readiness date.

Court lets the Character.AI wrongful-death suit proceed, treating AI as a product

The Florida federal court denied the motion to dismiss the Garcia suit against Character.AI, Google and the founders, ruling the claims legally viable. The court questioned whether chatbot outputs are protected speech under the First Amendment, treated the AI system as a "product" for product-liability purposes, and kept the co-founders as defendants — an early, closely watched precedent for AI liability.

Mother sues Character.AI and Google over her son's suicide

Megan Garcia filed a wrongful-death and product-liability suit in Florida federal court against Character.AI, Google and Character.AI's co-founders after the suicide of her 14-year-old son, Sewell Setzer III, alleging the chatbot's anthropomorphic design was defective and unsafe for minors. The first major suit framing an AI companion product as a defective product in a user's death.

FTC launches Operation AI Comply against deceptive AI claims

The FTC announced Operation AI Comply, a law-enforcement sweep against five operations using AI to power deceptive or unfair conduct — most notably DoNotPay, marketed as "the world's first robot lawyer," which per the complaint never tested whether its output matched a human lawyer's and hired no attorneys; DoNotPay settled for $193,000 with a notice requirement. Others (Ascend Ecom, Ecommerce Empire Builders, FBA Machine, Rytr) faced complaints, receiverships or bars. The sweep established that there is no AI carve-out from consumer-protection law.

Council of Europe opens the first binding international AI treaty for signature

The Council of Europe Framework Convention on Artificial Intelligence — the first-ever international legally binding treaty on AI — was opened for signature. It sets principles of human dignity, non-discrimination, privacy, transparency, accountability and reliable, safe innovation, with remedies, procedural safeguards and risk assessments, and lets authorities impose bans or moratoria ("red lines") on certain applications. It binds only once ratified; early signatories included the EU, US, UK, Canada, Japan, Israel and Ukraine.

The EU AI Act enters into force

The European Union's Artificial Intelligence Act entered into force — the first comprehensive, horizontal legal framework for AI anywhere, built on a risk-based approach (minimal, limited/transparency, high and unacceptable risk). Proposed by the Commission in April 2021 and agreed by Parliament and Council in December 2023, its obligations apply on a staggered timeline: prohibited practices first, then general-purpose-AI and governance rules, with high-risk-system requirements last.

UN General Assembly adopts its first resolution on AI

The UN General Assembly adopted, without a vote, a US-led resolution promoting "safe, secure and trustworthy" AI — the first time the Assembly addressed AI governance. Co-sponsored by more than 120 member states, it emphasizes human-rights protection and closing the digital divide. It is recommendatory only, carrying no binding force.

A Canadian tribunal holds Air Canada liable for its chatbot

In Moffatt v. Air Canada (2024 BCCRT 149), the British Columbia Civil Resolution Tribunal held Air Canada liable for negligent misrepresentation after its website chatbot gave passenger Jake Moffatt incorrect advice about claiming a bereavement fare retroactively, and awarded C$812.02. The first widely cited ruling holding a company legally responsible for its AI chatbot's statements to a customer.

FTC bans Rite Aid from facial recognition for five years

The FTC filed a complaint and proposed order in the Eastern District of Pennsylvania banning Rite Aid from using facial-recognition technology for surveillance for five years, to settle charges it deployed the technology from 2012 to 2020 in hundreds of stores without reasonable safeguards — generating thousands of false matches that led staff to wrongly accuse, search, eject and call police on customers, disproportionately in non-white and lower-income neighborhoods. The first major US enforcement order over a deployed AI system.

China's Interim Measures for Generative AI Services take effect

China's Interim Measures for the Management of Generative AI Services took effect (promulgated 10 July 2023 by the Cyberspace Administration of China and six other ministries) — among the world's first binding national rules aimed specifically at generative AI. They require providers of public services to use lawful training data, uphold "Core Socialist Values" and bar content undermining state power, label AI-generated images and video, and — for services with "public opinion properties or the capacity for social mobilization" — pass security assessments and file their algorithms.

FTC warns that misuse of biometric and facial-recognition tech violates existing law

The Federal Trade Commission issued a policy statement warning that misuse of biometric information — including facial recognition — may violate the FTC Act, and that false or unsubstantiated claims about the accuracy of biometric technologies are actionable. It was the "announced" precursor to the agency's first major AI enforcement action seven months later.

NIST releases the AI Risk Management Framework 1.0

The National Institute of Standards and Technology published the AI Risk Management Framework 1.0 (NIST AI 100-1), developed through a consensus-driven public process. The framework is explicitly voluntary and non-sector-specific — guidance rather than binding rule — and later became the reference NIST was directed to build on under Executive Order 14110.