On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

Continue Reading French CNIL Publishes Note on Agentic AI and Data Protection

On July 28, 2026, the FCC added foreign-produced power inverters and advanced robotic devices to its Covered List, following determinations by an executive branch interagency body that they pose “unacceptable risks” to the national security of the United States. The new additions continue a string of decisions placing entire categories of foreign-produced devices on

Continue Reading FCC Restricts Imports of New Foreign-Produced Power Inverters and Advanced Robotic Devices with Additions to its Covered List

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”  

The creation of Gold Eagle is the latest in a series of Administration actions focused

Continue Reading White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse

On July 22, 2026, the Federal Communications Commission (the “FCC”) voted to approve a Report and Order (the “Order”) and Further Notice of Proposed Rulemaking (the “FNPRM”) that will rework and modernize the FCC’s satellite licensing regime.  Stating that “[a]chieving American space superiority is critical to our nation’s future,” the Order streamlines the FCC’s satellite

Continue Reading FCC Approves Massive Modernization of Satellite Licensing Regime

On July 22, the Federal Communications Commission (the “FCC”) approved a Report and Order (the “Order”) to simplify the requirements for the broadband consumer label (the “Label”) that all ISPs have been required to provider to consumers since 2024.  The Order is meant to “refocus the rules on ensuring that consumers have the clear, accurate

Continue Reading FCC Simplifies Broadband Consumer Label Requirements

On 10 July 2026, Ofcom published a package of draft materials as part of the third phase of its implementation of the Online Safety Act (the “Act”). While the Act already imposes baseline duties to tackle illegal content and to protect children (where a service is likely to be accessed by them) on all regulated user-to-user and search services, the 10 July package provides a set of additional duties targeted at the UK’s largest and most widely used online services.

The package is comprised of three connected strands:

  • The Register of Categorised Services. Ofcom published its long-awaited register, formally designating services across Category 1, Category 2A, and Category 2B, together with a list of “emerging” Category 1 services.
  • Consultation: Draft Fraudulent Advertising Codes of Practice (Category 1 and 2A): The draft codes of practice set proposed measures for how the largest user-to-user and search services should tackle paid-for fraudulent advertising.
  • Consultation: Draft Additional Duties Code of Practice and Guidance (Category 1 only): The draft codes of practice and associated guidance address user empowerment and identity verification, protections for certain public-interest content, terms of service, complaints, and freedom-of-expression and privacy assessments.

This post focuses on the third strand—the additional duties for Category 1 services.

Continue Reading UK online safety update: Ofcom’s Category 1 proposals and DSIT’s latest response to “Growing Up in an Online World”

On July 16, 2026, the Federal Communications Commission (“FCC”) released a draft Notice of Proposed Rulemaking (“NPRM”) seeking comment on proposals to permit direct-to-device (“D2D”) operations from satellites to unlicensed equipment.  Currently, D2D devices that communicate with satellites would need to be licensed in one form or another.  The NPRM sets out the following bands

Continue Reading FCC to Vote on Unlocking Spectrum for Direct-to-Device Operation for Unlicensed Equipment
On 3 June 2026, the European Commission published several legislative and policy measures wrapped up in one “tech sovereignty” package (see our posts summarising the package as a whole here, and diving deeper into the Cloud and AI Development Act here). But the EU’s tech sovereignty drive has a long history, and is by no means limited to this package. In this post, we take a closer look at the current and forthcoming EU legislative measures aimed at increasing the resilience of services provided in the EU against external, malicious influence, a key aspect of tech sovereignty. Relevant legislation falls into two broad categories: (1) laws promoting cyber resilience generally, to prevent malicious actors from disrupting services and critical infrastructure; and (2) laws focused on building supply chain resilience and reducing dependencies on certain external actors by building European industrial capacity in key tech sectors. Continue Reading Looking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilience

This update highlights key legislative and regulatory developments in the second quarter of 2026 related to artificial intelligence (“AI”), connected and automated vehicles (“CAVs”), and Internet of Things (“IoT”).

Continue Reading U.S. Tech Legislative & Regulatory Update – Second Quarter 2026

On July 6, 2026, Illinois Governor JB Pritzker signed into law SB 315, a frontier model safety act that resembles the New York RAISE Act, discussed in our prior blog post here, and California’s Transparency in Frontier Artificial Intelligence Act (TFAIA), discussed in our prior blog post here. The law takes effect January 1, 2027, with transparency-reporting and audit obligations beginning January 1, 2028.  Similar to the New York and California laws, SB 315 will apply to frontier developers (i.e., persons that train, or initiate the training of, a frontier model using computing power greater than 10^26 integer or floating point operations), with certain provisions applicable only to large frontier developers (i.e., frontier developers with annual gross revenue over $500 million in the preceding year). SB 315 also includes public safety disclosure and reporting requirements. Notably, SB 315 also imposes a third-party audit requirement not found in either the New York or the California law.

Continue Reading Illinois Enacts Frontier Model Safety Law