Digital

On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

Continue Reading French CNIL Publishes Note on Agentic AI and Data Protection

On 10 July 2026, Ofcom published a package of draft materials as part of the third phase of its implementation of the Online Safety Act (the “Act”). While the Act already imposes baseline duties to tackle illegal content and to protect children (where a service is likely to be accessed by them) on all regulated user-to-user and search services, the 10 July package provides a set of additional duties targeted at the UK’s largest and most widely used online services.

The package is comprised of three connected strands:

  • The Register of Categorised Services. Ofcom published its long-awaited register, formally designating services across Category 1, Category 2A, and Category 2B, together with a list of “emerging” Category 1 services.
  • Consultation: Draft Fraudulent Advertising Codes of Practice (Category 1 and 2A): The draft codes of practice set proposed measures for how the largest user-to-user and search services should tackle paid-for fraudulent advertising.
  • Consultation: Draft Additional Duties Code of Practice and Guidance (Category 1 only): The draft codes of practice and associated guidance address user empowerment and identity verification, protections for certain public-interest content, terms of service, complaints, and freedom-of-expression and privacy assessments.

This post focuses on the third strand—the additional duties for Category 1 services.

Continue Reading UK online safety update: Ofcom’s Category 1 proposals and DSIT’s latest response to “Growing Up in an Online World”

The UK Government today announced that it intends to ban social media platforms from offering services to children under 16, alongside wider restrictions on certain online functionalities that the Government has identified as harmful to children.

The announcement follows the conclusion of the Department for Science, Innovation and Technology’s (“DSIT”) consultation, “Growing up in the online world,” which received more than 116,000 responses (we originally wrote about that consultation here). The Government intends to bring the first regulations to Parliament before the end of the year using powers created by the Children’s Wellbeing and Schools Act 2026 (“CWSA”), with protections expected to come into force in Spring 2027. Today’s announcement is the latest in a series of significant developments reshaping the UK’s online safety framework. We summarize some of these latest developments below.

Continue Reading Online Safety in the UK: Social Media Ban for Under 16s and Other Recent Developments

On 19 May 2026, the European Commission published its long-awaited draft, non-binding guidelines on the classification of high-risk AI systems (“HRAIs”) under the EU AI Act (the “Guidelines”). Across three documents—covering general principles, high-risk classification in the context of regulated products (Annex I), and high-risk use cases (Annex III)—the Commission sets out its approach to one of the AI Act’s central questions: when does an AI system fall within the high-risk regime (and, just as importantly, when does it not)?

Continue Reading EU AI Act Update: The European Commission Publishes Draft Guidelines on HRAIs

Quantum computing is largely in the research and developmental stage, but its commercial use is on the horizon. Due to the high cost and technical complexity of maintaining qubits, companies and individuals likely won’t own quantum computers themselves. Instead, access will mainly come through third-party platforms offering “Quantum-Computing-as-a-Service” (QCaaS) or “Quantum-as-a-Service” (QaaS).

Similar to the Software-as-a-Service (SaaS) or Infrastructure-as-a-Services (IaaS) models, QaaS would be a remote access service model with a subscription or “pay for what you use” fee structure. The key differentiating factor with QaaS will be the underlying quantum computing infrastructure and the quantum computing algorithm. Due to the similarities between SaaS, IaaS and QaaS models, terms in a typical SaaS or IaaS agreement would be a good starting point for QaaS contracts. However, due to the experimental and volatile nature of quantum computing technology (at least initially), lawyers and legal practitioners should also consider the risks that are unique to quantum computing when drafting or negotiating a QaaS agreement:

Continue Reading Quantum Computing: Overview of Drafting Considerations for Quantum-as-a-Service Agreements

Updated September 20, 2024.  Originally posted September 11, 2024.

On September 17, California Governor Gavin Newsom (D) signed two bills into law that limit the creation or use of “digital replicas,” making California the latest state to establish new protections for performers, artists, and other employees in response to the rise of AI-generated content.  These state efforts come as Congress considers the NO FAKES Act (S. 4875), introduced by Senator Chris Coons (D-DE) on July 31, which would establish a federal “digital replication right” over individual’s own digital replicas and impose liability on persons who knowingly create, display, or distribute digital replicas without consent from the right holder.

Continue Reading California Enacts Digital Replica Laws as Congress Considers Federal Approach

This year, the UK’s Competition and Markets Authority (“CMA”) is set to gain a range of new enforcement powers under the Digital Markets, Competition and Consumers (“DMCC”) Act (the final text is now available here). The DMCC Act received Royal Assent on 24 May 2024. However, with certain exceptions, the Act’s provisions will not come into force until secondary legislation is passed. The CMA initially expected its new responsibilities to become operational in the Autumn, but this timeline may be delayed due to the UK’s election on 4th July. On the same day as the DMCC Act became law, the CMA published for consultation its new Digital Markets Competition Regime Guidance.

An outline of the key provisions of the DMCC Act can be found here. As the CMA sets the groundwork for exercising its powers under this new regime, this blog post considers five practical considerations for firms active in the UK.

Key takeaways:

  1. The CMA will administer the new regime through a specialist Digital Markets Unit, which was established over three years ago.
  2. The DMCC Act may diverge from the EU’s Digital Markets Act, both in the companies being designated, and the obligations imposed on designated companies.
  3. The interplay between the DMCC regime and existing regulatory obligations – particularly the GDPR – is likely to raise practical challenges.
  4. We expect the CMA to exercise its powers under the digital markets regime alongside existing antitrust tools (which the DMCC Act amends).
  5. The CMA’s jurisdictional thresholds to review mergers under the UK’s merger control regime will change as a result of the DMCC Act.
Continue Reading The UK’s New Digital Markets Regime: Some Key Takeaways

The Digital Markets, Competition and Consumers (“DMCC”) Act received Royal Assent on 24 May 2024 (the final text is now available here). The DMCC Act will only enter into force, however, when secondary commencement legislation has been enacted (with some minor exceptions). This is expected to occur in Autumn 2024, but it could be delayed due to the General Election taking place on 4th July. This secondary legislation could also stagger the dates on which separate provisions become effective.

This legislation ushers in a new rulebook for the largest digital firms active in the UK, alongside some consequential changes to the broader UK competition law framework. In relation to digital markets specifically:

  • The Competition and Markets Authority (“CMA”) may designate certain companies active in digital markets in the UK as holding “Strategic Market Status” (“SMS“) in relation to a specific digital activity. Companies designated with SMS will need to comply with tailored conduct requirements imposed by the CMA and report certain transactions to the CMA ahead of completion.
  • The CMA can make “pro-competition interventions” (“PCIs“) to impose requirements to remedy or prevent conduct in relation to digital activities which the CMA considers to have an adverse effect on competition.
  • The CMA will be able to impose fines of up to 10% of worldwide group turnover for non-compliance with SMS conduct requirements or “pro-competition orders”.

More broadly, the DMCC Act includes some amendments to the UK’s existing competition law regime which apply to all sectors of the economy. In particular, the DMCC Act introduces a new merger control jurisdictional review threshold designed to capture vertical and conglomerate mergers where the parties do not overlap, applicable to any industry. Additionally, the DMCC Act introduces a fast-track route to a Phase 2 review without the need to concede at Phase 1 that there is a realistic prospect that the merger gives rise to a substantial lessening of competition.

This post outlines each of these changes. For an analysis of some key practical considerations for companies in light of the DMCC Act, please see this separate post here.

Continue Reading Overview of the UK’s New Digital Markets Regime

The field of artificial intelligence (“AI”) is at a tipping point. Governments and industries are under increasing pressure to forecast and guide the evolution of a technology that promises to transform our economies and societies. In this series, our lawyers and advisors provide an overview of the policy approaches and regulatory frameworks for AI in jurisdictions around the world. Given the rapid pace of technological and policy developments in this area, the articles in this series should be viewed as snapshots in time, reflecting the current policy environment and priorities in each jurisdiction.

The following article examines the state of play in AI policy and regulation in China. The previous articles in this series covered the European Union and the United States.

Continue Reading Spotlight Series on Global AI Policy — Part III: China’s Policy Approach to Artificial Intelligence

From February 17, 2024, the Digital Services Act (“DSA”) will apply to providers of intermediary services (e.g., cloud services, file-sharing services, search engines, social networks and online marketplaces). These entities will be required to comply with a number of obligations, including implementing notice-and-action mechanisms, complying with detailed rules on terms and conditions, and publishing transparency reports on content moderation practices, among others. For more information on the DSA, see our previous blog posts here and here.

As part of its powers conferred under the DSA, the European Commission is empowered to adopt delegated and implementing acts* on certain aspects of implementation and enforcement of the DSA. In 2023, the Commission adopted one delegated act on supervisory fees to be paid by very large online platforms and very large online search engines (“VLOPs” and “VLOSEs” respectively), and one implementing act on procedural matters relating to the Commission’s enforcement powers. The Commission has proposed several other delegated and implementing acts, which we set out below. The consultation period for these draft acts have now passed, and we anticipate that they will be adopted in the coming months.

Continue Reading Draft Delegated and Implementing Acts Pursuant to the Digital Services Act