Technology

On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

Continue Reading French CNIL Publishes Note on Agentic AI and Data Protection

On 10 July 2026, Ofcom published a package of draft materials as part of the third phase of its implementation of the Online Safety Act (the “Act”). While the Act already imposes baseline duties to tackle illegal content and to protect children (where a service is likely to be accessed by them) on all regulated user-to-user and search services, the 10 July package provides a set of additional duties targeted at the UK’s largest and most widely used online services.

The package is comprised of three connected strands:

  • The Register of Categorised Services. Ofcom published its long-awaited register, formally designating services across Category 1, Category 2A, and Category 2B, together with a list of “emerging” Category 1 services.
  • Consultation: Draft Fraudulent Advertising Codes of Practice (Category 1 and 2A): The draft codes of practice set proposed measures for how the largest user-to-user and search services should tackle paid-for fraudulent advertising.
  • Consultation: Draft Additional Duties Code of Practice and Guidance (Category 1 only): The draft codes of practice and associated guidance address user empowerment and identity verification, protections for certain public-interest content, terms of service, complaints, and freedom-of-expression and privacy assessments.

This post focuses on the third strand—the additional duties for Category 1 services.

Continue Reading UK online safety update: Ofcom’s Category 1 proposals and DSIT’s latest response to “Growing Up in an Online World”

On June 4, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a sweeping discussion draft of their Great American Artificial Intelligence Act. The latest bipartisan AI legislation quickly met bipartisan skepticism, particularly concerning the draft’s approach to federal preemption of state AI rules, with many House Democrats opposing the broad preemption for frontier model developers, while many House Republicans and other stakeholders lamented the bill’s omission of preemption for state laws reaching other parts of the AI ecosystem. 

The bill would also establish mandatory disclosure and risk-mitigation requirements for frontier models and task the Center for Artificial Intelligence Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) with oversight of federal AI-related research and analysis, standards and guidelines development, and risk-mitigation activities.  

Continue Reading Backlash to Bipartisan AI Omnibus Illustrates Preemption Impasse

Executive Summary

2026 has been a dynamic year so far for federal regulation of automotive safety. Federal regulators have demonstrated a sustained commitment to regulatory reform and innovation, while simultaneously advancing efforts to facilitate the deployment of autonomous vehicles. Congress has also renewed its focus on vehicle safety and automation as lawmakers consider legislation that could significantly reshape the federal framework governing AVs and vehicle-safety regulation.

Although the path to a comprehensive federal framework for AVs remains uncertain, NHTSA and other agencies continue to pursue opportunities to advance a deregulatory agenda while promoting innovation. Efforts to pave the way for large-scale autonomous vehicle deployment are underway at the National Highway Traffic Safety Administration (NHTSA) and the Federal Motor Carrier Safety Administration (FMCSA). Congress is also paying attention to motor vehicle safety, with surface transportation reauthorization looming and numerous proposed bills that could provide a federal framework for AVs and reform NHTSA’s exemption process, long viewed as a roadblock for vehicle manufacturers.

The next year-and-a-half presents a window of uncommon opportunity for industry to help shape vehicle safety rules that deliver safety value without stifling innovation. These developments collectively suggest that industry stakeholders will continue to have meaningful opportunities to influence vehicle-safety policy through agency engagement, rulemaking participation, and legislative advocacy.

Continue Reading Federal Vehicle Safety at Midyear: Regulatory Relief, Legislative Momentum, and the Road to the Broader AV Deployment

Since our prior post on Singapore’s Model AI Governance Framework for Agentic AI, Singapore’s Infocomm Media Development Authority (“IMDA”) has published an updated version (Version 1.5) (the “Updated Framework”), incorporating feedback from over 60 organizations.

The Updated Framework, published on May 20, 2026, retains the same four-pillar structure—(1) assess and bound the risks upfront, (2) make humans meaningfully accountable, (3) implement technical controls and processes, and (4) enable end-user responsibility—but expands the guidance in several notable respects. These include a new discussion of multi-agent systemic risks, more granular guidance on technical controls, and real-world case studies illustrating how the Framework can be applied across sectors. We summarize some of the key updates below.

Continue Reading Singapore Updates Model AI Governance Framework for Agentic AI

The UK Government today announced that it intends to ban social media platforms from offering services to children under 16, alongside wider restrictions on certain online functionalities that the Government has identified as harmful to children.

The announcement follows the conclusion of the Department for Science, Innovation and Technology’s (“DSIT”) consultation, “Growing up in the online world,” which received more than 116,000 responses (we originally wrote about that consultation here). The Government intends to bring the first regulations to Parliament before the end of the year using powers created by the Children’s Wellbeing and Schools Act 2026 (“CWSA”), with protections expected to come into force in Spring 2027. Today’s announcement is the latest in a series of significant developments reshaping the UK’s online safety framework. We summarize some of these latest developments below.

Continue Reading Online Safety in the UK: Social Media Ban for Under 16s and Other Recent Developments

On 19 May 2026, the European Commission published its long-awaited draft, non-binding guidelines on the classification of high-risk AI systems (“HRAIs”) under the EU AI Act (the “Guidelines”). Across three documents—covering general principles, high-risk classification in the context of regulated products (Annex I), and high-risk use cases (Annex III)—the Commission sets out its approach to one of the AI Act’s central questions: when does an AI system fall within the high-risk regime (and, just as importantly, when does it not)?

Continue Reading EU AI Act Update: The European Commission Publishes Draft Guidelines on HRAIs

On June 3, the European Commission published its Tech Sovereignty Package, a set of legislative and policy initiatives designed to address what the Commission characterizes as Europe’s technological dependencies on non-European suppliers. The Package marks a further step in the evolution of the EU’s technology policy, with initiatives spanning the full tech stack—from chips and infrastructure to software, cloud, and artificial intelligence. Through this “ecosystem” approach, the Commission seeks to reduce supply-side dependencies by strengthening domestic capabilities in Europe and stimulating demand in downstream sectors.

The Package comprises four components: two legislative proposals—(i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0—as well as two non-legislative initiatives—(iii) the EU Open Source Strategy and (iv) a Strategic Roadmap for Digitalisation and AI in Energy.

This blog post provides an initial, high-level overview of the four initiatives through which the Commission seeks to advance a “European way” to tech sovereignty, with potential implications for industrial ecosystems in Europe and beyond, including cloud, telecoms, automotive, aeronautics, and defense sectors.

Continue Reading EU Tech Sovereignty Package

California’s new autonomous vehicle regulations create the state’s first pathway for testing and deploying heavy-duty AVs while imposing a more rigorous permitting, safety-case, reporting, and enforcement framework for all AV manufacturers.

Finalized by the California Department of Motor Vehicles (the DMV) on April 28, 2026, the regulations (the Regulations) introduce significant new safety and oversight

Continue Reading California’s New AV Rules Open Door to Heavy-Duty Deployment While Imposing Significant New Compliance Obligations

International regulators are finalizing the first global safety standards for Automated Driving Systems (“ADS”). In January, the UN Working Party on Automated/Autonomous and Connected Vehicles (“GRVA”) approved a draft UN Regulation (“UNR”) under the 1958 Agreement and a draft Global Technical Regulation (“GTR”) under the 1998 Agreement, submitting both for adoption by the UN World Forum for Harmonization of Vehicle Regulations.

Developed in parallel to ensure harmonized technical requirements across jurisdictions, the UNR and GTR are expected to be adopted at the 199th WP.29 session in June 2026. In the meantime, work continues on finalizing the accompanying Guidance and Interpretation Document. This post provides an overview of the UN regulatory framework, the legislative status of the ADS instruments as of May 2026, an outline of the key provisions, and implications for companies across the ADS value chain.

Continue Reading UN Regulation and GTR on Automated Driving Systems: Current State of Play