On 10 July 2026, Ofcom published a package of draft materials as part of the third phase of its implementation of the Online Safety Act (the “Act”). While the Act already imposes baseline duties to tackle illegal content and to protect children (where a service is likely to be accessed by them) on all regulated user-to-user and search services, the 10 July package provides a set of additional duties targeted at the UK’s largest and most widely used online services.

The package is comprised of three connected strands:

  • The Register of Categorised Services. Ofcom published its long-awaited register, formally designating services across Category 1, Category 2A, and Category 2B, together with a list of “emerging” Category 1 services.
  • Consultation: Draft Fraudulent Advertising Codes of Practice (Category 1 and 2A): The draft codes of practice set proposed measures for how the largest user-to-user and search services should tackle paid-for fraudulent advertising.
  • Consultation: Draft Additional Duties Code of Practice and Guidance (Category 1 only): The draft codes of practice and associated guidance address user empowerment and identity verification, protections for certain public-interest content, terms of service, complaints, and freedom-of-expression and privacy assessments.

This post focuses on the third strand—the additional duties for Category 1 services.

Continue Reading UK online safety update: Ofcom’s Category 1 proposals and DSIT’s latest response to “Growing Up in an Online World”

On July 16, 2026, the Federal Communications Commission (“FCC”) released a draft Notice of Proposed Rulemaking (“NPRM”) seeking comment on proposals to permit direct-to-device (“D2D”) operations from satellites to unlicensed equipment.  Currently, D2D devices that communicate with satellites would need to be licensed in one form or another.  The NPRM sets out the following bands

Continue Reading FCC to Vote on Unlocking Spectrum for Direct-to-Device Operation for Unlicensed Equipment
On 3 June 2026, the European Commission published several legislative and policy measures wrapped up in one “tech sovereignty” package (see our posts summarising the package as a whole here, and diving deeper into the Cloud and AI Development Act here). But the EU’s tech sovereignty drive has a long history, and is by no means limited to this package. In this post, we take a closer look at the current and forthcoming EU legislative measures aimed at increasing the resilience of services provided in the EU against external, malicious influence, a key aspect of tech sovereignty. Relevant legislation falls into two broad categories: (1) laws promoting cyber resilience generally, to prevent malicious actors from disrupting services and critical infrastructure; and (2) laws focused on building supply chain resilience and reducing dependencies on certain external actors by building European industrial capacity in key tech sectors. Continue Reading Looking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilience

This update highlights key legislative and regulatory developments in the second quarter of 2026 related to artificial intelligence (“AI”), connected and automated vehicles (“CAVs”), and Internet of Things (“IoT”).

Continue Reading U.S. Tech Legislative & Regulatory Update – Second Quarter 2026

On July 6, 2026, Illinois Governor JB Pritzker signed into law SB 315, a frontier model safety act that resembles the New York RAISE Act, discussed in our prior blog post here, and California’s Transparency in Frontier Artificial Intelligence Act (TFAIA), discussed in our prior blog post here. The law takes effect January 1, 2027, with transparency-reporting and audit obligations beginning January 1, 2028.  Similar to the New York and California laws, SB 315 will apply to frontier developers (i.e., persons that train, or initiate the training of, a frontier model using computing power greater than 10^26 integer or floating point operations), with certain provisions applicable only to large frontier developers (i.e., frontier developers with annual gross revenue over $500 million in the preceding year). SB 315 also includes public safety disclosure and reporting requirements. Notably, SB 315 also imposes a third-party audit requirement not found in either the New York or the California law.

Continue Reading Illinois Enacts Frontier Model Safety Law

On June 4, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a sweeping discussion draft of their Great American Artificial Intelligence Act. The latest bipartisan AI legislation quickly met bipartisan skepticism, particularly concerning the draft’s approach to federal preemption of state AI rules, with many House Democrats opposing the broad preemption for frontier model developers, while many House Republicans and other stakeholders lamented the bill’s omission of preemption for state laws reaching other parts of the AI ecosystem. 

The bill would also establish mandatory disclosure and risk-mitigation requirements for frontier models and task the Center for Artificial Intelligence Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) with oversight of federal AI-related research and analysis, standards and guidelines development, and risk-mitigation activities.  

Continue Reading Backlash to Bipartisan AI Omnibus Illustrates Preemption Impasse

Executive Summary

2026 has been a dynamic year so far for federal regulation of automotive safety. Federal regulators have demonstrated a sustained commitment to regulatory reform and innovation, while simultaneously advancing efforts to facilitate the deployment of autonomous vehicles. Congress has also renewed its focus on vehicle safety and automation as lawmakers consider legislation that could significantly reshape the federal framework governing AVs and vehicle-safety regulation.

Although the path to a comprehensive federal framework for AVs remains uncertain, NHTSA and other agencies continue to pursue opportunities to advance a deregulatory agenda while promoting innovation. Efforts to pave the way for large-scale autonomous vehicle deployment are underway at the National Highway Traffic Safety Administration (NHTSA) and the Federal Motor Carrier Safety Administration (FMCSA). Congress is also paying attention to motor vehicle safety, with surface transportation reauthorization looming and numerous proposed bills that could provide a federal framework for AVs and reform NHTSA’s exemption process, long viewed as a roadblock for vehicle manufacturers.

The next year-and-a-half presents a window of uncommon opportunity for industry to help shape vehicle safety rules that deliver safety value without stifling innovation. These developments collectively suggest that industry stakeholders will continue to have meaningful opportunities to influence vehicle-safety policy through agency engagement, rulemaking participation, and legislative advocacy.

Continue Reading Federal Vehicle Safety at Midyear: Regulatory Relief, Legislative Momentum, and the Road to the Broader AV Deployment

A key benefit of quantum computing is that it may, in the future, enable a very substantial increase in computing power.  This could create significant benefits, in the life sciences and financial services sectors (see our prior posts on the potential implications for these sectors here and here).  However, it also creates potential risks.  In particular, it could lead to the breaking of many of the encryption methods currently used by governments and businesses alike.  As commercially-viable quantum computers become an increasing reality, organisations must prioritise “quantum readiness” and specifically migration to post-quantum cryptography (“PQC”).

In this post, we set out a brief overview of the main steps that regulators and industry bodies (including the U.S. National Institute of Standards and Technology (“NIST”), the UK National Cyber Security Centre (“NCSC”), and the EU Agency for Cybersecurity (“ENISA”)) have indicated businesses should take to move towards PQC and protect their data and systems from the risks posed by quantum computing.

Continue Reading Post-Quantum Cryptography: A Practical Guide

Since our prior post on Singapore’s Model AI Governance Framework for Agentic AI, Singapore’s Infocomm Media Development Authority (“IMDA”) has published an updated version (Version 1.5) (the “Updated Framework”), incorporating feedback from over 60 organizations.

The Updated Framework, published on May 20, 2026, retains the same four-pillar structure—(1) assess and bound the risks upfront, (2) make humans meaningfully accountable, (3) implement technical controls and processes, and (4) enable end-user responsibility—but expands the guidance in several notable respects. These include a new discussion of multi-agent systemic risks, more granular guidance on technical controls, and real-world case studies illustrating how the Framework can be applied across sectors. We summarize some of the key updates below.

Continue Reading Singapore Updates Model AI Governance Framework for Agentic AI

Today, the California Public Utilities Commission (“CPUC”) issued a decision revising and clarifying its regulatory framework for providers of interconnected voice over Internet protocol (“iVoIP”) services.  Most notably, the decision reopens the window for iVoIP providers to demonstrate that they do not provide services subject to a new license type that would, among other things

Continue Reading California Reopens Opt-Out Period for Certain Interconnected VoIP Licenses and Refines Associated Regulatory Framework