Neural Network - July 2026
In this edition of the Neural Network, we look at key AI developments from June and July 2026.
In regulatory and government updates, the EU Council has formally approved the AI Omnibus timetable changes; the European Commission has provided practical guidance on transparency requirements for AI-generated content and set out a new cybersecurity action plan; and the FCA has examined how AI could reshape retail financial services.
In technology developments and market news, Meta has released its latest update for the Muse Spark platform amidst controversy over its AI image generation products.
More details on each of these developments are set out below.
Regulatory and Government updates
EU Council gives final green light to revised AI Act timelines
European Commission publishes Code of Practice on marking and labelling AI-generated content
European Commission publishes Action Plan on AI and cybersecurity
Technology Developments and Market News
Regulatory and Government Updates
EU Council gives final green light to revised AI Act timelines
On 29 June 2026, the Council of the European Union gave its final approval to the AI Omnibus regulation amending the EU AI Act (the “AI Omnibus”), marking the latest step in the EU’s efforts to regulate AI technologies. The adoption of the AI Omnibus brings clarity to the timelines for compliance and adjusts the timetable and several targeted elements of the existing EU AI Act framework.
The key changes under the AI Omnibus are the postponement of certain compliance deadlines, giving businesses more time to prepare for regulatory changes under the EU AI Act. High-risk AI systems, which were originally subject to a compliance deadline of August 2026, now face extended deadlines: Annex III systems must comply by 2 December 2027, while Annex I systems have until 2 August 2028. High-risk systems already on the market can remain available without new certification, provided no significant design changes occur.
The AI Omnibus also introduces a new prohibition targeting AI systems used to generate non-consensual sexual or intimate content and child sexual abuse material, responding to concerns about online harms posed by “nudifier” tools and intimate deepfakes. This ban will take effect from 2 December 2026. Oversight of AI systems built on general-purpose AI models will be centralised under the AI Office, which now holds exclusive competence for such systems (subject to listed exceptions), as well as for those forming part of very large online platforms and search engines.
Despite the deferral of several key deadlines, core transparency obligations under Article 50 will still apply from 2 August 2026 for AI systems placed on the market after this date. These include informing individuals when interacting with AI systems, marking AI-generated outputs in a machine-readable format, and labelling deepfakes. Providers of generative AI systems already on the market will have a four-month grace period to implement detectability measures.
With final approval now complete, and publication in the Official Journal expected imminently, the immediate compliance focus is on the EU AI Act obligations that have not been pushed back. In particular, the Article 50 transparency rules applying from 2 August 2026. We consider the complementary voluntary Code of Practice on marking and labelling AI-generated content in our next article below.
The Commission has also now published final guidelines on the scope of Article 50, which should help organisations assess when chatbot disclosures, machine-readable marking and deepfake labelling are required in practice. The extended high-risk timetable therefore gives businesses more time on some obligations, but it is not a complete pause on EU AI Act compliance.
European Commission publishes Code of Practice on marking and labelling AI-generated content
On 10 June 2026, the European Commission (the “Commission”) published its Code of Practice on marking and labelling AI-generated content (the “Code”). The Code is intended to help providers and deployers meet the EU AI Act’s transparency obligations for AI-generated and manipulated content.
The Code outlines clear steps for identifying and labelling AI-generated content across a range of formats, including text, audio, images, and video. Organisations are encouraged to implement machine-readable markers and visible labels, ensuring that users can easily recognise when content has been created or modified by AI. The Code also recommends that providers develop robust detection mechanisms and maintain records of AI-generated outputs, helping to build trust and accountability in digital communications.
In addition to technical requirements, the Code emphasises the importance of user education and clear communication. Providers are advised to inform individuals when they are interacting with AI systems and to label deepfakes and other synthetic media in a manner that is accessible and understandable. These measures are designed to support compliance with Article 50 of the EU AI Act, which requires transparency in the deployment of AI systems and the outputs they generate.
The publication of the Code is intended to form part of the Commission’s stated strategy to strengthen cybersecurity and AI governance in Europe, following recent initiatives to streamline AI regulation and enhance cooperation between Member States. Signatories will be able to rely on the Code as a voluntary tool to demonstrate compliance, while organisations using other measures will need to show those measures are adequate.
European Commission publishes Action Plan on AI and cybersecurity
On 7 July 2026, the European Commission (the "Commission") presented its Action Plan on Cybersecurity and Artificial Intelligence, developed with the European Union Agency for Cybersecurity ("ENISA"). The Action Plan creates no new obligations for businesses, but rather sets out how the Commission, ENISA and Member States will apply the rules already in force (such as the EU AI Act, the NIS2 Directive, the Cyber Resilience Act and DORA) to the risks posed by advanced AI models. The Action Plan is not binding, but it is likely to shape how existing AI and cybersecurity obligations are applied in practice.
For providers of advanced AI models, the most important proposal is a new EU evaluation capability, expected to be operational in 2027, which will carry out independent assessments of advanced AI models and their risks in support of the AI Office. The evaluation capability will give the Commission its own technical means of assessing whether a model presents a risk, so providers should expect such assessments to depend less on their own documentation and more on independent testing as the facility comes online.
Organisations in critical sectors such as finance, energy, health, transport and public administration are addressed differently. ENISA and the Commission's Joint Research Centre will build a secure platform allowing these organisations to test AI systems in simulated environments before deploying them. This will operate in combination with a "European Blueprint" that will set out the conditions on which they can access advanced AI capabilities for cyber defence.
The Action Plan also encourages organisations to use available AI tools to identify and fix vulnerabilities faster. Both NIS2 and the Cyber Resilience Act require security measures appropriate to the risk, and where the regulator's stated expectation is that defenders use AI to keep pace with AI-enabled attackers, what counts as appropriate may be assessed against that higher standard.
The remaining actions concern industrial policy, including an EU Grand Challenge on AI for cybersecurity and continued investment in European AI infrastructure through the AI Factories programme.
FCA sets out roadmap for AI in retail financial services
On 6 July 2026, the Financial Conduct Authority (the "FCA") published the Mills Review (the "Review"), report commissioned by the FCA Board and led by Executive Director Sheldon Mills on how AI could reshape retail financial services by 2030 and beyond. The FCA describes the Review as the first of its kind initiated by a regulator anywhere in the world.
A key issue in the Review is whether the FCA’s regulatory perimeter needs to change. FCA regulation is built around regulated activities, not technologies, meaning that general-purpose AI tools giving users help with savings, pensions or borrowing may sit outside the regime, even where consumers rely on them in ways that look very close to financial advice. A consumer who acts on poor AI-generated guidance may not have the protections that apply to regulated advice, while authorised firms may find themselves competing with tools that do not carry the same obligations. The Review recommends that the FCA consider, within three to six months, whether these models should be brought within its remit.
The Review also examines how accountability works when AI takes on more decision-making. Research commissioned for the Review found that a fifth of consumers (around 11 million UK adults) would be willing to use AI that acts on their behalf within limits they set, such as moving savings or switching products automatically. The FCA's position is that its existing framework already governs this, since the “Consumer Duty” requires firms to deliver and evidence good outcomes for customers, and the “Senior Managers” regime makes named individuals personally accountable. The challenge is that those obligations become harder to meet where decisions are made by a system rather than an employee. Firms are likely to need clear records of what their AI systems decided and why, routes for customers to reach a person, and a senior manager who owns the outcome.
The FCA is expected to publish examples of good and poor practice in AI later this year, which should give firms a clearer benchmark for what the regulator expects in practice.
Technology Development and Market News
Meta enters pay-for-use AI coding market with Muse Spark update
On 9 July 2026, Meta announced a major update to its Muse Spark model, with Muse Spark 1.1 positioned as its strongest model to date for agentic and coding work. The update marks a shift in Meta’s AI strategy where developers can now access the model through a portal and pay for use, rather than relying on a private partner preview.
The move puts Meta more directly into competition with Anthropic and OpenAI in the fast-growing AI coding market. Meta’s AI chief Alexandr Wang described the pricing as “very aggressive and attractive”, with pricing starting at $1.25 per million input tokens and $4.25 per million output tokens. For now, Meta is limiting API access to its own infrastructure rather than making the model available through third-party marketplaces.
The launch comes as Meta faces pressure to show a clearer return on its heavy AI infrastructure and model investments. Unlike some of its rivals, Meta does not yet have a mature cloud infrastructure business through which to commercialise AI models at scale, making paid API access to Muse Spark an important step towards turning model development into a direct revenue stream.
Separately, Meta’s July AI rollout has already highlighted the risks of moving quickly in consumer-facing AI. On 7 July 2026, Meta launched Muse Image, its first image-generation model from Meta Superintelligence Labs, including a feature that allowed users to generate images by referencing public Instagram accounts. After user and industry backlash over privacy and consent concerns, Meta removed that Instagram-referencing feature on 10 July 2026, saying it had “missed the mark”.
Taken together, the Muse Spark and Muse Image developments show both sides of Meta’s renewed AI push. The company is moving to compete more seriously in paid developer tools, but its rapid reversal on the Instagram image feature is a reminder that AI products embedded in large social platforms can quickly raise questions around consent, likeness and user control.