Neural Network - September 2026
In this edition of the Neural Network, we look at key AI developments from August and September 2026.
In regulatory and government updates, we take a look at the latest on how leading LLM providers are addressing the new transparency requirements under the EU AI Act; review a recent decision by the Italian Data Protection Authority concerning deepfakes generated without the data subject’s consent; and examine the UK Jurisdiction Taskforce’s Statement on Liability for AI Harms. We also summarise the warnings issued by the Financial Conduct Authority regarding cybersecurity threats posed by AI; and review the Joint Committee on Human Rights’ proposals for legislative reform in the UK.
In technology developments and market news, we look at the pressure on leading AI companies to respond to concerns regarding security and the pace of development, and some standout investments and acquisitions.
More details on each of these developments are set out below.
Regulatory and Government updates
How leading LLM providers are addressing transparency obligations
Sanctions for deepfakes under the General Data Protection Regulation (the “GDPR”)
UK Jurisdiction Taskforce publishes statement on liability for AI harms
Financial Conduct Authority flags cybersecurity risks of frontier AI
Joint Committee on Human Rights identifies human rights risks posed by AI
Technology Development and Market news
Regulatory and Government updates
How leading LLM providers are addressing transparency obligations
As we reported in our August update, the Article 50 transparency obligations (“Transparency Obligations”) under the EU Artificial Intelligence Act (“EU AI Act”) came into force on 2 August 2026.
In addition to following the non-binding Commission Guidelines on the transparency obligations of providers and deployers of AI systems (“the Guidelines”), providers and deployers can also sign up to the Commission’s Code of Practice on Transparency of AI-generated Content (“the Code of Practice”) as a way to demonstrate compliance. Whilst voluntary, it is currently the only EU-wide framework the Commission has endorsed for demonstrating compliance with the Transparency Obligations. As at the date of writing, 234 organisations have signed up to the Code of Practice, including several prominent AI providers such as Anthropic, Google, Meta, Microsoft, Mistral, and OpenAI,.
Current Approaches
Providers of generative AI systems already on the EU market before 2 August 2026 have until 2 December 2026 to implement machine-readable detectability or watermarking for AI outputs.
Anthropic, the developer of the Claude AI system, has already published its approach. It has confirmed that all Claude models launched on or after 2 August 2026 will embed invisible watermarking in generated text and digitally signed provenance metadata in generated images. The watermarking will be undetectable to the reader but visible to anyone who holds a key (or submits a “Claude Watermark Detector Access Request Form”). When Claude generates a supported file type, such as .svg, .png, or .jpg, it attaches signed provenance metadata to the file. This metadata is structured in accordance with the C2PA (Coalition for Content Provenance and Authenticity) open standard, which is widely adopted across the industry. Claude has also published a corresponding “content credential” file checker so that individuals can ascertain whether a file may have been made or processed by Claude.
Google DeepMind appears to have been an early adopter of watermarking, having watermarked its AI-generated images since 2023. It now embeds invisible watermarks into images, audio, text and videos that are deployed across Google products at scale. For a user to check if an image was generated by AI it must ask Gemini, Google’s multi-modal LLM.
Microsoft has not yet detailed its method of watermarking but does offer users the option to add visible watermarks on generated pictures or audio. OpenAI uses C2PA metadata for images, and in May 2026 announced a partnership with Google DeepMind to embed SynthID watermarking in its AI generated image outputs. It previously released an AI text classifier in 2023 but discontinued it due to low accuracy. It has not since deployed a publicly available text detection system for written content. We will continue to monitor developments with interest.
A key takeaway is that whilst watermarking is rapidly becoming a standard capability, the technology is still being developed, and no single technique currently satisfies all requirements under the Transparency Obligations. A multi-layered approach - combining metadata, watermarking, and content provenance - is the interim industry standard.
Sanctions for Deepfakes under GDPR
On 23 July, the Italian Data Protection Authority (the “Garante”) issued a warning against broadcaster R.T.I. S.p.a (the “Company”) for airing satirical, AI-generated deepfakes depicting well-known Italian personalities. One data subject was journalist and TV host Enrico Mentana, who was depicted commenting on the news, in the studio in which he usually works, but with words generated by real footage aired on a different channel.
The Garante found that the videos had not been adequately marked as AI-generated, resulting in a breach of Article 5(1)(a) of the GDPR (lawfulness, fairness and transparency), notwithstanding the Company’s assertions that verbal disclaimers had been provided and that the comedic nature of the voiceover made it unlikely the footage would be mistaken for authentic content. The Garante specifically noted that, in the context of television broadcasts, a verbal disclaimer during the programme was insufficient, as some viewers may have tuned in after the disclaimer had already been given.
Additionally, the Garante concluded the Company had processed personal data, including images and voices, without obtaining valid, informed consent from the affected individuals, and noted that there had been insufficient considerations of fairness at the design stage, by failing to assess of the risk of harm, specifically reputational harm, which could arise as a consequence of the broadcast.
For businesses, this action illustrates the importance of complying with the deployer Transparency Obligations and demonstrates two key points from the Guidance on deepfakes, on the question of whether an AI-generated or manipulated image, audio or video content resembling an existing person would “falsely appear to a person to be authentic or truthful”:
such assessment is objective and does not require the intention of the deployer to deceive or mislead the natural persons exposed to the content for it to constitute a deepfake; and
due consideration must be given to the possible diverse composition of the “reasonably foreseeable audience that may be exposed to the deep fake content”.
UK Jurisdiction Taskforce publishes statement on liability for AI harms
LawTechUK’s Jurisdiction Taskforce (the “UKJT”) is an industry-led initiative, tasked with promoting the use of English law and UK’s jurisdictions for technology and digital innovation. The UKJT has published its final Legal Statement on Liability for AI Harms under the private law of England and Wales (the “Statement”), following a public consultation. The purpose of the Statement is to explain the application of existing laws when considering liability issues arising from AI-related harms, with the aim of providing certainty and predictability.
The Statement’s central message is that in most cases, liability for AI harms will be governed by existing principles of contract or tort law, with there being “no conceptual reason” why negligence principles cannot be applied to AI harms. Further, whilst no one can be vicariously liable for the actions or failures of an AI system itself, an employer can be held vicariously liable for AI-related harm caused by a human employee acting wrongfully while using AI.
We’ve highlighted some further useful learning points from the Statement below.
Loss Caused by AI
The Statement confirms that, in most commercial contexts, loss from the use of AI will be primarily managed and allocated through contractual arrangements between parties in the AI supply chain, but emphasises that businesses may be liable for loss caused by the use or deployment of AI, particularly where a company negligently fails to exercise reasonable care in selecting, testing, or overseeing AI systems, resulting in foreseeable harm to clients, customers, or third parties.
The strict liability regime under the Consumer Protection Act 1987 (i.e. for death, personal injury, or property damage caused by a defective product) applies when AI is integrated into physical products. Pure software and AI services fall outside the scope of strict liability, although it is anticipated that a future review of the law by the Law Commission will address the status of “pure software”. This position is especially relevant for manufacturers or those supplying AI-augmented products who are bound by product safety standards and consumer rules.
The Statement emphasises the need for reasonable care and skill to be taken by professionals when using AI. A professional can be found negligent for inappropriate use of AI, failure to validate outputs, or even failure to use AI where a competent professional would have done so. The Statement notes that professional standards are informed by expert evidence and guidance from relevant bodies, and corporates should ensure their teams are up to date with evolving practices.
False Statements
The potential liability for misrepresentation and deceit arising from the use of AI is also addressed in the Statement, particularly in relation to the impact of hallucinations.
If a business adopts or presents AI generated outputs (such as chatbot responses or automated reports) as its own and those outputs turn are false, the business could face liability for negligent misrepresentation if it failed to take reasonable care in verifying the information and a third party relied on it to their detriment. The Statement notes there is no English authority on whether AI can make a statement "on behalf of" a legal person; liability would generally require the business to have held the chatbot out as communicating on its behalf or to have represented that its outputs are correct. In more serious cases, if a business knowingly permits or intends its AI system to produce false or misleading statements (perhaps to induce another party to act), it could be exposed to liability for deceit if intent or recklessness is evidenced.
Whilst the Statement provides reassurance that English law is sufficiently adaptable to accommodate AI liability issues without the need for an AI-specific regime, as AI continues to transform business operations, it also underscores the importance of:
- proactive risk management;
- robust contractual protections;
- professional oversight; and
- clear statements and disclaimers when using AI to communicate with customers, partners and the public.
Financial Conduct Authority Flags Cybersecurity Risks of Frontier AI
On 2 September 2026, the Financial Conduct Authority ("FCA") published a review (the "Review") reporting the impact of frontier AI on the governance, vulnerability management and cybersecurity practices of small and medium-sized financial services firms ("Firms"). The Review follows the joint statement issued by the FCA, Bank of England and the HM Treasury in May 2026 on the relationship between frontier AI models and cyber resilience, as reported in our June Data and Cyber Update.
A central theme from the Review is that frontier AI is accelerating the "identification, validation, and prioritisation of vulnerabilities" within Firms. As AI capabilities rapidly advance, Firms have to ensure that their internal processes are sufficiently robust and adaptable to manage the increasing volume and complexity of cyber risks.
In practice, this means that Firms must continue to regularly stress-test their remediation and incident response procedures and ensure that appropriate third-party support is in place to address the pace of vulnerabilities uncovered by frontier AI.
The other themes reported by the FCA were that the value of frontier AI depends largely on a Firm’s operating environment, rather than the models being used, and that despite the efficiencies brought by frontier AI, effective human judgement and oversight remains critical. Firms should continue to rely on human oversight to prioritise action and manage risk and invest in robust governance. This should position them to harness the benefits of frontier AI while meeting regulatory expectations and protecting against emerging cyber threats.
Joint Committee on Human Rights identifies human rights risks posed by AI
On 14 September 2026 the UK’s Joint Committee on Human Rights (the “JCHR”) published a 100-day report (the “Report”) calling for new legislation in the UK to address the risk to human rights associated with rapid AI adoption and recommending the establishment of a new dedicated regulator to coordinate the response.
This development comes amid growing concern about the rapid advancement of AI, with several high-profile warnings, including claims widely publicised in mainstream media that the pace of development could result in a greater than 10% chance of AI posing an existential threat to humanity.
Criticism of the current legislative regime
The Report described the legislative framework as “patchy and confused” and identified three principal issues:
Equality and non-discrimination: despite well-documented risks of training AI models with biased data, the Report noted that the Equality Act 2010 applies only to individuals receiving services, excluding business-to-business contexts, which risks failing to address the various ways bias can be embedded in AI systems.
Privacy and personal data: the Report found “web scraping” for data to train AI models is unlikely to comply with UK GDPR and often insufficiently considers the balance between individual rights and legitimate interests, especially in invasive contexts such as live facial recognition. Additionally, the increased volume of personal data collected by AI models increases the ability and consequential risk of re-identifying individuals from previously anonymised information.
The right to an effective remedy: despite progress in Europe with the EU AI Act, transparency around AI remains limited. Individuals often cannot determine when or how AI has been used and are therefore unable to challenge its use. This issue is exacerbated by AI’s growing ability to convincingly imitate human behaviour. The opaque nature of AI processes makes it difficult to obtain information about potential harm, and existing legal protections are not comprehensive, resulting in significant gaps in legal protections.
The Proposals
The Report sets out two principal recommendations:
The adoption of an AI bill, which would give full effect to the EU Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, by assigning obligations commensurate with the risks of different AI models, including a requirement for pre-approval where the risk is deemed especially high.
Establishing a single independent AI oversight body, on a statutory basis, with broad powers to coordinate, monitor, enforce the AI Bill, and ensure responsible AI use across industries consistently.
Additionally, it is proposed that the AI Security Institute (“AISI”) be placed on a statutory footing, with authority to review new and revised powerful AI models and a duty to advise the independent AI oversight body of the need to prevent the launch or require the withdrawal of AI systems that pose significant human rights risks.
To avoid overlapping responsibilities, the report recommends combining the existing functions of the AISI with those of the new regulator.
The Labour Government previously acknowledged the need to regulate AI, confirming in the King’s Speech in 2024 its intention to introduce requirements for those developing the most powerful artificial intelligence models. While no progress into an AI Bill was made under the Starmer Government, Andy Burnham, upon forming his cabinet, appointed Kanishka Narayan as AI Minister on 20 July 2026 and elevated the role to cabinet level, indicating a potentially greater appetite for regulation.
We will continue to monitor developments closely in the coming months.
Technology Developments/Market News
AI Security Under Scrutiny: Meta, OpenAI, and Hugging Face Hacking Allegations and Responses
Technology firms are facing increased scrutiny following a series of AI security incidents in which advanced models exploited vulnerabilities during testing, resulting in unauthorised access to other organisations’ systems. These events are significant, as they highlight the risk of legal claims from affected parties and intensify pressure on international regulators to strengthen security standards. The incidents risk undermining confidence in the pace of AI development and prompt important questions regarding the safeguards needed as AI capabilities continue to evolve.
In July 2026, Anthropic disclosed that its AI models independently breached the systems of three organisations during a 'controlled' security experiment. The incident adds to a growing list of several high-profile incidents that have been reported in recent months, in which AI agents from major developers breached systems at other companies during testing, including:
Alleged exploitation of DseWiki: An OpenAI model was reported to have accessed DseWiki, a German website, raising concerns about AI’s unauthorised access of online platforms.
Compromise of Hugging Face’s internal systems: During internal testing of an AI model, OpenAI confirmed that the AI agent used had compromised Hugging Face’s systems, demonstrating the risks of AI even within controlled environments.
Meta reported the unauthorised access of an AI model: Following an independent evaluation conducted by Meta, it has been revealed that one of its AI models gained internet access and connected to another organisation’s systems without authorisation.
Each technology company involved has taken steps to demonstrate accountability and address the actions of its AI models. Following OpenAI’s disclosure regarding the Hugging Face incident, Meta initiated its own internal investigation into similar activities involving its AI models and has committed to publishing further details once its investigation concludes.
From a legal standpoint, these incidents raise the potential for claims of unauthorised access to information and the potential security risks posed by the fast pace of development.
Standout AI Investments and Acquisition
(a) Mistral secures €3 billion in Europe’s largest-ever private tech fundraising
Mistral AI, a Paris-based artificial intelligence startup, has raised €3 billion in its latest funding round, the largest private fundraising for a tech company in Europe to date. Mistral primarily focuses on developing AI solutions that allow organisations to maintain control over both the infrastructure and intelligence. The funding round was led by Samsung Electronics and is intended to support ongoing research and secure increased computing capacity, enabling Mistral to compete with Chinese AI labs in frontier AI training and model scaling.
(b) Nvidia to acquire AI platform Hugging Face in $13 billion deal
Nvidia has agreed to acquire the AI model platform Hugging Face for US $13 billion. Of which, US $11 billion will be paid to Hugging Face investors, with approximately US $1 billion allocated to an equity-based retention program for staff joining Nvidia. This transaction follows Hugging Face’s decision less than a year ago to reject a US $500 million investment, over concerns regarding Nvidia’s potential influence on the business.
Hugging Face has positioned itself as an alternative to traditional Silicon Valley models, offering “open” models that users can download, operate, or modify.
The transaction is scheduled to complete in 2027, although it is expected to be subject to scrutiny by competition regulators.
(c) Google strikes €13bn deal to power Finland’s AI infrastructure with nuclear energy
Google has made a record-breaking €13 billion investment, signing a 22-year contract with Finnish utility Fortum to purchase up to 50% of the output from the Loviisa nuclear power plant. In addition, Google plans to build three new Finnish data centres, and expand its existing facilities. Finland’s cold climate makes it an attractive location for data centres, as the low temperatures help reduce the energy required to cool computer servers.
Google’s significant investment and long-term energy contract in Finland reflects a growing trend of technology companies prioritising reliable and sustainable energy sources to support future growth and operational efficiency.