Story type
Regulation
Statutes, regulatory instruments and implementation milestones that reach legal practice and legal technology.
7 stories
Colorado lawmakers amended the state's Artificial Intelligence Act in a special session, narrowing the definition of consequential decisions and delaying the duty to conduct impact assessments by twelve months. Developers of general-purpose systems are carved out unless they market a system for a consequential use. The attorney general retains exclusive enforcement. The amendments take effect immediately on signature.
The European Commission published the final general-purpose AI code of practice, setting out how providers of large models can demonstrate compliance with the AI Act's transparency and systemic-risk obligations. Signatories gain a presumption of conformity; non-signatories must show equivalent measures. The code covers training-data summaries, copyright policy and incident reporting. Fifteen providers have signed. The Commission said the code is voluntary but that supervision begins immediately.
Read the long piece on LexRegisterMost obligations under the EU AI Act became applicable on 2 August 2026, two years after the regulation entered into force. The date covers Annex III high-risk systems, transparency duties and the national penalty regimes member states were required to lay down. Obligations for high-risk systems embedded in products regulated under Annex I follow on 2 August 2027.
Read the long piece on LexRegisterOfcom confirmed that law firm websites offering user-to-user messaging fall within the Online Safety Act's scope where the messaging is available to the public. Firms operating client portals behind authentication are outside it. The regulator published a decision tree for borderline cases and said enforcement will prioritise services with the largest reach rather than professional services sites.
Cloud switching obligations under the EU Data Act became enforceable, requiring providers to remove contractual, commercial and technical barriers to moving a customer's data to a competing service. Egress charges must be withdrawn entirely from January, and providers must publish the formats in which data is exported. Legal technology vendors hosting client matter data in the Union are in scope regardless of where the vendor is established, and several vendors have already republished their standard terms to reflect the change.
Read the long piece on LexRegisterUtah's Division of Consumer Protection issued guidance on when a regulated occupation must disclose that a consumer is interacting with generative AI. The guidance treats a prominent, plain-language notice at the start of an interaction as sufficient, and says a disclosure buried in terms of service is not. Legal services are named among the regulated occupations covered. The division said a first violation will be treated as an opportunity to cure, provided the interaction caused no demonstrable consumer loss.
NIST released a draft profile applying the AI Risk Management Framework to legal services, mapping the framework's govern, map, measure and manage functions onto tasks such as document review and legal research. The draft is open for comment for sixty days. It is guidance rather than a rule, and carries no independent enforcement mechanism.