OpenAI's standards proposal, read in full: what it asks of government, which bodies it names, how it compares with ISO/IEC 42001, the NIST AI RMF and EU harmonised standards, and where OpenAI's commercial interest lies.
What the UN scientific panel's first brief on AI agents actually says, what status it has, what its evidence from the OpenAI and Hugging Face incident carries, how it compares with the International AI Safety Report and UK AISI, and what to fix first.
The DPC's €403m Google fine covers 620 days that ended the day its inquiry opened. It names no articles, publishes no split, and one finding turns on evidence Google could not produce.
One Flock camera's firmware runs a person detector, held 27,321 video clips and left its media key on the same partition. What was found, what Flock says, how UK ANPR is regulated, and what buyers should demand.
Bessent says the US proposed an AI incident notification mechanism to China. Xinhua's 169-character readout mentions AI once and no mechanism. What each side committed to, what neither said, and the limited UK angle.
Of the 14 examples in the EDPB's new fining guidelines, three end in a fine. The draft changes whether regulators fine, not how much, and a repeat minor breach is the route to a penalty.
The __obi cookie is filed under analytics, lasts 365 days and travels from advertiser sites to OpenAI. We checked the claim against OpenAI's policies and set out what UK organisations and website owners must do.
Buist v. Anthropic is a real federal antitrust case. Its central facts remain allegations, and the difference between public agreement and commercial coordination will decide it.
The AI Force announcement sits on top of an existing federal AI structure. Until authority, mission and resources are published, duplication is the central risk.
The quoted phrases are real. They come from a plaintiffs' brief citing a fact statement whose exhibits are sealed, in a case where no court has ruled on fair use. What the filings establish, what they do not, and what UK buyers should check.
Governor Newsom's order does not require anyone to build a kill switch. It asks for a memo in 59 days, and quietly pulls two auditor deadlines forward by 245 and 397 days.
The Commission says no formal Article 55 report exists for RubyGems. On the AI Act's own definition of a serious incident, OpenAI may not have had to file one, and that gap is the story for anyone buying frontier models.
Domain control is a real enforcement lever against offshore people-search sites, but the Radaris record shows the address can move faster than the court. What the orders say, what stayed online, and what UK teams can actually do.
The AEPD's first AI-agent breach notification rests on the controller's own account. What was claimed, what was not, why it is an attack with AI rather than on AI, and what UK GDPR teams should actually change.
A practitioner reading of the UK's 32 healthcare AI recommendations: lifecycle evidence, model updates, equity, incident reporting, clinical oversight and what NHS buyers should do now.
Updated 16 September: the portal launched on time on 11 September. Our 8 September measurement found the host not completing a TLS handshake three days before the duty began. Three new obligations arrived in the same edit.
Read from Hansard and the Bills API. A returning commitment with a new gate, a contradiction inside one debate, and a Government vendor package the Government did not move.
Checked against the Bills API. Directions can require removing or disabling installed equipment, reach outside the UK, and arrive with neither a delegated powers report nor an impact assessment.
Read from the Bills API rather than the marshalled list. Three procedural duties, no defence, and a government commitment that has quietly lost its central phrase in nine months.
Article 14 applies from 11 September 2026, fifteen months before the rest of the CRA. Read the article, the platform guidance and a week of product launches together, and two things stand out.
Read both Hansard transcripts in full. Board ownership of cyber risk has fallen from 38% to 27%, staged reporting was refused, data centres get a broader threshold with no stated factors, and AI is not named anywhere.
Reddit and Roblox were designated Very Large Online Platforms on 31 August 2026. ChatGPT was designated a Very Large Online Search Engine, under a definition written in 2022 for services that index the web.
John Ternus became Apple's CEO on 1 September 2026 and the Newsroom feed has carried nothing since 27 August. Counted across the press release and both SEC filings: no AI, no Siri, no encryption.
Everyone is planning for December 2027. The duty that actually lands first arrives on 11 September 2026, applies retroactively to products already sold, and is the fourth incident clock now running in parallel.
Group people by what they do with AI, cover failure rather than only capability, tie it to your own tools, and keep the evidence an obligation of means actually requires.
Work from the risk treatment plan rather than from Annex A, justify every exclusion in terms an auditor accepts, and keep applicability separate from implementation.
Ten days: join the systems that already know, reconcile the disagreements, add classification and lifecycle state, and close the gap between withdrawn and disposed.
Seven steps to a completed gap assessment: every clause and Annex A objective in one of three states, each gap owned and dated, sequenced into what to do first.
High-risk slipped sixteen months. Article 50 transparency did not move an inch and applied from Sunday. The obligation that actually landed is the one that got no attention.