Two Weeks Until Brussels Can Fine — and Pull — an AI Model
Plus: a New York court fines a lawyer $10,500 over fake AI citations, The New York Times accuses OpenAI of hiding evidence in the copyright trial — and this week's workshop shows how to build an agent that audits your own website before a regulator, or a customer, does it for you.
Last week we covered the EU AI Act's Article 50 transparency duty, live from 2 August. There's a second deadline landing on exactly the same date that matters just as much: the European Commission's supervision and enforcement powers over general-purpose AI models with systemic risk also switch on that day — the power to demand documentation, run technical evaluations, order risk mitigation, force a model off the EU market, and fine providers up to 3% of global turnover or €15m, whichever is higher. Two different duties, one date, and most vendor due diligence questionnaires currently ask about neither. This week's issue also leans into a theme running through all three stories below — verification — with a featured agent that shows what an audit-ready, defensible AI output actually looks like end to end.
Or jump to: this week's featured agent & worked example · this week's workshop video
This Week's Reading
This changes the shape of vendor due diligence, not just your own compliance file. Ask every GPAI supplier sitting under your chatbots, drafting tools and copilots whether their model has been classified as systemic risk, and get contractual assurance about how they'll respond to a Commission information request, evaluation, or withdrawal order. A vendor who can't answer that in two weeks is a vendor whose model could disappear from the market with no notice to you.
The fix isn't banning the tool — it's a named, mandatory verification step before anything leaves the building. This applies well beyond litigation: regulatory submissions, board papers and internal memos with AI-sourced citations or figures all carry the same risk. This week's featured agent (below) is a working example of exactly that — an AI output built to be checked, not just trusted.
Whatever the outcome, this is a live demonstration of what "litigation hold" means for an AI vendor relationship. Check now — not after a court forces the question — whether your AI tool contracts let you preserve prompts, outputs and logs on request, and whether your vendor has actually confirmed it can search that data if asked.
This Week's Workshop
Building an AI Agent That Shops Your Website — Then Reports What It Found
Following the verification theme running through this week's reading, this workshop walks through building an agent that does what a mystery shopper would: browse, search, add to basket, and run checkout up to — but never through — the final payment screen, then flag every point of friction and every likely breach of UK consumer law it found along the way. Think fake urgency banners, prices that change at the last screen, pre-ticked consent boxes and cookie banners that nudge you toward "Accept all." It's relevant to any business with a consumer-facing website, and it's the same audit-ready thinking as this week's featured agent, below — applied to the site you already have live.
Agent Builder Course — Five Days, One Hour a Day
Learn to build, deploy and continuously improve AI agents for your legal team's hardest recurring work — contract triage, due diligence, document assembly, compliance monitoring. No coding required. Works with any LLM, including Microsoft Copilot. Spaces are limited.
More details and booking here →
Book a CallThis Week's Resource: The Consumer Journey & Compliance Audit Agent
This agent walks a website exactly as a real first-time customer would — browsing, searching, adding to basket, running checkout up to (never through) the final payment screen, creating an account, and handling the cookie banner — then produces a single report grading the shopping experience and rating compliance against UK consumer protection law, including the DMCCA 2024 provisions the CMA has been actively enforcing since April 2025: fake urgency claims, fake reviews, drip pricing, pre-ticked consent boxes and unlawful card surcharges. It never spends real money or submits a live payment — that boundary is checked twice in the agent's own process.
Attached below is the agent's golden example: a full worked audit report for a fictional retailer, Northbridge Outdoor Ltd, showing the target shape and depth of output — experience scorecard, RAG compliance findings table, and a remediation plan with named owners and dates. It's a worked example built to show what the output looks like, not a real audit — no real site was visited and no order was placed in producing it.
Want More Prompts & Workflows?
For prompts and more detailed workflows like this one, take a look at our book on AI for legal professionals. Explore step-by-step guides, ready-to-use prompts, and best practices for integrating AI safely into your legal work.
Explore the Book →Until next Monday,
— Richard Nicholas
Got a story I should cover, or a question about something here? Just hit reply — I read every one. (Received this one secondhand? Reach me directly at [email protected].)
Get This Newsletter Every Week
Curated AI and legal governance news, a copy-paste prompt, and a practical workshop — delivered free to in-house counsel every Monday.
Get Next Monday's Issue →