Brussels Just Took the Teeth Out of Most of the AI Act — But Not the Part That Bites on 2 August
Plus: Anthropic's $1.5bn book-piracy settlement gets final court approval, and an appeals court sanctions a lawyer over citations it merely "suspected" were AI-generated — no proof required.
Last week we flagged that two separate duties land on the same date, 2 August 2026, and that most vendor questionnaires ask about neither. One of those duties just moved. On 8 July, EU institutions reached political agreement on the "Digital Omnibus" package, pushing the AI Act's high-risk obligations back by well over a year: stand-alone Annex III systems (recruitment tools, credit scoring, education, law enforcement, border control, critical infrastructure) now face full compliance on 2 December 2027, not 2 August 2026, and AI embedded in regulated products under Annex I (medical devices, machinery) moves to 2 August 2028. Formal adoption and publication is expected before 2 August. What didn't move: Article 50 transparency duties and the Commission's enforcement powers over general-purpose AI models with systemic risk both still switch on 2 August 2026 exactly as planned. If your team read "AI Act delay" in a headline and stood down, that's the wrong takeaway from this one.
Or jump to: this week's workshop · the security self-assessment prompt · a couple of things from me
This Week's Reading
Update your compliance calendar, don't clear it. If you had an Annex III workstream racing toward August, you've bought well over a year. Redirect that team's near-term focus to the GPAI vendor questions and transparency-labelling decisions that are still due in under two weeks — that clock didn't move.
This is the first nine-figure price tag on "where did your AI vendor's training data actually come from." Most AI vendor due diligence still treats this as a generic IP indemnity question. After this settlement, it deserves its own specific warranty and its own line in the risk register — for every AI tool sitting under your team's workflows, not just the obvious ones.
The bar for sanctions just dropped further. Courts no longer need to prove a citation came from AI — only that it wasn't verified. Your verification checkpoint needs to cover every citation that leaves the building, not just the ones somebody flags as "AI-assisted."
This Week's Workshop
Security of Your Systems
You may have seen the story this week: an OpenAI model, chasing a better benchmark score, broke out of its own sandboxed test environment, exploited a zero-day vulnerability and used stolen credentials to gain remote code execution on Hugging Face's servers — without ever being instructed to. It's a stark illustration of why "Technical and Organisational Measures" (TOMs) aren't a compliance checkbox; they're what actually stands between an AI system and your infrastructure. Today's prompt (below) takes you through your own TOMs across seven areas, so you can find out where you genuinely stand. For a longer, 20-minute look at AI security and how it applies specifically to agents, see this post: watch here →
Agent Builder Course — Five Days, One Hour a Day
Learn to build, deploy and continuously improve AI agents for your legal team's hardest recurring work — contract triage, due diligence, document assembly, compliance monitoring. No coding required. Works with any LLM, including Microsoft Copilot. Spaces are limited.
More details and booking here →
Book a CallThis Week's Prompt: The Technical & Organisational Measures (TOMs) Interview Prompt
Use this when you need a first-pass picture of the security of your own organisation's systems — or a vendor's, before you sign. It interviews you across the seven areas a regulator or a customer's due diligence questionnaire will usually ask about: Backup, Authentication, Testing, Firewall, Internal Controls, Supply Chain, and Training. Paste the whole thing into Claude, ChatGPT, or any LLM and answer one question at a time — it ends with a RAG-rated summary, priority actions, and a list of evidence to go and request to verify what you've been told. It's a long, structured prompt, so it's saved as a document rather than run inline here:
A Couple of Things From Me
I'm speaking at an AI event in London, and as a speaker I've been given a handful of complimentary tickets. If you'd like one, just hit reply and let me know — first come, first served.
Second, a recommendation for something I didn't build. I've been working through a course on using AI in your personal life — specifically getting AI to actually know you: your personality type and how you think. It's genuinely useful, but worth knowing upfront that it works by having you share a fair amount of personal data with AI, which won't suit everyone.
If that trade-off is fine by you: take a look here →
This is an affiliate link — I get a small commission if you sign up, at no extra cost to you.
Want More Prompts & Workflows?
For prompts and more detailed workflows like this one, take a look at our book on AI for legal professionals. Explore step-by-step guides, ready-to-use prompts, and best practices for integrating AI safely into your legal work.
Explore the Book →Until next Monday,
— Richard Nicholas
Got a story I should cover, or a question about something here? Just hit reply — I read every one. (Received this one secondhand? Reach me directly at [email protected].)
Get This Newsletter Every Week
Curated AI and legal governance news, a copy-paste prompt, and a practical workshop — delivered free to in-house counsel every Monday.
Get Next Monday's Issue →