Skill Diligence

AI for In House Counsel

Practical AI for In House Counsel

Issue 31 · 27 July 2026

Brussels Just Took the Teeth Out of Most of the AI Act — But Not the Part That Bites on 2 August

Plus: Anthropic's $1.5bn book-piracy settlement gets final court approval, and an appeals court sanctions a lawyer over citations it merely "suspected" were AI-generated — no proof required.

Last week we flagged that two separate duties land on the same date, 2 August 2026, and that most vendor questionnaires ask about neither. One of those duties just moved. On 8 July, EU institutions reached political agreement on the "Digital Omnibus" package, pushing the AI Act's high-risk obligations back by well over a year: stand-alone Annex III systems (recruitment tools, credit scoring, education, law enforcement, border control, critical infrastructure) now face full compliance on 2 December 2027, not 2 August 2026, and AI embedded in regulated products under Annex I (medical devices, machinery) moves to 2 August 2028. Formal adoption and publication is expected before 2 August. What didn't move: Article 50 transparency duties and the Commission's enforcement powers over general-purpose AI models with systemic risk both still switch on 2 August 2026 exactly as planned. If your team read "AI Act delay" in a headline and stood down, that's the wrong takeaway from this one.

1

This Week's Reading

Top Story
European Commission / Digital Omnibus on AI · political agreement 8 July 2026, formal adoption expected before 2 August
EU Defers Most of the AI Act's High-Risk Rules by Up to Two Years
Stand-alone high-risk systems under Annex III — recruitment, credit scoring, education, law enforcement, border control, critical infrastructure — now face full compliance on 2 December 2027, a seventeen-month extension from the original 2 August 2026 date. AI embedded in regulated products under Annex I moves further still, to 2 August 2028. The changes still need formal adoption and publication in the Official Journal, expected before 2 August. Article 50 transparency duties and GPAI systemic-risk enforcement are unaffected and still land on 2 August 2026 as originally scheduled.
Key Insight:

Update your compliance calendar, don't clear it. If you had an Annex III workstream racing toward August, you've bought well over a year. Redirect that team's near-term focus to the GPAI vendor questions and transparency-labelling decisions that are still due in under two weeks — that clock didn't move.

US District Court, N.D. Cal. (Bartz v. Anthropic) · final approval 20 July 2026
Anthropic's $1.5bn Book-Piracy Settlement Gets Final Court Approval
Judge Araceli Martínez-Olguín approved the largest known US copyright settlement, resolving claims that Anthropic used pirated books to train Claude. Around 500,000 works are covered, with authors and publishers eligible for up to $3,000 per work; the court trimmed the attorneys' fee award from a requested $187.5m to $101.56m. The underlying ruling drew a sharp line: training on copyrighted books can be fair use, but storing pirated copies of them is not.
Key Insight:

This is the first nine-figure price tag on "where did your AI vendor's training data actually come from." Most AI vendor due diligence still treats this as a generic IP indemnity question. After this settlement, it deserves its own specific warranty and its own line in the risk register — for every AI tool sitting under your team's workflows, not just the obvious ones.

Eleventh Circuit Court of Appeals · decided 10 July 2026
Appeals Court Sanctions a Lawyer Over Citations It Only "Suspected" Were AI-Generated
Affirming summary judgment for the Florida Department of Corrections, the Eleventh Circuit sanctioned the employee's lawyer over non-existent case citations — without ever establishing that AI produced them. Asked to explain the citations, counsel said only that the material "did not come from a verified review of the cited opinions." The panel said it was "disappointed with counsel's lack of forthcoming candor" and held that, AI-generated or "simply made up," the standard of accuracy is the same either way.
Key Insight:

The bar for sanctions just dropped further. Courts no longer need to prove a citation came from AI — only that it wasn't verified. Your verification checkpoint needs to cover every citation that leaves the building, not just the ones somebody flags as "AI-assisted."

2

This Week's Workshop

Security of Your Systems

You may have seen the story this week: an OpenAI model, chasing a better benchmark score, broke out of its own sandboxed test environment, exploited a zero-day vulnerability and used stolen credentials to gain remote code execution on Hugging Face's servers — without ever being instructed to. It's a stark illustration of why "Technical and Organisational Measures" (TOMs) aren't a compliance checkbox; they're what actually stands between an AI system and your infrastructure. Today's prompt (below) takes you through your own TOMs across seven areas, so you can find out where you genuinely stand. For a longer, 20-minute look at AI security and how it applies specifically to agents, see this post: watch here →

Agent Builder Course — Five Days, One Hour a Day

Learn to build, deploy and continuously improve AI agents for your legal team's hardest recurring work — contract triage, due diligence, document assembly, compliance monitoring. No coding required. Works with any LLM, including Microsoft Copilot. Spaces are limited.

More details and booking here →

Book a Call

This Week's Prompt: The Technical & Organisational Measures (TOMs) Interview Prompt

Use this when you need a first-pass picture of the security of your own organisation's systems — or a vendor's, before you sign. It interviews you across the seven areas a regulator or a customer's due diligence questionnaire will usually ask about: Backup, Authentication, Testing, Firewall, Internal Controls, Supply Chain, and Training. Paste the whole thing into Claude, ChatGPT, or any LLM and answer one question at a time — it ends with a RAG-rated summary, priority actions, and a list of evidence to go and request to verify what you've been told. It's a long, structured prompt, so it's saved as a document rather than run inline here:

Open the Prompt in Google Docs →

A Couple of Things From Me

Speaking in London

I'm speaking at an AI event in London, and as a speaker I've been given a handful of complimentary tickets. If you'd like one, just hit reply and let me know — first come, first served.

See the event post on LinkedIn →

A Course Recommendation (Not Mine)

Second, a recommendation for something I didn't build. I've been working through a course on using AI in your personal life — specifically getting AI to actually know you: your personality type and how you think. It's genuinely useful, but worth knowing upfront that it works by having you share a fair amount of personal data with AI, which won't suit everyone.

If that trade-off is fine by you: take a look here →

This is an affiliate link — I get a small commission if you sign up, at no extra cost to you.

Want More Prompts & Workflows?

For prompts and more detailed workflows like this one, take a look at our book on AI for legal professionals. Explore step-by-step guides, ready-to-use prompts, and best practices for integrating AI safely into your legal work.

Explore the Book →

Until next Monday,

— Richard Nicholas

Got a story I should cover, or a question about something here? Just hit reply — I read every one. (Received this one secondhand? Reach me directly at [email protected].)

Get This Newsletter Every Week

Curated AI and legal governance news, a copy-paste prompt, and a practical workshop — delivered free to in-house counsel every Monday.

Get Next Monday's Issue →