Skill Diligence

AI for In House Counsel

Practical AI for In House Counsel

Issue 32 · 3 August 2026

The AI Act's Transparency Duty Just Went Live — Here's What Actually Changed

Plus: Nvidia and 30+ tech firms launch a security alliance after the OpenAI-Hugging Face breach — pointedly without OpenAI, Google or Anthropic — and Elon Musk's xAI sues Minnesota over the first state law banning AI "nudification" apps.

Here's what mattered most to me this week — after three issues tracking the countdown, 2 August arrived. The EU AI Act's Article 50 transparency duties and the Commission's enforcement powers over general-purpose AI models with systemic risk are now live: national market surveillance authorities can investigate and sanction breaches, and the AI Office can fine GPAI providers up to €15m or 3% of global turnover. The high-risk regime is still deferred to December 2027 — that's the only part of the timeline that moved. If your organisation hasn't yet worked out which of its systems need to disclose they're AI, this is the week to do it, not the week to relax because you heard "AI Act delay" somewhere. Also in this issue: the security-alliance fallout from last week's OpenAI/Hugging Face story, and a brand-new state AI law already in court before its ink is dry.

1

This Week's Reading

Top Story
European Commission / EU AI Act, Articles 50 & 55-101 · in force 2 August 2026
The AI Act's Transparency and GPAI Enforcement Duties Are Now Live
From 2 August, AI systems that interact directly with people must disclose they're AI, providers must mark AI-generated content in machine-readable form, and the Commission's AI Office can investigate, fine and force the withdrawal of general-purpose AI models with systemic risk. Fines for GPAI providers can reach €15m or 3% of global turnover, whichever is higher. The high-risk regime (Annex III/Annex I) remains deferred to December 2027 and August 2028 respectively under the Digital Omnibus — that part of the timeline hasn't changed.
Key Insight:

This is no longer a compliance calendar entry — it's live law. If you haven't already inventoried which of your organisation's chatbots, content tools and copilots need a disclosure, that's now overdue rather than upcoming. For every GPAI vendor sitting under those tools, ask directly whether they've been classified as systemic risk and how they'd respond to an Article 55 information request.

Nvidia / multiple outlets · launched 27 July 2026
Nvidia and 30+ Firms Launch a Security Alliance — Without OpenAI, Google or Anthropic
Days after an OpenAI model breached Hugging Face's servers (covered in our last issue), Nvidia launched the Open Secure AI Alliance with roughly three dozen partners — including Microsoft, IBM, Cisco, CrowdStrike, Hugging Face and the Linux Foundation — built around AI models that defenders can inspect, modify and run on their own infrastructure. The trigger, reportedly: during the Hugging Face incident, closed frontier models' own safety guardrails blocked the forensic analysis needed to investigate the breach, unable to distinguish malicious activity from defensive security work. OpenAI, Google and Anthropic — the three providers whose guardrails caused that problem — are notably absent from the founding members.
Key Insight:

If your incident response plan assumes you can point any AI tool at a live security investigation, this incident says otherwise. Closed-model guardrails can block the very forensic work you need most during a breach. Ask your security team whether your incident response tooling has been tested against exactly this failure mode, not just against the attack itself.

US District Court, D. Minn. (xAI v. Ellison) · filed 27-28 July 2026
Elon Musk's xAI Sues Minnesota Over the First State Ban on AI "Nudification" Apps
xAI filed suit against Minnesota's Attorney General to block a law, effective 1 August, that fines developers $500,000 per non-consensual explicit deepfake generated by their tools — a platform whose users created 100,000 such images would face $50bn in theoretical aggregate exposure. xAI argues the law is an overbroad, content-based restriction on speech; the state's Attorney General and Governor have both signalled they intend to defend it vigorously.
Key Insight:

Whatever happens in court, the exposure math is the real lesson. Per-violation state penalties can compound into existential numbers far faster than a typical liability cap anticipates. If your organisation offers or embeds any content-generation feature, check now whether your terms of use, technical safeguards and indemnities would actually hold up against a per-image, per-state penalty regime like this one — not just a generic IP or defamation claim.

2

This Week's Workshop

Does the AI Act Actually Apply to You?

Now that Article 50's transparency duties and the Commission's GPAI enforcement powers are live, the real question for most in-house teams isn't "is the AI Act delayed?" — it's "which of these four duties actually bite on what we're doing, and does anything need to change?" This week's workshop walks through the interactive prompt below live: interrogating a real (anonymised) set of AI tools against each Article 50 trigger and the Article 53/55 GPAI thresholds, to show what an honest applicability answer looks like — including the cases where the honest answer is "this sits with your vendor, not you."

Agent Builder Course — Five Days, One Hour a Day

Learn to build, deploy and continuously improve AI agents for your legal team's hardest recurring work — contract triage, due diligence, document assembly, compliance monitoring. No coding required. Works with any LLM, including Microsoft Copilot. Spaces are limited.

More details and booking here →

Book a Call

Copy-Paste Ready: The Article 50 & GPAI Applicability Interview

Use this to work out, in plain terms, whether the AI Act's Article 50 transparency duties and the Article 53/55 general-purpose AI (GPAI) obligations actually apply to what your organisation is doing — and if so, what needs to change. It interviews you across your interactive AI systems, synthetic content, emotion recognition/biometric tools, deepfakes and public-interest text, and your GPAI model status, with the legal basis for each question built in. Paste the whole thing into Claude, ChatGPT, or any LLM and answer one question at a time. It's a long, structured prompt, so it's saved as a document rather than run inline here:

Open the Prompt in Google Docs →

The prompt ends with a reminder that this is an indicative, first-pass check based on your own answers — not legal advice. Speak to a lawyer about how the AI Act applies to your organisation's specific circumstances.

Want More Prompts & Workflows?

For prompts and more detailed workflows like this one, take a look at our book on AI for legal professionals. Explore step-by-step guides, ready-to-use prompts, and best practices for integrating AI safely into your legal work.

Explore the Book →

Until next Monday,

— Richard Nicholas

Got a story I should cover, or a question about something here? Just hit reply — I read every one. (Received this one secondhand? Reach me directly at [email protected].)

Get This Newsletter Every Week

Curated AI and legal governance news, a copy-paste prompt, and a practical workshop — delivered free to in-house counsel every Monday.

Get Next Monday's Issue →