FAST Legal Update Member Bulletin – October 2026

Legislation Update

EU AI Act Transparency Obligations Come Into Force

From 2 August 2026, the transparency provisions of the EU AI Act (Article 50) apply to businesses that develop or deploy AI systems, wherever they are established, provided their outputs are intended for use in the EU. Article 50 imposes four distinct obligations on providers and deployers:

  • Providers of AI systems that interact directly with people must disclose, at the point of first interaction, that the user is communicating with a machine. The exception for ‘obvious’ AI is interpreted narrowly by the European Commission’s Guidelines, and will not cover AI chatbots in customer services or realistic avatars in immersive environments.
  • Providers of systems generating synthetic audio, images, video or text must mark outputs in a machine-readable format to ensure they are technologically detectable as artificially generated or manipulated. Standard editing operations are exempt, but AI-generated summaries, face alterations and object modifications are not.
  • Deployers must notify individuals when emotion recognition or biometric categorisation systems are in operation, whether in real-time or retrospectively applied.
  • Deployers must clearly label deepfakes and AI-generated text that is in the public interest or intended to inform the public as artificially generated, subject to a limited exception for content that has undergone human editorial oversight.

A voluntary Code of Practice provides the principal compliance framework for obligations relating to the marking and detection of AI-generated and manipulated content and the labelling of deepfakes and AI-generated or manipulated text. For providers, the Code requires machine-readable marking of synthetic content, accessible detection mechanisms and robust quality standards. For deployers, it requires clear disclosure labels, including a standardised EU “AI” icon at the point of first exposure, with some flexibility for artistic or satirical works.

The financial stakes are considerable, as non-compliance with Article 50 can attract fines of up to €15 million or 3% of global annual turnover.

Running in parallel, California’s AI Transparency Act (CAITA), originally enacted in 2024 and operative from 2 August 2026, establishes one of the most comprehensive disclosure frameworks for generative AI content in the United States. CAITA applies to generative AI services with more than one million monthly users that are publicly accessible in California. Providers must embed a disclosure into all AI-generated content, offer users the option to include a visible manifest disclosure clearly marking content as AI-generated, and provide a free, publicly accessible detection tool allowing anyone to check whether content was produced by their system.

Businesses should review existing AI deployments promptly and assess obligations under the EU AI Act.

Regulating for Growth Bill: AI Sandboxing Powers

Announced in the King’s Speech on Wednesday 13 May 2026, the Regulating for Growth Bill is the UK Government’s attempt to change a regulatory framework it considers too slow, too risk-averse, and ill-equipped to support modern technological innovation. The Bill builds on the 2025 Regulation Action Plan and aims to reshape the UK’s existing rules so that they actively support growth, rather than act as a barrier to it.

The Bill identifies AI as a central focus. It acknowledges that AI alone contributed an estimated £11.8 billion to UK GDP in 2025, with over £1 billion in venture funding raised in Q1 alone, yet nearly one third of UK AI startup leaders are reportedly considering relocating overseas due to regulatory complexity.

The Bill’s primary mechanism for supporting AI will be the introduction of cross-economy sandboxing powers, i.e. legal powers allowing existing rules to be temporarily relaxed under strict controls to test new technologies in real-world settings. Specifically, the Bill proposes exploring cross-cutting AI sandboxes enabling responsible testing and adoption of AI-enabled products and services across multiple sectors where existing regulatory frameworks currently slow down innovation.

AI in healthcare is highlighted as a particularly pressing use case. With nearly 750,000 patient imaging cases unreported within four weeks annually, and evidence that AI outperforms 78-90% of radiologists on certain diagnostic tasks, the Bill would enable controlled testing of AI-powered medical devices to accelerate patient access.

The Government emphasises that this is not deregulation; safeguards, accountability, and regulatory oversight remain central to all proposed sandbox trials. For companies operating in regulated sectors, the sandboxing mechanism may open up opportunities to pilot AI-driven solutions in environments where existing rules might otherwise create barriers.

It is worth noting that since this Bill was announced, the AI risk landscape has evolved considerably. High-profile incidents, including the withdrawal of a major frontier AI model over safety and alignment failures and unusually candid risk disclosures from leading AI developers, have heightened public and political awareness of the risks of advanced AI systems. Whilst the Bill remains in progress, organisations should be aware that the political appetite for relaxing regulatory constraints on AI may be subject to increasing scrutiny. We will continue to monitor progress of the Bill as it passes through Parliament.

Policy Update

UK Workplace Monitoring Technology Consultation

The UK government launched a consultation on the regulation of workplace monitoring technologies (WMT). These are digital tools used by employers to collect, track, analyse, and make decisions about workers and their activities. The consultation seeked views on potential policy approaches to govern how WMT should be introduced and managed in the workplace.

WMT encompasses a broad range of tools, from location tracking and biometric access controls to keystroke monitoring and AI-driven performance evaluation. AI is particularly significant in this context, as its integration into WMT enables employers to automate complex decisions about workers at a scale and speed that increases the scope for unfair, opaque, or discriminatory outcomes. The government acknowledges that use of such technologies is expected to grow significantly, while also recognising concerns around privacy, fairness, and worker autonomy where monitoring is poorly designed or governed.

The consultation proposes eight principles for responsible WMT use covering purpose, transparency, worker engagement, fairness, proportionality, human oversight, dignity, and accuracy.

Practically, employers must ensure a lawful basis for any processing of personal data by WMT, conduct Data Protection Impact Assessments where required, and apply particular scrutiny to the use of biometric data and automated decision-making.

Employers considering or already using WMT should review the ICO’s current guidance and applicable legislation. The consultation closed on 30 September 2026, so organisations should now watch for the government’s response and next steps, which are expected to shape the future regulatory framework for workplace monitoring.

UK AI Liability: UKJT Legal Statement

The UK Jurisdiction Taskforce (UKJT), a Ministry of Justice supported initiative, has published a substantial legal statement on liability for harm caused by AI systems under English law. Its central conclusion is that English common law is sufficiently flexible to address AI-related harm without immediate legislative intervention, and that courts are expected to adapt existing principles as cases arise.

Liability across the AI supply chain will primarily be allocated through contract, with negligence being the fallback where contractual provisions are absent or silent. Critically, duties and standards of care will be highly fact-specific, with potential exposure across foundation model developers, application developers, deployers, and professionals using AI tools. Application developers may find themselves caught in the middle, unable to fully disclaim liability to those they supply, but equally unable to push it back up the chain to model developers.

Several findings stand out. First, professionals face risk from both directions as liability may arise from negligent use of AI and from a failure to use it where a competent professional would have done so. Second, businesses deploying customer-facing chatbots are likely to be treated as responsible for the statements those systems make on their behalf. Third, issuing software updates to address identified risks may support a finding that a developer has therefore assumed a duty of care.

Evidential challenges will be central to AI disputes. Record-keeping, human oversight, due diligence, and transparency are likely to prove decisive on questions of liability, rather than being matters of good practice alone. Organisations across the AI supply chain should treat AI governance as a legal issue, not just an operational one.

For any business developing, deploying or using AI tools, the UKJT statement sets out a practical framework for thinking about risk exposure and supply chain contractual arrangements.

Cybersecurity Update  

NCSC Warning on Systems Connected to Internet and Edge Devices

In August 2026, the National Cyber Security Centre (NCSC) issued a warning about a rise in attacks targeting operational technology (OT) systems that are directly connected to the internet, across a range of sectors in the UK and internationally. OT systems are the kind of hardware and software used to monitor and control physical processes such as building controls and manufacturing equipment.

The NCSC’s recommended steps for organisations include checking what assets are exposed to the internet, making sure default passwords have been changed, tightening access controls, keeping a close eye on network traffic into and out of OT systems, and regularly testing that backups and recovery plans actually work. The guidance makes the point that organisations which have already invested in strong cyber resilience are in a far better position to detect and contain an attack before it causes serious disruption.

This follows a broader pattern tracked over recent months. In the UK, four in ten businesses have reported experiencing a cyber-attack in the last twelve months. Devices connected to the Internet, which are sometimes overlooked in security planning, remain one of the most common routes in for attackers.

For organisations operating any form of connected or networked infrastructure, this is a useful prompt to review asset inventories, check that patch management is in place and consider whether current access controls are sufficient given the current threat environment.

Five Eyes Guidance on AI-Driven Cyber Risk

The cybersecurity agencies of the UK, US, Canada, Australia and New Zealand, known collectively as the Five Eyes alliance, published a joint statement warning that AI is rapidly changing the cyber threat landscape. The agencies noted that frontier AI models are expected to accelerate the speed, scale and sophistication of cyber-attacks, while also offering new opportunities to improve cyber defences. They called on organisational leaders to assess their cyber risk and readiness, strengthen identity and access controls, keep systems up to date with security patches, address legacy systems, and consider how AI can be used to improve resilience and business continuity.

This sits alongside a separate joint statement published earlier in the quarter by the Bank of England, FCA and HM Treasury. Frontier AI models already exceed what skilled human practitioners can achieve in executing cyber-attacks, at greater speed, scale, and lower cost. Regulators warn that firms underinvesting in core cyber fundamentals face progressively greater exposure as more advanced models emerge.

The FCA has also separately published findings from a recent review into how regulated businesses are using frontier AI for cyber purposes, warning that the pace at which these models can surface vulnerabilities is outstripping many businesses’ remediation capacity, highlighting the urgency of the steps described above.

The message from regulators and intelligence agencies is consistent: the AI-driven cyber threat is moving quickly, and organisations that have not already taken a close look at their cyber position should do so as a matter of urgency.

Case Law Update

Tesla v InterDigital and Avanci – FRAND Licensing in the Supreme Court

On 27 July 2026, the Supreme Court ruled unanimously in Tesla’s favour, confirming that the English courts have jurisdiction to determine whether the terms on which Avanci licensed access to 5G patents were fair, reasonable and non-discriminatory (FRAND). The case is significant because it provides useful guidance on how FRAND obligations apply in the context of multi-party patent licensing platforms like Avanci, rather than a direct bilateral licence between a patent holder and a licensee. Key takeaways from the case include:

  • there is at least a properly arguable case that standard essential patent (SEP) owners remain bound by FRAND obligations even where they choose to make licences available through a platform agent;
  • the commercial reality is important in deciding what FRAND obligations require – the court treated the growing use of licensing platforms and the practical impossibility of negotiating thousands of bilateral licences as highly relevant to construing/operating the FRAND obligations;
  • In some circumstances, it can be arguable that the only FRAND licence is the platform licence, not a bilateral UK-only licence, particularly if bilateral licensing with all relevant SEP owners isn’t practically viable;
  • FRAND can be scrutinised even if the platform operator itself gave no FRAND undertaking, as the operator acts as a licensing agent for FRAND-bound SEP owners;
  • Declarations can be useful to make FRAND enforceable in a platform world; and
  • FRAND doesn’t mean that every commercial offer must be FRAND in every context – the court indicated in the commentary of the judgment that FRAND terms must always be available, but separate negotiations leading to non-FRAND commercial outcomes may be permissible in some circumstances.

FRAND disputes have grown in importance as 5G technology appears in a wider range of products and sectors. The judgment reinforces the English courts’ position as a leader in resolving complex IP licensing disputes. For businesses in the technology sector where these patents are a commercial reality, the decision is a useful reminder of the options available when licensing disputes arise.

JJH Enterprises Limited v Microsoft Corporation – Copyright Exhaustion and Software Licences

The Court of Appeal dismissed Microsoft’s appeal in this case on 14 July 2026. The dispute centred on whether used or surplus software licences can lawfully be resold, and specifically whether a rights holder’s copyright in software is exhausted once it has been sold, meaning they can no longer prevent the buyer from reselling it. The decision also considered the extent to which the Competition Appeal Tribunal has jurisdiction to decide copyright questions that arise as part of a competition law claim.

This builds on the earlier decision in Edozo v Valos, which confirmed that copyright in a computer program protects the expression of the code, not the underlying functionality. The two cases help to draw the line on what copyright does and does not protect in the software context, and to clarify the circumstances in which the resale of software licences may be permissible. The principles accepted by the court may apply where:

  • the licence is effectively a sale of a copy for an unlimited (perpetual) period for a fee;
  • the copy was first put on the market lawfully with the rights holder’s consent; and
  • the original customer stops using the software after resale.

The court also held that:

  • the Competition Appeal Tribunal can determine copyright issues where doing so is necessary to resolve a competition law claim;
  • contractual “no transfer” terms and transfer formalities won’t necessarily stop exhaustion applying;
  • depending on the structure of the licence, subdivision of volume entitlements may be allowed where what’s being resold are genuinely independent “seats/copies”, not a single indivisible right; and
  • exhaustion can extend to “non-program” elements that are supplied/inevitably downloaded as part of the product’s intended use.

For businesses whose commercial model depends on software licensing, whether as suppliers or customers, the judgment is worth reviewing. It is necessary to check whether the terms on which licences are granted or acquired adequately address the risk of onward resale.

CJEU Rules VPN Providers Not Liable for Copyright Infringement

This case arose out of the publication online of Anne Frank’s manuscripts in a territory where the content was not licensed. The question before the Court of Justice of the EU was whether publishers and VPN providers could be held liable for copyright infringement where users had relied on VPN software to access content that was restricted in their location.

The court ruled that they could not. It held that the availability of VPN software does not make a rights holder’s technical access controls inadequate or ineffective. The judgment is expected to have practical consequences for how rights holders across the EU approach digital copyright enforcement, and it reinforces the legal status of VPNs as legitimate tools. For organisations that distribute content under geographically limited licences, the decision is worth factoring into how enforcement strategies are structured.

UKIPO Updates Patent Practice Following the Emotional Perception Judgment

Following the Supreme Court judgment in Emotional Perception AI Limited v Comptroller General of Patents, Designs and Trade Marks, an immediate change was made to the way in which section 1 of the Patents Act 1977 should be interpreted and applied. This has changed the way in which UK patent applications, notably those for computer-implemented inventions, should be searched and examined under sections 17 and 18 of the Act. The Government has published an updated practice notice that gives a summary of the Emotional Perception judgment, setting out how examiners should interpret and apply section 1 of the Act, and gives some general guidance on how examiners should apply the judgment as a matter of practice. UKIPO examiners are now advised to follow a three-step approach:

  1. Step 1 – the first hurdle: Decide whether the subject matter of the claim qualifies as an “invention”, by applying the “any hardware” approach. This means that any claim which involves technical means is an “invention”.
  2. Step 2 – the intermediate step: Identify the features of the claim which contribute to the technical character of the invention, viewed as a whole. This involves a feature-by-feature analysis of the whole claim.
  3. Step 3 – the second hurdle: Assess whether the invention is new, then whether it involves an inventive step in relation to the prior art by considering only those features identified in step 2 which do contribute to technical character.

As we covered in our May 2026 edition, the Supreme Court’s ruling in Emotional Perception was a landmark moment for AI and patent law in the UK. The court held that an artificial neural network is not properly characterised as a mere computer program, because it can be implemented as both hardware and software simultaneously. The practical result is that AI systems based on neural networks can, in principle, qualify for patent protection under UK law.

The UKIPO’s updated practice notice now translates that ruling into guidance for examiners, meaning businesses and developers can engage with the patent application process with much greater certainty about what can and cannot be patented. AI-driven innovations that were previously considered unlikely to qualify for patent protection may now therefore be revisited with a view to filing or refiling applications.