The Brief
Issue 9 · 23 July 2026
Ten days to the deadline. Nineteen days without the model.
Ten days to the AI Act deadline. Nineteen days without the model that was supposed to be unstoppable.
Ten days from now, the EU AI Act's Article 50 transparency rules take effect. Anyone deploying a general-purpose AI system has to tell users when they're talking to one, no exceptions for firms that assumed they had more time. That deadline hasn't moved.
Something else has. On 29 June, the Council gave final approval to the AI Act's Digital Omnibus, a package of amendments Parliament had already passed on 16 June. The effect: obligations for high-risk AI systems get real breathing room. Standalone systems now have until 2 December 2027. AI embedded in already-regulated products, medical devices and the like, has until 2 August 2028.
So two clocks are running at very different speeds. The transparency duty lands in ten days, full stop, and applies regardless of firm size or risk category. The heavier compliance lift for high-risk systems just gained well over a year of runway. Most professional-services firms sit outside the high-risk category entirely, which is exactly why 2 August, not 2027, is the date that should be on your calendar: client-facing disclosures, chat interfaces, generated reports, anything that reaches a client without a human editing pass, needs an AI-use notice by then.
The night a frontier model went dark
On 12 June, three days after launch, the US Commerce Department ordered Anthropic to suspend Claude Fable 5 and its internal sibling Mythos 5 worldwide. Fable 5 was the first publicly available model in Anthropic's Mythos-class tier, a step up from its own Opus line, and the order cited export-control powers after reports the model could be jailbroken into an unrestricted cyber tool. Anthropic couldn't filter access by nationality fast enough to comply any other way, so it cut off everyone, American customers included. The models stayed dark for nineteen days before Washington reversed the order on 30 June.
Nobody in Europe voted on that decision, negotiated it, or got advance warning. A tool thousands of firms had started to depend on simply stopped answering, on a timeline set entirely outside the EU. That's the whole argument for sovereignty in one incident: it was never really about where servers sit, it's about who can turn your AI off.
Separately, and in the same window, the European Data Protection Board adopted guidelines on anonymisation and web scraping for generative AI on 8 July, open for public consultation until the end of October. The scraping guidance is blunt: GDPR governs it whenever personal data is involved, and something being publicly visible online is not consent.
The European Commission's proposed Cloud and AI Development Act would go further still, requiring public bodies to run a sovereignty risk assessment before signing a cloud or AI contract, scored against a four-tier framework. It's still a proposal working through Parliament and Council, not yet law, but the direction is unmistakable: sovereignty is turning into a procurement requirement, not a marketing line.
Also worth knowing
UK. The Solicitors Regulation Authority updated its compliance guidance on 9 February. No new rules, just a restatement: firms must make it clear to clients when they're dealing with AI.
France. The Conseil National des Barreaux's deontological guide for avocats, covering professional secrecy and GDPR, has applied since 17 March.
UK tax and accounting. Seven professional bodies, including ICAEW and CIOT, said in January that putting client data into a public AI model without consent is likely a confidentiality breach unless the data is properly anonymised.
What happens when nobody checked
In March 2026, the Sixth Circuit sanctioned two attorneys $15,000 each in Whiting v. City of Athens, on top of the other side's fees and double costs, the stiffest penalty the court's rules allow, for a brief with more than two dozen fabricated citations. The court didn't even need to prove AI was involved. Its point was simpler: no filing should cite anything a lawyer hasn't personally read.
In April 2026, the Nebraska Supreme Court went further: an indefinite suspension, the first in the US to take a lawyer's licence over an AI filing rather than just their money. 57 of 63 citations in the brief were defective, 20 entirely invented. Confronted, the attorney denied using AI, then admitted it once the inconsistencies couldn't be explained any other way.
Neither case is a fluke. A public database maintained by a researcher at HEC Paris had logged more than 1,590 of these incidents worldwide by early June, up from roughly 200 a year earlier, adding new ones almost daily. The fines are climbing and courts are visibly done extending the benefit of the doubt.
Reason, The Volokh Conspiracy·WOWT·AI Hallucination Cases Database
Our read
Two different failure modes, one root cause: trusting a black box you don't control. The hallucination cases above are what happens when nobody checks the AI's work. The Fable 5 shutdown is what happens when the AI's work depends on a vendor, and a government, you have no say over. It's why Inferis's model layer is a config choice, not a dependency: EU queries run on Mistral, an EU-based provider, chosen for sovereignty rather than loyalty, and nothing in the platform is wired to a single vendor. It's also why every answer in the product carries a citation back to the source paragraph it actually came from. Neither habit is optional once client confidentiality and a malpractice claim are both on the table.
Get the next issue in your inbox