Skip to content
Back to Press

The Brief

Issue 10 · 2 August 2026

Article 50 is live. Here's what actually changed today.

The EU AI Act's transparency duties took effect today, a US court handed down the largest AI-hallucination sanction on record, and the UK regulator drew a straight line from human supervision failures to AI ones.

Europe

The EU AI Act's Article 50 transparency obligations became enforceable today, 2 August 2026. Any provider or deployer of a general-purpose AI system must now disclose when content is AI-generated or AI-assisted, including chatbot interactions, synthetic audio, image and video, and deepfakes.

National market surveillance authorities can fine non-compliant firms up to 15 million euros or 3 percent of global annual turnover, whichever is higher. The machine-readable marking requirement for synthetic content, the more technical half of Article 50, was deferred to 2 December 2026 under the AI Omnibus amendments the Council approved in June.

For firms handling regulated client work, the practical requirement is narrower than the headline: disclosure has to be clear and timely, not buried in a footer. A chatbot needs to say it's a chatbot at the point of first interaction, not three screens later.

Enforcement is decentralised, and each member state runs it differently. Luxembourg's implementing bill designates the CNPD, the data protection authority, as the default market surveillance authority, with ILNAS acting as notifying authority for products entering the market, the CSSF supervising AI in financial services, the CAA doing the same for insurance, and the ILR monitoring high-risk systems at essential and important service operators. Maximum sanctions reach 35 million euros or 7 percent of global turnover, and the CNPD is required to launch its first regulatory sandbox by today, 2 August. A Luxembourg-based expert-comptable and a Paris-based avocat answering to the same Article 50 today are, in practice, answering to two different regulatory structures.

There's a partial safe harbour. The Commission published its final Code of Practice on marking and labelling AI-generated content on 10 June, drafted by six independent experts with input from more than 180 stakeholders. Signing up and adhering to it creates a presumption of compliance, though it isn't the only route: firms can still demonstrate compliance without it, just with less certainty about where the bar actually sits.

Cloud Security Alliance research note·European Commission transparency guidelines·Paperjam, on Luxembourg's AI Act authorities·European Commission, Code of Practice policy page

North America

The largest AI-hallucination penalty yet

A federal court in Oregon sanctioned a party's counsel $110,204.38 in Couvrette v. Wisnovsky, the largest confirmed monetary penalty for AI-fabricated citations to date. Filings across three separate briefs contained 15 non-existent case citations and 8 fabricated quotations attributed to real, unrelated cases.

The court dismissed the underlying claims with prejudice and referred the attorney to the Oregon State Bar for disciplinary review. The ruling adds to a fast-growing public database of sanctioned AI-hallucination cases, most logged within the last eighteen months.

Mondaq·WSBA NWSidebar

United Kingdom

What the Mazur ruling means for AI oversight

The Solicitors Regulation Authority issued new supervision guidance in June, developed jointly with the Law Society, CILEX, the Legal Aid Agency and the Law Centres Network, in direct response to the Court of Appeal's ruling in Mazur. That ruling confirmed unauthorised staff, paralegals, trainees, and by extension AI tools, can carry out litigation work provided a supervising solicitor exercises genuine oversight.

The guidance translates that principle into practice: firms delegating work to AI systems face the same accountability standard as firms delegating to a junior. Genuine oversight means checked output, not a rubber stamp.

Legal Futures·Law Gazette

Asia-Pacific

Canberra picks a direction, doesn't pick a law yet

Australia won't get a dedicated AI Act, but it just got a clearer signal of where the government is heading. On 15 July, Prime Minister Anthony Albanese announced a new Office of AI inside the Department of the Prime Minister and Cabinet and a forthcoming set of Australian Standards for AI. National Cabinet takes up the approach this month, with legislation expected to reach Parliament in early 2027.

The detail so far leans toward data-centre infrastructure and creative-content licensing rather than professional-services obligations directly, Albanese framed it around protecting Australian writers, artists and journalists from having their work used to train AI without consent. What that means for a law or accounting firm isn't settled yet. What already applies is narrower but real: APRA's CPS 230 amendments took effect 1 July, treating AI vendors used by APRA-regulated institutions as material service providers requiring a formal register and a documented fallback plan, and the Privacy Act's new automated-decision-making transparency rules land 10 December.

Singapore, meanwhile, is moving on testing rather than legislation: its AI Tester Accreditation Programme, reportedly the first of its kind in Asia, is due to launch in the third quarter.

Prime Minister of Australia·APRA, CPS 230·Mayer Brown, Singapore/Hong Kong checkpoint

Our read

Three different regulators reached the same conclusion this week from three different directions: enforcement is no longer theoretical. Article 50 carries real fines, Couvrette v. Wisnovsky carries a six-figure sanction, and the SRA's post-Mazur guidance makes clear that delegating work to AI doesn't lower the bar for supervision, it raises the question of who's checking it. That's the same question an audit trail is built to answer.

Get the next issue in your inbox

The brief

AI and regulation, every fortnight.

What's changing in AI regulation and enforcement. What it means for client work. The deadlines worth watching. Written for practitioners.