Skip to main content
Comment & Opinion

Technology & Digital round-up: July 2026

From AI and cyber resilience to regulatory reform, the pace of change remains relentless. This round-up highlights the key tech and digital developments businesses should have on their radar.

- Luke Jackson, Director, Technology & Digital

If you’d like to receive the Technology & Digital round-up and other similar updates direct to your inbox, please click here.

Ready to protect your business against cyberattacks? Click here to access our cybersecurity and data protection tool.

Get in touch with Sally Mewies, Andrew Northage, Nick Stubbs, Paul Armstrong, Luke Jackson, Matthew Lingard or any member of our Technology & Digital team if you have any queries or need advice or assistance.

Here’s your top stories for July. Lots to talk about this month:

#1: Government abolishes DSIT

The Department for Science, Innovation and Technology, which played a central role in advancing the UK’s AI ambitions, has been abolished by the Burnham government. Most of its responsibilities will be absorbed into the newly named Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport.

Recognising that the transformative scale of AI advances requires a strategic, whole-of-government approach from the centre”, a new Office for the Prime Minister and the Cabinet will include an AI taskforce to drive the government’s overall AI strategy. Responsibility for AI strategy, public sector AI adoption and the AI Security Institute moves to the Cabinet Office, while dedicated AI minister Kanishka Narayan will attend Cabinet.

At a critical time for AI adoption and investment, the decision to abolish DSIT has raised concerns across the technology sector. Only time will tell whether the new structure can deliver the progress needed and ensure AI retains its strategic importance within government.

#2: Landmark legal statement on liability for AI harms

The UK Jurisdiction Taskforce published a landmark legal statement on liability for non-deliberate AI harms under English private law. With the rapid development of generative AI use and capability, the aim is to provide much needed legal certainty and predictability in an area where few cases have reached the courts. Many issues will be fact-specific, but here are the headline points:

  • Contract will generally be the main mechanism for allocating liability for harm within an AI supply chain and between AI users and those harmed by its use. While poor drafting or unclear requirements may create difficulties, AI raises no unique contractual issues.
  • Where no contract applies, liability will usually be assessed under well-established negligence principles, which are flexible enough to address AI-related harm. Generally, while careless AI users and developers of narrowly targeted applications are likely to be liable for foreseeable harm, foundation model developers are unlikely to be liable for harm from unforeseeable or insufficiently tested uses of their general-purpose models.
  • As AI is not a ‘person’ in the legal sense, others can’t be held vicariously liable for its actions or failures. But employers and those owing non-delegable duties may be liable for AI-related harm caused through human wrongdoing, in the usual way.
  • A professional may be found negligent for using AI inappropriately, using an unsuitable model, failing to conduct proper due diligence or failing to test AI or validate its outputs effectively. Equally, a professional could be liable for failing to use AI in circumstances where a competent member of their profession would have done so.
  • Currently, strict liability for death, personal injury, or damage to private property caused by a defective product, regardless of whether the manufacturer was at fault, would arise only where AI is integrated into physical products (such as an automated industrial machine or a robot). The key question, as usual, is whether the product’s safety is lower than what people are generally entitled to expect.
  • AI developers and deployers are unlikely to be liable for misuse by bad actors unless the AI was obviously dangerous or the misuse could and should have been prevented. By contrast, they are likely to be liable for foreseeable harm caused by the AI acting autonomously.
  • Liability for negligent misstatement will generally be established if a legal person holds out an AI chatbot as communicating on their behalf.
  • For defamation, those who exercise any manual review over the output before it’s published will be liable as editors. Those deploying an AI model or application to publish statements publicly in the course of business will most likely be liable for the output as a commercial publisher.

This statement provides welcome clarity on how English law is likely to approach AI-related harms. While AI continues to evolve at pace, businesses should note that existing legal duties and responsibilities still apply, making effective governance, oversight and risk allocation more important than ever.

#3: Are UK data rules keeping up?

Unless we hear otherwise now that Andy Burnham is Prime Minister, the government is looking into whether data regulation is fit for purpose in the age of AI and other data-intensive technologies. Successful delivery of the government’s AI adoption plans depends on how well data is accessed, shared, governed and reused. But while most firms handle and analyse data, few harness its full potential. The government wants practical insights from businesses and innovators on what’s working well, where uncertainty remains, and where they see friction and challenge now and in the future. This will inform the need for further guidance, targeted regulatory changes or more fundamental reform.

At the same time, the government is reviewing the UK’s approach to international data transfers. Again, it’s asking for practical insights on the effectiveness of the current regime and where reform may be needed.

The deadline for responses to both calls for evidence is 9 September 2026.

With potential reforms to both data regulation and international data transfers on the table, this is a valuable opportunity to share what’s working, what isn’t, and identify the changes needed to unlock the full potential of data-driven innovation.

Grace Parkin, Senior Associate, Regulatory & Compliance

#4: AI transforming financial services

Not for the first time, we’re seeing a flurry of activity around AI adoption in the UK financial sector.

The FCA published a landmark review into the impact of AI on retail financial services. The review identifies the following systemic shifts that will reshape financial services to 2030: AI will transform how firms operate; consumer journeys will become agent-led; AI will reshape market power and competition; and fraud and cyber threats and defences will accelerate. The review sets out priority recommendations for the FCA, including enabling the foundations for agentic finance.

While the overall regulatory framework remains sound, and the FCA can provide clarity on how to interpret and govern increasing use of AI within the existing regime, the review recognises that the framework will need to evolve.

In a related development, and with the caveat that it was published under the Starmer government, HM Treasury published an independent report setting out the AI adoption plan for the financial services sector. Key themes and issues are regulatory clarity; the regulatory perimeter; AI sovereignty and resilience; skills and talent; and agentic payment readiness.

And in a recent speech, the Bank of England’s Deputy Governor for Financial Stability discussed how AI is reshaping finance at speed, with agentic AI transforming cyber risk, markets and payments. A subsequent Bank of England financial stability report highlights the risks from frontier AI developments and the steps firms should take now.

AI is rapidly becoming embedded across financial services, with agentic finance set to reshape how consumers access and use financial products. The challenge for firms is to harness these opportunities while maintaining robust governance, oversight and consumer protection.

Paul Armstrong, Director, Commercial

More legal and regulatory developments…

  • The EU AI Act’s transparency obligations start to apply on 2 August 2026. The European Commission has now published guidelines for AI providers and deployers, alongside a code of practice that can be used to demonstrate compliance.
  • The government is consulting until 30 September 2026 on proposals to support the fair, transparent and responsible use of workplace monitoring technologies, including whether regulatory intervention is necessary.
  • The government announced reforms through the Regulating for Growth Bill to help businesses test and commercialise new products faster and published guidance on what participation in a regulatory sandbox would feel like from a business perspective.
  • The Cyber Security and Resilience Bill received its second reading in the House of Lords on 14 July. Concerns raised include cumulative regulatory burden, divergence from the EU regime, absence of a dedicated regulator and the Bill’s failure to specifically address AI. Line by line examination of the Bill begins in September.
  • Following the social media ban for under-16s announced in June, the government published its full response to the March to May 2026 national consultation and set out a series of further measures. See the updated fact sheet for details.
  • A new mandatory regime for crypto regulation comes into force in October 2027.

…and in other news

  • Some of OpenAI’s most advanced AI models went rogue in what it described as “an unprecedented cyber incident”, hacking a start-up during a security test. This reinforces the consistent message from government and the National Cyber Security Centre for organisations to step up their cyber defences.
  • The Cyber Resilience Pledge officially launched, with more than 60 businesses signing up and committing to strengthen their cyber defences.
  • The NCSC published new response and recovery guidance for organisations on how to handle a highly disruptive cyber incident.
  • The UK and its allies urged critical sectors to improve their cyber defences against Russian intelligence targeting.
  • Click here for other recent NCSC blog posts on a range of topics such as building more resilient critical national infrastructure and the latest on post-quantum cryptography.
  • The UK’s Technology Trade Association techUK published an industry brief on agentic AI. It sets out how organisations across the UK economy can move beyond pilots and proofs of concept to deploy agentic AI responsibly and at scale.
  • The government issued a call for evidence to shape smart data schemes across the agri-food, property, retail, trade and transport sectors. The closing date is 1 October 2026.
  • Our Private Equity team published its latest Private Equity Trends & Transactions Report (July 2026), providing an analysis of private equity deal activity and execution trends from transactions advised on by the firm’s private equity team during H1 2026, alongside predictions for the second half of the year. Key findings include that sponsors are placing increased emphasis on operational value creation, digital transformation, and margin expansion as key drivers of future returns.

How we can support you

If you have queries about any of the points covered in this edition of the Technology & Digital round-up, or need further advice or assistance, please get in touch with Sally, Andrew, Nick, Paul, Luke, Matthew or one of our Technology & Digital experts.

Sally
Mewies

Head of Technology & Digital

CONTACT DETAILS
Sally's contact details

Email me

CLOSE DETAILS

Andrew
Northage

Partner

Regulatory & Compliance

CONTACT DETAILS
Andrew's contact details

Email me

CLOSE DETAILS

Nick
Stubbs

Partner

CONTACT DETAILS
Nick 's contact details

Email me

CLOSE DETAILS

Paul
Armstrong

Director

Commercial

CONTACT DETAILS
Paul 's contact details

Email me

CLOSE DETAILS

Luke
Jackson

Director

Commercial

CONTACT DETAILS
Luke's contact details

Email me

CLOSE DETAILS

Matthew
Lingard

Director

Intellectual Property, Trade Marks & Designs

CONTACT DETAILS
Matthew's contact details

Email me

CLOSE DETAILS