Skip to main content
Comment & Opinion

Technology & Digital round-up: August 2026

“As businesses move from exploring new technologies to deploying them at scale, regulators are increasingly focused on governance, transparency and resilience. Organisations that build these principles into their technology strategies now will be better placed to innovate with confidence as the regulatory landscape continues to evolve.”

Luke Jackson, Director, Technology & Digital

If you’d like to receive the Technology & Digital round-up and other similar updates direct to your inbox, please click here.

Ready to protect your business against cyberattacks? Click here to access our cybersecurity and data protection tool.

Get in touch with Sally Mewies, Andrew Northage, Nick Stubbs, Paul Armstrong, Luke Jackson, Matthew Lingard or any member of our Technology & Digital team if you have any queries or need advice or assistance.

Here’s your top stories for August. Two to focus on this month:

#1: Managing the cyber risk of agentic AI

The National Cyber Security Centre published a blog post on managing the cyber risk of agentic AI, encouraging organisations to prepare for increasingly autonomous AI systems that may behave unexpectedly or fail to function as intended. This practical advice will ultimately be replaced by formal guidance being developed by the NCSC and its partners.

The post follows a series of well-publicised incidents in which AI models and agentic AI systems carried out unsanctioned or unintended activity. The UK’s AI Security Institute recently published an incident report on unsanctioned agent behaviour during cyber testing, while OpenAI temporarily slowed training of some of its most advanced AI models to improve security.

The UK’s AI Minister told Reuters that the government would consider regulating advanced AI models if voluntary pre-deployment testing no longer proved sufficient to protect the public.

“Agentic AI could bring real benefits for organisations, but it also introduces new risks as systems become more autonomous and harder to control. The NCSC’s advice is a helpful reminder that businesses should think carefully about the level of autonomy they allow, put appropriate controls around access to systems and data, and ensure they can monitor, manage and intervene where needed.”

Sally Mewies, Head of Technology & Digital

#2: EU AI Act enters major new phase as enforcement and transparency requirements kick in

On 2 August 2026, the European Commission began enforcing key provisions of the EU AI Act, including transparency obligations for providers and deployers of certain AI systems. Ahead of implementation, almost 200 companies, including the key Big Tech players, signed up to the Commission’s code of practice on transparency of AI-generated content, which can be used to demonstrate compliance.

Application of the rules on high-risk AI systems has been postponed to 2 December 2027, and to 2 August 2028 for high-risk systems integrated into regulated products.

“While many businesses have spent the last few years exploring AI, adoption remains relatively modest, with legal uncertainty, governance concerns and skills gaps still acting as barriers. Although not every business will be caught by the EU AI Act, those using, developing or procuring AI should consider whether the new rules affect them and review their governance frameworks accordingly. We can help you assess your position and prepare for a more regulated AI landscape.”

Matthew Lingard, Director, Intellectual Property, Trade Marks and Designs

More legal and regulatory developments…

  • The rapid adoption of generative AI tools is reshaping workplace communication. Our recent article looks at the impact of AI on employee disputes, and strategies for management.
  • The Information Commissioner’s Office recently consulted on its corporate strategy as it transitions later this year from a single Information Commissioner model to a Commission structure with a non-exec chair, board and separate CEO. Recognising that it can’t be everywhere at once, it’s chosen to focus as much effort as possible on the four regulatory priorities of children’s data, AI, public sector data use, and cyber resilience.
  • The Digital Regulation Cooperation Forum highlighted the key takeaways from a recent event on regulators’ work to maximise consumer interests while supporting the government’s ambitions to harness AI as a driver of growth.
  • The Communications and Digital Committee launched an inquiry into the implementation, enforcement and impact of the Online Safety Act amid serious concerns that the regime is currently ineffective.
  • The Competition and Markets Authority is investigating three firms including Trainline and Virgin Atlantic over drip pricing concerns.
  • The Financial Conduct Authority is boosting support for innovative firms as they scale and grow, with five fast-growing firms joining the regulator’s Scale-up Unit. A recent pilot with high-growth firms identified good practice and areas for improvement.
  • The ICO published a report exploring public views on neurotechnology and neurodata, with the findings set to inform ICO guidance for innovators on how data protection law applies to these areas.
  • The European Commission published practical guidance on complying with the Cyber Resilience Act. UK organisations making, distributing or importing connectable products for the EU market should check scope and compliance steps. Reporting requirements apply from 11 September 2026; all others from 11 December 2027.

…and in other news

  • The chair of the Science, Innovation and Technology Committee wrote to three Secretaries of State asking about the government’s plans for science, innovation and tech policy following DSIT’s abolition and the redistribution of its responsibilities.
  • A recent Make UK report found that 30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain, while only around half have incident response plans in place.
  • The government is seeking views until 21 September 2026 on digital product record policy to inform future developments and assess impacts on businesses, consumers and supply chains. DPRs are being explored internationally to provide product information and sustainability data across supply chains.
  • The BBC reported that chipmaker Nvidia teamed up with Wall Street banks and investors to raise $500 billion for AI infrastructure, likely including new data centres. Data centre controversy continues, with this Guardian article reporting that a proposed London site, set to be one of Europe’s largest data centres if approved, is ‘incompatible’ with net zero.
  • In related news, the government announced a £300 million investment package for the Lanarkshire AI Growth Zone in Scotland, including an expanded existing data centre and second new site. Dell Technologies will establish its Scottish base in the area.
  • The government published guidance on the Critical Minerals Accelerator, a £25 million grant funding scheme to support the commercialisation and scaling of innovative critical minerals solutions.
  • The government is reviewing electric vehicle sales targets “to ensure they remain pro-business and grounded in the real world”. The consultation closes on 23 October 2026.
  • And finally, the BBC reported that robotaxis have been granted licences to operate on London’s roads – on the condition a human driver is present.

How we can support you

If you have queries about any of the points covered in this edition of the Technology & Digital round-up, or need further advice or assistance, please get in touch with Sally, Andrew, Nick, Paul, Luke, Matthew or one of our Technology & Digital experts.

Sally
Mewies

Head of Technology & Digital

CONTACT DETAILS
Sally's contact details

Email me

CLOSE DETAILS

Andrew
Northage

Partner

Regulatory & Compliance

CONTACT DETAILS
Andrew's contact details

Email me

CLOSE DETAILS

Nick
Stubbs

Partner

CONTACT DETAILS
Nick 's contact details

Email me

CLOSE DETAILS

Paul
Armstrong

Director

Commercial

CONTACT DETAILS
Paul 's contact details

Email me

CLOSE DETAILS

Luke
Jackson

Director

Commercial

CONTACT DETAILS
Luke's contact details

Email me

CLOSE DETAILS

Matthew
Lingard

Director

Intellectual Property, Trade Marks & Designs

CONTACT DETAILS
Matthew's contact details

Email me

CLOSE DETAILS