Cyber Computer Science

Commercial and tech

EU AI Act

The EU AI Act became law in summer 2024, but has had a staggered implementation programme. It applies to any AI output available within the EU, and so will affect UK companies that provide or deploy AI services in the EU. The Digital Omnibus on AI entered into force on 27 July 2026. The obligations on high-risk systems have been deferred: stand-alone Annex III systems (covering areas such as employment, education and credit scoring) now apply from 2 December 2027, and high-risk systems embedded in regulated products from 2 August 2028. However, the Article 50 transparency obligations still apply from 2 August 2026. These include telling users when they are interacting with an AI system (such as a chatbot) and labelling deepfakes and AI-generated or AI-manipulated content published on matters of public interest. Please see our article here for more information. Providers of AI systems that generate synthetic content must ensure that content is marked in a machine-readable format detectable as artificially generated. Systems already on the market before 2 August 2026 have until 2 December 2026 to comply with this marking requirement. Track developments on our AI resource centre.

EU Data Act

Key obligations under the EU Data Act will come into force in 2026, including an obligation for manufacturers to design and manufacture in-scope connected products placed on the EU market after 12 September 2026 (and provide related services) in a manner that allows a user to access the product data and related service data. The Data Act also introduced new rules in September last year regarding EU customers wishing to switch to an alternative cloud provider midway through a subscription and terminate their contracts early. Please see our article here for more information. This may be impacted by the Digital Omnibus Package (see below).

Digital Omnibus Package

The Digital Omnibus on AI is now law — see the EU AI Act entry above for its effect on implementation timelines. The broader Digital Omnibus (covering GDPR, Data Act, cybersecurity and cookie rules) was proposed alongside it in November 2025 and remains in the EU legislative process. Its proposals include a single reporting portal for cybersecurity incidents, targeted simplifications to GDPR compliance obligations, and targeted exemptions to the Data Act's cloud-switching rules for SMEs. Businesses should continue to comply with existing rules while monitoring the progress of this wider package.

Cloud and AI Development Act

The European Commission published its formal proposal for the Cloud and AI Development Act on 3 June 2026. The proposal introduces a sovereignty framework for EU public-sector cloud procurement, with four tiers of assessment criteria based on sensitivity of activity. It also targets tripling EU data centre capacity within five to seven years and supports research and innovation in EU-developed cloud and AI infrastructure. The proposal is in its early stages and will now progress through the standard EU legislative process.

UK AI Regulation

In the UK, there is a non-legislative approach to AI whereby regulators provide guidance based on a set of principles. No standalone AI Bill was included in the May 2026 King's Speech. The Government has confirmed it is not pursuing a cross-sector AI statute at this stage, preferring to use existing regulatory frameworks augmented by sector-specific guidance. The Regulating for Growth Bill, announced in the King's Speech, includes provision for an AI Growth Lab — a programme of regulatory sandboxes allowing new AI products and regulatory reforms to be tested in live market conditions, with a route to make successful changes permanent through secondary legislation. Following the change of Prime Minister on 20 July 2026, the Department for Science, Innovation and Technology was abolished and its functions split across other departments. Kanishka Narayan was appointed as the UK's Minister for Artificial Intelligence and is to attend Cabinet, and a new AI Taskforce has been established in the Cabinet Office. The Government's approach to AI policy under the new leadership should be monitored. Separately, the Government published its statutory report on copyright and AI on 18 March 2026, confirming it will not proceed with legislative reform at this stage (see the IP section).

Late Payments

The Commercial Payments Bill was introduced to Parliament on 19 May 2026. The Bill introduces a 60-day hard cap on payment terms (with some exemptions), makes statutory interest on late payments mandatory, gives the Small Business Commissioner powers to investigate poor payment practices and impose significant fines on persistent late payers, and requires boards of large companies with poor payment records to explain their performance publicly.

New EU rules on communicating software updates

In the EU, new rules will come into force in relation to communicating software updates on 27 September 2026 under the Empowering Consumers for the Green Transition Directive. This includes a ban on withholding the fact a software update will negatively impact the functioning of goods or services and falsely presenting software updates as necessary. Pre-contractual information must also be provided to consumers including telling them how long the producer or provider commits to providing software updates for.

Cybersecurity

Please see the Health & Safety/Product Safety section.

Ransomware payments

The Government is developing legislation to tackle ransomware payments following publication of its consultation response. The proposed framework has three elements: a ban on ransomware payments by public-sector bodies and operators of critical national infrastructure; a payment prevention regime under which all other organisations must notify the Government before making a ransom payment, allowing authorities to check for sanctions breaches and offer guidance; and mandatory incident reporting for all organisations, likely within 72 hours of an attack, though the precise timeframe has not yet been confirmed. A Private Members' Bill on reporting obligations (the Cyber Extortion and Ransomware (Reporting) Bill) has appeared in Parliament. Government legislation giving effect to the fuller package has not yet been introduced, but businesses should review incident-response plans now in anticipation of mandatory reporting obligations and notification requirements that may constrain future payment decisions.

Franchising Case Law

The case of APK Communications Ltd v Vodafone Ltd was heard at a case management conference in March 2026, where a split trial was approved. However, Vodafone settled the claim in July 2026, before the liability issues reached trial, without any admission of liability and on confidential financial terms. The settlement means there is no judgment on whether duties of good faith applied or whether Vodafone's contractual powers were exercised lawfully. An appeal is due to be heard in December 2026 in the case of Ellis v John Benson [2025]; the High Court in this case found implied duties of good faith and fair dealing in 20 one-sided franchise agreements.

Please fill in the form below to access the full report.