AI Quarterly September 2026

AI Quarterly | A Review of AI Law, Policy & Practice | 2026 Q3

Our AI Quarterly publication brings together the firm’s latest AI focused practical insights, key developments, and upcoming programs all in one place, including relevant writings, events, and firm news.

Insights

FTC Proposes Enforcement Policy Statement on Personalized Pricing

On August 19, 2026, the Federal Trade Commission (FTC) announced that it is seeking public comment on a proposed enforcement policy statement about personalized pricing. The proposed statement makes clear that the FTC intends to scrutinize personalized pricing practices under Section 5 of the FTC Act and marks the latest development in the FTC’s ongoing focus on how much consumers are being charged for goods and services.

Connecticut Court Issues First Prompt Injection Sanctions

A Connecticut pro se plaintiff has been caught—and sanctioned for—attempting to manipulate a court he believed was relying on an artificial intelligence tool to reach decisions by hiding instructions directed to the tool in court filings. The court held that the plaintiff’s attempted use of an AI “prompt injection” attack offended the integrity of the proceedings, and revoked the plaintiff’s electronic filing privileges. The episode is both a cautionary tale about an emerging AI security vulnerability and a signal of broader judicial concerns with AI use in legal proceedings.

IBM’s 2026 Cost of a Data Breach Report Signals a New Era of AI-Driven Cyber Risk

On July 29, 2026, IBM released its Cost of a Data Breach Report 2026, which highlights the changing cyber threat landscape in which artificial intelligence is accelerating how threat actors identify vulnerabilities, launch attacks, and exploit compromised systems. These trends are reflected in rising average breach costs, with the global average cost rising 12% to a record $4.99 million and the U.S. average reaching $11.5 million, up 14% from last year.

European Commission Publishes New Guidelines and Code of Practice on GenAI Transparency

On July 20, 2026, the European Commission published new Guidelines on Transparency Obligations for Providers and Deployers of AI Systems to complement the Code of Practice on Transparency of AI-Generated Content it released on June 10, 2026. The materials arrive just weeks before the AI Act’s transparency obligations take effect on August 2, 2026, and give businesses clearer direction on how to identify, label, and disclose AI-generated content in practice.

EU Regulators Outline GDPR Requirements for AI Web Scraping

On July 8, 2026, the European Data Protection Board, the body that coordinates the EU’s national data protection authorities, published its first draft of Guidelines 03/2026 on Web Scraping in the Context of Generative AI. The guidelines address practical compliance challenges for companies that develop AI models or systems and scrape personal data from internet sources to train generative AI, as well as companies that rely on third parties to carry out that scraping. They also matter for deployers and enterprise customers of downstream AI models and systems, including businesses using AI in EU-facing products, services, or operations.

The White House’s Gold Eagle Initiative Signals a New Phase in AI-Enabled Cyber Defense

The White House has launched “Gold Eagle,” a new cybersecurity vulnerability coordination clearinghouse designed to use advanced AI capabilities to accelerate how the government and industry identify, prioritize, verify, and remediate software vulnerabilities. The initiative was established under the June 2, 2026 Executive Order Promoting Advanced Artificial Intelligence Innovation and Security and is being framed by the White House as a new operational model for cyber defense.

GSA Seeks Input on Revised AI Data Safeguarding Clause for Government Contracts

On July 14, 2026, the General Services Administration (GSA) held a public listening session to gather stakeholder feedback on a revised draft General Services Administration Acquisition Regulation clause addressing the basic safeguarding of government data within large language model artificial intelligence systems. The session—part of the GSA’s second round of engagement on the draft clause—invited industry associations, companies, academics, and individual practitioners to comment on the clause’s strengths, weaknesses, and practical improvements.

Five Eyes Issues Urgent Call to Action on AI-Driven Cyber Threats

On June 22, 2026, the intelligence alliance known as Five Eyes released a statement warning that frontier AI models will fundamentally transform offensive and defensive cyber capabilities and that the timeline for this transformation is measured in months, not years. Five Eyes emphasized that AI is “not a future consideration—it is already here.” They warned that AI lowers barriers for malicious actors, increases the speed and complexity of attacks, and shrinks the window between vulnerability discovery and exploitation.

Publications

Events

News

  • July 1, 2026 – Cynthia Cole is quoted in the Anti-Corruption Report on emerging AI compliance considerations in commercial agreements, noting that companies are increasingly evaluating representations of AI laws, governance obligations, and the lawful use of data for AI systems.

 For additional updates, please visit our Privacy, Cyber & Data Strategy Blog.

You can subscribe for future updates by completing our 
publications subscription form.


Media Contact
Alex Wolfe
Communications Director