This week’s Tech-law round-up

July 10, 2026
UK law

Select Committee warns UK government must set out strategy to achieve sovereign AI capabilities

The House of Commons Science, Innovation and Technology Committee has published a report saying that, in an era of geopolitical instability and technological competition, the UK government “may not be able to count on its allies” for access to critical technologies and must set out an AI sovereignty strategy. It says that the government has “no coherent strategic framework” for how it will leverage its world-leading scientific research and institutions to advance its wider diplomatic and economic goals. The Committee concludes that the government takes an “opportunistic approach” to international agreements on science and technology. The report calls for a clear framework for science partnerships and engagements, backed by delivery plans to provide certainty for industry. The report argues that the UK is in a global race for sovereign tech capabilities, with AI emerging as a central arena for competition and collaboration. MPs warn that the US’s recent restrictions on some AI models highlight the risk of relying on allies for access to technologies that are critical to economic growth and national security, and that the government must protect its tech sovereignty. It needs to set out realistic ambitions for sovereign capabilities in key sectors such as AI, quantum and space. This would be a necessary precursor to a joined-up strategy to achieve them. Geopolitical pressures and the importance of technological sovereignty make long-standing challenges around commercialising homegrown research more urgent. While the UK produces world-class early-stage research, it struggles to scale companies domestically. Many innovative firms are forced to move overseas to grow, and MPs urge the government to address gaps in later-stage funding for deep tech companies through more targeted investment and public procurement. The report finds that the UK has failed to capitalise on opportunities to expand its reputation and soft power in science and tech through decisions in areas such as attracting international talent and cutting ODA R&D.

Automated Vehicles (Marketing Restrictions) Regulations 2026 made

The Automated Vehicles (Marketing Restrictions) Regulations SI 2026/733 have been made. They set out the authorisation process and marketing terms used to describe authorised or listed self-driving vehicles in Great Britain. They restrict terms such as “automated”, “automated driving”, “autonomous”, “autonomous driving”, “drive autonomously”, “drive itself”, “driverless” and “self-driving” in connection with road vehicles, with the terms “automated” and “autonomous” restricted only when used to describe a vehicle as a whole or its overall driving functionality or capability. These regulations will help prevent end users in Great Britain from being misled into thinking that vehicles that are not authorised automated vehicles can safely and lawfully drive themselves. They come into force on 7 January 2027.

ICO fines two companies £370,000 for making nuisance calls

Two home improvement companies have been fined a total of £370,000 for making hundreds of thousands of unlawful marketing calls to people who had asked not to be contacted. Thermotech Wall and Loft Surveys Ltd (TWLS) has been fined £240,000 and Jacksons Marketing Ltd (JML) has been fined £130,000 following investigations into calls about loft insulation, home surveys and government grants. Alongside the fines, both companies were issued with enforcement notices ordering them to stop making marketing calls without consent.

IJT seeks feedback on scoping papers

The International Jurisdiction Taskforce (IJT) is inviting feedback on four scoping papers. Produced by the IJT working groups, the papers cover tokenisation, principles of control, principles of transfer and good faith acquisition, and custody and insolvency arrangements. Feedback is sought by 4 September 2026.

UK government consults on workplace monitoring technologies

The government is seeking views on proposals to support the fair, transparent and responsible use of workplace monitoring technologies used to monitor, manage or make decisions relating to workers. The government recognises that the pace of advancement in workplace technologies means they offer opportunities to employers to drive productivity, investment and economic growth across the UK economy. However, there should be clear expectations about their use in the workplace. When used well, technology can support efficiency, innovation and growth. When used poorly, it can damage trust, undermine wellbeing and create workplace tensions. From an employer perspective, excessive use can be counterproductive: it is associated with lower motivation and commitment, higher staff turnover and increased workplace conflict. The consultation sets out that relevant legal frameworks may not always be clearly understood by employers or consistently applied. As well as creating uncertainty for employers seeking to adopt workplace monitoring technologies responsibly, this creates potential risks that can undermine transparency, fairness and trust among workers. The government is therefore seeking views on whether further intervention is needed to improve transparency, worker engagement and accountability, and whether any intervention should have a regulatory basis. The consultation ends on 30 September 2026.

UK government consults on Smart Data schemes

Following publication of the Smart Data strategy 2035, the UK government is considering how Smart Data schemes should be prioritised, designed and delivered in practice. It has called for evidence to inform decisions on sector readiness, use cases, how schemes should be designed and how to ensure cross‑economy alignment. Use cases identified through the call for evidence will be subject to targeted feasibility analysis and design, including assessment of data availability, governance models and the effect of the Data Use and Access Act 2025. They will also be subject to formal consultation before any regulatory change. The aim of the call for evidence is to seek stakeholder input on potential use cases for Smart Data across the agri-food, property, retail, trade and transport sectors; explore design considerations to support effective and scalable scheme implementation in the named sectors; invite views on cross-sector governance models and institutional arrangements; gather evidence on lessons from international Smart Data initiatives; and inform future sector-specific consultations and the overall scheme delivery approach. The call for evidence ends on 1 October 2026.

EU law

European Commission accepts binding commitments by SAP to address competition concerns

The European Commission has accepted commitments from SAP to address EU competition concerns relating to its aftermarket support services for on-premises Enterprise Resource Planning (ERP) software. These commitments are now legally binding under EU antitrust rules. In September 2025, the Commission opened a formal investigation and preliminarily found that SAP has been engaging in four practices that could restrict competition in the EEA-wide market for maintenance and support (M&S) services for SAP’s on-premises ERP software. In response to the Commission’s concerns, SAP offered commitments. Between November 2025 and December 2025 the Commission market-tested those commitments and consulted all interested third parties to verify whether they would remove competition concerns. In light of the outcome of this market test, SAP adjusted the initial proposal. SAP will clarify the conditions for splitting customers’ SAP landscape into separate parts, allow customers to terminate their licences and the respective M&S fees in some specific scenarios, give wider access to single-metric contracts, clarify its contractual provisions regarding the initial licence term and refrain from restarting a new term for every additional licence purchase, abolish reinstatement fees and reduce back maintenance fees charged to customers who return to SAP’s support after a period of absence, and create an internal clearing structure customers can turn to when they consider that SAP is not applying the commitments correctly. The Commission concluded that the final commitments adequately address its preliminary competition concerns and has decided to make them legally binding on SAP.

Council of the EU moves to reinstate interim measure to combat child sexual abuse online

The Council of the EU has adopted its position on a regulation to allow online service providers to resume voluntary detection and removal of child sexual abuse material on their platforms. The measure aims to protect children while a long-term legislative framework is under negotiation. The previous interim measure expired on 3 April 2026. The Council wants an interim measure to be reinstated as soon as possible until 3 April 2028. The interim measure constitutes a derogation from data protection rules in the electronic communications sector. This derogation allows online service providers to detect online child sexual abuse on their services, as well as to report and remove it. The European Parliament has adopted amendments to the Council’s position. It wants to exclude “communications to which end-to-end encryption is, has been or will be applied” from the scope of the law.

European Commission publishes EU Action Plan on cybersecurity and artificial intelligence

The European Commission has published an Action Plan on Cybersecurity and Artificial Intelligence to address the risks and harness the opportunities of advanced artificial intelligence models for cybersecurity. It focuses on four main areas: building EU capacity to evaluate advanced AI models for cybersecurity risks; creating a framework for trusted access to cutting-edge AI systems; establishing a secure testing platform for AI-driven cybersecurity tools; and strengthening cyber resilience across critical sectors through better cyber hygiene, security-by-design measures and wider use of AI to identify and fix vulnerabilities. It also aims to boost Europe’s own AI cybersecurity capabilities through public-private collaboration, support for open-source software security, and a new EU Grand Challenge on AI for cybersecurity. The initiative builds on existing EU legislation, including the AI Act, NIS2, DORA, the Cyber Resilience Act and the Cyber Solidarity Act, with the Commission emphasising that the EU must both guard against AI-enabled cyber threats and harness AI to improve cybersecurity across the digital economy.

European Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity

The European Commission has decided to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify measures transposing the NIS2 Directive on securing network and information systems (Directive (EU) 2022/2555) into national law. The Directive strengthens EU cybersecurity by setting high standards for entities operating in 18 critical sectors, including health, energy, transport, and the public sector. Its full implementation is key to improving the EU’s resilience and the incident response capacity of public and private entities operating in these critical sectors, and of the EU as a whole. Member States had until 17 October 2024 to transpose the Directive. While most complied, Spain, France, Ireland and the Netherlands have yet to notify full transposition. The Commission sent letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025. The referrals include a request to the Court to impose financial sanctions, consisting of a lump sum and daily penalties until notification of complete transposition.

European Data Protection Board holds latest plenary session

During its latest plenary, the EDPB adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board adopted the final version of its guidelines on the processing of personal data through blockchain technologies. The new EDPB guidelines bring clarity to the concept of anonymous data, also taking into account the ruling of the Court of Justice of the EU in C-413/23 P EDPS v SRB and other CJEU judgments. In its guidelines on web scraping in the context of generative AI, the Board clarifies various aspects of GDPR compliance, including the legal basis for such activities and the conditions under which special category data can be processed in this context. Building on the EDPB Opinion on AI models, the guidelines provide further clarifications and examples on the use of the legitimate interests legal basis in the specific context of web scraping for AI training. Finally, following consultation, the EDPB adopted the final version of its guidelines on blockchain technologies. The guidelines help organisations using blockchain technologies to comply with the GDPR. The EDPB explains how blockchains work, assessing the different possible architectures and their implications for the processing of personal data.