This week’s Tech-law round-up

August 21, 2026

UK law

Solicitors Regulation Authority issues warning on misuse of AI in legal practice

The SRA has issued a warning notice on the misuse of AI in legal practice, highlighting growing concerns about solicitors relying on unverified AI-generated content and failing to protect client confidentiality when using AI tools. The SRA notes that AI “hallucinations” have already led to fictitious case citations and inaccurate legal submissions being put before the courts, resulting in judicial criticism, wasted costs applications and referrals to professional regulators. The SRA also warns that entering confidential client information into public AI systems may breach duties of confidentiality, legal professional privilege and data protection obligations. While recognising the benefits of AI, the SRA emphasises that solicitors and law firms remain fully responsible for the accuracy of their work, compliance with professional duties and the effective supervision of staff using AI. Firms are expected to implement appropriate governance, controls and safeguards, and the SRA makes clear that failure to comply with existing professional obligations when using AI could result in disciplinary action.

National Cyber Security Centre issues guidance on managing the cyber risk of agentic AI |

The NCSC has published interim guidance on managing the cyber risks associated with agentic AI, highlighting that while increasingly autonomous AI systems can deliver significant productivity benefits, they can also carry out unintended or unsanctioned actions if not properly controlled. The guidance encourages organisations to take a risk-based approach, ensuring that AI agents are given only the level of autonomy necessary for their intended purpose and are subject to robust safeguards, including careful threat modelling, human oversight, sandboxed environments, restricted access to systems and credentials, comprehensive logging and monitoring, and emergency shutdown mechanisms. The NCSC stresses that organisations should not rely solely on built-in model safeguards, but instead implement layered technical and operational controls proportionate to the potential impact of an AI system malfunctioning or acting outside its intended scope.

CMA investigates more companies for online drip pricing

The CMA has launched formal consumer protection investigations into Trainline, Virgin Atlantic and RED Driving School over concerns that they may have used “drip pricing” practices by failing to include mandatory fees in the headline prices shown to consumers. The CMA will examine whether Trainline adequately disclosed booking fees for rail and coach tickets, whether Virgin Atlantic included mandatory resort fees and local taxes in package holiday prices, and whether RED Driving School sufficiently highlighted compulsory booking and digital fees. The investigations follow earlier advisory letters issued under the CMA’s enhanced powers under the Digital Markets, Competition and Consumers Act 2024, and form part of a broader crackdown on misleading pricing practices. While the CMA has not yet reached any conclusions, if it finds consumer law has been breached it can order refunds for affected customers and impose fines of up to 10% of global turnover.

ICO publishes children’s code strategy update

The ICO’s August 2026 update on its Children’s Code Strategy reports significant progress in improving children’s online privacy since the strategy launched in April 2024. The ICO estimates that changes secured from major social media and video-sharing platforms have benefited almost five million child users, including stronger age assurance measures, improvements to location-sharing features on Snapchat and Instagram, and enforcement action resulting in fines against Reddit and MediaLab (Imgur) for unlawful use of children’s personal data. The ICO has also expanded its focus to mobile gaming, secured commitments from gaming platforms to enhance privacy protections, and begun reviewing age assurance providers. Alongside its regulatory work, the ICO has increased public awareness through its “Switched on to Privacy” campaign, reaching around 1.2 million UK households. The update comes against the backdrop of proposed government reforms to restrict under-16s’ access to certain social media services, with the ICO emphasising that data protection obligations and the requirement to act in children’s best interests will continue to apply regardless of any future age-based restrictions.

UK government launches call for evidence launched on the impact and effectiveness of Sections 1 to 13 of the Telecommunications (Security) Act 2021

The UK government has launched a call for evidence as part of the statutory review of the telecommunications security framework introduced by the Telecommunications (Security) Act 2021. It seeks views from stakeholders who have engaged with the Act, the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice, with a particular focus on assessing the impact and effectiveness of the telecoms security regime since its implementation. Responses will help inform the government’s evaluation of whether the framework is meeting its objectives of improving the security and resilience of UK public telecommunications networks and services. The consultation ends on 12 October 2026.

EU law

European Commission clears creation of joint venture by ACS AIID, Telefónica, Banco Santander and SETT

The European Commission has approved, under the EU Merger Regulation, the creation of a joint venture by AI Infrastructure Development, S.L, Telefónica S.A. Banco Santander, S.A. and Entidad Pública Empresarial Sociedad Española para la Transformación Tecnológica, E.P.E., which are all based in Spain. The transaction relates primarily to third-party data centre colocation services in Spain and contributes to the EU’s tech sovereignty strategy of strengthening and expanding sovereign cloud and AI infrastructure in Europe, as part of the EU’s AI Gigafactories Initiative. The Commission concluded that the notified transaction would not raise competition concerns, given the companies’ limited market positions resulting from the proposed transaction. The notified transaction was examined under the simplified merger review procedure.