This week’s Tech-law round-up

February 27, 2026
UK law

Civil Justice Council consults on use of AI in court documents

The CJC has issued an interim report and consultation on using AI to prepare court documents.  It says that AI can be very beneficial but there are risks. In Ayinde v The London Borough of Haringey [2025] EWHC 1383 (Admin), Dame Victoria Sharp, President of the Kings Bench Division, observed that: “AI is a tool that carries with it risks as well as opportunities. Its use must take place therefore with an appropriate degree of oversight, and within a regulatory framework that ensures compliance with well-established professional and ethical standards if public confidence in the administration of justice is to be maintained.” The consultation is considering if rules are needed to govern the use of AI by legal representatives for the preparation of court documents. It sets out the CJC’s initial thinking on the issues and proposes a possible way forward. After the consultation, the CJC will produce a final report. In summary it proposes that in specific circumstances, and depending on what use of AI has been made, legal representatives involved in the preparation of court documents should be required to make a declaration relating to its use. The circumstances are addressed in detail in the consultation but in general terms are where AI has been used to generate evidence on which the court is being asked to rely. Other uses of AI, such as administrative uses for transcription, spell checking, assistance and the like do not require a declaration. The overall objective of the proposals is to maintain a balance, ensuring that the latest technology can be used to maximum advantage in the civil justice system to enhance access to justice by improving efficiency and reducing costs; while at the same time maintaining confidence in the rule of law. The consultation ends on 14 April 2026.

Ofcom fines porn company £1.35m for not having age checks

Ofcom has fined porn company 8579 LLC £1.35m for not having age checks in place, plus £50,000 for failing to respond to an information request. Under the UK’s Online Safety Act, sites that allow pornographic material must use highly effective age assurance to prevent children from readily accessing that content. Within days of this duty coming into force in July 2025, Ofcom launched investigations into the providers of dozens of adult sites, including 8579 LLC. These websites were prioritised based on their user numbers. Following investigation, it has fined 8579 LLC £1.35 million for failing to comply with these age check requirements. The company must immediately implement highly effective age assurance or face a daily penalty of £1,000. Firms are required, by law, to respond to Ofcom in an accurate, complete and timely way. For failing to abide by these requirements, it has also fined 8579 LLC £50,000. It will impose a daily penalty of £250 on the company until it responds, or for 60 days, whichever is sooner.

CMA issues interim report in Getty Images / Shutterstock merger

The CMA has issued its interim report as part of its Phase 2 investigation into the merger of Getty Images and Shutterstock. The CMA provisionally concluded that the merger will result in the creation of a relevant merger situation that may be expected to result in a substantial lessening of competition in the supply of editorial content in the UK, but not in the supply of stock content globally. The CMA invites comments on its interim report by 12 March 2026.

FCA announces sentencing of seven social media influencers for issuing unauthorised financial promotions

The Financial Conduct Authority (FCA) has announced that seven social media influencers have been sentenced at Southwark Crown Court after pleading guilty to issuing unauthorised financial promotions in connection with an unauthorised foreign exchange trading scheme. Communicating unauthorised financial promotions is an offence under Sections 21 and 25 of the Financial Services and Markets Act 2000 punishable upon conviction by a fine and/or up to 2 years’ imprisonment. highest fine was £3,750 plus £5,778.18 costs, while penalties for the other defendants ranged from absolute discharge to fines of £974, with all ordered to pay costs. The combined following of the Instagram accounts of these individuals was 4.5 million.

EU law

EDPB adopts report identifying challenges to full implementation of right to erasure

The European Data Protection Board (EDPB) has adopted a report on its fourth Co-ordinated Enforcement Action (CEF 2025) which is about controllers’ implementation of the right to erasure (“right to be forgotten”). The report identifies several key challenges which affect the full implementation of the right. These include a lack of documented, up-to-date internal procedures, insufficient role-specific training for staff, difficulty setting retention periods, weak anonymisation and poor practice relating to back-ups, among other things. The Irish DPC has issued a statement welcoming the report.

Irish Data Protection Commission opens investigation into X (XIUC)

The Irish Data Protection Commission has announced that it has opened an inquiry into X Internet Unlimited Company (XIUC) under section 110 of the Data Protection Act 2018. The inquiry concerns the apparent creation, and publication on the X platform, of potentially harmful, non-consensual intimate and/or sexualised images, containing or otherwise involving the processing of personal data of EU/EEA data subjects, including children, using generative artificial intelligence functionality associated with the Grok large language model within the X platform. The decision to commence the inquiry was notified to XIUC on Monday 16 February. The purpose of the inquiry is to determine whether XIUC has complied with its obligations under the GDPR, including its obligations under Article 5 (principles of processing), Article 6 (lawfulness of processing), Article 25 (Data Protection by Design and by Default) and Article 35 (requirement to carry out a Data Protection Impact Assessment) with regard to the personal data processed of EU/EEA data subjects.

International law

EDPB and ICO sign joint statement on AI-generated imagery and privacy protection

The European Data Protection Board (EDPB) and the ICO, among others, have signed a Joint Statement on AI-Generated Imagery and the Protection of Privacy, representing the united position of 61 authorities across the world coordinated by the Global Privacy Assembly’s International Enforcement Cooperation Working Group. The statement addresses concerns about AI systems that generate realistic images and videos depicting identifiable individuals without their knowledge or consent, particularly highlighting risks of cyber-bullying and exploitation affecting children and other vulnerable groups. The co-signatories remind organisations developing and using AI content generation systems that these must comply with applicable data protection and privacy rules, outlining four fundamental principles: implementing robust safeguards, ensuring meaningful transparency, providing effective and accessible protection mechanisms, and addressing specific risks to children. The statement calls on organisations to engage proactively with regulators, implement robust safeguards from the outset, and make sure that technological advancements do not compromise privacy, dignity, safety and other fundamental rights.