Wholestory

Last Updated: July 27, 2026

Law & Governance: The Rules Being Written

Both poles of AI regulation moved in the same week, and both moved away from enforcement. On 27 July the EU's Digital Omnibus on AI — Regulation (EU) 2026/1744, adopted 8 July and published in the Official Journal on 24 July — entered into force and amended the AI Act itself, pushing the obligations for standalone high-risk systems from 2 August 2026 to 2 December 2027, and high-risk AI embedded in machinery, toys and lifts to 2 August 2028. The same package widened the AI Office's reach and banned AI systems that generate non-consensual sexual imagery, and it left the Act's core transparency duties biting on 2 August. But the register at the centre of the high-risk regime does not exist: a Commission service-desk message seen by Euractiv says the database 'is not yet open and operational', and it is not expected to launch until the third quarter of 2027 — against a Council expectation of last June — while the omnibus appears to have deferred the high-risk obligations without moving the standalone article that imposes the duty to register. The Commission declined to say which date governs. Enforcement powers arrive on 2 August into an AI Office of 145 staff, only 34 of whom work on regulation and compliance. In the United States the direction is starker: Colorado's AI Act, the first comprehensive state statute, never took effect at all — xAI sued to enjoin it, the Justice Department intervened against it on 24 April in its first such intervention against a state AI law, and three days later the court suspended enforcement. Where AI law is actually biting is through older authorities: Pennsylvania's State Board of Medicine sued Character.AI in May for practising medicine without a licence, and a newly filed San Francisco suit, Winters v. OpenAI, asks a court to treat a chatbot's design as a defective product and names OpenAI's chief executive personally. The one large judgment stands: Judge Araceli Martínez-Olguín — who inherited the case when Judge Alsup retired — gave final approval to Anthropic's $1.5 billion settlement, with roughly $3,000 per work and 92% of eligible claimants opted in.

The Whole Story

The legal architecture of AI is being built now, in courtrooms and legislatures on multi-year timelines that outlast any news cycle: copyright suits over training data, liability claims over model outputs, and regulation from binding statutes to voluntary commitments. This page follows the dockets and the enforcement record — filings, rulings, enacted rules, and their actual consequences — rather than the announcement-day headlines.

Continue Reading →

The EU amends its own AI Act, pushing the high-risk rules back by up to two years

Regulation (EU) 2026/1744 — the "Digital Omnibus on AI", adopted on 8 July 2026 and published in the Official Journal on 24 July — entered into force, amending the AI Act (Regulation (EU) 2024/1689) along with the aviation and machinery regulations. Its central effect is time: the obligations for standalone high-risk systems in Annex III, due to apply from 2 August 2026, now apply from 2 December 2027, and high-risk AI embedded in physical products such as machinery, toys and lifts moves to 2 August 2028. The package also extends SME simplifications to small mid-cap companies, opens an EU-level regulatory sandbox, softens the AI-literacy duty, prohibits AI systems that generate non-consensual sexually explicit content or child sexual abuse material, and widens the AI Office's oversight to systems built on general-purpose models and embedded in very large platforms and search engines. Stephenson Harwood notes what did not move: the Act's core transparency obligations still bite on 2 August 2026, and apply to in-scope systems whenever they were placed on the market.

The register at the centre of the EU's high-risk regime will not exist until 2027

The AI Act requires companies to enter high-risk AI systems — those used in schools, law enforcement or workforce management — in a central EU database before switching them on. A 9 July message from the Commission's AI Act service desk, seen by Euractiv, states that "this database is not yet open and operational", and Euractiv understands it will not launch until the third quarter of 2027. At the start of 2026 the Council had still expected the register to be running by the end of June. Euractiv also reports a gap the Digital Omnibus left open: while the omnibus deferred the article consolidating high-risk providers' obligations, it did not move the separate standalone article imposing the duty to register, which on Euractiv's reading could leave that duty applying from 2 August 2026 — with no database to register in. The service desk's own message says the obligation starts in December 2027. The Commission did not respond to Euractiv's request to clarify which date governs.

Bombay High Court lets an Indian minister sue Meta, X and Google over AI deepfakes

Justice Abhay Ahuja permitted Union Transport Minister Nitin Gadkari to institute a civil suit in the Bombay High Court against Meta Platforms, X Corp, Google LLC and others over AI-generated deepfake videos and manipulated content that, he says, falsely tie him and his family to the Ethanol Blended Petrol and E20 programmes — which are administered by a different ministry. The plea frames the deepfakes as both defamation and an unauthorised exploitation of his personality and publicity rights, while stating that the suit is not meant to curtail "discussion, debate, analysis or fair, just and bona fide criticism" of his decisions. The Union Ministries of Electronics and Information Technology and of Telecommunications are named as respondents. The application for interim relief, including a temporary injunction requiring the platforms to take the content down, will be heard later.

Mythos showed that access to frontier models has become geopolitical leverage, but Europe's sovereignty will be judged by whether it defends its own rulebook rather than trading away enforcement for access.?

Context: A normative judgment by one of the AI Act's co-authors about how the EU should use enforcement powers that take effect on 2 August 2026. It sets no falsifiable metric or date, so it is recorded as a position rather than scored. What it will be measurable against is the AI Office's first cases: it has 145 staff, only 34 of them working directly on regulation and compliance, and from 2 August can demand information, require technical changes, and fine up to 3% of prior-year revenue.

Court grants final approval to Anthropic's $1.5 billion settlement

Judge Araceli Martínez-Olguín granted final approval to the $1.5 billion Bartz v. Anthropic settlement in the Northern District of California, closing the authors' pirated-books class action after a preliminary approval in September 2025 and a fairness hearing in May 2026. She took over the case after Judge William Alsup — who wrote the underlying rulings that training on lawfully acquired books is fair use but downloading pirated copies is not — retired at the end of 2025. Her order found the agreement "provides meaningful relief to the Settlement Class," noted that the estimated per-work payment of roughly $3,000 is "four times the minimum statutory damages amount for willful infringement," recorded that 92% of those eligible for an award had opted into the class, and denied all but two opt-out requests.

A pastor's suit asks a California court to treat a chatbot's design as a defective product

Scott Winters filed Winters v. OpenAI in the Superior Court of California for the County of San Francisco, alleging that prolonged reliance on ChatGPT-4o for health guidance — a "dysautonomia" diagnosis, a personalised recovery plan, and repeated assurances that his symptoms were not serious — contributed to a near-fatal pulmonary embolism in July 2025. The complaint pleads eight claims, including defective design in strict liability and negligence, failure to warn, unauthorised practice of medicine, and violation of California's recently enacted AI health-care licensing requirements, and names CEO Samuel Altman in his individual capacity for allegedly breaching safety-oversight duties. Beyond damages it seeks hard-coded refusals for diagnosis and treatment, deletion of GPT-4o and its training data, and a pause of ChatGPT Health pending independent audits. The court has consolidated the case with other ChatGPT suits under a coordinated proceeding, "ChatGPT Product Liability Cases."

We applaud the court's final approval of this settlement, which represents an important victory in the larger battle to hold big tech accountable for its unscrupulous appropriation of intellectual and creative properties that clearly belong to authors and publishers.±

Context: Accurate that the court approved the settlement and that Martínez-Olguín's order condemned downloading from pirate sites. But Pallante went on to argue that fair use should not be extended to let tech companies copy copyrighted material for training — and the order decided nothing of the kind. It approved a negotiated settlement, expressly reasoning that "success at trial was not assured"; the only fair-use holding in the case is Alsup's, which found training on lawfully acquired books IS fair use. Characterising the approval as a verdict on fair use overstates what the document holds.

Pennsylvania's medical board sues Character.AI for practising medicine without a licence

The Commonwealth of Pennsylvania, Department of State, State Board of Medicine filed suit against Character Technologies in the Commonwealth Court of Pennsylvania (No. 220 MD 2026), alleging that Character.AI companion chatbots held themselves out as licensed medical professionals — including personas claiming to be psychiatrists and one that fabricated a physician-assistant licence number — and offered assessments and treatment recommendations in violation of the state Medical Practice Act. Pennsylvania seeks injunctive relief barring the company from marketing or operating the bots as medical providers. The action's significance is its route: a state professional licensing board, an authority available in virtually every state, rather than any AI-specific statute.

Colorado's AI Act is suspended before it takes effect, with the Justice Department intervening against it

The first comprehensive US state AI statute was frozen before it ever applied. xAI sued the Colorado Attorney General in early April 2026 to enjoin the Colorado AI Act (SB24-205), whose effective date had already slipped from 1 February to 30 June 2026, arguing that designing a model is protected speech and that the law's carve-out for algorithms advancing "diversity" violates equal protection. On 24 April the Justice Department moved to intervene against the law — its first intervention in a challenge to a state AI statute, and the first practical use of Executive Order 14365's directive that DOJ contest state AI rules. The same day, xAI and the Attorney General jointly moved to suspend enforcement; on 27 April the court granted the motion, staying the law until Colorado's 2026 legislative session and any resulting rulemaking conclude and xAI's preliminary-injunction motion is decided. The court expressed no view on the merits.

Governor Polis signed the Colorado AI Act with reservations, warning it creates a complex compliance regime that could hamper innovation, urging sponsors to significantly improve it before it takes effect, and calling on Congress to enact preemptive federal AI legislation.?

Context: A signing-statement opinion and a call for federal action, not a determinate factual claim, so it is not scored. Two of its elements can now be checked in hindsight, and both cut in Polis's favour without vindicating the remedy he asked for. The law was never significantly improved before taking effect, because it never took effect: its start date slipped from 1 February to 30 June 2026, xAI sued the Colorado Attorney General to enjoin it, and on 27 April 2026 the court suspended enforcement pending the legislature's next move and a preliminary-injunction ruling. And Congress did not supply the preemptive federal statute he called for — the preemption came instead from the executive branch, through a Justice Department intervention against Colorado's law under Executive Order 14365.

Music publishers escalate the Anthropic lyrics fight with a discovery-fueled complaint

Concord, Universal Music Publishing Group and ABKCO filed a 71-page Second Amended Complaint against Anthropic in the Northern District of California, drawing on internal records obtained in discovery — including an alleged co-founder query for Bob Dylan lyrics and a decision to use an extraction tool that stripped copyright notices — and seeking statutory damages up to $150,000 per work. It follows a separate January 2026 suit by the same publishers covering more than 20,000 songs and seeking over $3 billion for alleged torrenting of lyrics.

Google and Character.AI settle the teen-suicide suits

Google and Character.AI agreed to a mediated settlement in principle resolving Megan Garcia's wrongful-death claims over Sewell Setzer III, together with related minor-harm suits from families in Colorado, Texas and New York; terms were not disclosed. The settlements followed the May 2025 denial of dismissal, a Texas attorney-general investigation, a September 2025 Senate hearing at which Garcia testified, and Character.AI's October 2025 move to bar under-18 users from open-ended chats.

UK High Court largely clears Stability AI after Getty drops its core claims

In the UK, the High Court (Mrs Justice Joanna Smith) largely ruled for Stability AI, holding that a model such as Stable Diffusion, which does not store or reproduce the copyrighted works, is not an "infringing copy." The framing of the result as a sweeping AI "win" understated what happened: Getty had voluntarily withdrawn its main training-copyright claim mid-trial because the training occurred outside the UK, and the court actually ruled for Getty on some trademark (watermark) claims.

The ruling resolves the core copyright concerns in the case, and Getty voluntarily dismissed most of its copyright claims at the close of trial testimony.±

Context: Stability AI's general counsel is accurate that Getty withdrew its principal training-copyright claims mid-trial and that the court found Stable Diffusion is not an infringing copy. But "resolves the core copyright concerns" overstates a narrow judgment: Getty prevailed on some trademark/watermark claims, and the withdrawal turned on where training occurred (a jurisdictional fact), not on a merits ruling that training is lawful.

California enacts SB 53, the first US frontier-AI safety statute

One year after vetoing SB 1047, Governor Newsom signed SB 53, the Transparency in Frontier Artificial Intelligence Act — also authored by Senator Wiener and the first state frontier-AI safety law in the nation. It requires large frontier developers to publish a safety framework, report critical safety incidents to the Office of Emergency Services, and protect whistleblowers, with civil penalties enforceable by the attorney general, and it establishes the CalCompute public computing consortium. A narrower, transparency-focused successor to the bill Newsom had rejected.

Anthropic settles the pirated-books class action for $1.5 billion

Anthropic agreed to pay about $1.5 billion to settle the Bartz class action over pirated books used to train Claude — the largest copyright recovery on record and the first major AI-era settlement. It covers an estimated 500,000 works at roughly $3,000 each, with Anthropic also agreeing to destroy the downloaded files, resolving the piracy liability that survived Alsup's June ruling and averting the December trial. Court filings had shown Anthropic downloaded more than 7 million books it knew were pirated (from Books3, LibGen and the Pirate Library Mirror) before shifting to buying and scanning physical books.

The Anthropic settlement will do little for European writers whose works are not registered with the US Copyright Office, and fits a tech-industry playbook of growing first and later paying a relatively small fine for breaking the rules.?

Context: A critical characterization by a rights-holder advocacy group. The registration limit it describes is real (the class requires timely US registration plus an ISBN/ASIN); the "small fine" framing is an opinion about deterrence, not a determinate fact.

Getty drops its US case against Stability AI to refile in California

Getty Images filed a notice of voluntary dismissal without prejudice of its Delaware copyright suit against Stability AI, stating it intended to refile in the Northern District of California to move faster. Defendants had filed no answer or summary-judgment motion. The Delaware docket's termination was Getty's own venue-driven withdrawal, not a ruling on the merits.

White House releases "America's AI Action Plan"

The White House released America's AI Action Plan, the strategy mandated by EO 14179, organized around three pillars: accelerating innovation by removing regulation and promoting open-weight models; building AI infrastructure through faster data-center, semiconductor and grid permitting; and leading in international AI diplomacy while tightening compute export controls. It is policy direction, not law, and marks the deregulatory turn from the Biden-era order.

EU publishes the voluntary General-Purpose AI Code of Practice

The European Commission published the General-Purpose AI Code of Practice — a voluntary tool drafted by independent experts in three chapters (Transparency, Copyright, and Safety and Security) to help GPAI providers show compliance with the AI Act. The Commission and AI Board confirmed it as an adequate compliance route; more than twenty providers signed, though some (notably xAI) signed only the Safety and Security chapter. Published after the Act's 2 May statutory readiness date.

A second judge reaches the opposite instinct in Kadrey v. Meta

Two days after Bartz, Judge Vince Chhabria granted Meta summary judgment that training Llama on books was fair use — but "on this record" only, and reluctantly, faulting the thirteen author-plaintiffs for failing to develop a market-harm case and noting Llama could not reproduce more than trivial snippets. He expressly disagreed with Alsup on pirated "shadow library" copies and rejected the "teaching children to write" analogy. The paired June rulings left US fair-use law genuinely unsettled.

In most cases it will likely be illegal to copy copyrighted works to train generative AI without permission, because AI trained on those works can generate countless competing works and thereby dilute the market for the originals — so companies will generally need to pay for training rights.?

Context: Dicta in the Kadrey opinion articulating a "market dilution" theory. It is a forecast about how future AI-training copyright cases should and will come out; as of this cycle the case law is split (contrast Bartz) and no appellate resolution has issued. Unresolved.

Alsup rules AI training fair use — but piracy is not

In Bartz v. Anthropic (N.D. Cal., No. 24-cv-5417), Judge William Alsup ruled on summary judgment that training Claude on books was "exceedingly transformative" fair use, and that digitizing lawfully purchased print books for training was also fair use. But he held that Anthropic's acquisition and retention of a permanent library of pirated books was not fair use, preserving liability for the piracy and setting a December 2025 trial on damages. In July the court certified a class for the piracy claim only, so the fair-use-on-training holding bound just the three named plaintiffs.

Texas enacts the Responsible AI Governance Act

Governor Greg Abbott signed the Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149). A pared-back version of an earlier draft, it bars government use of AI for social scoring and non-consensual biometric identification, prohibits AI intentionally designed to cause harm, incite crime, or produce unlawful sexual content, amends Texas biometric and privacy law, creates a Texas AI Council and sets up a regulatory sandbox. Enforcement is by the attorney general, with a 60-day cure period.

Ousted Register of Copyrights sues the president

Shira Perlmutter sued President Trump over her firing, arguing it was unconstitutional because the Copyright Office and Library of Congress sit within the legislative branch; the administration countered that the removals were lawful under the Federal Vacancies Reform Act. A federal judge denied her request for a temporary restraining order, with further hearings set for July 2025 — leaving the leadership of the US copyright system contested.

Court lets the Character.AI wrongful-death suit proceed, treating AI as a product

The Florida federal court denied the motion to dismiss the Garcia suit against Character.AI, Google and the founders, ruling the claims legally viable. The court questioned whether chatbot outputs are protected speech under the First Amendment, treated the AI system as a "product" for product-liability purposes, and kept the co-founders as defendants — an early, closely watched precedent for AI liability.

Register of Copyrights fired a day after the Part 3 report

Register of Copyrights Shira Perlmutter was fired on 10 May 2025 — one day after the Part 3 AI report's release, and two days after Librarian of Congress Carla Hayden was dismissed. The administration named DOJ officials Todd Blanche as Librarian and Paul Perkins as Register; the Office then paused issuing roughly 20,000 registration certificates for about 12 business days. NPR reported the sequence between the report and the firing without asserting causation.

Copyright Office Part 3 floats a "market dilution" theory of AI-training harm

The U.S. Copyright Office released a "pre-publication version" of Part 3 of its AI report, on using copyrighted works to train generative AI. Its central conclusion: many training uses are likely transformative, but fair use turns case-by-case on the works used, the source, the purpose and output controls. The report introduced a "market dilution" concern — that AI output competing in the same market can harm the market for originals even without direct copying. Observers called the unusual pre-publication release, issued with a final version promised, unprecedented.

First US AI fair-use ruling goes against the AI company

In Thomson Reuters v. ROSS Intelligence, Judge Stephanos Bibas (sitting in the District of Delaware) granted Thomson Reuters summary judgment on direct copyright infringement and rejected ROSS's fair-use defense — the first US merits ruling on fair use in an AI case. The court found ROSS copied 2,243 Westlaw headnotes, held the headnotes and Key Number System copyrightable, and found fair-use factors one (purpose) and four (market effect) favored Thomson Reuters, recognizing a potential market for AI training data. The ruling concerned non-generative AI, limiting how far it reaches.

Trump signs a new AI order directing an "AI dominance" agenda

President Trump signed EO 14179, "Removing Barriers to American Leadership in Artificial Intelligence" (published 31 January 2025, 90 FR 8741). It treats EO 14110 as revoked, directs agencies to suspend, revise or rescind actions taken under it that obstruct US "AI dominance," orders OMB to rewrite its AI memoranda within 60 days, and commissions an AI Action Plan within 180 days.

Trump revokes Biden's AI executive order on day one

On his first day in office, President Trump revoked Executive Order 14110 through EO 14148 ("Initial Rescissions of Harmful Executive Orders and Actions"), erasing the reporting mandates and agency directives that had been the core of US federal AI policy. The single largest reversal of AI governance in the record — a governance-as-announced-versus-enforced turning point.

Anthropic agrees to lyric "guardrails" in the music-publishers suit

A federal court approved a stipulation requiring Anthropic to maintain guardrails meant to stop its Claude model from reproducing copyrighted song lyrics, in the suit brought by music publishers Concord, Universal Music Publishing Group and ABKCO over some 500 songs (filed October 2023). It resolved only the injunction question; in March 2025 the court denied the publishers a preliminary injunction against training, finding any harm compensable by damages, and the case continued into discovery.

Mother sues Character.AI and Google over her son's suicide

Megan Garcia filed a wrongful-death and product-liability suit in Florida federal court against Character.AI, Google and Character.AI's co-founders after the suicide of her 14-year-old son, Sewell Setzer III, alleging the chatbot's anthropomorphic design was defective and unsafe for minors. The first major suit framing an AI companion product as a defective product in a user's death.

Newsom vetoes California's frontier-AI safety bill SB 1047, signs transparency laws

Governor Gavin Newsom vetoed SB 1047, the Safe and Secure Innovation for Frontier Artificial Intelligence Models Act by State Senator Scott Wiener, which would have required developers of the largest frontier models to build in safety protocols including full-shutdown capability and submit to audits against "critical harms." The same day he signed AB 2013, requiring public disclosure of generative-AI training-data summaries (effective 2026), and SB 896, directing state risk analysis of GenAI threats to critical infrastructure. The veto was the year's pivotal moment in US frontier-AI regulation.

Regulating only the largest and most expensive AI models could give the public a false sense of security while smaller specialized models may prove equally or more dangerous, and the bill applied stringent standards even to basic, low-risk uses.?

Context: The core reasoning of Newsom's SB 1047 veto message — a policy judgment about how to target frontier-AI regulation. It is a normative argument rather than a dated, falsifiable forecast, so it is recorded but not scored as a prediction.

FTC launches Operation AI Comply against deceptive AI claims

The FTC announced Operation AI Comply, a law-enforcement sweep against five operations using AI to power deceptive or unfair conduct — most notably DoNotPay, marketed as "the world's first robot lawyer," which per the complaint never tested whether its output matched a human lawyer's and hired no attorneys; DoNotPay settled for $193,000 with a notice requirement. Others (Ascend Ecom, Ecommerce Empire Builders, FBA Machine, Rytr) faced complaints, receiverships or bars. The sweep established that there is no AI carve-out from consumer-protection law.

Council of Europe opens the first binding international AI treaty for signature

The Council of Europe Framework Convention on Artificial Intelligence — the first-ever international legally binding treaty on AI — was opened for signature. It sets principles of human dignity, non-discrimination, privacy, transparency, accountability and reliable, safe innovation, with remedies, procedural safeguards and risk assessments, and lets authorities impose bans or moratoria ("red lines") on certain applications. It binds only once ratified; early signatories included the EU, US, UK, Canada, Japan, Israel and Ukraine.

Andersen v. Stability AI survives dismissal and heads to discovery

US District Judge William Orrick denied Stability AI's and Midjourney's motions to dismiss the artists' copyright claims in Andersen v. Stability AI, finding both direct and induced-infringement claims plausible and letting the case proceed to discovery. Trial was later set for September 2026, keeping the image-generation copyright question alive alongside the text cases.

The EU AI Act enters into force

The European Union's Artificial Intelligence Act entered into force — the first comprehensive, horizontal legal framework for AI anywhere, built on a risk-based approach (minimal, limited/transparency, high and unacceptable risk). Proposed by the Commission in April 2021 and agreed by Parliament and Council in December 2023, its obligations apply on a staggered timeline: prohibited practices first, then general-purpose-AI and governance rules, with high-risk-system requirements last.

US Copyright Office begins its landmark AI study with Part 1

The U.S. Copyright Office published Part 1 of its report "Copyright and Artificial Intelligence," addressing digital replicas and recommending a new federal digital-replica law. It was the first installment of a three-part study that would become central to the US copyright debate — and, with Part 3, to a governance crisis inside the Office itself.

Colorado enacts the first comprehensive US state AI law

Governor Jared Polis signed SB24-205, the Colorado AI Act, making Colorado the first US state to enact broad legislation governing high-risk AI and algorithmic discrimination in "consequential decisions" — employment, housing, credit, education and healthcare. It requires developers and deployers to use "reasonable care" against discrimination, complete impact assessments, disclose to consumers and offer appeal rights; the attorney general has exclusive enforcement. Operative obligations were later delayed, initially to 2026.

UN General Assembly adopts its first resolution on AI

The UN General Assembly adopted, without a vote, a US-led resolution promoting "safe, secure and trustworthy" AI — the first time the Assembly addressed AI governance. Co-sponsored by more than 120 member states, it emphasizes human-rights protection and closing the digital divide. It is recommendatory only, carrying no binding force.

A Canadian tribunal holds Air Canada liable for its chatbot

In Moffatt v. Air Canada (2024 BCCRT 149), the British Columbia Civil Resolution Tribunal held Air Canada liable for negligent misrepresentation after its website chatbot gave passenger Jake Moffatt incorrect advice about claiming a bereavement fare retroactively, and awarded C$812.02. The first widely cited ruling holding a company legally responsible for its AI chatbot's statements to a customer.

The New York Times sues OpenAI and Microsoft

The New York Times sued OpenAI and Microsoft in the Southern District of New York, alleging millions of Times articles were copied without authorization to train ChatGPT and related models that now compete with the Times. The complaint seeks no fixed figure but says defendants should be liable for "billions of dollars" in statutory and actual damages and asks the court to order destruction of models and training data built from Times material. It was the first major American news organization to bring such a suit.

FTC bans Rite Aid from facial recognition for five years

The FTC filed a complaint and proposed order in the Eastern District of Pennsylvania banning Rite Aid from using facial-recognition technology for surveillance for five years, to settle charges it deployed the technology from 2012 to 2020 in hundreds of stores without reasonable safeguards — generating thousands of false matches that led staff to wrongly accuse, search, eject and call police on customers, disproportionately in non-white and lower-income neighborhoods. The first major US enforcement order over a deployed AI system.

Biden signs Executive Order 14110, the first sweeping US federal AI order

President Biden signed Executive Order 14110, "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence" (published in the Federal Register 1 November 2023, 88 FR 75191). It imposed mandatory Defense Production Act reporting on developers of dual-use foundation models — training activities, model-weight security and red-team results — for models trained above 10^26 operations (10^23 for biological-sequence data) or clusters above 10^20 operations/second, and directed NIST to write red-teaming guidance and the Department of Energy to build model-evaluation testbeds for nuclear, bio, chemical and cyber threats. The foundational US federal AI action, and the one later reversals would be measured against.

Microsoft pledges to indemnify Copilot customers against copyright suits

Microsoft announced its Copilot Copyright Commitment: if a third party sues a commercial customer for copyright infringement over the use of Microsoft's Copilots or their output, Microsoft will defend the customer and pay adverse judgments or settlements — provided the customer used the built-in guardrails and did not try to generate infringing material. In November 2023 it expanded the pledge (as the Customer Copyright Commitment) to Azure OpenAI Service outputs. A private-ordering response to legal uncertainty, not law.

China's Interim Measures for Generative AI Services take effect

China's Interim Measures for the Management of Generative AI Services took effect (promulgated 10 July 2023 by the Cyberspace Administration of China and six other ministries) — among the world's first binding national rules aimed specifically at generative AI. They require providers of public services to use lawful training data, uphold "Core Socialist Values" and bar content undermining state power, label AI-generated images and video, and — for services with "public opinion properties or the capacity for social mobilization" — pass security assessments and file their algorithms.

New York City begins enforcing the first AI hiring-bias audit law

New York City's Department of Consumer and Worker Protection began enforcing Local Law 144, barring employers from using an automated employment decision tool unless it has passed an independent bias audit within the prior year, the audit results are posted publicly, and candidates are notified. It was the first US law to put an enforced compliance obligation on algorithmic hiring tools.

FTC warns that misuse of biometric and facial-recognition tech violates existing law

The Federal Trade Commission issued a policy statement warning that misuse of biometric information — including facial recognition — may violate the FTC Act, and that false or unsubstantiated claims about the accuracy of biometric technologies are actionable. It was the "announced" precursor to the agency's first major AI enforcement action seven months later.

Getty Images sues Stability AI over 12 million photographs

Getty Images (US) filed a copyright and trademark complaint against Stability AI in the U.S. District Court for the District of Delaware (No. 1:23-cv-00135), alleging Stability copied more than 12 million Getty photographs — with captions and metadata — to train Stable Diffusion, and that the model reproduces distorted Getty watermarks. Claims were brought under the Copyright Act, the Lanham Act and Delaware unfair-competition law, with copyright-management-information removal alleged and a jury demanded.

NIST releases the AI Risk Management Framework 1.0

The National Institute of Standards and Technology published the AI Risk Management Framework 1.0 (NIST AI 100-1), developed through a consensus-driven public process. The framework is explicitly voluntary and non-sector-specific — guidance rather than binding rule — and later became the reference NIST was directed to build on under Executive Order 14110.

Artists file the first class action against AI image generators

Sarah Andersen and other visual artists filed a class-action copyright suit against Stability AI, Midjourney and DeviantArt in the U.S. District Court for the Northern District of California, alleging their works were used without permission to train image-generation models. It was among the first US cases to test whether training generative AI on copyrighted works is infringement.