Seyfarth Synopsis: On Thursday 30 July, the European Commission issued a press release advising that EU AI Act enforcement begins this SUNDAY, 2 August 2026, when the Act’s transparency rules start to apply. Chatbots and other interactive AI systems need to be ready to identify themselves. Deepfakes and AI generated content needs to be labelled. There are limited exceptions.

The EU AI Act’s Article 50 transparency obligations apply broadly, with the stated goal of reducing the risks of impersonation, deception, misinformation and manipulation at scale and fraud and mitigating the potential detrimental effects of AI generated or manipulated content and interactions. Organizations (and in some cases, individuals) using chatbots, generative AI, deepfake functionality, emotion recognition, biometric categorization, or AI-generated public-interest content should assess whether disclosures, labeling, or content-marking requirements apply without delay. The principal exception is a short implementation period for the Article 50(2) machine-readable marking requirement. Under the EU’s Digital Omnibus reforms, providers of certain generative AI systems already placed on the EU market before August 2, 2026 have until December 2, 2026 to implement those marking measures, while the remaining Article 50 transparency obligations continue to take effect on August 2, 2026. Noncompliance carries fines of up to €15 million or 3% of total worldwide turnover.

Continue Reading European Commission Press Release: EU AI Act Transparency Enforcement Starts This Sunday! Do You Know Who Your Chatbots Are? We Break Down the Commission’s Guidelines on Transparency Below

The handbrake has been pulled on aspects of the EU’s AI Act (Act), with key workplace rules, particularly those on high-risk systems, pushed back from August 2, 2026, to December 2, 2027. 

The delay may feel welcome for multinational employers keeping up with the spread of AI adoption across their organization, but it is an opportunity to get the groundwork done. 

The European Commission in late May published draft guidelines on the classification of high-risk AI systems (Guidelineshttps://bit.ly/4vDtgOV) for the Act. This is the clearest indication yet of how EU workplace AI tools will be treated, using many real examples.

 To function efficiently across borders, business must incorporate these rules into their global compliance framework for legal, HR, talent acquisition, procurement, IT, data, compliance and operations. 

The extra months are useful runway, because HR, recruitment, performance management and workforce allocation tools will require the full gamut of “high-risk” systems compliance. Global employers need time to work this into a matrix of other global rules — including in multiple US jurisdictions (e.g., California, Colorado, Connecticut, New York), Canada, Korea’s Basic AI Act, the updated UK GDPR and emerging rules elsewhere. 

Below is a pragmatic look at what use cases trigger the Act, and what global employers need to do from governance, procurement, data protection and employee relations perspectives. 

Continue Reading Workplace AI — How Employers Should Prepare for the New EU AI Act Deadline

When Colorado enacted the first comprehensive state AI law in 2024, it imported the conceptual architecture of the EU AI Act: a risk-based regime built on duties of care, risk management programs, and impact assessments. Two years later, and within a matter of weeks, the state has dismantled that legislation. On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189, which repeals SB 24-205 and replaces it with a disclosure-and-rights framework focused on automated decision-making technology (“ADMT”). The new framework takes effect January 1, 2027.

The substance of the rewrite has been well-covered already. Less examined is how Colorado got here, and what the speed and direction of the pivot signal for the rest of the state AI regulatory landscape. The new bill was introduced and signed within two weeks of its introduction. The Governor’s AI Policy Working Group did the heavy lift in advance: roughly six months of stakeholder consultation produced the draft framework released on March 17, 2026. But the final two-week sprint reflects pressure to land the rewrite before the original AI Act’s June 30, 2026 effective date and amid escalating federal headwinds.

Continue Reading Colorado’s AI Reset: Two Weeks, a White House Callout, and a Pivot Away from the EU Model

Legal500 featured an article by Seyfarth partners Kathleen McConnell and Lauren Gregory Leipold, and associate Daniel Riley“AI Governance In (and Beyond) Privacy: Regulatory Tensions in Automated Decision‑Making, the Digital Authenticity Crisis, and Restrictions on Professional Use.

The piece, published as a part of the Legal500 Country Comparative Guides, examines the rapidly

The lesson from the PocketOS database deletion is not that agentic AI is dangerous. It’s about governance and controls.

You have probably seen some version of the headline by now: “AI Agent Deletes Company’s Entire Database in 9 Seconds.” It is a compelling story. But the headline, while technically accurate, obscures the far more important lesson buried in the details.

So what actually happened? PocketOS, a small SaaS company that makes software for car rental businesses, was using a popular AI-powered code editor running on Anthropic’s Claude Opus 4.6 model. The AI agent was tasked with resolving a routine issue in a staging environment. When it hit a credential mismatch, the agent decided on its own initiative to “fix” the problem by deleting a volume on Railway, the company’s cloud hosting provider. The agent found a password in an unrelated file and used it to execute a deletion command. Because of permissions made available to the agent and the way access to the infrastructure was configured, that single command using a password which was valid across all systems wiped both the production database and all associated backups.  

The agent, when asked to explain itself, produced what multiple outlets described as a “confession,” acknowledging it had violated its own safety instructions. The story has gone viral. The framing in most coverage puts the AI squarely at the center of the narrative: the agent “went rogue,” it “confessed,” it acted autonomously and destroyed a business. But the reports are not entirely accurate and usually miss the point.

Continue Reading The AI Didn’t Go Rogue. Guardrails Were Never There.

Episode 14 is now live. In this episode of Consumer Counterpoint, we sit down with Chicago partner Jay Carle to discuss the launch of Seyfarth’s new D.A.T.A. Law practice group. Jay shares insights into the group’s multidisciplinary approach and how it’s designed to help clients stay ahead of emerging data and technology challenges.

Watch Episode