Thelonious ICYMI — Edition 23 — 10 September 2026

Thelonious ICYMI — Edition 23— 10 September 2026

Age assurance regulation arrived from four directions this week, and three of them on the same day.

On 8 September the United Kingdom announced it would legislate at the level of the handset, Australia published a draft duty of care aimed at anyone building for under-18s, and Ireland opened the first enforcement investigation in the history of its Online Safety Code. Florida sued Netflix the following morning. The common thread is not child safety in the abstract. It is the collapse of self-declaration as an acceptable answer to the question of how old a user is, and the arrival of a documented obligation to know.

Where the previous edition tracked the statutes doing the enforcing, this one tracks a single question moving from policy paper to enforcement file. The two remaining developments concern who owns the material these systems were trained on, and whether a capability class can be prohibited by statute at all.

  • The United Kingdom Will Legislate for Device-Level Protections for Children

On 8 September 2026 Lisa Nandy, Secretary of State for Digital, Culture, Media and Sport, set out the government’s intention to bring forward primary legislation requiring device-level and app-level protections for children. The measures would oblige device makers, Apple and Google among them, to prevent children taking, sharing or viewing nude imagery on phones and tablets, with protection operating at operating-system level rather than being left to individual applications. Parallel obligations would apply to apps used by children. The statement follows a three-month deadline issued in June for voluntary action, which the government has concluded was not met. Apple has said it shares the commitment and has shared plans with UK officials to strengthen its Communication Safety feature, introduced in 2021 and since extended to third-party apps. No bill has yet been laid.

The regulatory target has moved down the stack, and that is the material development. The Online Safety Act 2023 regulates services. This proposal regulates the handset. It concentrates the compliance burden on two companies rather than thousands, and it makes the operating system a regulated safety layer for the first time. For anyone advising a platform, the practical question changes from what your service must verify to what the device has already verified and whether you are entitled to rely on it. That is a different due diligence exercise, and it is the kind of structural shift regulatory landscape tracking exists to catch before a client asks about it.

  • Australia Publishes a Draft Digital Duty of Care and an Algorithm Opt-Out

Also on 8 September 2026, the Australian government released draft legislation for targeted consultation establishing a Digital Duty of Care, with introduction to Parliament expected later in 2026. The duty would require digital services, including social media platforms, online games, apps, AI chatbots and messaging services, to identify and mitigate risks of harm to users under 18, to maintain minimum safety standards, and to document the measures taken and their continued effectiveness. Harmful design features are named alongside harmful content, with addictive design expressly in scope. The accompanying My Feed, My Way measure would require social media platforms to notify users aged 16 and over and offer a genuine choice between an algorithmically recommended default feed and a feed limited to the accounts a user has chosen to follow. The eSafety Commissioner would oversee compliance and gain removal powers covering nudity-altering applications and websites. Non-compliance with the duty could attract penalties of up to A$109.2 million (about £53 million).

Australia has moved the argument from age verification to platform accountability, which is a larger shift than it first appears. A duty of care carrying a documentation requirement is an evidentiary regime: the obligation is not only to be safe but to be able to demonstrate the reasoning. That is the same structure as a systemic risk assessment under the Digital Services Act, and a service already producing one for Brussels will find the Australian filing familiar rather than novel. The algorithm opt-out is the genuinely new piece, and the first statutory attempt anywhere to make personalisation a user election rather than a default. Thelonious Research will follow the draft through consultation and into the Parliament.

  • Ireland Opens Its First Online Safety Code Investigation, Into X

On 8 September 2026 Coimisiún na Meán commenced a formal investigation into X, the first investigation under Ireland’s Online Safety Code. Five further investigations into Irish-established platforms are already running under the Digital Services Act. The investigation concerns section 12(10) of the Code, covering age assurance, and sections 14(1), 14(2), 14(4) and 14(5), covering parental controls. The regulator has stated that age assurance based solely on self-declaration is not considered effective. On parental controls, John Evans said that platforms allowing users under the age of 16 must have controls which are under the control of parents and guardians, which are effective and easily located, and to which users’ attention is drawn at account creation. The Code provides for an administrative financial sanction of up to €20 million or 10% of relevant annual turnover, whichever is greater.

Self-declaration has been the industry default for two decades, and a regulator has now said in an enforcement context that it does not qualify. This is the first test of the Code, so the outcome will set the reference point for every video-sharing platform established in Ireland, which is most of them. The parental control provisions are the underrated part of the file. They are prescriptive about placement and prominence rather than mere existence, which makes them a design specification rather than a policy commitment, and design specifications are the kind of obligation that fails an audit quietly.

  • Florida v. Netflix

On 9 September 2026 Florida Attorney General James Uthmeier filed a 66-page complaint against Netflix, alleging that the company collected, logged and commercialised behavioural data from subscribers, including children, while marketing itself as an alternative to advertising-funded technology companies. The complaint alleges a bait and switch: that Netflix promised paying subscribers it would not collect their data for advertising, then built the advertising business launched in 2022 on precisely that data. It further alleges the deployment of dark patterns, autoplay among them, described as undermining parental screen time controls, and the sale of sensitive personal data to third-party advertising partners without consent. The claims run under the Florida Deceptive and Unfair Trade Practices Act and the Florida Digital Bill of Rights. The State seeks an order requiring Netflix to erase data collected from Florida residents and to cease the design practices complained of. Texas brought a comparable action in May 2026.

The theory is not that the data collection was unlawful but that the promise was, and that distinction is where the exposure sits. A subscription positioned as the privacy-respecting alternative becomes, on this argument, a representation capable of founding a deceptive practices claim once the product changes underneath it. The liability therefore attaches to marketing copy as much as to the privacy notice, and it reaches any subscription business that has since added an advertising tier. Anyone who has quietly changed the bargain while leaving the original positioning in place should read the complaint rather than the coverage of it.

  • The Seattle Times and Newsday v. OpenAI and Microsoft

On 5 September 2026 The Seattle Times and Newsday filed suit against OpenAI and Microsoft in the U.S. District Court for the Southern District of New York, alleging that their journalism was copied at scale to train and operate generative AI systems without permission or payment. The complaint alleges that articles were obtained by automated scraping, including by circumventing paywalls, and incorporated into training datasets; that the resulting models reproduce or closely paraphrase the plaintiffs’ reporting; and that copyright-management information was removed or altered. The plaintiffs allege the defendants’ products compete with them for readers, subscriptions, advertising and licensing revenue, and that the use is not protected by fair use. Federal copyright and state-law claims are pleaded, with damages and injunctive relief sought. The action follows The New York Times’s December 2023 suit against the same defendants, and both defendants have previously funded journalism projects at The Seattle Times.

Regional titles are now in, and that changes the shape of the licensing market rather than the law. The legal questions are the ones already before the court in the New York Times litigation, and this filing will not resolve them any faster. What is new is the class of plaintiff: publishers without the resources to litigate for four years, whose realistic outcome is a licence rather than a judgment. Each additional filing raises the cost of settling them one at a time and makes a collective licensing mechanism likelier than a run of bilateral deals. We set out the underlying argument in We Are All Thieves, and the pleadings have continued to move towards it.

  • The Ban Artificial Superintelligence Act

On 3 September 2026 Senator Bernie Sanders and Representative Greg Casar announced the Ban Artificial Superintelligence Act, which would prohibit the development and deployment of artificial superintelligence, defined to include systems that surpass human intelligence, that have the capacity to overthrow human governments, or that can subvert shutdown commands. The bill would impose a temporary pause on advanced AI development until a new cabinet-level federal agency, advised by an independent expert board, establishes safety rules and a model review process. The agency would monitor frontier systems for dangerous capabilities and supervise both their removal and the destruction of any artificial superintelligence. Penalties would extend to dissolution for corporate entities and up to 20 years’ imprisonment for individuals, a term the sponsors compare to that for unlawful nuclear weapons development. Sanders said the future of humanity “cannot be left in the hands of a handful of Big Tech oligarchs”.

The bill will not pass in this form, and its significance is not legislative. It marks where the outer boundary of the debate now sits, because a criminal prohibition on a capability class has entered the record and will be cited in every subsequent negotiation as the alternative to a lighter regime. It also exposes the drafting problem that every capability-based rule runs into. The definition turns on properties that no one has agreed how to measure, and a statutory ban is only ever as workable as its threshold test. Expect that objection to be the substance of the opposition rather than any argument about whether superintelligence would be desirable.


Six developments, five statutes, and only one of them written for artificial intelligence. If you would like to see how this reads for your own jurisdictions and practice areas, request a Snapshot and we will send you a one page exposure brief.

Download Edition 23 as a PDF

Home Who Are We Meet The Team Why Choose Us Consulting Thought Leadership & Strategic Partnership Tech-Enabled Intelligence IP Policy & Protection Thelonious Thelonious Research Regulatory Landscape The Snapshot ICYMI ARIAM ↗ Insights
Book a Demo → Client Login Contact Us