Thelonious ICYMI — Edition 14 — 9 July 2026

Thelonious ICYMI — Edition 14 — 9 July 2026

Thelonious ICYMI — Edition 14 — 13 July 2026

Welcome to the 14th edition of ICYMI — your weekly briefing on the developments shaping the AI legal and regulatory landscape, curated from Thelonious.

Here’s a snapshot of what’s inside this week:

  • British Columbia’s Stated Intention to Sue OpenAI — The Province of British Columbia has indicated that it intends to bring proceedings against OpenAI, alleging that the company was aware of threats made on its ChatGPT platform by the perpetrator of the mass shooting at Tumbler Ridge Secondary School, in which eight people were killed and 27 wounded, and failed to notify law enforcement. The Province contends that this inaction represented a missed opportunity to prevent the attack. No proceedings have yet been filed and the allegations are untested. The legal theory is what distinguishes this from the AI litigation that has come before it. It is not a claim about what a model generated, nor about the data it was trained on. It is a claim about what a provider knew and did not pass on — a duty-to-warn argument, of the kind more familiar from product safety and professional negligence than from technology litigation. If that theory is permitted to proceed, the operative question for any organisation running a user-facing system stops being whether its outputs are safe and becomes what its moderation and escalation processes are obliged to surface, to whom, and how quickly.
  • EVOX v. Stability AI — EVOX Productions alleges that the defendants used its copyrighted professional automotive photography as training data without permission, infringing its copyrights and removing copyright management information in the process. Note the second limb of that claim. Copyright management information — the embedded credit, ownership and licensing metadata attached to a professional image — has its own statutory protection, separate from the infringement claim it sits beside. That separation is the point. A CMI removal claim does not require the court to resolve whether training on the work was fair use; it asks a narrower and far more concrete question about whether identifying metadata was stripped. This is now the third significant matter in recent weeks to plead it. Claims that sidestep the fair use battleground are becoming the more durable route, and any organisation that ingests third-party media at scale should be asking what its pipeline does to the metadata attached to it.
  • Streamz and Others — The matter turns on a referral to the Court of Justice of the European Union, asking whether a Belgian copyright provision granting rights to press publishers, authors and performers is compatible with wider EU law, the freedom to provide services and the freedom to conduct a business. Most of the argument about creator remuneration has been conducted as a contest between rightsholders and technology companies. This is a different axis entirely. Here a national law written to protect creators is being tested against the internal market freedoms that underpin the Union — and the freedom to conduct a business is being deployed against a remuneration right rather than in defence of one. For anyone advising on licensing frameworks across member states, the outcome matters well beyond Belgium. It goes to how much room a member state has to legislate protection for its own creative sector at all.
  • The Mills Review — Led by Sheldon Mills of the Financial Conduct Authority, the Review examines how AI will reshape retail financial services in the United Kingdom by 2030 and beyond, identifying four principal shifts: the transformation of firm operations, the evolution of consumer journeys, the reshaping of competition and market power, and the amplification of fraud and cyber risk. Sector regulators are becoming AI regulators without waiting to be given AI powers. The FCA does not need new legislation to act here — conduct rules, operational resilience requirements and the consumer duty already reach most of what the Review describes. The inclusion of competition and market power in the four shifts is the line to mark. That is a regulator signalling concern not about what AI does to consumers but about what dependence on a small number of model providers does to the structure of a regulated market.
  • Cyber Shield — The UK’s National Cyber Security Centre and the Department for Science, Innovation and Technology have launched Cyber Shield, a blueprint for a national-scale sovereign cyber defence capability using agentic AI to automate vulnerability discovery and real-time threat response, with collaboration sought from academia, industry and critical infrastructure partners. Set this beside the regulatory activity elsewhere in this edition and the position becomes an interesting one. The state is simultaneously writing the rules for autonomous systems and deploying them at national scale against a live adversary. Agentic AI operating at machine speed on critical infrastructure raises precisely the accountability questions the regulatory frameworks are still working through — who authorised the action, on what basis, and who answers for it when the system is wrong. Governments tend to arrive at workable answers faster when they are the operator.
Home Who Are We Meet The Team Why Choose Us Consulting Thought Leadership & Strategic Partnership Tech-Enabled Intelligence IP Policy & Protection Thelonious Thelonious Research Regulatory Landscape The Snapshot ICYMI ARIAM ↗ Insights
Book a Demo → Client Login Contact Us