Thelonious ICYMI — Edition 16 — 23 July 2026
Thelonious ICYMI — Edition 16 — 23 July 2026
Welcome to the 16th edition of ICYMI — your weekly briefing on the developments shaping the AI legal and regulatory landscape, curated from Thelonious.
Here’s a snapshot of what’s inside this week:
- Sony v. Udio — Sony Music alleges that Udio unlawfully copied over 30,000 of its copyrighted sound recordings to train its commercial generative AI music service, and that Udio obtained those recordings by stream ripping them from YouTube, circumventing technological protection measures contrary to the DMCA. Sony contends the use is not fair use, and seeks damages and an injunction. The allegations are untested. Read the second limb carefully, because it is doing distinct work. The circumvention claim does not depend on the training use being unlawful. It concerns the act of defeating a technical protection to obtain the material in the first place — a separate statutory wrong with its own remedies, which stands or falls independently of the fair use analysis everyone is waiting on. Acquisition method is becoming the pressure point. How the corpus was obtained is turning out to be a far more answerable question than what the model then did with it.
- Google v. SerpApi — Google alleges that SerpApi unlawfully scrapes Google Search results by circumventing its SearchGuard anti-scraping technology, contending that the conduct breaches the DMCA, imposes significant costs, and undermines its licensed content agreements. The allegations are untested. This one deserves to be read alongside the previous edition of this briefing, in which Google appeared as a defendant to a class claim alleging that it took content at scale without permission. Here it appears as the plaintiff, invoking the DMCA’s anti-circumvention provisions against a party accused of taking content at scale without permission. The positions are not formally inconsistent — scraping a proprietary index protected by a technical measure is not the same act as ingesting published books — but the doctrinal argument matters more than the optics. Whatever theory Google advances this year about circumvention as a standalone wrong becomes available to every rightsholder suing a model developer next year. Precedent does not stay on the side that created it.
- Sovereign AI invests in CuspAI — Sovereign AI, a UK government-backed entity, has announced its participation in the $450 million Series B financing of Cambridge-based CuspAI, which is developing a platform to accelerate the discovery and design of new materials — in effect a search engine for materials with specified properties. Track the position the state is taking here against the ones it has taken in recent weeks elsewhere: purchaser at scale, operator of autonomous systems on critical infrastructure, and now equity investor in a frontier developer. Each is defensible in isolation. Collectively they place government on every side of the technology it also regulates. That is not an accusation of bad faith; it is a structural observation with practical consequences. Anyone modelling the pace and shape of AI regulation should factor in that the regulator increasingly holds a position in the outcome.
- Guidelines on Transparency of AI-Generated Content — The Commission has published guidelines clarifying the transparency obligations owed by providers and deployers under Article 50 of the EU AI Act, defining key concepts including deepfakes and interactive AI, setting out the scope of the rules, and explaining how compliance may be demonstrated. They are intended to provide legal certainty ahead of the Article’s application date. Of everything in this edition, this is the item with a date attached to it, and the date is close. Guidelines are not binding, but they are the clearest available statement of how the body responsible for enforcement reads the obligation — which makes them the most useful document in the room for anyone still deciding what their disclosure practice needs to look like. If your organisation deploys a system that interacts with people, generates synthetic media, or produces content that a reader might reasonably take to be human-authored, the scope section is where to start.
- Commission Fines AliExpress €550 Million — The European Commission has fined AliExpress €550 million for breaching the Digital Services Act, concluding a 28-month investigation. The Commission found that the platform failed to diligently assess and mitigate systemic risks relating to illegal products, that its detection systems were ineffective, that it had insufficient content moderation staff, and that harmful products remained available for weeks after being identified. Two findings here should give pause well beyond the platforms directly in scope. The first is that the quality of a systemic risk assessment is now something a regulator will examine and penalise — not whether one was produced, but whether it was done diligently. The second is that inadequate staffing was itself part of the finding. Under-resourcing a compliance function has moved from a commercial decision to an enforceable failure. The AI Act imports a comparable architecture of risk assessment and documented mitigation, and this is a fairly clear preview of how the Commission intends to examine it.