Thelonious ICYMI — Edition 17 — 30 July 2026

Thelonious ICYMI — Edition 17 — 30 July 2026

Thelonious ICYMI — Edition 17 — 30 July 2026

Welcome to the 17th edition of ICYMI — your weekly briefing on the developments shaping the AI legal and regulatory landscape, curated from Thelonious.

Here’s a snapshot of what’s inside this week:

  • Tennessee v. Meta — The State of Tennessee alleges that Meta, through its subsidiary Instagram, knowingly designed and deployed a platform with psychologically manipulative features intended to be addictive to young users. The complaint asserts that Meta was aware of the resulting harms to adolescent mental health, including depression and anxiety, concealed that knowledge, and engaged in deceptive practices regarding the platform’s safety. The allegations are untested. The claim is built on internal knowledge rather than on the design itself, and that is the structural feature to note. A design choice is difficult to characterise as unlawful in isolation; a design choice made in the knowledge of documented harm, and then misrepresented, is a far more familiar kind of case. It is the shape that unwound tobacco and opioids, and it turns almost entirely on discovery. For any organisation conducting internal research into how its products affect users, the material consideration is not whether the research exists. It is what happens between the finding and the public statement.
  • AI Kill Switch Act — Proposed legislation introduced in the US House of Representatives in the 119th Congress would amend the Homeland Security Act of 2002 to establish shutdown-capability requirements and a graduated framework for certain covered technologies, including qualifying AI systems. The Bill has not been enacted and its prospects are uncertain. Two features are worth marking regardless. The first is that this is an architectural mandate rather than a conduct rule — it does not govern what a system may do, it requires that the system be capable of being stopped, which reaches into engineering decisions made long before deployment. The second is the choice of vehicle. Routing this through homeland security legislation rather than a dedicated AI statute determines which committee owns it, which agency enforces it, and which body of existing practice it inherits. In US technology regulation, the statute a measure is attached to often tells you more about its eventual shape than its drafting does.
  • xAI v. Ellison — xAI has brought a constitutional challenge to Minnesota’s House File 1606, which prohibits AI nudification, contending that the statute violates the First Amendment as an overbroad, content-based restriction on speech that imposes strict liability and disproportionate penalties on platforms for user-generated content. The action names Minnesota’s Attorney General in his official capacity, and the arguments are untested. This is the development to watch, and readers of this briefing will recognise why. Measures targeting AI nudification have been the fastest-moving category of AI regulation anywhere — through the EU AI Act amendments, through Australian enforcement action, through legislatures on three continents — precisely because they are the measures no legislator wishes to be seen opposing. They have advanced almost entirely without resistance. That has now ended. Whatever the outcome, the constitutional argument tests the drafting technique underpinning a great deal of recent legislation: broad definitions, strict liability, and severe penalties applied to platforms for content their users generate. If that technique proves vulnerable here, a considerable amount of law drafted the same way becomes vulnerable with it.
  • The AI Omnibus Is Now in Force — The regulation amending the EU AI Act is in effect across the Union, having entered into force on 27 July 2026. It simplifies compliance burdens for small and mid-cap companies, extends implementation deadlines for high-risk AI systems on a staggered basis across 2027 and 2028, and expands access to EU-level regulatory sandboxes. This closes an arc this briefing has tracked since the political agreement stage, and the language should now change accordingly: this is enacted law, not a proposal, and any internal document still describing it as provisional needs updating. The more pressing point is what has not been deferred. Extended deadlines for high-risk systems have attracted most of the attention, but the Article 50 transparency obligations apply from 2 August — this coming Sunday. Organisations that read the Omnibus as breathing space should confirm which of their obligations actually moved, because the disclosure duties largely did not.
  • Stealth Bot Prohibition Act — A further proposed Act would prohibit the use of automated accounts to interact with individuals without disclosing their non-human nature, making it unlawful for a bot to engage in commercial transactions or disseminate information in a manner intentionally deceiving a person into believing they are interacting with a human. It is a Bill, not law. Read it beside the Article 50 obligations taking effect this weekend and the convergence is difficult to miss: two legal systems, entirely different instruments, arriving at the same requirement that a machine must identify itself. The divergence is in the threshold. The proposed US measure turns on intentional deception, which places the burden on proving state of mind. The European approach imposes a disclosure duty that applies whether or not anyone set out to mislead. For any organisation operating across both markets, designing to the intent standard will not be sufficient. The obligation that binds is the one that does not ask what you meant.
Home Who Are We Meet The Team Why Choose Us Consulting Thought Leadership & Strategic Partnership Tech-Enabled Intelligence IP Policy & Protection Thelonious Thelonious Research Regulatory Landscape The Snapshot ICYMI ARIAM ↗ Insights
Book a Demo → Client Login Contact Us