The Tech Counsel - June 2026
Welcome to the June edition of The Tech Counsel — our monthly overview of key legal and regulatory developments across AI, privacy and the broader digital landscape. This edition is packed with practical updates from the EU AI Act and new privacy enforcement trends to digital sovereignty, cybersecurity and platform regulation.
Artificial Intelligence
EU Commission publishes draft guidelines on high-risk AI classification
On 19 May 2026, the European Commission published draft guidelines on classifying high-risk AI systems under Article 6 of the EU AI Act, with stakeholder consultation running until 23 June 2026.
There are two routes to high-risk classification. Under Article 6(1) and Annex I, an AI system qualifies as high-risk when it functions as a safety component of a regulated product covered by EU harmonisation legislation. Under Article 6(2) and Annex III, classification follows from the system’s intended purpose within eight designated high-risk use-case areas, including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice.
The guidelines establish that where a provider presents a system as broadly applicable without consistently excluding high-risk uses, the intended purpose encompasses high-risk uses that are feasible and reasonably foreseeable — boilerplate exclusions in terms of service are insufficient. Four exemption conditions under Article 6(3) permit an otherwise in-scope system to avoid high-risk classification (narrow procedural task; improving a previously completed human activity; detecting decision-making patterns or deviations; and genuinely preparatory tasks), but profiling always disqualifies a system, and reliance must be documented before the system is placed on the market.
Colorado’s new AI bill
On 12 May 2026, Colorado’s legislature passed Senate Bill SB26-189, replacing the 2024 Colorado AI Act. Signed on 14 May and taking effect on 1 January 2027, the bill moves away from the risk-based approach of the EU AI Act, removing the duty of care to prevent algorithmic discrimination, mandatory risk management programmes, and impact assessment requirements. Instead it adopts a narrower framework focused on transparency, disclosure, and limited consumer rights for automated decision-making technologies in “consequential decisions.”
AI hallucinations under judicial scrutiny
The English High Court’s decision in Cork v Smith (22 May 2026) has become a reference point for professional liability and AI use in legal practice. A junior associate had used the firm’s internal AI tool to research a claim, and the AI had fabricated a non-existent rule of insolvency legislation. The court found that the failures extended to the supervising senior associate and partner, who reviewed and approved the letter without checking the purported rule.
Cork v Smith is not isolated — earlier decisions such as Ayinde v London Borough of Haringey and, in the US, Mata v Avianca and Johnson v Dunn point to a developing line of case-law. Key takeaways: AI output is a draft, not a source; supervision obligations are heightened, not diminished, by AI; and the cover-up is worse than the error.
AI Act obligation toolkit
As August 2026 approaches, the AI Act becomes generally applicable. While high-risk classification deadlines were postponed by the AI Omnibus, the transparency and general-purpose AI (GPAI) obligations are proceeding on schedule. Prohibitions on certain unacceptable-risk AI systems (subliminal manipulation, social scoring, and most real-time remote biometric identification in public spaces) are already in force, with transparency and GPAI documentation and incident-reporting obligations entering into force on 2 August 2026.
Privacy
CCPA 2026: amended regulations now in force
Final Regulations under the CCPA (as amended by the CPRA) took effect on 1 January 2026, significantly expanding compliance obligations. Article 9 introduces mandatory annual cybersecurity audits for businesses meeting specified thresholds; Article 10 requires risk assessments for high-risk processing activities such as selling or sharing personal information, processing sensitive personal information, and using ADMT for significant decisions; and Article 11 establishes a dedicated framework for automated decision-making technology, including advance notice, opt-out rights, and, in certain circumstances, consent.
Tracking pixels in emails: Italy’s new GDPR guidelines
On 17 April 2026, Italy’s Garante issued dedicated guidelines on tracking pixels in email communications. A tracking pixel that fires when a recipient opens an email constitutes both storage on, and access to, information in the user’s terminal device — the same classification that applies to cookies — triggering a default prohibition subject to prior consent or narrow exemptions. Unlike the CNIL, the Garante permits a single unified consent covering both promotional emails and embedded pixels, provided the request is neutral, but requires a standardised footer link to a granular preference area.
Other digital topics
European technological sovereignty package and CADA
On 3 June 2026 the Commission presented its European technological sovereignty package, aimed at strengthening the EU’s capacity in semiconductors, AI, cloud and open source. It comprises the Chips Act 2.0, the Cloud and AI Development Act (CADA), the Open Source Strategy, and a Roadmap for Digitalisation and AI in the Energy Sector. CADA, the most significant proposal, focuses on data residency and portability for sensitive workloads, transparency in AI training infrastructure, and interoperability obligations that reduce vendor lock-in.
NIS2 Cooperation Group adopts common incident reporting templates
On 26 May 2026, the NIS Cooperation Group adopted common templates for cybersecurity incident reporting, addressing the divergence of national reporting formats. The templates cover all reporting phases under Article 23 NIS2 — the early warning (24 hours), the incident notification (72 hours), the intermediate report, and the final report (30 days) — and are expected to be made mandatory through an implementing act.
Commission fines Temu EUR 200 million for DSA breach
On 28 May 2026, the Commission issued a EUR 200 million fine to Temu for breaching the DSA — the largest penalty under the regulation to date — finding that Temu failed to properly assess the systemic risks of illegal and unsafe products on its platform, relying on generic sector-wide information rather than evidence from its own service.
General Court annuls Meta Marketplace gatekeeper designation
On 4 June 2026, the General Court annulled the Commission’s decision designating Meta as a gatekeeper under the DMA in respect of Facebook Marketplace — the first successful annulment of a DMA gatekeeper designation — finding that the Commission had not established that Marketplace constitutes an “important gateway.” Meta remains designated as a gatekeeper for Facebook, Instagram, WhatsApp, Messenger and Meta Ads.