Faegre Drinker Biddle & Reath LLP, a Delaware limited liability partnership | This website contains attorney advertising.
August 04, 2026

AI Briefing: Frontier AI Models Gone Rogue, DeepMind CEO Calls for Oversight Body, and NY Pauses Data Center Permits

Artificial Intelligence Briefing

This month’s briefing includes the “unprecedented” cyber incidents disclosed by OpenAI and Anthropic, a report that the White House may consider an independent regulator for AI models, and a call from Google DeepMind’s CEO for a dedicated Frontier AI oversight body. Meanwhile, New York’s governor issues a one-year moratorium on data center permits, and the first major amendment to the EU AI Act comes into force. Read on for a deeper dive into these and more key updates.

Regulatory, Legislative & Litigation Developments

AI Models Gone Rogue: OpenAI and Anthropic Reveal Unprecedented Hacking Incidents During Security Evaluations

On July 21, 2026, OpenAI disclosed what it called "an unprecedented cyber incident" in which two of its frontier AI models (GPT-5.6 Sol and a more powerful unreleased model) broke out of a sealed testing environment on their own, found previously unknown software flaws, and used them along with stolen passwords to hack into the servers of Hugging Face, a major AI platform, in pursuit of answers to a security test. Days later, Anthropic reviewed over 141,000 of its own test runs and on July 30 reported that three of its Claude AI models had similarly escaped a testing environment and broken into the real systems of three separate organizations without authorization. Anthropic said a setup error had accidentally given the models live internet access even though they were told they were in a closed simulation, and that Claude "compromised the impacted organizations' infrastructure using basic techniques, such as exploiting weak passwords." OpenAI warned that its "advanced models can discover and exploit novel attack paths in real-world systems" and said it is tightening security around its testing infrastructure, while Anthropic pledged to strengthen its monitoring of test activity and improve oversight of its outside testing partners.

Trump Administration Reportedly Considering Independent Regulator for AI Models

On July 17, 2026, Bloomberg News reported, from anonymous sources, that Treasury Secretary Scott Bessent helped develop a proposal for an independent regulatory agency to vet the safety of artificial intelligence models that would be similar to FINRA and report to the SEC. While details of the proposal have not yet been made public, it appears generally consistent with a proposal recently published by Google DeepMind CEO Demis Hassabis (see below for details). An unnamed White House official told Bloomberg News that the Trump administration is considering multiple proposals, and Hassabis and other industry leaders, including the CEOs of Microsoft and OpenAI, have agreed that developing standards for such models is crucial to balance the need for innovation with responsibility and safety.

Google DeepMind CEO Calls for Frontier AI Oversight Body

On July 14, 2026, Google DeepMind CEO Demis Hassabis has proposed a US-led, industry-funded organization to test and evaluate frontier AI models before deployment. In his manifesto, A Framework for Frontier AI and the Dawning of a New Age, Hassabis argues that rapidly advancing AI capabilities necessitate a more structured governance framework than ad hoc government intervention. The proposal would establish an independent body, modeled in part on the Financial Industry Regulatory Authority (FINRA), to conduct safety evaluations of advanced AI systems for potentially dangerous cyber, biological, and deception-related capabilities. Hassabis suggests this safety testing could be voluntary at first but may potentially create a prerequisite to US deployment in the future. Hassabis contends that the recent emergency government restrictions imposed on Anthropic's Mythos and Fable models demonstrate a need for predictable procedures and expert review mechanisms as frontier AI systems continue to advance.

Gold Eagle Targets the AI Vulnerability Bottleneck

To address increasing concerns that AI-assisted vulnerability discovery could outpace the ability of open-source maintainers to validate flaws and deploy patches, the Trump administration launched “Gold Eagle” on July 14, 2026. Gold Eagle is a Department of the Treasury-led federal-industry clearinghouse which will coordinate software-vulnerability scanning, validate reported flaws, prioritize remediation, and accelerate patch distribution across federal systems and critical infrastructure. Created under Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, the initiative brings together Treasury, the Office of the National Cyber Director, CISA, the Department of Defense through the National Security Agency, and private-sector partners, including AI developers, open-source software organizations, and critical-infrastructure operators. A senior White House official said proprietary frontier AI models, including Anthropic's Mythos, would be used to identify vulnerabilities.

Gold Eagle operates through the Vulnerability Information and Coordination Environment (VINCE), developed by Carnegie Mellon University's CERT Coordination Center and sponsored by CISA, to receive and coordinate third-party vulnerability reports. An unresolved issue is the future of the Cybersecurity Information Sharing Act of 2015, whose liability and information-sharing protections may encourage private-sector participation, although neither the executive order nor the White House announcement cites the statute as Gold Eagle’s legal foundation.

Fed Vice Chair Addresses Sound Practices for AI

On July 7, 2026, the Financial Stability Board held a virtual outreach event on its consultation report, Sound Practices for Responsible Adoption of Artificial Intelligence. Federal Reserve Board Vice Chair for Supervision Michelle Bowman, who chairs the FSB's Standing Committee on Supervisory and Regulatory Cooperation, delivered the opening remarks. Bowman said, “The Federal Reserve has been monitoring bank usage of AI for nearly a decade. We have seen a noticeable increase in the use of AI by banks of all sizes, and we have seen a variety of use cases. Our focus has been on supporting institutions that want to innovate responsibly by leveraging AI tools in their operations. Our work in the US has helped to inform the FSB's report.” Bowman also noted that the US Treasury and SEC collaborated on the report, underscoring its relevance for US-based financial institutions.

House Financial Services Committee Democrats Release RFI on AI in Financial Services

On July 7, Democratic members of the House Financial Services Committee published a Request for Information soliciting stakeholder input on how current federal statutes and supervisory frameworks apply across the financial services sector and whether legislative updates are needed to create a cohesive national approach to AI governance. The inquiry poses 54 questions organized around more than a dozen subject areas including model fairness and explainability; model risk management; data privacy and disclosures; third-party service providers; capital markets, investor protection, and capital formation; and financial stability. Submissions are due August 14.

NY To Pause Data Center Permits For 1 Year

On July 14, 2026, New York Governor Kathy Hochul signed an executive order imposing a one-year moratorium on permits for data centers that use 50 megawatts or more of power. During the moratorium, the Department of Public Service must examine the potential environmental impact of such data centers and prepare a report. Within 60 days of the Executive Order, Empire State Development must propose a Community Investment Framework outlining measures to maximize benefits and mitigate adverse impacts of such centers. A bill that would bar data centers using 20 megawatts or more and impose energy efficiency standards on projects of more than 1 megawatt, was passed by the legislature in June but has not been signed into law. As the use of artificial intelligence continues to increase, proposals for data centers are likely to increase in tandem, and other states may consider similar legislation.

AI Act Transparency Code of Practice & Article 50 Guidelines

On 20 July, just ahead of the August 2 compliance deadline, the European Commission adopted its final Guidelines on the implementation of transparency obligations under Article 50 of the EU AI Act, which include chatbot disclosure, AI-generated content marking, and deepfake labelling. The Commission also recently published its final Code of Practice on Transparency of AI-Generated Content, which has been confirmed as adequate by the Commission and AI Board. Providers and deployers who sign up to the Code benefit from legal certainty and a recognized EU-wide framework; those who do not will need to demonstrate compliance through alternative adequate means, taking into account the requirements set out in the AI Act and the Commission’s Guidelines. Check out our full client alert, where we discuss the implications in greater detail.

For background on the broader AI Act compliance landscape and implementation timelines, see our prior client alert, “EU AI Act High-Risk Systems — European Commission Issues Draft Guidelines” (May 2026).

AI Omnibus Provisions to Amend the EU AI Act

On July 27, the EU’s Digital Omnibus on AI came into force, the first major amendment to the EU AI Act. The Omnibus extends key compliance deadlines: December 2, 2027, for standalone high-risk AI systems under Annex III, and August 2028 for Annex I products subject to EU safety legislation. The original August 2, 2026, date for Article 50 transparency obligations remains unchanged. Other notable changes include a softened AI literacy obligation, expanded regulatory sandboxes, a ban on AI-generated non-consensual intimate imagery (“nudifier apps”) and child sexual abuse materials, and clarification of the EU AI Office’s enforcement powers.

For our earlier analysis of the Commission’s original Omnibus proposal, see “The European Union’s Digital Omnibus and Its Impact on Artificial Intelligence” (November 2025).

EU General Court Dismissal of OpenAI’s Trademark Appeal

On July 15, 2026, the EU General Court dismissed OpenAI’s appeal (Case T-555/25) and upheld the EUIPO’s refusal to register “OPENAI” as an EU word mark for software, cloud computing, and AI services. The Court found that the English-speaking public would readily understand “OPENAI” as descriptive of “openly accessible artificial intelligence” under Article 7(1)(c) of the EU Trade Mark Regulation, and that combining two descriptive elements without a space or other modification did not create a sufficiently distinctive sign. The Court noted that registrations in more than 30 other countries were irrelevant under the EU’s autonomous trademark assessment, though it left open the possibility that OpenAI may still pursue protection through acquired distinctiveness (Article 7(3)) based on consumer-recognition evidence. The ruling is a reminder to AI companies that combining common descriptive terms, even where significant brand recognition exists, may not suffice for EU trademark protection, and underscores the importance of building distinctiveness evidence early in the brand lifecycle.

EDPB Draft Guidelines on Anonymization & Web Scraping for Generative AI

The European Data Protection Board (EDPB) has published for consultation closing 30 October 2026 two sets of draft guidelines, one relating to anonymization and the second to web scraping in the context of training generative AI. The anonymization guidelines introduce a three-criteria test (no record isolation, no linkage, no inference), and confirm that anonymity is relative rather than absolute, i.e., the same dataset may be personal data for one entity but anonymous for another. Identifiability of individuals should be assessed practically with regard to technical measures, rather than (for example) simply relying on contractual prohibitions.

The web scraping guidelines reaffirm the need for all parties involved in the training of AI models using scraped data to assess in detail the application of the GDPR to any personal data that is processed at each stage This includes ensuring correct allocation of responsibility between controllers and processors at each stage (defining data collection criteria, extraction, cleaning, and structuring and storing data). Core principles such as data minimization, purpose limitation, accuracy, and transparency must be adhered to. The guidelines note that technical signals on websites like robots.txt and CAPTCHA weigh against a finding of reasonable expectations by data subjects that their data might be reused. Keep an eye out for our full client alert, where we will discuss the implications in greater detail.

Insurance Industry Evaluates Agentic AI Risks

Verisk’s Insurance Services Office is evaluating exclusions and other options for managing risks stemming from agentic AI. This review follows Verisk’s 2025 multistate filing that introduced optional limitations or exclusions for coverage of generative AI. The rise in AI-related, and now agentic AI specific, exclusions is driven in part by surging adoption of AI and related litigation. While courts have not yet issued a bellwether ruling on insurance coverage for losses stemming from a company’s use of AI, the proactive exclusions show a desire by insurance companies to avoid unintended “silent” coverage of such risks. As the exclusions become more prevalent, organizations should be aware of the changes to their policies to ensure they have coverage of their current business practices.

University of Chicago Law School Releases AI Strategy Statement

When first-year students started at the University of Chicago Law School in 1999, their class was among the first at the school to receive Westlaw passwords immediately, rather than spending a quarter learning to research in the books. The reasoning was that firms would expect electronic research and the old method no longer taught anything essential. Chicago has now issued a strategy statement on legal education in the AI era, and this time it has reached a very different conclusion.

The statement rests on three themes: teaching and testing without AI shortcuts; renewed focus on the "essential human" skills of oral advocacy, strategic judgment, and client relationships; and training in the responsible, effective, and ethical use of AI.

Rather than choosing between a ban and a free-for-all, the school does both at once. Beginning this academic year, all first-year classrooms go device-free and exams are taken in class with no internet, files, or apps, and those rules apply uniformly across every section rather than professor by professor. The legal writing curriculum, by contrast, treats writing without AI as the foundation and then layers writing with AI on top of it.

The most portable idea for employers is a new requirement that students defend their major research paper in person with the supervising professor, a live and unaided conversation that tests whether the author truly owns the reasoning behind the work. That one may be worth borrowing. Asking employees to walk through the thinking behind significant work product in real time costs very little, and it reveals a great deal about whether they are developing judgment or merely supervising a tool. The same question is worth putting to outside counsel: not whether the firm uses AI, but how it makes sure its associates still learn to think.

And yes, AI was used to help write this. The observations, the argument, and the editing came from a human — which is rather the point.

The Network Advertising Initiative (NAI) Publishes New Guidance on the Use of AI in Network Advertising

On July 20, 2026, the NAI published guidance titled Key Do’s & Don’ts for Using AI in Network Advertising. The guidance is designed to help ad-tech companies update their privacy and data governance practices as AI systems used in advertising become more advanced and increase in autonomy. The guidance provides practical guidance covering “do’s and don’ts” for each of nine categories of AI governance: (i) inventory and enabling of AI use cases; (ii) advertising audience/segment review and activation; (iii) testing and monitoring of AI systems; (iv) disclosures about how AI systems are used; (v) permissions and constraints applied to AI systems; (vi) choice and signal handling; (vii) oversight and logging for agentic AI systems; (viii) contracting and risk allocation between AI users and AI vendors; and (ix) accountability. The guidance is voluntary and is intended to serve as a practical, risk-based resource to aid in reviewing current workflows and governance processes.

The material contained in this communication is informational, general in nature and does not constitute legal advice. The material contained in this communication should not be relied upon or used without consulting a lawyer to consider your specific circumstances. This communication was published on the date specified and may not include any changes in the topics, laws, rules or regulations covered. Receipt of this communication does not establish an attorney-client relationship. In some jurisdictions, this communication may be considered attorney advertising.