Technology

On 19 May 2026, the European Commission published its long-awaited draft, non-binding guidelines on the classification of high-risk AI systems (“HRAIs”) under the EU AI Act (the “Guidelines”). Across three documents—covering general principles, high-risk classification in the context of regulated products (Annex I), and high-risk use cases (Annex III)—the Commission sets out its approach to one of the AI Act’s central questions: when does an AI system fall within the high-risk regime (and, just as importantly, when does it not)?

Continue Reading EU AI Act Update: The European Commission Publishes Draft Guidelines on HRAIs

California’s new autonomous vehicle regulations create the state’s first pathway for testing and deploying heavy-duty AVs while imposing a more rigorous permitting, safety-case, reporting, and enforcement framework for all AV manufacturers.

Finalized by the California Department of Motor Vehicles (the DMV) on April 28, 2026, the regulations (the Regulations) introduce significant new safety and oversight requirements, and expand California’s AV framework to include heavy-duty vehicles over 10,000 pounds, which had previously been excluded. The Regulations do not alter the California Public Utilities Commission requirements that separately apply to AV companies operating robotaxis in the state.

Continue Reading California’s New AV Rules Open Door to Heavy-Duty Deployment While Imposing Significant New Compliance Obligations

On June 3, the European Commission published its Tech Sovereignty Package, a set of legislative and policy initiatives designed to address what the Commission characterizes as Europe’s technological dependencies on non-European suppliers. The Package marks a further step in the evolution of the EU’s technology policy, with initiatives spanning the full tech stack—from chips and infrastructure to software, cloud, and artificial intelligence. Through this “ecosystem” approach, the Commission seeks to reduce supply-side dependencies by strengthening domestic capabilities in Europe and stimulating demand in downstream sectors.

The Package comprises four components: two legislative proposals—(i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0—as well as two non-legislative initiatives—(iii) the EU Open Source Strategy and (iv) a Strategic Roadmap for Digitalisation and AI in Energy.

Continue Reading EU Tech Sovereignty Package

EU Member States are currently designing two possible new Important Projects of Common European Interest (“IPCEIs”) to support the development of AI and compute infrastructure in the EU (together the “Digital IPCEIs”), subject to European Commission (“Commission”) approval.

On 10 March 2026, the “matchmaking” phase under the IPCEI on Artificial Intelligence (“IPCEI-AI”) was officially launched in Berlin. It brings together companies whose AI projects have been pre-selected through national calls for expressions of interest (“CEIs”) in each participating Member State. Its objective is to form European consortia eligible for State co-funding under the IPCEI-AI. National CEIs in 17 participating Member States are now closed; Finland and Lithuania are still expected to launch their CEIs.

A second digital IPCEI on Compute Infrastructure Continuum (“IPCEI-CIC”) was launched in late 2025 by 15 Member States. Several of these participating Member States – including Belgium, Croatia, Estonia, Finland, France, Germany, Hungary, Lithuania, the Netherlands, Romania, Slovakia, and Spain – have not yet launched their CEIs.  

Continue Reading Important Projects of Common European Interest (IPCEIs) on Artificial Intelligence and Compute Infrastructure Continuum

In introducing the American Security Robotics Act of 2026, Senators Tom Cotton (R-AR) and Chuck Schumer (D-NY) have extended a now familiar congressional playbook into a new and consequential domain:  robotics.  The bill would prohibit executive agencies from procuring or operating unmanned ground vehicle systems (UGVs) manufactured or assembled by “covered foreign entities,” a term that targets companies tied to adversarial nations such as China.

The legislation also reflects early signs of bicameral alignment.  Representative Elise Stefanik (R-NY-21) has introduced companion legislation in the House, signaling that concerns regarding robotics systems manufactured by certain foreign entities are not confined to a single chamber or party.

At one level, the proposal is straightforward.  At another, it reflects a maturing legislative architecture that has evolved across successive National Defense Authorization Acts (NDAAs) and related statutes—an architecture that is increasingly product-specific, attentive to supply chain risk, and focused on issues of data access, operational control, and systemic vulnerability.

Continue Reading The Next Frontier of Supply Chain Security: Congress Trains Its Sights on Robotics

This update highlights key legislative and regulatory developments in the first quarter of 2026 related to artificial intelligence (“AI”), connected and automated vehicles (“CAVs”), and Internet of Things (“IoT”).

I. Federal AI Legislative Developments

In the first quarter, members of Congress introduced several AI bills related to nonconsensual images, chatbots

Continue Reading U.S. Tech Legislative & Regulatory Update – First Quarter 2026

On 19 March 2026, Advocate-General Capeta issued an opinion in the case of Elisa Eesti AS v Estonian Government Security Committee (C-354/24). This case concerned, among other things, whether a 2022 order from the Estonian Government for Elisa Eesti AS—a 5G network operator—to remove Huawei components from its network for national security reasons was subject to EU law, constituted a lawful restriction on the right to offer an electronic communications network, and amounted to a “deprivation of property” requiring compensation.

AG Capeta concluded that the relevant Estonian regime was within scope of EU law—specifically the European Electronic Communications Code (“EECC”)—even though that regime allowed for the imposition of orders on electronic communications network (“ECN”) providers for national security reasons. She also concluded that the requirement to obtain prior authorization from the Estonian government for use of network equipment constituted a restriction on the freedom to provide an ECN, but that this could be justified on national security grounds if the decision was based on a genuine risk assessment that meets the requirements for proportionality under EU law. She stated that this determination should be left to the referring court. Finally, she concluded that the Estonian Government’s order did not amount to a “deprivation” of property for which compensation would be required, as it was instead a mere “restriction” on the use of property.

Below, we describe these non-binding conclusions in more detail. The Court’s final ruling in this case will have significant implications for the European Commission’s proposed revisions to the EU Cybersecurity Act, which as drafted would—among other things—allow the Commission to require ECN providers to remove and cease using components from designated high-risk jurisdictions in their networks. See our prior blog post on the proposal for a revised Cybersecurity Act here.

Continue Reading CJEU Advocate-General indicates that communications network operators can lawfully be required to remove Chinese components, and that compensation is not required

In late December 2025, the FCC updated its “Covered List” to add foreign-produced Uncrewed Aircraft Systems (“UAS”) and their critical components. In early January 2026, the FCC narrowed that action by creating a temporary exception for certain UAS and critical components, including those on the Department of War’s Blue UAS

Continue Reading FCC Updates Covered List to Conditionally Approve the Use of Certain Drones

On March 17, Colorado Governor Jared Polis released a draft bill that would substantially overhaul the Colorado AI Act, replacing its core requirements with a narrower regime focused on disclosure, recordkeeping, and consumer notice requirements for “automated decision-making technology” (“ADMT”).  The proposal, which is still in draft form and

Continue Reading Colorado Officials Push to Repeal and Replace the Colorado AI Act

As artificial intelligence (AI) technologies continue to advance and states increasingly pass legislation to regulate AI development and use, Congress and the White House are proposing comprehensive nationwide laws.

New proposals from the White House Office of Science and Technology Policy (OSTP) and Senator Marsha Blackburn (R-TN) offer comprehensive approaches

Continue Reading White House, Blackburn Introduce Visions of Comprehensive Federal AI Policy