Legal prism · 2026-08-26

Legal prism — 2026-08-26

Archive
Updated: 2026-08-26 14:55
The day's news through a legal prism — grounded in our database of EU legislation.
Original — verbatim from the source Analysis — our legal insight (not a source)

Today's news through the legal prism (3)

Selected for a legal angle. For each: original → fact-check and legal basis → substantive analysis.
Filter by area of law:
Original — Global Sources
EU AI Act Raises Compliance Requirements for Businesses Using AI - Global Sources Copy link
Businesses must now identify and classify all AI systems they use, including shadow deployments, as the EU AI Act introduces immediate transparency obligations and significant penalties for non-compliance. Companies developing, purchasing…
Analysis
Under GDPR Article 83(5), infringements of specified GDPR provisions may be subject to fines of up to EUR 20,000,000 or 4% of worldwide annual turnover.
For prohibited AI practices, the cited compliance summaries identify maximum fines of EUR 35,000,000 or 7% of worldwide annual turnover.

Core issue

The immediate legal position is one of operational uncertainty: a company cannot determine its obligations under the AI Act until every deployed tool has been inventoried and classified.

  • Because Article 50 transparency obligations are already in force, an undocumented vendor feature or business-unit tool may already constitute a compliance failure.
  • The precise legal question is whether the business acts as a provider, deployer, importer, or distributor of an AI system placed on the EU market or used in the EU.
  • The determinative rules are the AI Act classification categories: prohibited, high-risk, limited-risk, and minimal-risk applications.
  • Article 50 determines immediate transparency obligations for certain AI interactions and for AI-generated or manipulated audio, images, video, and text.
  • The evidence also links AI governance to data protection where automated processing affects individuals.
  • Under GDPR Article 35(3)(a), a data protection impact assessment is required for systematic and extensive automated evaluation that produces legal or similarly significant effects.

Legal assessment

The AI Act is described as applying to companies that develop, purchase, or deploy AI systems in the European Union.

  • It may also apply to non-EU companies where their systems are placed on the EU market or used within the EU.
  • As an EU regulation, the AI Act is directly applicable in every Member State.
  • The first practical obligation is visibility: identifying AI systems, including vendor features and shadow deployments.
  • The second obligation is classification: determining whether each system is prohibited, high-risk, limited-risk, or minimal-risk.
  • The high-risk areas identified in the evidence include employment, credit assessment, biometric identification, critical infrastructure, education, law enforcement, and migration.
  • For higher-risk systems, the evidence supports technical documentation, controls, ownership records, monitoring, and periodic review.
  • Article 50 creates current transparency obligations where users interact with AI or receive certain AI-generated or manipulated content.
  • Employers and other users may also need to notify individuals about certain emotion-recognition and biometric-categorization systems.
  • Other infringements may result in additional penalties, including failures relating to high-risk systems and the provision of false or misleading information to regulators.
  • No case law is included in the evidence, so no precedent can be applied to this situation.

Consequences

The lowest-risk scenario is administrative: the company establishes an inventory, assigns owners, classifies systems, and integrates review into procurement and operations.

  • The higher-risk scenario is an active breach: an undisclosed AI interaction or use of manipulated content already falls within Article 50.
  • The most severe scenario concerns prohibited practices, for which the evidence indicates fines of up to EUR 35,000,000 or 7% of worldwide annual turnover.
  • A company with EUR 600,000,000 in worldwide annual turnover would face a maximum percentage-based amount of EUR 42,000,000, exceeding the fixed EUR 35,000,000 amount.
  • This has practical significance for EU businesses and for non-EU providers, deployers, importers, and distributors whose systems reach the EU market.
  • Procurement teams also become part of compliance, because vendor AI features may determine classification and disclosure obligations.
  • The evidence points to classification, risk mapping, documentation, and ownership assignment.
Legal basis (3)
REGULATION (EU) 2017/1001 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL Article 3 (statute)
Article 3 Capacity to act For the purpose of implementing this Regulation, companies or firms and other legal bodies shall be regarded as legal persons if, under the…
Article 3 Capacity to act For the purpose of implementing this Regulation, companies or firms and other legal bodies shall be regarded as legal persons if, under the terms of the law governing them, they have the capacity in their own name to have rights and obligations of all kinds, to make contracts or accomplish other legal acts, and to sue and be sued. CHAPTER II THE LAW RELATING TO TRADE MARKS SECTION 1 Definition of an EU trade mark and obtaining an EU trade mark
Council Directive (EU) 2016/1164 laying down rules against tax avoidance practices (ATAD) Article 2 (statute)
or more entities, all the entities concerned, including the taxpayer, shall also be regarded as associated enterprises. For the purposes of Articles 9 and 9a: (a) Where…
or more entities, all the entities concerned, including the taxpayer, shall also be regarded as associated enterprises. For the purposes of Articles 9 and 9a: (a) Where the mismatch outcome arises under points (b), (c), (d), (e) or (g) of the first subparagraph of point (9) of this Article or where an adjustment is required under Article 9(3) or Article 9a, the definition of associated enterprise is modified so that the 25 per cent requirement is replaced by a 50 per cent requirement; (b) a person who acts together with another person in respect of the voting rights or capital ownership of an entity shall be treated as holding a participation in all of the voting rights or capital ownership of that entity that are held by the other person; (c) an associated enterprise also means an entity that is part of the same consolidated group for financial accounting purposes as the taxpayer, an enterprise in which the taxpayer has a significant influence in the management or an enterprise that has a significant influence in the management of the taxpayer.
Council Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC) Article 8a (statute)
amended or renewed; (b) in respect of the information exchanged pursuant to paragraph 2 — before 1 January 2018. 6. The information to be communicated by a Member State…
amended or renewed; (b) in respect of the information exchanged pursuant to paragraph 2 — before 1 January 2018. 6. The information to be communicated by a Member State pursuant to paragraphs 1 and 2 of this Article shall include the following: (a) the identification of the person, other than a natural person, and where appropriate the group of persons to which it belongs; (b) a summary of the advance cross-border ruling or advance pricing arrangement, including a description of the relevant business activities or transactions or series of transactions and any other information that could assist the competent authority in assessing a potential tax risk, without leading to the disclosure of a commercial, industrial or professional secret or of a commercial process, or of information whose disclosure would be contrary to public policy
Original — Amnesty International
Türkiye: Osman Kavala must be immediately released after European Court orders his conviction quashed Copy link
The Grand Chamber of the European Court of Human Rights has issued a landmark ruling in the case of Osman Kavala, a human rights defender and civil society leader unlawfully imprisoned in Türkiye since November 2017, finding that his…
Analysis
Because the Grand Chamber ordered release and quashing of the conviction, Türkiye now has a compliance obligation covering both custody and conviction.

Core issue

Osman Kavala’s position is no longer merely a detention dispute; the evidence indicates that his conviction itself is legally unsustainable.

  • The evidence identifies the applicable rule as Türkiye’s obligation, as a Council of Europe member and party to the Convention, to implement binding judgments of the Court.
  • The evidence also identifies the supervisory framework: the Committee of Ministers supervises the execution of, and compliance with, Court judgments. The cited EU instruments do not provide the operative enforcement route for this criminal human-rights judgment against Türkiye. Those provisions apply directly in every EU Member State, but the evidence does not link them to Kavala’s release.

Legal assessment

The Grand Chamber’s finding changes the practical legal burden on the Turkish authorities. The evidence states that the Court examined the indictment, charges, evidence, trial, appeals, and conviction, and then found a “flagrant denial of justice.”

  • Türkiye’s required steps are immediate release, quashing of the conviction, and measures to remedy structural judicial shortcomings.
  • Kavala’s right is not limited to a fresh review; the evidence states that the Court ordered his release at the earliest possible date and the quashing of his conviction.
  • Judicial and prosecutorial authorities are expressly identified as authorities required to act.

The case law in the evidence is the Kavala line of European Court judgments. In December 2019, the Court found unlawful detention and an ulterior purpose of silencing him as a human-rights defender. In July 2022, the Court found that Türkiye had breached its obligation to abide by the 2019 judgment. The latest Grand Chamber judgment goes further because it covers the entire Gezi proceedings and the conviction. It also finds violations of the right to a fair trial, freedom of expression and association, and the prohibition of inhuman and degrading treatment arising from the aggravated life sentence. The cited EU rules show how different legal instruments address enforcement, but they do not displace the Convention mechanism described in the news report. Those Regulations apply directly in every Member State, yet the evidence provides no basis for treating them as governing this ECHR compliance dispute.

Consequences

For Kavala, the direct practical consequence is release without making it conditional on ordinary domestic criminal finality. For his conviction, the practical consequence is that the state must set it aside, not merely reconsider detention.

  • For Türkiye, continued non-compliance would deepen an already established breach following the 2019 and 2022 judgments.
  • For the Council of Europe, the next institutional pressure point is supervision and the use of available tools to secure implementation.
  • For member states, the evidence supports concrete diplomatic demands for immediate release in dealings with Turkish authorities.

The broader legal significance is institutional rather than financial. The supported consequences are release, quashing of the conviction, remedial measures for judicial shortcomings, and intensified Council of Europe supervision. The next expected step is action by the Turkish authorities to release Kavala and set aside the conviction.

Legal basis (3)
REGULATION (EU) No 650/2012 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL Article 61 (statute)
Article 61 Enforceability of court settlements 1. Court settlements which are enforceable in the Member State of origin shall be declared enforceable in another Member…
Article 61 Enforceability of court settlements 1. Court settlements which are enforceable in the Member State of origin shall be declared enforceable in another Member State on the application of any interested party in accordance with the procedure provided for in Articles 45 to 58. 2. For the purposes of point (b) of Article 46(3), the court which approved the settlement or before which it was concluded shall, on the application of any interested party, issue an attestation using the form established in accordance with the advisory procedure referred to in Article 81(2). 3. The court with which an appeal is lodged under Article 50 or Article 51 shall refuse or revoke a declaration of enforceability only if enforcement of the court settlement is manifestly contrary to public policy (ordre public) in the Member State of enforcement. CHAPTER VI EUROPEAN CERTIFICATE OF SUCCESSION
REGULATION (EU) No 1215/2012 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL Article 44 (statute)
Article 44 1. In the event of an application for refusal of enforcement of a judgment pursuant to Subsection 2 of Section 3, the court in the Member State addressed may…
Article 44 1. In the event of an application for refusal of enforcement of a judgment pursuant to Subsection 2 of Section 3, the court in the Member State addressed may, on the application of the person against whom enforcement is sought: (a) limit the enforcement proceedings to protective measures; (b) make enforcement conditional on the provision of such security as it shall determine; or (c) suspend, either wholly or in part, the enforcement proceedings. 2. The competent authority in the Member State addressed shall, on the application of the person against whom enforcement is sought, suspend the enforcement proceedings where the enforceability of the judgment is suspended in the Member State of origin. SECTION 3 Refusal of recognition and enforcement Subsection 1 Refusal of recognition
REGULATION (EU) No 1215/2012 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL Article 41 (statute)
Article 41 1. Subject to the provisions of this Section, the procedure for the enforcement of judgments given in another Member State shall be governed by the law of the…
Article 41 1. Subject to the provisions of this Section, the procedure for the enforcement of judgments given in another Member State shall be governed by the law of the Member State addressed. A judgment given in a Member State which is enforceable in the Member State addressed shall be enforced there under the same conditions as a judgment given in the Member State addressed. 2. Notwithstanding paragraph 1, the grounds for refusal or of suspension of enforcement under the law of the Member State addressed shall apply in so far as they are not incompatible with the grounds referred to in Article 45. 3. The party seeking the enforcement of a judgment given in another Member State shall not be required to have a postal address in the Member State addressed. Nor shall that party be required to have an authorised representative in the Member State addressed unless such a representative is mandatory irrespective of the nationality or the domicile of the parties.
Original — Tech Policy Press
Colombia Is Preparing a Poor Copy of the EU’s AI Rules Copy link
Shortly before leaving office, Colombia’s Historic Pact party introduced Bill 025 of 2026 to regulate artificial intelligence, a move critics see as a belated and inadequate attempt to copy the EU’s AI Act after years of failing to make…
Analysis
Article 35(3)(a) GDPR requires an impact assessment for systematic automated evaluation that produces legal or similarly significant effects.
Under Article 7, that authority may issue binding technical recommendations on the risk levels of AI systems.

Core issue

Colombian deployers would be in the most difficult position because the bill regulates the use of AI, even where control rests with foreign developers. Although Bill 025 of 2026 is currently only before the Colombian House of Representatives, it would make AI adoption a compliance exercise. The legal issue is whether Colombia can allocate AI-related duties on a risk-based basis without overburdening actors that lack technical control. The decisive provisions are Articles 5 and 7 of Bill 025 of 2026, together with the impact-assessment model reflected in Article 35 GDPR.

  • Article 5 establishes the categories and general criteria for risk classification.
  • Article 7 designates the Ministry of Science, Technology and Innovation as the national AI authority.

Legal assessment

The bill’s structure assigns duties to developers, providers and deployers according to the role they perform in relation to an AI system. Those duties include risk and impact assessments, transparency, human oversight and monitoring for systems affecting fundamental rights or protected interests.

  • Providers are comparable to their counterparts under the EU model because they control documentation, risk management and proof of compliance.
  • Deployers are comparable to their counterparts under the EU model because they control use, human oversight and monitoring.
  • Colombian deployers may lack access to training data, architecture, evaluation procedures and internal safeguards for foreign closed models.

The GDPR is a Regulation and therefore applies directly in every Member State. Article 35(7) GDPR indicates what an assessment must contain: a description of the processing, necessity, proportionality, risks, safeguards and compliance mechanisms. Article 35(9) GDPR also supports obtaining input from affected persons where appropriate. The Colombian bill would centralise risk-classification authority in an executive body. Under Article 5, it may update high-risk uses by reasoned administrative act following public consultation. That design raises a due-process concern because risk classification triggers enhanced legal obligations and may affect deployment. The evidence indicates that final intervention measures remain with the authorities that hold the relevant legal powers. Even so, classification must remain linked to clear legislative criteria and effective review. The Inter-American Court’s judgment in Velásquez Rodríguez v. Honduras is relevant because formal rights require enforceable state conditions. Suárez Peralta v. Ecuador points in the same direction for duties that require monitoring, investigation and enforcement capacity. Applied here, impact assessments and audits have limited legal force without technical expertise, infrastructure, information and budget.

Consequences

The practical effect is not immediate sanctioning, because the bill is still pending before the Colombian House of Representatives. The market consequence is planning pressure for companies using AI in health, justice, security, surveillance and public services.

  • Local deployers should expect scrutiny of human oversight, monitoring and impact assessment.
  • Foreign providers are less clearly covered because the bill lacks the same clear extraterritorial reach as the EU AI Act.
  • Public bodies would need technical staff, inspection mechanisms and cooperation channels before obligations become enforceable.

If enacted as described, the first disputes are likely to concern who controls the AI system and who can provide compliance evidence. A small Colombian company using a closed foreign model could be required to explain a system it cannot inspect. That mismatch is the bill’s central enforcement risk.

Legal basis (3)
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 35 (statute)
the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in…
the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; (b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale.
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 2 (statute)
execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. 3. For the processing of personal data by the Union…
execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. 3. For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98. 4. This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.
Council Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC) Article 25 (statute)
the extent required in order to safeguard the interests referred to in point (e) of Article 23(1) of that Regulation. 2. Regulation (EU) 2018/1725 of the European…
the extent required in order to safeguard the interests referred to in point (e) of Article 23(1) of that Regulation. 2. Regulation (EU) 2018/1725 of the European Parliament and of the Council shall apply to any processing of personal data under this Directive by the Union institutions, bodies, offices and agencies. However, for the purposes of the correct application of this Directive, the scope of the obligations and rights provided for in Article 15, Article 16(1), and Articles 17 to 21, of Regulation (EU) 2018/1725, shall be restricted to the extent required in order to safeguard the interests referred to in point (c) of Article 25(1) of that Regulation.