AI Round-Up: Four Stories That Show Where Regulation Is Heading
14th September 2026
If you are waiting for a single AI law to tell you what you can and cannot do, you may be waiting a while. What is actually happening is quieter: existing regulators are applying existing law to AI, one sector at a time. Four stories from the last few weeks make the point.
Norway moves on smart glasses
On 25 August, Norway’s Digitalisation Minister Karianne Tung announced plans to regulate smart glasses more strictly, including a possible ban on facial recognition in public spaces. An expert group will advise, and no timetable has been set. Reported by TechCrunch among others, Tung’s concern was broader than one product: the pattern of combining AI with cameras and microphones in glasses, earbuds, caps and other everyday objects, and the risk of that equipment being used to monitor people in public.
The SRA puts solicitors on notice
On 17 August, the Solicitors Regulation Authority published a warning notice on the misuse of AI, following 42 reports of potential misuse between July 2025 and July 2026. Two concerns are singled out. The first is fabricated case citations reaching court. The second matters to every organisation, not just law firms: confidential client information entered into public AI tools, creating risks to confidentiality and to data protection compliance. The SRA’s position is blunt and correct: individuals remain responsible for the work they produce, whether or not AI was used.
The MHRA draws a line on AI scribes
On 29 July, the MHRA clarified when ambient voice technology products count as medical devices. Tools intended solely to transcribe a consultation, summarise it, draft a letter or suggest clinical codes for a clinician to review are not regulated as devices. Tools that go further, into diagnosis or automated action, are. That resolves real uncertainty for the NHS, but note what it does not do: a product outside medical device regulation is still processing health data, and the UK GDPR applies in full either way.
And the question nobody has answered
Running underneath all this is agentic AI: systems that act rather than merely respond. Bristows’ Spotlight on Agentic AI series sets out how these systems are already planning, deciding and acting inside live business workflows, and how accountability for what they do remains unsettled, particularly where responsibility has to be traced across several vendors. Contracts written today are unlikely to have anticipated it.
What connects them
None of these is an AI law. A government ministry, a professional regulator and a medical devices agency have each applied rules they already had. That is how AI regulation is arriving for most organisations, and the consequence is practical: your obligations do not wait for new legislation. If your staff use an AI notetaker in meetings, the data protection questions that raises apply now. If anyone pastes client or patient information into a public chatbot, that is a disclosure now. And a new AI tool is exactly the kind of innovative technology that calls for a DPIA before it goes live.
The second thread is accountability. The SRA says the solicitor remains responsible. The MHRA draws its line where a clinician stops reviewing the output. Norway’s concern is equipment used to monitor people who never agreed to it. In each case the regulator puts the human back at the centre, and none treats ‘the AI did it’ as an answer.
How Griffin House Consultancy Can Help
Most organisations have more AI in use than their policies acknowledge. We help organisations find out what is actually being used, assess the privacy risks, write policies people will follow, and train teams on where the lines sit. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.