
Weekly research report, edition 6 — 6–12 September 2026
Abstract
The week of 6–12 September 2026 produced two connected shifts in AI assurance.
First, liability became more concrete just as insurance protection became less dependable. Two Munich decisions attributed legal responsibility for AI-generated content directly to providers. Google was held responsible for AI Overview statements treated as its own attributable content, while Suno was held liable at first instance for copyright infringement involving training, model memorisation and generated output. Neither case settles the law finally—the Google matter concerned a preliminary injunction and the Suno judgment remains appealable—but together they weaken the proposition that an AI provider merely supplies neutral infrastructure.
At the same time, Verisk’s ISO made three optional generative-AI exclusion endorsements available with a January 2026 edition date. Actual adoption depends on the insurer and the applicable filing or approval process. Liability is being assigned while the availability of conventional risk transfer may be narrowing.
Second, the week exposed the chain behind the interface as a control object in its own right. A chatbot may silently rely on connectors, tools, shared infrastructure, external models, personal accounts and cross-border data routes. A provenance label may record file history without proving truth. A benchmark may demonstrate performance without establishing reliability in the workflow where the system is deployed. An ISO certificate may describe a management system while excluding the purchased service from its scope.
Across the nineteen analyses, the same evidential pattern recurred: assurance depends on showing which actor used which model, data, authority and route; which control operated at runtime; what evidence it produced; and where a human accepted responsibility.
Edition 5 ended with a practical change in regulatory posture: the auditor had an address, a questionnaire and a deadline. Edition 6 follows the questions into the systems that must answer them. The result is a two-pillar thesis: liability now attaches more directly to actors in the AI chain, while assurance increasingly depends on reconstructing the hidden chain through which the consequential action occurred.
The decisive question is no longer whether an organisation has an AI policy, but whether it can reconstruct the route from model and source to action, harm and accountable decision.
Liability meets retreating cover
The strongest material of the week came from two decisions of the Landgericht München I.
According to DLA Piper’s analysis and the official court communication, the court issued a preliminary injunction on 28 May 2026 in case 26 O 869/26 after Google AI Overviews associated two publishers with scams and dubious business practices. Because Google created and controlled the system that formulated claims not found in the linked sources, the court treated the statements as Google’s own content rather than information neutrally transmitted from elsewhere.
The statements infringed the publishers’ corporate personality rights. The decision was provisional and not final when reported, but its allocation logic matters: generation can make the provider an originator rather than an intermediary.
The second decision applied a comparable allocation principle in copyright law. In GEMA v. Suno, case 42 O 763/25, the Munich court held at first instance that the provider—not users entering ordinary prompts—was responsible for infringing acts involving six protected musical works.
As described in the official court communication and analysed by Reed Smith, those acts included reproduction during training, reproducible retention or memorisation in the model, making the model available and producing infringing outputs. The court awarded injunctive, disclosure and damages-related relief, but the judgment remains open to appeal and should not be presented as settled European precedent.
The insurance development runs in the opposite direction. Verisk’s ISO made three optional generative-AI exclusion endorsements available with a January 2026 edition date. Actual adoption depends on the insurer and the applicable filing or approval process.
According to Insurance Journal, the forms offer different scopes:
- CG 40 47 excludes coverage for bodily injury, property damage and personal and advertising injury arising out of generative AI under the Commercial General Liability Coverage Part.
- CG 40 48 applies to personal and advertising injury under Coverage B.
- CG 35 08 applies to bodily injury and property damage under the Products/Completed Operations Coverage Part.
The forms do not automatically amend every policy. An insurer must adopt and attach the relevant endorsement in accordance with the applicable jurisdictional process.
The combined development matters more than either strand in isolation. Providers may face direct claims for what their systems generate, professional users remain accountable under their own duties of care, and organisations cannot assume that ordinary liability insurance will absorb the resulting loss. Liability analysis, supplier governance, workflow design and insurance review consequently become parts of the same assurance file.
A third strand shows how far remedies may reach. In litigation brought by the Seattle Times and Newsday against OpenAI and Microsoft, the plaintiffs are seeking destruction under 17 U.S.C. §503(b) of copies of their works, training datasets and models alleged to have been created using those works, according to Reuters.
In separate litigation involving The New York Times, the US Department of Justice filed a statement supporting a fair-use reading of AI training, as Reuters reported on 2 September. Neither filing decides whether the training at issue was lawful, and the government’s statement is not binding on the court.
But the demand for destruction itself explains why documented training provenance is becoming a survival condition for the model asset. The same evidential pressure appears in Europe: Directive (EU) 2024/2853 expressly includes software, including AI systems, within the definition of a product. Member States must transpose the revised Product Liability Directive by 9 December 2026, and it applies to products placed on the market or put into service after that date.
Our advice. Review AI liability by workflow rather than by provider alone. For every material use case, identify the potentially liable provider and professional, inspect the actual policy endorsement schedule, record contractual indemnities and audit rights, and preserve the model version, inputs, sources, human review and final decision needed to reconstruct a claim.
The interface is not the boundary
The week’s second pillar concerns the architecture hidden behind an apparently simple interface.
Check Point Research demonstrated a cross-account command channel between isolated ChatGPT code-execution environments. Containers belonging to separate accounts could use mutable metadata in a shared internal Artifactory service as a “shared clipboard,” allowing an attacker-controlled instruction to run a concealed second task while the victim received a normal-looking answer.
In the proof of concept, the victim’s connected Gmail account was read and the result returned through the covert channel. The visible answer did not reveal the hidden request or the data returned to the attacker.
Check Point disclosed its findings to OpenAI, which confirmed that the internal Artifactory instance identified during the research had been decommissioned. By the time Check Point completed its report, the cross-account channel was no longer available. The available reporting does not establish how long the channel existed before remediation.
The connector analysis extends that lesson. Once an assistant can reach Gmail, Drive, Teams, GitHub or another external service, it becomes a privileged meta-client over several systems. The relevant boundary is no longer the chatbot window but the complete path through retrieved content, connector permissions, tool execution, internal services and outbound destinations.
A normal answer in the interface proves nothing about what else the agent read or did during the same turn.
The July 2026 Model Context Protocol revision reinforces this distinction. MCP now provides stronger transport-level authorisation mechanisms, including OAuth-based protected-resource metadata, issuer validation, token audience binding and resource indicators. But application-level consent, least privilege, tool safety and policy enforcement remain implementation responsibilities.
The same hidden-route issue appears on the data side. The week’s GDPR analysis separates scraping, training, inference and logging into distinct processing phases, each requiring its own role allocation, legal basis and evidence. The privacy-gate analysis similarly treats consent not as a banner but as a user journey through acceptance, refusal, later withdrawal, storage and downstream personalisation.
The procedural background to the DPG matter predates the report week. In Decision 16/2025 of 24 January 2025, case DOS-2023-03278, the Belgian Data Protection Authority addressed objections concerning the complainants’ standing, their representation by noyb and alleged abuse of process. It found sufficient grounds to continue the four complaints concerning hln.be, demorgen.be, vtm.be and 7sur7.be to examination on the merits.
That decision did not determine whether the cookie banners themselves were lawful. It allowed the substantive proceedings to continue and left questions concerning the evidential strength of the complaints and the alleged infringements for the merits phase. The September analysis uses that continuing proceeding to illustrate why refusal, colour, placement, withdrawal and downstream processing must be examined as one consent workflow rather than as isolated design elements.
Shadow AI is the organisational version of the same problem. The Netskope AI Report 2026 reported that, among weekly AI users visible in Netskope telemetry from a subset of its customers between June 2025 and July 2026, 30% used only personal AI applications and another 14% combined personal and organisation-managed tools. Within that observed population, 44% therefore had at least some personal-app component in their AI use.
That percentage is bounded by Netskope’s customer base, telemetry and definition of weekly AI users. It should not be treated as a universal workforce estimate or combined uncritically with surveys measuring different populations, periods or behaviours.
The final article of the week moves the route behind the vendor name itself. It reports Anthropic’s accusation, covered by CNBC, that DeepSeek and Moonshot forwarded customer prompts to Claude without informing their users. Whether every allegation ultimately holds or not, the governance implication remains: the service named in the interface may not be the only model receiving the prompt.
A prompt must therefore be treated as a data object with its own route, retention period, legal basis, training status and possible onward transfers.
Our advice. Draw the actual runtime route for every sensitive AI workflow. Include connectors, retrieved sources, internal services, subprocessors, underlying models, tool permissions, destinations and logs; then test whether the route observed in operation matches the route described in contracts and privacy documentation.
A proxy is not evidence
Several analyses examined controls that are useful but easily overstated.
Article 50 of the AI Act distinguishes visible notification from machine-readable marking and detection. The European Commission’s guidelines state that relevant providers must inform people when they interact directly with AI and must make generated or manipulated content machine-readable and detectable. Deployers have separate disclosure duties for deepfakes and certain AI-generated or manipulated public-interest text.
A technical mark without an available means of detection does not by itself satisfy the marking-and-detection requirement.
The Commission’s Code of Practice on Transparency of AI-generated Content details measures intended to help providers and deployers comply with the relevant marking and labelling obligations. The Commission and the AI Board assessed the code as adequate. Signatories can use it as a more predictable route for demonstrating compliance; organisations that do not sign must still meet the underlying legal obligations in practice.
C2PA illustrates the difference between provenance and truth. As the C2PA specification describes, a valid manifest can establish which credential signed the claim, which assertions were recorded and whether the provenance information remains cryptographically associated with the asset.
It cannot establish that the depicted event occurred, that manipulation did not happen before signing, that the recorded assertions are substantively true or that the signer was trustworthy. Provenance is therefore evidence about attributed history and integrity, not a verdict on factual authenticity.
The legal-AI material makes a related distinction between retrieval and verification. In the peer-reviewed study Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools, published in 2025, the evaluated LexisNexis and Thomson Reuters legal-research systems hallucinated between 17% and 33% of the time, depending on the tool, under the benchmark conditions.
The findings describe the systems and versions evaluated at that time. They are not a measurement of those products’ performance in September 2026.
GPT-6 Astra shows why better performance does not remove that distinction. In OpenAI’s Legora case study, an Astra-powered agent reviewed 41 financial documents in one run and found all four errors Legora had planted in the accounts, including a £500,000 discrepancy hidden in the revenue note.
OpenAI reported a performance improvement of nearly 40% over the previous model on that workflow and approximately 3% on average across Legora’s broader internal BAR benchmark. These are vendor-reported results from a defined evaluation, not an independent assurance result.
The appropriate conclusion is not that benchmarks are irrelevant. It is that a benchmark supports a model-selection decision, while an audit trail must still show which documents the agent read, which checks it performed, which discrepancies it surfaced and where a lawyer or other professional accepted, amended or rejected the result.
Our advice. Use labels, certificates, benchmarks and explanations as inputs to assurance, never as substitutes for it. Attach each proxy to operational evidence showing its scope, detection method, runtime application, limitations and accountable human decision.
The control map
For each recurring governance claim, the map contrasts the weak proxy usually offered with the evidence that carries more weight.
- “We know which AI we use.” Weak proxy: vendor or product name. Stronger evidence: exact model and version, workflow inventory, underlying provider and observed route.
- “Access is controlled.” Weak proxy: connector list or shared API key. Stronger evidence: bound identity, permitted scopes, delegation record and tool-call log.
- “Consent was obtained.” Weak proxy: cookie banner or stored consent flag. Stronger evidence: complete user journey showing acceptance, refusal, withdrawal, timing and downstream effect.
- “The content is authentic.” Weak proxy: C2PA label or watermark. Stronger evidence: validated provenance plus independent source corroboration and documented human assessment.
- “The model performs well.” Weak proxy: headline benchmark score. Stronger evidence: task-specific evaluation, failure distribution, model version and local acceptance criteria.
- “The supplier is governed.” Weak proxy: ISO/IEC 42001 certificate. Stronger evidence: certificate scope, Statement of Applicability, product-specific controls, audit findings and corrective actions.
- “The output was reviewed.” Weak proxy: human-in-the-loop statement. Stronger evidence: named reviewer, reviewed version, intervention, reason and final approval.
- “The loss is insured.” Weak proxy: general liability policy. Stronger evidence: current endorsement schedule, confirmed coverage position, exclusions and tested notification procedure.
The map does not reject proxies. It places them in their proper evidential role. A proxy helps direct attention; evidence must show what happened in the specific workflow under review.
Governance becomes selection
The remaining analyses show the same evidential burden moving into procurement and institutional design.
The supplier-selection article combines three axes: regulatory conformity for the relevant risk category, a demonstrable AI management system and contractually enforceable access to logs, provenance, incident information and audit evidence.
ISO/IEC 42001:2023 is relevant because it specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI management system. But it is a management-system standard rather than a product guarantee. A certificate only speaks to the organisation, activities and controls included within the audited scope.
The public-sector and healthcare analyses add jurisdictional and sectoral dimensions. A general AI policy cannot by itself resolve whether a particular use case is a medical device, a high-risk AI system, a GDPR processing operation or several of these at once. The applicable rules, required oversight, supplier evidence and monitoring regime must be mapped per use case.
The two Clauze.AI analyses make that concrete for legal technology. White & Case’s position as both investor and potential ecosystem participant raises questions about client-data routes, Saudi data residency, Arabic-language review, conflicts of interest, model access and the separation between an agent’s technical capabilities and its permitted authority.
These questions do not allege misconduct. They identify the controls needed when commercial interest, professional responsibility and confidential workflows meet in one platform.
Mistral’s funding round adds concentration and dependency to the supplier question. The strategic relevance of a European provider does not remove the need for contractual audit rights, provenance information, incident arrangements and exit options. “European,” “sovereign” and “compliant” remain claims until their practical meaning is established for the workflow in which the model operates.
Our advice. Move evidence requests to the beginning of procurement. Require service-specific documentation, certificate scope, model and data provenance, subprocessor routes, incident obligations, insurance position, audit rights and an executable exit plan before price and feature scoring can make a supplier eligible.
What organisations must demonstrate
Across the nineteen analyses, the recurring evidence requirement can be expressed as an eight-point pattern:
- Object — Which workflow, decision, document, output or agent action is being assessed?
- Actor — Which provider, deployer, professional, agent and reviewer participated?
- Identity — Under which human or non-human identity did each system act?
- Authority — What was each actor permitted to read, generate, change or transmit?
- Route — Through which models, connectors, services, jurisdictions and subprocessors did the data travel?
- Source — Which documents, datasets, prompts and provenance claims supported the result?
- Control — Which privacy, security, verification, transparency and human-oversight measures operated at runtime?
- Outcome — What happened, who approved it, which harm or exception arose, and which contractual or insurance response applies?
These eight points turn separate governance files into a reconstructable event. They also expose where the evidence stops: an unknown subprocessor, an unlogged connector action, an excluded product scope or a reviewer whose approval cannot be tied to the final version.
Advice by audience
Boards
- Require a combined liability, insurance and AI-workflow review rather than separate legal, cyber and procurement reports.
- Ask which AI losses are excluded from current policies and which workflows could create uninsured exposure.
- Demand an inventory connecting material AI use cases to providers, model versions, data routes, accountable executives and tested fallback options.
- Treat certificate scope, audit rights and incident evidence as board-level dependency indicators.
Professionals
- Treat AI output as a proposed work product until its propositions, sources and current legal or factual status have been checked.
- Record the model, documents consulted, material prompts, corrections and final sign-off in the matter or case file.
- Do not assume that a connector, provenance label or specialist legal interface has already performed the necessary verification.
- Escalate workflows where the provider route, data destination, insurance position or applicable human responsibility cannot be reconstructed.
Public decision-makers
- Procure and supervise generative AI per use case, with an explicit public purpose, permitted data, risk classification, oversight and appeal route.
- Require suppliers to expose model changes, subprocessors, incidents and the operational evidence behind transparency claims.
- Preserve a record of where public officials intervened, especially where AI contributes to information, eligibility, enforcement or service decisions.
- Design pilots so that evidence survives scaling; a controlled experiment without reconstructable logs cannot support public accountability.
Closing synthesis
Edition 5 ended when enforcement stopped being abstract: the auditor had an address, a questionnaire and a deadline. Edition 6 shows what an organisation must have ready when the questionnaire arrives.
The first answer concerns responsibility. Courts are beginning to identify providers as direct actors, professionals remain accountable for how outputs enter consequential work, and insurers may use new standard endorsements to withdraw parts of ordinary cover.
The second answer concerns reconstruction. Models, connectors, agents, prompts, sources and human interventions form a chain that must be visible beyond the interface.
The hidden chain has therefore become the control object—but it is not the only one. The complete assurance object is now the chain together with the allocation of liability when that chain fails.
An organisation that can reconstruct the route but has not examined responsibility and coverage knows what happened but not who carries the loss. An organisation that has contractual allocations but cannot reconstruct the event has positions on paper without the evidence needed to defend them.
Articles discussed
Publication dates follow the visible dates on the live IamVera.ai blog page, which is the sole authority for inclusion in this edition.
6 September 2026
- Who is liable for an AI error? How the law divides responsibility in 2026
- Privacy gate as a workflow: what to check on a cookie wall after the DPG case
7 September 2026
- AI error in production or output: what to record now providers become liable and insurers exclude cover
- GPT-6 Astra in legal workflows: what you must be able to demonstrate per task
- Securing MCP integrations after the 28 July 2026 spec: what you must now prove per tool call
8 September 2026
- Why courts may order AI model destruction and how to document your model’s origins
- ChatGPT connected to Gmail, Drive, Teams and GitHub: what to check now about your connectors
- Distinguishing explainability from auditability under Article 50: tracing and proving AI content use
- Mistral’s €3 billion funding: recording European AI model use and governance obligations
9 September 2026
- Why a C2PA label does not prove a deepfake is real: what you should record instead
- GDPR responsibilities per phase of your generative-AI workflow
10 September 2026
- Buying AI services after 2 August 2026: the three axes for vetting suppliers
- Exposing shadow AI before you can control it: what 2026 figures demand of your organisation
- Recording controls and oversight for GenAI in government: EU guidance on workflow-level governance
- Setting up healthcare AI governance for fragmented rules in the UK, EU and US
- Legal AI still hallucinates in 1 in 5 to 3 in 10 searches: how to build a verification layer
- Deploying Saudi legal AI such as Clauze.AI: what to record about data residency and governance
- White & Case invests in Clauze.AI: governance, data flows and conflicts in contract AI adoption
11 September 2026
No article was published on 12 September 2026.