Sign in

michael veale

@michae.lv
9K followers 1.8K following 1.6K posts

prof @laws.ucl.ac.uk, technology, law, policy, society, whimsical latvian top level domain names. michae.lv and fediverse someone.elses.computer/@mikarv 🏳️‍🌈

PostsRepliesMedia
michael veale @michae.lv · 30/08/2026
if the president decided to rename another country via EO, would google implement it for US users? where does google draw the limit?
5358
michael veale @michae.lv · 27/08/2026
note, when radovan karadžić (president of republika srpska, also convicted of war crimes in bosnia and sentenced to life) dies, if he does not move prisons he will die on the Isle of Wight where he is being held
033
michael veale @michae.lv · 21/08/2026
uber fined 825m EUR for violating GDPR by dutch DPA re deactivation of drivers‘ accounts nos.nl/artikel/2627...
nos.nl
Uber schond rechten chauffeurs, AP legt megaboete van 825 miljoen op
Uber zou chauffeurs hebben geschrapt via automatische systemen, zonder dat er een mens bij te pas kwam.
062
michael veale @michae.lv · 21/08/2026
disappointed that out of the huge number of digital sovereignty conferences, none have yet centred the lived experience of actual sovereigns
3121
michael veale @michae.lv · 17/08/2026
sainsbury‘s pauses AI shoplifting detection face scanning from Gordon’s Wine Bar spin out surveillance company Facewatch after incorrect customer ejection www.theguardian.com/technology/2...
theguardian.com
Sainsbury’s store pauses AI scanning after false shoplifting accusation
Supermarket chain says ‘human error’, not its Facewatch technology, to blame for ejecting a customer
1134
michael veale @michae.lv · 17/08/2026
have not seen anyone note that, in relation to AI SynthID text watermarking: all methods deployed by AI firms rely on private keys for security so no cheap/local/private detection. EU AI Act guidelines say it should not be this way, it should be local/interoperable. the deployed methods are not!
2133
michael veale @michae.lv · 17/08/2026
given Amazon provide the 'Sidewalk' infrastructure that makes Tile trackers work via Alexa and Ring devices as detectors, they don't exactly have a leg to stand on when investigative journalists slip an AirTag in a book
061
Reposted by michael veale
Emanuel Maiberg @emanuelmaiberg.bsky.social · 17/08/2026
We put a tracking device in a shipment of rare books acquired by an anonymous buyer. It ended up at an Amazon facility where the company scans books for training data and destroys them in the process: www.404media.co/we-tracked-a...
404media.co
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We placed a tracking device in a shipment of rare books to see which AI company was buying it, and found an Amazon facility where Amazon scans and destroys books.
391572914
Reposted by michael veale
Alex Hern @hern.bsky.social · 17/08/2026
I’m convinced, upon rereading, that this simply misunderstands how either or both of how LLMs or watermarking works daringfireball.net/2026/08/anth...
daringfireball.net
Anthropic’s ‘Watermark’ Text Adulteration in Claude Is a Perversion of Writing
It’s unacceptable for a tool to sacrifice an iota of clarity, coherence, meaning, quality, etc. for the purpose of embedding hidden clues within the text to suggest its provenance. The idea that anyth...
179814
michael veale @michae.lv · 17/08/2026
I've updated UCL Massively Crossreferenced Digital Laws — it now features ~40 EU instruments as well as Irish & UK digital laws; what cites each article/para/sub para from a db of 6.5M cases, statutes, decisions, guidance, pending CJEU preliminary rulings & more homepages.ucl.ac.uk/~ucqnmve/law...
Image of the linked interface focussing on Art 59 of the AI Act
11410
michael veale @michae.lv · 14/08/2026
media is a hugely important thing to study, it’s dismal to reduce it to ‘content’ degrees.asu.edu/bachelors/ma...
degrees.asu.edu
Content Creation - BA | Degree Details | ASU Degree Search
Turn your creativity into content that connects with audiences. Learn to create powerful video, podcasts and social media content that builds engaged audiences and uses analytics to understand what wo...
131
michael veale @michae.lv · 11/08/2026
i see government is taking its online presence seriously in this troubled digital age, passing GDS responsibility to the minister in charge of ‘ceremonials’ (ie remembrance day parades) and tourism.
011
Reposted by michael veale
Jonty Wareing @jonty.bsky.social · 10/08/2026
I always suspected a UK government would eventually reverse course on "coding in public". So I've been backing up all government code. For six years. Today I finally generated a report on what has been deleted. Its much worse than I realised. github.com/uk-gov-mirro...
Deleted UK Government code repositories

Total deleted repositories: 1526
Organisations affected: 56

See RECENTLY_DELETED.md for the most recently deleted repositories.

Organisation	Deleted Repos	% Deleted
hmrc	195	9.8%
nhsdigital	169	33.8%
SkillsFundingAgency	154	22.7%
informatics-lab	154	100.0%
UKHomeOffice	101	7.5%
ministryofjustice	74	2.8%
ONSdigital	66	4.3%
moj-analytical-services	65	75.6%
ukwa	47	46.1%
dwp	46	6.7%
UKGovernmentBEIS	43	27.4%
6219134
Reposted by michael veale
Inside the Black Box @itbb.bsky.social · 07/08/2026
The default is the consequential part. Scraping consent has operated as opt-out-if-you-knew-to, so silence became permission. Cloudflare now turns silence into reservation at a chokepoint covering over 20% of domains, changing the baseline for sites that never expressed a view.
021
michael veale @michae.lv · 07/08/2026
meta fears a google 'glasshole' style catchy moniker situation for their unpleasant new tech. perhaps it's time to strike fear into their corporate partner and make 'raybanned' a verb?
47425
michael veale @michae.lv · 07/08/2026
Cloudflare (>20% of all domains) has started automatically implementing DSM Dir art 4 rights reservation (ie copyright/TDM objection to scraping) for all sites that do not have a robots.txt file. They also adding purpose fields to robots.txt unilaterally. developers.cloudflare.com/bots/additio...
# As a condition of accessing this website, you agree to abide by the following
# content signals:

# (a)  If a Content-Signal = yes, you may collect content for the corresponding
#      use.
# (b)  If a Content-Signal = no, you may not collect content for the
#      corresponding use.
# (c)  If the website operator does not include a Content-Signal for a
#      corresponding use, the website operator neither grants nor restricts
#      permission via Content-Signal with respect to the corresponding use.

# The content signals and their meanings are:

# search:   building a search index and providing search results (e.g., returning
#           hyperlinks and short excerpts from your website's contents). Search does not
#           include providing AI-generated search summaries.
# ai-input: inputting content into one or more AI models (e.g., retrieval
#           augmented generation, grounding, or other real-time taking of content for
#           generative AI search answers).
# ai-train: training or fine-tuning AI models.
# use:      how AI systems may consume the content (immediate, reference, or full).

# ANY RESTRICTIONS EXPRESSED VIA CONTENT SIGNALS ARE EXPRESS RESERVATIONS OF
# RIGHTS UNDER ARTICLE 4 OF THE EUROPEAN UNION DIRECTIVE 2019/790 ON COPYRIGHT
# AND RELATED RIGHTS IN THE DIGITAL SINGLE MARKET.

# BEGIN Cloudflare Managed content
49143
michael veale @michae.lv · 06/08/2026
on protest and bluetooth mesh networking apps - india attempts to restrict source code to stop people circumventing internet shutdowns restofworld.org/2026/india-g...
restofworld.org
Why India asked GitHub to geoblock Jack Dorsey’s Bitchat code - Rest of World
Jack Dorsey’s Bluetooth messaging app surged during India’s internet blackout — and the government’s response suggests a new tech battleground.
042
michael veale @michae.lv · 05/08/2026
if i were in the lords i would submit a private members bill to remove " (Text with EEA relevance)" from the end of the titles of all assimilated EU law
030
michael veale @michae.lv · 05/08/2026
UCL Massively Crossreferenced Digital Laws now includes *pending preliminary references & AG Opinions* for all EU laws. Currently updates weekly. Based on Eurlex data which is a bit later to update than CURIA data (if you can even find it on the new website...) homepages.ucl.ac.uk/~ucqnmve/law...
List of 'before the court' and which preliminary references are before them, clickable, relating to the GDPR, 24 visibleLists 'before the court' and which preliminary references are before them, clickable
184
michael veale @michae.lv · 05/08/2026
$SPCX was, indeed, going to the moon www.yahoo.com/news/science...
yahoo.com
SpaceX rocket stage believed to have slammed into Moon
A four-tonne piece of a SpaceX rocket was believed to have unintentionally crashed into the Moon on Wednesday, a collision that posed no danger to Earth but is expected to leave behind a lunar crater....
110
michael veale @michae.lv · 05/08/2026
so much talk about the EU AI Act, but so little talk about the California AI watermarking provisions, SB 942, (extremely similar to the AIA) which became enforceable on the 2nd August
2117
Reposted by michael veale
Marijn Sax @marijnsax.bsky.social · 16/07/2026
Aan de KU Leuven lijken specifieke onderzoekslijnen te koop. Future of Life Institute – bruidschat van Musk en vooral Buterin à $660 miljoen – financieert een AI lab via een donatie en plaatst de *eigen policy director* aan het hoofd van het lab aan de KU Leuven. www.demorgen.be/niet-te-miss...
demorgen.be
Geld van Elon Musk en crypto-ondernemers voor KU Leuven: waarom het Future of Life Institute vragen oproept
Het kreeg miljoenendonaties van Elon Musk en crypto-ondernemers en luidt al jaren de alarmklok over de existentiële gevaren van AI. Wat is het Future of Life Institute, dat een nieuw AI-veiligheidslab...
2104
michael veale @michae.lv · 03/08/2026
You can now access many more digital laws, not just the GDPR, at the UCL Massively Crossreferenced Digital Laws page: EU: GDPR, DSA, DMA, AI Act, UCPD, NIS2 UK: OSA, DPA18, ...+ Each article/para/recital, links to what-cites-it in int'l cases/statutes/guidance homepages.ucl.ac.uk/~ucqnmve/law...
UCL Massively Crossreferenced Digital Laws

Varying digital legal instruments across jurisdictions, each able to be clicked on a section/article/paragraph basis to find the hard and soft law instruments that cite and interpret each specific part (or substantively very similar parts of previous/neighbouring laws.) Snippets provided for each citing source along with original links to that source. Typically thousands of citations for each. Citing documents can be ordered by date, citation numbers, or 'authority/influence' (PageRank algorithm).

Database of citing documents maintained and updated daily/weekly; the below documents intended to be updated weekly. Last update 3 August 2026.

Document coverage and national grammar for document detection is strongest and best tested for UK, Ireland, France, Germany, the Netherlands, EU and ECHR, but the database contains and attempts to link administrative decisions and guidance from other jurisdictions. Unlike Westlaw or other providers, this is not only free, with links to the originals, and incorporates a large amount of guidance and secondary material.

Documents generated from a dataset held and maintained by Michael Veale, Professor of Technology Law and Policy, Faculty of Laws, University College London. If you wish to study these instruments and the tech and practices that interact with them, consider learning about it at UCL Laws: on our LLM in Law and Technology, or our week-long executive education on AI for Lawyers: Technological Understanding for Compliance and Litigation.
55940
Reposted by michael veale
Rachel Coldicutt @rachelcoldicutt.bsky.social · 31/07/2026
My boiling hot take on this is that, if tech companies are going to fund this kind of research (looking at Schmidt too), then the money needs to be given *no strings* to an independent arm's length research body, pooled with other funding, and treated as a donation not as direct funding.
36822
michael veale @michae.lv · 30/07/2026
Parts of the GDPR are cited and interpreted by thousands of pieces of case law and guidance, but there's no easy and free way to find out what. We've made a tool which makes it super easy, for 13,000 citing documents, all in one place. More regulations to come! homepages.ucl.ac.uk/~ucqnmve/law...
Image of the interface, featuring Article 5 with citation counts per article and per paragraph.Image of the interface, featuring Article 17(3) with citation counts per article and per paragraph, and sources.
1611654
michael veale @michae.lv · 24/07/2026
that racoon is Getting Busy!
030
michael veale @michae.lv · 24/07/2026
now the AI Omnibus has been published, if you want to read a version with redline or a total consolidated version (not just the list of what has been deleted and added, which is what the omnibus is), i've published both recast and track-change versions on my website michae.lv/ai-act-as-am...
An illustration of the recast text at the available link showing that it has green text for new introduced text and red strikethrough text for that which has been removed. The link contains the machine readable text; strikethrough text cannot be put into an alt text on bluesky.
13014
michael veale @michae.lv · 01/07/2026
in the legislative proposal to expand the supreme court, could you please also tell them to publish HTML versions of their judgments? (you can still paginate them precisely, technology is amazing!). section 508 of the rehabilitation act called and it wants the judicial branch in scope.
0184
michael veale @michae.lv · 28/06/2026
genuine q: if ai coding is massively increasing engineers’ productivity why does software either feel the same or worse? where is this productivity actually going?
69320
michael veale @michae.lv · 22/06/2026
Information Compliance team at the House of Commons managed to send an incorrect email to 120,000 recipients (me included), ironically intended as an internal puff piece about how good their information compliance is www.whatdotheyknow.com/request/inco...
whatdotheyknow.com
Incorrect email recipients May 2026 - a Freedom of Information request to House of Commons
On May 28 2026 an email entitled “Information Compliance - FPP” was sent in error from the Finance, Portfolio and Performance Communications group. Please write back (FOI Act 2000) to tell me how ma...
2228
Reposted by michael veale
Eoin O’Dell @cearta.bsky.social · 18/06/2026
Michael, Michael, Michael … sigh It’s the CJEU; the line is: CJEU: provide necessary and proportionate protections for my Margaux
051
michael veale @michae.lv · 16/06/2026
UK: social media ban CJEU: hold my beer
1229
Reposted by michael veale
Jennifer Cobbe @jennifercobbe.bsky.social · 16/06/2026
Relying on Google Translate for this as the official translation isn't up yet - so this could be wrong - but the Court's position here (left) seems to be essentially what we argued in *2019* (right): ejlt.org/index.php/ej... If so, nice to see the Court catch up
CJEU judgment:

111 As the Advocate General observed, in essence, in point 239 of his Opinion, it is in particular by means of the algorithm used that such an operator exercises control over the information stored. As long as it has predetermined, by means of that algorithm, the conditions for the dissemination or not of such information, it is irrelevant that that operator does not itself carry out additional interventions having the effect of promoting, modifying or deleting information stored with a view to its dissemination.

112 In that regard, it must be stated that if, in addition to merely categorising and indexing the information with a view to making it more accessible, the algorithm used determines, in the interest of the operator or its service, under what conditions, in what manner and in what order of priority that information is or is not disseminated, That operator exercises control over those services, with the result that the service which it offers cannot be classified as an 'information society service consisting in the storage of information provided by a recipient of the service' within the meaning of Article 14(1) of Directive 2000/31 (see, to that effect, judgments of 23 March 2010, Google France and Google, C-236/08 to C-238/08, EU:C:2010:159, paragraphs 115 and 117; of 12 July 2011, L'Oréal and Others, C-324/09, EU:C:2011:474, paragraph 116, and of 22 June 2021, YouTube and Cyando, C-682/18 and C-683/18, EU:C:2021:503, paragraph 114).Extract from paper:

The situation is somewhat different in relation to open recommending of user-generated content, as service providers are unlikely, in most cases, to have knowledge of the content itself. Rather, they will have knowledge of metadata about the content – for example, information about which users have viewed or provided feedback or indications of its general ‘popularity’ (e.g. ‘likes’ or ‘shares’). However, in open recommending, service providers do exercise control over content. Indeed, control over content is the very point of recommending; service providers exercise such control in order to show people what they want them to see in order to drive engagement, profit, and market position. The normative nature of recommender systems – the fact that they enable platforms to exercise control over content distribution in pursuit of their own goals – is the reason for their use. 

In open recommending, service providers are not simply storing user content and displaying it neutrally in a merely technical or passive way. They control the criteria for recommending and thus they determine what is recommended in line with the outcomes that they desire. According to the CJEU, simply providing general information to users cannot itself be sufficient to deprive a service provider of the protection afforded to hosts . But, in recommending content, service providers do not provide general information – they provide and promote specifically selected information, determined by the service provider (by way of their algorithmic processes) on the basis of predicted relevance, interest, and so on to the user or groups of users in question. They therefore do not take a neutral position between the uploader of the content and the potential viewers ; rather, they are actively involved in selecting content for distribution and promotion according to their own criteria, in selecting the audience for that content according to their own determination, and, as a result, in s…
2105
michael veale @michae.lv · 16/06/2026
if journalists/bloggers are looking for people to comment in the news on today's CJEU intermediary liability judgment in WebGroup CZ and Coyote System, you should ask @jennifercobbe.bsky.social because 7 years ago she correctly predicted the CJEU's argument in this article: ejlt.org/index.php/ej...
ejlt.org
Regulating Recommending: Motivations, Considerations, and Principles | European Journal of Law and Technology
162
Reposted by michael veale
TJ McIntyre @tjmcintyre.com · 16/06/2026
The age verification aspect might be misleading - this seems to be just a restatement of the position under the e-commerce directive. But the decision on liability for algorithmic recommendation is *explosive*.
612977
Reposted by michael veale
Mylee Joseph @mylee.bsky.social · 03/06/2026
Martin Eve on Shadow Libraries, the pirate architectures and infrastructures that circumvent academic scholarly paywalls. dhdebates.gc.cuny.edu/read/critica...
dhdebates.gc.cuny.edu
0139
michael veale @michae.lv · 04/06/2026
This case brought by @awo.agency will have to deal with a few big questions: 1. how much platform input in content negates the user-to-user dimension that might usually grant intermediary shielding? 2. will English courts apply the logic of the CJEU in Russmedia or come to a different conclusion?
2108
michael veale @michae.lv · 04/06/2026
after Brexit, any of the pan-European PLC type company, the ‘Societas Europaea’, were converted into ‘UK Societas’. This is now a highly endangered species of legal person, with only seven active, and no way to form new ones.
031
michael veale @michae.lv · 03/06/2026
wow, save energy by not saying please or thank you to your AI. the individualistic ‘turn of the lights’ moment for LLMs. models use tools and hidden thinking that expend thousands of tokens in seconds. two or three tokens of nicety isn’t going to move the needle. www.newscientist.com/article/2529...
newscientist.com
Ditch the niceties in AI prompts to save energy use, say researchers | New Scientist
A UN report warns of the rapid growth in AI energy consumption, but suggests users can improve efficiency by making prompts more concise
2288
michael veale @michae.lv · 02/06/2026
on vibe coding as an ADHD multiplier — a strong, short blog on the author’s personal experience of building repeated things they don’t need as a form of pseudo productivity thoughts.hmmz.org/2026-05-31.h...
1195
michael veale @michae.lv · 01/06/2026
Peter Mandelson was asked for his Whatsapp messages on his phone but refused to hand them over. A legal minefield: @vmantouvalou.bsky.social and I have written about it here in 'Bring Your Own Device — Now Hand It Over!' digitalcommons.osgoode.yorku.ca/cllpj/vol45/...
The explanatory notes at the start of the document dump explains that "on 31 March the [Cabinet Office] wrote to Peter Mandelson - via his solicitors - to request any information held on his personal phone.

"Peter Mandelson declined to comply with this request. The government has no further recourse to search the personal devices of Peter Mandelson."
086
Reposted by michael veale
Follow the Money EU @ftm.eu · 30/05/2026
Cloudflare protects a quarter of the internet from cyberattacks, including Follow the Money. The downside? The US tech giant needs access to an enormous amount of sensitive data to do so. That’s why we’re switching to a European alternative.
ftm.eu
FTM ditches US cybersecurity firm over surveillance and privacy fears
Follow the Money has parted ways with tech giant Cloudflare. The US company protects a quarter of the internet from cyberattacks. The downside: to do so, it needs access to sensitive data. FTM is now switching to a European alternative.
24222
Reposted by michael veale
Andrea Matwyshyn @andreamm.bsky.social · 30/05/2026
Unfortunately, it looks like it's time for me to repost my article about the relationship between First Amendment protection and security research (again). IYKYK. scholarlycommons.law.northwestern.edu/nulr/vol107/...
scholarlycommons.law.northwestern.edu
Hacking Speech: Informational Speech and the First Amendment
By Andrea M. Matwyshyn, Published on 01/19/15
165
michael veale @michae.lv · 30/05/2026
Meta's latest attempt to stop the progress of my 2018 GDPR access complaint dramatically failed in the Irish High Court last week www.irishtimes.com/business/202...
irishtimes.com
Meta loses High Court challenge to possible €430m fine
Data Protection Commission has power in inquiry into individual complaint to make orders affecting general data access practices, High Court rules
527776
michael veale @michae.lv · 29/05/2026
In Memoriam: Prof William Twining currentlegalproblems.org/article/in-m... (Philip Schofield, David Sugarman, Jane Holder)
120
Reposted by michael veale
UCL Faculty of Laws @laws.ucl.ac.uk · 15/05/2026
Can law stop criminals misusing #AI? 🤔 Join us for a free online open event with Prof Michael Veale (@michae.lv) exploring AI, technology law and digital regulation - followed by an intro to our new LLM Law and Technology specialism and Q&A. 📅 10 June, 12:00–13:00 BST 🔗 Register: shorturl.at/pEHAH
ucl.ac.uk
‘Can Law Stop Criminals Misusing AI?’ – UCL Master of Laws (LLM) online open event
Join UCL Laws for an online LLM open event with Professor Michael Veale exploring AI, technology law and digital regulation, followed by a UCL Master of Laws (LLM) introduction and Q&A
024
Reposted by michael veale
anil oza @aniloza.bsky.social · 14/05/2026
wow — the preprint host, arxiv, is banning authors for a year if they submit papers with hallucinated citations 🤖
Twitter thread from Thomas Dietterich, reading "Attention 
@arxiv
 authors: Our Code of Conduct states that by signing your name as an author of a paper, each author takes full responsibility for all its contents, irrespective of how the contents were generated. 1/
3:03 PM · May 14, 2026
·
66.7K
 Views
Relevant
View quotes

Thomas G. Dietterich
@tdietterich
·
1h
If generative AI tools generate inappropriate language, plagiarized content, biased content, errors, mistakes, incorrect references, or misleading content, and that output is included in scientific works, it is the responsibility of the author(s). 2/
Thomas G. Dietterich
@tdietterich
·
1h
We have recently clarified our penalties for this. If a submission contains incontrovertible evidence that the authors did not check the results of LLM generation, this means we can't trust anything in the paper. 3/
Thomas G. Dietterich
@tdietterich
·
1h
The penalty is a 1-year ban from arXiv followed by the requirement that subsequent arXiv submissions must first be accepted at a reputable peer-reviewed venue. 4/
Thomas G. Dietterich
@tdietterich
·
1h
Examples of incontrovertible evidence: hallucinated references, meta-comments from the LLM ("here is a 200 word summary; would you like me to make any changes?"; "the data in this table is illustrative, fill it in with the real numbers from your experiments") end/"
9458131915
michael veale @michae.lv · 13/05/2026
“It has not been a productivity booster at all, it feels like a speedrun towards severe mental exhaustion” www.404media.co/software-dev...
404media.co
Software Developers Say AI Is Rotting Their Brains
“It's making me dumber for sure.”
0147
michael veale @michae.lv · 12/05/2026
more Hugging Face content moderation challenges — the model marketplace finds itself hosting infostealers disguised as legitimate models www.heise.de/en/news/Info...
heise.de
Infostealer on AI platform Hugging Face disguised as OpenAI repository
The Open-OSS/privacy-filter repository contained an infostealer and was downloaded over 240,000 times before Hugging Face removed it.
093
michael veale @michae.lv · 12/05/2026
Digital Markets Act sees jump in alternative browser usage on Android and iOS due to choice screens, says Firefox blog.mozilla.org/netpolicy/20...
graph showing increase in firefox on android after the dma graph showing increase in firefox for ios after the dma
042