This briefing report uncovers claims across issues about surveillance, online speech and AI oversight, alongside a major court ruling on copyright information in generated code. Governments are proposing wider powers over data and online content and lawmakers are pressing for stronger AI oversight. Each development has a defensible purpose. Each also demands evidence about how decisions will be made and who can challenge them. This briefing report examines the distance between a rule’s promise and its likely effect on the people who use, or are affected by, digital services.
Newsletter Edition 101
🔥 This edition includes important updates and news in technology law from Canada, European Union, China, the United States and the United Kingdom. Access the latest opportunities, including remote jobs in technology law, internships, and call for papers.
This Week in Technology Law:
1. Canada and the European Union: European digital rights groups urged the EU to challenge Canada’s proposed Bill C-22. They warn its surveillance capability and data retention provisions could weaken encryption and reach European users. Those are the groups’ concerns; the bill remains under consideration.
2. China: The cyberspace regulator publicised a further crackdown on online malicious posts about companies, reporting over 1.56 million removals and 26,000 accounts penalised during the campaign. Authorities cite false allegations and extortion; the scale raises questions about how legitimate corporate criticism is distinguished.
3. Australia and the United States: The US government publicly challenged Australia’s proposed digital duty of care for online services, warning that broad definitions of harm could encourage censorship and affect Americans’ feeds. Prime Minister Anthony Albanese defended the proposal as a way to improve online safety and user control.
4. The United Kingdom: Parliament’s Joint Committee on Human Rights called for an AI Bill covering the full development and deployment cycle. It proposed risk based duties, stronger transparency, prior approval for certain high risk systems, and a regulator with enforcement powers.
5. Case Note (United States): In Doe v GitHub, No. 24-7700 D.C., No. 4:22-cv-06823- JST, the Ninth Circuit upheld dismissal of programmers’ Digital Millennium Copyright Act claims concerning Copilot and Codex outputs. The court held that the pleaded output theory did not show removal of copyright information from an existing work; contract claims remain pending.
Lead Story
Canada and the European Union: A surveillance Bill becomes a European concern
A group of European civil society organisations asked European officials to challenge Canada’s proposed Lawful Access Act, known as Bill C 22. The organisations want its provisions on technical access and data retention removed or narrowed. They also want European officials to raise the issue during digital trade discussions with Canada. Canada’s Parliament records the bill as having passed the House of Commons and awaiting further consideration in the Senate. The proposal remains under consideration.
Canada presents lawful access as a way to help authorised investigators obtain information. The European signatories focus on what providers might have to build or retain.
Their letter indicates the bill could require providers to develop capabilities that facilitate government access and to keep information about communications. It argues that a demand directed at one company might affect people outside Canada, including people using services provided by European businesses. Those consequences are the signatories’ assessment of the proposed powers.
Encryption protects the contents of messages. Information about a communication can reveal who contacted whom and when. Records of contacts can be sensitive even if the conversation itself stays private.
A law can therefore affect privacy without requiring a provider to hand over readable message text. The signatories question the bill’s safeguards and ask the EU to examine continued transfers of personal data to Canada.

The central issue is how much authority investigators can receive without requiring providers to introduce security risks or retain information on people who are not under investigation.
Canada’s c-22 Bill tests whether domestic surveillance powers can require providers with international operations to retain data or alter security practices affecting users abroad, making the scope of access orders and protection of encrypted communications matters of concern for European lawmakers.
Technology Law: Updates and Developments
China: Scrutiny of false information about companies
China’s cyberspace regulator have allegedly reported further action under a campaign targeting online information about businesses. It said regulators and major platforms had removed more than 1.56 million posts described as infringing business interests and taken action against more than 26,000 accounts during the campaign. It identified accounts accused of false claims, demanding payments to remove material, and circulating negative stories.
There is a clear public interest in stopping fabricated product claims and demands for money backed by threats of false publication. The announcement also describes action against accounts that repeatedly gathered or revived negative business news.
What we can gather from this story is that fewer false claims may improve a search for information about a product or employer. However, a broad removal of business criticism could make that same search less informative. The campaign’s credibility should therefore depend on the reasons for removals, correction of mistakes, and room for substantiated consumer reporting.
Australia and the United States: An online safety proposal draws a censorship warning
Australia has circulated a draft digital duty of care for online services. It would require platforms to take greater responsibility for foreseeable harms, including risks to children.
On 22 September, the United States publicly objected during the Australian consultation, arguing that broad definitions of harm could encourage platforms to suppress lawful speech. It sought exemptions for American platforms.
Prime Minister Anthony Albanese defended the proposal as giving users more control.
United Kingdom: Parliament calls for an AI Bill
The UK Parliament’s Joint Committee on Human Rights has called for a legislation governing artificial intelligence. The report recommends rules that apply from the design of an AI system through its use.
It also calls for people to be told when AI plays a part in important decisions, given a clear way to challenge harmful outcomes, and protected by prior approval requirements for systems that pose serious risks. It also wants an oversight body able to test systems and enforce rules.
A person affected by an automated decision may know little about the system used or which organisation can correct an error. The organisation using the system may have purchased it from a developer that controls important design choices.
The report argues that duties should reach those responsible at different stages, with heavier requirements where the likely harm is greater. It also proposes restrictions on some uses involving profiling, biometric information, or techniques that undermine a person’s ability to choose freely.
This is a parliamentary recommendation. Any future bill will have to address how people learn about important decisions, challenge mistakes, and obtain a correction.
Case Note
Case: Doe v. GitHub, Inc.
Citation: United States Court of Appeals for the Ninth Circuit, opinion filed 16 September 2026.
Material facts
Programmers published code in public GitHub repositories with notices identifying the authors and setting out licence terms. They alleged that GitHub Copilot and Codex, tools trained on public code, sometimes produced portions of their work without those notices. They sued GitHub, Microsoft, and several OpenAI entities.
The programmers pointed to examples of reproduced code, research showing that AI tools can reproduce training material, and a GitHub feature that blocks some suggestions matching public code. The court considered these allegations at an early stage of the case. It did not decide whether any particular output infringed copyright.
Brief explanation of the dispute
The programmers claimed that producing code without its original attribution violated a provision of the Digital Millennium Copyright Act concerning the removal of copyright management information. The companies argued that generating an output without a notice was different from removing a notice attached to an existing work.
The district court dismissed this statutory claim but allowed the programmers’ contract claims to continue. The programmers appealed the dismissal.
Legal issue
The provision applies when copyright management information is removed or altered in connection with an existing protected work. The issue was whether the programmers had alleged that the tools removed information from their code, or that the tools generated outputs that did not include that information.
The appeals court also clarified that a claim does not require the disputed output to be identical to the original work. A substantial copy with its attribution removed could still support a claim.
What the court considered
The court examined whether the facts alleged were sufficient to support the programmers’ claim under the Digital Millennium Copyright Act. It also considered whether the programmers had a sufficient stake to bring the claim. The court found that their allegations showed a plausible risk of harm, allowing it to consider the claim.
The programmers raised a separate argument about information allegedly removed when code entered the training process. The appeals court did not decide that argument because it had not been properly maintained in the proceedings under review.
Final decision
The Ninth Circuit upheld the dismissal of the claim concerning the tools’ outputs. As the complaint described them, Copilot and Codex used patterns learned from existing code to generate responses. The court found that this account did not allege an act of removing copyright information from a copy that already carried it.
The decision addressed this particular statutory claim. The judges did not decide whether a sufficiently similar output could infringe copyright under another provision of law. The programmers’ contract claims also remained pending.
The distinction is the key to the ruling: missing attribution can raise a serious concern, but this claim required allegations that attribution had been removed or altered on an existing work. The court found that the programmers’ account of the generated outputs did not meet that requirement.
Latest Opportunities
Remote technology law jobs
1. Legal Counsel, Privacy, TRM Labs (Remote - Germany, Netherlands, Sweden, UK): Lead privacy advice for a technology product used in financial crime investigations and work with product and engineering teams.
2. Legal Counsel, Datatonic (Remote - UK): Handle agreements and legal matters for an AI and data business, including data protection compliance.
3. Legal Counsel, Privacy, TRM Labs (Remote - US): Lead privacy advice for a technology product used in financial crime investigations and work with product and engineering teams.
4. Policy Strategist, Nava (Remote - US): Interpret public programme rules and regulatory requirements for government technology services. Medicaid policy experience is required.
Conferences, fellowships, events and calls for papers
5. Funded AI policy fellowship: The Institute for AI Policy and Strategy’s Spring 2027 fellowship is accepting applications until 27 September 2026. It runs for three months and offers a stipend.
6. Law and technology submissions: BILETA 2027 welcomes abstracts on AI, privacy, digital markets, cybersecurity and related subjects until 13 November 2026. The conference takes place in Glasgow.
7. Privacy conference submissions: CPDP 2027 welcomes papers on privacy and digital governance until 15 November 2026 and panel proposals until 30 November. The conference takes place in Brussels in March 2027.
Final summary
These developments place considerable power in the hands of organisations that decide what information is collected, retained, displayed, or removed. Clear legal limits matter most when a decision affects people who cannot inspect the underlying system.
The Canadian bill is still under scrutiny, the Australian proposal remains a draft, and the British committee has recommended legislation rather than enacted it.
That leaves room for a serious public discussion about safety, privacy, free speech, and due attributions to creators.








