Michael Veale
Professor of Technology Law and Policy at University College London (#UCL), Faculty of Laws.
Not resigned to today's technological power structures (yet). Researching at the intersection of emerging technologies, law and policy; data protection; machine learning; PETs and cryptographic infrastructures; platform and infrastructural regulation. 🏳️🌈
administrating a small exoplanet in the fediverse
.

on vibe coding as an ADHD multiplier — a strong, short blog on the author’s personal experience of building repeated things they don’t need as a form of pseudo productivity https://thoughts.hmmz.org/2026-05-31.html
Information Compliance team at the House of Commons managed to send an incorrect email to 120,000 recipients (me included), ironically intended as an internal puff piece about how good their information compliance is https://www.whatdotheyknow.com/request/incorrect_email_recipients_may_2#incoming-3456681
genuine q: if ai coding is massively increasing engineers’ productivity why does software either feel the same or worse? where is this productivity actually going?
AI overviews pulling in through RAGs old gov pages that are there for archiving and poserity, wreaking havoc. DoE advises to “design w/ the expectation that much of what we publish will be [..] atomized, summarized or reinterpreted by systems we don't control”
https://www.theregister.com/2026/04/23/stale_govuk_pages_are_feeding/
wow, save energy by not saying please or thank you to your AI. the individualistic ‘turn off the lights’ moment for LLMs. models use tools and hidden thinking that expend thousands of tokens in seconds. two or three tokens of nicety isn’t going to move the needle. https://www.newscientist.com/article/2529017-ditch-the-niceties-in-ai-prompts-to-save-energy-use-say-researchers/?utm_campaign=RSS%7CNSNS&utm_source=NSNS&utm_medium=RSS&utm_content=technology
Stable Firefox identifier (the order of a set of IndexedDB databases) allowed cross-site linkage within a single browsing session, private window or not — also in the Tor Browser https://fingerprint.com/blog/firefox-tor-indexeddb-privacy-vulnerability/
“It has not been a productivity booster at all, it feels like a speedrun towards severe mental exhaustion” https://www.404media.co/software-developers-say-ai-is-rotting-their-brains/
UK: social media ban
CJEU: hold my beer
The techlash against AI amongst the young – early signs, but culturally something to watch. https://www.theverge.com/ai-artificial-intelligence/920401/gen-z-ai
Palantir sells AI tool to the Met Police to discover bent coppers, trawls over presumably IT & telemetry data that few look at, starts hundreds of investigations for non compliance, WFH, roster fraud, and dozens related to… undeclared membership of the Freemasons? https://www.theguardian.com/uk-news/2026/apr/25/met-police-investigates-hundreds-officers-palantir-ai-tool
Canvas pays presumably enormous ransom to end extortion of universities and schools — receives questionable promise that data has been deleted. Moodle less of a monoculture but unis must harden it, possibly rebuild from the ground up in something other than PHP… https://www.theregister.com/security/2026/05/12/double-canvas-intrusion-confirmed-as-shinyhunters-resets-leak-deadline/5238361
Amazon employees race to automate non-essential tasks to expend tokens to impress managers on internal AI usage leaderboards. Great outcome, all. https://giftarticle.ft.com/giftarticle/actions/redeem/4965c8a3-169e-4815-bd1b-16f5e9a22e70
Musk’s xAI rapidly appoints an EU representative for the DSA following Grok investigation, choosing an entity with an address in Estonia but no registered presence in the country. https://www.ftm.eu/articles/elon-musk-ai-company-basement-address @fantafanta@mastodon.social
‘Going to the cloud’: renting servers, or integration of deeply proprietary services? “both options go by the same name, and organizations often slide from the first into the second without realizing the fundamental difference, until it’s too late” - @C__CS@someone.elses.computer https://www.tandfonline.com/doi/full/10.1080/1369118X.2026.2645879#d1e228
more backlash to scraping, this time to Common Crawl — a notoriously intransparent org for what they moderate (if they moderate, or eg remove csam) or what they include https://www.bloomberg.com/news/articles/2026-04-30/news-organizations-push-back-against-web-archive-used-for-ai
Firefox raises the alarm about Google’s attempt to build ‘Prompt API’ into Chrome-like browsers — de facto standardisation towards local Gemini models, required agreements to terms of use despite being local — a Chrome infrastructure play all over again? https://www.theregister.com/2026/04/30/mozilla_pushes_back_against_googles/
more Hugging Face content moderation challenges — the model marketplace finds itself hosting infostealers disguised as legitimate models https://www.heise.de/en/news/Infostealer-on-AI-platform-Hugging-Face-disguised-as-OpenAI-repository-11290946.html
after Brexit, any of the pan-European PLC type company, the ‘Societas Europaea’, were converted into ‘UK Societas’. This is now a highly endangered species of legal person, with only seven active, and no way to form new ones.
EDPB writes to the Commission to ask whether they are reconsidering Israel's data protection adequacy agreements following Israeli law requiring EEA humanitarian orgs in Palestine to provide a lot of personal data on their staff, including their spouses/kids https://www.edpb.europa.eu/system/files/2026-04/edpb_letter_20260420_regarding_ingo_registration_requirements_en.pdf
Astounding story from @FTM_nl@social.ftm.nl: An administrative judge in the Netherlands sent 4000 deliberately crippling FOI requests to municipialities just to see what would happen, because he had a 'feeling' abuse was possible, and... potentially to do a PhD on it, although he doesn't seem to have thought through the research design much. https://www.ftm.nl/artikelen/mysterieuze-indiener-duizenden-informatieverzoeken-blijkt-rechter-die-misbruik-wet-wil-aantonen
It seem that archive.today has been blocked at some technical level by an order by the Roskomnadzor — seemingly from laws cited not for piracy (these sites, and their .is and .ph domains, avoid paywalls) but under disinformation law — they are often used to document/subvert Russian media censorship.
Republicans introduce ‘Secure Data Act’, an attempt to copy some of the weakest US state privacy laws and apply them across the country to eg pre-empt the strong ones like California or Colorado. No private right of action, 45 day ‘curing’ period for any violations. https://www.cnbc.com/2026/04/22/data-privacy-bill-congress-states.html
Interesting read on how business models and imaginaries of future engineering tasks are competing, and which AI firms are placing bets on different directions to act as their new platform ‘moat’ https://thenewstack.io/ai-agent-harness-pricing-split/
Many voters who use big, old platforms may rarely see age verification practices and not be aware of invasiveness, as such platforms (Apple already does) use age of account as a proxy and never check more. Younger users get no such benefit. good for data minimisation, but keeps people in a bubble.
really useful primer on data, ai and trade law from @streinz@someone.elses.computer https://www.cambridge.org/core/books/abs/cambridge-companion-to-world-trade-law/conceptualising-data-and-artificial-intelligence-in-world-trade-law/1D280F68D70CFBA9E0171B8C15939BCF especially good if the issue comes up in teaching
A good start to a proposal for reviews, requiring authors of submitted papers to expend tokens to submit and earn them back through reviewing. Needs to be more radical though in light of AI slop: cap on total submissions, earn further at steep rate through reviewing. https://dl.acm.org/doi/10.1145/3770921
Still waiting for the AI Act advisory forum (Art 67), meanwhile the all important, de facto compulsory, privatised harmonised standards, made without democratic process (yet part of EU law), charge ahead. EC opines on their suitability without civil society input or views. https://edri.org/our-work/the-eu-ai-office-must-prioritise-setting-up-the-advisory-forum/
More TV specific US privacy law, this time from Kentucky, as ‘smart television’ data is determined as sensitive by HB 692 https://apps.legislature.ky.gov/recorddocuments/bill/26RS/hb692/bill.pdf
vibes of the 1988 Video Privacy Protection Act 1988, specifically protecting eg Blockbuster history https://www.congress.gov/bill/100th-congress/senate-bill/2361
Interesting recent blog on reverse engineering Google SynthID (images) and adding fake watermarks in that Google detects. Also on the stupidity of making Gemini the detector, as it hallucinates its own detection capabilities… https://hackerfactor.com/blog/index.php?/archives/1092-Reversing-SynthID.html
Google marks all Gemini-created text with its SynthID text watermarking system. They have released public detectors for media. They have not for text, and they have not publicly said why they haven't. Regulators and legislators should ask them.
the Court of Appeal massively rejects the High Court’s finding in RTM v Bonne Terre (Sky Bet) that marketing/cookie consent might be invalid as the gambling firm is aware this person is a vulnerable gambler close to the regulatory exclusion threshold. https://caselaw.nationalarchives.gov.uk/ewca/civ/2026/488
Some injunctive success against ICE tracking app store takedowns pressured by the US DoJ. Law not very good at constraining implicit state power and threats though, esp where plaintiff isn’t the threatened party. Incentive to kiss the ring can be too great. https://www.theverge.com/policy/914619/trump-administration-violated-first-amendment-ice-tracking
Florida AG launches criminal investigation into OpenAI for aiding and abetting the 2025 FSU gunman https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeier-launches-criminal-investigation-openai-chatgpt
in the legislative proposal to expand the supreme court, could you please also tell them to publish HTML versions of their judgments? (you can still paginate them precisely, technology is amazing!). section 508 of the rehabilitation act called and it wants the judicial branch in scope.
Short report from one of @Alina Trapova’s copyright rights holders roundtables @at UCL Laws — the slow trudge towards licensing as fair use and similar exemptions internationally become harder to defend. But how will it work; and cui bono? https://legalblogs.wolterskluwer.com/copyright-blog/report-on-a-roundtable-on-music-generative-ai-and-copyright-at-the-ucl-institute-of-brand-and-innovation-law/
2 year research postdoc at UCL Laws on data and democracy, public law focus — could focus on surveillance and/or AI issues https://www.ucl.ac.uk/work-at-ucl/search-ucl-jobs/details?jobId=43885&jobTitle=Research+Fellow+%28Data+and+Democracy%29
In Memoriam: Prof William Twining https://currentlegalproblems.org/article/in-memoriam-prof-william-twining/ (Philip Schofield, David Sugarman, Jane Holder)





