⚡ Week in Review: June 18–24, 2026

Chinese Edition

AI and Web3 Weekly Legal Briefing

Cross-Border AI and Fintech Practice — United States · New York · California · China · Hong Kong · European Union

 

I. Key Developments and New Legislation This Week

Legislative activity was relatively quiet this week; accordingly, this section covers only genuine new developments from June 18 to 24. Previously reported deadlines and ongoing matters are included in the summary table in Section II.

U.S. Federal — Web3

CLARITY Act: Section 604 Emerges as the Decisive Provision.

The Digital Asset Market Clarity Act remains on the Senate calendar without having been brought to a full Senate vote; however, this week’s controversy has centered onSection 604(i.e., the Blockchain Regulatory Certainty Act), which confirms that non-custodial developers who do not control user funds are not money transmitters. More than 60 crypto asset industry CEOs (from Coinbase, Uniswap, Kraken, a16z crypto, and Paradigm) jointly sent a letter to Senate leadership stating that this provision is a non-negotiable precondition for their support of the bill. Meanwhile, an anti-human trafficking coalition, representing 82 Catholic leaders, sent a letter to Senate Majority Leader Thune and Minority Leader Schumer requesting the deletion of this provision. The White House Crypto Council convened the National Sheriffs’ Association, the Fraternal Order of Police, and the National District Attorneys Association to address law enforcement’s objections.

United Kingdom — Web3 (Cross-Border Considerations)

Bank of England FinalizesSystemic StablecoinFinal Policy (June 22).

The Bank of England has removed the originally proposed single-user holding cap, replacing it with a £40 billion aggregate issuance cap for each systemic stablecoin, and has relaxed reserve requirements (up to 70% may be held in short-termUKgovernment bonds, with the remaining 30% in non-interest-bearing central bank deposits). This is of reference value to clients engaged in multi-jurisdictional stablecoin businesses.

Litigation — New Frontiers in AI Infringement

The following three cases demonstrate that AI liability is extending from copyright law to product liability, child protection, and criminal liability for developers. All three cases are summarized in the table below.

(1)Grok Child Sexual Abuse Material (CSAM) Class Action — Initial Case Management Conference Held (June 18).

In Doe 1 et al. v. X.AI Company (CaliforniaNorthern District Court, San Jose; Case No. 5:26-cv-00772, presiding Judge P. Casey Pitts), three minor plaintiffs (represented by the law firm Lieff Cabraser) allege that xAI its Grok knowingly generated, possessed, and distributed AI child sexual abuse material targeting them. The complaint points to Grok the less restrictive "Spicy Mode" filter and Grok the Imagine image-to-video tool, alleging that these tools can generate sexualized content from real photographs; and further alleges that xAI by Grok licensing to third-party applications, thereby profiting from such content, with the relevant images subsequently disseminated on Discord, Telegram, and file-sharing websites. The causes of action are based on the Masha Act(18 U.S.C. § 2255), the Trafficking Victims Protection Act, andCalifornialaw, seeking compensatory and punitive damages and injunctive relief. This week’s hearing established the litigation schedule; attention should be paid to early rulings on Section 230 and product design, which may define platforms’ liability for synthetic CSAM content.

(2) Wave of wrongful-death and product-liability lawsuits concerning OpenAI’s chatbot (April–May 2026).

The core case is Raine v. OpenAI (filed in the Superior Court of San Francisco in August 2025; counsel: Jay Edelson): The parents of a 16-year-old allege that ChatGPT (GPT-4o) exacerbated their child’s suicidal ideation and discouraged help-seeking, even though OpenAI its own moderation system had flagged hundreds of self-harm messages. In April–May 2026, additional suits emerged, including claims by families connected to the school shooting in Tumbler Ridge, British Columbia (alleging that the account had been flagged but recommendations to refer it to law enforcement were overridden), families of victims of the Florida State University shooting, a Texas family, and the Soelberg murder-suicide case in Connecticut (naming OpenAI and Microsoft as defendants, alleging that they reinforced “paranoid delusions”). Their common theory—asserting negligence and defective design directly against the model developers—constitutes a new category of AI liability risk.OpenAI defenses focus on pre-existing risks and violations of the terms of use.

(3) Tornado Cash—Roman Storm motion for rehearing (scheduled for approximately October 5/12).

In the United Stateslawsuit Roman Storm (U.S. District Court for theSouthern District of New York): After Storm was convicted in August 2025 under 18 U.S.C. § 1960(b)(1)(C) (operating an unlicensed money transmitting business), the Department of Justice moved on March 10 for a retrial on two counts on which the jury had hung—conspiracy to commit money laundering and conspiracy to violate sanctions under the International Emergency Economic Powers Act (IEEPA). This retrial (with a potential maximum aggregate sentence of up to 40 years) serves as a real-world test case for whether non-custodial developers may bear criminal liability for developing privacy software that is subsequently misused by others, and lies at the heart of the debate over Section 604 of theCLARITY ActArticle 604the core of the dispute.

 

II. Summary Table — Ongoing and New Developments

Items under the “As of” column are displayed in bold by date; matters marked as “Ongoing” were previously reported and are retained here for tracking purposes.

 

III. Compliance Action Recommendations

Actions AI Enterprises Should Take Now

• China — July 15 (approximately 21 days): Complete a compliance gap analysis for the Interim Measures for Personalized AI Interactive Services—AI pop-up notices, two-hour rest reminders, dependency detection, and prohibition of companion features directed at minors. No grace period. Verify CAC filing; reporting channels are now live.

• European Union — August 2: Ensure GPAI technical documentation, capability assessments, and systemic risk assessments are in place; consider signing the Code of Practice as the fastest path to meeting the transparency requirements under Article 50.

 United States — Litigation risk (new): In light of GrokCSAM litigation and OpenAI the surge in tort lawsuits, review security upgrades and content moderation processes, retain records of model safety decisions and overrides, and incorporate CSAM safeguard controls and event logging into the generative pipeline.

• United States — Colorado: Do not structure operations based on the repealed June 30 high-risk criteria; instead, adjust to the “disclosure + rights” ADMT framework under SB 189 (effective January 1, 2027).

Actions Web3 Enterprises Should Take Now

• European Union — MiCA July 1 (urgent, approximately 7 days): Confirm by July 1 MiCA authorization; if no license has been obtained, prepare an immediately executable wind-down or customer migration plan, and review stablecoin support (USDT is effectively restricted on compliantEuropean Unionplatforms, with USDC as the default option).

• United States — CLARITY Actand Developer Liability: Map token portfolios against CFTC/SEC classifications; and distinguish between “building” and “operating”: front-end maintenance, fee mechanisms, and ongoing support may transform protected code writing into accountable “conduct” under §1960(b)(1)(C)—i.e., the prosecution theory in the Storm case. Closely monitor the October rehearing.

• United States — GENIUS Act: If issuingU.S.payment stablecoins, confirm 100% reserves in eligible liquid assets in accordance with the OCC’s proposed rules, and implement reserve audits and public attestation.

• Hong Kong — Stablecoin license: Ensure that reserve documentation, governance, and AML/KYC programs are up to date; entities that have not yet applied should promptly assess eligibility. It is essential to maintain a firewall with mainland China.

This briefing is for informational purposes only and does not constitute legal advice. Certain litigation matters involve sensitive topics (self-harm and child exploitation) and are summarized solely at the level of factual allegations. If you require AI legal governance or Web3 digital asset compliance support, please feel free to contact our attorneys. Thank you!

Mankun Law Firm (Mankun Law PLLC)

Contact email: Joanna.fan@mankunlaw.com

        

English Version

AI & Web3 Weekly Legal Newsletter

Cross-Border AI and Fintech Practice — United States · New York · California · China · Hong Kong · EU

 

1.  This Week — News & New Laws

A relatively quiet legislative week, so this section is limited to genuinely new developments in the June 18–24 window. Deadlines and ongoing matters previously reported appear in the Summary Table (Section 2).

U.S. Federal — Web3

CLARITY Act: Section 604 becomes the make-or-break issue.

The Digital Asset Market Clarity Act stayed on the Senate calendar with no floor vote, but the fight crystallized this week around Section 604 (the Blockchain Regulatory Certainty Act), which confirms that non-custodial developers who do not control user funds are not money transmitters. 60-plus crypto CEOs (Coinbase, Uniswap, Kraken, a16z crypto, Paradigm) wrote to Senate leadership calling it a non-negotiable condition of support, while the Alliance to End Human Trafficking delivered a letter from 82 Catholic leaders to Leaders Thune and Schumer urging its removal, and the White House Crypto Council convened the National Sheriffs’ Association, Fraternal Order of Police, and National District Attorneys’ Association over law-enforcement objections.

United Kingdom — Web3 (cross-border)

Bank of England finalises systemic-stablecoin policy (June 22).

The BoE dropped per-user holding limits in favour of a temporary £40 billion issuance cap per systemic stablecoin, and softened reserve rules (up to 70% short-term UK gilts, 30% non-interest-bearing central-bank deposits). Relevant for clients running multi-jurisdiction stablecoin operations.

Litigation — A New AI-Tort Front

Three matters illustrate how AI exposure is moving beyond copyright into product liability, child-safety, and developer criminal liability. All three are tracked in the table below.

(1) GrokCSAM class action — first case-management conference held (June 18).

In Doe 1 et al. v. X.AI Corp. (N.D. Cal., San José; No. 5:26-cv-00772, Judge P. Casey Pitts), three minor plaintiffs — represented by Lieff Cabraser — allege that xAI’s Grok knowingly generated, possessed, and distributed AI-generated child sexual abuse material depicting them. The complaint targets Grok’s less-filtered “Spicy Mode” and the Grok Imagine image-to-video tool, which allegedly produced sexualized content from real photographs, and further alleges xAI profited by licensing Grok to third-party apps that generated such material, which then spread via Discord, Telegram, and file-sharing sites. Claims arise under Masha’s Law (18 U.S.C. §2255), the Trafficking Victims Protection Act, and California law, seeking compensatory and punitive damages plus injunctive relief. This week’s conference sets the schedule; watch for early Section 230 and product-design rulings that could define platform liability for synthetic CSAM.

(2) Chatbot wrongful-death / product-liability wave against OpenAI (April–May 2026).

The anchor case is Raine v. OpenAI (San Francisco Superior Court, filed Aug. 2025; counsel Jay Edelson), where the parents of a 16-year-old allege ChatGPT (GPT-4o) encouraged their son’s suicidal ideation and discouraged help-seeking even as OpenAI’s own moderation flagged hundreds of self-harm messages. A wave of further suits followed in April–May 2026: families connected to the Tumbler Ridge (BC) school shooting (alleging a flagged account and an overridden referral to law enforcement), a Florida State University shooting victim’s family, a Texas family, and the Soelberg murder-suicide in Connecticut (naming OpenAI and Microsoft over alleged reinforcement of “paranoid delusions”). The unifying theory — negligence and defective design aimed at the model developer itself — is a genuinely new category of AI exposure. OpenAI’s defenses emphasize pre-existing risk and terms-of-use violations.

(3) Tornado Cash — Roman Storm retrial sought (set ~Oct. 5/12, 2026).

In U.S. v. Roman Storm (S.D.N.Y.), DOJ moved on March 10 to retry the two hung counts — conspiracy to commit money laundering and to violate IEEPA sanctions — after Storm’s August 2025 conviction under 18 U.S.C. §1960(b)(1)(C) for operating an unlicensed money-transmitting business. The retrial (combined exposure up to 40 years) is the live test of whether a non-custodial developer can be criminally liable for building privacy software that others misuse, and it sits at the center of the CLARITY ActSection 604 debate. A full memorandum on this case is available.

 

2.  Summary Table — Ongoing & New Developments

Deadlines are bolded by date. Items marked “Ongoing” were reported previously and are retained here for tracking.

 

3.  Call to Compliance Actions

What AI Companies Should Do Now

• China — July 15 (~21 days): Complete a gap analysis against the Anthropomorphic AI Interim Measures — pop-up AI disclosures, two-hour break prompts, dependency detection, and a ban on companion features for minors. No grace period. Verify CAC registration; a public reporting channel is now live.

• EU — August 2: Ensure GPAI documentation, capability evaluations, and systemic-risk assessments are complete; consider signing the Code of Practice as the fastest path to Article 50 transparency compliance.

• U.S. — Litigation exposure (new): In light of the GrokCSAM action and the OpenAI tort wave, audit safety-escalation and content-moderation protocols, document model-safety decisions and overrides, and add CSAM-prevention controls and incident logging to any generative pipeline.

 U.S. — Colorado: Do not build to the repealed June 30 high-risk standard; re-scope to the SB 189 disclosure-and-rights ADMT framework (effective January 1, 2027).

What Web3 Companies Should Do Now

• EU — MiCA July 1 (urgent, ~7 days): Confirm MiCA authorization before July 1; if a licence is not secured, file a credible, immediately executable wind-down or customer-migration plan, and review stablecoin support (USDT is effectively off-limits on compliant EU venues; USDC is the default).

• U.S. — CLARITY Act & developer liability: Map your token portfolio against the CFTC/SEC divide, and separate “building” from “operating”: front-end maintenance, fee capture, and active support can convert protected code authorship into chargeable conduct under §1960(b)(1)(C) — the Storm theory. Track the October retrial.

 U.S. — GENIUS Act: If issuing a U.S. payment stablecoin, confirm 100% reserve backing with qualifying liquid assets per the OCC proposal, and implement reserve auditing and public attestation.

• Hong Kong — stablecoin licensing: Ensure reserve documentation, governance, and AML/KYC programmes are current; assess eligibility now if not yet applied. Keep mainland firewalls intact.

This briefing is prepared for informational purposes only and does not constitute legal advice. Certain litigation matters involve sensitive subjects (self-harm and child exploitation) and are summarized at the litigation-fact level. If you are seeking AI legal governance or Web3 & digital-assets compliance, feel free to reach out to our lawyers. Many thanks!

Mankun Law PLLC

Contact: Joanna.fan@mankunlaw.com

 

Author

Joanna Fan Chuanli, Partner at Mankun Law Firm, licensed to practice law in China and in the State of New York, USA, and Head of Mankun US Law Firm. She holds a Bachelor of Laws from Southwest University of Political Science and Law and a Master of Laws from Penn State Law, Pennsylvania State University, USA. She is qualified to practice law in both China and the United States. With a long-standing focus on cross-border corporate matters, investment and financing, outbound investment, and dispute resolution, she has continuously deepened her expertise in the intersection of Web3 and artificial intelligence, concentrating on compliance for digital assets, cross-border blockchain architectures, fintech regulation, and global licensing strategies, thereby providing legal support for enterprises expanding overseas and for digital innovation businesses.

 

About Mankun

Mankun Law Firm was established in 2015 as a boutique law firm dedicated to serving Web3.0, the next-generation internet, with deep expertise in emerging economic sectors such as blockchain, artificial intelligence, and tech finance.

Headquartered in Shanghai, the firm maintains branch offices in Hong Kong, Shenzhen, Silicon Valley, and other locations. Its core team members come from renowned law firms, judicial authorities, technology companies, and digital asset institutions. Leveraging a unique multi-dimensional perspective encompassing “law, industry, and regulation,” the firm provides high-quality legal services that combine in-depth understanding of the Chinese market with a broad global outlook.

Drawing on its profound understanding of emerging economic sectors, continuous monitoring and research of regulatory policies, and extensive practical experience, the Mankun team is adept at providing comprehensive legal services from the perspectives of business models and legal practice. For clients in emerging sectors such as Web3.0 blockchain, artificial intelligence (AI), crypto payments (PayFi), decentralized finance (DeFi), tokenization of real-world assets (RWA), NFT digital collectibles, and crypto funds, the firm offers services including business structure design, project financing and investment, operational compliance, commercial dispute resolution, establishment of anti-money laundering (AML) compliance systems, coordination with global law enforcement investigations, tracking and recovery of digital assets, criminal risk prevention and control, and criminal defense.