← The Intake
The Intake · Weekly briefing

This week in AI, for legal

The White House accused Moonshot AI of covertly distilling Anthropic's Fable to build Kimi K3 — a launch so popular Moonshot had to pause new subscriptions within 48 hours — while Google quietly shipped three Gemini models and left its long-teased flagship unshipped. Crowell & Moring published six months of firmwide Legora usage data, and two federal judges took opposite approaches to AI-hallucinated filings in the same week. And with nine days left before the EU AI Act's Article 50 transparency rules bind regardless of the high-risk deferral, most legal teams are bracing for the wrong deadline.

Week of 18 – 24 July 2026
Category Market intelligence
Reading time 9 minutes
01 — The week at a glance

Five stories that matter

July 17 — Enforcement
Judge Hala Jarbou finds a government brief cites a Sixth Circuit case, Taylor v. Hott, that does not exist. She warns it "goes without saying" that federal filings can't contain hallucinated law, but stops short of sanctions.
July 21 — Frontier models
3.6 Flash cuts output pricing by roughly 17% and posts double-digit benchmark gains over 3.5 Flash. A dedicated security-focused variant, Gemini 3.5 Flash Cyber, also ships. The mid-tier update lands quietly; the flagship Google has teased for months still doesn't exist in production.
July 22 — Adoption
Eighty-two percent of the entire firm has become a Legora user since the January 2026 firmwide launch, with nearly 70% of attorneys using it at least weekly. One of the more granular adoption data sets any large firm has published this year.
July 22 — Infrastructure
Beetaloo Digital, a unit of a shale-gas producer sitting atop the Beetaloo Basin, plans two hyperscale campuses drawing up to 2 gigawatts, burning the region's own gas reserves to power the compute.
July 22–23 — Dispute
OSTP director Michael Kratsios says Moonshot ran the copying through a purpose-built internal system, rotating access routes to obscure it. No penalties have been announced; Kimi K3's full weights are due to go public July 27.
02 — The distillation dispute

The White House accuses Moonshot AI of secretly copying Anthropic's outputs to build its newest model — a theft-of-training-data question this briefing has never faced before.

Model distillation, feeding a stronger model's outputs to a weaker one so it learns to imitate the stronger one, is a normal, often licensed, technique in AI development. On July 23, White House Office of Science and Technology Policy director Michael Kratsios accused Moonshot AI, the Beijing-based lab behind Kimi K3, of doing it covertly: running the copying through a purpose-built internal system and rotating access routes to stay hidden while pulling outputs from Anthropic's Fable model. Kratsios also said Moonshot obtained access to export-controlled, high-end Nvidia AI servers to train the model, hardware that is barred for export to Chinese entities without a license. Anthropic itself had flagged unusual activity back in February, tracing 3.4 million Claude exchanges to the Chinese startup. Moonshot has not responded to the allegations. No penalties have been announced. And the punchline is almost absurd: Kimi K3's own public launch a few days earlier was so popular that Moonshot had to pause new subscriptions within 48 hours, "the love," as the company put it on social media, outstripping its GPU capacity.

February 2026
Anthropic traces 3.4 million Claude API exchanges to Moonshot AI-linked accounts — an early signal, in hindsight, of large-scale output harvesting.
July 21, 2026
Kimi K3 launches publicly: a 2.8-trillion-parameter, open-weight model. Demand overwhelms Moonshot's compute within 48 hours; new subscriptions are paused.
July 23, 2026
Kratsios accuses Moonshot of covertly distilling Anthropic's Fable and of using export-controlled Nvidia chips without a license. No penalties announced. Moonshot has not responded.
July 27, 2026 (scheduled)
Kimi K3's full model weights are due to be released publicly — potentially before either government has resolved whether the model was built lawfully.
The structural question for enterprise legal teams

Every enterprise legal AI contract has a clause, somewhere, about what the vendor can and can't do with your firm's inputs and outputs. This dispute is the first widely reported case of a frontier lab allegedly doing exactly that to a rival, at industrial scale, in violation of usage terms. If a well-resourced state-linked lab can allegedly do this to Anthropic and still ship a product before anyone can prove or stop it, what confidence should an enterprise buyer have that its own outputs, contract clauses, negotiating positions, internal analysis, aren't being harvested by whatever model sits underneath a vendor's product today? Provenance of training data is becoming a genuine legal due-diligence question, not a theoretical one.

The Flank read

This story is a reminder of something this briefing keeps returning to from different angles: the intelligence layer underneath every legal AI product is rented, contested, and increasingly adversarial. Whether or not the specific allegations against Moonshot hold up, the incentive they describe, that outputs are valuable enough to steal at industrial scale, applies just as much to the outputs your legal team generates inside whatever AI tool it uses today. Flank's model doesn't ask a client to trust a single model vendor's training practices as a matter of faith. Supervision sits above the model layer: a human reviews every agent output before it reaches the business, and the workflow, not any one underlying model, is what the client is actually buying. When the model layer is this volatile, the thing worth building trust around is the review step, not the vendor's word about what its model was trained on.

03 — The model churn

Three models moved in three different directions this week — one shipped quietly, one stayed vaporware, one got overwhelmed by its own popularity.

Google shipped three new Gemini models on July 21: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and a narrow, security-focused variant called Gemini 3.5 Flash Cyber. 3.6 Flash cuts output token pricing by roughly 17% against its predecessor and posts double-digit gains on coding and reasoning benchmarks, but Gemini 3.5 Pro, the flagship this briefing has now heard teased across two editions, following a full architectural rebuild after the original base model was scrapped, still has not shipped. Meanwhile Moonshot's Kimi K3, a 2.8-trillion-parameter open-weight model, launched the same day and proved so popular that Moonshot paused new subscriptions within 48 hours to protect existing users' access, before the distillation allegations above had even surfaced.

Shipped quietly
Gemini 3.6 Flash
Google's mid-tier workhorse, replacing 3.5 Flash. ~17% cheaper output tokens, double-digit benchmark gains. Live now in the Gemini API and Google Antigravity.
Still vaporware
Gemini 3.5 Pro
Teased for months after a full rebuild; reportedly a 2-million-token context window and a "Deep Think" tier. Google has confirmed none of it. Gemini 4 is now teased on top.
Paused on demand
Kimi K3
Open-weight, 2.8T parameters. New subscriptions suspended 48 hours after launch; Moonshot says it's adding capacity "as fast as we can."
The structural question for enterprise legal teams

Three models, three different states, shipped, promised, and overwhelmed, inside a single week, and almost none of it is visible to the person typing into a legal AI product's chat window. Does your legal AI vendor tell you when the model underneath your workflow changes, and does your audit trail record which model produced a given output? A flat interface hides model churn by design. A governed workflow has to surface it, because the model that drafted last month's NDA redline may not be the model that drafts next month's.

04 — The deadline that wasn't deferred

The EU AI Act's high-risk deadline slipped to 2027. A different deadline, one this briefing hasn't flagged before, lands in nine days.

The political fight this briefing covered across April and May, over whether the EU AI Act's high-risk compliance deadline would hold at August 2026 or slip, is over: the Digital Omnibus on AI was signed into law on July 8, formally deferring high-risk obligations to December 2026 and December 2027 in stages. But Article 50, the AI Act's transparency regime, was not touched by that deferral and becomes enforceable on schedule on August 2, 2026: mandatory disclosure when a user is interacting with an AI system, labelling of AI-generated synthetic content, and disclosure of deepfakes. Unlike the high-risk provisions, Article 50 isn't limited to systems classified as high-risk. It applies to any business using generative AI to produce content that reaches an end user, a considerably wider net than the compliance conversation of the last four months has focused on.

ObligationScopeStatus after the OmnibusEffective High-risk system requirements (Arts. 9–17, 26)AI systems classified high-risk under Annex IIIDeferred by the Digital Omnibus, signed July 8Dec 2026 / Dec 2027, staged Transparency obligations (Art. 50)Any generative AI producing content for end users; not limited to high-riskUntouched by the Omnibus — binds as originally scheduledAug 2, 2026

The practical risk is that legal and compliance teams who spent the spring tracking the high-risk deferral fight now read the Omnibus headline, "deadlines pushed back," and stand down, when the obligation that actually lands in nine days was never part of that fight. Chatbot disclosure, AI-content labelling, and deepfake marking apply whether or not a given tool is high-risk, which in practice covers most of what a legal team's own AI vendors are producing for it today: drafted correspondence, summarised research, generated first-pass documents.

The Flank read

This is a small, specific illustration of a pattern this briefing keeps documenting: regulatory complexity doesn't resolve into a single deadline a legal team can put on a calendar and forget. It resolves into a set of overlapping obligations that a governance layer has to track continuously, not a compliance program that gets built once. Flank's supervision model exists for exactly this reason: every agent workflow runs through human review before output leaves the system, which means disclosure, labelling, and audit-trail obligations are met as a structural property of how the work gets done, not as a separate compliance exercise bolted on after the fact once the deadline is finally clear.

05 — The firm that published its numbers

Last week's survey found 83% of in-house teams can't prove their AI spend paid off. This week, one firm published the usage data almost nobody has.

Crowell & Moring piloted Legora in late 2025 and launched it firmwide in January 2026. On July 22, the firm published six-month results: more than 2 million platform interactions, 82% of the entire firm, including 91% of its more than 700 attorneys, now counted as users, and nearly 70% of those attorneys using the platform at least weekly. That last figure is the one that matters most. Adoption numbers are easy to publish and easy to inflate with one-time logins; weekly active usage at that depth, across a firm of that size, is a different claim entirely, evidence of the tool being embedded in how the work actually gets done rather than sitting unused after a launch announcement.

2M+
Platform interactions in six months, since the January 2026 firmwide launch
91%
Of the firm's 700+ attorneys now counted as Legora users
~70%
Of those attorneys using the platform at least weekly

An associate in the firm's Patents Group described the platform as having "accelerated my learning curve and, therefore, value to clients in ways I didn't anticipate." The firm also cited a recent trial where the team used the platform to prepare more thoroughly and respond more nimbly than an opposing team with more people on it. Both are anecdotes rather than measured outcomes, and Crowell & Moring didn't publish a cost or time-saved figure to sit alongside the usage data, which is itself notable given how squarely last week's ROI-measurement gap sits over this exact kind of announcement.

The structural question for enterprise legal teams

Weekly-active-usage data like Crowell & Moring's is genuinely useful, and rare. But usage depth answers a different question than the one Axiom's survey found 83% of in-house teams can't answer: not "are people using the tool," but "does the work cost less or get done better because of it." If your own legal AI vendor can't produce Crowell & Moring's kind of usage number, and your own team can't produce a cost or outcome number to go with it, which of the two gaps is actually the harder one to close?

06 — The courts split on mercy

Two federal judges reached opposite conclusions this week about AI-hallucinated filings — and how much mercy a mistake deserves.

This briefing has spent months tracking an escalation: sanctions climbing from four-figure fines toward $15,000-per-attorney penalties, bar suspensions, and disqualifications. This week ran in the other direction in two separate cases. On July 17, Michigan federal judge Hala Jarbou caught a DOJ brief citing Taylor v. Hott, a Sixth Circuit case that does not exist, and warned the government that hallucinated law in federal filings is unacceptable, but declined to sanction. Around the same time, Kentucky federal judge Thomas Cullen declined to sanction attorney Thomas Guyer over a brief filled with AI-generated misquotes and incorrect citations, finding Guyer had "owned the mistake," had no history of misconduct, and was, in his own lawyer's words, "incredibly remorseful." Cullen was explicit that a warning could serve as "sufficient deterrent" on a clean record, while still insisting that generative AI's growing role in practice, its becoming the "new normal," doesn't relax a lawyer's duty to take reasonable measures to verify what gets filed.

The escalation this briefing has tracked
A New York firm ordered to pay $10,500. A Sixth Circuit panel fining two attorneys $15,000 each. Bar suspensions and disqualifications following repeat or egregious fabrications. Courts treating hallucinated citations as a professional-conduct failure that compounds with disregard for a court's time.
The restraint this week introduced
A government attorney warned, not sanctioned, over a fabricated Sixth Circuit citation in an immigration case. A solo Kentucky attorney with a clean record and visible remorse spared formal sanction in favor of a warning. Two judges, independently, treating a first offense with contrition as different in kind from repeat or careless disregard.

Neither case suggests courts are going soft on the underlying problem. Both judges were explicit that verification remains the lawyer's job regardless of the tool. What they introduced is a distinction between the mistake and the response to being caught: remorse, a clean record, and taking ownership now appear to buy real leniency, in a way that a pattern of hallucinations, or a lawyer who fights the finding, does not.

The Flank read

The distinction these two rulings are drawing, first-offense contrition versus a pattern of disregard, is itself a supervision question, not a sanctions question. A firm that can show a court it has a real verification step built into how AI-assisted work gets produced and checked has a materially different story to tell than a firm that can only say a lawyer was sorry after the fact. That is the entire premise behind building supervision as core product rather than as a policy memo: every Flank agent workflow runs through human review before anything leaves the system, so the question a court is now implicitly asking, "was there a real check here, or just good intentions", has an answer that doesn't depend on how convincingly remorseful anyone sounds afterward.

07 — So what

What this week tells us

A frontier-model dispute over stolen intelligence, three models moving in three different directions in a single week, a compliance deadline hiding behind a headline about deferral, a law firm's usage numbers with no outcome numbers attached, and two judges quietly rewriting how much mercy a hallucination earns: none of these stories were coordinated, and all of them describe the same market working through the same unresolved question. Intelligence keeps getting more contested and more volatile at the same time it gets cheaper and more available. Oversight keeps arriving in pieces, a transparency article here, a judicial distinction there, rather than as one governed system. And the gap this briefing keeps finding, between using AI and being able to prove what it did, hasn't moved.

Intelligence is contested, not just cheap
The Moonshot dispute puts a legal question under a trend this briefing has covered as pure economics: if outputs can allegedly be stolen at industrial scale, provenance becomes a due-diligence question for every enterprise AI buyer.
The model underneath your tool keeps moving
Shipped, teased, and paused, all in one week. Almost none of it is visible from inside a legal AI product's interface unless the vendor chooses to surface it.
Compliance arrives obligation by obligation
The EU AI Act's high-risk deadline slipped to 2027. Its transparency rules didn't, and bind in nine days, on a wider set of systems than the deferral conversation suggested.
Usage data still isn't outcome data
Crowell & Moring's numbers are a real, rare data point on adoption depth. They still don't answer the question last week's survey found 83% of in-house teams can't answer.
The Flank view

Every story in this week's briefing is a variation on the same structural gap: inexpensive work is being done by expensive resources, and neither cheaper intelligence, nor a firm's usage numbers, nor a court's evolving sense of how much mercy a mistake deserves, closes it on its own. A frontier lab allegedly stealing another's outputs to build a faster model doesn't change who reviews the work before it reaches a client. A compliance deadline hiding behind a deferral headline doesn't change whether a legal team can actually show a regulator what its AI systems did. And a law firm publishing real, granular adoption numbers, genuinely rare, still isn't the same claim as being able to show the work costs less or gets done to a verified standard.

Flank's answer to all of it is structural, not a bet on any one model, vendor, or court's mood this quarter: tools are a commodity, outcomes are not. We compete for the budget line where routine legal work already sits, the outside counsel, ALSP, and internal headcount spend that dwarfs any software line, not just a new tool to add to it. Agents execute the work under your playbooks, a human reviews every output before it leaves the system, and you don't pay until the first workflow is live in production. Whichever model is running underneath any given vendor this week, whichever deadline just quietly bound, whichever judge just drew a new line on mercy, the one part of this week's news that doesn't change is that outsourcing the work to supervised agents is what turns "we use AI" into an answer a court, a regulator, or a CFO can actually verify.

Subscribe

The Intake

Weekly briefings on what's actually changing in legal AI — the market shifts, regulatory moves, and structural questions that matter for enterprise legal teams. Written by the Flank team.

Subscribe on Substack
Flank

Outsource legal work to supervised agents

Enterprise legal teams use Flank to handle high-volume contracting end-to-end: NDAs, MSA redlines, procurement, triage. Agents that know your templates, terms, and escalation rules. Every output reviewed before it leaves the system.

Learn more at flank.ai