This month's key compliance news includes the ongoing extreme heat risks, PwC's flawed thinking, Levi's cyberattack, and more.
Lloyd's of London, JPMorgan Chase, Deutsche Bank and ING have relaxed their return-to-office rules in recent weeks as employees faced temperatures above 33°C.
Lloyd's of London allowed staff to use their own judgment and work from home, although offices will remain open with air conditioning for its staff, insurance brokers and underwriters.
The insurance marketplace also reportedly offered staff complimentary ice cream to help them stay cool.
Previous strict desk orders have also been dropped at JP Morgan Chase and Deutsche, with Nomura, Hiscox and M&G also allowing employees to work from home.
Despite the flexibility, some firms say many employees are opting to stay in work in order to benefit from the air conditioning.
Many schools, hospitals and homes are "woefully unprepared" for the extreme heat and only 4.3% of UK homes have built-in air conditioning.
Insurers are warning that the heatwaves pose a serious risk to economic output across Europe.
"The heatwave is not an exception, it is a direction. Extreme heat costs all of us as workers, as businesses, as taxpayers, and there is a difference between countries that adapt and those that wait. It would be better to stop treating it as a summer problem and start treating it as a permanent economic policy challenge."
-Allianz Investment Management
An amber heat health warning has been issued by the UK's Health Security Agency (UKHSA), with the UK and Europe expecting another heatwave this week. Keep an eye out for the new addition to our Essentials Library: Hot Weather at Work.
Experts warn that firms face increasing risks from extreme and prolonged periods of hot weather, following record summer temperatures across Europe.
The June heatwave cost the UK economy £1.15 billion and resulted in 24 million lost working hours, according to research by the Grantham Research Institute on Climate Change and the Environment at the London School of Economics and Political Science and the Euro-Mediterranean Center on Climate Change (CMCC).
The main findings were:
"Our findings point to a country that remains insufficiently adapted to the changing climate. The Government cannot continue to ignore extreme heat. Unless it acts now, and makes workplaces safer, we are likely to see growing impacts on workers' productivity, health, and the economy."
-Elizabeth Robinson, Grantham Research Institute on Climate Change and the Environment
An Allianz Research study identified extreme heat as a "structural economic risk" across Europe. The biggest risk was a loss of working hours, particularly in agriculture and construction.
Productivity falls sharply when temperatures exceed 30°C. Prolonged hot weather can cause fatigue, dehydration, heat exhaustion and heatstroke, especially in physical roles. Our ability to do physical work falls by 40% at 32°C and by two-thirds at 38°C.
Construction, manufacturing and logistics are impacted most, as well as people working outdoors and in hot places (such as kitchens). The estimated loss of economic output from extreme heat is around 7% of gross domestic product.
Prolonged heat creates safety, operational and public health risks too. For example:
High temperatures also create perfect conditions for infectious diseases to spread, the European Centre for Disease Prevention and Control (ECDC) has warned. Rising temperatures are also accelerating bacterial growth in food, increasing the risk of ill-health and sickness.
Although there is no legal maximum temperature, we have a duty of care to ensure temperatures are reasonable and keep people safe in hot weather.
Big Four accountancy firm PwC has been accused of publishing four thought leadership reports with patterns of irresponsible AI usage, such as hallucinated claims and fake citations.
A study by GPTZero, a company specialising in AI detection software, looked at four reports that were published between 2024 and 2026 by PwC Middle East. It found they contained unverified information and one of the reports was identified as "100% AI-generated".
GPTZero estimated that there was an 84% likelihood that PwC's report on 'Transforming Governance' was AI-generated. This rose to 100% when the reference section was excluded.
The report promoted the PwC framework named 'Citizen Pulse', which it claimed was used by the governments of Denmark, Saudi Arabia, the United States and Australia. But GPTZero claims there is no public evidence that the product or the government deals actually existed.
GPTZero said the report citations did not "follow the normal academic or consultancy conventions" as they were not all numbered or correspond to footnotes.
"Additionally, the report seems unsure if 'Citizen Pulse' is an existing PwC product or a vague exercise in thought leadership, cycling between describing the potential benefits of the Citizen Pulse framework and concrete claims about current use. This inconsistency is a common symptom of text generated by a poorly-prompted LLM."
-GPTZero
There are similar fabricated claims in the other three reports, alongside false correlations and conflated statistics.
"This is not a minor citation error, nor does it appear to be an isolated incident. These are serious claims about governments' adoption of PwC technology that cannot bear the weight placed on them. When a major consultancy publishes claims like these under its byline, misinformation can gain an unwarranted veneer of authority."
-GPTZero
In response, a spokesperson for PwC Middle East said:
"PwC Middle East takes the accuracy of our published research seriously and is updating a limited number of supporting citations in the reports mentioned. Consistent with our approach to Responsible AI, we have quality control processes for research and content development we expect all our people to adhere to."
Last month, GPTZero found a KPMG report on agentic AI contained AI-generated hallucinations and fake citations. In May, EY withdrew a study on loyalty rewards programmes due to AI hallucinations and fake footnotes. Deloitte also issued a partial refund to the Australian government after a report was found to have errors caused by AI use in October 2025.
Jeans and apparel maker Levi Strauss has confirmed that an unauthorised third party accessed company files, after social engineering techniques targeted three employees.
In a regulatory filing, the company said it had initiated response controls and implemented containment measures. Certain corporate information was accessed and extracted.
Access was terminated quickly as a result of its rapid response.
Levi's, best known for its signature 501 jeans, said the incident has not disrupted its business operations. It does not expect there to be a material impact on its operations or financial results. It has engaged the services of third-party cybersecurity experts and an investigation is ongoing.
Levi's joins a growing list of organisations being targeted by cyberattacks and ransomware, designed to steal sensitive data and disrupt business activity.
The FBI warned in April 2024 that cyber criminals were targeting individuals and companies with social engineering techniques in AI-driven attacks. This includes:
Google Threat Intelligence Group (GTIG) warned last week that hackers were targeting the employees of dozens of private equity companies and law firms. In recent weeks, hackers have built 72 malicious websites, effectively setting digital traps for over 200 companies (including Levi's). This includes Blackstone, Apollo Global Management, Bain Capital, CME Group, KKR, TPG and Moody's, according to Reuters.
Company employees are then targeted using voice phishing (vishing), via their personal mobile devices. Criminals impersonate IT helpdesk staff and ask employees to facilitate mandatory, urgent security migrations.
Victims are lured to spoofed login portals where their credentials and multi-factor authentication are intercepted (so-called adversary-in-the-middle attacks). Automated scripts are then used to extract data from cloud environments, like Microsoft 365 and Okta.
The use of low-level tactics like phone calls does not surprise experts.
"Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us. That human element consistently is why this has exploded in the way it has."
- Lee Clark, Retail and Hospitality ISAC
Allied Irish Bank is warning customers to watch out for scammers after payment fraud cases jumped 59% in July.
Scammers are using sophisticated methods to gain people's trust and then persuading them to transfer funds or reveal security information, it said.
Customers often get a text claiming to be from a bank, which is followed up with a phone call from a supposed member of staff.
Scammers create a sense of urgency to trick people into sending money, sharing security codes, bank cards and cash.
AIB is now advising customers to "wait a sec, double check" before acting.
"We are seeing a notable increase in the number of customers being targeted in sophisticated text message and phone call scams. We are asking customers to 'wait a sec, double check' before acting on any unexpected request. A genuine organisation will never pressure you into making immediate decisions about your finances."
-Harold Perez, AIB
AIB said some fraudsters are even persuading customers to withdraw cash and then arranging a collection point.
Banks will never ask customers to share security codes, passwords or login details, move money to "safe accounts", or to withdraw cash.
"If you're unsure, end the conversation and contact us directly using a trusted phone number. Taking a moment to pause could prevent significant financial loss."
-Harold Perez, AIB
Over 220,000 fraud cases were recorded in the first half of 2026, according to CIFAS's latest fraud report, the highest number ever recorded for this period.
The Fraudscape 2026 report shows how stolen personal information is a key factor in enabling wider fraud.
This highlights the growing threat that online platforms and social media pose to people under 30.
Cases linked to money muling rose by 69% compared with the same period last year, with more than 13,000 reports. Mule activity accounted for 30% of all misuse-of-facility cases, where an account or product is misused by the account holder. More than half of those involved in money-muling cases were under 30, with 17% aged under 21.
CIFAS said this reinforced the need for early intervention and education to stop young people getting involved in muling.
A recent report, Fraud in the Digital Age, also recommends mandatory financial education for anyone under 18 who opens a bank account. Fraud prevention, awareness of money muling and targeted intervention should be embedded into the curriculum. It is calling on the Financial Conduct Authority to take the lead.
"The Financial Conduct Authority should work with consumer banks to introduce mandatory educational learning for individuals under 18 years old before they can open an account. This could take the form of a short video or interactive session delivered via a mobile application, which explains the risks of fraud, scams and money muling. The goal is to promote early financial literacy and reduce the risk of exploitation of young people in facilitating fraud and money laundering."
-Recommendation 46, Fraud in the Digital Age report
Its author Jonathan Fisher KC would also like to see a fraud levy imposed on social media and tech firms. He argues this would address the fundamental imbalance of financial firms reimbursing victims of fraud. Around 66% of APP fraud originates on social media and online platforms, according to UK Finance.
In the meantime, CIFAS and banks, such as NatWest, are leading the way to raise awareness of fraud.
"The findings reinforce the importance of early intervention. Greater reporting, stronger detection and cross-sector data and intelligence sharing are helping organisations build a clearer picture of the key threats. By working together and acting earlier, we can better protect consumers, support businesses and prevent fraud before it takes hold."
- Mike Haley, CIFAS
Google has beenfined €890 million (£760m) for breaches of competition laws relating to its search and app store services.
The European Commission said that Google breached the Digital Markets Act by prioritising its own services, such as shopping and hotel deals, over those offered by its rivals.
It also prevented app developers from guiding consumers towards cheaper offers, such as subscriptions, on websites and other app stores.
Google was fined €460m for the search breach and €430m for the app store breach.
The commission has ordered Google to:
Allow app developers distributing apps via the Google Play Store to freely communicate, promote offers and conclude contracts with users not only within but also outside the Google Play app store.
Not everyone is happy. The Open Markets Institute Europe thinktank said the fines were the "bare minimum". Google's revenues exceeded $400 billion last year.
"Having finally established Google's non-compliance, the commission must now move quickly to force Google to end its anti-competitive practices once and for all. Europe's startups and innovators cannot wait much longer."
-Max von Thun, Open Markets Institute Europe thinktank
Google's president of global affairs, Kent Walker, criticised the fine as "product degradation driven by a small group of self-serving complainants".
"To comply, we are having to strip away real-time Search features Europeans love - like instant pricing and direct availability for hotels, flights and restaurants - and dismantle safety protections on Google Play. This isn't fair competition."
-Kent Walker, Google
The Commission argued that Google's practices limited consumer choice and gave Google's services an unfair advantage over rivals.
"The best products should succeed because they're better, not because they're owned by the company running the search engine."
-Teresa Ribera, European Commission
UBS has been fined $125 million by US regulators for violating the Bank Secrecy Act (BSA). It is the biggest fine imposed against a broker-dealer for violating US anti-money laundering laws.
The Financial Crimes Enforcement Network (FinCEN) said UBS Financial Services (UBSFS) had wilfully violated the Bank Secrecy Act by failing to implement and maintain an anti-money laundering programme and by failing to file suspicious activity reports.
It is the second time that enforcement action has been taken against UBSFS. The company was fined $14.5 million in 2018 for failing to monitor foreign currency wires due to weaknesses in its automated systems.
Subsequent violations occurred between January 2019 and June 2023. Regulators said that UBS failed to conduct appropriate due diligence on high-risk customers with links to Russia and Latin America.
The regulator claimed UBSFS failed to consider and mitigate money laundering and illicit finance risks linked to customers' source of wealth. In one example, concerns were not acted upon, even when its own affiliates flagged adverse media linking a customer to corruption, fraud and money laundering.
UBSFS also failed to remediate previously highlighted deficiencies and report hundreds of suspicious transactions on time, depriving law enforcement of critical information.
UBSFS is working with an outside consultant to review its AML programme and focus on "priority illicit finance risks". These include the US Southwest border, cartels and narcotics trafficking, along with Iran, Russia and Venezuela.
"Today's historic action against UBSFS should send a clear message that recidivist financial institutions will face severe repercussions."
- Andrea Gacki, FinCEN
UBS said that it cooperated fully with regulators and it has strengthened its AML programme "in line with leading industry practices".
Elsewhere in Switzerland, Lombard Odier has been fined $37 million by a Swiss court over money laundering failings while FINMA has continued to identify weaknesses in banks’ money laundering risk analyses. These cases underline the growing pressure on financial institutions to strengthen AML controls, risk assessment and oversight.
There has been a record number of referrals to the UK's Prevent scheme, a rise of 39% from last year, according to official data released by the Home Office.
A total of 10,293 referrals were made to the counter-radicalisation scheme, which is designed to prevent people going on to commit acts of terrorism. This is the highest number recorded in a single year since 2015.
Most referrals came from the education sector, with the 11-15 age bracket making up the highest proportion (36%).
The Home Office said that the increased referrals were partly due to greater awareness of Prevent following the Southport attack in July 2024. Three young girls attending a dance class were killed by the teenager Axel Rudakubana, who had been referred to Prevent three times between 2019 and 2021.
Although awareness is important, the government's Prevent Commissioner said, "the system wasn't set up for the problem it's currently dealing with".
"The role of the online world and online influence, and how people with some grievance, some sense of fascination in violence can find communities that will echo those beliefs and develop those beliefs is a phenomenon... which is relatively new."
-Tim Jacques, the government's Independent Prevent Commissioner
The Prevent programme has long faced criticism from people who believe certain groups are unfairly targeted.
Almost one in five (18%) of referrals related to people with autism, while 36% had at least one mental health or neurodiversity condition on the referral.
"There is no excuse for unleashing this much suspicion against autistic people."
-Jacob Smith, Rights & Security International
The Southport case highlights the significant challenges in preventing harm and safeguarding the public.
"We will continue to improve Prevent to ensure it has the tools it needs to do its job of stopping people from becoming terrorists or supporting terrorism. We all have a role to play in keeping each other safe and spotting the signs of radicalisation."
- Dan Jarvis, UK government minister