Skillcast Blog

Compliance News | August 2026 | Skillcast

Written by Emmeline de Chazal | 13 Aug 2026

This month's key compliance news includes the ongoing extreme heat risks, PwC's flawed thinking, Levi's cyberattack, and more.

Our pick of compliance stories this month

Return to office policy reprieve amid heatwaves

Lloyd's of London, JPMorgan Chase, Deutsche Bank and ING have relaxed their return-to-office rules in recent weeks as employees faced temperatures above 33°C.

Lloyd's of London allowed staff to use their own judgment and work from home, although offices will remain open with air conditioning for its staff, insurance brokers and underwriters.

The insurance marketplace also reportedly offered staff complimentary ice cream to help them stay cool.
Previous strict desk orders have also been dropped at JP Morgan Chase and Deutsche, with Nomura, Hiscox and M&G also allowing employees to work from home.

Despite the flexibility, some firms say many employees are opting to stay in work in order to benefit from the air conditioning.
Many schools, hospitals and homes are "woefully unprepared" for the extreme heat and only 4.3% of UK homes have built-in air conditioning.

Insurers are warning that the heatwaves pose a serious risk to economic output across Europe.

"The heatwave is not an exception, it is a direction. Extreme heat costs all of us as workers, as businesses, as taxpayers, and there is a difference between countries that adapt and those that wait. It would be better to stop treating it as a summer problem and start treating it as a permanent economic policy challenge."

-Allianz Investment Management

An amber heat health warning has been issued by the UK's Health Security Agency (UKHSA), with the UK and Europe expecting another heatwave this week. Keep an eye out for the new addition to our Essentials Library: Hot Weather at Work.

Firms face rising risks from extreme heat

Experts warn that firms face increasing risks from extreme and prolonged periods of hot weather, following record summer temperatures across Europe.

The June heatwave cost the UK economy £1.15 billion and resulted in 24 million lost working hours, according to research by the Grantham Research Institute on Climate Change and the Environment at the London School of Economics and Political Science and the Euro-Mediterranean Center on Climate Change (CMCC).

The main findings were:

  • People in higher risk sectors, such as construction and agriculture, were affected most
  • Around 3.6% (1.25 million workers) did not work at all that week because of the heat, which is equivalent to an additional 8 million lost hours
  • 87% of workers reported at least one health-related impact, from disrupted sleep and tiredness at work, to dizziness, fainting and a faster heartbeat
  • 5% sought medical attention and around 3% reported an accident or injury at work
  • Women, people under 35 and those with existing health conditions were most impacted.

"Our findings point to a country that remains insufficiently adapted to the changing climate. The Government cannot continue to ignore extreme heat. Unless it acts now, and makes workplaces safer, we are likely to see growing impacts on workers' productivity, health, and the economy."

-Elizabeth Robinson, Grantham Research Institute on Climate Change and the Environment

An Allianz Research study identified extreme heat as a "structural economic risk" across Europe. The biggest risk was a loss of working hours, particularly in agriculture and construction.

Productivity falls sharply when temperatures exceed 30°C. Prolonged hot weather can cause fatigue, dehydration, heat exhaustion and heatstroke, especially in physical roles. Our ability to do physical work falls by 40% at 32°C and by two-thirds at 38°C.

Construction, manufacturing and logistics are impacted most, as well as people working outdoors and in hot places (such as kitchens). The estimated loss of economic output from extreme heat is around 7% of gross domestic product.
Prolonged heat creates safety, operational and public health risks too. For example:

  • An increased risk of fire in and around our locations
  • Disruption on transport networks, with extreme heat leading to buckled rails and cancelled or delayed services
  • Increased accidents (including more collisions on the roads), due to lower concentration and slower reaction times
  • Supply chain and logistics disruption: for example, low water on rivers, such as the Rhine, can reduce capacity on barges and increase freight costs, if cargo has to be moved by road instead. A 1°C rise in temperatures can also halve the shelf life of fresh produce and medicines
  • Increased energy use, as companies cool machinery and buildings
  • Droughts cause water shortages, impacting agriculture and food production, leading to rising food prices
  • Footfall and customer demand can fall, causing stock shortages

High temperatures also create perfect conditions for infectious diseases to spread, the European Centre for Disease Prevention and Control (ECDC) has warned. Rising temperatures are also accelerating bacterial growth in food, increasing the risk of ill-health and sickness.

Key takeaways:

Although there is no legal maximum temperature, we have a duty of care to ensure temperatures are reasonable and keep people safe in hot weather.

  • Stay alert and ready - by proactively monitoring local heat-health warnings, alerts and transport advisories, and regularly checking cold-storage facilities, freight routes, etc.
  • Be aware of the risks associated with extreme weather - eg safety, financial and operational, supply chain and logistics risks
  • Look out for high-risk groups - eg young and old people, pregnant workers, those with existing medical conditions, outdoor workers, those doing physical work and those returning from sick leave who may need time to acclimatise
  • Remind your staff to follow good practices - eg by staying hydrated, using appropriate measures (such as blinds, reflective film, etc), repositioning desks out of strong sunlight, and taking extra breaks
  • Provide flexibility and organise work to protect your team - eg undertaking higher-risk activities early in the mornings or into the evenings, allowing flexible working if this is beneficial, etc
  • Consider job rotation or rotas - for specific activities during hot weather (eg in kitchens or outdoors), such as one hour on/off
  • Ensure targets are safe and realistic in hot weather - eg temporarily suspend or reschedule some activities where necessary
  • Remember, quality matters too - for example, pouring concrete in hot weather can cause thermal cracking and reduce long-term strength. Sensitive equipment, machines and medical devices (such as insulin pumps, hearing aids and mobility equipment) may malfunction in hot weather. Hot weather also reduces the shelf-life of perishable goods so you should increase checks on temperature-sensitive products and processes
  • Assess whether changes to PPE or uniforms are required - eg weather-appropriate alternatives, relaxing dress codes, etc
  • Arrange adequate oversight and monitoring of your team - to ensure they use equipment and cooling systems, stay hydrated, and also impose rest periods on anyone at increased risk of heatstroke
  • Strengthen business continuity, contingency planning and resilience - to manage disruption caused by absenteeism, supply-chain delays and machinery breakdowns due to overheating. Reassess your response plans to ensure they are fit for purpose.

Flawed thinking? PwC's thought leadership is "100% AI", report claims

Big Four accountancy firm PwC has been accused of publishing four thought leadership reports with patterns of irresponsible AI usage, such as hallucinated claims and fake citations.

A study by GPTZero, a company specialising in AI detection software, looked at four reports that were published between 2024 and 2026 by PwC Middle East. It found they contained unverified information and one of the reports was identified as "100% AI-generated".

GPTZero estimated that there was an 84% likelihood that PwC's report on 'Transforming Governance' was AI-generated. This rose to 100% when the reference section was excluded.

The report promoted the PwC framework named 'Citizen Pulse', which it claimed was used by the governments of Denmark, Saudi Arabia, the United States and Australia. But GPTZero claims there is no public evidence that the product or the government deals actually existed.

GPTZero said the report citations did not "follow the normal academic or consultancy conventions" as they were not all numbered or correspond to footnotes.

"Additionally, the report seems unsure if 'Citizen Pulse' is an existing PwC product or a vague exercise in thought leadership, cycling between describing the potential benefits of the Citizen Pulse framework and concrete claims about current use. This inconsistency is a common symptom of text generated by a poorly-prompted LLM."

-GPTZero

There are similar fabricated claims in the other three reports, alongside false correlations and conflated statistics.

"This is not a minor citation error, nor does it appear to be an isolated incident. These are serious claims about governments' adoption of PwC technology that cannot bear the weight placed on them. When a major consultancy publishes claims like these under its byline, misinformation can gain an unwarranted veneer of authority."

-GPTZero

In response, a spokesperson for PwC Middle East said:

"PwC Middle East takes the accuracy of our published research seriously and is updating a limited number of supporting citations in the reports mentioned. Consistent with our approach to Responsible AI, we have quality control processes for research and content development we expect all our people to adhere to."

Last month, GPTZero found a KPMG report on agentic AI contained AI-generated hallucinations and fake citations. In May, EY withdrew a study on loyalty rewards programmes due to AI hallucinations and fake footnotes. Deloitte also issued a partial refund to the Australian government after a report was found to have errors caused by AI use in October 2025.

Unzipped: Levi's cyberattack reveals growing threat to financial firms

Jeans and apparel maker Levi Strauss has confirmed that an unauthorised third party accessed company files, after social engineering techniques targeted three employees.

In a regulatory filing, the company said it had initiated response controls and implemented containment measures. Certain corporate information was accessed and extracted.

Access was terminated quickly as a result of its rapid response.

Levi's, best known for its signature 501 jeans, said the incident has not disrupted its business operations. It does not expect there to be a material impact on its operations or financial results. It has engaged the services of third-party cybersecurity experts and an investigation is ongoing.

Levi's joins a growing list of organisations being targeted by cyberattacks and ransomware, designed to steal sensitive data and disrupt business activity.

The FBI warned in April 2024 that cyber criminals were targeting individuals and companies with social engineering techniques in AI-driven attacks. This includes:

  • Impersonating employees to update login information and gain access to the company network
  • SIM swaps - where criminals impersonate the victim's mobile carrier to transfer their mobile number to the criminal's device and bypass multi-factor authentication
  • Posing as a trusted organisation or their employer's VPN portal to gain information and login credentials.

Google Threat Intelligence Group (GTIG) warned last week that hackers were targeting the employees of dozens of private equity companies and law firms. In recent weeks, hackers have built 72 malicious websites, effectively setting digital traps for over 200 companies (including Levi's). This includes Blackstone, Apollo Global Management, Bain Capital, CME Group, KKR, TPG and Moody's, according to Reuters.

Company employees are then targeted using voice phishing (vishing), via their personal mobile devices. Criminals impersonate IT helpdesk staff and ask employees to facilitate mandatory, urgent security migrations.

Victims are lured to spoofed login portals where their credentials and multi-factor authentication are intercepted (so-called adversary-in-the-middle attacks). Automated scripts are then used to extract data from cloud environments, like Microsoft 365 and Okta.

The use of low-level tactics like phone calls does not surprise experts.

"Because the fence is now so fancy and high-tech, we just ⁠have to trick the guard into opening the door for us. That human element consistently is why this has exploded in the way it has."

- Lee Clark, Retail and Hospitality ISAC

Key takeaways:

  • Train your team to recognise key threats - such as the common social engineering tactics (eg phishing, vishing and smishing) and how to reduce risks
  • Be vigilant - monitor for suspicious activity and respond to early warnings
  • Encourage your team to speak up if they make a mistake - early reporting enables prompt action to be taken, as the Levi's case shows
  • Follow the NCSC's guidance on preventing lateral movement - ensure that the "principle of least privilege" is applied across your organisation, with a tiering model for administrative accounts
  • Share the findings from penetration testing across the entire company - this ensures risks are addressed universally and not siloed in individual business units
  • Invest in key controls and provide adequate resourcing - so teams are able to react within target response times.

"Wait a sec"

Allied Irish Bank is warning customers to watch out for scammers after payment fraud cases jumped 59% in July.
Scammers are using sophisticated methods to gain people's trust and then persuading them to transfer funds or reveal security information, it said.

Customers often get a text claiming to be from a bank, which is followed up with a phone call from a supposed member of staff.
Scammers create a sense of urgency to trick people into sending money, sharing security codes, bank cards and cash.
AIB is now advising customers to "wait a sec, double check" before acting.

"We are seeing a notable increase in the number of customers being targeted in sophisticated text message and phone call scams. We are asking customers to 'wait a sec, double check' before acting on any unexpected request. A genuine organisation will never pressure you into making immediate decisions about your finances."

-Harold Perez, AIB

AIB said some fraudsters are even persuading customers to withdraw cash and then arranging a collection point.
Banks will never ask customers to share security codes, passwords or login details, move money to "safe accounts", or to withdraw cash.

"If you're unsure, end the conversation and contact us directly using a trusted phone number. Taking a moment to pause could prevent significant financial loss."

-Harold Perez, AIB

Fraud report shows 69% increase in money muling

Over 220,000 fraud cases were recorded in the first half of 2026, according to CIFAS's latest fraud report, the highest number ever recorded for this period.

The Fraudscape 2026 report shows how stolen personal information is a key factor in enabling wider fraud.

  • Identity fraud rose 9% in the first half of 2026, with bank accounts and cards the main targets (accounting for two-thirds of cases)
  • Online retail and card account takeovers rose by 84% and 59% respectively
  • SIM swap cases rose by 402% in the first half of 2026, reflecting their continued use to intercept security codes and account protections
  • Concerns are growing around the use of synthetic identities, AI-enabled impersonation and manipulated documentation
  • Although most identity fraud victims were 61 years and over, the largest uplift concerned the 21-30 year age group (cases rose by 32%)

This highlights the growing threat that online platforms and social media pose to people under 30.

Cases linked to money muling rose by 69% compared with the same period last year, with more than 13,000 reports. Mule activity accounted for 30% of all misuse-of-facility cases, where an account or product is misused by the account holder. More than half of those involved in money-muling cases were under 30, with 17% aged under 21.

CIFAS said this reinforced the need for early intervention and education to stop young people getting involved in muling.

A recent report, Fraud in the Digital Age, also recommends mandatory financial education for anyone under 18 who opens a bank account. Fraud prevention, awareness of money muling and targeted intervention should be embedded into the curriculum. It is calling on the Financial Conduct Authority to take the lead.

"The Financial Conduct Authority should work with consumer banks to introduce mandatory educational learning for individuals under 18 years old before they can open an account. This could take the form of a short video or interactive session delivered via a mobile application, which explains the risks of fraud, scams and money muling. The goal is to promote early financial literacy and reduce the risk of exploitation of young people in facilitating fraud and money laundering."

-Recommendation 46, Fraud in the Digital Age report

Its author Jonathan Fisher KC would also like to see a fraud levy imposed on social media and tech firms. He argues this would address the fundamental imbalance of financial firms reimbursing victims of fraud. Around 66% of APP fraud originates on social media and online platforms, according to UK Finance.

In the meantime, CIFAS and banks, such as NatWest, are leading the way to raise awareness of fraud.

"The findings reinforce the importance of early intervention. Greater reporting, stronger detection and cross-sector data and intelligence sharing are helping organisations build a clearer picture of the key threats. By working together and acting earlier, we can better protect consumers, support businesses and prevent fraud before it takes hold."

- Mike Haley, CIFAS

EU fines Google €890m for competition violations

Google has beenfined €890 million (£760m) for breaches of competition laws relating to its search and app store services.

The European Commission said that Google breached the Digital Markets Act by prioritising its own services, such as shopping and hotel deals, over those offered by its rivals.

It also prevented app developers from guiding consumers towards cheaper offers, such as subscriptions, on websites and other app stores.

Google was fined €460m for the search breach and €430m for the app store breach.

The commission has ordered Google to:

  • Treat third-party services that appear in Google's search results in a "fair and non-discriminatory manner"
  • Allow app developers distributing apps via the Google Play Store to freely communicate, promote offers and conclude contracts with users not only within but also outside the Google Play app store.

Not everyone is happy. The Open Markets Institute Europe thinktank said the fines were the "bare minimum". Google's revenues exceeded $400 billion last year.

"Having finally established Google's non-compliance, the commission must now move quickly to force Google to end its anti-competitive practices once and for all. Europe's startups and innovators cannot wait much longer."

-Max von Thun, Open Markets Institute Europe thinktank

Google's president of global affairs, Kent Walker, criticised the fine as "product degradation driven by a small group of self-serving complainants".

"To comply, we are having to strip away real-time Search features Europeans love - like instant pricing and direct availability for hotels, flights and restaurants - and dismantle safety protections on Google Play. This isn't fair competition."

-Kent Walker, Google

The Commission argued that Google's practices limited consumer choice and gave Google's services an unfair advantage over rivals.

"The best products should succeed because they're better, not because they're owned by the company running the search engine."

-Teresa Ribera, European Commission

Swiss banks fined for money laundering violations

UBS has been fined $125 million by US regulators for violating the Bank Secrecy Act (BSA). It is the biggest fine imposed against a broker-dealer for violating US anti-money laundering laws.

The Financial Crimes Enforcement Network (FinCEN) said UBS Financial Services (UBSFS) had wilfully violated the Bank Secrecy Act by failing to implement and maintain an anti-money laundering programme and by failing to file suspicious activity reports.

It is the second time that enforcement action has been taken against UBSFS. The company was fined $14.5 million in 2018 for failing to monitor foreign currency wires due to weaknesses in its automated systems.

Subsequent violations occurred between January 2019 and June 2023. Regulators said that UBS failed to conduct appropriate due diligence on high-risk customers with links to Russia and Latin America.

The regulator claimed UBSFS failed to consider and mitigate money laundering and illicit finance risks linked to customers' source of wealth. In one example, concerns were not acted upon, even when its own affiliates flagged adverse media linking a customer to corruption, fraud and money laundering.

UBSFS also failed to remediate previously highlighted deficiencies and report hundreds of suspicious transactions on time, depriving law enforcement of critical information.

UBSFS is working with an outside consultant to review its AML programme and focus on "priority illicit finance risks". These include the US Southwest border, cartels and narcotics trafficking, along with Iran, Russia and Venezuela.

"Today's historic action against UBSFS should send a clear message that recidivist financial institutions will face severe repercussions."

- Andrea Gacki, FinCEN

UBS said that it cooperated fully with regulators and it has strengthened its AML programme "in line with leading industry practices".

Elsewhere in Switzerland, Lombard Odier has been fined $37 million by a Swiss court over money laundering failings while FINMA has continued to identify weaknesses in banks’ money laundering risk analyses. These cases underline the growing pressure on financial institutions to strengthen AML controls, risk assessment and oversight.

Record referrals to Prevent scheme

There has been a record number of referrals to the UK's Prevent scheme, a rise of 39% from last year, according to official data released by the Home Office.

A total of 10,293 referrals were made to the counter-radicalisation scheme, which is designed to prevent people going on to commit acts of terrorism. This is the highest number recorded in a single year since 2015.

Most referrals came from the education sector, with the 11-15 age bracket making up the highest proportion (36%).

  • In over half of referrals (56%), no specific ideology was identified
  • Concerns about extreme right-wing ideologies accounted for 20% of referrals, while 8% of referrals related to Islamist extremism
  • A further 8% of referrals related to a fascination with extreme violence or mass casualty attacks
  • 1% concerned Incel extremism, which is linked to misogynist ideology.

The Home Office said that the increased referrals were partly due to greater awareness of Prevent following the Southport attack in July 2024. Three young girls attending a dance class were killed by the teenager Axel Rudakubana, who had been referred to Prevent three times between 2019 and 2021.

Although awareness is important, the government's Prevent Commissioner said, "the system wasn't set up for the problem it's currently dealing with".

"The role of the online world and online influence, and how people with some grievance, some sense of fascination in violence can find communities that will echo those beliefs and develop those beliefs is a phenomenon... which is relatively new."

-Tim Jacques, the government's Independent Prevent Commissioner

The Prevent programme has long faced criticism from people who believe certain groups are unfairly targeted.

Almost one in five (18%) of referrals related to people with autism, while 36% had at least one mental health or neurodiversity condition on the referral.

"There is no excuse for unleashing this much suspicion against autistic people."

-Jacob Smith, Rights & Security International

The Southport case highlights the significant challenges in preventing harm and safeguarding the public.

"We will continue to improve Prevent to ensure it has the tools it needs to do its job of stopping people from becoming terrorists or supporting terrorism. We all have a role to play in keeping each other safe and spotting the signs of radicalisation."

- Dan Jarvis, UK government minister