This website uses cookies

Read our Privacy policy and Terms of use for more information.

AI governance, policy, and risk frameworks.

Edition №11 · Tuesday, July 21, 2026 · ~4 min read

📌 The Brief

The Commission published its final Article 50 transparency guidelines on July 20, thirteen days before the obligations become enforceable. Every open question you were using to justify a wait-and-see posture on chatbot disclosure and content marking now has an official answer, and August 2 has no asterisks left.

⚖️ Regulation & Enforcement

US federal · US states · enforcement actions · compliance deadlines

🦅 US Federal

Executive orders · federal agencies · Congress · NIST · FTC · OMB

White House · 2 min

Launched July 14 under EO 14409: frontier AI models scan for software flaws, a federal clearinghouse routes prioritized fixes across Treasury, DHS/CISA, DoD, and private operators.

Do this: If you run critical infrastructure or sell into it, expect vulnerability intelligence to start arriving through this channel and assign an owner for intake.

If you're an AI developer, note the direction: the June EO asked frontier labs for early government access, and Gold Eagle is that ask becoming operational.

🏛️ US States

State AI laws · attorneys general · state agency rules · enforcement

NY Governor's Office · 2 min

Hochul's July 14 executive order pauses state environmental permits for data centers at 50 megawatts or more, for up to one year, while regulators write binding development standards.

Do this: Reprice your compute expansion assumptions. Already-approved New York projects proceed, but new siting shifts to other states, and the moratorium template (pause first, write standards, then permit) is drafted for copying.

If your AI roadmap assumes cheap incremental capacity, energy is now a regulatory variable, not just a cost line.

Hawaii State Legislature · 2 min

Governor Green signed two AI acts July 14. SB 3001 (Act 248) requires AI-companion disclosure, hourly reminders for minors, and self-harm response protocols; HB 2137 (Act 247) creates civil liability up to $25,000 per piece of harmful deepfake content.

Do this: If you operate a conversational AI product, add Hawaii to the compliance matrix next to California, New York, and the other 14 states with companion-chatbot laws enacted this year. The pattern is stable across states: disclosure, minor protections, crisis protocols. Build one control set to the strictest version rather than 17 variants.

🌍 Global Policy Watch

EU AI Act · UK · APAC · OECD · multilateral · enforcement actions

🇪🇺 EU & Enforcement

EU AI Act · enforcement actions · compliance deadlines

European Commission · 3 min

Adopted July 20: definitive guidance on who must disclose interactive AI, mark synthetic content, and label deepfakes when Article 50 becomes applicable August 2.

One warning inside the fine print: signing the Transparency Code of Practice eases how you demonstrate compliance, it is not a presumption of lawfulness.

Do this: Run your August 2 checklist against the final text this week, not the May draft. Confirm three things per system: users are told they're talking to AI at first interaction, generative outputs carry machine-readable marking (new systems from August 2; pre-existing systems have until December 2), and deepfake labelling is wired into your publishing flow.

Assign gaps by Friday; there is no later slot.

🌏 UK · APAC · Multilateral

UK · APAC · OECD · Council of Europe · multilateral

Cyberspace Administration of China · 3 min

Two frameworks became enforceable July 15: the CAC/NDRC/MIIT Implementation Opinions on intelligent agents (the world's first dedicated agent regulatory category, with mandatory filing in healthcare, transport, media, and public safety, plus recall provisions) and the Interim Measures on anthropomorphic AI services. ByteDance's Doubao and Alibaba's Qwen shut down personalized companion-agent features rather than rebuild them in time.

Do this: If you deploy agents touching Chinese operations, verify your decision-authorization documentation and filing status now; you're in scope as of last Tuesday. For everyone else, read the platform shutdowns as the signal: regulators are treating agents and companion AI as their own categories, and persistent-memory personalization is the feature they target first. Expect the category split to migrate west.

📅 On the Radar

Forward look: deadlines, comment windows, effective dates coming up

  • By July 30, 2026: The Digital Omnibus on AI must publish in the Official Journal for its deferred deadlines to bind before August 2. It was signed July 8 and enters into force three days after publication.

  • July 31, 2026: Comment window closes on the FTC's proposed policy statement on AI accuracy claims.

  • August 2, 2026: Article 50 transparency obligations apply, and Commission GPAI enforcement powers go live with fines up to €15M or 3% of global turnover.

  • December 2, 2026: Machine-readable marking deadline for pre-August generative systems, and the two new Article 5 prohibitions take effect.

🔍 One Big Thing

EU AI Office · 25 min read at source

The AI Office published findings from over 100 experts (developers, investors, industry, Member States) on July 15, and the sentence that matters is uncharacteristically blunt for Brussels: the next one to two years could be decisive for whether Europe remains a serious actor in frontier AI.

The diagnosis is sober. Europe produces world-class research and trains a large share of global AI talent, but frontier model development is concentrated outside the EU, and the binding constraints are compute and the energy to power it, not regulation or talent.

The prescription is equally telling: the goal is framed as sovereign ability to access, select, control, and benefit from frontier models, working with trusted partners, rather than building a European frontier lab from scratch.

The report feeds the European Frontier AI Initiative under the Apply AI Strategy, with 2030 as the target year. For compliance leads, the subtext is the point: the same institution enforcing the AI Act is now formally worried about dependence on the foreign models it regulates, and that tension will shape how enforcement discretion, sandboxes, and procurement preferences get used.

Do this: Read it for the dependency map, not the strategy. If your EU operations run on US frontier models, this report is the best official articulation of the supply-chain risk your board will eventually ask about. Use its framing (access, choice, control) to structure your own model-vendor contingency review.

💬 From the desk

A concentrated week: five stories carried all the weight, so this edition runs lean rather than padded. Two flags before next Tuesday. First, the Omnibus clock is now inside a ten-day window; publication in the Official Journal must land by July 30, and when it does, the deferred dates finally bind. That's next edition's lead unless something larger interrupts. Second, the final Article 50 guidelines trigger a maintenance pass on our EU AI Act Deadline Calendar; the status banner and the August 2 row both get updated this week.

Was this forwarded to you? Subscribe →

Intelligence and Compliance · intelligenceandcompliance.com

Keep Reading