Weekly AI Governance Brief: 13–19 July 2026
Bringing you the latest developments in the AI governance world.
European Commission sets binding DMA requirements for AI assistants and search data
On 16 July 2026, the European Commission adopted two binding specification measures directed at Google under the Digital Markets Act.
The first measure concerns interoperability between competing AI assistants and Android. According to the Commission, Google must provide competing AI assistant providers with effective access to key Android functionalities on terms that allow their services to interact with the operating system in ways comparable to Google’s own AI services. The measures cover functions including voice activation and the ability of an AI assistant to perform actions through applications on a user’s behalf.
The second measure concerns access to Google Search data. It specifies how Google must make certain search data available to third-party search engines, including AI chatbots incorporating search functionality. The Commission’s measures address conditions relating to anonymisation and pricing, alongside security and data-protection safeguards.
The Commission published the measures through its Digital Markets Act framework and confirmed that the final decision was adopted on 16 July 2026.
Why this matters
The measures turn the DMA’s interoperability and data-access requirements into specific obligations for AI services. Competing AI assistants gain regulated access to key Android functions, while AI-enabled search providers can access Google Search data subject to anonymisation, security and data-protection safeguards.
German media regulator applies media law to AI search and chatbot services
On 14 July 2026, Germany’s Commission for Licensing and Supervision, the ZAK, announced supervisory notices concerning AI services offered by Google and Perplexity. The action was published in ZAK press release 02/2026 following proceedings led by the Hamburg-Schleswig Holstein and Berlin-Brandenburg media authorities.
The ZAK stated that German media law had been found applicable to AI search and chatbot services for the first time.
According to the authority, AI-generated answers constitute the providers’ own content and therefore do not fall within the Digital Services Act liability privilege applicable to certain intermediary activities. The ZAK also found that Google’s AI Overviews can place the conventional search-results link list at a disadvantage by reducing its discoverability.
The authority further stated that chatbot functions displaying source links, further-reading prompts or link lists can meet the criteria for classification as a media intermediary under German law.
The providers may appeal the supervisory notices.
Why this matters
The action brings parts of AI search and chatbot services under German media supervision. It distinguishes AI-generated content from intermediary functions and extends regulatory scrutiny to source links, ranking and presentation. For operators in Germany, this adds a national compliance layer alongside EU digital regulation.
EDPB calls for legal basis for cross-regulatory information sharing
On 17 July 2026, the European Data Protection Board published an official statement calling on the European Commission to establish a legal basis for information sharing between regulators with different areas of competence.
The position followed a high-level EDPB meeting in Dublin on 16 and 17 July.
The Board called for a framework allowing authorities to exchange information, including confidential information, where it is relevant to enforcement within their respective mandates. The EDPB linked the issue to the increasing complexity of the regulatory environment and noted that the growth in AI use has contributed to more complex complaints.
The meeting also covered cooperation between supervisory authorities, including resource pooling and work relating to enforcement procedures. The Board discussed preparations connected with the forthcoming Procedural Regulation.
Why this matters
The EDPB’s position addresses coordination between regulators where AI cases span multiple digital regimes. A legal basis for information sharing would enable evidence and confidential supervisory information to move more easily between authorities, affecting how cross-regulatory investigations are conducted.
United Kingdom consults on payment rules for agentic payments
On 14 July 2026, HM Treasury opened its Modernising Payment Services Regulation consultation. Responses are due by 6 October 2026.
The consultation examines changes to the United Kingdom’s regulatory framework for payment services and electronic money. HM Treasury states that the framework needs to account for developments including tokenised payments, Open Banking and agentic payments.
In relation to agentic payments, the consultation asks whether existing requirements concerning authentication, consent and liability for unauthorised transactions require changes to accommodate payment activity involving autonomous agents.
HM Treasury states that changes to the existing regulatory framework following the consultation would be implemented through secondary legislation.
Why this matters
The consultation brings agentic payments into formal financial regulation, with particular attention to consent and liability. It also sets the basis for how these issues may be addressed through future UK payment rules.
White House launches Gold Eagle AI cybersecurity clearinghouse
On 14 July 2026, the White House announced the launch of the Gold Eagle initiative, a cybersecurity vulnerability coordination clearinghouse using advanced AI capabilities to support the detection, prioritisation and remediation of vulnerabilities affecting government and critical infrastructure.
The White House described the initiative as an implementation measure under Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, issued on 2 June 2026.
According to the White House release, the Executive Order directed the Treasury Secretary, in consultation with the National Cyber Director, the National Security Agency and the Cybersecurity and Infrastructure Security Agency, to establish an AI cybersecurity clearinghouse in voluntary collaboration with AI developers and critical-infrastructure operators.
Gold Eagle provides a named coordination mechanism through which AI capabilities are incorporated into vulnerability-management activity.
Why this matters
The initiative places AI governance within cybersecurity and critical-infrastructure operations. It also creates a coordination framework between federal authorities and private operators for vulnerability management.
China extends generative AI filing to additional on-device services
On 15 July 2026, the Cyberspace Administration of China announced that seven additional mobile-device-side generative AI services had completed filing under China’s Interim Measures for the Management of Generative AI Services. The services listed by the CAC included Apple Intelligence.
The announcement forms part of the CAC’s continuing filing process for generative AI services.
Related CAC filing guidance states that generative AI applications or functions made available online should disclose information about the filed generative AI service they use. This includes displaying the model name and filing number in a prominent location or on the relevant product-information page.
The July announcement confirms the application of the filing process to additional generative AI functionality operating on mobile devices.
Why this matters
The announcement extends China’s generative AI filing framework to on-device services. For providers and device manufacturers, this links market availability to filing and product-level disclosure requirements.
Looking ahead
The developments published between 13 and 19 July show AI governance continuing to operate through a combination of AI-specific measures and established sectoral frameworks.
In Europe, the Commission’s DMA measures and the German ZAK proceedings address AI services through competition and media regulation respectively. The EDPB’s position focuses instead on the institutional arrangements needed when regulatory responsibilities overlap.
Similar patterns are visible internationally. The United Kingdom is considering agentic AI through payments regulation, while the United States has incorporated AI capabilities into an operational cybersecurity coordination mechanism. China continues to apply its existing generative AI filing framework to additional forms of deployment, including services operating on mobile devices.
Across these developments, regulatory attention extends beyond the characteristics of AI models themselves to the environments in which AI services are distributed, supervised and integrated into regulated activities.
Sources
European Commission DMA specification measures on Google AI interoperability and Search data access: https://digital-markets-act.ec.europa.eu/commission-provides-guidance-google-ai-interoperability-android-and-sharing-google-search-data-under-2026-07-16_en
ZAK supervisory notices concerning Google and Perplexity AI services: https://www.die-medienanstalten.de/presse/pressemitteilungen/zak-bescheide-ki-angebote-google-perplexity/
EDPB statement on cross-regulatory information sharing: https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en
HM Treasury consultation on modernising payment services regulation: https://www.gov.uk/government/consultations/modernising-payment-services-regulation
White House announcement of the Gold Eagle initiative: https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/
Cyberspace Administration of China generative AI filing information: https://www.cac.gov.cn/