Weekly AI Governance Brief: 14–20 September 2026

Share

Bringing you the latest developments in the AI Governance world.

EU KIDS Act extends child-safety regulation directly to AI systems

On 17 September, the European Commission adopted its proposal for the EU KIDS Act, establishing a new framework for protecting minors across digital services and AI systems.

The proposal establishes an EU-wide approach to children's access to specified online services. Children below 15 would not be permitted to create autonomous accounts on covered social-networking and video-sharing services, with differentiated arrangements for younger age groups.

The proposal extends beyond social media. It expressly covers risky AI systems used by minors, including AI companions and chatbots. Providers of those systems would need to demonstrate compliance with the new obligations before placing them on the market and maintain mechanisms for monitoring emerging risks and incidents.

For Very Large Online Platforms, the proposal reverses the conventional compliance logic. Before covered services interact with children, providers would need to submit a compliance plan and demonstrate, through independent verification, that they intend to meet the applicable requirements.

The proposal would operate alongside the EU's existing digital regulatory framework, with supervision divided between the Commission and relevant national authorities.

Why this matters

The KIDS Act would create a direct regulatory bridge between online-safety governance and AI regulation.

For child-facing AI companions and chatbots, compliance would no longer concern only general AI transparency or model-level obligations. Providers would face requirements connected to market access and continuing monitoring of risks after deployment.

The proposal also places independent verification within the compliance structure for major platforms. This reinforces a broader movement in AI and digital governance toward requiring organisations to demonstrate that safeguards work rather than relying only on formal policies.

Finland translates AI Act transparency rules into operational guidance

On the same day, Finland's Transport and Communications Agency, Traficom, published detailed guidance explaining how the AI Act's transparency obligations should operate in practice.

The guidance addresses providers of interactive AI systems and generative AI, as well as organisations deploying AI within their own activities. For systems interacting directly with people, users should be informed that they are dealing with AI no later than the beginning of the interaction. A disclosure hidden in terms and conditions or documentation will generally not be sufficient.

Traficom also provides detailed interpretation of the requirement to make AI-generated or manipulated content machine-readable and detectable. It identifies possible mechanisms including digital watermarks, metadata, cryptographic provenance methods and digital fingerprints. The chosen method must, as far as technically feasible, be effective and interoperable.

The authority distinguishes between substantial AI alteration and routine editing. Changes such as grammar correction or minor image adjustments generally fall outside the marking requirement, while generated summaries, removal of objects or people, composite images and other substantial alterations generally fall within it.

For deployers, the guidance covers disclosures around emotion recognition, biometric categorisation, deepfakes and AI-generated public-interest text. It also confirms that AI agents fall within the transparency rules when they interact with people while performing tasks.

Traficom identifies itself as the Finnish supervisory authority for most AI Act transparency requirements and provides a mechanism through which suspected breaches can be reported.

Why this matters

The publication illustrates the next stage of AI Act implementation: national authorities translating the Regulation's provisions into practical compliance expectations.

The distinction between adequate and inadequate disclosure is particularly useful for operators. Traficom makes clear that transparency cannot ordinarily be satisfied through buried contractual language and provides concrete examples of how disclosures can be presented.

Its interpretation of technical marking also gives generative-AI providers a more practical indication of what regulators may expect when assessing whether generated content can be identified as artificial.

UK regulator develops AI sandbox for medicines-safety evaluation

On 16 September, the UK's Medicines and Healthcare products Regulatory Agency opened a call for evidence under its Beyond ADMET: AI for medicines safety initiative.

The exercise examines how AI can be used in evaluating medicines safety, including prediction and assessment of absorption, distribution, metabolism, excretion and toxicity. The MHRA is seeking evidence from organisations involved across medicines development, as well as biotechnology and AI developers.

The regulator is specifically examining model development and validation, access to appropriate data, data-sharing constraints and regulatory considerations.

The evidence will inform development of a dedicated regulatory sandbox. It will also support future MHRA regulatory work and engagement with innovators and researchers.

The consultation does not itself establish new compliance requirements. It instead represents a formal regulatory-development process intended to establish how AI models might be evaluated within a specialised medicines-safety context.

Why this matters

The initiative shows sector-specific AI regulation moving toward questions of evidence and validation.

Rather than attempting to establish a universal standard for AI performance, the MHRA is examining what validation methods are appropriate for a defined regulatory use case.

The planned sandbox provides a mechanism for testing those expectations before they become embedded in wider regulatory practice.

Canada and Germany move toward a sovereign AI cooperation framework

On 17 September, Canada and Germany held the first co-chairs' meeting of the Sovereign Technology Alliance, led by Canadian AI Minister Evan Solomon and German Digital Transformation Minister Karsten Wildberger.

The two governments describe the Alliance as a platform through which Canada, Germany and trusted partners can cooperate to strengthen sovereign AI capabilities.

At the meeting, ministers reviewed interest from prospective participants and agreed to continue preparations toward a launch involving founding members. The initiative builds on existing bilateral AI cooperation between the two countries.

The Alliance is not a regulatory instrument and does not establish compliance obligations. Its relevance lies in the creation of an institutional framework centred on AI sovereignty, economic security and development of a more diverse technology ecosystem.

Why this matters

AI governance increasingly encompasses dependencies on the infrastructure and technology required to develop and operate AI, rather than only rules governing individual systems.

The Sovereign Technology Alliance reflects that wider institutional focus. It frames AI capability as a matter for coordinated government action among trusted partners and connects technology policy with questions of economic security and strategic dependence.

Looking ahead

The developments of 14–20 September show two distinct dimensions of AI governance becoming more concrete.

Within the EU, regulatory attention is moving toward operational rules affecting deployed systems. The KIDS Act would add use-case-specific obligations for child-facing AI, while Traficom's guidance translates existing AI Act transparency requirements into practical expectations for providers and deployers.

The UK initiative similarly moves from general AI principles toward evidence requirements for a defined regulatory setting. Alongside these compliance-focused developments, the Canada-Germany initiative demonstrates how access to AI capabilities and infrastructure is increasingly being treated as a governance and sovereignty issue in its own right.

Sources

European Commission proposal for the EU KIDS Act: digital-strategy.ec.europa.eu

Finnish Traficom guidance on AI Act transparency obligations: traficom.fi

UK MHRA Beyond ADMET AI for medicines safety call for evidence: gov.uk

Canada-Germany Sovereign Technology Alliance statement: canada.ca

Read more