Weekly AI Governance Brief: 20–26 July 2026
Bringing you the latest developments from the AI governance world.
European Commission clarifies Article 50 AI Act transparency duties
On 20 July, the European Commission published its Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act.
The guidelines were published alongside the Code of Practice on Transparency of AI-Generated Content. The Commission and the AI Board consider the code an adequate voluntary tool for demonstrating compliance with the relevant transparency obligations.
The package is intended for providers and deployers of affected AI systems, as well as competent authorities, ahead of the 2 August 2026 application date for Article 50.
The Commission’s guidance provides implementation detail for transparency requirements concerning interactions with AI systems and certain forms of AI-generated or manipulated content. It addresses how transparency duties apply to AI interaction notices and deepfake labelling. It also covers the marking of AI-generated or manipulated content.
The accompanying Code of Practice provides a voluntary framework that organisations can use when seeking to demonstrate compliance with these obligations.
Why this matters
The publication provides a concrete EU implementation reference shortly before Article 50 becomes applicable.
For providers and deployers, the guidance provides greater clarity on the practical forms that transparency controls may need to take. This is directly relevant to product design and compliance processes for affected AI systems.
The Code of Practice also creates a recognised voluntary mechanism for demonstrating compliance. For competent authorities, the package provides a common reference point for applying Article 50.
Commission confirms continued EU–Korea data adequacy
On 23 July, the European Commission completed its first review of the EU adequacy decision for the Republic of Korea.
In its formal review report, COM(2026) 384 final, the Commission concluded that Korea continues to ensure an adequate level of protection for personal data transferred from the European Union.
The review concerned the adequacy decision adopted in 2021 and considered legislative amendments introduced in Korea since 2023. Following the assessment, the existing adequacy decision remains in place.
The result preserves the current GDPR basis for personal-data transfers covered by the EU-Korea adequacy framework.
Why this matters
The review is relevant to organisations whose AI development or deployment depends on personal-data transfers between the EU and Korea.
The Commission’s conclusion means that affected organisations can continue to rely on the existing adequacy framework for covered transfers. It therefore preserves continuity for established cross-border data flows and vendor arrangements.
For AI governance functions, the decision also confirms that the existing transfer mechanism remains available where personal data moves between the two jurisdictions as part of AI-related processing.
TikTok and Apple sanctioned over behavioural and voice data practices
The Republic of Korea’s Personal Information Protection Commission published an enforcement notice on 23 July following decisions taken at its 14th plenary meeting on 22 July.
The PIPC decided to impose penalties totalling KRW 10.558 billion, together with corrective and publication orders, on TikTok and two Apple affiliates for violations of Korea’s Personal Information Protection Act.
According to the regulator, TikTok collected and linked third-party behavioural data and device identifiers without a lawful basis. The data was then used for personalised advertising.
Apple was penalised in relation to the collection and use of Siri voice data and transcripts without proper consent.
The enforcement notice also records findings concerning unlawful overseas transfers and associated corrective measures.
Why this matters
The decision shows how privacy enforcement is being applied to data practices connected with digital platforms and AI-enabled services.
For organisations handling behavioural information, the case draws attention to the legal basis supporting both collection and subsequent use. In relation to voice-assistant services, the decision focuses on consent requirements around interaction data.
The overseas-transfer findings add a separate cross-border data-governance issue. Taken together, the enforcement action links product-level data practices with the controls governing how personal information is transferred and reused.
Singapore issues complementary privacy and transparency guidance for generative AI
On 20 July, two Singapore authorities published separate but related governance instruments concerning generative AI.
The Personal Data Protection Commission issued its Advisory Guidelines on Use of Personal Data in Generative AI. The finalised guidance explains how Singapore’s personal-data regime applies to the use of personal information in generative AI models and systems.
The guidelines address the collection and use of personal data, as well as the allocation of roles across the AI value chain. They also cover due diligence relating to publicly available personal data.
The document was issued as final guidance following consultation rather than as a new legislative proposal.
On the same day, Singapore’s Infocomm Media Development Authority launched voluntary Transparency Guidelines for Generative AI Chatbots.
The IMDA guidelines introduce a Chatbot Information Card intended to provide users with plain-language information about a chatbot’s purpose and limitations. The card also covers how data may be handled and how users can report problems.
The framework is voluntary and is intended to be refined through industry input. Its launch was publicly associated with early adopters including DBS and Google, as well as Meta and OCBC. Singapore Airlines was also identified among the early adopters.
Why this matters
Taken together, the two publications show Singapore developing more operational guidance around the use of generative AI.
The PDPC guidelines focus on how personal data is handled within model development and deployment. They also clarify how responsibilities may be distributed across organisations participating in the AI value chain.
The IMDA guidelines address a different layer of governance by focusing on information presented directly to users. The Chatbot Information Card provides a standardised format for disclosures that might otherwise be spread across product documentation or terms of service.
For organisations developing or procuring generative AI applications, the two documents provide separate governance reference points for internal data handling and external transparency.
Looking ahead
This week’s developments show regulators continuing to move from broad governance principles toward more specific implementation frameworks.
In the EU, the Commission has provided detailed guidance shortly before Article 50 of the AI Act becomes applicable. Its review of the Korea adequacy decision also preserves continuity within an established international data-transfer framework.
The Korean enforcement action shows existing privacy law being applied to behavioural data and voice-assistant information. Singapore’s two guidance documents address the use of personal data in generative AI while also introducing a standardised model for chatbot transparency.
Across the developments, the common feature is a greater focus on how governance requirements are reflected in actual systems and data practices.
Sources
European Commission Guidelines on Article 50 AI Act transparency obligations: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
European Commission Code of Practice on Transparency of AI-Generated Content: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
European Commission adequacy decisions page and Republic of Korea review announcement: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
European Commission COM(2026) 384 final review report: https://ec.europa.eu/transparency/documents-register/api/files/COM(2026)384_0/090166e530f429d9
Republic of Korea PIPC enforcement notice concerning TikTok and Apple: https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12330
Singapore PDPC Advisory Guidelines on Use of Personal Data in Generative AI: https://files.app.optical.gov.sg/pdpc/production/assets/143cb9d4-532e-4cca-9a77-bcc0415ca294.pdf
Singapore PDPC publication on generative AI personal-data guidance: https://www.pdpc.gov.sg/media-events/pdpc-issues-guidance-for-organisations-on-responsible-use-of-personal-data-in-generative-ai
Singapore IMDA Transparency Guidelines for Generative AI Chatbots announcement: https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/new-transparency-guidelines-to-help-consumers-use-generative-ai-chatbots-safely-and-responsibly
Singapore ministerial speech accompanying the chatbot transparency guidelines launch: https://www.mddi.gov.sg/newsroom/opening-speech-by-minister-josephine-teo-at-singapore-data-festival-at-sands-expo-and-convention-centre/