Weekly AI Governance Brief: 6–12 July 2026

Share

Bringing you the latest developments in the AI governance world.

EU Commission presents an action plan linking AI oversight to cyber resilience

On 7 July 2026, the European Commission published the EU Action Plan on Cybersecurity and Artificial Intelligence. The policy and legislative action plan connects the governance of advanced AI systems with the EU's broader cybersecurity and resilience framework. The plan is organised around the safe and responsible use of advanced AI and the development of European AI capabilities for cybersecurity. It states that the Commission will strengthen the EU’s capacity to evaluate AI models before they are placed on the European market.

The Commission also intends to work with the European Union Agency for Cybersecurity, ENISA, on a European blueprint for secure access to advanced AI systems for cybersecurity purposes. Further measures include a secure testing platform for critical sectors and an EU Grand Challenge focused on AI for cybersecurity.

The publication links these initiatives to existing EU frameworks, including the Network and Information Security Directive, the Cyber Resilience Act, the Cyber Solidarity Act and the Digital Operational Resilience Act.

Why this matters

The action plan places AI oversight within the operational structures already used for cybersecurity and resilience governance. Organisations operating in critical sectors may therefore need to consider AI deployment alongside existing ICT risk, testing and incident preparedness arrangements.

The involvement of ENISA also indicates an institutional role for the agency in developing technical and operational approaches to secure AI access. For regulated entities, the plan establishes a clearer connection between AI governance processes and obligations arising under frameworks such as DORA and NIS2.

EU Commission and AI Board endorse the transparency code ahead of August obligations

On 9 July 2026, the European Commission published its opinion on the assessment of the Code of Practice on Transparency of AI-generated content. The Opinion followed the Commission’s conclusion on 8 July that the code adequately addressed the obligations contained in Article 50(2), Article 50(4) and Article 50(5) of the AI Act.

The European Artificial Intelligence Board later adopted its own adequacy assessment. According to the Commission, the code may be signed by providers and deployers of generative AI systems and constitutes an EU-wide instrument intended to facilitate compliance with the relevant transparency obligations.

The code addresses the detection and labelling of AI-generated content, including deepfakes. The Commission also stated that the AI Office will facilitate formal updates to the code at least once every two years. The underlying transparency obligations become applicable on 2 August 2026.

Why this matters

The EU Commission Opinion and the AI Board assessment provide an institutionally recognised route for demonstrating compliance shortly before the relevant AI Act provisions begin to apply.

Providers and deployers using the code will have a common reference point for implementing content marking and labelling controls across the EU. This may reduce divergence between national approaches while clarifying the respective roles of the Commission, the AI Office and the AI Board in maintaining the compliance framework.

Operationally, organisations covered by Article 50 will need to connect the code’s requirements with product design, content management and documentation processes.

EU Commission opens a targeted consultation on safeguarding data sovereignty

On 8 July 2026, the European Commission opened a targeted consultation on safeguarding the EU’s data sovereignty. The consultation will remain open until 8 September 2026.

The Commission is seeking evidence from participants across the data value chain about dependencies affecting European organisations. The consultation covers barriers to accessing or using data held in third countries, obstacles to transferring data into the European Union and risks associated with third-country access to sensitive data.

The Commission presents the consultation as a follow-up to the Data Union Strategy. It is also linked to the European Tech Sovereignty Package, which includes measures concerning AI, cloud infrastructure, semiconductors and open-source technologies.

Why this matters

Although the consultation is not limited to AI systems, the issues under consideration affect access to training data, model deployment and the use of cloud infrastructure. They are also relevant to public bodies and regulated organisations that rely on third-country technology providers or process sensitive data through external platforms.

The consultation may help define how responsibility for data dependencies is distributed between technology providers, users and public authorities. It also brings data access and third-country exposure into the wider institutional discussion about European technology sovereignty.

UK places four hyperscalers under direct financial-sector resilience oversight

On 10 July 2026, HM Treasury announced that four major technology providers would be designated as Critical Third Parties from 13 July 2026. The designated entities are Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL and Oracle Corporation UK Limited.

The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority stated that they would begin joint oversight of the designated firms’ critical services to the financial sector on the same date. The designation is reflected in the Critical Third Parties (Designation) Regulations 2026, SI 2026/777.

Under the regime described by the regulators, the authorities may gather information and assess the resilience of critical services. They may also address system-level risks arising from concentrated reliance on major technology providers.

Why this matters

The designations bring selected cloud and technology providers directly within the United Kingdom’s financial-sector supervisory perimeter. Oversight is therefore no longer limited to the regulated financial institutions purchasing the relevant services.

The regime creates a direct supervisory relationship between the authorities and providers whose disruption could affect multiple financial firms. UK authorities describe this arrangement as complementary to existing outsourcing and operational resilience requirements, and comparable EU arrangements under DORA.

For financial institutions, the regime changes the institutional context in which cloud concentration and third-party resilience are assessed.

China’s CAC publishes first-phase results of its AI application enforcement campaign

On 6 July 2026, the Cyberspace Administration of China published the first-phase results of its special campaign addressing disorderly AI applications.

The CAC stated that the campaign focused on failures to complete required large-model filing and registration procedures. It also examined weaknesses in platform safety, review and filtering capabilities, as well as AI data poisoning and non-compliance with synthetic-content labelling requirements.

According to the authority, action was taken against more than 14,000 AI products, including websites, applications and agents. More than six million items of illegal or non-compliant information were removed, and action was taken against more than 26,000 accounts. The CAC also reported the removal of 1,300 non-compliant AI goods and nine open-source datasets.

The second phase will address AI-generated false information, violent or vulgar material, impersonation and harms involving minors. It will also cover AI-enabled coordinated manipulation activity.

Why this matters

The figures reported by the CAC show enforcement being applied across several parts of the AI supply and deployment chain. The campaign covers model registration, dataset governance and platform moderation, rather than focusing on a single category of prohibited content.

For organisations operating in China, compliance responsibility extends beyond formal filing. Platforms must also maintain review, labelling and safety controls capable of functioning at scale. The campaign further demonstrates the CAC’s central supervisory role in assessing both AI products and the information distributed through them.

ITU launches a standards mechanism for trust and identity in agentic AI

On 9 July 2026, the International Telecommunication Union announced the establishment of a Focus Group on Trust and Identity for Humans and Agentic AI.

The new standards initiative will examine trusted digital identity and accountable behaviour by AI agents across their lifecycle. Its stated areas of concern include impersonation, unauthorised actions and the use of AI agents in financial transactions or critical infrastructure.

The group’s programme includes development of common terminology and reference architectures for identity and interoperability. It will also consider assurance models, credential mechanisms and criteria for the continuous assessment of AI agents.

The initiative is expected to produce a standardisation roadmap. Its first meeting is scheduled for November 2026.

Why this matters

The focus group does not create binding legal obligations. It establishes a formal international process for developing technical and governance concepts relevant to systems that can authenticate, communicate or act across digital environments.

Identity and assurance mechanisms are particularly relevant where responsibility must be attributed between an AI agent, its provider and the organisation deploying it. The initiative also creates a venue for considering how human control can be represented in technical standards for autonomous or semi-autonomous systems.

Looking ahead

The developments published during the week show AI governance being integrated more closely with cybersecurity, data infrastructure and operational resilience. Within the European Union, the Commission combined preparatory implementation of the AI Act with broader work on cyber controls and data sovereignty.

Outside the EU, authorities and standards bodies focused on direct supervision of technology providers, enforcement across AI applications and governance mechanisms for agentic systems. Across these initiatives, oversight increasingly concerns the infrastructure and organisational controls surrounding AI, rather than the characteristics of individual models alone.

Sources

European Commission, EU Action Plan on Cybersecurity and Artificial Intelligence: https://digital-strategy.ec.europa.eu/en/news-redirect/946754

European Commission, Commission Opinion and AI Board adequacy assessment of the Code of Practice on Transparency of AI-generated content: https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content

European Commission, Code of Practice on Transparency of AI-Generated Content: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content

European Commission, targeted consultation on safeguarding the EU’s data sovereignty: https://digital-strategy.ec.europa.eu/en/consultations/targeted-consultation-safeguarding-eus-data-sovereignty

HM Treasury, UK financial system strengthened with new safeguards for major technology providers: https://www.gov.uk/government/news/uk-financial-system-strengthened-with-new-safeguards-for-major-technology-providers

Bank of England, UK financial regulators to begin overseeing Critical Third Parties announced by HM Treasury: https://www.bankofengland.co.uk/news/2026/july/uk-financial-regulators-to-begin-overseeing-critical-third-parties-announced-by-hmt

UK Government, The Critical Third Parties (Designation) Regulations 2026, SI 2026/777: https://www.legislation.gov.uk/uksi/2026/777/contents/made

Cyberspace Administration of China, first-phase results of the campaign addressing disorderly AI applications: https://www.cac.gov.cn/2026-07/06/c_1785081384384987.htm

International Telecommunication Union, launch of the Focus Group on Trust and Identity for Humans and Agentic AI: https://www.itu.int/en/mediacentre/Pages/PR-2026-07-09-focus-group-agentic-AI.aspx

International Telecommunication Union, Focus Group on Trust and Identity for Humans and Agentic AI: https://www.itu.int/en/ITU-T/focusgroups/tida/Pages/default.aspx

Read more