Tech Policy Unit Horizon Scanner
June 2026
As we reached the mid-point of the year the global focus on AI remained fixed: the EU Council and Parliament both signed off on amendments to the EU AI Act, including the postponement of the high-risk deadlines, the commission pressed ahead with transparency obligations for AI-generated content, Japan consulted on a new AI Basic Plan, Thailand launched its AI 2026 strategy, and the UAE established a national Artificial Intelligence and Data Authority. At the same time, regulators in Singapore, the DIFC and the UK sought to clarify how existing data protection and governance obligations should apply across the AI lifecycle.
There also continues to be growing convergence of AI and cybersecurity policy. Most notably, the Five Eyes cybersecurity agencies warned that frontier AI is accelerating the speed, sophistication and scale of attacks, reinforcing a global regulatory expectation that cyber resilience be treated as a board-level priority. But elsewhere, Japan updated government cybersecurity standards to address AI-enabled threats, Australia consulted on revisions to its Essential Eight framework, and South Korea issued guidance following incidents involving exposed credentials in cloud and development environments.
Data governance and digital trust also remained a major focus. China introduced new requirements for network data security risk assessments, consulted on distributed digital identity frameworks and proposed updates to its personal information protection standards. Singapore strengthened international privacy cooperation through new arrangements with South Korea and Hong Kong, while the UK implemented new statutory requirements for handling data protection complaints and published final guidance for consumer IoT products.
Beyond AI and data regulation, governments continued to pursue wider digital policy objectives centred on sovereignty, market oversight and online safety. The European Commission unveiled an ambitious Technology Sovereignty Package covering semiconductors, cloud infrastructure and AI, while the EU courts delivered another significant Digital Markets Act judgment in Meta's gatekeeper challenge. Meanwhile, the UK announced far-reaching child online safety measures, and US lawmakers advanced draft federal frameworks for both frontier AI governance and consumer privacy.
THE REGIONS IN DETAIL
APAC (Excluding China)
Australia
Australian digital platform regulators sign MoU to strengthen coordinated oversight
On 17 June 2026, the Digital Platform Regulators Forum (DP-REG) signed a Memorandum of Understanding to formalise cooperation among Australia's digital platform regulators. The MoU establishes structured arrangements for information sharing and coordination on issues including scams, privacy, online safety, and competition. Each regulator retains its independent statutory functions while participating in a coordinated oversight framework for emerging digital-platform risks.
ACSC consults on updated Essential Eight cybersecurity framework
On 15 June 2026, the Australian Signals Directorate's Australian Cyber Security Centre (ACSC) launched a public consultation on a revised Essential Eight cybersecurity framework. The updated framework is designed to offer greater flexibility and clearer guidance for organisations seeking to build cyber resilience. The new framework is based on the Information Security Manual (ISM) and will offer prioritised, threat‑informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance.
Japan
NCO revises government cybersecurity guidelines to address AI-enhanced threats
On 12 June 2026, Japan's National Cyber Director's Office (NCO) partially revised its Guidelines for Establishing Security Standards for Government Agencies, updating the cybersecurity baseline applicable to 122 government bodies. The revisions respond to the growing sophistication and automation of cyber-attacks, including through the use of high-capability AI. Key areas of revision include strengthening vulnerability measures, ensuring the establishment of IT Business Continuity Plans, strengthening incident response requirements (including enhanced reporting obligations to the NCO), reinforcing principal authentication including multi-factor authentication, and improving anti-phishing measures through DMARC (countermeasures against email spoofing).
CSTP publishes draft AI Basic Plan for public consultation
On 19 June 2026, Japan's Cabinet Office (Council for Science, Technology and Innovation Policy, CSTP) published a draft revision of its Basic Plan for Artificial Intelligence The draft sets out an updated policy framework under Japan's AI Act, structured around four principles: promoting innovation while mitigating risks; adopting agile and adaptive policy approaches; advancing integrated domestic and international strategies; and strengthening data sharing and utilisation. It identifies four policy pillars: accelerating AI deployment, strengthening development capabilities, leading AI governance, and enabling transformation toward an AI-driven society.
Singapore
PDPC consults on proposed guidelines for personal data use in generative AI
On 2 June 2026, Singapore's Personal Data Protection Commission (PDPC) launched a public consultation on proposed Advisory Guidelines for the use of personal data in generative AI systems. The proposed guidelines address three stages of the generative AI lifecycle: development, deployment, and post-deployment. They set out responsibilities for model providers, system providers, and system deployers, and include recommended practices such as upstream data verification, case-by-case review of access requests, and machine unlearning. It also sets out their relevant data protection responsibilities under the Personal Data Protection Act (PDPA) , including obligations relating to retention limitation, protection, purpose limitation, and accountability. Submissions closed on 1 July 2026.
PDPC Strengthens International Cooperation through Memoranda of Understanding (MOUs) with the Republic of Korea and Hong Kong.
On 15 June the Personal Data Protection Commission (PDPC) announced that it has signed a new Memorandum of Understanding (MOU) with the Personal Information Protection Commission of the Republic of Korea and renewed its MOU with the Office of the Privacy Commissioner for Personal Data, Hong Kong. The agreement with Korea focuses on enabling trusted cross-border data flows, supporting responsible data innovation, and enhancing enforcement cooperation, including collaboration on emerging areas such as privacy enhancing technologies (PETs) and regulatory sandboxes, while the renewed Hong Kong MOU expands existing cooperation to cover enforcement, knowledge sharing, and joint research on technologies including artificial intelligence and PETs.
Singapore launches Online Safety Commission
On 29 June 2026, Singapore's Online Safety Commission (OSC) began operations, creating a new avenue for victims to seek redress for online harms. In its first phase it will address five harms – online harassment (including sexual harassment), doxxing, online stalking, intimate image abuse, and image-based child abuse – with victims generally required to report to platforms first for harassment/stalking (before escalating if no adequate response within 24 hours) but able to report directly to OSC for more severe harms such as doxxing or image abuse, while the Commissioner can issue binding directions to users, group administrators, or platforms to remove or restrict harmful content, with non-compliance constituting a criminal offence. The OSC also introduces enhanced obligations for six major online service providers and plans to expand coverage to additional harm categories over time.
South Korea
PIPC advises organisations to strengthen credential management in cloud and development environments
On 15 June 2026, South Korea's Personal Information Protection Commission (PIPC) issued guidance advising organisations to strengthen credential management following an increase in data breaches involving credentials stored in cloud environments and development tools. Organisations are advised not to store credentials in development tools and to adopt robust management protocols. The guidance also recommends monitoring source code repositories to reduce the risk of credential exposure.
Thailand
ETDA announces AI 2026 strategy to promote trust in AI governance
On 9 June 2026, Thailand's Electronic Transactions Development Agency (ETDA) announced its AI 2026 strategy, which aims to promote trust in AI governance and position Thailand as a regional hub for responsible AI. The strategy includes the development of AI Governance Guidelines and Toolkits, a Red Teaming Challenge to test AI systems for vulnerabilities, and capacity-building programmes integrating AI ethics across sectors. ETDA also intends to establish an AI Governance Practice Centre as a UNESCO Category 2 Centre.
Vietnam
Government advances draft High Technology Decree with focus on R&D incentives
On 17 June 2026, Vietnam's Government led by the Ministry of Science and Technology (MST), announced progress on a draft decree implementing the Law on High Technology, with a focus on research and development incentives. The proposal includes support for strategic technologies, business incentives, land-use incentives, and mechanisms to attract talent. The initiative forms part of Vietnam's broader innovation and digital transformation agenda. The Government has also indicated a preference not to create a new standalone AI fund, but to integrate AI development into existing funding mechanisms to improve efficiency and avoid duplication.
China
Chinese Authorities issue Measures on Network Data Security Risk Assessment
On 18 June 2026, the Cyberspace Administration of China, jointly with the Ministry of Industry and Information Technology and the Ministry of Public Security, issued the Measures for Network Data Security Risk Assessment. The Measures establish a structured approach for network data security risk assessments, requiring processors handling important data to conduct annual assessments and report findings to the relevant authorities. The Measures will take effect on 20 August 2026
Chinese Authorities Releases the Guidelines on Data Classification for Financial Information Services
On 8 June 2026, the Cyberspace Administration of China, together with the People's Bank of China and four other authorities, jointly issued the Guidelines on Data Classification and Grading for Financial Information Services. The Guidelines provide a framework for classifying and grading financial information service data, covering data identification, classification, grading, and cataloguing. The framework is intended to guide institutions in identifying important data and strengthening data security management.
CAC consults on Provisions on Distributed Digital Identity
On 18 June 2026, the Cyberspace Administration of China issued the draft Provisions on Promoting the Interoperability and Mutual Recognition of Distributed Digital Identity for public consultation. The draft aims to promote the development and cross-platform recognition of distributed digital identities based on blockchain technology, and to establish a unified public service framework. It outlines rules on identity registration, credential issuance, and application in sectors including finance and public services. Comments are requested by 18 July 2026.
TC260 invites comments on draft Personal Information Security Specification
On 17 June 2026, the National Technical Committee 260 on Cybersecurity of SAC invited public comments on a draft Personal Information Security Specification. The draft updates the personal information protection framework across the data lifecycle and introduces enhanced requirements on processing legal bases, consent, and governance. Comments are requested by 16 August 2026.
Africa
Kenya's Data Commissioner Calls for Coordinated Action on Data Protection in Humanitarian Contexts
On 2 June 2026, Kenya's Data Commissioner, Immaculate Kassait, called upon Data Protection Officers to adopt coordinated approaches and strengthen information sharing and skills development to address growing data protection and cybersecurity risks. Speaking at a DPO Humanitarian Action Certification Course held in Mombasa, the Commissioner also stressed the need for transparency and community engagement in humanitarian data use, warning that advancing technologies increase privacy risks and require strong accountability and governance standards.
Nigeria
NDPC Launches Data Protection Programme with Meta Following Regulatory Settlement
On 8 June 2026, the Nigeria Data Protection Commission (NDPC) announced the launch of the Meta-Supported Initiatives for Data Protection (M-SIDP), a two-year programme aimed at strengthening data protection standards and safeguards across Nigeria's digital ecosystem. The M-SIDP is structured around four strategic areas: governance, research and development; fostering safety and sustainability mechanisms across digital technology ecosystems; capacity building for Data Protection Officers and Data Protection Compliance Organisations; and public awareness campaigns with a particular focus on vulnerable groups. The NDPC indicated that it will provide periodic updates on the programme's progress and called on all stakeholders to support the initiative in advancing a secure and accountable privacy ecosystem in Nigeria.
South Africa
High Court Holds Bitcoin is "Capital" and "Money" Under Exchange Control Regulations
On 1 June 2026, the Gauteng Division of the High Court (Johannesburg) held in Mangundhla v South African Reserve Bank that Bitcoin constitutes both "money" and "capital" for the purposes of regulation 10(1)(c) of the Exchange Control Regulations, 1961 and the Currency and Exchanges Act 9 of 1933, expressly departing from the contrary 2025 High Court decision in Standard Bank of South Africa v South African Reserve Bank. The case concerned the transfer of approximately 1,680 Bitcoin, valued at around ZAR 182 million, to wallets held on cryptocurrency exchanges registered outside South Africa, which the court accepted constituted an export of capital in breach of the Regulations — resulting in an order for the forfeiture of approximately ZAR 6 million in Bitcoin assets and funds. The court held that once Bitcoin is placed beyond the Reserve Bank's jurisdiction, the capital has been exported, regardless of whether the wallets could be accessed from within South Africa or whether the assets had been converted into foreign currency.
Europe
European Union
General Court partially annuls Meta's DMA gatekeeper designation
On 3 June 2026, the General Court of the European Union partially upheld Meta’s challenge against the European Commission’s 5 September 2023 decision designating several Meta services as core platform services under the Digital Markets Act (DMA). The Court annulled the Commission’s decision insofar as it designated Marketplace as an online intermediation service meeting the criteria for gatekeeper designation. The Court, however, upheld the designation of Messenger as a gatekeeper interpersonal communications service. It confirmed the Commission’s assessment that Messenger constitutes a service distinct from Facebook and that it may be assessed independently under the DMA framework. The Court found that the Commission had not erred in concluding that Messenger individually constitutes an important gateway.
European Commission presents European Technological Sovereignty Package
On 3 June 2026, the European Commission presented the European Technological Sovereignty Package aimed at strengthening the EU’s capabilities in semiconductors, artificial intelligence, cloud and open source. According to the Commission, the package seeks to reduce dependencies on non-EU providers of critical digital technologies and support Europe’s digital capacity. The package includes two legislative proposals – the Chips Act 2.0 and the Cloud and AI Development Act – as well as an Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy. The Commission stated that these measures are intended to support AI deployment, expand technological options for businesses, citizens and public administrations, and reinforce the EU’s digital resilience.
European Commission publishes Code of Practice on labelling AI-generated content
On 10 June 2026, the European Commission released a voluntary Code of Practice on marking and labelling content generated by artificial intelligence. The new code outlines practical measures for providers and deployers of generative AI systems to comply with upcoming transparency requirements in the EU’s AI Act, which from 2 August 2026 will require clear labels for AI-generated content (such as deepfakes or AI-created text on public interest topics) and disclosure when users interact with AI systems like chatbots. Drafted by independent experts with broad stakeholder input, the code is structured in two sections for AI providers and deployers, detailing how to mark AI-generated audio, images, video or text and ensure deepfakes and unreviewed AI content are clearly identified. The Commission has opened the code for signatures and noted that signatories will be able to show compliance with the AI Act’s transparency rules once those rules take effect.
European Parliament and Council both approve AI Act simplification measures
On 16 June 2026, the European Parliament and on 29 June, the Council of the European Union, approved targeted amendments to the AI Act as part of the EU’s Omnibus simplification package. The measures delay key compliance deadlines for high-risk AI systems to 2 December 2027 (stand-alone systems) and 2 August 2028 (embedded systems), while requiring transparency obligations for AI-generated content by 2 December 2026, and the establishment of AI regulatory sandboxes by competent authorities at the national level by 2 August 2027. The package also introduces a new prohibition on AI systems that generate non-consensual intimate imagery or child sexual abuse material. Products covered by machinery regulation (and previously classified as high-risk under Annex I) were exempted from direct applicability of the AI Act. The changes are intended to reduce compliance burdens, improve legal certainty and support more consistent implementation across Member States. The final text will now by published in the Official Journal of the European Union. It will enter into force three days after it is published there.
United Kingdom
UK Government Announces Social Media Ban for Under-16's
On 15 June 2026, the UK Department for Science, Innovation and Technology (DSIT) announced that, from 2027, the Government will ban social media platforms from offering services to children under 16. The ban will capture user-to-user platforms whose primary purpose is to enable social interaction and that allow users to post material and use algorithms. The package also introduces default restrictions on harmful features such as livestreaming and stranger-to-child communication, a minimum age of 18 for AI "romantic companion" chatbots, and stronger age assurance requirements. Regulations are expected by the end of 2026, with implementation from Spring 2027.
UK DSIT Publishes Digital Standards Policy Aims
On 17 June 2026, the UK Department for Science, Innovation and Technology (DSIT) published “Shaping tomorrow: The UK’s Digital Standards Strategy (2026–2030)”, outlining how the UK will strengthen its leadership in international digital standards to drive economic growth, innovation, trade, and national security. The strategy highlights the significant economic role of standards (contributing to GDP growth, productivity, and trade) and identifies priority areas including AI, cybersecurity, advanced connectivity, quantum technologies, semiconductors, and the internet. It emphasises active UK participation in global standards development organisations to influence outcomes amid increasing geopolitical complexity and safeguard UK values such as security, openness, and interoperability.
UK DSIT to Partner with Tech Companies, Trade Unions and Industry Leaders to Boost AI Adoption and Equip Workers with AI Skills
On 8 June, the Department for Science, Innovation and Technology (DSIT) announced a £200+ million AI adoption package aimed at making the UK the fastest AI-adopting economy in the G7 by boosting business uptake and workforce skills. The initiative combines public funding with industry partnerships (including Cisco, IBM, Deloitte and major UK employers) to expand programmes such as Bridge AI (£100m), Tech Towns, AI Growth Zones, and AI Scholarships, alongside new AI Advisory Growth Labs (starting with legal services) to support safe, regulated deployment. A new AI Economics Institute, chaired by Nobel laureate Simon Johnson, will analyse AI’s impact on jobs and growth, supported by data-sharing from over 30 firms to inform policymaking. Additional measures include sector-led AI Adoption Plans, an AI Assurance Stakeholder Consortium.
UK Government Announced Plans to Stop Children taking, viewing and sharing nude Pictures
On 8 June 2026, the UK Government announced plans to require operating system providers (e.g. Apple, Google) to activate or introduce device-level technology that detects and blocks nude images for children by default across all apps and services, aiming to make it impossible for children to take, share or view such content. Companies are required to implement these measures within three months and must do so without compromising user privacy or collecting data, with adults still able to access content via age verification. If companies fail to act, the Government has signalled it will introduce legislation to compel compliance, including fines and, as a "last resort", potential criminal liability for executives, potentially extending obligations across the supply chain.
ICO Announces New Legal Requirements for Data Protection Complaints
On 23 June 2026, the ICO announced that new legal requirements governing how organisations handle data protection complaints have come into force, alongside the full commencement of the Data (Use and Access) Act 2025. All organisations handling personal data are now required to implement clear complaints procedures, including: providing accessible channels for complaints, acknowledging them within 30 days, conducting appropriate investigations, and communicating outcomes. The ICO has emphasised that the regime is intended to support organisations in embedding good practice and resolving issues at an early stage and has published guidance with practical examples (e.g. subject access requests, data accuracy issues, and marketing complaints) to assist organisations of all sizes. The regulator also highlighted that many businesses remain unaware of the changes, underscoring the need to review complaints processes to ensure compliance and support transparency and customer trust.
ICO Publishes Finalised Guidance on Consumer IoT Products and Services
On 11 June 2026, the ICO published finalised guidance for manufacturers and developers of consumer Internet of Things (IoT) products and services. The guidance addresses the application of UK GDPR and also reflects changes to UK privacy law introduced by the Data (Use and Access) Act 2025 (DUA Act). The guidance emphasises a lifecycle approach to compliance, requiring organisations to embed data protection by design and default throughout the product’s development and operation, including limiting data collection to what is strictly necessary and maintaining ongoing security measures. Noting that most IoT processing is likely to be high risk, organisations may need to conduct data protection impact assessments (DPIAs) more often, particularly where children may be affected.
Ofcom Updates Guidance on Illegal Harms and New Priority Offences
On 25 June 2026, Ofcom published final updates to its Illegal Harms framework under the Online Safety Act 2023, strengthening requirements for platforms to address two offences that became priority offences in December 2025: encouraging or assisting serious self-harm and cyberflashing. Ofcom will assess suicide and serious self-harm as a single category of illegal harm for risk management purposes, while treating cyberflashing as a distinct harm requiring targeted mitigations. Platforms must update their illegal content risk assessments, implement appropriate safety measures, and strengthen systems for detecting, reporting, moderating and removing illegal content. The updated guidance highlights risks linked to AI chatbots, messaging features and the non-consensual sharing of intimate images, and builds on Ofcom's earlier recommendation that certain services deploy automated detection tools, including hash matching technology, to help prevent the spread of illegal intimate images and explicit deepfakes.
Five Eyes Cyber Security Agencies Call for Urgent Actions for AI Shift in Cyber Risk
On 22 June 2026, Five Eyes cyber security agencies (including NCSC, CISA, ACSC, CCCS and GCHQ partners) called for urgent action as frontier AI rapidly transforms cyber risk, warning that timelines for disruptive capability are measured in months, not years. They stress that AI increases the speed, scale, and sophistication of attacks while also offering defensive advantages, making cyber resilience a core leadership and business priority rather than a purely technical issue. Leaders are urged to assess risk and readiness, prioritise foundational controls, empower cyber teams, and remain actively engaged as threats evolve. Key actions include reducing attack surfaces, accelerating patching, addressing legacy systems, strengthening identity and access controls, and rigorously testing incident response plans. The agencies emphasise secure-by-design principles, defence in depth, and preparedness for inevitable breaches, alongside adopting AI to enhance detection and response. They conclude that organisations must act immediately to integrate cyber security into core strategy or face increasing operational, financial, and reputational risk..
Americas
The United States of America
Representatives release bipartisan discussion draft of the Great American AI Act
On June 4, 2026, Reps. Jay Obernolte and Lori Trahan released a bipartisan discussion draft of the Great American Artificial Intelligence Act of 2026, a proposed federal framework for governing frontier AI systems. The draft would apply to large frontier developers, generally entities developing foundation models trained on more than 10²⁶ integer or floating-point operations and generating more than $500 million in gross annual revenue (together with affiliates). Covered developers would be required to publish a public frontier AI framework, issue transparency reports before or concurrent with the deployment of new frontier models, undergo audits and assessments by licensed Independent Verification Organizations, and report critical safety incidents within 15 days. Notably, the draft would pre-empt state and local laws specifically regulating AI model development for three years, while preserving laws of general applicability and state authority over AI use and deployment.
House Republicans introduce SECURE Data Act as proposed federal privacy framework
On April 21, 2026, House Republicans introduced the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act, or SECURE Data Act (H.R. 8413), which would establish a national consumer privacy and data security framework. The bill would: grant consumers rights to access, correct, delete, and port personal data, as well as to opt out of targeted advertising, data sales, and certain automated profiling; require opt-in consent for sensitive data processing; impose data minimization obligations tied to disclosed purposes; and require qualifying data brokers to register with the Federal Trade Commission (FTC). Enforcement would rest with the FTC and state attorneys general, subject to a 45-day cure period, with no private right of action. Notably, the bill includes a broad preemption clause that could displace many state privacy laws that overlap with the federal framework, and would repeal the Video Privacy Protection Act (VPPA), raising concerns among privacy advocates and companies facing VPPA and adtech-related litigation.
Middle East
UAE
UAE establishes Artificial Intelligence and Data Authority
On 14 June 2026, His Highness Sheikh Mohammed bin Rashid Al Maktoum, Vice President and Prime Minister of the United Arab Emirates and Ruler of Dubai, approved the establishment of the Artificial Intelligence and Data Authority, creating a single national body responsible for overseeing artificial intelligence, data governance and digital government across the country. The Authority aims to unify public data and digital capabilities into one integrated national ecosystem, supporting the UAE’s transition to an AI-driven model of governance. It will consolidate the functions of several entities, including the Office of Artificial Intelligence and the digital government sector of the Telecommunications and Digital Government Regulatory Authority, reflecting a move towards coordinated and streamlined oversight. The Authority will also be responsible for setting national policies, legislation and strategic priorities, while ensuring alignment between federal and local initiatives.
UAE Federal Tax Authority expands AI-driven services
On 23 June 2026, the UAE’s Federal Tax Authority (FTA) announced the implementation of artificial intelligence (AI)-driven services as part of its broader digital transformation strategy aimed at enhancing tax administration and customer experience. The initiative focuses on streamlining procedures, reducing administrative burdens and accelerating transaction processing through the deployment of advanced AI technologies across key tax functions, including data analysis, risk assessment, request processing and workflow automation. The programme forms part of the FTA’s AI Strategy, aligned with the UAE Artificial Intelligence Strategy 2031, and reflects a wider effort to build efficient, user-centric and technology-driven government services.
CBUAE and CBK sign MoU on supervisory and FinTech cooperation
On 16 June 2026, the Central Bank of the United Arab Emirates (CBUAE) and the Central Bank of the Republic of Kosovo (CBK) signed a Memorandum of Understanding to strengthen supervisory, financial, and FinTech cooperation. The agreement facilitates the exchange of information and expertise across areas including financial technology development, monetary policy, macroprudential oversight, and financial stability. It also covers cooperation on anti-money laundering, counter-terrorist financing, Islamic finance, banking supervision, and the oversight of payment systems.
UAE presents AI governance approach at International Labour Conference
On 10 June 2026, the United Arab Emirates presented its people-centric approach to AI governance at the 114th International Labour Conference in Geneva. The UAE delegation outlined a framework that prioritises human wellbeing, transparency, and sustainable labour market development, and highlighted the integration of advanced technologies to enhance economic efficiency while protecting workers. The approach emphasises agile legislative frameworks that adapt to rapid technological change while ensuring ethical deployment and social protection.
Dubai
DIFC consults on amendments to Data Protection Regulations
On 18 June 2026, the Dubai International Financial Centre (DIFC) launched a public consultation on proposed amendments to its Data Protection Regulations, as set out in Consultation Paper No. 3 of 2026. The proposed changes are aimed at strengthening and modernising the framework in response to the growing use of artificial intelligence and data-driven systems. Key elements include enhanced governance, accountability, and safety requirements for systems processing personal data, refinements to privacy-by-design and ethical data processing standards, clarification of certification requirements, and further definition of the role of the Autonomous Systems Officer. The consultation is open for 30 days.
DIFC report identifies AI-driven challenger banks as major shift in global banking
On 17 June 2026, the Dubai International Financial Centre published the second report in its 2026 Future of Finance series, The Changing Face of Banking: Building Resilience Through Change. The report examines how digital-native, AI-driven challenger banks are reshaping global banking, finding that their cloud-first and asset-light models are redefining standards for speed, personalisation, and cost efficiency, and intensifying competitive pressure on incumbent institutions. The report warns that without decisive transformation, global banking profit pools could decline significantly by 2030.
Key Dates on the Horizon
July 2026
· 12 July 2026
Deadline for responses to the ACSC consultation on the revised Essential Eight cybersecurity framework (Australia).
· 15 July 2026
China's Interim Measures on the Administration of Artificial Intelligence Anthropomorphic Interaction Services take effect. Article Link
· 18 July 2026
Deadline for public comments on China's draft Provisions on Promoting the Interoperability and Mutual Recognition of Distributed Digital Identity.
· 18 July 2026
Deadline for responses to the DIFC consultation on amendments to Data Protection Regulations.
August 2026
· 2 August 2026
Most transparency requirements for certain AI systems under Article 50 of the EU AI Act will enter into force.
· 16 August 2026
Deadline for public comments on TC260's draft Personal Information Security Specification (China).
· 20 August 2026
China's Measures for Network Data Security Risk Assessment take effect.
December 2026
· 2 December 2026
Transparency obligations to watermark AI‑generated or manipulated synthetic content will enter into force.
EU AI Act
January 2027
- 1 January 2027
China’s mandatory standard on information erasure in electronic products takes effect.
December 2027
· 2 December 2027
Obligations for standalone high‑risk AI systems (Annex III) will enter into force.
August 2028
· 2 August 2028
Obligations for high‑risk AI systems subject to EU product harmonisation legislation (Annex I) will enter into force.
Additional information
This publication does not necessarily deal with every important topic nor cover every aspect of the topics with which it deals. It is not designed to provide legal or other advice. Clifford Chance is not responsible for third party content. Please note that English language translations may not be available for some content.
The content above relating to the PRC is based on our experience as international counsel representing clients in business activities in the PRC and should not be construed as constituting a legal opinion on the application of PRC law. As is the case for all international law firms with offices in the PRC, whilst we are authorised to provide information concerning the effect of the Chinese legal environment, we are not permitted to engage in Chinese legal affairs. Our employees who have PRC legal professional qualification certificates are currently not PRC practising lawyers.