Tech Policy Unit Horizon Scanner
July 2026
July 2026 saw regulators and policymakers across the world's major digital economies continue to accelerate efforts to operationalise AI, data and cybersecurity governance. In the European Union, policymakers advanced implementation of the AI Act through the publication of the Digital Omnibus and new EDPB guidance on web scraping and anonymisation, while the European Commission also demonstrated its willingness to enforce digital regulation through significant penalties under the Digital Markets Act. In the United Kingdom, the Government launched major reviews of data regulation and international data transfers, while Ofcom intensified implementation of the Online Safety Act through consultations, enforcement actions and investigations. Meanwhile, the United States continued to build momentum behind AI legislation, with Congress advancing multiple bills addressing AI transparency, research infrastructure and model governance.
A notable feature of this month's developments was the growing convergence of AI governance, cybersecurity and operational resilience. Taiwan's financial regulator issued guidance addressing risks from frontier AI models, Singapore introduced new cybersecurity obligations for providers supporting critical information infrastructure, and China launched consultations on cybersecurity requirements for the financial sector while publishing guidance on the secure deployment of AI agents. In the UK, major cloud providers were formally designated as Critical Third Parties to the financial sector, reflecting an increasing willingness by governments to treat digital infrastructure providers as systemically important actors requiring direct regulatory oversight.
The month also highlighted increasing regulatory focus on trust, accountability and consumer protection in digital markets. Japan strengthened its data protection framework through amendments to the APPI, including new protections relating to biometric data and children's information, while Australia expanded its Consumer Data Right regime to non-bank lenders. Across Europe and the UK, regulators continued to prioritise platform accountability, age assurance and child safety online, while jurisdictions including Kenya, Saudi Arabia and the UAE advanced national AI governance and digital economy initiatives. Collectively, these developments demonstrate a broader global trend: regulators are moving from establishing digital policy frameworks to demanding demonstrable compliance, governance and resilience from organisations deploying AI, processing data and operating digital platforms at scale.
We also published a number of publications in July reflecting the importance of tech across all sectors.
Since generative AI hit the mainstream in 2022, there has been a huge amount of litigation about generative AI and copyright infringement. However, there have been very few substantive judgments so far, and we are still waiting for The Big Questions to be answered. Our latest article looks at what issues have been decided, and what remains uncertain, from the case law in the UK, EU and the US so far.
The Court of Justice of the European Union (CJEU) delivered its long-awaited judgment in the Google Android case. The judgment upholds the General Court's (GC) 2022 ruling, which had largely confirmed the European Commission's (EC) 2018 decision against Google for abusing its multiple dominant positions in relation to the Android mobile operating system. Clifford Chance has been at the heart of this case from the outset, acting for FairSearch, the organisation that made the original complaint to the EC, and for Seznam, a leading Czech search engine and direct competitor of Google that has been damaged by Google’s abuse of its dominant position. Our recent briefing looks at the judgment.
Meanwhile, our fintech firms regulatory horizon scanner provides a high-level overview of key ongoing and expected EU and UK regulatory developments relevant to fintech firms. We outline key developments between Q3 2026 and Q2 2028 that will be of interest to firms in the fintech sector. Initiatives covered relate to financial markets, digital assets, and cross-sector initiatives.
Finally, Data center developers increasingly look for funding in the capital markets, where the rating of the bond is, in substance, a rating of the underlying data center lease. Our recent briefing maps how specific lease terms drive the rating band across the agencies, and where the agencies diverge. The practical implication: the lease should be drafted to the target rating from the outset. We set out the terms that matter most, and how to hold them.
THE REGIONS IN DETAIL
APAC (Excluding China)
Australia
Non-Bank Lenders Join Consumer Data Right
On 13 July 2026, non-bank lenders in Australia were required to share product data through the Consumer Data Right (CDR), marking a significant expansion of the open finance framework. The CDR empowers consumers to opt in to sharing their financial data with full transparency over who accesses it and for what purpose. Product information sharing obligations commence immediately, while more granular consumer data sharing will be phased in from 9 November 2026. The ACCC and OAIC jointly regulate the CDR to ensure compliance by all participating entities. Businesses in the non-bank lending sector should review their data infrastructure and governance frameworks to meet the new obligations.
OAIC Publishes Quick Reference Guide for Responding to Data Breaches
On 29 June 2026, the Office of the Australian Information Commissioner (OAIC) published a quick reference guide to assist entities responding to data breaches under the Notifiable Data Breaches (NDB) scheme. The guide sets out four key steps: containing the breach, assessing it, notifying affected individuals and the OAIC, and reviewing the incident to prevent recurrence. An eligible data breach is defined as one likely to result in serious harm that cannot be mitigated through timely remedial action. Entities subject to the Privacy Act must notify both the OAIC and affected individuals where serious harm is likely and cannot be prevented. The guide serves as a practical compliance resource for organisations handling personal information in Australia.
Japan
House of Councillors Passes Bill to Amend Part of APPI
On 17 July 2026, Japan's House of Councillors passed Bill No. 54, amending the Act on the Protection of Personal Information (APPI) across several key areas. The amendments remove the consent requirement for certain disclosures of personal information used for statistical analysis, facilitating broader data utilisation. The bill strengthens protections for minors, introducing specific rules governing how legal representatives may handle personal information of individuals under the age of 16. Enhanced rights and prohibitions relating to biometric personal information are also introduced. On enforcement, the amendments establish a surcharge payment regime and increase criminal penalties for the unauthorised provision of personal information to third parties.
Singapore
MDDI Issues Regulations for Providers Responsible for Third-Party-Owned CII Cybersecurity
On 10 July 2026, the Ministry of Digital Development & Information (MDDI) issued the Cybersecurity Regulations 2026, imposing obligations on designated providers responsible for the cybersecurity of third-party-owned Critical Information Infrastructure (CII). The regulations prescribe specific incident reporting timelines, requiring providers to submit initial notifications, supplementary information, and final reports. Providers must also obtain commitments from CII owners to conduct and document cybersecurity risk assessments on an ongoing basis. The scope is limited to designated providers, ensuring that entities managing CII on behalf of third parties are held to appropriate cybersecurity standards. The regulations came into force on 13 July 2026.
MDDI Amends Cybersecurity Service Providers Regulations
On 10 July 2026, the MDDI issued amendments to the Cybersecurity Service Providers Regulations 2026, applicable to providers licensed under the Cybersecurity Act 2018. Key changes include making the prescribed application form available via an electronic application service, reducing the notification period from two months to one day, and updating the official website reference. These amendments streamline administrative requirements and facilitate more efficient regulatory compliance for licensed providers. The amended regulations entered into force on 13 July 2026.
Sri Lanka sets January 2027 commencement date for Personal Data Protection Act
On 22 July 2026, the Data Protection Authority (DPA) published an order by the President setting the commencement date for key provisions of the Personal Data Protection Act, No. 9 of 2022. Section 2, Section 3, Part I (Processing of Personnel Data), and Part III (Controllers and Processors) of the Act shall come into operation on 1 January 2027. The order was issued under subsection (3) of Section 1 of the Personal Data Protection Act and Article 44 of the Constitution of the Democratic Socialist Republic of Sri Lanka.
Taiwan
FSC Issues Recommendations for Financial Industry to Counter Frontier AI Model Attacks
On 13 July 2026, Taiwan's Financial Supervisory Commission (FSC) issued recommendations urging financial institutions to strengthen defences against AI-driven cyberattacks, particularly threats posed by frontier AI models. Institutions are advised to implement zero-trust architectures, enhance continuous monitoring, and adopt a 'security left-shift' approach embedding security considerations earlier in operational processes. Third-party governance is highlighted as a critical risk area, with institutions encouraged to use Software Bill of Materials (SBOM) and improve information sharing through the Financial Information Sharing and Analysis Centre (F-ISAC). Institutions should develop plans for deploying defensive AI with human oversight and audit trail requirements. Senior management is expected to treat AI-related cybersecurity risks as a board-level corporate governance priority.
Vietnam
MST Issues Catalogue of More Than 3,000 Standards for Strategic Technologies
On 3 July 2026, Vietnam's Ministry of Science and Technology (MST) issued a comprehensive catalogue of 3,030 standards for strategic technologies, covering 30 groups of strategic technology products. The catalogue comprises 1,150 Vietnamese National Standards (TCVN) and 1,880 international, regional, and foreign standards. Key technology areas covered include AI, cloud computing, blockchain, and 5G networks, reflecting Vietnam's strategic priorities in the digital economy. Of the total, 1,632 standards relate to 22 technology areas identified as having strong economic growth potential. The MST encourages adoption of international standards to accelerate innovation, commercialisation, and global competitiveness.
Government Urges Ministries to Finalize 15 Draft Laws and Resolutions
On 27 June 2026, the Vietnamese Government directed relevant ministries and agencies to finalise 15 draft laws and resolutions by 3 July 2026, as part of its accelerated legislative programme. Among the key instruments in scope is a Draft Law on the Digital Technology Industry, which includes proposed amendments to the Law on Telecommunications. The MST was specifically instructed to urgently complete the telecommunications-related amendments, reflecting the Government's prioritisation of digital infrastructure regulation. The directive signals Vietnam's commitment to building a modern legislative framework for the digital economy. Stakeholders in the telecommunications and digital technology sectors should monitor developments closely given the tight legislative timeline.
China
China Releases Security Guidelines for Agent Deployment and Use
On 1 July 2026, the National Technical Committee 260 on Cybersecurity of SAC released the Cybersecurity Standards Practice Guidelines – Security Guidelines for Agent Deployment and Use. The Guidelines provide recommendations on security measures to be put in place throughout the lifecycle of agent deployment and use, covering assessment, preparation, deployment, operation and decommissioning stages. The Guidelines aim to help organisations identify and mitigate security risks associated with AI agents and serve as a reference for selecting commercial agent services.
China Publishes Revised Draft Administrative Measures for Internet Information Services for Public Consultation
On 3 July 2026, the Cyberspace Administration of China (CAC) published the revised draft Administrative Measures for Internet Information Services for a second round of public consultation, with comments due by 2 August 2026. The draft seeks to modernise China's regulatory framework for internet information services, reflecting developments in areas such as platform governance, account management, online content regulation, algorithmic recommendation services, generative AI, digital identities and agent services. It also aims to align the regulatory regime with the amended Cybersecurity Law and other recently enacted internet and data governance legislation.
China Launches Consultation on Cybersecurity Management Rules for the Financial Industry
On 3 July 2026, the People's Bank of China, together with the National Financial Regulatory Administration and the China Securities Regulatory Commission, issued the draft Measures for Cybersecurity Management in the Financial Industry for public consultation, with comments due by 3 August 2026. The draft proposes a comprehensive cybersecurity governance framework for approved entities that engage in the financial sector (including financial institutions and financial infrastructure), covering organisational responsibilities, network security protection, risk monitoring, incident response, outsourcing management and regulatory supervision. It aims to strengthen cybersecurity resilience across the financial sector and to provide a unified compliance framework for financial market participants.
Africa
African Union Commission and ITU sign MoU on digital transformation and AI
On 8 July 2026, the African Union Commission (AUC) and the International Telecommunication Union (ITU) signed a Memorandum of Understanding on Africa's inclusive, secure and sustainable digital transformation. Cooperation under the agreement spans artificial intelligence governance, digital public infrastructure, universal connectivity, cybersecurity, space technologies, standardisation and digital regulation. The instrument aligns the AU's Digital Transformation Strategy for Africa and Continental AI Strategy with the ITU's global mandate across its 194 Member States, supporting the continent's participation in the development of the world's digital standards. It also establishes the AUC as the continental partner for coordinating digital transformation across all 55 AU Member States.
Kenya
Ministry of ICT opens public consultation on draft AI and Emerging Technologies Policy
On 21 July 2026, Kenya's Ministry of Information, Communications and the Digital Economy opened a public consultation on its draft Artificial Intelligence and Other Emerging Technologies Policy, inviting comments from the public, stakeholders, and interested parties by 4 August 2026. The Policy aims to provide a national framework for the governance, development, deployment, and use of AI and other emerging technologies, with objectives including promoting innovation, strengthening infrastructure and human capital, supporting sustainable development, and enhancing Kenya's economic resilience and strategic autonomy.
South Sudan
South Sudan operationalises Cybercrime and Computer Misuse Act, 2026 ahead of December elections
On 17 July 2026, the Government of South Sudan commenced implementation of the Cybercrime and Computer Misuse Act, 2026, pursuant to Presidential Directive No. 03/2026. The Act establishes a legal framework to address cybercrime and regulate digital platforms, criminalising offences including the publication of content that promotes tribalism or incites violence, the dissemination of false or misleading information, and cyberbullying and cyber harassment, with custodial sentences of up to five years. A National Cyber-Security Task Force has been established to coordinate inter-agency enforcement, with policy oversight provided by a National Cyber-Security Steering Committee chaired by the Minister of Justice and Constitutional Affairs. The government has framed the measure as strengthening digital governance, enhancing national security and promoting a safe online environment.
Europe
European Union
The EU publishes the Digital Omnibus on AI
On 24 July 2026, the Digital Omnibus on AI was published in the Official Journal of the European Union and will enter into force on 27 July 2026, three days after its publication. The European Parliament adopted the text on 16 June 2026, and the Council gave its final approval on 29 June 2026, with the act signed on 8 July 2026. It amends the AI Act (Regulation (EU) 2024/1689) to streamline its application. In parallel, the Transparency Guidelines under Article 50 of the AI Act were adopted by the European Commission on 20 July 2026, following a stakeholder consultation that ended on 3 June 2026. As regards the Transparency Code of Practice, the European Commission issued its adequacy opinion on 8 July 2026, confirmed by the AI Board on 9 July 2026.
EDPB adopts guidelines on Web Scraping and Anonymisation
On 7 July 2026, the European Data Protection Board (EDPB) adopted two sets of guidelines open for public consultation. Guidelines 03/2026 on web scraping in the context of generative AI address the extraction of personal data from internet sources for AI training purposes, setting out obligations on purpose limitation, data minimisation and transparency. Legitimate interest under Article 6(1)(f) GDPR may serve as a legal basis, subject to a balancing test and appropriate safeguards, while the processing of special categories of data remains subject to a derogation under Article 9(2) GDPR. Guidelines 02/2026 on Anonymisation provide a framework for assessing whether data has been effectively anonymised, based on three cumulative criteria: No Record Isolation, No Linkage, and No Inference, applicable through either a contextual or a simplified approach.
The European Commission fines Google €890 million under the Digital Markets Act
On 23 July 2026, the European Commission handed Google two fines amounting to €890 million in total for non-compliance with the Digital Markets Act. One relates to the way Google promotes its own services in Search results at the expense of third-party competitors, in breach of the equal treatment obligations binding on gatekeepers (€460 million). The other targets the conditions imposed on app developers distributing through Google Play, who were unable to freely redirect users to more competitive offers available elsewhere (€430 million). Google is required to bring both situations into compliance.
European Commission amends implementing acts under the eIDAS Regulation
On 22 July 2026, The European Commission has published an implementing regulation amending four implementing acts adopted under the European Digital Identity Framework of the revised eIDAS Regulation. The amendments concern the rules applicable to person identification data and electronic attestations of attributes, the integrity and core functionalities of European Digital Identity Wallets, notification requirements to the Commission, and the protocols and interfaces to be supported by the framework. The updated requirements are relevant for digital identity providers, wallet issuers, relying parties and technology providers involved in developing or integrating EUDI Wallet solutions.
United Kingdom
NCSC issues guidance on helping organisations recover from cyberattacks
On 28 July 2026, the UK National Cyber Security Centre (NCSC) published guidance on responding to and recovering from highly disruptive cyber incidents. The guidance sets out a three-stage recovery framework covering: (1) initial incident response, (2) the implementation of a recovery programme focused on restoring essential services and business functions, and (3) longer-term rebuilding activities aimed at returning to business as usual and strengthening resilience. It also highlights the importance of governance arrangements, coordinated communications, and addressing the causes of incidents. In addition, the NCSC encourages organisations to prepare for disruptive cyber incidents by maintaining and testing response and recovery plans, failover and recovery capabilities, backup restoration processes, and incident response exercises.
UK Government abolishes the Department for Science, Innovation and Technology (DSIT)
On 20 July 2026, the new UK Prime Minister announced his new cabinet including a new minister for Business, Innovation, Science and Trade (DBIST) - Jonathan Reynolds. This new department will replace the Department for Science, Innovation and Technology (DSIT), redistributing its functions across the new Department for Business, Innovation, Science and Trade (DBIST), the Department for Digital, Culture, Media and Sport (DCMS), and the Cabinet Office. At the same time, AI has been given greater prominence through the appointment of a dedicated AI Minister, Kanishka Narayan, and the creation of a central AI Taskforce within the Cabinet Office.
DSIT publishes final response to regulatory measures banning social media for under-16s
On 15 July 2026, the Department for Science, Innovation and Technology (DSIT) published its final response to the Growing up in the online world consultation, setting out plans to strengthen protections for children online through new regulatory measures. These include (i) default social media restrictions for 16- and 17-year-olds such as overnight curfews (midnight–6am); (ii) disabling addictive features like push notifications and personalised feeds (with the option to opt out); and (iii) requirements for AI chatbots to introduce usage breaks for under-18s, alongside potential restrictions or bans on chatbots providing harmful mental health advice. The government will also place obligations on platforms to detect and prevent under-16s circumventing age checks (including via VPNs), with Ofcom tasked to explore enforcement options, and will expand support for parents and digital literacy initiatives for children. The first regulations are due to be laid before Parliament by end-2026, with implementation expected in spring 2027, followed by further measures within a year.
DSIT launches call for evidence on regulation of AI and other data-intensive technologies
On 15 July 2026, DSIT launched a call for evidence, which will remain open until 9 September 2026, on how existing data regulation operates in practice in relation to AI and other data-intensive technologies. The call for evidence focuses on five themes: (1) accessing and using data; (2) data quality, accuracy and downstream impacts; (3) governing data use across organisations; (4) transparency and rights in complex data environments; and (5) the effectiveness of current data frameworks in regulating AI. DSIT is seeking evidence on issues including synthetic data, privacy-enhancing technologies, automated decision-making, data sharing and interoperability, AI supply-chain governance, and transparency obligations. The exercise is intended to inform the Government's assessment of whether the UK's data regulatory framework remains effective, proportionate and adaptable as AI and other data-intensive technologies continue to evolve.
DSIT launches call for evidence on UK's approach to international data transfers
On 15 July 2026, DSIT launched a call for evidence, open until 9 September 2026, seeking views on the effectiveness of the UK's international data transfer regime and whether aspects of the current framework should be preserved or reformed. The exercise focuses on how international data transfer rules operate in practice, including in the context of cloud services, distributed data infrastructures, AI and other data-intensive technologies, whether existing international transfer tools remain clear, effective and proportionate and existing safeguards remain responsive to evolving technological and security challenges, and how international data flows affect trust, resilience and technological sovereignty. DSIT states that the exercise is intended to gather practical evidence on how organisations manage international data transfer risks and challenges, rather than to consult on specific policy proposals.
UK financial system strengthened with new safeguards for major technology providers
On 10 July 2026, HM Treasury announced that four major cloud providers - Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL, and Oracle Corporation UK Ltd – will be designated as Critical Third Parties (CTPs) from 13 July 2026, bringing them under direct oversight of the Bank of England, Prudential Regulation Authority, and Financial Conduct Authority to strengthen the resilience of the UK financial system. The regime, established under the Financial Services and Markets Act 2023, enables regulators to assess these providers’ operational resilience, gather information, and enforce standards to ensure they can prevent, respond to, and recover from disruptions that could impact multiple financial institutions simultaneously. The move reflects increasing reliance on cloud services across banking and financial markets, aims to reduce systemic risk and protect critical services used by consumers and businesses, and forms part of a targeted, evolving framework under which additional providers may be designated over time.
House of Commons' Digital and Communications Committee launches inquiry into Online Safety Act 2023
On 27 July 2026, the House of Commons' Communications and Digital Committee launched an inquiry into the implementation, enforcement and effect of the Online Safety Act 2023 (OSA). As an initial step, it has issued a public call for evidence, open until 7 September 2026, on questions about how Ofcom has interpreted, implemented and enforced the OSA, whether its measures have led online services to make meaningful changes to their systems, processes and design, and the impact of the OSA so far on the experience of children and adults online. The inquiry is a response to criticism that Ofcom has been slow and ineffectual in taking the OSA forward, that new technologies have rendered some of the provisions less effective than they should be and that the OSA itself requires amendment to make it sufficiently effective.
Ofcom report shows age checks already helping make online experiences safer for UK children
On 15 July 2026, Ofcom published an Age Assurance report, which highlights significant early progress in the rollout of online age assurance measures under the Online Safety Act (OSA), with the proportion of children encountering highly effective age checks rising from 25% to 43% between July 2025 and January 2026, and widespread adoption across major pornography platforms. The report, however, reported that gaps remain, including continued access to unprotected sites and weak age inference methods used by some social media platforms. The regulator warns that current approaches are insufficient to support a planned under‑16 social media ban, signalling that age inference alone will not meet compliance expectations and urging firms to adopt more robust methods. Ofcom is taking enforcement action against non-compliant adult services, working with search providers to reduce harmful content discoverability, and pushing for stronger, industry‑wide innovation, including at app store, operating system, and device levels. It will deliver further guidance to Parliament by October 2026 on effective age checks for over‑16 verification, ahead of potential restrictions in 2027, and publish a statutory report on app‑store protections by January 2027.
Ofcom investigations into porn companies for age check failures under the OSA
On 9 July 2026, Ofcom announced two enforcement actions relating to online pornography providers' compliance with the Online Safety Act (OSA) age assurance requirements. Ofcom fined the provider of fapello.com £630,000, including £600,000 for failing to implement highly effective age assurance measures to prevent under-18s from accessing pornographic content and £30,000 for failing to respond on time to a legally binding information request. Following Ofcom's action, the site geo-blocked UK users. On the same day, Ofcom also published details of an investigation into Bit Hive SP. Z O.O., the provider of eporner.com, concerning whether it has complied with its duties under sections 12 and 36 OSA to implement highly effective age assurance and carry out children's access assessments.
Ofcom consults on new fraudulent advertising code under the Online Safety Act
On 10 July 2026, Ofcom launched a consultation on a new fraudulent advertising code under the Online Safety Act (OSA) that would require major platforms (including large social media and search services) to implement nearly 40 measures to tackle scam adverts, with the consultation open until 2 October 2026 and final decisions due next year. The proposals mandate proactive prevention and enforcement actions such as banning repeat scam advertisers, verifying advertiser identities (including FCA authorisation for financial promotions), strengthening account security, detecting misuse of AI-generated ads, and enabling fast-track reporting channels for trusted bodies like law enforcement. Firms are also urged to act immediately rather than wait for formal adoption, with non-compliant companies facing fines of up to £18 million or 10% of global revenue once the rules are in force.
Ofcom consults on additional duties for Category 1 Services
On 10 July 2026, Ofcom launched a consultation, open until 2 October 2026, on a proposed Code of Practice and guidance for the additional duties that will apply to Category 1 services under the UK Online Safety Act 2023 (OSA). The consultation forms part of the third phase of the OSA's implementation and covers duties relating to user empowerment, user identity verification, news publisher content, journalistic content, content of democratic importance, terms of service, complaints, and freedom of expression and privacy impact assessments.
Online safety groups call for stronger online safety regulation and reform of the Online Safety Act
On 1 July 2026, the Online Safety Act Network published a joint statement signed by 48 organisations and academics urging the new Prime Minister to adopt a more ambitious approach to online safety and AI regulation. The statement argues that the Government's response to online harms has been fragmented and insufficient, citing concerns over harmful AI chatbots, online violence against women and girls, disinformation, unsafe platform design, and delays to measures intended to improve transparency and researcher access to platform data. The signatories also criticise Ofcom's implementation of the Online Safety Act (OSA), arguing that enforcement has been too cautious and that important protections, including measures relating to fraudulent advertising and user empowerment tools, have not yet taken effect. The statement calls for the Government to strengthen the OSA, adopt the Network's proposed "Safety by Design" approach, introduce broader online safety and AI regulation, and establish an annual Digital Media, Data and Communications Bill to ensure legislation can be updated in response to emerging harms.
Americas
The United States of America
House Science Committee Advances Bipartisan AI Legislative Package
On 25 June 2026, the House Committee on Science, Space, and Technology favourably reported ten bipartisan artificial intelligence bills addressing AI research infrastructure, cybersecurity, model transparency, workforce development, consumer protection, and federal data governance. The package included the CREATE AI Act, which would establish the National Artificial Intelligence Research Resource (NAIRR) to expand access to computing resources and datasets for AI research; the AI Security and Innovation Act, which would strengthen efforts to secure AI systems and support the development of trustworthy AI technologies; and the READ AI Models Act, which would direct the National Institute of Standards and Technology (NIST) to develop voluntary resources for documenting AI models, as well as additional measures. This measure reflects growing bipartisan support for strengthening the technical infrastructure, standards, and governance mechanisms underpinning U.S. AI development and deployment.
Senators Introduce AI Labeling Act of 2026
On 24 June 2026, Sens. Brian Schatz, John Curtis, and Mark Warner introduced the AI Labeling Act of 2026 (S. 4915), legislation that would require providers of generative AI systems to include clear disclosures on AI-generated audio, video, and image content. The bill would require both visible labels and machine-readable disclosures identifying AI-generated content, the system used to create or modify the content, and the date and time of creation or modification. The legislation would also require providers to ensure that AI-generated content can be detected through available tools and would establish standards for disclosure. The proposal reflects increasing congressional interest in authentication and transparency requirements for synthetic media as policymakers consider responses to the growing use of generative AI across digital platforms.
FTC Seeks Public Comment on Policy Statement Addressing AI Accuracy
On 1 July, the Federal Trade Commission (FTC) launched a consultation on a proposed policy statement that would clarify how Section 5 of the FTC Act may apply when AI companies allegedly manipulate AI system outputs to advance undisclosed ideological objectives, potentially misleading consumers about the objectivity, accuracy, effectiveness, or suitability of those systems. The proposal also addresses the interaction between federal and state AI regulation, arguing that state laws requiring alteration of AI outputs, such as Colorado’s Artificial Intelligence Act, may be pre-empted where they conflict with a federal regulatory scheme. The consultation follows a December executive order from President Trump directing the FTC to consider the legal implications of state laws affecting the “truthful outputs” of AI models. The proposed policy statement will be published in the Federal Register, with public comments accepted until 31 July 2026.
Bipartisan bill for a kill switch for advanced AI systems
On 23 July, U.S. Congressmen Ted W. Lieu and Nathaniel Moran introduced the bipartisan AI Kill Switch Act, legislation requiring developers of the most powerful artificial intelligence systems to maintain the technical capability to throttle, suspend, or shut them down. Following recent incidents where advanced models bypassed testing bounds or demonstrated high-level hacking capabilities, the bill authorizes the Secretary of Homeland Security, in consultation with Commerce and National Intelligence leadership, to mandate slowdowns or shutdowns of systems threatening catastrophic harm. To enforce control over autonomous technology, the act establishes a graduated response framework aligned with incident severity and introduces mandatory incident reporting and forensic record preservation.
Middle East
UAE
UAE, Indonesia Advance Cooperation on Digital Payments and Financial Connectivity
On 26 July 2026, Khaled Mohamed Balama, Governor of the Central Bank of the UAE (CBUAE), met with Judha Nugraha, Indonesia’s Ambassador to the UAE, to discuss strengthening financial and banking cooperation between the two countries. The discussions focused on enhancing cross-border payment connectivity through the interconnection of payment systems and the development of fast, efficient, transparent and cost-effective payment solutions. Both sides also explored opportunities to accelerate digital financial innovation and support growing trade and investment flows between the UAE and Indonesia. The meeting highlighted initiatives such as Local Currency Transactions (LCT), increased payment system interoperability and continued knowledge exchange between the two countries’ central banks. The engagement reflects broader efforts to deepen the UAE–Indonesia strategic partnership and advance financial integration while supporting economic growth.
Dubai
Middle East Stablecoin Association Incorporates in DIFC to Support Responsible Stablecoin Adoption
On 15 July 2026, the Middle East Stablecoin Association (MESA), the region’s first industry body focused exclusively on stablecoins, announced its incorporation in the Dubai International Financial Centre (DIFC) as a Non-Profit Incorporated Organisation (NPIO). The move formalises MESA’s transition from an industry-led initiative into a non-profit platform dedicated to promoting responsible stablecoin adoption through policy dialogue, education, research, standards development and international knowledge exchange. MESA aims to bring together stablecoin issuers, financial institutions, fintech firms, investors, legal advisers and regulators to support the safe, transparent and interoperable growth of digital money across the Middle East.
DIFC Proposes AI-Focused Amendments to Data Protection Regulations
On 18 June 2026, the Dubai International Financial Centre (DIFC) launched a public consultation on proposed amendments to its Data Protection Regulations aimed at strengthening governance of artificial intelligence (AI) and data-driven systems. The proposed changes focus on enhancing safeguards for the processing of personal data by autonomous and semi-autonomous systems, reinforcing requirements for privacy-by-design, safety and accountability throughout the AI lifecycle. The amendments would broaden recognised governance frameworks, introduce additional transparency obligations for organisations deploying AI-enabled systems, and clarify the responsibilities of Autonomous Systems Officers overseeing such technologies. The consultation also proposes a new regulation empowering the Commissioner to recognise accreditation and certification schemes, supporting consistent standards for AI governance and compliance. Building on reforms introduced in 2023, the proposals reflect DIFC’s efforts to ensure its data protection framework remains responsive to evolving AI technologies while maintaining high standards of privacy, transparency and responsible innovation in the UAE’s financial and digital ecosystem.
Dubai Introduces AI-Driven Bus Management System to Improve Public Transport Efficiency
On 6 July 2026, the Roads and Transport Authority (RTA) in Dubai launched an AI-powered smart system designed to enhance the operational efficiency, responsiveness and readiness of the city’s public bus network. The system monitors more than 1,100 buses and supports 26 operational scenarios, enabling real-time decision-making and rapid adjustments to service demands and disruptions across the transport network. Using real-time data, machine learning technologies and advanced optimisation algorithms, the platform can identify and deploy the most suitable buses within seconds, significantly reducing response times and improving resource management. The system also strengthens coordination between buses and other public transport modes, including the Dubai Metro and Tram, helping ensure service continuity and a better passenger experience.
Saudi Arabia
SDAIA issues AI bias reference guide with over 100 bias types
On 21 July 2026, the Saudi Data and Artificial Intelligence Authority (SDAIA) released the first edition of its AI Bias Reference Guide, identifying more than 100 types of bias that may affect the accuracy, fairness and reliability of artificial intelligence systems. The guide explains how biases can emerge throughout the AI lifecycle, including through unrepresentative training data, algorithmic design and data interpretation, and outlines their potential societal and organisational impacts. It provides practical mitigation strategies and real-world examples, highlighting risks in critical sectors such as healthcare, education and justice, where biased AI could lead to unfair outcomes, discrimination, reputational harm and legal liability. The publication forms part of SDAIA’s broader efforts to advance responsible and ethical AI governance in Saudi Arabia, building on initiatives such as its AI Ethics Principles, Generative AI Principles and AI Adoption Framework. The guide reflects the Kingdom’s commitment to promoting transparency, fairness and accountability as AI adoption expands across the public and private sectors.
Abu Dhabi
Bitcoin Suisse Advances Middle East Expansion, receiving Financial Services Permission in Abu Dhabi
On 7 July 2026, Bitcoin Suisse Group announced that its subsidiary, BTCS (Middle East) Ltd., had received Financial Services Permission (FSP) from the Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market (ADGM), enabling it to provide regulated digital asset financial services to institutional and professional clients in the United Arab Emirates. The authorisation follows a multi-stage licensing process and forms part of Bitcoin Suisse’s broader international expansion strategy. The company, which has over a decade of experience in digital asset markets and currently safeguards approximately USD 3.7 billion in crypto assets, will offer services including regulated trading, institutional-grade custody and digital asset exposure management in a compliant regulatory environment. The approval also positions the firm to support future opportunities involving tokenised real-world assets as the market develops.
Abu Dhabi Strengthens AI-Driven Life Sciences Ecosystem Through Global Partnerships
On 4 July 2026, the Department of Health – Abu Dhabi (DoH) announced a series of strategic agreements aimed at strengthening the emirate’s intelligent life sciences ecosystem through genomics, artificial intelligence (AI), biotechnology, precision medicine and healthcare investment. Signed during Abu Dhabi’s strategic mission to the United States, the partnerships expand collaboration with leading healthcare, pharmaceutical and research organisations to accelerate innovation in areas including AI-enabled genomics, advanced therapeutics, obesity and Alzheimer’s disease research, and precision healthcare. The initiatives support Abu Dhabi’s ambition to become a global hub for life sciences by integrating genomics, AI, clinical research, advanced health data and healthcare delivery within a single ecosystem. The agreements also seek to accelerate the translation of scientific discoveries into real-world health outcomes, strengthen research and development capabilities, attract investment and advance personalised, predictive and preventive healthcare.
Key Dates on the Horizon
August 2026
2 August 2026
- Deadline for public comments on China's revised draft Administrative Measures for Internet Information Services. Consultation
3 August 2026
- Deadline for public comments on China's draft Measures for Cybersecurity Management in the Financial Industry. Consultation
4 August 2026
- The Ministry of ICT closed public consultation on the draft AI and Emerging Technologies Policy
September 2026
9 September 2026
Deadline for submissions to DSIT's calls for evidence on the regulation of AI and other data-intensive technologies, and on the UK's approach to international data transfers. Consultation
7 September 2026
- Deadline for written submissions to the House of Lords Communications and Digital Committee's inquiry into the implementation, enforcement and effect of the Online Safety Act 2023. Consultation
October 2026
2 October 2026
- Deadline for responses to Ofcom's consultations on a new fraudulent advertising code under the Online Safety Act 2023. Consultation
- Deadline for responses to Ofcom's consultations on additional duties for Category 1 services, under the Online Safety Act 2023. Consultation
November 2026
9 November 2026
- More granular consumer data sharing obligations under Australia's Consumer Data Right will be phased in for non-bank lenders.
Additional information
This publication does not necessarily deal with every important topic nor cover every aspect of the topics with which it deals. It is not designed to provide legal or other advice. Clifford Chance is not responsible for third party content. Please note that English language translations may not be available for some content.
The content above relating to the PRC is based on our experience as international counsel representing clients in business activities in the PRC and should not be construed as constituting a legal opinion on the application of PRC law. As is the case for all international law firms with offices in the PRC, whilst we are authorised to provide information concerning the effect of the Chinese legal environment, we are not permitted to engage in Chinese legal affairs. Our employees who have PRC legal professional qualification certificates are currently not PRC practising lawyers.