Tech Policy Unit Horizon Scanner
August 2026
August continued to see technology regulation move from high-level principles towards implementation, supervision and enforcement. The EU AI Act’s transparency obligations entered into application alongside new Commission powers over providers of general-purpose AI models, while Japan advanced implementing measures for its amended data protection regime and China proposed a dedicated compliance framework for large personal information processors.
The governance of increasingly autonomous AI systems emerged as a particularly strong cross-jurisdictional theme. Australian and UK authorities highlighted risks associated with agentic and multi-agent systems, including unintended actions, cascading failures, excessive access and exploitation of technical weaknesses. Their recommendations converge around clearly defined objectives, restricted permissions, secure deployment environments, robust logging and continued human oversight. In parallel, proposed US legislation would require greater transparency about the models, training data, infrastructure and security controls underlying AI systems used in defence procurement and would bring AI-related systemic risks more clearly within financial-sector oversight.
Regulators also demonstrated a growing willingness to test digital governance obligations through enforcement. European action addressed automated decisions with significant consequences and compliance with digital market rules, while in the UK Ofcom continued investigations and imposed penalties under the UK Online Safety Act. Children’s online safety remained prominent, with UK research questioning the practical effectiveness of age checks and parental controls, alongside a major US litigation settlement concerning platform design and child protection that could have a knock-on effect for other platforms.
Meanwhile, cybersecurity developments similarly emphasised that outsourcing security functions does not remove the need for clear internal responsibility, effective patch management and appropriate responses to security alerts.
Our latest publications looked at the emerging space tech space in Space and satellite infrastructure: Opportunities for private equity and the potential dangers of AI notetaking apps in When AI Joins the Meeting: Legal and Governance Considerations for AI Notetakers
THE REGIONS IN DETAIL
APAC (Excluding China)
Australia
Australia’s DISR releases report on multi-agent AI system risks and safeguards
On 10 August 2026, Australia's Department of Industry, Science, and Resources (DISR) published a report addressing risks and controls for multi-agent AI systems. The identified risks include emergent behaviors, cascading failures, false consensus, context leakage, and algorithmic collusion. The report recommends controls such as structured handoffs, logging and monitoring, action-specific permissions, context isolation, and shared standards. These measures are intended to manage operational and governance risks associated with complex multi-agent AI environments.
Australia’s ACSC warns of unintended risks from agentic AI systems
On 11 August 2026, Australia’s Cyber Security Centre (ACSC) highlighted risks arising from agentic AI, particularly where AI systems act in ways that are misaligned with intended goals. The summary notes concerns such as specification gaming and over-optimisation, which may cause unintended outcomes. Individuals are advised to restrict AI use to lower-risk activities and ensure continued human oversight. Organisations are encouraged to adopt security practices, use AI defensively in cybersecurity, and maintain appropriate authentication controls.
Japan
NCO Launches Public Consultation on Draft Guidelines for Critical Infrastructure Cybersecurity
On 5 August 2026, Japan’s National Cybersecurity Office (NCO) launched a public consultation on a draft of the Guidelines for Developing Security Standards and Other Measures for Critical Infrastructure Cybersecurity. The consultation follows the Cybersecurity Strategic Headquarters’ adoption of the Unified Standards for Cybersecurity Measures for Critical Infrastructure on 31 July 2026 under the amended Cybersecurity Basic Act. The draft Guidelines provide detailed guidance for competent ministries and agencies and relevant industry associations when developing or updating sector-specific security standards and related measures.
PPC Publishes Implementation Roadmap for Amended APPI
On 26 August 2026, Japan’s Personal Information Protection Commission (PPC) published a draft outline of the principal matters to be addressed in cabinet orders, enforcement rules, guidelines and FAQs for the implementation of the amended Act on the Protection of Personal Information (APPI), which was passed on 17 July 2026. The document sets out the key issues that will require further specification through these implementing measures and guidance. It also notes that the government’s Basic Policy on the Protection of Personal Information will be reviewed as necessary. The PPC also outlined its proposed approach to the implementation process.
Japan's Cabinet Office consults on draft generative-AI code on IP protection
On 18 August 2026, the Cabinet Office of Japan published a revised "Principle-Code for Protection of Intellectual Property and Transparency for the Appropriate Use of Generative AI" applying a comply or explain framework to domestic and foreign generative AI businesses operating in Japan, requiring them to protect intellectual property, respect paywalls and machine-readable access restrictions, avoid pirate sites, implement training and output safeguards, and provide transparency and inquiry mechanisms for rights holders regarding training data and collection methods.
Japan’s PPC survey finds transparency and verification gaps in opt-out data transfers
On 19 August 2026, Japan’s Personal Information Protection Commission (PPC) published results of a fact-finding survey concerning businesses that notify opt-out personal data transfers. The survey identified significant transparency concerns in relation to such transfers. It also found that many businesses did not verify the identity or reliability of third parties receiving the data. In addition, 44 out of 187 respondents did not confirm whether recipients would avoid illegal or improper use of the transferred data, highlighting the need for clearer notification of individual rights and opt-out methods.
Philippines
Philippines establishes government data classification and residency framework under EO 119
On 13 July 2026, the Philippines Government issued Executive Order No. 119, creating a government data classification and residency framework. Government data is divided into restricted access data - including top secret, secret, confidential, and restricted categories - and open access data. The framework imposes residency requirements requiring top secret and secret data to be stored within Philippine territory, while offshore storage of confidential data requires approval. Government agencies and private entities processing government data must comply within a three-year transition period.
Thailand
Thailand’s PDPC issues new rules for handling data subject access requests
On 21 July 2026, Thailand’s Personal Data Protection Committee (PDPC) issued new rules on handling data subject access requests under the Personal Data Protection Act (PDPA). The rules address request submission, identity verification, response requirements, grounds for refusal, recordkeeping, and fees. Controllers may verify the requester’s identity and require evidence where a representative makes the request. Requests may be refused where they affect the rights of others or where legal exemptions apply, and reasonable fees may be charged for repetitive, excessive, or unfounded requests.
India
India’s CEA issues cybersecurity regulations for the power sector
On 31 July 2026, India’s Central Electricity Authority (CEA) the publication of has published cybersecurity regulations for the power sector, with effect from April 1, 2027. The regulations apply to entities that manage operational technology and information technology systems connected to the power system. They also establish CSIRT-Power to coordinate cybersecurity incident reporting and response. Covered entities must appoint a chief information security officer (CISO), report incidents, monitor systems, store data securely, and comply with specified cybersecurity practices.
India’s SEBI uses AI tools to detect fraudulent social media activity
On 10 August 2026, India’s Securities and Exchange Board (SEBI) deployed AI tools to monitor social media for potentially fraudulent activity. Project SUDARSAN has been operational since November 2025 and scans social media for deceptive posts. SEBI has also implemented R(AI)DAR to audit promotional content and educational resources from asset management firms. The initiative reflects a shift from manual monitoring to automated, technology-based supervision, although the report does not specify risk scoring methods, retention periods, or privacy safeguards.
China
China Launches Consultation on Personal Information Protection Requirements for Large Personal Information Processors
On 7 August 2026, the Cyberspace Administration of China (CAC) published the draft Provisions on Personal Information Protection for Large Personal Information Processors for public consultation, with comments due by 7 September 2026. The draft establishes a dedicated compliance framework for large personal information processors, including criteria for designation, transparency obligations, consent requirements, personal information protection measures and regulatory oversight arrangements. It seeks to strengthen accountability for entities processing large volumes of personal information, enhance the protection of individual rights and interests, and further implement the requirements of the Personal Information Protection Law and related data governance legislation.
China publishes five-year internet-tech plan
On 21 August 2026, CAC published an Action Plan for Promoting High-Quality Development of Internet and Information Enterprises (2026-2030). The plan aims to enhance the competitiveness and development of cyberspace enterprises through technological innovation, product quality, and service delivery. The plan prioritises breakthroughs in critical areas such as high-end chips, quantum computing, artificial intelligence, and cybersecurity, while mandating strengthened personal data protection, algorithm management, content quality, and anti-monopoly measures.
China Releases Security Guidelines for Individual Users of AI Services
On 24 August 2026, the National Technical Committee 260 on Cybersecurity of SAC released the Cybersecurity Standards Practice Guidelines – Security Guidelines for Individual Users of AI Services. The Guidelines provide practical recommendations for individuals using AI services over the internet, covering security awareness, safe usage practices and responsible user conduct. They also provide reference guidance for AI service providers, developers and operators in enhancing user protection and mitigating security risks associated with AI adoption.
Africa
Mauritius
Mauritius FSC issues Guidance Notes on stablecoins, tightening the regulatory regime
On 24 August 2026, the Financial Services Commission (FSC) of Mauritius has issued final Guidance Notes on stablecoins that distinguish between asset-linked and algorithmic variants, explicitly excluding algorithmic and yield-bearing stablecoins from the licensing framework while permitting only traditional reserve assets such as cash, securities, and bank deposits. The framework requires issuers to redeem stablecoins at par value within five days of a request, establishes dual oversight with the Bank of Mauritius for payment instruments and fiat-pegged stablecoins, prescribes liquid asset composition rules, and mandates reserve segregation, independent valuation, and enhanced operational standards covering anti-money laundering, cybersecurity, governance, and incident reporting.
South Africa
SARB and National Treasury publish draft Crypto Asset Manual for cross-border transactions
On 3 August 2026, the National Treasury and the South African Reserve Bank (SARB) are consulting on a draft Crypto Asset Manual governing cross-border crypto asset activity, which introduces a new "Authorised CASP" status requiring crypto asset service providers to obtain explicit authorisation before facilitating international transactions. The draft text outlines specific cross-border trigger points, establishes resident individual externalisation limits while restricting South African entities, sets capital and operational requirements across three categories of Authorised CASPs. Comments are requested by 30 September 2026.
Europe
European Union
The EU marks the entry into application of the AI Act transparency obligations
On 2 August 2026, the transparency obligations under Article 50 of the AI Act entered into application, alongside the European Commission's new enforcement powers over providers of general-purpose AI models. The Commission adopted the final Transparency Guidelines under Article 50 on 20 July 2026, following a stakeholder consultation.. , The European Commission issued its opinion on the Transparency Code of Practice on 8 July 2026, confirmed by the AI Board's adequacy assessment the following day. The Code, published in final form on 10 June 2026, remains a voluntary instrument that providers and deployers may rely on to demonstrate compliance with the marking and labelling obligations. It does not, however, constitute conclusive evidence of compliance with Article 50.
United Kingdom
UK and Ukraine issue a Joint Declaration of Intent to establish an AI partnership
On 24 August 2026, the UK Government and the Government of Ukraine announced a legally non-binding Joint Declaration of Intent establishing a UK-Ukraine Artificial Intelligence Partnership. The declaration provides a framework for defence-focused cooperation on AI, autonomous systems and related technologies, with the aim of accelerating the development and deployment of AI-enabled military capabilities and supporting the development of next-generation armed forces. The partnership will operate through government-to-government collaboration, industry cooperation and academic research, including work on AI models, secure data and compute pathways, AI assurance, cyber security and synthetic data. The declaration also sets out principles relating to safeguards for data and intellectual property, export controls, proportionate governance and NATO interoperability.
NCSC publishes guidance on managing cyber risks of agentic AI
On 20 August 2026, the National Cyber Security Centre (NCSC) published guidance on managing the cyber risks associated with agentic AI systems. The guidance highlights that risks increase with the level of autonomy granted to AI agents, noting that they may act in unintended ways, access information beyond their intended scope, or discover and exploit configuration weaknesses or vulnerabilities in technical controls, and should not be assumed to possess human judgement or common sense. The NCSC recommends that organisations should conduct threat modelling, define clear agent objectives, and maintain active human oversight to manage AI risks. Additionally they should deploy agents in secure sandboxes with strict access controls, robust logging, rapid kill switches, and continuous reviews.
Ofcom continues Online Safety Act enforcement activity against non-compliant service providers
On 20 August 2026, Ofcom expanded its separate investigations into Teen-Chat.org and Chat-Avenue.com following a review of information provided in response to a statutory information notice issued under section 100 OSA. Ofcom will now consider whether the providers complied with section 102(8) OSA in relation to information provided during the investigation and with obligations under section 66 OSA relating to the reporting of UK-linked child sexual exploitation and abuse content. Separately, on 18 August 2026, Ofcom also published a non-confidential version of the Confirmation Decision issued to the provider of Fapello.com on 8 July 2026. The decision imposed penalties totalling £630,000, comprising £600,000 for breaches of section 12 and £30,000 for failure to comply with an information notice. It also required the provider to disclose information identifying the entity and/or individuals controlling the service and imposed a daily penalty of £200 until compliance is achieved or 7 September 2026, whichever occurs first.
ICO publishes research on children's online privacy and parental controls
On 19 August 2026, the Information Commissioner's Office (ICO) published research highlighting a growing gap between parents’ confidence in managing children’s online activity and the realities of young people’s digital lives. Surveys of more than 4,000 children and parents found that 36% of children talk or play online with people they do not know, 52% would seek to bypass age checks to access a platform, and 41% have attempted to circumvent parental controls despite 91% of parents using monitoring tools. The ICO said the findings demonstrate the importance of regular conversations about online privacy alongside technical controls and encouraged families to follow its “chat, choose, check” approach through its Switched on to Privacy campaign. The research was published alongside a Children’s Code strategy update, in which the ICO reported that regulatory interventions since April 2024 have improved protections for an estimated five million child users, including through enhanced age assurance commitments from Snapchat and improvements to location-sharing features on Snapchat and Instagram.
ICO reprimands ACRO Criminal Records Office over cyber security failings
On 7 August 2026, the Information Commissioner's Office (ICO) reprimanded ACRO Criminal Records Office after an investigation found that, between August 2022 and March 2023, a hacker gained unauthorised access to ACRO's website and content management system (CMS), potentially exposing the personal data, including names, dates of birth, National Insurance numbers, passport and driving licence details, bank details, biometric data, and highly sensitive criminal offence information, of up to 10,920 people. The ICO found that ACRO had engaged third-party providers for security services but had failed to ensure clear responsibility for identifying and monitoring critical CMS security updates, lacked an effective patch management process, and did not adequately investigate security alerts that could have identified the intrusion earlier, amounting to infringements of Article 32 of the UK GDPR.
Americas
The United States of America
Senators Introduce AI Functional Bills of Materials Act
On August 6, 2026, Sen. Elissa Slotkin introduced the AI Functional Bills of Materials Act (S. 5345), which would require Department of Defense contractors supplying AI-enabled products or services to provide detailed inventories of the software, data, and hardware components underlying their AI systems. The bill mandates disclosures regarding AI model provenance, training data, dependencies, security controls, access permissions, and computing infrastructure, and would extend existing software bill of materials concepts to AI systems used in defense procurement. The proposal reflects increasing congressional attention to AI supply-chain transparency and the security risks associated with opaque AI systems deployed in sensitive government environments.
Senators Introduce FAIRR Act to Address AI Risks in the Financial Sector
On August 6, 2026, Sens. Mark Warner and John Kennedy introduced the Financial Artificial Intelligence Risk Reduction (FAIRR) Act (S. 5358), which would expand the role of the Financial Stability Oversight Council (FSOC) in identifying and responding to AI-related risks to the U.S. financial system. The bill would require federal financial regulators to assess threats such as AI-enabled market manipulation, deepfakes, cybersecurity vulnerabilities, autonomous AI agents conducting unauthorized transactions, and alleged concentration risks associated with AI infrastructure providers. It would also direct the SEC to establish AI governance requirements for regulated entities and require federal agencies to conduct scenario-based exercises testing resilience against AI-driven financial disruptions. The proposal reflects a growing concern among policymakers that AI may create novel systemic risks requiring coordinated regulatory oversight.
Meta settles landmark child-safety trial with US states for $17 billion
On 26 August 2026, Meta agreed to pay approximately $17 billion over ten years and to adopt new child-safety measures, including daily time limits, nighttime and school-hour restrictions, and enhanced parental controls, ending the federal trial brought by 29 US state attorneys against the company. The case alleged that aspects of Facebook's and Instagram's design may have encouraged prolonged use by children and teenagers, in violation of consumer protection laws and the Children's Online Privacy Protection Act (COPPA). The settlement resolves claims brought by 47 states in total and follows a separate New Mexico ruling earlier in August ordering Meta to pay $567 million over related child-safety harms.
Middle East
UAE
Launch of UAE Dirham-Backed Stablecoin DDSC Approved by Central Bank
On 4 August 2026, UAE-focused financial platform Masarif reported that the Central Bank of the UAE (CBUAE) approved the launch of DDSC, a UAE dirham-backed stablecoin developed by International Holding Company (IHC), Sirius International Holding and First Abu Dhabi Bank (FAB). The stablecoin will operate on the ADI Chain blockchain and is designed to support institutional and government-led use cases, including payments, collections, treasury operations, trade finance and programmable financial services. DDSC is intended to provide a regulated digital payment instrument backed by the UAE dirham, combining blockchain technology with regulatory oversight.
UAE Launches World's First Fully Integrated AI-Powered Judicial Platform
On 28 July 2026, the UAE announced the launch of the world’s first fully integrated AI-powered judicial platform, designed to function as an advanced legal assistant that analyses case files, searches legislation and precedents, generates legal recommendations, and assists in drafting documents, while maintaining complete human judicial oversight and final decision-making independence.
Dubai
Dubai Launches AI-Powered Building Permit System for Instant Approvals
On 9 August 2026, Dubai Municipality announced the launch of an AI-powered system to automate the building permit approval process for private and investment villas, reducing processing times from several days to minutes. The platform analyses submitted drawings and documents, verifies compliance with the Dubai Building Code and technical requirements, assesses architectural, structural, mechanical, electrical and plumbing designs, and generates building card information without human intervention. The system also enables applicants to conduct pre-submission design checks and receive feedback on required amendments.
ADGM Authorises Coinbase to Establish International Tokenised Securities Hub
On 11 August 2026, Coinbase announced the establishment of its international tokenisation hub in Abu Dhabi Global Market (ADGM), after receiving Financial Services Permission from the Financial Services Regulatory Authority (FSRA). The authorisation allows Coinbase to arrange investment deals and provide custody services for the issuance and management of tokenised securities within a regulated framework. The platform is designed to facilitate blockchain-based access to capital markets through tokenised assets backed by underlying securities, incorporating regulatory safeguards, investor protections, sanctions screening and compliance controls.
Dubai Duty Free Launches Crypto Payments for UAE Residents Across Airports and Online
On 5 August 2026, Dubai Duty Free became the first airport retailer in the Middle East to accept regulated cryptocurrency payments, enabling eligible UAE residents to make purchases using Crypto.com Pay at Dubai International Airport, Al Maktoum International Airport and through its online platform. Customers complete transactions by authorising payments through the Crypto.com app, while Dubai Duty Free receives settlement in UAE dirhams through Crypto.com's regulated payment infrastructure. The initiative follows a 2025 partnership between the two organisations to explore blockchain-enabled payment solutions.
Key Dates on the Horizon
September 2026
- 7 September 2026: Deadline for stakeholders to submit comments to the Cyberspace Administration of China on the draft Provisions on Personal Information Protection for Large Personal Information Processors. Consultation
- 30 September 2026: Deadline for stakeholders to submit comments on South Africa’s draft Crypto Asset Manual and draft Capital Flow Management Regulations. Consultation
October 2026
- 1 October 2026: Apple's new EU App Store fee structure enters into effect, replacing the Core Technology Fee with simplified commissions. Announcement
December 2026
- 2 December 2026: Transparency obligations to watermark AI‑generated or manipulated synthetic content will enter into force. EU AI Act
April 2027
- 1 April 2027: India's Central Electricity Authority cybersecurity regulations for the power sector enter into effect. Regulation
December 2027
- 2 December 2027: Obligations for standalone high‑risk AI systems (Annex III) will enter into force. EU AI Act
August 2028
- 2 August 2028: Obligations for high‑risk AI systems subject to EU product harmonisation legislation (Annex I) will enter into force. EU AI Act
Additional information
This publication does not necessarily deal with every important topic nor cover every aspect of the topics with which it deals. It is not designed to provide legal or other advice. Clifford Chance is not responsible for third party content. Please note that English language translations may not be available for some content.
The content above relating to the PRC is based on our experience as international counsel representing clients in business activities in the PRC and should not be construed as constituting a legal opinion on the application of PRC law. As is the case for all international law firms with offices in the PRC, whilst we are authorised to provide information concerning the effect of the Chinese legal environment, we are not permitted to engage in Chinese legal affairs. Our employees who have PRC legal professional qualification certificates are currently not PRC practising lawyers.