Skip to main content

Clifford Chance
Tech<br />

Tech

Talking Tech

Tech Policy Unit Horizon Scanner

September 2026

Artificial Intelligence Data Privacy Cyber Security 1 October 2026

September 2026 saw a noticeable shift in the global conversation around artificial intelligence. While governments and businesses continued to invest heavily in increasingly capable and autonomous AI systems, regulators, legislators and parts of industry devoted growing attention to the question of whether frontier AI development is advancing faster than the safeguards needed to govern it. Leading this shift were developments in the United States, where proposals around pausing future artificial superintelligence until safety rules exist culminated in the signing of the White House Accord on Super Intelligence: Joint Commitment on Frontier Responsibilities. This accord establishes that AI companies training and deploying frontier models will implement four layers of controls and audits and meet regularly to establish standards and best practices to improve system safety. Alongside these US commitments, calls grew in the United Kingdom for dedicated AI legislation and a specialist regulator, while European Commission initiatives focused on model evaluation, verification and risk mitigation, centering the broader debate not on whether AI should continue to advance, but whether the rate of capability growth should be moderated until governance frameworks, security controls and societal protections can catch up.

Online safety and the protection of children continue to be a prominent theme. Australia consulted on draft digital duty-of-care legislation that would require digital service providers to take greater responsibility for user safety and offer users greater control over algorithmically personalised feeds. In the EU, the Commission proposed the EU KIDS Act, including minimum-age requirements, privacy-preserving age verification and safety-by-design obligations covering social media, video-sharing services, online games, AI companions and chatbots. These measures sit alongside the Commission’s planned Digital Fairness Act, which is expected to address issues including addictive online design. 

On the cyber and data front, UK developments included National Cyber Security Centre guidance on the risks created by “shadow AI” and confirmation of the transition from the Information Commissioner’s Office to the new Information Commission. Elsewhere, the EU Agency for Cybersecurity launched the Cyber Resilience Act’s Single Reporting Platform for reporting actively exploited vulnerabilities and severe incidents affecting products with digital elements, while the UAE Central Bank introduced a new operational-risk regime requiring financial institutions to strengthen resilience against cyberattacks, fraud, outages and third-party disruption. Meanwhile, Australia proposed reforms encompassing consent, sensitive information, breach notification and enforcement; Kenya consulted on extending protection for specified categories of sensitive personal data; and Singapore proposed licensing regimes for major cloud providers and data centres. 

THE REGIONS IN DETAIL

APAC (Excluding China)

Australia

Australian Government published the draft Privacy Amendment (Personal Data Protection) Bill 2026 for public consultation

On 31 August 2026, the Australian Government published the draft Privacy Amendment (Personal Data Protection) Bill 2026 for public consultation. The draft bill proposes updated definitions, tougher consent requirements, and the treatment of geolocation and genomic data as sensitive information. The bill also introduces stronger breach response obligations, including 72-hour notification to the Information Commissioner, and expanded enforcement powers for the Office of the Australian Information Commissioner (OAIC). Comments were requested by 18 September 2026.

Australian Government consults on draft digital duty-of-care bill

On 8 September 2026, the Australian Government launched a consultation on draft Digital Duty of Care legislation that would require digital service providers to take greater responsibility for user safety online and meet minimum standards for platform design and risk management. The proposal includes the Australian-first “My Feed, My Way” initiative, requiring social media platforms to give new and existing users a choice between algorithmically personalised feeds and feeds based on accounts they actively follow. The draft laws would also require online games, apps and AI chatbots to protect under-18s from harmful design features and content, including material promoting eating disorders, misogyny, pornography, crime glorification, dangerous stunts, bullying and abuse. The legislation would strengthen powers of the eSafety Commissioner, including the ability to issue removal notices for nudify apps and websites, streamline cyber-abuse schemes, and require platforms to document and maintain measures that address risks to Australian users. Non-compliance could result in penalties of up to A$109.2 million. The Government is seeking feedback from digital platforms, industry bodies and civil society stakeholders before introducing the legislation to Parliament later this year. Comments were requested by 22 September 2026.

Japan

Japan’s PPC releases monitoring and breach statistics

On 24 September 2026, Japan’s Personal Information Protection Commission (PPC) published a report stating that it had processed 5,650 data breach reports in Q1 FY2025, most of which were submitted by private businesses. The majority of incidents involved special care-required personal information, frequently arising from incorrect document delivery. The PPC also issued 166 guidance actions, mainly concerning inadequate security measures, with common causes including unpatched vulnerabilities, weak passwords, and poor access controls.

Japan launches public consultation on draft ministerial ordinance for wideband low-power radio systems in the 800 MHz band

On 12 September 2026, Japan's Ministry of Internal Affairs and Communications (MIC) launched a public consultation on a draft ministerial ordinance amending the Radio Act Enforcement Regulations to establish additional regulatory arrangements for wideband low-power radio systems in the 800 MHz band. The consultation follows MIC's earlier revision of the relevant ordinance on 30 July 2026, based on its review of technical standards for these systems. These initiatives stem from the planned termination of the Digital MCA System by the end of May 2029, which prompted MIC to examine new uses for the 800 MHz band currently used for that system.

India

India’s Department of Telecommunications introduces mandatory biometric verification

On 21 August 2026, India's Department of Telecommunications (DoT) published the Telecommunications (User Identification) Rules, 2026 which require authorised telecoms entities to carry out biometric identification of users. The rules set out e-KYC and D-KYC processes, require subscriber record-keeping, complaint handling, user support, and explicit user acknowledgement. Entities must comply within three months from 21 August 2026, with non-compliance treated as a breach of authorisation conditions and a possible three-month extension available.

Singapore

Singapore’s Ministry of Digital Development and Information proposes licensing framework for cloud services and data centres

On 8 September 2026, Singapore’s Ministry of Digital Development and Information proposed the Digital Infrastructure Bill for First Reading. The bill proposes licensing regimes for major cloud service providers and data centres operating in the country. Providers would be required to adopt security risk management measures and maintain business continuity plans, while data centres with a critical IT load of at least three megawatts would need a licence. The IMDA would oversee the regimes, with a six-month transition period for existing providers. The Bill will now proceed to a Second Reading. The bill's First Reading follows publication of the consultation outcome of the Ministry of Digital Development and Information and the Infocomm Media Development Authority's public consultation which ran from 1 July to 22 July 2026.

Vietnam

Da Nang City Police in Vietnam highlights compliance obligations under Decree 174 for online businesses

On 10 September 2026, Da Nang City Police issued guidance on Decree No. 174/2026/ND-CP, which introduces penalties for non-compliant online business activities from 1 July 2026. The Decree applies to Vietnamese and foreign organisations, business households, and individuals, covering areas such as online content, e-transactions, information security, customer data protection, and intellectual property. Potential sanctions include fines, business suspension, licence revocation, equipment confiscation, and social media account blocking, with businesses advised to review online activities, strengthen data protection, monitor legal updates, train staff, enhance security, and verify advertising content.

China

China publishes AI Safety Governance Framework 3.0

On 14 September 2026, the National Technical Committee 260 on Cybersecurity of SAC released the AI Safety Governance Framework 3.0. The Framework 3.0 was developed under the guidance of the Cyberspace Administration of China to respond to new trends in AI development and new challenges in safety governance, following the release of the 1.0 and 2.0 versions in 2024 and 2025. It continues the core approach of risk classification, technical response and integrated governance, while updating the classification of risks and optimising technical response and governance measures to support consensus-building and risk prevention in AI security governance.

China releases Practice Guidelines on cockpit data processing security

On 15 September 2026, the National Technical Committee 260 on Cybersecurity of SAC released the Cybersecurity Standards Practice Guidelines - Security Requirements for Cockpit Data Processing. The Guidelines provide security requirements for cockpit data processing activities, covering basic security requirements, technical security requirements and security management requirements. They aim to guide cockpit data processors in conducting cockpit data processing activities in a standardised manner, protecting the rights and interests of personal information subjects, and providing a reference for the design and development of vehicle cockpit functions.

China releases Three Practice Guidelines on information erasure for electronic products

On 15 September 2026, the National Technical Committee 260 on Cybersecurity of SAC released three Cybersecurity Standards Practice Guidelines relating to information erasure: the Technical Guidelines for Block Erasure of Semiconductor Storage Media, the Management Guidelines for Information Erasure in Electronic Product Recycling, and the Technical Guidelines for Information Erasure of Mobile Smart Terminals. The Guidelines are intended to support the implementation of the mandatory national standard GB 46864-2025 Data Security Technology - Technical Requirements for Information Erasure of Electronic Products. They aim to guide relevant organisations in carrying out information erasure activities in a standardised manner and are provided as references for relevant parties.

China releases four Practice Guidelines on AI application security

On 15 September 2026, the National Technical Committee 260 on Cybersecurity of SAC released four Cybersecurity Standards Practice Guidelines on AI application security, comprising one general guideline and three sector-specific guidelines. The four Guidelines cover general principles, education, healthcare, and radio, television and online audiovisual services. The Guidelines seek to address new risks and challenges arising from the rapid development and application of artificial intelligence, while supporting the secure deployment and use of AI applications. The General Principles provide common security guidance for AI application activities across industries, while the sector-specific documents provide targeted security practice guidance for AI application activities in education, healthcare, and radio, television and online audio-visual services.

Africa

Kenya

Kenya consults on expanding categories of sensitive personal data

On 11 September 2026, Kenya's Office of the Data Protection Commissioner (ODPC) published a draft notice proposing additional categories of sensitive personal data under section 47 of the Data Protection Act 2019. The proposal would classify political affiliation and trade union membership as sensitive personal data where such information is transferred into Kenya from jurisdictions that already treat those categories as sensitive or special-category data. The draft notice is intended to address risks associated with cross-border transfers and to ensure that data transferred from jurisdictions with higher protections does not lose equivalent safeguards when processed in Kenya. The ODPC is consulting on the proposal, with stakeholder comments invited until 25 September 2026.

Europe

European Union

European Commission designates ChatGPT, Reddit and Roblox under the Digital Services Act

On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE), and Reddit and Roblox as Very Large Online Platforms (VLOPs), under the DSA, after each was found to reach at least 45 million average monthly EU users. Following designation, the services have four months, until around January 2027, to comply with enhanced DSA obligations, notably assessing and mitigating systemic risks (e.g. illegal content, harm to minors, fundamental rights, electoral processes, public security), undergoing an annual independent audit, and sharing data with regulators and vetted researchers.

State of the Union 2026: European Commission Signals continued push on AI, Cyber Security and Digital Resilience

On 16th September 2026, Ursula von der Leyen, President of the European Commission, delivered her 2026 State of the Union address, setting the priorities for the Union for the year ahead. This included plans to strengthen Europe’s technological sovereignty, cyber resilience and capacity to deploy artificial intelligence, while introducing tighter safeguards for advanced systems, where the President said that the Commission would work with partners including Canada and the United Kingdom on model evaluation, verification, early-warning mechanisms and AI security. It will also engage leading frontier-model developers on industry efforts to moderate the development of self-improving models. Alongside implementation of the AI Act, the Commission intends to expand Europe’s computing capacity and develop new ways of combining public and private investment in European technology companies. Its industrial AI programme will focus on health, transport, agri-food, advanced manufacturing, defence and space, with sector-specific initiatives due to be announced in November 2026. The Commission’s objective is to move AI into practical economic and public-service applications while reducing cost and energy consumption, preserving human oversight and ensuring that AI supports rather than replaces professionals. Wider cyber and hybrid-security measures will include a new European security strategy, enhanced collective responses to cyberattacks and sabotage, and proposals for a European Security Council. The Commission also plans a technology alliance with Canada covering AI, quantum technology, cybersecurity and economic security. Finally, she announced the EU KIDS ACT (see below) which will impose age-based protections for children using social media and require platforms to demonstrate that their services are safe; a broader Digital Fairness Act addressing issues including addictive online design is scheduled for autumn 2026.

European Commission adopts proposal for the EU KIDS Act

On 17 September 2026, the European Commission adopted its proposal for the EU KIDS Act, aimed at making online services safer for minors. The text would ban social media access for children under 13, set an EU-wide minimum age of 15 for minors to open their own account, and allow supervised parental accounts in between. It reverses the burden of proof, requiring providers of social media, video-sharing platforms, online games, AI companions and chatbots to demonstrate that their services are safe by design. This includes banning addictive features, engagement-driven recommender feeds, and unsolicited contact from strangers targeting minors. The proposal also mandates privacy-preserving age-verification tools and builds enforcement on the existing DSA/AI Act framework.

The proposal now goes to the European Parliament and Council for examination.

ENISA launches single reporting platform under the Cyber Resilience Act

On 11 September 2026, the European Union Agency for Cybersecurity (ENISA) launched the Single Reporting Platform (SRP) under the Cyber Resilience Act, coinciding with the entry into application of the CRA's reporting obligations for manufacturers. The SRP allows them to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements, through a single notification which the coordinating Computer Security Incident Response Team (CSIRT) disseminates to other relevant national CSIRTs while making it simultaneously available to ENISA. ENISA intends to further expand the platform's functionalities based on operational experience and user needs.

European Commission proposes new European Innovation Act

On 9 September 2026, the European Commission proposed a new European Innovation Act as part of its Startup and Scaleup Strategy and Competitiveness Compass. The proposal aims to improve the conditions for developing, financing and scaling innovative technologies in the EU through measures covering intellectual property, public procurement and regulatory experimentation. It will notably create a common EU framework to value intellectual property, a digital marketplace connecting IP buyers and sellers, and a common procedure for research and development (R&D) procurement. The proposal sits within the Commission's broader competitiveness and technological sovereignty agenda.

United Kingdom

ICO to become Information Commission on 30 September 2026

On 15 September 2026, the Information Commissioner's Office (ICO) announced that it will become the Information Commission on 30 September 2026. The Data (Use and Access) Act 2025 (Commencement No 9 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/1015) were made on 10 September 2026 and bring into force sections 117(4)(a), 118 and 119 of the Data (Use and Access) Act 2025 (DUA Act) on 30 September 2026 relating to the abolition of the Information Commissioner's Office (ICO) and transfer of functions to the new Information Commission, and reforms the regulator's governance structure by replacing the current model with a board-led framework. The regulator has stated that its statutory functions, powers and responsibilities will remain unchanged. Seven non-executive members were appointed to the new board in July 2026 and will assume their roles when the transition takes effect.

UK Parliament committee calls for dedicated AI legislation and regulator

On 14 September 2026, the UK Parliament's Joint Committee on Human Rights published a report examining the impact of artificial intelligence on human rights in the UK. The report concludes that AI presents significant risks to rights including privacy, data protection, equality and access to effective remedies, and argues that the current regulatory approach is fragmented and insufficiently coordinated. The Committee recommends that the UK Government introduce dedicated AI legislation, establish a dedicated AI regulator, and strengthen accountability and enforcement mechanisms for AI-related harms. The report also urges the Government to engage with international initiatives including the Council of Europe's Framework Convention on AI and Human Rights.

Digital Twins Bill proposed in UK Parliament

On 9 September 2026, Dame Chi Onwurah MP introduced the Personal Data (Digital Twins) Bill. The Bill has been proposed with the intention of regulating software and algorithms that use or hold personal data to model an individual's preferences or behaviours. This could cover content creation algorithms, deepfakes, and chatbots and explicit consent would be required before a digital twin of a person could be created. The full text of the Bill has not yet been published, with its second reading scheduled for 13 November 2026.

UK NCSC publishes guidance on managing cybersecurity risks arising from shadow AI

On 7 September 2026, the National Cyber Security Centre (NCSC) published a blog on managing the cybersecurity risks associated with "shadow AI", referring to the use of AI tools that fall outside an organisation's approved systems and governance processes. The NCSC noted that such tools are increasingly common and may create risks including data leakage, loss of intellectual property, security vulnerabilities and regulatory non-compliance. The guidance recommends that organisations understand why employees are adopting unauthorised AI tools, foster a positive cybersecurity culture, and provide secure, approved AI alternatives supported by appropriate governance, monitoring and risk management measures.

Americas

The United States of America

US Representatives introduce Stop Rogue AI Act

On 14 September 2026, Reps. Josh Gottheimer and Mike Lawler introduced the Stop Rogue AI Act (H.R. 10362), which would direct the National Institute of Standards and Technology to develop standards for identifying, monitoring, and controlling AI agents operating within organisational networks.

Lawmakers announce Ban Artificial Superintelligence Act

On 3 September 2026, Sen. Bernie Sanders and Rep. Greg Casar announced the Ban Artificial Superintelligence Act, which would prohibit the development and deployment of artificial superintelligence and pause advanced AI development until a new federal regulator establishes safety rules. The bill would create a cabinet-level AI agency, establish penalties for violations, and direct the United States to pursue international coordination aimed at preventing the development of superintelligent systems.

Whitehouse secures agreement from AI companies for self-regulation for frontier AI

On 29 September 2026, the White House issued the "White House Accord on Super Intelligence: Joint Commitment on Frontier Responsibilities," establishing that AI companies training and deploying frontier models will implement four layers of controls and audits: establishing internal controls to monitor capabilities and alignment regarding cybersecurity, biosecurity, and chemical threats; empowering a dedicated internal team to oversee controls and remediation; partnering with independent external auditors or evaluators; and designating an independent board committee to oversee reporting and issue resolution. As a further action, participating companies will meet regularly to establish standards and best practices to improve system safety, while noting that these measures may eventually be codified into laws or regulations. In addition, the White House has issued an Executive Order establishing that executive branch departments and agencies must use the terms "Super Intelligence" and "SI" in place of "Artificial Intelligence" and "AI" across non-statutory documents, public communications, official correspondence, reports, and websites to the maximum extent permitted by law.

Middle East

UAE

New UAE Central Bank rules target outages, fraud and cyberattacks

On 14 September 2026, the Central Bank of the UAE (CBUAE) brought into force its new Operational Risk Management Regulation, replacing the previous 2018 framework and introducing stricter requirements for banks and licensed financial institutions to strengthen operational resilience. The regulation requires institutions to identify critical operations, establish disruption tolerance levels, and implement comprehensive contingency plans to ensure the continuity of essential financial services during technology failures, cyberattacks, fraud incidents, system outages, and third-party service disruptions. It also places direct responsibility on boards of directors and senior management for overseeing operational risk, resilience, and cybersecurity governance. The framework mandates enhanced incident management, business continuity planning, risk monitoring, and recovery capabilities, reflecting the growing reliance on digital banking channels, payment systems, and financial technology services. By strengthening safeguards against operational disruptions and cyber threats, the regulation aims to protect customers, maintain confidence in the financial system, and support the UAE’s broader strategy of building a secure, resilient, and digitally advanced financial sector.

UAE accelerates AI-led governance with new Cabinet Adviser platform

On 2 September 2026, Sheikh Mohammed bin Rashid Al Maktoum, Vice President and Prime Minister of the UAE and Ruler of Dubai, chaired the first Cabinet meeting of the new government season and approved the launch of the Cabinet AI Adviser System. The new platform deploys 32 specialised AI assistants to analyse government policies, legislation, strategies and systems, assess their potential impacts, review international best practices, and provide recommendations to ministers. The system will also support the implementation and monitoring of Cabinet decisions, with the aim of improving the speed and quality of government decision-making. The initiative forms part of the UAE’s broader AI-led transformation agenda and was described as a strategic national project intended to drive long-term changes in government operations. The Cabinet also reaffirmed its commitment to accelerating artificial intelligence adoption across the public sector while strengthening efficiency, innovation and data-driven governance.

Abu Dhabi

Abu Dhabi embraces Agentic AI to strengthen hazardous materials risk monitoring

On 14 September 2026, the Abu Dhabi Hazardous Materials Management Centre (ADHMMC) and Presight signed a strategic cooperation agreement to deploy agentic artificial intelligence solutions across Abu Dhabi’s hazardous materials monitoring and management ecosystem. The partnership aims to enhance risk detection, monitoring, analytics, and decision-making capabilities by enabling the continuous analysis of data from multiple sources, identifying anomalous patterns, and supporting specialist teams with timely operational insights. The collaboration will explore AI applications across the entire hazardous materials lifecycle, including transportation, storage, trading, usage, recycling, and disposal, while developing and testing high-impact use cases in controlled environments. The partners will also ensure compliance with AI governance, cybersecurity, data privacy, sovereignty, and human oversight requirements, supporting the responsible adoption of advanced technologies for proactive risk management across the emirate.

Dubai

Dubai Chambers launches Agentic AI training programme for 14,000 businesses

On 1 September 2026, Dubai Chambers launched specialised training programmes to help more than 14,000 member companies of its Business Groups and Business Councils adopt Agentic AI across their operations. Delivered through the newly established Dubai Chambers Academy, the training is designed to equip businesses with practical knowledge of Agentic AI, including its applications in decision-making, productivity enhancement, operational efficiency, and business innovation.

Saudi Arabia

Saudi Arabia advances AI investment and innovation partnerships in Silicon Valley

On 9 September 2026, Saudi Arabia’s Minister of Communications and Information Technology, Abdullah Alswaha, held a series of meetings with leading technology and investment firms in Silicon Valley to strengthen the Kingdom’s artificial intelligence (AI), computing, and deep technology partnerships. Discussions focused on expanding investments in Saudi AI and deep-tech companies, connecting portfolio firms with HUMAIN’s computing capabilities, and supporting the international growth of Saudi startups. Alswaha also met technology leaders to explore the use of AI agents in semiconductor design and verification, with the aim of accelerating development cycles and enhancing the Kingdom’s advanced chip design capabilities. The engagements form part of Saudi Arabia’s broader strategy to attract high-value technology investments, expand international AI collaborations, strengthen digital infrastructure, and position the Kingdom as a globally competitive hub for innovation, advanced technologies, and AI-driven economic growth.

Key Dates on the Horizon

October 2026

  • 1 October 2026: Apple's new EU App Store fee structure enters into effect, replacing the Core Technology Fee with simplified commissions. Announcement

November 2026 

  • 13 November 2026: Second reading of the Digital Twins Bill. First Reading
  • 21 November 2026: Authorised telecoms entities in India must comply with the Telecommunications (User Identification) Rules, 2026. User Identification Rules

December 2026

  • 2 December 2026: Transparency obligations to watermark AI‑generated or manipulated synthetic content will enter into force. EU AI Act

April 2027

  • 1 April 2027: India's Central Electricity Authority cybersecurity regulations for the power sector enter into effect.  Regulation

December 2027

  • 2 December 2027: Obligations for standalone high‑risk AI systems (Annex III) will enter into force. EU AI Act

August 2028

  • 2 August 2028: Obligations for high‑risk AI systems subject to EU product harmonisation legislation (Annex I) will enter into force. EU AI Act

Additional information

This publication does not necessarily deal with every important topic nor cover every aspect of the topics with which it deals. It is not designed to provide legal or other advice. Clifford Chance is not responsible for third party content. Please note that English language translations may not be available for some content.

The content above relating to the PRC is based on our experience as international counsel representing clients in business activities in the PRC and should not be construed as constituting a legal opinion on the application of PRC law. As is the case for all international law firms with offices in the PRC, whilst we are authorised to provide information concerning the effect of the Chinese legal environment, we are not permitted to engage in Chinese legal affairs. Our employees who have PRC legal professional qualification certificates are currently not PRC practising lawyers.