From Principles to Practice: The Next Phase of AI Governance
July's developments reveal a clear shift in global AI governance. Regulators are moving beyond broad principles and high-level strategies toward practical implementation. Rather than asking whether AI should be regulated, jurisdictions are defining how organizations should deploy, monitor, and govern AI in practice.
Three themes stand out. First, transparency is becoming a universal expectation, with increasing emphasis on AI-generated content labeling and user disclosures. Second, regulators are taking a lifecycle approach to AI governance, introducing requirements that span design, deployment, monitoring, and incident response. Finally, technical governance is emerging as a priority, with guidance on AI agents, privacy-enhancing technologies, cybersecurity, and interoperability complementing legal obligations.
For organizations, compliance can no longer be treated as a one-time exercise. AI governance is becoming a continuous operational capability that requires collaboration across legal, privacy, security, engineering, and business functions to keep pace with evolving regulatory expectations.
North & South America Jurisdiction
1. Hawaii Enacts AI Companion and Deepfake Protection Laws
July 14, 2026 Hawaii, United States
On July 14, 2026, Hawaii Governor Josh Green enacted two AI-focused laws: HB 2137 / Act 247, addressing deepfake protections, and SB 3001 / Act 248, establishing safeguards for AI companion services. HB 2137 creates consumer protection rules and civil remedies for certain harmful or unauthorized AI-generated digital replicas, while SB 3001 requires AI companion providers to give clear user disclosures, maintain protocols for responding to suicidal ideation or self-harm prompts, and file annual reports with the Department of Health’s Behavioral Health Administration.
The measures reflect Hawaiʻi’s growing focus on regulating AI applications that may affect personal identity, privacy, user safety, mental health, and minors. Providers of AI companion tools or synthetic media technologies should review their disclosure practices, safety escalation processes, reporting obligations, and controls around harmful AI-generated content.
2. Brazil ANPD Publishes First AI Regulatory Sandbox Monitoring Report
July 2, 2026 Brazil
On July 2, 2026, Brazil’s ANPD released the first partial monitoring report for its AI regulatory sandbox. The initiative involves three selected technology companies testing innovative AI projects under regulatory supervision, with an initial focus on governance, security, transparency, anonymization, data protection safeguards, and evidence-building.
This is significant because it provides early insight into how Brazil’s data protection authority may assess AI systems in practice, particularly around accountability, risk management, and privacy-by-design. Organizations developing or deploying AI in Brazil should monitor the sandbox outcomes as they may inform future ANPD guidance, enforcement expectations, and AI governance standards.
On July 27, 2026, the AI Omnibus Regulation entered into force across the European Union, introducing targeted amendments to the EU AI Act to simplify compliance while maintaining protections for safety and fundamental rights. The changes extend certain compliance timelines, broaden access to regulatory sandboxes, reduce administrative obligations for small and mid-cap companies, and clarify the interaction between the AI Act and other EU legislation.
This is significant because it provides organizations with additional time to prepare for key AI Act obligations while promoting AI innovation by expanding testing opportunities and aligning compliance requirements with proportionate measures. Businesses developing or deploying AI in the EU should review the revised implementation timelines and updated compliance obligations to align their AI governance programs accordingly.
4. CNIL & CIANum Co-author Explanatory Note on Agentic AI Risks
July 20, 2026 France
The French Data Protection Authority (CNIL) and the French Council for AI and Digital Technology (CIANum) have co-authored an explanatory note on personal data protection risks introduced by the rise of agentic AI. The note highlights that agentic AI systems possess decision-making autonomy, persistent memory, and the ability to interact with multiple connected services to execute tasks on a user's behalf.
This shift in agentic AI, moving beyond standard generative AI, drastically increases the volume and complexity of data processing, creating hyper-personalized profiles, obscuring data flows, and making GDPR compliance and responsibility-sharing among decentralized actors difficult to trace. While existing EU data protection laws and AI regulations apply, the note emphasizes that their implementation must be adapted to address the unique cybersecurity risks, data persistence, and delegation capabilities inherent in agentic AI.
5. European Commission Issues Guidelines on Transparency Standards Under the EU AI Act
July 20, 2026
The European Commission has published official guidelines detailing transparency standards under Article 50 of the AI Act, which will apply starting August 2, 2026.
These guidelines establish specific obligations for both providers and deployers of AI systems posing transparency risks. Under the guidance, organizations must inform users whenever they are directly interacting with an AI system, label AI-generated content (including synthetic audio, video, images, or text), disclose deepfakes, and explicitly notify individuals if they are exposed to emotion-recognition or biometric-categorization tools.
Providers and deployers are expected to follow these guidelines to ensure consistent, proportionate, and uniform compliance across the EU.
6. Greece Adopts National AI Act Implementation Framework
July 16, 2026 Greece
On July 16, 2026, the Greek Parliament approved legislation establishing Greece's national framework for implementing the EU AI Act. The law designates the competent supervisory and enforcement authorities, establishes complaint-handling mechanisms, introduces administrative sanctions for non-compliance, enables AI regulatory sandboxes, and creates a public-sector AI systems registry. It also prohibits removing transparency labels from deepfake content and imposes criminal penalties for violations.
This is significant because Greece is among the first EU Member States to establish a comprehensive national implementation framework for the EU AI Act. Organizations developing or deploying AI systems in Greece should monitor the designated authorities, enforcement mechanisms, and national compliance requirements, particularly regarding regulatory sandboxes, public-sector AI governance, and transparency obligations for AI-generated content.
7. European Commission Endorses AI Transparency Code of Practice
July 9, 2026
On July 9, 2026, the European Commission published its opinion concluding that the Code of Practice on Transparency of AI-generated Content adequately supports compliance with the transparency obligations under Articles 50(2), 50(4), and 50(5) of the EU AI Act. The AI Board subsequently adopted its adequacy assessment, confirming the Code as an appropriate voluntary instrument to help providers and deployers of generative AI systems, including general-purpose AI models, meet the AI Act's transparency requirements.
This is significant because the Code provides organizations with practical, EU-wide guidance on implementing the AI Act's transparency obligations, including those related to AI-generated content and deepfakes. While adherence to the Code does not create a presumption of compliance, organizations developing or deploying generative AI systems should consider aligning their practices with its commitments to support AI Act compliance.
8. South Korea's PIPC Releases Public AI Privacy Protection Guide
July 23, 2026 South Korea
South Korea's Personal Information Protection Commission (PIPC) published the Public AX Privacy Protection Guide to support the safe adoption of AI in the public sector. The guidance outlines privacy measures across the AI lifecycle, including defining clear processing purposes and legal bases during system design, implementing technical safeguards such as pseudonymization, anonymization, Privacy-Enhancing Technologies (PETs), and input/output filtering during development, and conducting ongoing privacy and safety assessments during operation while ensuring transparency and data subject rights.
This is significant because the guidance provides public institutions with practical expectations for embedding privacy into AI systems throughout their lifecycle. Organizations developing or deploying AI solutions for the Korean public sector should consider aligning their governance, technical controls, and privacy compliance practices with the PIPC's recommendations.
9. Singapore Expands Privacy-Enhancing Technologies Guidance and Sandbox Use Cases
July 20, 2026 Singapore
Singapore's Personal Data Protection Commission (PDPC) published a new Guide on Federated Learning and updated its Guide on Synthetic Data Generation to support the adoption of Privacy-Enhancing Technologies (PETs). The guidance provides practical implementation roadmaps, risk management recommendations, and use cases to help organizations adopt privacy-preserving AI techniques. In parallel, the Infocomm Media Development Authority (IMDA) expanded its PET Sandbox with new real-world use cases, including secure AI-assisted medical image analysis by Singapore General Hospital using Trusted Execution Environments (TEEs) and privacy-preserving payment verification by Ant International using Multi-Party Computation (MPC).
This is significant because it reinforces Singapore's focus on enabling privacy-preserving AI innovation through practical guidance and regulatory support. Organizations developing AI systems or processing sensitive data should consider whether PETs such as Federated Learning, Synthetic Data, TEEs, or MPC can help reduce privacy risks while supporting AI development and cross-organizational collaboration.
10. China Introduces Regulatory Framework for AI Companion Services
July 15, 2026 China
China's Interim Measures for the Administration of AI Anthropomorphic Interactive Services came into effect, establishing a regulatory framework for AI systems designed to simulate human personalities and provide continuous emotional interaction, such as AI companion services. The measures prohibit providers from offering virtual intimate or kinship relationships to minors and require anti-addiction controls, safeguards against emotional manipulation, robust data governance, and emergency intervention protocols for users expressing severe distress or self-harm.
This is significant because it introduces dedicated compliance requirements for AI companion services, reflecting China's growing focus on addressing the psychological and societal risks associated with anthropomorphic AI.
11. Taiwan FSC Urges Financial Institutions to Prepare for AI-Driven Cyber Threats
July 14, 2026 Taiwan
Taiwan's Financial Supervisory Commission (FSC) issued strategic recommendations urging financial institutions to strengthen resilience against cyberattacks enabled by advanced AI models. The guidance recommends adopting zero-trust security, enhancing continuous monitoring, integrating security earlier into software development, strengthening third-party and supply chain risk management, improving threat intelligence sharing, conducting resilience exercises, and exploring defensive AI capabilities.
This is significant because it reflects growing regulatory expectations for financial institutions to address AI-driven cybersecurity risks through stronger governance, operational resilience, and proactive security controls as advanced AI models accelerate the speed and sophistication of cyber threats.
12. Vietnam Designates High-Risk AI Systems Across Key Sectors
July 9, 2026 Vietnam
Vietnam announced Decision 33/2026/QD-TTg, which establishes a list of high-risk AI systems across sectors such as education, health, banking, justice, transportation, ethnicity, and religion. AI systems within these categories must comply with the requirements of Vietnam's AI Law, including risk-based governance, human oversight, accountability, and restrictions on prohibited AI practices.
This is significant because the decision operationalizes Vietnam's AI Law by identifying sectors subject to enhanced regulatory oversight. Organizations developing or deploying AI systems in these areas should assess whether their systems fall within the high-risk categories and ensure appropriate governance, risk management, and human oversight measures are in place.
13. South Korea Unveils 2027–2029 Personal Information Protection Plan for the AI Era
July 3, 2026 South Korea
South Korea's Personal Information Protection Commission (PIPC) announced its Third Basic Plan for Personal Information Protection (2027–2029), setting out a three-year strategy to support trustworthy AI innovation. The plan adopts a risk-based approach to privacy regulation, strengthens preventive data protection measures, expands AI-specific privacy safeguards, enhances cross-border data transfer frameworks, and introduces a one-stop system for data subject redress. It also proposes guidance for emerging technologies, including Agent AI and physical AI, while promoting Privacy-Enhancing Technologies (PETs) and MyData initiatives.
This is significant because it outlines South Korea's long-term policy direction for balancing AI innovation with stronger privacy governance and individual rights.
Thailand's Ministry of Digital Economy and Society (DES), through the Electronic Transactions Development Agency (ETDA), launched a public consultation on the draft principles of the country's first Artificial Intelligence Act. The proposed framework adopts a risk-based approach, with enhanced requirements for high-risk AI systems, while promoting responsible AI, regulatory sandboxes, transparency, accountability, and human rights protections. The draft also contemplates incentives to support AI innovation alongside governance measures.
This is significant because it marks an important step toward establishing Thailand's first comprehensive AI regulatory framework, balancing innovation with safeguards for individuals and providing greater regulatory certainty for AI developers and deployers.
15. Vietnam Requires AI-Generated News Content to Be Clearly Labeled
July 1, 2026 Vietnam
Vietnam issued Decree No. 237/2026/ND-CP, requiring media organizations to clearly label text, images, audio, and video created or edited using AI when such content could mislead audiences about the authenticity of events or individuals. The Decree also requires editorial oversight, verification of AI-generated content, risk management procedures, audit logs, and prohibits the use of AI to create or distribute false or harmful content. The requirements took effect on July 1, 2026.
This is significant because it establishes mandatory transparency and governance obligations for the use of AI in journalism, reinforcing accountability and public trust in AI-assisted media content.
16. China Issues Security Guidelines for the Deployment and Use of AI Agents
July 1, 2026 China
China's National Cybersecurity Standardization Technical Committee issued the Cybersecurity Standards Practice Guide: Security Guidelines for the Deployment and Use of Intelligent Agents. The guidance provides recommended security measures across the AI agent lifecycle, including assessment, preparation, deployment, operation, and decommissioning, and is intended to help organizations identify and mitigate cybersecurity risks associated with deploying AI agents. It also serves as a reference for selecting and using commercial AI agent services.
This is significant because it provides practical cybersecurity guidance for organizations deploying AI agents, reflecting China's increasing focus on secure AI implementation and lifecycle risk management.
17. China Releases National Standards for AI Agent Interoperability
July 1, 2026 China
China released seven national standards in the "Artificial Intelligence Intelligent Agent Interconnection" series to promote interoperability between AI agents. The standards establish a common framework covering architecture, identity management, capability descriptions, agent discovery, interactions, and tool invocation, creating a unified lifecycle for AI agent collaboration and communication.
This is significant because the standards provide a common technical foundation for interoperable AI agent ecosystems, helping organizations reduce development complexity, improve compatibility between AI systems, and strengthen identity authentication and traceability as AI agents become more widely deployed across industries.
The UK’s Department for Science, Innovation and Technology (DSIT) has opened a public call for evidence to evaluate how current data regulations interact with AI and emerging technologies. Stakeholders have until September 9, 2026, to submit real-world feedback on regulatory friction and legal uncertainties, which will inform potential regulatory guidance, targeted tweaks, or broader framework reforms.
Innovation, Science and Economic Development Canada (ISED) launched a public consultation on AI transparency, seeking input on AI-generated content labeling, AI interaction disclosures, system capability information, serious incident tracking, and AI agent monitoring.
The Federal Trade Commission (FTC) seeks public comment on a proposed AI accuracy policy statement, signaling potential scrutiny of AI systems that manipulate outputs or deviate from consumer expectations of objectivity and accuracy under Section 5 of the FTC Act.
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
Executive summary In June 2026, South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.68 billion won (approximately $409 million) which was the largest...
An access-review tool flags an account with more privilege than its role needs: routine, filed, forgotten. That same week, a separate scan shows that the same...
Explore DSPM best practices for discovering sensitive data, reducing exposure, governing access, prioritizing risk, and strengthening enterprise data security.
Explore why DSPM is becoming essential for modern data security, helping organizations discover sensitive data, reduce exposure, govern access, and prepare securely for AI.
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...