Regulators stopped talking about principles in June and started enforcing deadlines. Europe, Asia, and the Americas converged on the same toolkit at once: labeling, prohibition registries, mandatory human oversight, turnover-based fines, even as Italy outpaced the EU timeline it's supposed to follow. The rulemaking also got specific: emotion-detection plug-ins, biometric surveillance, and Brussels turning competition law into an AI access lever by forcing Meta to open WhatsApp to rivals.
The message is the same everywhere: policies no longer satisfy regulators. What's expected now is evidence, audit trails, documented oversight, registries of what's been excluded, not statements of intent.
North & South America Jurisdiction
1. Canadian Privacy Commissioner Found X and xAI in Breach of PIPEDA
June 11, 2026 Canada
The Canadian Privacy Commissioner has ruled that X Corp., provider of a social media platform to Canadian users, and xAI, developer of the generative AI chatbot “Grok”, have breached PIPEDA by launching Grok’s Image Generator without appropriate safeguards.
Grok AI Tool allowed the creation of millions of non-consensual and sexualized deepfakes. The companies failed to obtain valid consent for collecting, using, and disclosing personal information required to construct these harmful deepfakes/synthetic images, posing serious privacy risks. While the companies have rejected recommendations to suspend the tool, they have agreed to produce quarterly progress reports, improve risk mitigation measures, and undergo independent third-party privacy audits.
The ruling stands as a major regulatory warning that "privacy-by-design" frameworks must be built into generative AI tools prior to launch.
2. US President Signs Executive Order for Promotion of Advanced AI Innovation and Security
June 2, 2026 United States
President Donald Trump has signed an Executive Order aimed at advancing AI innovation while strengthening cybersecurity and protecting critical infrastructure.
The Order promotes the adoption of AI-enabled cybersecurity tools across federal agencies and critical infrastructure sectors, establishes an AI cybersecurity clearinghouse to identify and remediate software vulnerabilities, and introduces voluntary collaboration frameworks for frontier AI models. It also calls for the development of AI cybersecurity benchmarking processes and increased federal investment in AI cyber capabilities.
The Order emphasizes a pro-innovation approach, expressly stating that it does not create mandatory licensing or approval requirements for AI model development or deployment.
3. Colorado Enacts AI Chatbot Safeguards for Children
June 1, 2026 Colorado, United States
Colorado Governor Jared Polis has signed HB26-1263 into law, establishing new safeguards for AI chatbots, particularly those accessible to children.
Effective January 1, 2027, the law requires AI developers to clearly disclose when users are interacting with an AI chatbot and prohibits features designed to encourage excessive engagement. The legislation also requires developers to take reasonable measures to prevent chatbots from generating sexually explicit content involving minors or fostering emotional dependency through romantic, sexual, or deceptive human-like interactions. In addition, covered chatbot providers must offer parental controls for younger users and provide suicide prevention resources when users express self-harm or suicidal ideation.
This marks a growing shift toward regulating the behavioral impacts of AI systems, particularly where chatbots interact with children and vulnerable users.
4. European Parliament Approves AI Act Simplification Measures and Ban on AI “Nudifier” Apps
June 16, 2026 EU
The European Parliament has approved amendments to the EU AI Act as part of the Digital Omnibus package, introducing targeted simplification measures while preserving the Act’s risk-based framework. The amendments postpone the application of certain obligations for high-risk AI systems and delay watermarking requirements for some AI-generated content to provide organizations with additional time to prepare for compliance.
The legislation also introduces a ban on AI systems designed to generate non-consensual intimate imagery, commonly referred to as “nudifier” applications, as well as AI systems used to create child sexual abuse material. Additional changes clarify the treatment of AI-enabled machinery products, streamline certain compliance requirements, and expand regulatory support for smaller businesses.
The amendments reflect the EU’s continued effort to balance innovation and regulatory certainty while strengthening safeguards against harmful and abusive uses of AI.
5. European Commission Publishes Final Code of Practice for AI-Generated Content Labeling
June 10, 2026 EU
The European Commission has published the final Code of Practice for AI-generated content labeling, providing guidance on how providers and deployers of generative AI can comply with the transparency requirements under Article 50 of the AI Act.
The Code outlines expectations for machine-readable labeling of AI-generated content and visible disclosures for deepfakes and certain AI-generated public interest content. Organizations that adopt the Code may use it as a means of demonstrating compliance once formally recognized by the Commission and AI Board.
The Code represents one of the first practical compliance frameworks under the EU AI Act and signals increasing regulatory emphasis on transparency and traceability for AI-generated content.
6. Italy Gives Preliminary Approval to Two National AI Decrees Ahead of AI Act
June 10, 2026 Italy
Italy's Council of Ministers has granted preliminary approval to two implementing decrees under its national AI framework, positioning Italy among the first EU member states to establish a comprehensive domestic AI governance regime ahead of the full implementation of the EU AI Act. The proposed measures address AI governance, AI literacy, workplace protections, healthcare oversight, public sector use of AI, and enforcement powers for national authorities.
The decrees also introduce civil and criminal liability provisions for certain AI-related harms, prohibit mass biometric surveillance, and impose strict conditions on the use of real-time biometric identification by law enforcement. The proposals reflect a growing trend among EU member states to supplement the AI Act with national rules addressing governance, accountability, and sector-specific AI risks.
7. EU Orders Meta to Restore Rival AI Assistants' Access to WhatsApp
June 9, 2026 EU
The European Commission has ordered Meta to restore access to the WhatsApp for Business API for competing general-purpose AI assistants while its antitrust investigation continues.
The Commission preliminarily found that Meta may have abused its dominant position by restricting rival AI assistants’ access to WhatsApp while continuing to support its own Meta AI services. Meta must restore access under the same terms that existed before October 2025 and faces significant fines for non-compliance.
The decision reflects increasing regulatory scrutiny of competition concerns arising from large technology platforms integrating and prioritizing their own AI services.
8. Italy’s Garante Warns Startup Over Employee Emotion Detection Plug-In
June 1, 2026 Italy
The Italian Data Protection Authority (Garante) has issued a formal warning to a startup offering an AI-powered plug-in for Slack and Microsoft Teams that analyzes employee communications to detect psychological stress levels and provide personalized recommendations. Although employers cannot access individual results or message content, they may receive aggregated reports on workforce stress trends.
Garante raised concerns about the processing of sensitive information relating to employees’ emotional states and instructed the company to implement privacy safeguards by design. The authority emphasized that employers are generally prohibited from accessing such information under Italian law and noted that the EU AI Act prohibits AI systems used to infer or analyze emotions in workplace settings.
9. South Korea’s PIPC Releases Roadmap for Personal Information Lifecycle Protection
June 9, 2026 South Korea
South Korea’s Personal Information Protection Commission (PIPC) has released its R&D and Standardization Roadmap for Personal Information Lifecycle Protection and Utilization Technology (2026–2030), outlining a long-term strategy to strengthen privacy protection in the age of artificial intelligence. The roadmap identifies 11 priority technologies across four strategic areas, with a particular focus on AI-related privacy challenges and the development of Privacy Enhancing Technologies (PETs).
Key technologies highlighted include homomorphic encryption, synthetic data generation, secure de-identification, and other tools designed to support the safe use and sharing of personal information while enabling innovation in AI and data-driven services.
10. Thailand Unveils ‘AI 2026’ Strategy to Advance AI Governance and Regional Leadership
June 9, 2026 Thailand
Thailand’s Electronic Transactions Development Agency (ETDA) has unveiled its AI 2026 strategy under the theme “Driving Trust AI Governance,” aimed at strengthening AI governance and positioning Thailand as a regional AI hub. The initiative includes the development of AI governance guidelines, risk assessment toolkits, AI safety testing programs, and capacity-building initiatives across government, education, business, and civil society.
As part of the strategy, Thailand is advancing the establishment of an AI Governance Practice Center (AIGPC) and pursuing recognition as a UNESCO-supported regional center for AI governance. The initiative reflects a growing regional focus on responsible AI development, AI literacy, and governance frameworks aligned with international standards.
11. Singapore Consults on Generative AI Personal Data Guidelines
June 2, 2026 Singapore
Singapore’s PDPC has launched a public consultation on proposed advisory guidelines clarifying how the PDPA applies to the use of personal data in Generative AI. The draft covers the collection and use of personal data for model development, including when publicly available data or user data may be used, and requires AI-specific notifications where personal data is used for model training or fine-tuning.
The guidelines also clarify responsibilities across model providers, system providers, and deployers, including retention, protection, purpose limitation, and accountability obligations. They further address how organizations should handle access and correction requests involving Generative AI. Comments are due by July 1, 2026.
Portugal's ANACOM has opened a consultation, until July 16, 2026, on draft guidance for implementing Article 5 of the EU AI Act's ban on rights-threatening AI practices. The six-step framework covers identifying, classifying, and removing prohibited systems, applies retroactively to pre-February 2025 deployments, and carries fines up to €35 million or 7% of global turnover.
The UAE’s newly established Artificial Intelligence and Data Authority (AIDA) is expected to play a central role in shaping the country’s AI governance, data strategy, and digital transformation agenda.
New York’s Senate Bill 9051B, prohibiting operators from deploying unsafe AI companion features designed for minors and introducing mandatory, secure age-verification protocols, has passed the Senate assembly.
In Colorado, the Attorney General’s Office has launched a pre-rulemaking public consultation on the state's upcoming Automated Decision-Making Technology (ADMT) Act and Chatbot Safety Act, seeking feedback on compliance challenges before both frameworks take effect on January 1, 2027.
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
Learn how to operationalize compliance with India's Digital Personal Data Protection Act (DPDPA) using automation for consent, data governance, security, vendor management, and data...
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
This infographic breaks down the key transparency obligations for both deployers and providers under the AI Act’s Article 50 Code of Practice. Access it...
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...