Global AI Regulatory Update - July 2026
We’re delighted to share our quarterly Global AI Regulatory Update brought to you by our Knowledge team, summarizing key developments from around the globe.
July 23, 2026
Global AI Regulatory Update - July 2026We’re delighted to share our quarterly Global AI Regulatory Update brought to you by our Knowledge team, summarizing key developments from around the globe.July 23, 2026 This bulletin reflects the current position as of July 6, 2026, and may be subject to change.
GlobalGlobal: AI supervision toolkit for markets published On May 25, 2026, the International Organization of Securities Commissions (IOSCO) published a final report setting out a supervisory toolkit for AI use in capital markets. It aims to support proportionate, risk-based oversight while enabling innovation. The toolkit considers the full lifecycle of AI systems, complements, rather than replaces, national frameworks, and encourages dialogue between firms and regulators. Impact: Organizations should assess existing AI governance and risk management frameworks against IOSCO’s focus areas. They may need to strengthen oversight of third-party providers and improve documentation and reporting practices. Businesses should also monitor emerging expectations on disclosure and record keeping, as further IOSCO work is expected. AsiaHong Kong: Commission issues guidance on AI-enabled cyber threats On June 2, 2026, Hong Kong's Securities and Futures Commission (SFC) issued a circular to licensed corporations and virtual asset service providers addressing AI-related cybersecurity risks. The SFC warns that frontier AI models are lowering the cost and expertise needed to conduct cyberattacks, while increasing their scale and sophistication. AI tools can now identify previously undetected software vulnerabilities and combine multiple weaknesses to accelerate attacks. Threats may include automated intrusion, phishing, deepfake impersonation, and large-scale coordinated attacks. The circular covers five key areas: patch management, access controls, threat detection, third‑party supply chain risks, and incident response. The SFC also flags that firms using AI tools internally face additional risks such as data leakage and adversarial manipulation. Impact: Licensed firms should:
Senior management bears ultimate responsibility for managing these risks. The SFC indicated it may conduct further reviews of firms' preparedness and take supervisory action where appropriate. Hong Kong: Privacy Commissioner expands AI privacy compliance checks On May 19, 2026, Hong Kong's Privacy Commissioner (PCPD) published findings from its third annual round of compliance checks on 60 organizations using AI. The review assessed compliance with the Personal Data (Privacy) Ordinance across 15 sectors, expanding this year to include accounting, logistics, and property management. The findings show that 95% of organizations now deploy AI in daily operations, up 15 percentage points from 2025. Around 42% used AI to process personal data, underscoring the growing importance of privacy safeguards. No breaches of the law were identified, but practices varied across sectors. The report also included new guidance on the responsible use of agentic AI. Impact: Organizations should:
The PCPD specifically flagged agentic AI as an area of caution. Organizations should grant agentic AI only the minimum access rights needed for each task. These findings suggest the PCPD will continue to expand its AI oversight activities. Singapore refines AI governance and studies liability allocation for agents On May 20, 2026, the Infocomm Media Development Authority (IMDA) updated its Model AI Governance Framework for Agentic AI. It also published a discussion paper on legal responsibility for AI agents. The updated framework adds focus on system complexity, multi-agent risks, and third-party dependencies. It also strengthens guidance on human oversight, technical controls, logging, monitoring, and change management. The discussion paper studies liability allocation for AI agents under existing laws and finds that existing laws, including contract and negligence, may address many AI‑agent harms. However, proving intention, causation, foreseeability, and liability allocation may be difficult. It also explores strict liability models, but notes concerns around overbroad risk exposure and reduced incentives for responsible use. Overall, the materials signal growing policy and regulatory focus on agentic AI deployment risks. Impact: Businesses should:
For further information please refer to the Eversheds Sutherland briefing published in June 2026 by Albert Yuen and Yue Lin Lee. EUEU: EIOPA seeks clarity on AI Act for insurers On April 14, 2026, the European Insurance and Occupational Pensions Authority (EIOPA) explained how the AI Act applies to the insurance sector. The letter explains that insurers already follow detailed EU rules on governance and risk management, and they may overlap. These include Solvency II Directive, the Insurance Distribution Directive, and the Digital Operational Resilience Act. This could create duplication, legal uncertainty, and inconsistent supervision across Member States. EIOPA is concerned where new authorities supervise AI instead of existing insurance supervisors. In an annex, EIOPA proposes targeted amendments to the AI Act framework. EIOPA also asks for clearer rules on what counts as an AI system, and what is classified as high risk. Impact: Clarifications on the application of the AI Act should help insurers understand how existing sectoral rules interact with horizontal AI obligations. They may increase focus on AI governance, for systems used in pricing and risk assessment, which may fall within high-risk categories. The transition period may involve parallel oversight by both AI and sectoral supervisors, making early preparation important. Businesses may consider the following actions:
EU agrees to simplify AI Act rules On May 7, 2026, the Council of the EU and the European Parliament struck a deal to simplify the AI Act. Key elements of the agreement include:
Following Parliament adoption on June 16, 2026, the text needs to be adopted by the Council as well before entering into force. Impact: The delay gives businesses additional time to prepare for compliance with high‑risk AI obligations. It also clarifies governance, transparency, and sectoral overlap issues. However, businesses should continue preparing for compliance and avoid delaying implementation while final timelines are confirmed. Businesses should:
EU: Commission issues draft high-risk AI classification guidance On May 19, 2026, the European Commission published draft guidelines clarifying how to classify high‑risk AI systems under the AI Act. The guidance supports providers, deployers, and authorities in applying Article 6 consistently. High‑risk classification arises in two main scenarios under the AI Act framework:
The guidelines include practical examples of systems that should or should not be considered high‑risk. These examples are indicative and may be expanded over time as technology evolves. A targeted consultation on the draft guidelines closed on June 23, 2026. The consultation sought feedback on clarity and usefulness of examples supporting classification decisions under the AI Act. The final guidelines will be adopted by the end of 2026. Impact: The draft guidance improves clarity but does not change the underlying legal obligations of the AI Act. Businesses may consider:
EU: Digital Omnibus on AI agreed On May 7, 2026, it was announced that political agreement had been reached between the European Parliament and Council on the Digital Omnibus on AI. The Digital Omnibus package was adopted by the European Commission in November 2025 and it includes proposals for two simplifying Regulations, one relating to the AI Act, and the other to data, cybersecurity and privacy rules. The intention is to make compliance easier without diluting the impact of the rules. Political agreement now needs to be formally adopted, following which the amending Regulation will be published in the OJEU and enter into force. This will need to happen before August 2, 2026. Impact: The delayed implementation timetable will be welcomed by businesses who should now have the benefit of supporting technical standards and guidance before compliance obligations kick in. Middle EastUAE: Cabinet advances AI healthcare framework On May 18, 2026, the UAE Cabinet adopted a national AI healthcare policy and directed related legislation. The policy sits within wider plans to use Agentic AI across federal government services and operations. It aims to build an AI-enabled medical system covering prevention, treatment, rehabilitation, and healthcare operations. The planned law will regulate smart health applications and AI-based health systems. It is expected to cover data governance, safety, quality, licensing, liability, patient rights, and federal‑local coordination. Impact: Businesses should:
Healthcare providers, insurers, investors, and vendors should map health-data flows and strengthen accountability controls. Contracts should clearly allocate responsibility for approvals, quality standards, data use, and legal liability. UKUK: AI reshapes financial services workforce and skills On May 21, 2026, the Financial Services Skills Commission published a report on how AI and other technologies will reshape work in the financial services sector. The report finds that over time, 30% to 50% of tasks in most roles will see significant automation. Key highlights include:
The report also highlights a potential talent shortage, with up to 450,000 of 780,000 skilled workers expected to leave the sector by 2035 through turnover or retirement. Impact: The report highlights a need for firms to actively plan for workforce transformation and skills development. Businesses should invest in training programs that combine technical, business and behavioral skills. They may also need to redesign entry-level roles and career pathways to reflect automation trends. The report also indicates that collaboration with government and education providers will be important to address future skills shortages. Further practical recommendations are expected in a follow-up report due by early 2027. UK: Government rejects broad AI copyright exception approach On May 15, 2026, the House of Lords Communications and Digital Committee published the Government’s response to its AI and copyright report. The response confirms the Government no longer supports a broad copyright exception for AI training with an opt-out mechanism and no longer has a preferred consultation proposal. The Committee had warned this approach would be unworkable and place unfair burdens on rightsholders. Instead, the Government’s focus shifts towards supporting an emerging licensing market for AI training data, though at this stage the government has indicated it is carrying out information gathering and believes it is premature to intervene in the licensing market at this stage. The Government agreed with the Committee’s position that stronger, mandatory transparency requirements are needed in relation to how AI developers train their models (including the content and data they use). Impact: Businesses should expect the status quo to continue while the Government develops its final position on AI and copyright. UK: Guidance warns on agentic AI adoption risks On May 15, 2026, the UK National Cyber Security Centre published ‘Thinking carefully before adopting agentic AI’, summarizing its new joint guidance on 'Careful adoption of agentic AI services’. The guidance explains that these systems can access data, make decisions, use tools, and act towards defined goals. However, their autonomy and complexity introduce heightened risks compared with traditional AI. These include broader access to systems and data, unpredictable behavior, and increased difficulty spotting problems (especially when actions occur faster than human oversight). Overall, it emphasizes that whilst agentic AI can deliver benefits, the technology requires careful and controlled adoption. Impact: Businesses should assess proposed agentic AI deployment carefully, and adopt a responsible, thoughtful, and scalable approach to deployment. They are encouraged to start with small, controlled pilots and expand use gradually once confidence is established. There should be clarity - before a system is deployed – as to who owns, approves access to, monitors and reviews incidents arising from agentic AI system. The guidance emphasises embedding security from the outset and applying existing cyber security practices. This includes limiting system access, restricting agent actions, and managing supply chain risks. Businesses should also consider potential failure scenarios, plan for incidents, and ensure adequate oversight and monitoring, which may increase governance and risk management expectations for AI deployments. UK: Regulators set out approach to agentic AI On March 31, 2026, the Digital Regulation Co-operation Forum (DRCF) published a foresight paper exploring how the UK regulatory frameworks can support safe and responsible adoption of agentic AI. The DRCF stresses that Agentic AI systems remain subject to a wide range of existing legal obligations. These include transparency, fairness, consumer protection, safety, and competition requirements. The paper highlights potential risks linked to autonomy, such as reduced transparency and challenges for users seeking to contest decisions, which could lead to non-compliance with various legal obligations. It also considers impacts across governance, data protection and cybersecurity, consumer rights, and market competition. Impact: Businesses developing agentic AI are encouraged to, among other things:
The paper notes that continued coordination between market regulators, including the Information Commissioner’s Office, Financial Conduct Authority, Ofcom and the Competition and Markets Authority, will be essential. UK: Financial Conduct Authority publishes The Mills Review In early 2026, the Financial Conduct Authority Board commissioned Sheldon Mills to conduct a strategic review into how advances in AI could transform retail financial services by 2030 and beyond. The review was published on July 6, 2026 (The Mills Review). The Mills Review introduces an ‘AI autonomy spectrum’ to illustrate how the human role changes as AI systems become more capable and autonomous. As firms move from AI-assisted decision-making towards greater delegation, questions of accountability, governance and oversight become increasingly important. It also identifies four systemic shifts that are underway: AI transforming firm operations; consumer journeys becoming agent-led; competition being reshaped by AI platforms; and threats and defences both accelerating. Impact: Firms should, among other things:
See our Insights post on this here: The Mills Review – what FCA-regulated firms should do now on AI, outsourcing and operational resilience USUS: Administration issues Executive Order promoting advanced AI innovation and security On June 2, 2026, the current US administration issued an Executive Order directing federal agencies to promote AI innovation while addressing national security risks. The order calls for strengthened cybersecurity defences for government and critical infrastructure systems, along with expanded use of AI‑enabled cybersecurity tools. It introduces a voluntary framework for engaging with frontier AI models, emphasizing intellectual property protection and accelerating responsible, secure adoption of advanced AI technologies. The order stresses enforcement of existing laws addressing criminal misuse of AI, while declining to impose licensing or permitting requirements on development or distribution. Impact: The order signals the administration’s continued preference for a light-touch, innovation-first approach to AI regulation at the federal level. Organizations developing or deploying AI should monitor agency implementation actions and consider aligning their cybersecurity and AI governance practices with the voluntary framework. US: Federal Trade Commission begins TAKE IT DOWN Act enforcement On May 19, 2026, the compliance deadline under the TAKE IT DOWN Act took effect, triggering active enforcement by the Federal Trade Commission (FTC). The Act, signed into law on May 19, 2025, requires platforms to implement a notice‑and‑removal process for nonconsensual intimate imagery, including AI‑generated deepfakes within one year. Platforms must remove content and identical copies within 48 hours of a valid request or face civil penalties of up to $53,088 per violation. Ahead of the deadline, FTC Chairman Andrew Ferguson issued formal compliance letters to more than a dozen major technology companies. Impact: Platforms hosting user-generated content should ensure robust notice-and-removal systems are operational and capable of meeting the 48-hour takedown window. Given the FTC’s active enforcement posture and significant per-violation penalties, noncompliance carries substantial financial and reputational risk. US: Colorado AI law overhauled amid federal constitutional challenge On April 9, 2026, xAI LLC filed suit challenging Colorado’s AI antidiscrimination statute (SB 24‑205) on First Amendment and Dormant Commerce Clause grounds. On April 24, 2026, the US Department of Justice intervened, marking the first federal challenge to a state AI law. The DOJ added an Equal Protection Clause argument, asserting the statute compels AI companies to embed discriminatory algorithmic outcomes into their systems. The intervention is procedurally significant, as the federal government joined a private suit and secured standing to argue constitutional issues before the court. On May 14, 2026, Governor Jared Polis signed SB 26‑189, replacing the original statute with a narrower automated decision‑making technologies law. The revised law reflects industry concerns and shifts from broad discrimination controls to a more limited documentation‑and‑disclosure framework. Impact: Taken together, these developments reflect the intensity of the legal and political contest over state AI regulation. On the substantive side, Colorado’s replacement of its AI Act with a narrower documentation-and-disclosure framework may reduce compliance burdens for companies in the state. But it also underscores the potential vulnerability of comprehensive state-level AI regulation in the face of industry opposition. On the procedural side, the DOJ’s intervention in xAI v. Colorado—the first federal challenge to a state AI law—sets a significant precedent. It signals the administration’s willingness to use litigation to constrain state regulatory authority over AI. US: Connecticut advances state AI regulatory trends by enacting new laws On May 27, 2026, Connecticut Governor Lamont signed a broad 39-section AI bill into law, creating new requirements. These span several fast-moving areas of AI policy, including companion chatbots, automated employment decision tools, social media, and provenance data. The law also includes provisions related to frontier AI whistleblower protections, AI-related layoff notices, and planning for a state AI regulatory sandbox. This makes it one of the broader state AI packages enacted this year. Impact: The breadth of Connecticut’s law means organizations deploying AI in the state, particularly in employment, social media, and consumer-facing applications, should review new obligations. The regulatory sandbox provision may also create opportunities for companies seeking a controlled environment to test innovative AI products. US: Illinois mandates independent audits for frontier AI safety On July 6, 2026, Illinois signed into law landmark AI safety legislation, joining California and New York in imposing robust requirements for frontier AI developers. The Illinois law goes further than its counterparts by requiring independent auditors to verify that AI labs adhere to their own safety standards. This is the first state law to mandate third-party accountability for AI safety claims. Impact: Frontier AI developers operating in or serving Illinois customers should prepare for independent audit requirements. The law raises the bar for AI safety compliance nationally and may influence other states considering similar legislation. Co-authored by: Uendi Barreti, Paola Paccani, Jon Botham (Knowledge Insights) Key contacts
Nasser Ali Khasawneh Partner Dubai, United Arab Emirates Rachel M. Reid Partner Atlanta, United States Simon Gamlin Partner United Kingdom Olaf van Haperen Partner Rotterdam, Netherlands Jenny D. Lambert Partner Atlanta, United States Albert Yuen Partner Hong Kong SAR, Asia Karishma Brahmbhatt Partner United Kingdom Andrew Garbett Principal Associate Abu Dhabi, United Arab Emirates Yue Lin Lee Senior Associate Hong Kong SAR, Asia Latest Insights
Latest News
Latest Events
legal updates July 23, 2026 AI Governance Bill: Malaysia’s Next Step Towards the First AI Rulebook legal updates July 22, 2026 Commercially Connected shorts - 22 July 2026 legal updates July 21, 2026 RESS 6 Terms and Conditions Published legal updates July 20, 2026 Industrials Unpacked #1: Supply Chain Contracts firm news July 10, 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... client news July 10, 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... client news July 09, 2026 Eversheds Sutherland advises Costello Medical on transition to employee own... firm news July 01, 2026 Eversheds Sutherland lands lateral partner-led Paris Funds team, as its wid... virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States |