AI View - August 2026

Our fortnightly round-up of key AI legislative, regulatory and policy updates from around the world.

05 August 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

Welcome to AI View, Simmons & Simmons' fortnightly round-up of key AI legislative, regulatory, and policy updates from around the world.

EU AI Act now enforceable by regulators

From 2 August 2026, the EU AI Act became enforceable. The AI Office (which regulates GPAI model obligations) and EU Member State Market Surveillance Authorities (MSAs) (which regulate AI system obligations i.e. prohibited, high-risk and transparency obligations) now have enforcement powers. These powers are extensive and the enforcement landscape is complex (with various exceptions to this general position).

Following the recent adoption of the Digital Omnibus on AI, the high-risk regime has been delayed. Obligations on Annex III high-risk systems will apply from 2 December 2027, and those on Annex I high-risk systems will apply from 2 August 2028.

Importantly, the Art. 50 transparency regime also applies from 2 August 2026. Subject to certain exceptions:

  • Providers of AI systems intended to interact directly with individuals must be labelled as AI.

  • Providers of AI systems that generate or manipulate content must ensure that content is marked in a machine-readable format and detectable as such, which is a particularly tricky provision (NB: there is a grace period until 2 December 2026 for genAI systems already launched as at 2 August 2026).

  • Deployers of emotion recognition or biometric categorisation systems must inform users of their operation.

  • Deployers of AI systems that generate deep fake content or public interest text must label the content.

We have been advising extensively on enforcement of the AI Act and on the various regimes, particularly the transparency regime given it is a current priority. Please feel free to contact us if we can help you.

We have various AI Act resources, available on our website here.

This edition brings you:

  1. EU's Digital Omnibus package comes into force

  2. European Commission issues transparency guidelines for AI providers and deployers

  3. US House lawmakers introduce bill to establish federal oversight of advanced AI

  4. China proposes global framework for AI ethics and AI agents

  5. Singapore issues transparency guidelines for generative AI chatbots

  6. Singapore to tighten cybersecurity rules for AI threats

  7. Australian government outlines AI consumer safety priorities

  8. South Korea introduces bill to amend the AI Basic Act and introduce tiered generative AI disclosure requirements

1. EU's Digital Omnibus package comes into force

On 27 July 2026, the AI Omnibus entered into force. First proposed as part of the digital omnibus package on 19 November 2025, it simplifies the AI rulebook by streamlining certain requirements, easing compliance for smaller businesses, expanding testing opportunities for companies developing and deploying AI in Europe and improving consistency across other EU legislation.

Key changes include:

  • Prohibitions on explicit content: From 2 December 2026, AI systems that generate non-consensual sexually explicit content or child sexual abuse material will be prohibited. Where it is reasonably foreseeable that a system placed on the market has the capability to generate such material, providers must implement reasonable safety measures to prevent it.

  • High-risk AI regime extended: Rules for high-risk AI systems under Annex III will apply from 2 December 2027, and rules for high-risk AI systems under Annex I will now apply from 2 August 2028.

  • Data use for bias correction: Processing of personal data will be permitted where strictly necessary to detect and correct biases in AI systems, subject to proper safeguards.

  • Extended enforcement powers: The AI Office gains extended oversight of certain AI systems, including those built on general-purpose models and embedded in large online platforms and search engines.

Read the regulation here.

2. European Commission publishes transparency guidelines for AI providers and deployers

On 20 July 2026, the European Commission published final guidelines (the Guidelines) on the transparency obligations under Art. 50 of the AI Act for AI systems. The AI Act transparency obligations apply from 2 August 2026, subject to a limited grace period for generative AI systems placed on the market or put into service before that date, in respect of which providers will have until 2 December 2026 to comply with the marking obligation in Art. 50(2).

Art. 50 sets out five transparency obligations:

  • Art. 50(1): providers of AI systems that interact directly with natural persons must ensure users are informed that they are interacting with AI.

  • Art. 50(2): providers of AI systems generating or manipulating synthetic content must ensure outputs are marked in a machine-readable format and detectable as AI-generated or AI-manipulated.

  • Art. 50(3): deployers of emotion recognition and biometric categorisation systems must inform affected individuals of the operation of the system.

  • Art. 50(4): deployers must label AI-generated or AI-manipulated deepfakes.

  • Art. 50(4) (cont.): deployers must label AI-generated or AI-manipulated text published on matters of public interest.

The Guidelines provide non-binding practical guidance on how to interpret these obligations to assist providers and deployers in determining whether AI systems fall within scope (and also on ensuring compliance). They also include extensive examples of both in-scope and out-of-scope use cases. Of particular note, the Guidelines expressly address agentic AI systems and include specific guidance on AI agent disclosures, including disclosure of the person on whose behalf an AI agent is acting.

The Guidelines sit alongside the Code of Practice on Transparency of AI-generated Content, a voluntary code which provides guidance on demonstrating compliance with the marking and labelling obligations in Arts. 50(2) and 50(4).

Read the Guidelines here.

3. US House lawmakers introduce bill to establish federal oversight of advanced AI

On 23 July 2026, a bipartisan group of US House Representatives introduced a draft Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act (the Bill).

The Bill, which was developed as part of the broader Great American AI Act framework, proposes a national, risk-based framework governing the development and deployment of the most advanced AI models.

The Bill proposes tiered requirements based on the size of a frontier AI developer, including model cards, risk-management frameworks, independent audits, incident reporting, and ongoing assessments. It also creates a uniform national standard for transparency, auditing, and reporting of catastrophic risk in order to prevent a patchwork of state regulations.

The Bill takes a targeted approach, focusing oversight on the handful of companies developing the most powerful frontier AI models rather than on start-ups and smaller developers. By doing so, the Bill aims to avoid one-size-fits-all mandates and allows smaller developers to build new technologies without navigating unnecessary federal red tape. Its sponsors describe the Bill as a common sense measure designed to protect the public from catastrophic risk while preserving American innovation and competitiveness, and they are clear that it represents a starting point, with further measures expected to follow.

Looking ahead, the House Energy and Commerce Committee is expected to schedule a hearing or markup on the bill once the House reconvenes in September.

Read the Bill here.

4. China proposes global framework for AI ethics and AI agents

On 17 July 2026, at the 2026 World Artificial Intelligence Conference in Shanghai, China's Cyberspace Administration proposed a Global Cooperation Initiative on Mutual Trust, Connectivity and Interoperability for AI Agents (the Initiative).

The Initiative calls for international cooperation on technical standards, interoperable infrastructure and cross-border data collaboration to support trusted AI-agent ecosystems, while encouraging responsible innovation, lifecycle safety governance and ethical safeguards. It also calls for broader participation across countries, companies, research institutions and open-source communities, support for developing economies through infrastructure and capacity building, and efforts to improve AI literacy in order to prevent a widening digital divide.

Alongside the Initiative, China unveiled an International AI Ethics Governance Action Plan (the Action Plan), published in full on 17 July 2026 and jointly guided by the Ministry of Industry and Information Technology and other government bodies. The Action Plan encourages governments to adopt a tiered approach to AI-ethics governance, encouraging countries to identify and classify ethical risks according to an AI system's technical characteristics and scope of impact.

The Action Plan's key features include:

  • Differentiated oversight: Differentiated governance rules for AI agents and embodied AI based on data sensitivity, permissions to access external tools and the degree of autonomous decision-making.

  • Ethics across the AI lifecycle: Embedding ethical considerations from research and development through to deployment and operation, including improving the quality of training data and the transparency and explainability of AI systems, and preventing misuse once systems are deployed.

  • Clearer responsibilities: Clarifying the respective roles of foundation-model providers, AI-agent developers, deployers, interface providers, terminal-device manufacturers, distribution platforms, operators and users, to help address growing uncertainty over liability.

  • Multi-stakeholder governance: A framework led by governments, with a stronger coordinating role for the United Nations and greater representation for developing countries.

Read the press release here.

5. Singapore issues transparency guidelines for generative AI chatbots

On 20 July 2026, Singapore's Infocomm Media Development Authority (IMDA) published new voluntary Transparency Guidelines for generative AI chatbots (the Guidelines), which are aimed at helping organisations share information about the capabilities and limitations of their generative AI systems.

At their core, the Guidelines set out how chatbot deployers can offer meaningful transparency to their users through a chatbot "info card", described as being akin to a "medical label". This covers the information that users are likely to find relevant, and how deployers can present it clearly and accessibly.

The Guidelines set out that chatbot info cards should help users understand the following:

  • What the chatbot can and cannot do: its capabilities, or the tasks that the chatbot can handle, its limitations, or caveats related to its performance and any prohibitions, so users can select appropriate tasks.

  • How reliable and safe it is: the common risks the chatbot may pose, the safeguards in place, any residual risks, and recommended user precautions.

  • How user data is used and protected: what data is collected, who can access it, whether it is used for model training, and what controls are available to users.

  • How users can report issues: the appropriate channel for raising a concern, the types of issue that can be raised, and how a report will be acknowledged and followed up.

The Guidelines were developed with input from industry, government agencies and consumers, and are intended to balance these perspectives by providing a practical framework that is useful to consumers and realistic for deployers to implement.

Several organisations have indicated that they will follow the Guidelines to strengthen their transparency practices for their public-facing chatbots over the next 6 to 12 months.

Read the Guidelines here.

6. Singapore to tighten cybersecurity rules for AI-enabled threats

On 22 July 2026, the Cyber Security Agency of Singapore (CSA) announced that it will release an updated Cybersecurity Code of Practice for Critical Information Infrastructure (the CCoP) and a new Cybersecurity Code of Practice for Cloud Services (the CCoP (Cloud)) in the later part of this year.

The announcement was made by the Minister for Digital Development and Information at the Operational Technology Cybersecurity Expert Panel Forum 2026.

Since the CCoP was last updated in 2022, the cyber threat landscape has shifted with new AI-enabled threats, allowing threat actors to launch attacks faster and at greater scale. With the emergence of Frontier AI, threat actors can now discover vulnerabilities faster, narrowing the window for exploitation.

To address advanced persistent threats and AI-enabled threats, the updated CCoP will include technical guidance covering adversarial attack simulation, penetration testing and threat hunting. In line with the amendments made to the Cybersecurity Act, the updates focus on strengthening the governance, visibility, detection and readiness of Critical Information Infrastructure (CII), as well as the broader enterprise networks interconnected with it.

Among other measures, the legal entities, organisations, and operators responsible for computer systems and networks essential to national security, the economy, public health, or safety (CII owners) will be required to:

  • Strengthen board accountability: Boards and senior management must take greater accountability for cybersecurity, maintaining a documented cyber resilience framework reviewed at least annually.

  • Attain higher certification: CII owners must attain the CSA's Cyber Trust Mark Level 5 certification. The Cyber Trust mark is a cybersecurity certification developed by the CSA for organisations with digital operations. It has five tiers, with level 5 being the highest.

  • Broaden oversight and detection: CII owners must maintain oversight of interconnected systems that communicate with CII, work with CSA to deploy threat detection systems across their networks and develop a comprehensive cybersecurity exercise plan to ensure a coordinated response to incidents.

Both the updated CCoP and the new CCoP (Cloud) are expected to be launched in the later part of 2026.

Read the press release here.

7. Australian government outlines AI consumer safety priorities

On 20 July 2026, the Australian government outlined a series of AI safety priorities under its National AI Plan (the Plan). The Plan emphasises that, to fully realise the economic and social benefits of AI, Australians must have confidence that AI is being developed and deployed safely.

The Plan sets out five priorities intended to strengthen protections, increase accountability and support the safe adoption of AI across the community and within the government itself:

  • Duty of care: Legislating a Digital Duty of Care that puts the onus on AI companies to build in safety by design and to address potential harm proactively.

  • Privacy: Consulting on a second tranche of privacy reform to strengthen, modernise and simplify Australia's personal data protection laws, on the basis that a robust framework for personal data protection is crucial for both conventional and AI-driven services.

  • AI safety in the workplace: Pursuing AI safety in the workplace as one of the five agreed priority areas of the tripartite Artificial Intelligence Workplace and Employment Forum.

  • Consumer protections: Examining options in Australian consumer law to address consumer risks such as retail surveillance pricing and agentic commerce.

  • Framework for automated decision-making: Developing a framework to better regulate the use of automated decision-making within federal agencies, recognising the importance of fair, accurate and transparent government decision-making in the context of emerging technologies such as AI.

The government stated that these priorities are not exhaustive of its safety agenda, and that they build on the establishment of the AI Safety Institute, which has commenced safety testing of frontier AI systems, formed research partnerships with the Commonwealth Scientific and Industrial Research Organisation (CSIRO), finalised a project on multi-agent risk with the Gradient Institute, and is collaborating on best practice AI safety with the International Network for Advanced AI Measurement, Evaluation and Science.

Read the press release here.

8. South Korea introduces bill to amend the AI Basic Act with tiered generative AI disclosure requirements

On 27 July 2026, a bill amending the Artificial Intelligence Basic Act (the Bill), including provisions on differentiated generative AI disclosure requirements, was introduced to the South Korean National Assembly. The Bill sets out different disclosure obligations for generative AI outputs based on a business's role in the AI value chain.

Under the current law, uniform transparency requirements apply to all AI operators, requiring them to indicate when generative AI has produced products, services or results. The Bill notes that this uniform labelling duty does not distinguish between the different roles and responsibilities within the industry, making it unclear how each type of operator must fulfil its obligations.

To address this, the Bill distinguishes between two categories of business:

  • AI development businesses: Those which develop and provide AI models, APIs and generative engines. They would be required to display generative AI results using machine-readable methods aligned with international technical standards.

  • AI user businesses: Those which utilise AI to deliver final products and services, including applications, platforms and content services. They would be required to present generative AI outputs in a manner that users can clearly recognise.

The Bill aims to ease the regulatory burden created by the current uniform approach, reduce compliance costs, and improve both the effectiveness and international consistency of AI transparency regulation.

The Bill has been introduced to the National Assembly and is subject to the legislative process before it can be enacted.

Read the Bill here (only available in Korean).

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.