NextAI+ Research · ai-governance-w2-Jun-2026
The week's five developments point to a single through line: in the major economies, the center of gravity in AI governance is expanding from regulating what models do to building what nations can do. The United States is folding frontier models into its national cyber defense apparatus while attempting to federalize the regulation of model development; the European Union is pushing governance down from models to cloud, compute, and software supply chains; South Korea is acquiring frontier model capability outright through international cooperation. This reading still needs to be tested against events — the three documents released this week are, respectively, an executive order, a discussion draft, and a legislative proposal, each with different binding force and durability — but the directional resonance is unmistakable: AI governance is converging with infrastructure policy, industrial policy, and national security policy.
On June 2, 2026, US President Trump signed the executive order Promoting Advanced Artificial Intelligence Innovation and Security, bringing frontier models' advanced cyber capabilities, AI-assisted vulnerability discovery and remediation, and the cyber misuse of AI agents into the framework of national cybersecurity and critical infrastructure protection, with 30- and 60-day deadlines for federal agencies. Frontier model security has thereby been written into America's national cyber defense system. The same day, Singapore's Personal Data Protection Commission published its draft Proposed Advisory Guidelines on Use of Personal Data in Generative AI and opened a public consultation, breaking personal data governance in generative AI down into model development, system deployment, post-deployment management, and the handling of individual rights requests. Companies using generative AI in Singapore will need data protection mechanisms that cover the full lifecycle.
On June 3, 2026, the European Commission tabled the proposed Cloud and AI Development Act, which — through incentives for data center expansion, a four-level cloud and AI sovereignty assessment framework, and public sector adoption mechanisms — extends the focus of AI governance from model and application risk to cloud, data centers, compute supply, and supply chain resilience. The EU is institutionalizing AI sovereignty as a matter of infrastructure and public procurement. The same day, South Korea's Ministry of Science and ICT confirmed that the Korea Internet & Security Agency had joined Anthropic's Project Glasswing and obtained access to Claude Mythos Preview. National cybersecurity capability-building is beginning to incorporate frontier model collaboration, and the governance agenda is extending accordingly to access control, usage auditing, and vulnerability response processes.
On June 4, 2026, US Representatives Jay Obernolte and Lori Trahan released a discussion draft of the Great American Artificial Intelligence Act, an attempt to establish a federal AI governance framework and to redraw the boundary between federal and state authority over model development and application deployment. US AI regulation is moving from fragmented state-level experimentation toward a debate over a unified federal framework.
On June 2, 2026, President Trump signed the executive order Promoting Advanced Artificial Intelligence Innovation and Security, directing federal agencies to work with the AI industry to strengthen AI cyber defenses for national security systems, federal government systems, and critical infrastructure, and to establish a classified benchmarking process and a voluntary early access framework for frontier models' advanced cyber capabilities. Key tasks carry 30- and 60-day deadlines, with first deliverables due by July 2 and August 1, 2026.
This order is best read against the arc of US federal AI policy. President Biden's Executive Order 14110 of October 30, 2023, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, had routed frontier model testing through the National Institute of Standards and Technology — a civilian standards body — and emphasized international norm-building; it was rescinded on January 20, 2025. The America's AI Action Plan of July 2025 then set a deregulatory, pro-innovation baseline. The new order is the first executive action on that trajectory to rebuild a federal evaluation mechanism for frontier models — but along a visibly different path: testing authority shifts from a civilian standards body to the Treasury, the National Security Agency, and the Cybersecurity and Infrastructure Security Agency; the benchmark moves from public to classified; and the focus narrows from safety and trustworthiness broadly to cyber offense and defense. According to TechPolicy.Press, the text of the order had been shelved for months before signing — a sign of the administration's ongoing internal tug-of-war between regulating frontier models and staying out of innovation's way.
a. Priority targets: national security systems, federal systems, and critical infrastructure
The order moves frontier model security out of the narrow lane of model safety and into the framework of national cybersecurity and critical infrastructure protection. It directs agencies to prioritize hardening the cyber defenses of national security systems, defense-related systems, and civilian federal systems, and to extend AI defense tools to federal agencies, state and local governments, and critical infrastructure operators.
What US regulators are watching is not merely whether AI generates harmful content, but whether highly capable AI changes the balance of cyber offense and defense: frontier models can be used for vulnerability discovery and attack automation, and can equally become part of defense augmentation and the protection of critical systems.
b. An AI cybersecurity clearinghouse to scale vulnerability discovery and remediation
The order directs the Secretary of the Treasury, in consultation with the National Cyber Director, the National Security Agency (NSA), and the Cybersecurity and Infrastructure Security Agency (CISA), to form an AI cybersecurity clearinghouse. The text describes its function as one that "coordinates and deconflicts scanning for software vulnerabilities, discovers and validates such vulnerabilities, and coordinates and prioritizes remediation and distribution of vulnerability patches."
Cybersecurity governance is thus adding AI-assisted, large-scale vulnerability identification, validation, and remediation coordination alongside traditional human-driven response. For companies in critical infrastructure, finance, healthcare, energy, telecommunications, and cloud services, future regulatory attention may increasingly fall on whether they possess AI-assisted vulnerability management capabilities.
c. Frontier model evaluation: classified benchmarking plus voluntary early access
The order introduces the concept of a "covered frontier model" but does not define it in the text. Instead, it requires the Treasury, the Department of War (through the NSA), and the Department of Homeland Security (through CISA) to establish, within 60 days, a classified benchmarking process to assess AI models' advanced cyber capabilities and to set the capability threshold at which a model is designated a covered frontier model. The order also calls for a voluntary framework under which AI developers may give the federal government secure early access to models up to 30 days before public release.
Notably, the United States has chosen voluntary, cooperative evaluation between government and model developers rather than mandatory licensing or pre-release approval. This differs from the EU's emphasis on uniform statutory obligations and from the audit- or disclosure-centered approach of some state bills, and it reflects the federal government's current weighting of innovation speed, early government visibility, and cybersecurity cooperation. Because the benchmarking process is classified, companies developing models with significant cyber-relevant capabilities may need to engage the government proactively to learn whether their models fall within the designation.
Policy researchers have already registered reservations about the voluntary framework's effectiveness. A June 2026 assessment by the Council on Foreign Relations observes that the government cannot assess what it cannot see, and frontier capabilities are visible only to the labs that build them; leading labs will likely participate voluntarily — if only to forestall more invasive regulation later — but the framework has little purchase on models built outside that circle. The instrument itself is also unstable: an executive order can be revoked at the stroke of the next president's pen, as the fate of EO 14110 demonstrates. Whether this mechanism hardens into durable US frontier model governance ultimately depends on congressional codification — which is precisely where the GAAIA discussion draft, below, comes in.
d. Cyber misuse of AI agents enters the enforcement agenda
The principal risk of AI agents is not erroneous output but their capacity to autonomously connect to systems, access data, execute actions, and amplify cyberattack capability. The order directs the Attorney General to prioritize enforcement against the use of AI to unlawfully access or damage computer systems or steal data, and against the use of AI agents to unlawfully access data in furtherance of crime.
On June 4, 2026, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a discussion draft of the Great American Artificial Intelligence Act (GAAIA), inviting feedback from experts, companies, workers, researchers, and the public. The document has not been formally introduced and creates no legal obligations, but it attempts to establish a federal AI governance framework, bringing frontier model transparency, third-party audits, whistleblower protection, and the federalization of state rules on AI model development into the legislative conversation.
Federal attempts to restrain state AI legislation have already failed once, in 2025. That June, the Senate Commerce Committee tried to attach to the budget reconciliation bill a ten-year freeze on state AI laws, tied to 500 million dollars in broadband subsidies; a compromise briefly shortened the term to five years, but the deal collapsed within 24 hours, and on July 1, 2025, the Senate stripped the provision in an overwhelming 99-1 vote. In November 2025, House Republican leadership was reported to be weighing the National Defense Authorization Act as a new vehicle for preemption. That history calibrates how much GAAIA actually changes: the scope of preemption narrows from all state laws "limiting, restricting, or otherwise regulating" AI to state laws specifically regulating model development; the term shrinks from ten years to a three-year sunset; and federal transparency, audit, and whistleblower obligations are offered in exchange. It is a compromise draft written with the 99-1 lesson in mind — but its passage still runs through the same coalition that sank the moratorium.
a. A legislative attempt to move from state fragmentation to a unified federal framework
GAAIA's first significance is its attempt to answer the fragmentation of US AI regulation. The official press release states that the draft aims to establish a federal framework for governing AI and to gather input before formal introduction.
US AI governance is moving from state-led experimentation into a debate over a unified federal framework. For companies, this is not yet a settled compliance rule, but it signals that US AI compliance may no longer mean tracking states one by one, and may instead take the shape of a two-tier structure: a federal floor plus state-level application regulation.
b. Frontier model safety designed as a national standard: transparency, third-party audits, whistleblower protection
GAAIA centers frontier model safety: large frontier AI developers would be required to publish and adhere to catastrophic risk plans, report critical safety incidents, undergo third-party audits, and refrain from retaliating against employees or contractors who report violations. The official FAQ states that the framework would elevate leading state-level transparency, audit, and whistleblower anti-retaliation requirements into national standards.
Frontier AI safety would no longer rest on voluntary corporate commitments; it could be converted into a nationally uniform regime of transparency, audit, and internal accountability. For model developers, risk assessment, model release reporting, safety incident reporting, audit materials, and internal whistleblower protections may all become baseline compliance capabilities.
c. CAISI designed as the central executor of US AI safety governance
The draft would formally establish in statute the Center for AI Standards and Innovation (CAISI), administered by the Department of Commerce and authorized at 100 million dollars per fiscal year, responsible for developing AI safety guidelines and standards, testing and evaluating frontier AI systems, and administering a licensing regime for independent verification organizations.
The United States, on this evidence, is unlikely to build a single super-regulator for AI; it is concentrating AI safety capability in standards, evaluation, and verification institutions. This differs from the EU's Artificial Intelligence Act, implemented through uniform regulation and a multi-layer supervisory architecture, and leans instead on technical standards, evaluation capacity, and an independent verification ecosystem.
d. Redrawing the state line: preempting model development laws while preserving use and deployment regulation
GAAIA's most contested move is its redrawing of state AI law. The draft would preempt state or local laws "specifically regulating the development" of an AI model, while expressly preserving generally applicable laws, common law remedies, and laws regulating the use or deployment of AI; the preemption sunsets after three years. The FAQ further specifies that state regulation of model deployment, distribution, provision, and use survives, as do general laws on product liability, civil rights, labor protection, copyright, child protection, and consumer privacy.
The controversy began the day the draft was released. Brad Carson, president of the advocacy group Americans for Responsible Innovation, called the preemption provision "a generational mistake," arguing that it "takes the current floor on state AI legislation and turns it into a federal ceiling," leaving state legislatures unable to address emerging AI harms. The safety-focused Alliance for Secure AI welcomed the draft's bipartisan attention to catastrophic risk but likewise opposed preemption, arguing the framework's protections do not justify removing states' ability to enact their own safeguards. Supporters' core argument is the real cost of fragmentation: inconsistent state rules impose duplicative and conflicting obligations on model developers. This floor-versus-ceiling fight will be the main battleground once GAAIA is formally introduced.
The likely shape is a two-tier governance structure: federalized model development, state-governed application scenarios. Model developers may face a more uniform federal standard, while specific use contexts — hiring, finance, healthcare, education, consumer protection, privacy, child safety — remain subject to state regulation.
On June 3, 2026, the European Commission tabled the proposed Cloud and AI Development Act (CADA), aimed at strengthening the EU's cloud and AI ecosystem, investment, and infrastructure, and at reducing dependence on non-EU cloud providers and critical digital infrastructure through data center expansion, a cloud and AI sovereignty assessment framework, and public sector adoption mechanisms. CADA is at present a Commission proposal; it must pass through the Council and the European Parliament and creates no legal obligations yet.
Europe's anxiety over cloud dependence did not begin with CADA. Gaia-X, launched by France and Germany in 2019, attempted to build a European federated cloud through an industry alliance, but loose governance and the deep involvement of US hyperscalers diluted its sovereignty ambitions and limited its impact; in the past two years, the EuroStack initiative from academia and industry has pushed full-stack European technological sovereignty further up the policy agenda. CADA can be read as the legislative turn in that lineage: the EU is no longer relying on voluntary industry alliances, but reaching for regulatory instruments and public procurement leverage. In scholarly terms, this also marks a strategic shift. The pattern Anu Bradford described in The Brussels Effect (Oxford University Press, 2020) was the EU exporting regulatory standards to global firms through its single market; what CADA pursues is no longer rule export but capability retention within the Union. Whether that shift succeeds will be one of the defining case studies in digital governance over the coming years.
a. AI governance extends from models and applications to cloud, compute, and data center infrastructure
CADA's first change is to push AI governance beyond model capability, output risk, and high-risk applications, down to the cloud, data center, and compute supply layer. The Commission states that the deployment of AI Factories and AI Gigafactories is providing high-capacity computing resources for European companies and researchers, and that the EU still needs to expand cloud and data center capacity to support broader AI deployment and diffusion.
The EU is beginning to treat AI deployment capacity as an infrastructure question, not merely an algorithmic or compliance one. For companies, model compliance will be only part of deploying AI in the EU; which cloud the model runs on, where the data centers sit, whether compute is sustainable, and whether the supply chain is trusted will all become components of AI governance.
b. Cloud and AI sovereignty institutionalized as a four-level assessment framework
CADA's most consequential mechanism is a unified EU cloud and AI sovereignty assessment framework. The proposal defines four assurance levels, set by criteria including control over the service, control over the supply chain, treatment of data, infrastructure location, and cybersecurity: Level 1 requires infrastructure located in the EU; Level 2 requires providers to demonstrate independence from third countries and transparency over their software supply chain; Level 3 requires EU ownership and control plus additional criteria such as personnel citizenship; Level 4 requires full transparency and control over the software supply chain with no third-country interference. Member states and Union entities must each conduct sovereignty risk assessments to set the appropriate level for different public sector use cases; cloud providers must be audited before member states may recognize them.
Cloud selection will no longer be a matter of price, performance, and availability alone; it will be assessed for sovereignty, control, and supply chain resilience. For companies serving the public sector, critical infrastructure, finance, healthcare, energy, or government services, whether a cloud vendor can meet a given sovereignty level may directly determine procurement outcomes and deployment architecture.
The framework drew immediate fire. The Computer and Communications Industry Association (CCIA), representing major US technology firms, called it "a dangerous recipe for progressive market shutdown," and its Europe senior vice president Daniel Friedlaender warned the act would produce "fragmented discrimination across Europe in 27 different ways." Analysts further note that because the US CLOUD Act subjects US-incorporated companies to US law wherever their servers sit, Levels 3 and 4 are effectively unreachable for American hyperscalers by design. Trade bodies from Australia, Canada, and Japan have warned that the arrangement could incidentally shut other non-EU firms out of the European market as well. Given that the proposal must still pass the Council and Parliament, dilution of the upper levels in legislative negotiation is a real possibility — companies making architecture decisions should include a final-standard-weaker-than-draft scenario in their planning.
c. Public procurement as the policy lever for European cloud and AI capability
CADA does not merely encourage industrial investment; it tries to shape the market through public sector demand. The Commission says CADA will establish public sector adoption mechanisms and enable public administrations to pool purchasing power through common EU-level procurement frameworks, while accelerating cloud and AI uptake in key sectors and strengthening the added value of EU innovation and supply chain resilience.
The public sector thus becomes not only a subject of AI regulation but a demand-side instrument for cultivating European cloud and AI capability. Companies serving the EU public or quasi-public sector may in future need to demonstrate that their cloud, AI, data, and software supply chains meet specified sovereignty levels, not merely general IT security standards.
d. CADA and the AI Act as complements: one governs risk, the other builds infrastructure capacity
The EU Artificial Intelligence Act is organized around AI system risk, high-risk applications, general-purpose AI models, transparency, and market surveillance; CADA addresses the supply side — AI and cloud infrastructure, data center capacity, digital sovereignty, and public sector adoption. The Commission positions CADA as a component of the AI Continent Action Plan, intended to lift Europe's leadership in cloud and AI by strengthening the ecosystem, investment, and infrastructure.
EU AI governance is taking the shape of a network in which regulatory rules, industrial infrastructure, and sovereignty assessment run in parallel. For companies, compliance is no longer just answering whether a system is high-risk under the AI Act; it also means answering whether model deployment, cloud choice, data residency, and supply chain control align with the EU's strategic direction.
On June 2, 2026, Singapore's Personal Data Protection Commission (PDPC) published the Proposed Advisory Guidelines on Use of Personal Data in Generative AI and opened a public consultation. The document is a draft advisory guideline, not a new binding regulation. It addresses generative AI model development, system deployment, responsibility allocation, and individual rights requests, explaining how the Personal Data Protection Act 2012 (PDPA) applies to personal data processing across the generative AI lifecycle.
The draft is the latest step in Singapore's incremental approach, not an isolated move. In March 2024 the PDPC issued the Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems, resolving PDPA questions for conventional discriminative AI; in May 2024 the Infocomm Media Development Authority and the AI Verify Foundation published the Model AI Governance Framework for Generative AI at the level of principles. The increment in this draft is to bring generative AI — training data provenance, user data in fine-tuning, the deployment responsibility chain, personal data in hallucinated output — formally under the interpretive application of the PDPA. Singapore is staying its course of extending existing data law by interpretation rather than legislating a dedicated AI statute, a methodological counterpoint to the EU's horizontal legislation and a useful reference for jurisdictions that likewise do not plan a standalone AI law.
a. Personal data governance in generative AI extends from training data to the full lifecycle
The PDPC draft does not stop at training data. It expressly covers the development, deployment, and post-deployment phases of generative AI, including how personal data is used in model development, how data protection responsibility is allocated among different actors, and how individuals may make access and correction requests regarding their data used in generative AI.
Generative AI compliance cannot consist of a one-time data provenance review before training; it must cover data entering the model, system launch, user input, inference output, log retention, and individual rights response. For companies, AI compliance is moving from point-in-time review to continuous operational governance.
b. Publicly available does not mean freely trainable
The draft clarifies how the Publicly Available Exception applies in generative AI settings. The PDPC explains that certain publicly available personal data may be collected and used under specific conditions, but organizations must still assess whether the data is genuinely public, whether digital barriers exist, what the purpose of access restrictions is, whether the data is obtainable from other sources, and whether the use meets reasonableness requirements.
The point is critical for AI training: visible online does not mean usable without condition for training generative AI. For companies that train on web scraping, social media content, public forums, review data, images, or voice data, provenance assessment must become more granular than a one-line "public data" justification.
c. User-provided data for training or fine-tuning requires AI-specific notice
The draft proposes that when an organization wishes to use personal data provided directly by users to develop a generative AI model, its notice should explain the model's function, the types of data used, the training or fine-tuning purpose, and how users can decline or withdraw consent. The draft's examples include updated privacy policies, dedicated privacy pages, in-platform notices, and email updates.
The core change: a generic "product improvement" clause in a standard privacy policy may not be sufficient to support generative AI training. Companies that use user-uploaded text, images, audio, conversation logs, or business data for model training, fine-tuning, or product improvement will need notice mechanisms that are more specific, more comprehensible, and operationally opt-out-able.
d. Responsibility refined from who provides the model to who develops, who integrates, who deploys
The PDPC distinguishes model providers, system providers, and system deployers in the generative AI ecosystem, and sets out the data protection responsibilities each may bear. For system deployers in particular, the PDPC is explicit: when procuring systems they must obtain sufficient information, assess upstream safeguards, and ensure the chosen system supports their own PDPA obligations.
Companies cannot treat the use of third-party AI tools as outsourced responsibility. Even where the model comes from a vendor, the deploying company must still manage the data it inputs, configure system purposes, restrict access scope, handle user rights requests, and verify that the vendor's data retention, access control, and security measures satisfy the company's own obligations.
On June 3, 2026, South Korea's Ministry of Science and ICT confirmed that the Korea Internet & Security Agency (KISA), through participation in Anthropic's Project Glasswing, has obtained access to Claude Mythos Preview and accompanying tools such as Claude Security. Anthropic simultaneously announced the expansion of Project Glasswing to more than 150 organizations across over 15 countries; alongside KISA, Korean companies including SK Telecom, Samsung Electronics, and SK hynix are participating. The collaboration shows South Korea folding frontier AI models into national cybersecurity capability-building for the discovery, validation, and remediation of software vulnerabilities.
a. AI cybersecurity upgraded from conventional tooling to a frontier capability question
Project Glasswing is not an ordinary vulnerability scanner; it gives vetted institutions access to frontier models such as Claude Mythos Preview with advanced code comprehension and vulnerability discovery capabilities. Anthropic states that Claude Mythos Preview exceeds the large majority of human experts at finding and exploiting software vulnerabilities; Korean media report that early participants have used the model to uncover more than ten thousand high-severity or critical vulnerabilities within weeks.
These capability claims and vulnerability counts come from Anthropic's announcements and participants' accounts; independent third-party evaluation is so far lacking, and early results from a single program are not yet grounds for declaring the whole industry to have entered a frontier-model-driven era. The safer formulation: if this discovery rate replicates across more institutions and codebases, AI security tooling will extend beyond automated scanning and alerting to finding complex vulnerabilities, generating patches, assisting penetration testing, and refactoring legacy code.
b. South Korea's participation: national cyber capability begins to draw on international AI model collaboration
Reuters reported that the Ministry of Science and ICT confirmed KISA's access to Mythos through Project Glasswing, and that South Korea will continue to strengthen national cybersecurity by using multiple frontier AI models and advancing homegrown AI security technology.
AI cyber capability is becoming part of national capability-building. South Korea is not relying solely on domestic tools; it is acquiring state-of-the-art AI cyber defense through cooperation with frontier model companies such as Anthropic while developing its own AI security industry — a dual-track pattern similar to Japan's combination of imported frontier capability and domestic security industry-building covered in our previous issue. The other side of this model bears watching: when national cyber defense depends on controlled access granted by a single foreign company, changes in access conditions, tightened export controls, or shifts in commercial strategy all become new dependency risks — structurally the same problem the EU is attempting to solve for cloud in CADA.
c. Project Glasswing uses controlled access rather than open release of high-capability cyber models
Anthropic's expansion announcement states that newly admitted institutions must meet security requirements before gaining access, and that broadly releasing Mythos-level cyber capability without sufficiently strong and precise anti-abuse measures would pose serious challenges.
The governance question for high-capability cyber AI is not only how powerful the model is, but who may access it, under what conditions, for which defensive tasks, and with what abuse prevention. For companies, access control, usage auditing, result confidentiality, and vulnerability disclosure processes will become key governance requirements when using AI cybersecurity models.
d. As AI vulnerability discovery scales, the bottleneck shifts to validation, remediation, and patch deployment
Anthropic notes in its expansion announcement that the cybersecurity bottleneck is shifting to vulnerability validation, disclosure, remediation, and patch deployment; Project Glasswing partners have used Mythos Preview to scan codebases at scale and surface high-severity vulnerabilities, and the next priority is helping the industry adapt to the new pace of discovery.
Once AI raises the rate of vulnerability discovery, the real challenge for companies shifts to operational response. If AI surfaces a large volume of vulnerabilities at once and a company lacks adequate triage, validation, remediation, testing, and release mechanisms, the result may be a new kind of security governance pressure rather than relief.
The implications of this week's developments differ by role and should not be generalized:
Cite as · AI Governance Weekly · 11 June 2026
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.