NextAI+ Praxis--:----UTC
AI Governance Weekly

Asia-Pacific: China Issues Three Large-Scale Model Standards; EMEAP Flags Shared AI Dependencies in Finance; Australia Clarifies Automated Decision-Making Disclosures; Korea Opens UK Data Protection Review and Prepares Public AI Agents

5 October 2026
Long read · 13 min
By NextAI+ Praxis

On 28 September 2026, China’s State Administration for Market Regulation and Standardization Administration of China published three recommended national standards covering government, computer vision and multimodal large-scale models. The standards provide technical references for system selection and acceptance and will take effect in stages in 2027. On 30 September, the Executives’ Meeting of East Asia-Pacific Central Banks (EMEAP) published an AI report calling attention to systemic risks arising from common supplier dependencies and similar model decisions in finance. That day, the Office of the Australian Information Commissioner (OAIC) updated its privacy principles guidance, clarifying that human participation in a final decision does not necessarily remove the forthcoming automated decision-making disclosure obligation. On 1 October, Korea’s Personal Information Protection Commission (PIPC) began reviewing whether the UK provides an equivalent level of personal information protection; companies must continue to rely on existing grounds for overseas transfers pending a recognition decision. On 2 October, Korea’s National AI Strategy Committee discussed a draft AI legislative framework and coordinated data access, personal information protection and security validation ahead of the launch of public AI agent services.

§ i

China Issues Three Large-Scale Model Standards and Sets Implementation Dates

On 28 September 2026, the State Administration for Market Regulation and the Standardization Administration of China published three recommended national standards: Artificial intelligence—Technical requirements for large-scale model systems of government (GB/T 48324-2026), Artificial intelligence—Large-scale model—Part 4: Computer vision large-scale model (GB/T 45288.4-2026), and Artificial intelligence—Large-scale models—Part 5: Multimodal large-scale model (GB/T 45288.5-2026). They cover government large-scale model systems, computer vision models and multimodal models, respectively.

All three standards have been published but are not yet in effect. The computer vision and multimodal standards take effect on 1 January 2027, and the government large-scale model standard on 1 April 2027. The first two are parts of the GB/T 45288 Artificial intelligence—Large-scale model series; the government standard has a separate number and addresses system-level technical requirements. Under Article 2 of China’s Standardization Law, adoption of recommended standards is encouraged; their effective dates alone do not establish a uniform mandatory compliance deadline for all companies. As of 4 October 2026, this review has verified the official catalogue records but has not obtained the final full texts. Their exact scope, technical metrics and verification methods remain to be checked.

Companies selecting or delivering relevant systems can first review whether procurement documents, supplier commitments and acceptance plans refer to these standards. The Standardization Administration’s interpretation of the Standardization Law explains that a recommended standard binds the contracting parties when they adopt it as a delivery quality benchmark. Before incorporating a new standard into acceptance criteria, the parties should identify its version, applicable provisions and supporting evidence, and only then commit to conformity. For example, where a government materials review system uses both image recognition and visual question answering, teams can examine the full texts when available to determine which requirements address the model capabilities and which address the complete system; a test report for one model should not stand in for evidence covering the entire system. Projects due for delivery in 2027 can allocate responsibility and timing for standards review, gap remediation and retesting. Test records should link model versions, input samples and deployment configurations so that differences between the supplier’s test environment and actual use can be explained. These are procurement and deployment preparations, not specific obligations already confirmed in the three standards.

GB/T 45288.1-2025, Artificial intelligence—Large-scale model—Part 1: General requirements, and GB/T 45288.2-2025, Artificial intelligence—Large-scale model—Part 2: Evaluation indicators and methods, were published and took effect on 28 February 2025. The newly published Parts 4 and 5 add dedicated computer vision and multimodal components to that series. In the EU, Article 40 of the Artificial Intelligence Act (AI Act) links harmonised standards to statutory requirements: high-risk AI systems or general-purpose AI models that comply with relevant harmonised standards whose references have been published in the Official Journal of the EU may benefit from a presumption of conformity to the extent covered by those standards. Cross-border suppliers therefore need to examine both the technical scope and legal effect of standards in each jurisdiction; evidence of conformity to a Chinese national standard is not automatically proof of EU compliance. The next steps are to examine the final texts of the three standards against existing general requirements and evaluation methods, and determine how individual procurement projects adopt them.

§ ii

EMEAP AI Report Flags Supplier and Model Dependencies

On 30 September 2026, the Executives’ Meeting of East Asia-Pacific Central Banks (EMEAP) published its EMEAP Note on AI: Implications for Economy, Financial Stability, and Central Banking Operations. The report analyses financial risks from AI adoption and highlights the potential systemic effects of shared supplier dependencies and the use of similar models.

This is a research report and does not create uniform supplier admission, model approval or deployment obligations. It distinguishes two channels of risk transmission: service concentration and convergent decisions. Reliance by financial institutions on a small number of AI and cloud providers can create points of failure affecting multiple institutions, while high switching costs make replacement difficult. Similar models and data used in trading can lead institutions to make similar decisions and amplify market volatility. The report also identifies uncertainty over cross-border data sovereignty and the allocation of responsibility, and calls for examining shared dependencies and interactions among institutions at the financial-system level, alongside risk management at individual firms. These are risk assessments and governance recommendations; they do not demonstrate that any particular model or supplier will necessarily cause financial instability.

When a bank procures customer data analysis from two suppliers, it can check whether both actually use the same upstream model, run in the same cloud region or share an identity service. Separate contracting parties do not guarantee isolation of failures. Contingency plans should test both service availability and the reliability of business outcomes: simulate an upstream outage, assess whether the alternative can handle actual workloads and whether it changes the data processing location, and check if critical tasks can move to a human workflow. Then run the same anomalous cases through primary and backup models to see whether both miss material information. For investment analysis or trading support, institutions can also simulate multiple strategies responding similarly to one market signal and assess portfolio-level risk. Contracts can provide for disclosure of upstream dependencies and changes, outage cooperation and migration support. Operational records can link actual model versions, call regions, switch times and human decisions. These are implementation suggestions based on the report’s risk analysis, not technical procedures imposed by it.

On 14 November 2024, the Financial Stability Board (FSB) published The Financial Stability Implications of Artificial Intelligence, identifying third-party dependencies, supplier concentration and market correlations as key vulnerabilities. The EMEAP report continues this research, drawing on member discussions and a 2025 survey of central bank applications. By comparison, the EU’s Digital Operational Resilience Act (DORA), applicable from 17 January 2025, imposes ICT third-party risk management, contractual and resilience testing requirements on financial entities within its scope. A regional research report and binding legislation have different effects; EMEAP’s report does not imply that Asia-Pacific members have adopted a uniform regime. Cross-border financial institutions can reuse dependency inventories and outage exercise materials while checking local requirements separately. Future developments to watch are whether member regulators turn the report’s issues into examination priorities or supervisory guidance.

§ iii

Australia Clarifies Automated Decision-Making Disclosures; Human Review Is No Automatic Exemption

On 30 September 2026, the Office of the Australian Information Commissioner (OAIC) updated Chapter 1 of the Australian Privacy Principles Guidelines and published explanatory materials and a decision flowchart. The materials help covered entities prepare for automated decision-making disclosures in privacy policies, effective 10 December 2026.

These materials explain the implementation of an existing legislative amendment; the statutory obligation has not yet commenced. Three conditions must all be met: an entity subject to the Australian Privacy Principles (APPs) has arranged for a computer program to make a decision or do something substantially and directly related to making one; the decision could reasonably be expected to significantly affect an individual’s rights or interests; and the program uses that individual’s personal information in the process. Where the conditions apply, the privacy policy must describe the kinds of personal information used, the kinds of decisions made solely by a program, and the kinds of decisions informed by a program’s substantially and directly related activity. Human participation in the final decision does not automatically remove the disclosure obligation. The OAIC considers how much staff rely on the output, whether they can and are realistically likely to override it, and how deeply the system is embedded in the workflow. Ordinary rules-based software and generative AI can both be in scope. Use of a third-party tool does not automatically transfer responsibility from the entity arranging its use in the decision.

If a bank uses AI to organise loan materials and generate a risk score before a credit officer approves the application, it should trace which personal information enters the program, how its output affects the credit decision and whether staff can change the conclusion independently. Disclosures should correspond to the system’s actual business configuration: automatic rejection, scores for staff reference and assistance in setting credit limits are distinct uses that a generic statement such as “we may use AI” does not adequately explain. Buyers can ask external suppliers to specify categories of input information, uses of outputs and feature changes, and allocate responsibility for updates. If a system evolves from summarising materials to ranking applications or recommending credit limits, the organisation should reassess coverage and its privacy policy. Teams can retain the necessary assessment rationale, workflow versions and disclosure versions to check that public statements remain accurate. These are implementation suggestions; the transparency provisions do not create a general right to request human review or prescribe a uniform log retention period.

The obligation stems from the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024; the new guidance translates its legal criteria into an implementation assessment. The amendment also makes clear that decisions taken after commencement can be covered even if the software arrangement or related data processing predates it, so existing systems should be reviewed. In the EU, Article 22 of the General Data Protection Regulation (GDPR) sets a general restriction, exceptions and safeguards for decisions based solely on automated processing that produce legal or similarly significant effects. Australia’s new provision focuses on privacy policy disclosure and expressly covers some assisted decisions; the two regimes serve different purposes and should be assessed separately. Nominal human involvement does not itself settle the EU analysis either. Cross-border teams can maintain a common inventory of decision workflows while separately checking disclosure, restrictions on decision making and individual remedies. Future OAIC examples should clarify what counts as “substantially and directly related.”

§ iv

Korea Opens UK Equivalence Review; Overseas Transfer Rules Remain Unchanged

On 1 October 2026, Korea’s Personal Information Protection Commission (PIPC) announced the start of a review of whether the UK provides an equivalent level of personal information protection. It will assess the UK’s legal framework, supervision and enforcement, and remedies for individuals against a standard of substantially equivalent protection to Korea’s.

This is the start of a recognition process, not a final decision permitting simplified transfers; the announcement sets no completion date. Under Article 28-8(1)(5) of Korea’s Personal Information Protection Act (PIPA), recognition of a country or international organisation can provide a legal basis for overseas transfers without satisfying the conditions of another transfer route. Other duties relating to the collection, use, provision and security of personal information continue to apply. Companies cannot cancel existing transfer arrangements simply because the review has begun. Even if recognition follows, it is not blanket authorisation for model training, broader uses of data or onward transfers to other countries.

A Korean company planning to send support tickets containing customers’ personal information to a UK cloud model should first confirm its existing transfer basis and then trace inference, logs, backups and operational access. Choosing a UK supplier or UK endpoint does not establish that all processing occurs in the UK: the supplier may use a diagnostic team elsewhere or call an upstream model in another country. Procurement checks can request recipients, processing locations, subcontractors and training uses, with notice and reassessment for region changes, remote access and new subcontractors. Teams can use simulated tickets to check actual behaviour after disabling training use, limiting logs and fixing a processing region. The PIPC’s earlier interpretation explains that overseas transfers encompass provision to foreign third parties, entrusted processing, storage and access from abroad, so data-flow reviews should cover remote access. These are deployment preparations; the announcement imposes no uniform technical requirements for routing, logs or contracts.

Korea first recognised the EU and European Economic Area as providing equivalent protection in September 2025. Its UK review continues an approach that assesses protections in the recipient jurisdiction to support cross-border transfers. The direction of transfer between Korea and the UK matters: tthe UK’s Data Protection (Adequacy) (Republic of Korea) Regulations 2022 took effect on 19 December 2022 and facilitates personal data transfers from the UK to Korea within its scope. Korea’s current review concerns the opposite direction; UK recognition does not imply that Korea has already recognised the UK. Cross-border AI teams should record the direction, recipient and legal basis of each data flow. The next developments to verify are any final Korean decision, its scope, effective date and conditions.

§ v

Korea Discusses AI Legislative Framework and Prepares Public Agent Deployment

On 2 October 2026, Korea’s National AI Strategy Committee convened the fifth Chief AI Officer (CAIO) consultative meeting to discuss a draft Korean AI legislative framework and coordinate data access, personal information protection and security validation for the launch of the “AI for All” (모두의 AI) service.

This was cross-government policy coordination; no new law or uniform technical specification for agents was adopted. The draft framework proposed centring the AI Basic Act, addressing legislative gaps in defence and security, making the regulatory environment more predictable for companies and responding promptly to adverse impacts. For the planned formal launch of “AI for All” in December 2026, the Ministry of Science and ICT (MSIT) asked relevant agencies to connect already open public application programming interfaces (APIs), open further interfaces and data, develop standards for agents’ handling and use of personal information, and conduct security validation. The meeting identified launch preparations; it did not authorise use of unopened data or establish that personal information handling standards have already been issued.

Companies delivering public service agents can separate permissions for policy lookup, access to a person’s case information and submission of an application. A benefits assistant, for example, may read public guidance, but accessing an applicant’s income records or filing on their behalf calls for separate checks of the processing basis, identity and operational permissions. Acceptance testing should check both “can the interface be connected?” and “is this specific operation authorised?” The service interface can verify identity, accessible fields and task scope for each call, while tests simulate access to another person’s records, malicious content inducing unauthorised actions, and repeated submissions after a timeout. Procurement contracts can allocate among the data-owning agency, integrator and model provider responsibility for authorisation, security testing, incident response and retesting after version changes. Necessary records can link user confirmation, interface calls and outcomes, with limits on the scope and duration of personal information retention. These are deployment suggestions drawn from the meeting agenda; the announcement did not prescribe a uniform acceptance procedure or log retention period.

On 29 July 2026, MSIT and the National IT Industry Promotion Agency (NIPA) published an amended call for applications for the “AI for All” project to help the public use domestic AI services. The latest meeting further coordinated data and security preparations before launch. The UK Government Digital Service (GDS) published its AI Playbook for the UK Government on 10 February 2025, providing guidance for the selection, procurement and deployment of AI in the public sector. Cross-border suppliers can reuse interface permission and security test materials while separately confirming each project’s authorisation to use data and its acceptance criteria. In Korea, developments to check include the interfaces actually opened, personal information handling standards, security validation arrangements and whether the legislative framework becomes concrete legislation.

← Back to AI Governance Weekly

Cite as · AI Governance Weekly · 5 October 2026

§ Recent signalsBack to Governance Weekly→
06 Oct 2026The US signs a voluntary frontier AI accord, California restricts AI-based dismissals, and the Bank of England calls for continuous testing.29 Sep 2026The EU adopts data centre ratings, the UK sizes up agentic cyber defence, and the FTC examines platform ad optimisation.28 Sep 2026China publishes on-device AI filings, Korea expands data innovation zones and debates agent privacy, and Japan studies consumer remedies.22 Sep 2026UK lawmakers call for dedicated AI legislation, the EU moves to limit AI companions for children, and California enacts synthetic-performer disclosure.21 Sep 2026China issues AI Safety Governance Framework 3.0 and four security guidelines, consults on secure agent development, and Hong Kong pilots procurement declarations.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.