On 21 September 2026, Korea's Personal Information Protection Commission provisionally designated the National Tax Service and the Korea Disease Control and Prevention Agency as operators of Personal Information Innovation Zones, expanding opportunities for controlled research use of tax and health data. Formal opening remains subject to on-site verification. On 23 September 2026, China's Cyberspace Administration published filing information for three on-device generative AI services for smartphones, enabling companies to verify service providers, while actual cloud calls and data flows still require separate confirmation. On the same day, Korea's Personal Information Protection Commission discussed agent permissions, approval boundaries and the handling of personal information in logs and memory, identifying issues for future guidance without introducing new agent-specific obligations. On 24 September 2026, Japan's Consumer Commission released research materials on AI's influence over consumer decisions, comparing regulatory and redress approaches across jurisdictions and highlighting the need for companies to preserve transaction records and resolve complaints. Also on 24 September, Singapore's Institute of Banking and Finance launched a collaborative AI workforce initiative with 23 financial institutions, combining training and job redesign to clarify employees' judgement and oversight responsibilities as AI is adopted.
On 23 September 2026, the Cyberspace Administration of China (CAC) issued its announcement of filing information for three smartphone on-device generative AI services, publishing the filing details of additional services.
This is a publication of filing results under an existing regime. It covers YOYO Claw, Xiaomi miclaw and StepFun Terminal AI, and does not separately establish uniform technical controls for on-device services. On-device inference means running model computations locally on a device such as a smartphone. The announcement does not disclose the three services' complete data flows, cloud calls or permission settings, so it cannot establish that all their functions operate offline. Article 2 of the Interim Measures for the Management of Generative Artificial Intelligence Services defines scope by whether generative AI services are offered to the public in China. The Measures do not apply where enterprises or other entities research, develop or use the relevant technologies without providing services to the domestic public.
When enabling contract summarisation or customer email processing on work smartphones, companies should verify filing information and test actual data flows as separate steps. During procurement, they should check the service name, provider and delivered features, and ask suppliers to explain which tasks are processed on the device, which may be routed to the cloud, and whether diagnostic logs, backups or model improvement use business data. Acceptance tests can use simulated contracts to compare behaviour when the device is online, offline and configured with cloud features disabled. If data is transmitted externally, the recipient, processing location and purpose should then be verified. Where email, contacts or document repositories are connected, teams should limit the data that can be read and check that access stops when permissions are revoked. Contracts can require notification of changes to features and data flows, with relevant settings retested after system upgrades. Records should prioritise versions, authorisations and necessary call information instead of copying complete contracts or conversations by default. These are deployment recommendations informed by the filing announcement and Article 11 of the Interim Measures on protecting input information and usage records; the announcement itself adds no operational obligations.
The Interim Measures took effect on 15 August 2023. On 15 July 2026, the CAC published filing information for seven smartphone on-device services, including “Apple Intelligence”. The latest publication continues that established filing practice. A related question beyond checking filing status is how end-user devices implement data protection. Article 25 of the EU's applicable General Data Protection Regulation (GDPR) requires controllers to embed safeguards such as data minimisation into the design and, by default, process only personal data necessary for specific purposes, considering the amount collected, extent of processing, retention period and accessibility. An on-device architecture can reduce external data transfers, but the protection achieved depends on its actual configuration. Teams operating across markets can share data-flow and permission tests while separately assessing the scope of China's service filing regime and local personal data processing obligations. Subsequent monitoring should compare updates to official filing information with suppliers' feature changes.
On 21 September 2026, Korea's Personal Information Protection Commission (PIPC) issued a provisional designation notice, naming the National Tax Service (NTS) and the Korea Disease Control and Prevention Agency (KDCA) as additional operators of Personal Information Innovation Zones to support research using tax and fiscal data, and data covering the full cycle of infectious diseases and the national health survey, respectively.
The zones support more flexible use of pseudonymised data within a more secure data processing environment. Pseudonymisation means that an individual cannot be identified from the data without additional information, although the risk of re-identification still requires control. According to the PIPC's explanation published the same day, controls within the zones include multi-factor authentication and real-time screen recording. The arrangements allow calibrated relaxation of the degree of pseudonymisation, use of different data linkage identifiers, long-term retention for continuing research and reuse by third parties. The two newly designated institutions must still pass final on-site inspections. Formal operations are planned for early 2027, and the provisional designation does not mean the relevant data is already available to companies.
Teams planning to develop disease risk prediction models can first confirm the research purpose, available fields, data linkage method and compute conditions with the operator before deciding whether to conduct training or validation in that environment. Permission to conduct a project and permission to export its results should be confirmed separately. Teams should list the code, models and software components they intend to import, along with the statistical outputs, model parameters and test reports they wish to take out, and assess whether any could contain identifiable information. They should also agree with the operator on authorised personnel, the period for repeat research, version records and cleanup responsibilities at the end of a project. The process used by existing innovation zones includes review of research plans, checks on imported software and review of exported results, offering a preparation reference; requirements for each newly designated institution still need separate confirmation. The notice does not specify conditions for exporting model weights, remote access from overseas or cross-border transfers. Procurement and R&D contracts should therefore identify these as matters requiring confirmation before promising to integrate research outputs into products hosted on foreign cloud infrastructure. These are deployment preparations, not uniform procedures introduced by the provisional designation.
Korea introduced the innovation-zone mechanism in 2024, and the PIPC opened this round of applications for operators on 20 July 2026. The addition of tax and health data institutions to the construction and verification process makes the final inspection results, available data catalogues and project admission criteria key points to monitor. On 6 September 2022, the UK's Department of Health and Social Care (DHSC) published its Secure data environment policy guidelines for research using relevant health and social care data in England, providing for approved users to analyse data in a controlled environment and for outputs to be checked before release. Both approaches combine data use with controls over access, analysis and exported results. Korea's initiative expands cross-sector innovation zones, whereas the UK guidelines address a specific health data environment; institutional eligibility and approval outcomes are not interchangeable. Cross-regional research can reuse analytical code and risk tests, but data access and output export should be applied for and verified in each jurisdiction.
On 23 September 2026, Korea's Personal Information Protection Commission (PIPC) held the second plenary meeting of the second-term Public-Private Policy Council on AI Privacy, discussing agent autonomy, responsibilities of participating parties and the handling of personal information in logs and memory.
This was a policy discussion ahead of guidance development and did not introduce agent-specific compliance obligations. The meeting presented findings from interviews with 15 domestic and international AI developers and users. Interviewees identified prompt injection and excessive agent permissions as major risks and called for clearer boundaries in three areas: autonomous execution versus human approval, responsibilities across participants, and retention of logs and memory. Prompt injection involves malicious inputs inducing a system to take unintended actions. Participants also suggested that future guidance should be principles-based, risk-based and technology-neutral. The announcement set no uniform retention period or specific deletion procedure.
When deploying a travel agent that can read employee itineraries, contact suppliers and submit bookings, companies can assign separate permissions for reading information, sending it externally and confirming orders, and limit authorisations by employee, necessary fields and task duration. Pre-launch tests can place an unauthorised instruction such as “send all employees' itineraries” in a supplier email to verify that the system blocks it and escalates the matter to a human. For data management, teams should distinguish logs used for traceability from memory that informs later decisions. Logs can link necessary authorisations, tool calls and approval outcomes; long-term memory should have its own purpose, access scope and deletion conditions rather than absorbing every conversation by default. After an employee corrects or deletes a preference, teams can test whether summaries, caches or indexes still surface the old information in later tasks, while handling audit records that must be retained by law separately. Procurement contracts should also assign responsibility for adjusting permissions, handling deletion requests, supplying investigation materials and disabling tools. These are implementation recommendations based on the meeting topics, not procedures prescribed by the meeting.
The council's second term began in February 2026; this meeting brought the interview findings into preparations for future rules. The PIPC plans to publish guidance on the handling of personal information by agents before the end of the year. Subsequent monitoring should assess how it allocates responsibilities, establishes retention bases and addresses deletion requests. The UK's National Cyber Security Centre (NCSC), in its 21 September 2026 security blog on agentic cyber defence, recommends assessing automation risks by operational capabilities, scope of impact, system criticality, degree of deployment validation and recoverability. It provides non-binding advice. Korea's discussion focuses on the boundaries of personal information processing, while the UK advice addresses the impact of automated actions on business operations. Teams operating across regions can share permission and anomaly tests, but should separately assess the conditions for processing personal information and the permissible scope of autonomous execution.
On 24 September 2026, Japan's Consumer Commission under the Cabinet Office published materials from the tenth meeting of its Expert Committee on the Use of AI Technology and Consumer Issues, held on 18 September. These include a commissioned report on overseas legal frameworks and an expert report comparing regulatory approaches, accountability and routes to redress when AI influences consumer decisions.
The publication consists of research materials and creates no new mandatory obligations. The study takes 9 September 2026 as its factual reference date, and its comparative assessments reflect the researchers' views. It distinguishes between businesses using AI to make decisions about consumers, such as pricing and credit assessments, and consumers delegating their own decisions to AI, such as choosing and executing transactions through an agent. Its analysis of remedies emphasises that regulatory prohibitions and consumer claims must be assessed separately. A rule prohibiting certain conduct does not necessarily give consumers a direct right to claim damages under that provision; the applicable civil cause of action, evidentiary requirements and means of obtaining evidence must also be identified. The materials further compare the different legal effects of standards, codes of conduct and risk management frameworks; adopting a governance framework should not be equated with immunity from liability.
Companies operating AI shopping guides or purchasing agents can review recommendations, price displays, user authorisations and actual purchases as a continuous transaction flow. For example, if a system promises that an item “can be returned at any time” and buys it on the consumer's behalf, but the consumer later discovers it is non-returnable, the complaints team should be able to determine whether the promise came from product data, model generation or business configuration, and exactly which actions the user authorised. Complaint acceptance tests should establish whether the transaction can be reconstructed and errors effectively corrected. Teams should link and retain necessary product and price snapshots, key conversations, model and business rule versions, user confirmations and order results, rather than saving only the final answer. Human handlers should be able to correct explanations and process cancellation, refund or compensation claims under applicable rules. Procurement contracts can assign evidence delivery and investigation responsibilities among model providers, platforms and merchants, preventing complaints from being repeatedly passed between parties. Records should be limited by purpose, access and retention period. These deployment recommendations draw on the materials; their publication does not impose a uniform log retention or refund procedure.
The expert committee first met in February 2026 and has continued to study consumer issues arising from AI use. The new materials provide cross-jurisdictional comparisons for its consideration of subsequent measures. As the Cabinet Office summarises in its secretariat report, the EU combines comprehensive risk-based legislation with consumer protection rules; US federal authorities primarily enforce existing prohibitions on unfair or deceptive practices alongside state law; and China applies sector-specific rules and mechanisms including filing, security assessments and regulatory interviews. These are the study's comparisons of regimes as of its reference date, not a choice of regulatory path by Japan. Companies operating across regions can share transaction traceability and complaint investigation capabilities, but should assess disclosure, personalised choice and claims conditions separately. The next question is how the Commission turns the research into formal recommendations, including whether it clarifies responsibility for agent-mediated transactions and consumers' access to evidence.
On 24 September 2026, the Institute of Banking and Finance (IBF) in Singapore launched the IBF AI Workforce Co-Lab with 23 financial institutions and announced the Job Redesign Playbook for Financial Services. The initiatives support AI training, changes to job tasks and employees' career transitions in financial institutions.
This is an industry workforce development partnership, not a new uniform statutory training or job redesign requirement. The 23 participating institutions have committed to train their entire Singapore workforce through IBF-accredited courses by 2028, covering more than 80,000 people, over half of whom have already received training. The programme offers pathways for leaders, wealth managers and operations staff, emphasising the alignment of AI skills with specific job responsibilities. Leaders study use-case selection, governance and workforce transformation; wealth managers combine AI use with professional advisory skills; and operations staff strengthen exception handling, risk oversight and output validation. IBF is also deepening cooperation with unions and seven industry associations to expand training and career support.
When a bank assigns document collation and preliminary checks in customer due diligence to AI, it can redesign operations staff's tasks, permissions and performance measures at the same time. As employees move from data entry to resolving identity discrepancies and investigating unusual relationships, training should use simulated cases to test whether they can spot model omissions, check source evidence and escalate complex matters. Job redesign should align judgement skills, authority to act and workload arrangements. It should be clear who can reject AI outputs, pause automated processing or request further investigation, so that employees tasked with review can access the evidence and change outcomes. Performance measures can reflect anomaly detection, correction quality and customer impact, with adequate time for complex cases. When employees change roles, system permissions should be updated and access no longer needed for their former roles revoked. When procuring AI systems, institutions can ask suppliers for explanations of output limitations, training scenarios and version changes, with targeted refresher training after feature updates. These are implementation recommendations informed by the initiative; completing a course or receiving a certificate alone does not demonstrate effective oversight of business processes.
In June 2026, IBF and the National Trades Union Congress (NTUC) announced a partnership to support AI upskilling for up to 100,000 financial-sector workers over three years. The latest initiative adds commitments by participating institutions to train their entire workforce and introduces role-specific pathways; the two coverage figures should not be added together. By contrast, Article 4 of the EU's Artificial Intelligence Act (AI Act) imposes an AI literacy obligation. The European Commission's updated questions and answers clarify that providers and deployers must take measures to support AI literacy among relevant personnel, without guaranteeing that each person reaches a specified level or requiring a uniform certificate. Singapore's initiative promotes training and career transitions through industry cooperation, while the EU has a legal duty applying to entities within scope. Financial institutions operating across regions can share role-based training materials while separately checking local requirements. Subsequent monitoring should focus on the partnership's published job examples, skills assessment methods and outcomes for employees changing roles.
Cite as · AI Governance Weekly · 28 September 2026
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.