NextAI+ Praxis--:----UTC
AI Governance Weekly

EU AI Transparency Code Lands as U.S. Preemption Talks, New York Disclosure Law, G7 and Frontier Lab Reviews Advance

18 June 2026
Long read · 13 min
By NextAI+ Praxis
§ i

Weekly Brief

A concise view of the most notable global AI governance developments over the past week, grouped into four categories.

Legislative and Regulatory Developments

  • 06-10 · European Union | The European AI Office released the final Code of Practice on Transparency of AI-Generated Content, implementing Article 50 of the AI Act. Signature is voluntary, with the deadline for first-round signatories set for July 22. In parallel, the Digital Omnibus postponed the effective date of Article 50 obligations from August 2 to December 2, and delayed high-risk system obligations to 2027.
  • From 06-09 · United States | The White House and Senator Blackburn restarted negotiations on federal preemption of state AI laws, reportedly seeking to package a three-year preemption arrangement with legislation such as the Kids Online Safety Act. The matter remains under negotiation and does not yet create legal obligations.

Industry Rules Enforcement

(Obligations with penalties entering into force)

  • 06-09 · United States, New York State | The advertising disclosure law for “synthetic performers” under GBL §396-b formally entered into force. Violations are subject to a first penalty of USD 1,000 and USD 5,000 for each subsequent violation. The Governor’s Office described it as the first law of its kind in the United States.

Frontier Safety and Governance Practice

  • 06-15 · United States | Anthropic executives met with White House officials regarding controlled access conditions for Claude Mythos and its offensive-defensive cyber capabilities, but no agreement was reached. Background: CAISI had already included five frontier labs in pre-deployment evaluation as of May 5.

Multilateral Governance and Frontier Research

  • 06-15 to 06-17 · Multilateral | The G7 Evian Summit was held, while the OECD released the Digital Government Outlook 2026 on the same day. The India AI Impact Summit and the UN Global Dialogue on AI Governance continued to carry forward Global North-South inclusiveness issues.
  • Recent Research | A RAND study commissioned by the UK AISI on offensive cyber “human uplift” found that the uplift was statistically insignificant in many cases. METR has been conducting misalignment risk pilots within frontier developers. Stanford HAI’s 2026 AI Index recorded 362 AI incidents in 2025.
§ ii

Overview

This week’s developments across jurisdictions concentrate on two issues: first, equipping already enacted legal obligations with operational tools and effective dates; second, contesting who has the authority to set the rules.

The European Union released a Code of Practice for labeling AI-generated content, while at the same time using the Digital Omnibus to postpone the corresponding statutory obligations from August to December and delay high-risk system obligations to 2027. In the same week that the Code became available, the binding timeline for the related legal obligations was pushed back overall.

At the U.S. federal level, negotiations over preemption of state AI laws have resumed, this time using online child safety legislation as part of the legislative package. At the state level, the momentum is receding: Colorado’s law has already been delayed and substantially narrowed. While most developments remain at the stage of draft proposals, negotiations, or voluntary cooperation, New York’s synthetic performer disclosure law is the only obligation this week that has entered into force with penalties.

On frontier safety, the focus is shifting from “whether the model should be released” to “who may access offensive-defensive cyber capabilities, and under what conditions.” Anthropic and the White House did not reach agreement in their discussions. At the same time, an independently commissioned study offered a more restrained estimate of the real-world threat posed by such capabilities than vendor narratives would suggest.

At the multilateral level, the G7 Summit and OECD report continued the construction of coordination mechanisms, but representational divides in global governance remain unresolved.

I. Legislative and Regulatory Developments

(I) The European Union Releases the Final Code of Practice on Transparency of AI-Generated Content

On June 10, 2026, the European AI Office released the final Code of Practice on Transparency of AI-Generated Content. The Code was led by six independent experts and jointly drafted by more than 187 participating stakeholders. It is directed at providers of generative AI and requires them to mark audio, image, video, and text outputs in a machine-readable format to ensure they can be detected as artificially generated or manipulated. It also identifies two technical pathways: digitally signed metadata and imperceptible watermarking. For deployers, content that constitutes a deepfake — synthetic or manipulated audio-visual content sufficiently realistic to be mistaken as real — must be labeled. Signature of the Code is voluntary. Providers must submit by July 22 to be included in the first list of signatories.

The Code implements the transparency obligations under Article 50 of the EU Artificial Intelligence Act, or AI Act. It needs to be understood in light of the contemporaneous timeline changes: on May 7, 2026, the European Parliament and the Council of the European Union reached a provisional political agreement on the Digital Omnibus, postponing the application date of the new Article 50 transparency obligations from August 2 to December 2, delaying Annex III high-risk system obligations to December 2027, and adding a new prohibition on AI-generated non-consensual intimate content and child sexual abuse material, applicable from December 2. In other words, in the same week that the voluntary Code became available, the statutory obligations linked to it were pushed back overall.

The controversy surrounding this postponement is public. Around 60 civil society organizations, including European Digital Rights, or EDRi, jointly called on legislators to reject the relevant amendments, arguing that postponement and simplification would weaken enforcement, legal certainty, and fundamental rights protection. Some analysis further noted that exempted companies would no longer need to register in the EU database, raising enforcement costs for regulators and information costs for the public. The supporting argument for simplification centers on compliance burden and industrial competitiveness. Although the Code is voluntary, it is directly linked to the December 2 statutory obligations. The list of signatories will become a compliance signal in the market. For enterprises relying on generative AI to produce content, labeling and watermarking capabilities need to be in place before the end of the year, rather than waiting for the controversy to settle.

(II) The United States Restarts Negotiations on Federal Preemption of State AI Laws

Around June 9, 2026, the White House and congressional Republicans restarted efforts to pursue federal preemption of state AI laws. Senator Marsha Blackburn, Republican of Tennessee, reportedly led negotiations with the White House on the text of a proposal. Structurally, the plan appears to exchange a three-year preemption of state-level AI regulation for passage of the Kids Online Safety Act, or KOSA, the NO FAKES Act, and a federal age verification mandate. Senator Blackburn’s office emphasized that this is not a blanket preemption of all AI or child safety legislation, but issue-by-issue preemption by subject matter. The proposal remains under negotiation and has not yet created any legal obligations.

This is another development along the same policy line. In 2025, a ten-year moratorium on state AI laws was removed by the Senate in a 99-to-1 vote. On June 4, 2026, Representatives Obernolte and Trahan released a discussion draft of the Great American Artificial Intelligence Act, narrowing preemption to state laws that “specifically regulate model development,” adding a three-year sunset, and offering federal transparency, audit, and whistleblower obligations in exchange. The change this week lies in the political vehicle: online child safety legislation is being bundled into the package in an attempt to create passage momentum for preemption that lacks sufficient independent support.

Meanwhile, state-level momentum is receding. Colorado’s Artificial Intelligence Act, SB 24-205, has been delayed to January 1, 2027 and substantially narrowed by SB 189, signed on May 14. Combined with litigation involving xAI and the Department of Justice, its enforcement has been suspended.

The central controversy is whether this package can hold. The opposition includes bipartisan coalitions of state attorneys general, child safety and bereaved parent groups, and consumer advocacy organizations — the same forces that defeated the moratorium in 2025. They question the use of child safety legislation as a political bargaining chip for preemption and argue that it would weaken states’ ability to protect minors. If the bundling strategy can maintain its coalition, a two-layer structure of federal baseline standards plus state-level application regulation will move closer. If child safety provisions are seen by opponents as a hijacked bargaining chip, this round of negotiations risks repeating the 99-to-1 outcome.

II. Industry Rules Enforcement

(III) New York’s Synthetic Performer Advertising Disclosure Law Enters into Force

On June 9, 2026, New York State’s advertising disclosure law for “synthetic performers” formally entered into force. The law was signed by Governor Hochul on December 11, 2025, as S.8420-A / A.8887-B, amending Section 396-b of the General Business Law. It requires prominent disclosure when an advertisement includes a “synthetic performer” created by generative AI or algorithmic means and intended to lead viewers to believe that the performance is by a real person, without referring to any identifiable real person. Certain categories of advertisements, including film, television, and gaming, are exempted. Violations carry a first penalty of USD 1,000 and USD 5,000 for each subsequent violation. The Governor’s Office described the law as the first of its kind in the United States.

In this week’s broader landscape, the significance of this law lies not in the complexity of its provisions, but in its status. While EU labeling obligations have been postponed, the U.S. federal framework remains under negotiation, and frontier safety still relies on voluntary cooperation, this is the only obligation this week that has entered into force, carries penalties, and can be directly enforced. For the advertising and content industries, it provides an immediate compliance checkpoint: disclosure is not a rhetorical statement such as “this advertisement contains AI elements,” but a prominent label specifically targeting synthetic human likenesses. Synthetic performers are a relatively clear category within content authenticity governance. New York’s enforceable example may provide a template for similar legislation in other states.

III. Frontier Safety and Governance Practice

(IV) The Controlled Access Dispute over Frontier Cyber Capabilities

On June 15, 2026, Anthropic executives met with officials from the Trump Administration to discuss controlled access conditions for Claude Mythos, a frontier model with offensive-defensive software vulnerability discovery and exploitation capabilities. No agreement was reached, and both sides stated that they would continue discussions promptly.

This issue follows the thread in the previous report that South Korea obtained access to Mythos through Project Glasswing: the governance focus for frontier cyber capabilities is shifting from “whether the model should be publicly released” to “who may access it, under what conditions, and how misuse should be prevented.” In institutional terms, the Center for AI Standards and Innovation, or CAISI, under the Department of Commerce, had already included Google DeepMind, Microsoft, and xAI in pre-deployment evaluation as of May 5. Together with Anthropic and OpenAI, five frontier labs are participating in government pre-release review, with more than 40 model evaluations completed. The Frontier Model Forum also released Emerging Safety Practices for AI Agents on June 3.

A restrained comparison is necessary here. Vendor narratives emphasize that Mythos has surpassed most human experts in vulnerability discovery and that early participating institutions discovered tens of thousands of high-risk vulnerabilities within weeks. By contrast, the offensive cyber “human uplift” study commissioned by the UK AISI and conducted by RAND, released on May 28, offered a more conservative estimate. The study found that current state-of-the-art AI tools can help lower-skilled actors get started more quickly, but for completing end-to-end complex attack chains, the uplift is statistically insignificant in many cases.

The two are not measuring the same thing: the former concerns expert-level vulnerability discovery capability, while the latter concerns the real-world threshold for low-skilled actors to execute a complete attack. Therefore, they do not directly contradict each other. Considered together, however, they indicate that governance judgments should not rely solely on capability claims from a single source. The real value of controlled access depends on how capabilities translate into risk under real-world conditions.

If controlled access becomes the mainstream governance model for frontier cyber capabilities, access conditions, usage auditing, and anti-abuse measures will become more important than the question of “whether to release.” At the same time, when a country’s cyber defense capability depends on controlled authorization from a single company, the authorization conditions themselves become a new dependency risk.

IV. Multilateral Governance and Frontier Research

(V) The G7 Evian Summit and Multilateral Coordination

From June 15 to 17, 2026, the G7 Summit was held in Evian, France. In addition to G7 members, Kenya, India, Brazil, Egypt, and South Korea were invited to attend. The Organisation for Economic Co-operation and Development, or OECD, produced two documents during the same period: the discussion paper The Benefits of Openness in AI, prepared for the G7 on May 29, and the Digital Government Outlook 2026, released on June 15.

The broader context is that at the India AI Impact Summit 2026, Brazilian President Lula called for inclusive global governance, but according to TechPolicy.Press, Brazil’s governance proposals were marginalized at the summit. The UN Global Dialogue on AI Governance is planned to be held annually starting from the 2026 AI for Good Global Summit in Geneva, with topics covering capacity gaps in developing countries, interoperability among national governance frameworks, and socioeconomic impacts.

The signal at the multilateral level this week is that coordination mechanisms are being built, but representation and North-South divides have not been resolved. For enterprises, this is more distant background context. For governance research, it is a window into whether global rules can move from fragmentation toward interoperability. While major economies are advancing their domestic frameworks, if the multilateral layer fails to make progress on representation, “interoperability” is more likely to remain a statement of principle than a substantive alignment mechanism.

(VI) Recent Research Worth Monitoring

The following studies were mostly not first released this week, but they are directly relevant to this week’s developments and are worth bringing into view:

The RAND study on offensive cyber human uplift commissioned by the UK AISI, released on May 28, as discussed above, provides a restrained estimate of the real-world threshold for lower-skilled actors to use AI to carry out complete attacks. It is an important empirical reference for governance of frontier cyber capabilities.

Since February 2026, METR has been conducting misalignment risk pilots within frontier developers, with participants including Anthropic, Google, Meta, and OpenAI. The mechanism targets institutions rather than individual models, is repeated periodically, and is not tied to public release. It represents a continuous internal risk assessment approach.

The responsible AI chapter of Stanford HAI’s 2026 AI Index recorded 362 AI incidents in the AI Incident Database in 2025, continuing to rise from 233 incidents in 2024. It also noted that improving one dimension of responsibility, such as safety, may undermine another, such as accuracy. This finding is structurally similar to the trade-offs behind New York’s disclosure obligation and the EU’s labeling obligations this week: transparency, safety, and usability often cannot all be optimized at the same time.

§ iii

What This Week Means for Different Roles

The implications of this week’s developments vary by enterprise and institutional role:

  • Content and advertising industries: New York’s disclosure law has entered into force with penalties. Advertisements containing synthetic human likenesses need to implement prominent disclosure immediately. The EU labeling Code is voluntary, but the corresponding obligations take effect on December 2. Labeling and watermarking capabilities should be in place before the end of the year, and companies should assess whether signing the Code would send a useful compliance signal.
  • Model developers: CAISI pre-deployment evaluation now covers five frontier labs, and government evaluation before release is becoming a regular element for frontier models. For models with offensive-defensive cyber capabilities, access authorization, usage auditing, and anti-abuse measures will be governance priorities. Companies should prepare by reference to the controlled access paradigm, rather than assuming public release as the default.
  • Enterprises operating across multiple states or subject to multi-state regulation: U.S. federal preemption does not change the current situation in the short term. State-by-state tracking of use-case regulation remains necessary. Colorado’s delay shows that state-level timelines themselves remain variable, so compliance planning should retain flexibility.
  • Critical infrastructure and security teams: The RAND study suggests that organizations should not allow a single capability claim to dictate their pace. Nevertheless, the issue of “discovery speed exceeding remediation speed” brought by AI-assisted vulnerability discovery will still arrive. Enterprises can begin strengthening vulnerability classification, validation, and patch operations before regulatory requirements emerge.
Back to AI Governance Weekly

Cite as · AI Governance Weekly · 18 June 2026

§ Recent signalsBack to Governance Weekly
16 Jul 2026FTC AI certification, EU cyber and data transparency moves, and a UK AI security review.09 Jul 2026UK MHRA AI response checks, BoE agentic-risk warning, an FTC accuracy probe, and the UN’s first AI report.02 Jul 2026China’s AI+Consumption push, Hong Kong anti-financial-crime guidance, US incident reporting, and EU gatekeeper moves.25 Jun 2026US model export controls as NO FAKES advances, UK DUAA rules bite, and the EU launches its AI Act forum.11 Jun 2026AI governance turns national: US frontier-model security, EU cloud sovereignty, Singapore’s GenAI data rules.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.