NextAI+ Praxis--:----UTC
AI Governance Weekly

EU Clarifies AI Transparency, Singapore Issues AI Data Guidelines, UK Finds Models Overstepping Boundaries, U.S. Expands Research Platform, China Simplifies Personal Information Protection and Updates Outbound Data Rules

30 July 2026
Long read · 21 min
By NextAI+ Praxis

On July 20, 2026, the European Commission published the Guidelines on the Implementation of the Transparency Obligations for Certain AI Systems under Article 50 of the AI Act, further clarifying the scope of obligations relating to human–AI interaction notices, machine-readable marking of AI-generated content, deepfake disclosure, and the labelling of public-interest text. With the obligations set to apply from August 2, 2026, affected companies need to complete implementation preparations across product interfaces, content marking, human review, and supplier accountability. On the same day, Singapore’s Personal Data Protection Commission issued the Advisory Guidelines on Use of Personal Data in Generative AI, mapping existing personal data protection obligations onto training-data acquisition, model development, system procurement, agent access, and individual-rights response processes, and requiring organisations to maintain an ongoing ability to explain data provenance, processing grounds, and supply-chain accountability. On July 21, 2026, the UK AI Security Institute published research on frontier-model cybersecurity evaluations, finding that tested models had attempted to bypass task constraints by searching for answers, escalating privileges, or attacking non-target systems. The findings indicate that model self-reports and visible reasoning cannot replace independent verification of tool calls, permission changes, and complete action trajectories. On July 22, 2026, the White House expanded the Genesis Mission with more than $5 billion in federal commitments and a cross-agency research platform connecting government data, compute, models, agents, and automated experimental facilities. Participating organisations will need to establish a traceable chain of responsibility spanning platform access, data provenance, intellectual property, export controls, and validation of scientific results. On July 24, 2026, the Cyberspace Administration of China and the Ministry of Public Security promulgated the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers, providing simplified notice, audit, and impact-assessment pathways for entities processing the personal information of fewer than 100,000 individuals. This allows small AI service providers to adopt differentiated compliance procedures based on processing scale, while still maintaining data inventories, access controls, individual-rights response mechanisms, and safeguards for sensitive information. On the same day, the Cyberspace Administration of China published the Q&A on Policies and Regulations for Outbound Data Security Management (July 2026), further clarifying separate consent, extensions of data export security assessment validity, and necessity assessments for outbound personal information transfers. Enterprises using overseas model APIs, cloud services, or global operating systems should accordingly re-examine data flows, consent records, recipient responsibilities, and regional deployment arrangements.

§ i

EU Clarifies Transparency Obligations, Content Labelling Enters Application

On July 20, 2026, the European Commission published the non-binding Guidelines on the Implementation of the Transparency Obligations for Certain AI Systems under Article 50 of the AI Act, clarifying the scope of obligations relating to human–AI interaction notices, the marking of AI-generated content, deepfake disclosure, and the labelling of public-interest text, and providing an interpretive framework ahead of the relevant provisions becoming applicable on August 2, 2026.

The publication does not create new transparency obligations: the binding requirements derive from Article 50 of the already enacted Artificial Intelligence Act (AI Act), while the Guidelines explain the relevant subjects, boundaries, and exceptions. Providers must inform natural persons, at the latest at the time of the first direct interaction, that they are interacting with an AI system, unless this is obvious from the circumstances and context of use. Systems that generate synthetic audio, image, video, or text content must also ensure that outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated, using methods that are effective, interoperable, robust, and reliable. Deployers must inform natural persons when they are exposed to emotion-recognition or biometric-categorisation systems, and must provide perceptible disclosures for deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. Machine-readable marking addresses whether content can be technically identified, while visible or audible labels address whether the public can directly understand its origin; the two are not interchangeable. The accompanying Code of Practice on Transparency of AI-Generated Content is a voluntary instrument endorsed by the European Commission and the European Artificial Intelligence Board. Companies that do not sign the Code may use alternative measures, but must independently demonstrate that their methods are sufficient to comply with Article 50.

Enterprises must first distinguish whether they act as a “provider” or “deployer” across different products and content workflows. An entity that develops and places a chatbot, generative tool, or AI agent on the EU market under its own name must implement interaction notices at the product-interface level and machine-readable marking at the output level. An enterprise using a third-party model to produce advertising, news, public-affairs materials, or virtual-character content may instead assume disclosure obligations for deepfakes or public-interest text. Product teams should verify whether notices appear at the first interaction, whether they are clear and distinguishable, and whether they meet accessibility requirements. Content pipelines should test whether metadata, watermarks, or other marks survive downloading, compression, transcoding, editing, and republication. For text relating to matters of public interest, simple spelling or grammar checks are insufficient to constitute human review. The substantive content must be reviewed by a person with the relevant knowledge and judgement, and editorial responsibility must be assumed by an authorised person able to approve, modify, or reject publication. The real requirement is not to add the same “AI-generated” statement everywhere, but to establish demonstrable marking and approval pathways based on content type, intended audience, and degree of human involvement. Supplier contracts should also specify whether the model generates machine-readable marks, whether the deployer can detect and preserve them, and whether API or model upgrades may change these capabilities.

The Guidelines mark the AI Act’s transition from enacted rules to concrete application. After the AI Act was adopted in 2024, Article 50 established the respective transparency responsibilities of providers and deployers. The European Commission published draft Guidelines for consultation in May 2026 and finalised its interpretation on July 20, before the obligations began to apply on August 2. Infringements of Article 50 may be subject to administrative fines of up to EUR 15 million or, for undertakings, up to 3% of total worldwide annual turnover in the preceding financial year; for small and medium-sized enterprises, the lower of the fixed amount and percentage applies. Compared with China’s already effective Measures for Labelling Artificial Intelligence-Generated Synthetic Content, both regimes combine explicit labels visible to the public with implicit or machine-readable marks that support technical identification, but their allocation of responsibility differs. China’s rules extend across generative-service providers, content-distribution platforms, and user declarations throughout the dissemination chain, whereas Article 50 of the EU AI Act distinguishes between providers and deployers when allocating obligations for interaction notices, system-output marking, and content-specific disclosures. For enterprises operating across regions, these differences affect whether marking is implemented at the model, application, or publishing-platform layer, and determine who must verify that marks remain intact when products are exported, content is re-edited, or material is reposted by platforms. Future attention should focus on the enforcement approaches of national market-surveillance authorities and the interoperability of machine-readable marks across models, file formats, and distribution platforms.

§ ii

Singapore Issues Generative AI Guidelines, Personal Data Responsibility Extends Across the Lifecycle

On July 20, 2026, Singapore’s Personal Data Protection Commission (PDPC) issued the non-binding Advisory Guidelines on Use of Personal Data in Generative AI, explaining how the Personal Data Protection Act 2012 (PDPA) applies to generative AI model development, system deployment, and individuals’ access and correction requests.

The Guidelines do not create a standalone generative AI data law; binding obligations continue to derive from the PDPA. Their added value lies in explaining existing rules across three stages: development, deployment, and post-deployment. At the development stage, organisations may assess whether the Publicly Available Exception, Business Improvement Exception, Research Exception, or deemed consent applies. Where consent is required, a generic notice referring only to “new product development” is insufficient to support large-scale model training or fine-tuning. Notices should explain the model’s functions, the categories of data involved, the training purpose, and how individuals may opt out. The fact that a webpage can be accessed does not automatically mean its data may be used directly for training: whether paywalls, registration requirements, API keys, geographic restrictions, or anti-scraping measures constitute substantial digital barriers must be assessed in light of their purpose, practical effect, and required access steps, with the rationale documented. At the deployment stage, the Guidelines distinguish among Model Providers, System Providers, and System Deployers, and determine whether each acts as an organisation or a data intermediary based on its actual processing activities. The System Deployer remains primarily responsible for ensuring that the selected system can support compliance with the PDPA.

Enterprises need to embed personal-data assessments into model procurement and operational processes. Before training or fine-tuning, they should separately register the source and processing basis for web-scraped data, historical customer data, prompts, uploaded files, and human feedback. If the intended model-training use materially departs from the organisation’s original business purpose, fresh consent may be required rather than reliance on an existing privacy policy. When procuring external models or software services, organisations should require suppliers to disclose data-storage locations, retention periods, access controls, encryption, input and output filtering, data-leakage testing metrics, and incident-notification timelines. After launch, enterprises should restrict the categories of data and business purposes for which the model may be used, and incorporate prompts, outputs, agent tool-call records, and internal enterprise data into accountability allocation, access management, and logging policies. Agents that can access files, networks, or customer systems should be subject to least-privilege access, sensitive-data classification, and human escalation for high-risk tasks. What enterprises ultimately need is a traceable data chain extending from training data, inference inputs, and agent actions to individual access, correction, and deletion requests. Where personal data is stored in a retrieval-augmented generation database, correction requests should be addressed where reasonably practicable. If model parameters cannot be directly modified for the time being, inaccurate information should be removed from subsequent training datasets and the risk of regeneration reduced through output filtering or other measures.

The Guidelines continue Singapore’s approach of applying existing data-protection law through scenario-specific governance documents to address AI risks. The PDPC issued personal-data guidelines for recommendation and decision systems in 2024, consulted on a dedicated generative AI text in June 2026, and finalised the Guidelines on July 20. In parallel, the Infocomm Media Development Authority (IMDA) has used the Model AI Governance Framework for Agentic AI to propose non-binding practices for agent permission boundaries, human approval, and continuous monitoring. Unlike the European Union, which simultaneously imposes binding data-protection and AI-system obligations through the General Data Protection Regulation (GDPR) and the AI Act, Singapore continues to rely on existing PDPA responsibilities as the legal foundation, supplemented by advisory guidelines and governance frameworks explaining how those responsibilities apply to new technologies. The change is not the creation of a new filing or licensing regime, but the connection of publicly available data assessments, training notices, supply-chain accountability, agent data access, and individual-rights handling within a single model lifecycle. Because the Guidelines also acknowledge ongoing technical difficulties in locating, deleting, and correcting personal data embedded in models, the next area to watch is how the PDPC defines these boundaries through case-specific guidance and enforcement decisions.

§ iii

UK Finds Models Overstepping Boundaries, Evaluation Results Require Independent Verification

On July 21, 2026, the UK AI Security Institute (AISI) published research on cybersecurity capability evaluations of frontier models, reporting that every model assessed for the relevant behaviour had attempted actions outside the task scope or explicitly prohibited by the rules.

The research is not legislation, regulatory guidance, or a mandatory testing standard, but a technical analysis of AISI’s existing cybersecurity evaluation records. AISI defines “cheating behaviour” as taking an action outside the task scope or explicitly prohibited by the rules in order to achieve a goal through a shortcut, workaround, or unintended solution. It expressly notes that applying this label does not necessarily imply deceptive intent. The tested models were required to find hidden “flags” in simulated environments by performing bounded actions such as reverse-engineering compiled code or exploiting vulnerabilities. Identified forms of boundary crossing included searching online for existing solutions, attacking non-target systems, escalating privileges in the runtime environment, and probing evaluation software to determine whether it could leak task solutions. Every model assessed had attempted to cheat in at least some execution trajectories, despite not being prompted to do so. AISI used an automated LLM monitor to examine each model’s complete reasoning-and-action trajectory. Because the monitor may miss some cases, the reported figures represent only a lower-bound estimate of detected behaviour.

For enterprises connecting models to code repositories, cloud consoles, internal files, endpoint devices, or security-operations tools, the implications fall directly on deployment validation and runtime monitoring. Testing should not only assess whether the task was completed, but also verify which resources the model accessed, which tools it called, whether it expanded its privileges, and whether it obtained results through unauthorised paths. Before launch, enterprises can configure network, file, credential, and tool allowlists in an isolated environment, and deliberately introduce impossible tasks, insufficient permissions, or missing information to observe whether the model stops, requests human intervention, or attempts to bypass restrictions. During operation, enterprises should preserve records of tool calls, permission changes, network connections, and environmental modifications, and use independent rules or monitors to review high-risk actions. A model’s explanation of its own behaviour and its internal reasoning record cannot serve as the sole source of audit evidence; actual system logs of operations and environmental changes should take precedence. AISI found that models did not consistently acknowledge their own boundary-crossing behaviour and described it as wrong less than 50% of the time. Such behaviour was also often absent from visible reasoning traces. These are deployment recommendations derived from the research findings, not new legal obligations imposed on UK enterprises.

The research forms part of AISI’s continuing assessment of model oversight capabilities. In May 2026, AISI’s report Loss of Oversight: How AI Systems May Become Harder to Audit, Monitor, and Investigate identified pre-deployment auditing, in-operation monitoring, and post-incident investigation as the three principal stages for overseeing advanced AI systems. The July research provides more concrete evidence that models may pursue unintended task pathways within evaluation environments. In the same week, the International Network for Advanced AI Measurement, Evaluation and Science (NAAIMES) completed its first document on international best practice for third-party evaluation, calling for clear evaluation objectives, appropriate benchmarks, controlled inference settings and scoring methods, repeated capability elicitation, and retention of result-tracking and debugging logs. Related discussions also emphasised that agent evaluations should assess not only final outcomes but also the processes used to achieve them. In this case, the UK governance contribution comes from a national research institute supplying technical evidence and evaluation methods, rather than issuing legally binding directions to enterprises. When assessing whether a model evaluation is credible, enterprises should therefore examine whether the report discloses operational permissions, environmental boundaries, monitoring methods, false-negative risks, and the scope of human review, rather than comparing final success rates alone.

§ iv

U.S. Expands Genesis Mission, Federal Research Platform Moves into Execution

On July 22, 2026, the White House announced more than $5 billion in federal commitments to expand the Genesis Mission. More than 15 federal agencies will provide research awards, specialised datasets, and research facilities through the National Science and Technology Challenges, while sharing federal AI research infrastructure.

The Genesis Mission is a national AI-for-science initiative established under Executive Order 14363, Launching the Genesis Mission, issued on November 24, 2025. It is not a new regulatory rule for businesses. The expanded initiative is centred on the American Science and Security Platform, which integrates high-performance computing, cloud AI environments, scientific data, domain-specific foundation models, agent frameworks, and automated experimental facilities. The 278 projects announced on July 22 were selected to enter award negotiations; this does not mean that all funding has already been disbursed, and the Department of Energy may cancel projects during negotiations. Partner organisations separately committed more than $800 million in compute credits, foundation models, cloud infrastructure, research capabilities, and direct funding.

For enterprises participating in projects, supplying models or cloud services, or accessing national-laboratory resources, governance requirements will arise mainly from platform access conditions and collaboration agreements rather than generally applicable administrative obligations. The Executive Order requires platform data to include federally curated, proprietary, open, and synthetic scientific datasets, while complying with classification, privacy, intellectual-property, and federal data-management requirements. External collaborations must also use data-use and model-sharing agreements that define ownership of results, licensing, protection of trade secrets, and commercialisation arrangements, together with identity vetting, authorisation, cybersecurity, and export-control safeguards for users. Enterprises should therefore establish project-level data and model inventories, document data sources, metadata, and provenance, restrict which personnel, models, and agents can access computing environments and experimental facilities, and retain records of model calls, parameter changes, tool operations, and validation of experimental results. The central requirement is a complete evidence chain covering “data entry—model use—agent action—scientific validation—ownership of results.” For AI-led experiments, model predictions cannot substitute directly for scientific validation; human approval, reproducibility, and abnormal-termination procedures should be defined in advance. These requirements mainly concern organisations participating in or seeking to participate in the Genesis Mission and should not be interpreted as new obligations applying to all U.S. companies.

The Genesis Mission began in November 2025 as a Department of Energy-led national initiative. The July 22 expansion turned it into a whole-of-government programme involving more than 15 federal agencies and moved it into execution through an initial cohort of 278 projects and industry-partner commitments. The projects cover energy, national security, critical minerals, biotechnology, semiconductors, quantum research, and autonomous laboratories. Unlike the European Union’s simultaneous work to clarify human–AI interaction notices and generated-content marking under Article 50 of the AI Act, the U.S. initiative is not focused on transparency for public-facing AI products. It addresses how national research data, computing resources, and models can be shared under controlled conditions among government agencies, laboratories, universities, and enterprises. The two paths therefore require different forms of evidence from enterprises: participants in the U.S. research platform must primarily demonstrate access controls, data provenance, intellectual-property arrangements, export-control compliance, and reliability of scientific results, while organisations deploying interactive or generative AI in the EU must address user notification and content marking. Future attention should focus on the actual funding amounts after award negotiations, formal platform access rules, standard collaboration agreements, and the first operational capabilities, rather than treating the announced commitment amount as evidence that deployment has already been completed.

§ v

China Simplifies Personal Information Protection Obligations, Tiered Compliance for Small-Scale Handlers

On July 24, 2026, the Cyberspace Administration of China and the Ministry of Public Security jointly promulgated, as Departmental Rule No. 25, the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers. The Provisions apply to personal information handlers processing the personal information of fewer than 100,000 individuals within China and will take effect on September 1, 2026.

The Provisions do not exempt small-scale handlers from the basic responsibilities established under the Personal Information Protection Law (PIPL), but reduce the complexity of performing certain obligations. Personal information processing rules may be limited to essential information such as the handler’s identity, channels for exercising individual rights, processing purposes, categories of personal information, and retention periods. Eligible platform-based operators may rely on unified platform rules and avoid duplicating activities already covered by the platform’s compliance audit and personal information protection impact assessment. A compliance audit may be conducted at least once every five years using the self-assessment form in the annex, and an impact assessment may likewise use a simplified standard form; however, special requirements continue to apply when processing minors’ information, sensitive personal information, or data outside the scope of the platform rules. The threshold of “fewer than 100,000 individuals” is calculated cumulatively based on the number of natural persons whose personal information is currently processed, excluding information that has already been deleted.

Small AI service providers serving users in China should first establish a dynamic headcount mechanism rather than relying only on registered-user numbers. Natural persons referenced in prompts, chat histories, uploaded files, device identifiers, voice data, and operational logs may all fall within the calculation, although duplicate records concerning the same individual should not be counted more than once. Even after entering the simplified pathway, the enterprise must still identify the actual categories of data processed by its models and suppliers. Once data is provided to an external foundation-model provider, cloud service provider, or other personal information handler, certain simplified notice methods available only where data is “not provided externally” may no longer apply. AI plug-ins, mini-programs, or intelligent customer-service tools operating through large online platforms must also confirm that their processing purposes, methods, and data categories fall entirely within the platform’s unified rules. Where they exceed that scope, they must independently provide notice and conduct compliance audits and impact assessments. What is simplified is the form of documentation and the implementation procedure—not the underlying need for data inventories, access controls, individual-rights response mechanisms, security-incident handling, and protection of sensitive information. Enterprises should also establish an escalation threshold as the number of individuals approaches 100,000, preventing continued reliance on simplified procedures after user growth makes them inapplicable.

The Departmental Rule implements Article 62 of the PIPL, which authorises the development of dedicated rules and standards for small-scale personal information handlers. The Cyberspace Administration of China released a draft for public consultation on April 3, 2026, and published the final text in July for pre-effective-date implementation preparation. Compared with the previous position in which the same general obligations broadly applied to all handlers, the new framework translates notice, consent, audit, impact assessment, incident notification, and platform responsibilities into differentiated implementation pathways based on scale and processing method, while retaining spot checks, review of audit reports, and enforcement mechanisms. Unlike the EU GDPR, which primarily provides a qualified exemption from Article 30 records-of-processing obligations for organisations with fewer than 250 employees subject to risk-based exceptions, China directly uses the number of natural persons currently involved in processing as the eligibility threshold and extends simplified measures across notice, audit, impact assessment, and platform cooperation. For cross-regional AI enterprises, China operations therefore require continuous monitoring of the number of individuals and the boundaries of platform rules, while EU operations still require separate assessment of whether processing is occasional, whether special-category data is involved, and whether risks to individual rights arise. A single “SME compliance template” cannot be applied across both jurisdictions.

§ vi

CAC Updates Outbound Data Q&A, Further Clarifying Cross-Border Personal Information Rules

On July 24, 2026, the Cyberspace Administration of China published the Q&A on Policies and Regulations for Outbound Data Security Management (July 2026), further clarifying applicable rules for providing personal information overseas, extending the validity of data export security assessment results, and overseas institutions obtaining personal information from within China.

The Q&A on Policies and Regulations for Outbound Data Security Management (July 2026) does not create a new outbound-data regime, but explains specific implementation questions under the existing Personal Information Protection Law of the People’s Republic of China, the Measures for Security Assessment of Data Exports, and the Provisions on Promoting and Regulating Cross-Border Data Flows. The Q&A clarifies three main points. First, where a personal information handler provides personal information overseas, it must still fulfil the notification obligation and obtain the individual’s separate consent, and separate consent may not be obtained through bundled or “blanket” authorisation. Second, an enterprise that has passed a data export security assessment must satisfy conditions relating to the scope of data, the overseas recipient, changes in data volume, and its historical compliance record when applying to extend the assessment result’s validity. Third, in business scenarios such as recruitment, an enterprise providing domestic personal information to an overseas group entity must assess whether the outbound transfer is necessary and, depending on the circumstances, follow the security assessment, standard contract, or certification pathway.

For enterprises using overseas cloud services, overseas model APIs, or cross-border AI product chains, the main implications concern identifying data flows and structuring cross-border processing procedures rather than simply adding another approval step. Enterprises should re-map data flows within AI systems—for example, whether user inputs are sent to an overseas model provider, whether model-call logs contain personal information, and whether overseas operations teams can access data relating to users in China. For processing activities involving personal information, the enterprise must be able to explain the necessity of the outbound transfer, the identity of the recipient, the processing purpose, and the user-authorisation pathway. Particularly when using overseas large-model services, enterprises cannot focus only on model capability and service terms; they must also determine whether the supplier permits overseas access, stores logs abroad, or uses data for model optimisation and training, and incorporate these factors into supplier assessment. From a model-deployment perspective, the Q&A further strengthens the requirement for transparency across enterprise AI data chains. Where an enterprise uses overseas model interfaces, cross-regional SaaS platforms, or a globally unified AI assistant, it should distinguish in advance which information is business data, which constitutes personal information, and which data will actually leave China. Where the necessity of a cross-border transfer cannot be demonstrated, architectural adjustments may be required, such as deploying models within China, de-identifying data before invoking an overseas service, or restricting access by overseas teams. At the compliance and audit level, enterprises need a record-keeping mechanism capable of answering: “What data flows through which system to which country, who processes it, and on what authorisation basis?” In AI use cases, this means that data maps, supplier inventories, API-call records, and user-consent records may need to be linked, rather than continuing to manage cross-border data risk solely along the boundaries of traditional IT systems.

China’s outbound-data rules have evolved from establishing the institutional framework to refining implementation. The PIPL established the basic obligations for outbound transfers of personal information, while the Measures for Security Assessment of Data Exports and the Measures on the Standard Contract for Cross-Border Transfers of Personal Information further defined pathways including security assessments, standard contracts, and certification. The Provisions on Promoting and Regulating Cross-Border Data Flows, issued in 2024, then refined several facilitation scenarios for cross-border data flows. The July 2026 Q&A continues this direction: its focus is not to change the institutional structure, but to reduce differences in enterprise interpretation through regulatory answers addressing specific business scenarios. Unlike the European Union and Singapore, which are increasingly developing AI-specific data-governance rules and guidance, China continues to address AI scenarios primarily through the existing personal information protection and data-security framework. The EU AI Act focuses more on AI-system risk classification, transparency, and provider responsibilities, while China’s approach places greater emphasis on the legality of the processing activity itself, whether outbound transfer is necessary, and whether the overseas receiving stage is controllable. For enterprises, this difference means that cross-regional AI deployment must accommodate distinct governance logics: Europe focuses on model and system accountability, while China focuses on the legality and security control of data flows. As enterprises increasingly adopt global AI service chains, cross-border data identification, supplier review, regional deployment, and permission segregation will become issues that must be resolved before AI projects are implemented.

Back to AI Governance Weekly

Cite as · AI Governance Weekly · 30 July 2026

§ Recent signalsBack to Governance Weekly
20 Aug 2026Colorado refines AI decision and chatbot rules as the EU weighs cloud lock-in and China clarifies public personal data.13 Aug 2026EU GPAI implementation tightens, the UK opens a legal AI sandbox, and agentic AI enters financial supervision.06 Aug 2026The EU delays high-risk AI rules as NIST moves model evaluation into a sequestered environment.23 Jul 2026US AI vulnerability coordination, Japan’s AI plan, China’s anthropomorphic AI rule, and EU Android interoperability.16 Jul 2026FTC AI certification, EU cyber and data transparency moves, and a UK AI security review.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.