NextAI+ Praxis--:----UTC
AI Governance Weekly

FTC AI Certification, EU Cyber/Data Transparency Moves, UK AI Security Review

16 July 2026
Long read · 16 min
By NextAI+ Praxis

On July 7, 2026, the Office of Administrative Law Judges of the U.S. Federal Trade Commission reaffirmed generative AI drafting certification requirements in a specific administrative review proceeding, bringing AI use disclosure, verification against authoritative legal sources, and ultimate professional responsibility into the formal materials submission process. On the same day, the European Commission released the Action Plan on Cybersecurity and Artificial Intelligence, proposing collaborative arrangements around external evaluations of frontier models, controlled security testing, and AI-accelerated vulnerability remediation, making model permissions, cyberattack capabilities, and vulnerability response concrete objects of enterprise security review. On July 8, 2026, the European Commission launched a targeted consultation on data sovereignty, examining the risks faced by EU organizations in third-country data access, cross-border data flows, and reliance on non-EU infrastructure, bringing data location, remote access, key control, supplier migration, and regional alternatives into deployment assessment. On July 9, 2026, the European Commission and the European Artificial Intelligence Board confirmed the adequacy of the Code of Practice on Transparency of AI-Generated Content, providing a unified voluntary compliance pathway for machine-readable marking, deepfake disclosure, and public-interest text notification under Article 50 of the Artificial Intelligence Act. On July 10, 2026, the UK Department for Science, Innovation and Technology released a market study on AI and software security services, finding that existing services more frequently cover design, testing, and vulnerability management, while operational monitoring, customer communication, and decommissioning remain relatively underdeveloped. This means enterprises procuring external security services need to reassess lifecycle coverage and internal responsibility boundaries.

§ i

U.S. FTC Reaffirms AI Drafting Certification, Creating Traceability for Verification of Legal Materials

On July 7, 2026, the Office of Administrative Law Judges (OALJ) of the U.S. Federal Trade Commission issued an order revising the written submission schedule in the Vance Childers administrative review proceeding, reaffirming that parties submitting case materials must certify the use of generative AI and the corresponding human verification.

This document is a procedural order in a specific administrative case. It is not a universal rule applicable to all FTC administrative proceedings, attorneys, or enterprises. The order requires the certificate of service for each filing to further certify one of two circumstances: either no part of the filing was drafted by generative AI such as ChatGPT, Perplexity, Microsoft Copilot, Harvey.AI, or Google Gemini; or any text drafted by generative AI has been checked for accuracy by an attorney or paralegal using printed legal reporters or online legal databases. Filings that do not comply with this mandatory certification requirement may be struck from the record. In addition, the order separately requires legal arguments to be supported by applicable legal authority, and factual statements to correspond to specific proposed findings of fact and record page citations. This places AI use certification, legal citation requirements, factual evidence, and filing format controls within the same procedural control framework.

This arrangement does not affect enterprise model products themselves. Rather, it affects the process by which legal, litigation, and regulatory affairs teams use generative AI to prepare formal materials. Enterprises should first distinguish ordinary internal drafts from formal documents that may be submitted to courts, arbitral institutions, or regulators. The latter should not depend only on employees’ own judgment that a model answer “looks reasonable.” A more robust process is to preserve the scope of AI-assisted drafting, the original output, and the human-edited version, and to require reviewers to check case names, statutes, precedents, citations, and factual records item by item. What needs to be recorded is not merely “which model was used,” but also who verified the content, which authoritative database was used, which citations were modified, and who assumes professional responsibility for the final document. The FTC order does not currently require enterprises to build a unified AI logging system, but for teams that frequently handle regulatory responses, administrative appeals, investigation materials, and legal opinions, such records can support later certification and accountability tracing.

This is not the first time a similar requirement has appeared in U.S. administrative proceedings. A prior order in the same case dated June 16, 2026 already contained the same certification clause. In another case handled by the same administrative law judge, involving Dr. Donald McCrosky, an order issued in March 2026 adopted a similar mechanism; a party later expressly certified that certain materials had been drafted with the assistance of generative AI, and stated that a licensed attorney had checked the accuracy of the materials using legal materials and online databases and had assumed professional responsibility. Therefore, the more cautious conclusion is not that “the FTC has established an agency-wide AI document certification regime,” but that a specific FTC administrative law judge is repeatedly applying generative AI use disclosure and human legal verification as conditions for formal submissions in cases before that judge. This approach is similar to the earlier position taken by the UK Medicines and Healthcare products Regulatory Agency on AI-generated inspection responses: neither prohibits assisted drafting, but both return final responsibility to professionally qualified individuals and require output to be verifiable against authoritative sources. The difference is that the UK event concerned life sciences regulatory responses, while the U.S. event is currently limited to individual administrative proceedings.

§ ii

EU Releases AI Cybersecurity Plan, Shaping Cooperation on Frontier Model Evaluation

On July 7, 2026, the European Commission released the Action Plan on Cybersecurity and Artificial Intelligence (COM(2026) 577 final), setting out joint action arrangements around frontier AI model evaluation, secure access, cyber defense applications, vulnerability remediation, and European autonomous capabilities.

This action plan does not establish a separate set of AI cybersecurity regulations. Instead, it connects existing legal frameworks with a set of new evaluation, testing, and collaboration projects. The document divides its actions into three directions: strengthening pre-release evaluation and security testing capabilities for frontier models; helping critical sectors and small and medium-sized enterprises respond to AI-driven attacks and accelerate vulnerability remediation; and expanding the European supply of domestic AI cybersecurity tools, compute, and talent. The most concrete institutional change is that the EU plans to establish an external evaluation system for AI models that includes cybersecurity evaluation capabilities, as well as controlled environments for testing advanced AI cyber capabilities.

The European Commission plans to support the establishment of EU AI model evaluation capabilities in 2027 and to propose qualification criteria for third-party evaluation bodies for general-purpose AI models. The European Union Agency for Cybersecurity (ENISA) and the Commission’s Joint Research Centre will also develop a security testing platform in the fourth quarter of 2026, enabling advanced models to be tested in cyber ranges for capabilities such as vulnerability discovery, threat detection, incident triage, and response, without directly exposing real critical infrastructure. The plan also proposes developing a European blueprint for structured access to advanced AI cyber capabilities. This blueprint will take into account applicant eligibility, security standards, misuse risks, and information-sharing mechanisms, while the document expressly states that the blueprint itself will not impose new mandatory obligations on model providers.

For enterprises, the impact falls more directly on model access, security testing, and vulnerability response processes. Enterprises using general-purpose AI models for code generation, vulnerability scanning, security operations, or autonomous tool use need to first identify whether the model has the capability to discover, exploit, or chain vulnerabilities, and then decide which code repositories, network environments, credentials, and external tools it may access. Pre-launch model testing also cannot assess only response quality and business accuracy. For cybersecurity-related scenarios, enterprises also need to test the possibility of prompt injection, data and model poisoning, adversarial attacks, unauthorized tool invocation, malicious code generation, and the circumvention of security measures. The action plan does not require ordinary enterprises to immediately undergo new EU evaluations, but the third-party evaluation and testing infrastructure it proposes may provide a new technical pathway for enterprises to select models, verify suppliers’ risk mitigation measures, and demonstrate compliance with the Artificial Intelligence Act. Vulnerability handling processes also need to be reassessed at “AI speed.” The action plan notes that AI is shortening the time between vulnerability discovery and exploitation at scale by attackers. Enterprises therefore need to clarify which systems and open-source dependencies are critical assets, which vulnerabilities can be automated by AI, and whether high-risk patches can bypass ordinary release cycles and enter emergency handling.

This plan continues the EU’s broader trajectory of gradually connecting AI model risks with traditional cybersecurity regimes. The Artificial Intelligence Act already requires providers of general-purpose AI models with systemic risk to identify and mitigate model misuse risks, including cyber-domain risks; from August 2, 2026, the European Commission will exercise supervisory and enforcement powers over general-purpose AI models under that law. The Cyber Resilience Act places security by design, vulnerability management, and continuous updates into the lifecycle of software and hardware products, while the NIS2 Directive and the Digital Operational Resilience Act cover operational security in critical sectors and financial institutions, respectively. The change introduced by this action plan is not that these obligations are restated, but that it supplements currently insufficient EU internal capabilities in model evaluation bodies, security testing environments, structured access channels, and AI-assisted vulnerability remediation.

The same issue is being addressed through different pathways in the United States and the United Kingdom. Recent U.S. frontier model governance has focused more on incident reporting, national security testing, and developer responsibility. The UK, through its AI Safety Institute, has advanced frontier model capability evaluation and international cooperation on evaluation methodologies. The EU, by contrast, connects evaluation capability building simultaneously to Artificial Intelligence Act enforcement, critical infrastructure cyber resilience, and technological sovereignty, and proposes using AI Factories, future AI Gigafactories, and EU-based compute resources to support the training, testing, and deployment of cybersecurity models. The action plan also explicitly proposes cooperation with the UK AI Safety Institute within an international evaluation network and promotes common approaches among G7 countries on model evaluation and open-source software security. This makes the differences facing cross-regional enterprises more concrete: the same model may be subject to different review priorities in different regions, including developer incident reporting, external security evaluation, critical-sector cybersecurity, and dependence on regional compute capacity.

§ iii

EU Launches Data Sovereignty Consultation, Scrutinizing Third-Country Data Dependencies

On July 8, 2026, the European Commission launched the Targeted consultation on safeguarding the EU’s data sovereignty, addressing participants across data value chains in different sectors and examining the dependencies, barriers, and risks faced by EU organizations in international data flows and third-country data access.

This consultation is not about simple data localization, nor does it require all data to remain within the EU. Rather, it assesses whether EU organizations can retain the necessary level of control when using data across borders. The survey scope listed on the official page includes three areas: barriers encountered by EU organizations when accessing or using third-country data; restrictions faced when transferring third-country data to the EU; and risks arising from access to sensitive data by third-country governments, suppliers, or other actors. The consultation is addressed to data value chain participants across different industries, not only cloud service providers or large technology companies. The focus of the procedure is to identify structural dependencies in international data chains, not to immediately impose new data residency obligations. The European Commission also states that unjustified data localization requirements, discriminatory rules, and data leakage to third countries may weaken the EU’s data sovereignty; however, the EU continues to support cross-border data exchange with trusted partners, provided such flows are fair, secure, and aligned with EU interests and values.

This issue is directly connected to enterprise AI data pipelines and supplier dependencies. Enterprises using non-EU cloud platforms, foundation model APIs, data labeling services, or remote operations teams need to map where training data, prompts, retrieval data, model outputs, and runtime logs are stored, which non-EU actors can access them, whether data and workloads can be repatriated to the EU, and whether they can be fully exported and deleted after service termination. Additional points requiring review include who controls encryption keys, where subcontractors are located, whether non-EU administrators can access systems remotely, and whether supplier switching would create lock-in of data or model configurations. The consultation itself does not yet require enterprises to make these adjustments immediately, but these materials will become the basis for assessing third-country dependency and regional deployment risk.

This consultation follows the third policy track of the EU’s Data Union Strategy. The strategy divides action into three areas: expanding data available for AI, simplifying data rules, and safeguarding the EU’s data sovereignty. It also proposes developing guidance to assess whether EU data is treated fairly abroad and creating a policy toolbox to respond to unjustified localization, data exclusion, and data leakage. Compared with earlier policy direction-setting, the July 8 targeted consultation begins collecting concrete dependencies and barriers from enterprises and data chain participants, thereby establishing a factual basis for later guidance or tool design. At this stage, it is still not possible to determine what legal or policy measures the EU will ultimately adopt.

The consultation is also directly linked to the EU’s broader technological sovereignty agenda. The EU’s technological sovereignty framework places data, artificial intelligence, cloud, semiconductors, and open-source technologies within the same set of dependency relationships, emphasizing the reduction of excessive reliance on non-EU suppliers through control over key technologies, data, and infrastructure. This differs from the focus of traditional data protection regulation. Personal data rules primarily ask whether processing is lawful and whether individual rights are protected. Data sovereignty discussions further ask who controls the infrastructure, whether foreign law can reach the data, whether enterprises can migrate workloads, and whether supplier dependency affects the autonomous decision-making of EU organizations. For cross-regional AI deployment, the compliance assessment may therefore involve data protection, cloud infrastructure, model provenance, and regional alternatives at the same time, rather than a single cross-border transfer approval.

§ iv

EU Confirms Content Transparency Code, Creating a Compliance Pathway for Generated-Content Marking

On July 9, 2026, the European Commission and the European Artificial Intelligence Board (AI Board) completed their adequacy assessment of the Code of Practice on Transparency of AI-Generated Content, recognizing it as an EU-wide voluntary tool to help providers and deployers of generative AI comply with the content marking and disclosure obligations under Article 50 of the Artificial Intelligence Act.

The code itself is not a mandatory regulation, and adherence to the code is voluntary. The legally binding requirements are the transparency obligations under Article 50 of the Artificial Intelligence Act. The code is divided into two parts, one for providers and one for deployers. Providers need to equip AI-generated or manipulated text, audio, images, and video with machine-readable marking and, to the extent technically feasible, ensure that marking solutions are effective, interoperable, robust, and reliable. Deployers need to disclose deepfake content and certain AI-generated or manipulated text published to the public on matters of public interest. The significance of this confirmation is that an industry co-drafted code has been turned into an EU-recognized pathway for demonstrating compliance, rather than a new set of standalone obligations. Signatories may use the measures in the code to demonstrate compliance, but signing the code does not in itself constitute conclusive evidence of compliance.

Generative AI companies first need to determine whether, in a particular product, they act as the provider of a model or system, or as a deployer using the system to publish content, because the required actions differ. Providers’ work will sit within the generation pipeline and technical architecture: at which stage the marking should be embedded, whether it can cover different content formats, whether the content remains detectable after editing, compression, screenshots, or redistribution, and how the relevant technical testing is retained. Deployers need to handle user-facing disclosure: which content qualifies as a deepfake, where labels should appear, whether the disclosure is sufficiently clear, and whether public-interest text has undergone human review and is subject to editorial responsibility by a natural or legal person. Enterprises should not reduce transparency requirements to a single statement on a page saying “generated by AI.” Instead, machine-readable marking, user interface labels, content publication records, and responsible entities need to correspond to one another. If an enterprise does not adhere to the code, it may still comply through other methods, but it will need to demonstrate to market surveillance authorities in different Member States that its alternative measures are sufficiently effective.

This confirmation marks a step in the implementation preparation for Article 50 from legislative text toward operational tools. The AI Office launched a multi-stakeholder drafting process in 2025, and the final code was released on June 10, 2026. After the Commission and the AI Board completed the adequacy assessment, signatory companies obtained a common implementation framework that can be used across EU Member States. The Article 50 obligations will begin to apply on August 2, 2026, and the European Commission will also issue accompanying guidelines to explain the covered actors, content scope, exemptions, and specific implementation methods. Unlike the United States, which focuses more on using consumer protection law to examine whether AI product representations are deceptive, the EU has chosen to embed transparency into content generation and dissemination processes. It requires both technical detectability and visible disclosure to recipients. For enterprises operating across regions, the more robust approach is to establish a unified foundation for content provenance and marking, and then configure different front-end disclosure methods according to EU rules on deepfakes and public-interest text, as well as consumer disclosure rules in other jurisdictions.

§ v

UK Assesses AI Security Services, Testing the Market’s Ability to Implement Standards

On July 10, 2026, the UK Department for Science, Innovation and Technology (DSIT) released Mapping of the AI and Software Security Services Market, assessing whether security tools and services in the UK market can support enterprises in implementing the AI Security Code of Practice and the global standard for AI security, EN 304 223.

This study is not about whether AI risk principles are complete. It is about whether enterprises can obtain the practical services needed to implement those principles from the market. The survey shows that 92% of AI security service providers are aware of the UK AI Security Code of Practice, 86% are aware of EN 304 223, and roughly half already reference those documents when designing or selling security services. Existing supply covers secure design, development testing, penetration testing, and vulnerability management relatively well, but services in the later stages of the AI lifecycle—such as monitoring, customer communication, retirement, and disposal—remain relatively limited, with some still at the experimental stage. The report also finds that pricing for AI security services is highly dispersed: some services are offered free of charge, while a significant share charge annual fees above £50,000, indicating that the market has not yet formed unified service boundaries or pricing models.

When procuring AI security services, enterprises should first break “security” down into concrete lifecycle tasks, rather than treating a one-off penetration test as the completion of an assessment. During model development and launch, they can examine threat modeling, training data and model weight protection, prompt injection testing, interface permissions, and supply chain vulnerabilities. During operation, they also need continuous monitoring of anomalous calls, model and software updates, incident triage, and patch status. When decommissioning or changing suppliers, they must address the deletion or migration of models, keys, logs, and sensitive data. A supplier’s ability to provide a particular tool does not mean it can cover the enterprise’s full chain of responsibility from design to decommissioning. Procurement teams should translate the code and EN 304 223 into a service requirements checklist and confirm, item by item, delivery scope, testing basis, evidence format, retesting arrangements, and responsibility boundaries. For areas where market supply is insufficient, enterprises still need to retain internal owners and control processes, and cannot fully outsource ultimate security responsibility.

This report continues the UK policy trajectory from setting security principles toward verifying implementation conditions. DSIT and the UK National Cyber Security Centre (NCSC) previously developed the AI Security Code of Practice, whose requirements were later incorporated into EN 304 223 issued by the European Telecommunications Standards Institute (ETSI). This study further examines whether enterprises can find the tools, talent, and services needed to support those requirements. The UK AI security research gap analysis released on the same day also identifies third-party model source verification, the integrity of training data and model weights, the connection between AI model attack surfaces and traditional IT infrastructure, and the tools called by agents and agent-to-agent communications as areas where research remains insufficient. Compared with the EU’s approach this week of building model evaluation and cybersecurity testing infrastructure, the UK study focuses more on determining whether the market can provide implementation services for enterprises. Together, the two developments raise a practical question: policies and standards can specify security principles, but enterprises still need to prove whether they have executable controls covering models, infrastructure, supply chains, and the decommissioning stage.

Back to AI Governance Weekly

Cite as · AI Governance Weekly · 16 July 2026

§ Recent signalsBack to Governance Weekly
09 Jul 2026UK MHRA AI response checks, BoE agentic-risk warning, an FTC accuracy probe, and the UN’s first AI report.02 Jul 2026China’s AI+Consumption push, Hong Kong anti-financial-crime guidance, US incident reporting, and EU gatekeeper moves.25 Jun 2026US model export controls as NO FAKES advances, UK DUAA rules bite, and the EU launches its AI Act forum.18 Jun 2026The EU AI transparency code lands as US preemption talks and New York’s disclosure law advance.11 Jun 2026AI governance turns national: US frontier-model security, EU cloud sovereignty, Singapore’s GenAI data rules.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.