NextAI+ Praxis--:----UTC
AI Governance Weekly

US AI Vulnerability Coordination, Japan AI Plan, China’s Anthropomorphic AI Rule, UK Data Consultation, EU Android Interoperability

23 July 2026
Long read · 18 min
By NextAI+ Praxis

On July 14, 2026, the White House launched GOLD EAGLE, an official partnership bringing together the Department of the Treasury, the Cybersecurity and Infrastructure Security Agency, open-source software partners, and critical infrastructure companies to use frontier AI in the coordinated intake, validation, prioritization, and remediation of cross-sector software vulnerabilities. This further integrates AI-assisted vulnerability discovery into existing government and industry security operations and patch distribution processes. On the same day, the Cabinet of Japan approved the second AI Basic Plan, incorporating agentic AI, vertical AI, physical AI, and open AI sovereignty into the national deployment agenda, while further specifying arrangements for government procurement, model substitutability, data and compute infrastructure, and accountability rules for AI agents. On July 15, 2026, five Chinese authorities implemented the Interim Measures for the Administration of Anthropomorphic Interactive Artificial Intelligence Services, introducing requirements for user identity notices, protection of minors, interaction data management, intervention in extreme situations, security assessments, and algorithm filing for services providing sustained emotional interaction. This extends the governance of emotionally oriented AI products beyond content controls to the management of ongoing interactions and user dependency risks. On the same day, the UK Department for Science, Innovation and Technology launched a call for evidence on data regulation in the age of AI, seeking practical examples concerning data access and use, data quality, cross-organizational accountability, individual rights, and agent permissions to inform whether the existing data protection framework requires supplementary guidance or institutional adjustment. On July 16, 2026, the European Commission specified Alphabet’s interoperability obligations under the Digital Markets Act, requiring it to open certain Android invocation points, device context, cross-application actions, and on-device model capabilities to third-party AI services. This moves competition among mobile AI assistants further into system interfaces, access control, eligibility certification, and operational auditing.

§ i

U.S. Launches GOLD EAGLE, Operationalizing AI-Assisted Vulnerability Coordination

On July 14, 2026, the White House announced the launch of the GOLD EAGLE initiative, under which the U.S. Department of the Treasury, the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security (DHS), the Department of War (DOW), and other agencies will work with open-source software partners and critical infrastructure companies to coordinate the intake, prioritization, scan validation, remediation, and patch distribution of cross-sector software vulnerabilities.

GOLD EAGLE is accurately characterized as an official partnership established by executive order and already in initial operation. It is not an act of Congress, a regulatory rule, or a mandatory reporting regime for private companies. Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, signed on June 2, 2026, directed the Secretary of the Treasury, in coordination with the National Cyber Director, the National Security Agency (NSA), and CISA, to establish an AI cybersecurity clearinghouse based on voluntary participation by AI companies and critical infrastructure operators. Its responsibilities include coordinating and reducing duplicative or conflicting software scans, identifying and validating vulnerabilities, and prioritizing and coordinating remediation work and patch distribution. The White House subsequently confirmed that GOLD EAGLE had begun receiving vulnerabilities identified across industries, determining their handling priority, and coordinating scan validation. The new mechanism is not intended to create another vulnerability list, but to use frontier AI capabilities to expand the scale of vulnerability handling and connect dispersed findings to cross-agency and cross-industry remediation processes. The publicly available executive order and launch announcement have not yet specified enterprise eligibility, data submission formats, the permitted scope of model use, vulnerability confidentiality classifications, patch validation standards, or detailed allocations of responsibility, and no complete list of industry participants has been released.

The initiative does not currently require ordinary enterprises to establish an additional statutory compliance process, but it will directly affect companies involved in U.S. critical infrastructure, government software supply chains, and open-source software maintenance. The first issue for enterprises is not whether to deploy a vulnerability-scanning model, but whether AI-generated findings can be integrated into existing security operations. Vulnerability reports should be traceable to specific software versions, components, assets, and affected environments. Model outputs should preserve information on provenance, confidence levels, duplicate detection, and human validation, so that unconfirmed findings do not directly trigger remediation in production environments. At the patching stage, enterprises also need to define who approves remediation, how compatibility is tested, which systems are updated first, and how failures are rolled back. The records that matter are not limited to which vulnerabilities were discovered; they should also show who validated them, why a priority was assigned, which patch was selected, and whether remediation was completed. When participating in external information sharing, enterprises should distinguish among vulnerability information suitable for public disclosure, technical details that could expose attack paths, and sensitive data containing customer asset or internal system information. Supplier contracts and internal permission structures should also specify who may submit such materials to government or industry platforms. These are deployment preparations inferred from the initiative’s operating model, not mandatory obligations already announced under GOLD EAGLE.

This is not the first U.S. mechanism for receiving and prioritizing vulnerabilities. CISA already operates a coordinated vulnerability disclosure (CVD) process and uses the Known Exploited Vulnerabilities Catalog (KEV Catalog) to require federal agencies to prioritize remediation of vulnerabilities with evidence of active exploitation. Binding Operational Directive 26-04, issued on June 10, 2026, further required federal agencies to schedule security updates according to actual risk. GOLD EAGLE continues this policy trajectory, but the change is the addition of frontier AI, cross-industry scanning results, and centralized remediation prioritization to the existing vulnerability coordination system. Coordinated vulnerability disclosure guidance issued by CISA and partner agencies on July 16 still treats report intake, classification, remediation, vulnerability numbering, and communication with security researchers as the foundational process, indicating that AI is primarily intended to expand processing capacity rather than replace human validation and the allocation of responsibility. Compared with the U.S. approach of administrative coordination and voluntary enterprise participation, the EU Cyber Resilience Act (CRA) places certain vulnerability-handling responsibilities directly on manufacturers of products with digital elements. Its Article 14 reporting obligations for actively exploited vulnerabilities and severe security incidents will begin to apply on September 11, 2026. The two approaches address similar issues, but create different governance relationships for enterprises. In the United States, the near-term priority is whether companies can connect to government and industry coordination networks and accelerate remediation. In the EU, manufacturers must also prepare to meet statutory vulnerability reporting procedures and deadlines. Cross-regional software suppliers should therefore not rely on a single generic vulnerability mailbox, but should map voluntary sharing, contractual requirements, and statutory reporting to different approvers, time limits, and evidentiary records.

§ ii

Japan Approves Second AI Plan, Integrating AI Sovereignty into Deployment Strategy

On July 14, 2026, the Cabinet of Japan approved the second AI Basic Plan by Cabinet decision. The national plan covers agentic AI, government and industry applications, data and compute infrastructure, model evaluation, and risk governance.

The plan was formulated under Article 18 of Japan’s Act on the Promotion of Research, Development and Utilization of Artificial Intelligence-Related Technology, referred to below as the AI Act. It primarily sets out policy measures to be comprehensively advanced by the Japanese government and is not itself a regulatory rule that directly imposes obligations or penalties on ordinary enterprises. Compared with the first plan adopted in December 2025, the second plan retains four policy pillars—accelerating AI adoption, strengthening AI development capabilities, leading AI governance, and promoting the continuous transformation of an AI-enabled society—while adding a principle of “challenge and learning” and identifying agentic AI, vertical AI, and physical AI as priority application areas. The plan proposes establishing open AI sovereignty, meaning that Japan will seek to reduce excessive dependence on a single country, company, or foundation model while maintaining international cooperation, and preserve operational continuity through multi-model orchestration, domestic infrastructure development, and arrangements that allow models to be substituted.

The practical impact on enterprises will first be felt in government procurement, quasi-public-sector projects, and supplier architecture design. The plan proposes expanding the use of the government AI environment GENAI, introducing AI agents and domestically developed Japanese models, and developing rules governing the government use of AI agents. Healthcare, finance, education, disaster prevention, transportation, and manufacturing are also included among the priority sectors for the development, testing, and deployment of vertical and physical AI. Companies participating in these projects will need to prepare more than descriptions of model functionality. They will also need evidence concerning model provenance, evaluation results, data-processing pathways, tool-use permissions, human approval points, and abnormal termination mechanisms. The plan’s emphasis on open AI sovereignty will also affect supplier selection. Enterprises may need to demonstrate that their systems can connect to multiple models, that critical data and business processes are not locked into a single provider, and that technical pathways exist for model replacement, interface migration, and supplier exit. On data, the plan promotes the construction of data connectivity infrastructure across government, quasi-public institutions, industry, and research organizations, while explicitly identifying the risk that trade secrets and other sensitive information may flow overseas. Enterprises will therefore need to distinguish which data may be shared across organizations, which data should be processed only within Japan, and whether training, retrieval, and log data may be transmitted to external models. These provisions currently represent policy deployment directions and should not be characterized as statutory enterprise obligations to localize data or adopt multi-model configurations.

Japan produced its second AI Basic Plan less than seven months after adopting the first plan on December 23, 2025. One direct reason is the government’s assessment that agentic AI has moved from being an assistive tool to a system capable of planning, executing, and correcting tasks, requiring policy to move beyond encouraging adoption toward redesigning organizational processes, infrastructure, and accountability relationships. Compared with the first plan, the change is not a departure from the basic direction of promoting innovation while managing risk, but the addition of implementation arrangements concerning experimental learning, multi-model operations, rules for AI agents, model evaluation, traceability, and technical guardrails. The plan also provides that it should, in principle, be updated annually at the current stage and monitored through appropriate benchmarks and key performance indicators. Key areas to watch include government rules for the use of AI agents, procurement standards, model evaluation methods developed by Japan’s AI Safety Institute (AISI), and the implementation of sector-specific vertical AI strategies. By contrast, the EU Artificial Intelligence Act directly imposes legal obligations on certain developers and deployers through risk classification. Japan currently relies more heavily on national planning, government-led procurement, sectoral guidance, and iterative policy adjustment. Enterprises operating across regions therefore cannot simply replicate a single governance baseline: EU projects require early determination of the applicable legal risk category and obligations, while Japanese projects require earlier preparation for model substitutability, government procurement evidence, sector-specific scenario evaluation, and accountability records for AI agents.

§ iii

China Implements New Rules for Anthropomorphic Interaction, Bringing Emotionally Oriented AI Under Full-Lifecycle Governance

On July 15, 2026, the Interim Measures for the Administration of Anthropomorphic Interactive Artificial Intelligence Services, jointly issued by the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation, formally took effect. The Measures apply to AI services offered to the public within China that provide sustained emotional interaction.

The Measures were promulgated as Order No. 21 of the five authorities and are now in force. They do not apply to every chatbot, but to services directed at the domestic public that simulate the personality traits, thought patterns, and communication styles of natural persons and provide sustained emotional interaction. Intelligent customer service, knowledge question answering, workplace assistants, educational services, and scientific research services that do not involve sustained emotional interaction fall outside the scope. The rules cover training data, deployment, operation, upgrades, and termination. Providers are required to retain network logs, protect user interaction data, establish a mode for minors, identify and intervene in extreme situations, continuously remind users that they are interacting with AI, and provide a convenient exit mechanism. Security assessments are also required when a service is launched, relevant functions are added, the use of new technology materially changes the service, registered users reach one million, or monthly active users reach 100,000. Algorithm filings are subject to annual verification, and app stores must also verify the relevant security assessments and filing status.

For enterprises offering AI companionship, virtual characters, emotional support, or social products with long-term memory in China, the first task is to reassess whether the product falls within the concept of “sustained emotional interaction.” Applicability cannot be excluded solely on the basis of internal labels such as “customer service,” “assistant,” or “entertainment.” Products within scope need to incorporate the lawful sourcing of training data, data cleaning and annotation, security assessments of synthetic data, and protections against data poisoning into model governance. User interaction data should be managed separately from ordinary operational data, with encryption, access controls, copying, and deletion capabilities, and separate consent should be obtained before sensitive personal information is used for model training. Deployment and operations should also include age identification, a mode for minors, reminders for continuous use, detection of dependency tendencies, escalation procedures for extreme situations, and workflows for contacting emergency contacts. What enterprises ultimately need is a traceable risk-handling chain: the risk identified by the system, the reminder or restriction triggered, the point at which the case was escalated to human handling, whether a guardian was contacted, and how the incident was closed should all be traceable to logs and responsible personnel. Version upgrades, changes in character capabilities, and growth in the user base should also be linked to security assessment triggers. For cross-regional products, this may require the China version to have separately configured age identification, authorization for the use of data in training, and crisis-intervention mechanisms rather than relying entirely on a globally standardized process. These are deployment adjustment recommendations derived from obligations now in force; they do not mean that regulators have prescribed a uniform technical implementation.

The rules further refine generative AI governance for long-term emotional relationships within the existing framework of the Cybersecurity Law, Data Security Law, Personal Information Protection Law, and Regulations on the Protection of Minors in Cyberspace. Previous rules primarily addressed training data, content safety, algorithm filing, and the labeling of generated content. The new Measures add the detection of excessive dependency, intervention in extreme situations, emergency contacts, reality reminders, and restrictions on virtual intimate relationships, extending the object of regulation from individual content outputs to the ongoing interaction process. Compared with the EU Artificial Intelligence Act, both frameworks address manipulative AI and transparency in human–AI interaction, but they approach the issue differently. Article 5 of the EU Act prohibits AI practices that use manipulative or deceptive techniques to materially impair a person’s ability to make an informed decision and cause or are reasonably likely to cause significant harm; that prohibition has applied since February 2, 2025. Article 50 requires certain AI systems that interact directly with natural persons to disclose their AI nature and will generally apply from August 2, 2026. China’s Measures go further in anthropomorphic companionship scenarios by regulating usage-duration reminders, protection of minors, psychological crisis intervention, and restrictions on using interaction data for training. At present, the Measures require only “effective measures” to identify minors and user risks. The formal text does not establish uniform requirements for identification accuracy, risk-classification thresholds, human takeover time limits, or standards for contacting emergency contacts. These implementation details will directly affect subsequent product design, security assessment materials, and preparation for regulatory inspection.

§ iv

UK Seeks Evidence on Data Regulation, Moving AI Rule Adaptation into Assessment

On July 15, 2026, the UK Department for Science, Innovation and Technology (DSIT) published the call for evidence Data Regulation in the Age of AI and Other Data-intensive Technologies. It seeks practical evidence from organizations and individuals involved in AI development, procurement, deployment, operations, and data services. Submissions close at 11:59 p.m. on September 9, 2026.

The document is an open call for evidence, not a draft law, regulatory guidance, or a new rule already in force, and therefore does not currently alter enterprises’ existing obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA), or sector-specific regulation. Through practical examples, DSIT seeks to determine where the existing framework remains effective, which issues arise from technical or organizational implementation, and which issues may require supplementary guidance, targeted legislative amendment, or broader reform. The call covers both personal and non-personal data and is structured around five themes: data access and use, data quality and downstream effects, cross-organizational data governance, transparency and individual rights, and the effectiveness of existing data frameworks as applied to AI. Specific questions address lawful bases for processing during training and deployment, purpose limitation and data minimization, identification of special category personal data, data provenance and metadata, anonymization and pseudonymization, controller and processor responsibilities, and how permissions granted to AI agents can be controlled and evidenced. Copyright and intellectual property issues are outside the scope of the call.

Although the call for evidence creates no new mandatory obligations, it translates the UK government’s questions directly into enterprise data-processing workflows. Enterprises need to prepare more than a high-level “Responsible AI policy.” They need evidence showing how data enters, moves through, and exits AI systems: which data is involved in training, fine-tuning, retrieval-augmented generation, prompts, model outputs, and operational logs; which lawful basis supports the processing of personal data; how processing is reassessed when the original purpose changes; and whether model providers, cloud service providers, and deploying enterprises act as controllers, processors, or joint controllers. For AI agents, enterprises should also record which data and systems they may access, which actions they may perform on behalf of users, how permissions are approved and revoked, and whether human review can genuinely alter the outcome. What may ultimately influence subsequent policy design is whether enterprises can submit concrete examples that include data flows, contractual allocations of responsibility, permission controls, impact assessments, and procedures for handling rights requests. Enterprises with UK operations that have faced persistent uncertainty over data access, reuse, or responsibility allocation can use the process to document regulatory gaps and practical evidence and submit views to DSIT before the deadline. This is a channel for participating in policy formation, not a newly established statutory filing procedure.

The call for evidence continues the UK’s institutional approach of addressing AI risks through existing law and sector regulators. In its 2023 white paper A Pro-innovation Approach to AI Regulation, the UK government proposed that existing regulators apply cross-sector principles—including safety, transparency, fairness, accountability, and contestability—within their respective remits. The Data $Use and Access$ Act 2025 subsequently made targeted amendments to the UK data protection framework. The change is not the immediate creation of a standalone AI data law, but an assessment of whether existing data concepts, individual rights, and organizational responsibilities can cover large-scale model training, complex supply chains, and autonomous agents. Unlike the EU, which has adopted unified legislation establishing AI risk categories and obligations for regulated actors, the UK is again beginning with the collection of practical evidence before determining whether issues should be addressed through regulatory interpretation, supplementary guidance, targeted legislation, or broader institutional reform. For enterprises deploying AI in both the UK and the EU, EU projects generally require an initial determination of the system’s risk category and applicable legal obligations. UK projects require a more detailed explanation of how existing data protection principles are implemented in specific data flows, supply-chain allocations, and processes for handling user rights. Key developments to monitor include DSIT’s formal response to the evidence received and whether the government proposes more specific arrangements concerning agent permissions, data reuse, identification of special category data, and allocation of responsibilities across organizations.

§ v

EU Specifies Android Interoperability, Opening System Capabilities to Third-Party AI

On July 16, 2026, the European Commission adopted a binding specification decision under Article 8(2) of the Digital Markets Act (DMA) in Case DMA.100220, identifying 11 Google Android system capabilities that Alphabet must open to third-party AI services in order to comply with its interoperability obligation under Article 6(7).

The decision is not a new regulation for all AI companies, but a technical specification of Alphabet’s existing gatekeeper obligations. The 11 capabilities are divided into four groups: assistant invocation points; application, sensor, and screen context; cross-application and system actions; and on-device models and background execution. Google must provide third parties with free access in the Android ecosystem that is as effective as the access available to its own services, together with complete documentation, testing conditions, and technical support. Subsequent updates to the relevant capabilities must also be made available to third parties. Objective and non-discriminatory eligibility conditions may be imposed for five sensitive capabilities—screen automation, structured on-device integration, system integration, centralized access to on-device application data, and context-aware intelligence—but no commercial requirements may be attached, and all access remains subject to the user’s explicit consent. Most measures must be implemented with Android 18 no later than August 1, 2027, while the parallel wake-word functionality must be implemented with Android 19 no later than August 1, 2028.

Alphabet, rather than all third-party AI service providers, bears the direct legal obligation. However, companies seeking to provide assistant or agent services on Android devices in the EU will gain access to system entry points previously used primarily by Gemini, while also facing more specific integration requirements. Service providers need to define which on-device application data, sensors, and screen content an assistant may read; which cross-application or system actions it may perform on behalf of a user; and how permissions are granted, revoked, and logged. Access to the five sensitive capabilities will also require eligibility materials demonstrating privacy, security, and system integrity. Application developers are not compelled to make data or operations available to all assistants, but once they choose to integrate, they should limit callable data fields, task types, and the confirmation steps required for irreversible actions. For organizations using enterprise mobile devices, the key missing control is an audit chain covering “user instruction—assistant invocation—application execution—result confirmation”, with AI assistant permissions incorporated into mobile device management, application allowlists, sensitive data segregation, and abnormal-operation termination processes.

The decision continues the DMA’s approach of translating a principle-based interoperability obligation into specific interfaces and implementation timelines. In September 2023, the European Commission designated Alphabet as a gatekeeper and Google Android as a core platform service, with the relevant substantive obligations applying from March 2024. The Commission opened the specification proceeding in January 2026, published preliminary measures and sought third-party feedback in April, and adopted the final decision in July. In March 2025, the Commission had already used the same provision to require Apple to open certain iOS and iPadOS capabilities to third-party connected devices. The Android decision extends interoperability further into AI assistant activation, context acquisition, cross-application execution, and access to on-device models. Together, the two cases show that the EU is no longer leaving system-level access entirely to platform design, but is using binding specification decisions to test whether third parties receive conditions that are as effective as those available to a platform’s own services. It is important to distinguish the scope of the DMA: it addresses platform access and market contestability, while data processing, security, and product liability for third-party services must separately comply with the General Data Protection Regulation and other EU rules. The currently published document is a provisional non-confidential version and sets out only the final measures, not the Commission’s full legal reasoning. Certain technical boundaries and justifications will therefore need to be reviewed again after the complete non-confidential decision is published.

Back to AI Governance Weekly

Cite as · AI Governance Weekly · 23 July 2026

§ Recent signalsBack to Governance Weekly
20 Aug 2026Colorado refines AI decision and chatbot rules as the EU weighs cloud lock-in and China clarifies public personal data.13 Aug 2026EU GPAI implementation tightens, the UK opens a legal AI sandbox, and agentic AI enters financial supervision.06 Aug 2026The EU delays high-risk AI rules as NIST moves model evaluation into a sequestered environment.30 Jul 2026EU AI transparency obligations apply, Singapore issues generative-AI data guidelines, and China reforms privacy compliance.16 Jul 2026FTC AI certification, EU cyber and data transparency moves, and a UK AI security review.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.