The new rules, in plain language. EU, UK, Singapore, US state-level, mainland China — what changed, who has to act, by when. We do not summarise statutes; we read them the way a compliance officer at a mid-sized firm reads them, and report what is enforceable on Monday morning.
The NSA, CISA and FBI extend distillation defences across aggregator routing chains, the Commission proposes harmonised R&D procurement and IP financing, the NCSC addresses shadow AI data and permission risks, and the UK seeks evidence on energy AI and publishes recommendations for continuous monitoring of healthcare AI.
China’s Supreme People’s Court treats AI-fabricated competitor reviews as unfair competition, MOFCOM challenges geographic restrictions on model access, South Korea’s PIPA amendments require 72-hour breach notification and sharpen management accountability, and Japan examines how conversational AI and agents shape consumer decisions.
ChatGPT is designated a Very Large Online Search Engine under the DSA, the Commission sends requests for information to more than 30 AI companies without establishing violations, the US DOJ supports training-stage fair use in the OpenAI litigation, and a NIST-hosted forum brings agent interactions into threat modelling.
The CAC reports action across content, accounts and apps, MIIT consults on intelligent decision-making standards for manufacturing, seven departments propose generative-AI resource assessment and disclosure, Hong Kong’s school AI sandbox keeps compliance with schools, and Singapore’s ACRA pairs automated detection with human validation.
The Commission moves GPAI oversight and generative-content transparency into enforcement, the UK and Ukraine bring data sovereignty and AI assurance into defence cooperation, the FTC finalizes $930,000 in AI marketing settlements, and California’s AB 2713 extends provenance data into the download chain.
Hong Kong’s PCPD turns least privilege and human oversight into deployment controls for agents, Japan publishes a generative-AI IP principle-code, Korea implements public-sector AI risk management, Singapore consults on training and output liability, and China issues a cluster of national standards covering agents, RAG and model platforms.
The FDA brings premarket evaluation and postmarket monitoring into its design for GenAI-enabled devices, the FTC sets out how it would police data-driven personalized pricing, the UK moves on usage limits and mental-health safety for children’s chatbots, and the NCSC puts isolation controls at the centre of agent deployment.
China’s cyber data security risk assessment measures take effect, putting important data processors on an annual assessment, reporting and verification cycle, while Korea’s National Assembly amends the PIPA to let lawfully collected personal information be used for AI development — but only with public necessity and PIPC approval.
Colorado turns decision explanations, human review and protections for minors into operational procedure, the EU’s cloud and AI study feeds lock-in and extraterritorial risk into CADA, the CAC holds publicly available personal information to a reasonable scope, NIST consults on NVD modernization, and Korea updates its CBPR certification standards.
The EU refines GPAI post-market monitoring and copyright transparency, the UK’s AI Growth Lab brings legal AI under coordinated regulatory consultation, NIST joins the Genesis Mission on industrial agent security, the US keeps outbound AI investment restrictions in force, and Korea and Singapore both pull agents inside existing frameworks.
The EU’s Digital Omnibus pushes high-risk obligations back again, NIST launches a blind testing programme and a data-centre security analysis that extends AI governance to computing infrastructure, Korea eases the clinical evidence pathway for medical AI, and China pushes IPv6 into large-model deployment.
The EU’s content-labelling obligations enter application, Singapore’s PDPC explains how the PDPA applies across the generative-AI lifecycle, the UK AI Security Institute finds every evaluated model overstepping task boundaries, the US expands its Genesis Mission research platform, and China eases obligations for small-scale handlers while updating outbound-data rules.
The White House launches GOLD EAGLE to run AI-assisted vulnerability coordination across agencies, Japan’s cabinet approves a second AI Basic Plan built on open AI sovereignty, China brings emotionally oriented AI services under full-lifecycle governance, the UK opens a call for evidence on data regulation, and the EU orders Alphabet to open Android to third-party AI.
The FTC reinforces AI drafting disclosure and human verification, while the EU advances model cybersecurity, data sovereignty and content transparency, and the UK reviews lifecycle gaps in AI security services.
The UK’s MHRA requires fact-checked, human-signed AI-generated regulatory responses, the Bank of England flags systemic risk from agentic AI in trading and payments, the US FTC probes whether suppressed AI accuracy is consumer deception, and the UN issues its first scientific AI assessment.
China’s eight ministries roll out an AI+consumption plan, a US bill would require frontier developers to report dangerous capabilities within 7 days, the EU joins the Pax Silica supply-chain pact, and Brussels moves to designate AWS and Azure as DMA gatekeepers.
The US restricts foreign access to frontier models on national-security grounds, the NO FAKES Act clears committee, the UK’s DUAA complaint rules take effect, and the EU launches its AI Act advisory forum while selecting EUROPA as its sovereign model project.
The EU issues an AI content-labeling code while pushing its deadline to December, New York’s synthetic-performer disclosure law becomes the week’s only enforceable rule, and US federal preemption talks resume as frontier cyber-capability access stays unresolved.
The US folds frontier model safety into national cybersecurity and proposes a federal AI framework, the EU’s Cloud and AI Development Act pushes compute sovereignty, and Singapore details lifecycle rules for personal data in generative AI.
Illinois’s SB315 mandates third-party audits for frontier models, the EU fines Temu €200M under the DSA, the G7 folds generative AI into child-safety rules, and China issues agent-interconnection standards covering identity and tool-calling governance.
Colorado simplifies AI compliance and the EU delays high-risk deadlines again, while China blocks Meta’s Manus acquisition and issues its first AIGC fines — an East-West divergence that demands embedded compliance.
China rolls out full-cycle AI risk oversight in education, the Bank of England stress-tests algorithmic herding, and Singapore proposes an ISO generative-AI testing standard. Governance is moving from ethical principle to auditable, machine-checkable enforcement.
China bans AI virtual companions for minors, the EU makes 6-month tamper-proof logs admissible as legal evidence, and the US FTC cracks down on AI-washing. Three shifts that move compliance out of policy and into the architecture.
The EU’s content-labeling rule takes effect in November with fines up to 7% of revenue, while China mandates ethics review for high-risk systems. The compliance clock is running, pushing governance from legal sign-off into built-in technology.
The White House unveils a national AI policy framework, the EU defers high-risk obligations to 2027–2028, and Singapore and Brazil tighten their rules. As regulation densifies, the corporate task shifts from checkbox compliance to building governance capability.
The US challenges state AI laws and mandates “American AI systems” for federal contracts, the EU delays high-risk compliance to December 2027, and FINRA flags agentic-AI risk. A week that reopens questions of supply chain and accountability.
The EU AI Act enters enforcement with fines up to 7% of revenue; the US hits a March 11 federal-vs-state clash; attacker breakout time collapses to 29 minutes. A jurisdiction-by-jurisdiction read of why compliance and security now converge into one governance agenda.
A close, weekly reading of how large enterprises actually wire AI into the business. Architecture, vendor choice, where the money lands. Filed every Thursday.
The reports worth an afternoon, taken seriously at length. One document per entry — we read the appendices so the argument holds.
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.