NextAI+ Praxis--:----UTC
AI Governance Weekly

Europe & US: US Issues Distillation Advisory; EU Proposes Innovation Act; UK Highlights Shadow AI Risks, Seeks Evidence on Energy AI and Publishes Healthcare AI Reform Recommendations

18 September 2026
Long read · 12 min
By NextAI+ Praxis

On 8 September 2026, the US National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation jointly issued a security advisory on model distillation, recommending cross-platform detection and response measures and highlighting the need for companies to verify upstream authorisations and model response quality across aggregator routing chains. On 9 September 2026, the European Commission proposed a regulation establishing the European Innovation Act, seeking to harmonise public R&D procurement procedures and support intellectual property financing, with implications for AI companies' eligibility to bid, R&D locations and licensing of project results. On 7 September 2026, the UK's National Cyber Security Centre issued security advice on shadow AI, highlighting the need to bring employees' use of unapproved tools, sensitive data inputs and agent permissions within organisational controls. On 8 September 2026, the Department for Energy Security and Net Zero launched a call for evidence on AI in energy, bringing multi-agent interactions, effective human oversight and dependence on model and cloud providers into policy discussions, without introducing new mandatory deployment obligations. On 10 September 2026, the Medicines and Healthcare products Regulatory Agency published an independent commission's recommendations for healthcare AI reform, proposing staged authorisations, continuous performance monitoring and allocation of risk-control responsibilities. The recommendations set out a direction for reform of market access, operations and procurement contracts for healthcare AI, with implementation pending the government's response.

§ i

Three US Agencies Issue Distillation Advisory Covering Aggregator Routing Chains

On 8 September 2026, the US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) jointly issued the cybersecurity advisory China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies, recommending measures for US AI companies to identify and mitigate the risk of model capability extraction.

The advisory provides threat information and non-binding protective recommendations; it does not impose sanctions. Model distillation involves using an existing model's outputs to train other models. The document acknowledges legitimate research uses, while alleging that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Zhipu extract restricted capabilities; these allegations do not constitute judicial findings. Recommended safeguards include verifying account identities, monitoring anomalous usage, correlating infrastructure and behavioural indicators across model providers, cloud platforms and aggregators, and modifying responses to requests identified with high confidence as malicious distillation. Requests confirmed as serving malicious distillation may be routed to a less capable model without notifying the user.

Companies deploying customer service tools, coding assistants or internal agents through aggregator gateways should focus procurement reviews on verifiable upstream authorisations and request routing paths. This includes confirming model provenance, service territories, resale rights and permitted uses of outputs for training, while linking each request to its tenant, upstream account identifier, endpoint, model identifier and routing change records. High-frequency evaluation and synthetic data tasks should have their purposes separately documented, their licensing scope confirmed in advance and supporting evidence prepared for appeals against misclassification. As the advisory recommends targeted response adjustments, operational monitoring should also cover business-level accuracy and task success rates. Contracts should address model change notifications for legitimate workloads and the resolution of quality disputes, with authorised alternative models available. Aggregators participating in intelligence sharing should limit disclosures to necessary infrastructure and behavioural indicators, and separately verify the basis and scope for disclosing customer data. These are deployment recommendations; the advisory does not prescribe a uniform log retention period or mandate the sharing of customer content.

On 23 April 2026, the White House Office of Science and Technology Policy (OSTP) issued the memorandum Adversarial Distillation of American AI Models (NSTM-4), proposing intelligence sharing with companies and joint development of protective practices. The three-agency advisory translates those collaboration arrangements into technical recommendations, providing cross-platform detection indicators and response strategies. On 9 September 2026, China's Ministry of Commerce rejected the factual and legal basis of the allegations, emphasised the technological neutrality of distillation and questioned US model providers' territorial restriction clauses. Given the differing characterisations of specific access and output-use practices, companies operating across borders should separately assess applicable law, contractual authorisations and actual access conditions. Key developments to monitor include whether providers incorporate the advisory's recommendations into their service rules, and how they implement misclassification remedies and quality assurance.

§ ii

European Commission Proposes Innovation Act to Advance R&D Procurement and IP Financing

On 9 September 2026, the European Commission proposed a regulation establishing the European Innovation Act (EIA), covering public R&D procurement, cross-border joint procurement, and intellectual property valuation and financing support.

The proposal remains subject to legislative scrutiny. It seeks to harmonise qualifying public R&D procurement procedures and support intellectual property commercialisation. Its procurement provisions cover R&D services and would require at least 50% of contractual R&D activities to take place in the EU or eligible countries covered by relevant agreements, subject to exceptions. In principle, suppliers would retain intellectual property rights in the results, while procurers would receive usage rights. The European Union Intellectual Property Office (EUIPO) would establish a competence centre to develop a voluntary intellectual property valuation and disclosure framework for companies, alongside a matchmaking platform for licensing and transfers and technical support for financing.

Companies seeking AI R&D contracts from EU public bodies can incorporate bid eligibility, the allocation of R&D activities and licensing of project results into early project reviews. This involves checking the bidding entity's substantive business activities, the location of key R&D personnel and subcontracting arrangements to assess whether existing teams could meet the proposed conditions. Contract preparation should distinguish proprietary code, third-party model licences, training data usage rights and newly generated project results. Each category should be reviewed to establish which rights can be granted to the procurer and which results can continue to be licensed to others, so that delivery commitments remain within the scope of upstream authorisations. These recommendations draw on the access, origin and results-related rights provisions in Articles 11, 12 and 19 of the proposal. Teams planning to raise finance against intellectual property should also assemble evidence of ownership, licensing restrictions and verifiable commercialisation revenues, distinguishing proprietary technology assets from capabilities dependent on external model services to support valuation and financing reviews.

The EU Startup and Scaleup Strategy, published on 28 May 2025, had already outlined R&D procurement procedures and intellectual property financing support. The new proposal gives those policy directions concrete legislative form. Harmonisation of procurement procedures within Europe is proceeding alongside access conditions for external suppliers. The Commission explains that non-EU countries currently covered by the relevant R&D procurement agreements include countries in the European Economic Area and the Western Balkans; suppliers from other countries cannot assume equivalent access solely on the basis of general public procurement agreements. AI companies operating across regions should therefore assess market access, R&D location and conditions for commercialising results separately when evaluating European R&D opportunities. Priorities for monitoring include amendments to these provisions during legislative scrutiny and the detailed arrangements for intellectual property valuation and disclosure methodologies.

§ iii

UK Cyber Security Centre Issues Shadow AI Advice on Data and Permissions

On 7 September 2026, the UK's National Cyber Security Centre (NCSC) published the security blog The hidden risks of shadow AI, examining data exposure, governance blind spots and agent permission risks arising from employees' use of AI tools without organisational approval.

Shadow AI refers to AI use outside an organisation's approved systems and processes. The publication provides non-binding security advice. It notes that when employees enter sensitive information into consumer services, that information may be retained or used to improve services outside existing governance arrangements. If a software vulnerability in an agent is exploited, an attacker may gain the agent's existing data access and system permissions. The NCSC recommends understanding why employees use unapproved tools, providing secure alternatives that meet business needs and following existing guidance when connecting agents securely.

Companies can start with practical tasks such as contract summarisation, coding assistance and customer communications, using employee declarations, managed endpoints and application authorisation records to map the tools, accounts and data connections in use. Approvals should specify account types, permitted data scope and executable actions. Personal accounts, enterprise accounts and different connection features within the same service can be assessed separately. Agents connected to email, document repositories or customer systems should have separate identities and only the permissions necessary to complete their tasks. Appropriate human confirmation should be required for actions such as sending, deleting or bulk exporting, with necessary records of authorisations, calls and approvals retained, and clear responsibility for revoking credentials and disconnecting integrations when anomalies arise. These measures can be implemented with reference to the NCSC's existing agent security advice. Tool reviews should also be supported by an accessible request process and ongoing feedback on functional gaps and approval times, so that approved tools meet employees' actual work requirements.

The NCSC's interim advice blog Managing the cyber risk of agentic AI, published on 20 August 2026, had already addressed runtime isolation, monitoring and emergency shutdown. The new publication extends the focus to employee use that has yet to enter formal governance processes, encouraging companies to assess whether existing controls cover actual access paths. It also directly cites Careful adoption of agentic AI services, non-binding joint guidance developed by cybersecurity agencies in the UK, US, Australia, Canada and New Zealand, which recommends incorporating agent risks into existing security management and limiting agent permissions. Companies operating across regions can use common identity, permission and incident response controls on this basis, while separately assessing local data processing requirements. Further monitoring should focus on the formal guidance that the NCSC has announced it is developing to replace the August blog, and on the specific changes to its protective recommendations.

§ iv

UK Seeks Evidence on Energy AI, Focusing on Automated Control and System Risks

On 8 September 2026, the UK's Department for Energy Security and Net Zero (DESNZ) published the call for evidence Vision for an AI-enabled clean energy system, seeking views across England, Scotland and Wales on AI applications in energy, barriers to deployment and system risks.

With the aims of lowering energy costs, improving efficiency, supporting decarbonisation and safeguarding energy security, the document seeks evidence on data access, regulatory clarity and system integration. Responses are due by 6 November 2026. Key governance questions include how to validate overall safety when multiple agents interact, how to maintain effective human oversight of automated decisions, and how to sustain operations when dependence is concentrated among model or cloud providers. The highly autonomous energy systems described in the document are scenarios for examining risks, rather than an agreed implementation roadmap. The call for evidence introduces no new mandatory deployment obligations.

Teams responsible for energy storage dispatch, charging aggregation or load management should first define which recommendations AI may make, which actions it may execute directly, and the limits governing equipment states and the extent of control actions. Testing can simulate data delays, forecasting errors and multiple systems responding simultaneously to the same price signal, to assess whether local optimisation creates risks for the wider system. The ability to transfer control to humans and operate safely following service disruption should be validated through practical exercises. This requires clear switchover conditions, designated operational owners and backup controls capable of operating independently, ensuring that human responsibility extends beyond policy statements. Companies can also maintain linked records of model versions, input data timestamps, control commands and human interventions, and revalidate critical controls following model updates. Supplier contracts should address change notifications, incident cooperation and migration support. These deployment recommendations draw on the risks discussed in the document and established industry practices.

On 20 May 2025, the UK's Office of Gas and Electricity Markets (Ofgem) published the non-binding guidance Ethical AI use in the energy sector, setting out practices for governance, accountability and risk assessment. The new call for evidence extends the discussion to future autonomous control, interactions among multiple actors and market coordination. Its findings will inform the AI for Clean Energy Strategy. Subsequent monitoring should assess which recommendations enter formal policy and whether specific regulatory or validation arrangements emerge. The EU's Artificial Intelligence Act (AI Act), which has entered into force and applies in phases, already classifies AI used as a safety component in the supply of electricity as high-risk under point 2 of Annex III. Companies operating across regions should assess existing UK sector requirements separately from EU high-risk classification and application dates, based on each product's intended use and control functions, rather than applying a single classification to all energy AI applications.

§ v

UK Publishes Healthcare AI Recommendations on Continuous Monitoring and Allocation of Responsibilities

On 10 September 2026, the UK's Medicines and Healthcare products Regulatory Agency (MHRA) published the independent commission report National Commission into the Regulation of AI in Healthcare: Recommendations for a future regulatory framework, covering lifecycle regulation, clinical deployment and the allocation of responsibilities for healthcare AI.

The report makes 44 recommendations for reform, pending a government response, and does not itself introduce new mandatory obligations. Its proposed staged authorisations would allow suitable AI medical devices to accumulate evidence from real-world use within a limited scope and subject to oversight and risk controls before progressing to full authorisation. For post-market surveillance, it recommends adding continuous performance reporting and initiating reporting and remedial action when performance deteriorates, even before a reportable incident occurs. Its approach to responsibility emphasises documenting safe deployment conditions and the allocation of risk-control responsibilities in regulatory submissions and procurement contracts, with clear roles for manufacturers and healthcare providers.

Hospitals procuring AI-assisted diagnostic imaging systems can work with suppliers to simulate a performance anomaly following a model update: can the hospital identify affected cases, can the manufacturer provide the relevant version and change records, and can the clinical lead suspend use and revert to established care pathways? Acceptance criteria should assess whether monitoring, anomaly response and responsibility handovers are workable in practice. To support this process, the parties can agree performance metrics for different patient groups, anomaly triggers, provision of investigation data and corrective actions, while linking case records, model versions, outputs and records of human handling. When sharing patient data, they should separately verify the authority to process it and the scope necessary for the purpose. These preparations can help identify gaps between supplier capabilities and hospital operating conditions. They are deployment recommendations derived from the report, rather than standardised operating procedures imposed by its publication.

New medical device post-market surveillance requirements have applied in Great Britain since 16 June 2025, requiring manufacturers of devices within scope to proactively collect and analyse safety and performance data. The recommendations build on this foundation to address frequent AI updates, differences between deployment settings and responsibilities across organisations. The government will issue a separate response; subsequent monitoring should assess whether staged authorisations and recommendations on contractual responsibilities are incorporated into formal rules. The US Food and Drug Administration (FDA) issued its final, non-binding guidance Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions on 18 August 2025. It explains how planned updates and validation methods can be specified in advance in marketing submissions, allowing modifications consistent with an authorised plan to proceed without a separate submission for each change. Teams operating across markets can manage validation documentation centrally, while separately assessing authorised uses, the permitted scope of updates and local deployment responsibilities.

← Back to AI Governance Weekly

Cite as · AI Governance Weekly · 18 September 2026

§ Recent signalsBack to Governance Weekly→
17 Sep 2026China rules on AI-fabricated reviews and answers distillation claims, Korea tightens breach notification, and Japan weighs consumer AI risks.11 Sep 2026The EU designates ChatGPT and questions AI firms, the DOJ backs training fair use, and a US forum examines multi-agent security.10 Sep 2026China reports on AI enforcement and resource disclosure, Hong Kong advances a school sandbox, and Singapore details AI screening of financial reports.04 Sep 2026The EU refines AI Act enforcement, the UK and Ukraine form a defence AI partnership, and the FTC closes its Active Listening cases.03 Sep 2026Hong Kong refines agentic AI privacy, Japan applies comply or explain to AI and IP, and China sets national standards for agents.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.