On June 12, 2026, Anthropic issued a statement saying that the U.S. government, citing national security authorities, required the company to suspend foreign nationals’ access to two models, Fable 5 and Mythos 5. Anthropic subsequently disabled the relevant models for all customers, bringing access to frontier models itself within the scope of export controls and national security governance.
On June 18, 2026, the U.S. Senate Judiciary Committee advanced the Nurture Originals, Foster Art, and Keep Entertainment Safe Act, or NO FAKES Act. The bill seeks to establish federal protection for individuals’ voice and visual likeness rights in digital replicas, moving deepfake governance from content labeling toward rights authorization, platform takedown, and accountability tracing.
On June 19, 2026, Section 103 and Schedule 10 of the UK Data (Use and Access) Act 2025, or DUAA, came into force, requiring data controllers to establish formal complaint handling procedures for disputes involving personal data processing. This moves AI-related data disputes earlier into enterprise internal remedy and recordkeeping processes.
On the same day, the European Commission convened the first meeting of the AI Act Advisory Forum, incorporating industry, academia, SMEs, and civil society into the implementation support mechanism for the Artificial Intelligence Act, or AI Act. As a result, discussions around high-risk AI classification, transparency codes of practice, and standardization are entering a more concrete implementation phase.
In addition, the European Commission selected the EUROPA consortium, led by Domyn, to build an open European frontier AI model covering all 24 official EU languages. This advances Europe’s effort to create more options in local model supply, compute resources, and public-sector adaptation.
On June 12, 2026, the U.S. Department of Commerce, citing national security export control authorities, issued a directive to Anthropic requiring the suspension of all access by foreign nationals to two models, Claude Fable 5 and Claude Mythos 5, regardless of whether those individuals were located inside or outside the United States. The directive also explicitly included Anthropic’s own foreign-national employees. Anthropic chose not to segment users by nationality, but instead disabled the two models for all customers in order to ensure compliance. Other Claude models were not affected. The specific statutory basis for the directive has not been publicly disclosed. Reporting has generally referred to “national security export controls”; therefore, this section refers to the legal basis only according to official statements and authoritative reporting, without speculating on the specific provisions relied upon.
According to accounts relayed by Fortune, Reuters, The Wall Street Journal, and The Information, the chain of events that triggered the directive was as follows: Amazon researchers identified a jailbreak that could bypass Fable 5’s safety guardrails and unlock Mythos’s cyber offensive and defensive capabilities. A jailbreak refers to the use of specific prompts to bypass a model’s established safety restrictions. Amazon CEO Andy Jassy raised the issue with the White House on June 11 and directly with Treasury Secretary Scott Bessent. The government then reportedly gave Anthropic CEO Dario Amodei approximately 90 minutes to fix the jailbreak or take the models offline. Amodei refused. The Department of Commerce then issued the export control directive.
White House AI adviser David Sacks stated that “a highly trusted partner to both Anthropic and the government found a jailbreak in Fable 5’s guardrails.” Senior White House officials told Politico that the use of export controls was a “last resort.”
On June 2, President Trump signed the Executive Order titled Promoting Advanced Artificial Intelligence Innovation and Security. Its overall direction was to establish a primarily voluntary early access framework for the safe deployment of frontier models. The June 15 meeting between Anthropic and the White House, discussed in the previous weekly report, in which the two sides failed to reach agreement on controlled access to Mythos, was in fact part of the follow-up to the June 12 export control action. Anthropic technical personnel traveled to Washington over the weekend after the directive was issued to meet with White House officials.
Within two weeks, the governance tools for frontier cyber capabilities progressed from a “voluntary safety framework” to “controlled access negotiations,” and then to “mandatory cutoff through export controls.” A voluntary framework depends on corporate cooperation. Export controls, by contrast, are hard constraints that take immediate effect and impose liability for non-compliance. This also marks the first time the control object has shifted from chips to access to models themselves.
The government and Amazon’s position is that the relevant capability could be used to assist cyberattacks and therefore poses a real national security risk. Export controls were, in their view, a last resort. Anthropic, by contrast, clearly rejected this characterization in its official statement. It argued that the issue was a narrow and non-universal jailbreak, essentially involving a model reading a specific codebase and fixing software defects within it. Similar capabilities are widely available in other models, including OpenAI’s GPT-5.5, and are used every day by defenders protecting system security. On that basis, Anthropic argued that a narrow potential jailbreak should not justify recalling a commercial model already deployed to hundreds of millions of people. Otherwise, such a standard would effectively halt deployment of all new models by frontier model providers.
There are substantial differences across the parties’ descriptions of the seriousness of the jailbreak. The government characterized it as sufficient to constitute a national security threat, while Anthropic described it as narrow and non-universal. There is currently no independently verifiable, unified standard for connecting capability claims with real-world risk. This is the same class of issue as the restrained estimates in the RAND study commissioned by the UK AI Security Institute on offensive cyber “human uplift” referenced in the previous issue: measured “capability” and real-world “risk” are not the same thing.
If export controls become a regular tool of frontier model governance, model access will be brought into national security export management in a manner similar to chips. Availability in cross-border deployment will itself become an operational risk. At the same time, when the basis for hard enforcement is not public and the judgment of severity depends heavily on a single source, it remains to be seen whether this can develop into a predictable and reusable institutional mechanism, rather than remain a case-specific response.
On June 18, 2026, the U.S. Senate Judiciary Committee advanced the Nurture Originals, Foster Art, and Keep Entertainment Safe Act, or NO FAKES Act, a bill aimed at combating deepfakes. Its core objective is to establish a federal, intellectual-property-style right in an individual’s voice and visual likeness. The bill is specific in what it seeks to address: distributing deepfakes without the individual’s consent would give rise to liability. A deepfake refers to synthetic or manipulated audio-visual content sufficiently realistic to be mistaken as real. If social platforms fail to make reasonable efforts to remove reported content, they could face penalties of up to USD 750,000 per item. This is only a committee advancement; the bill must still be considered by the full Senate before becoming law.
The reason this development deserves attention is that it has been placed inside a larger political transaction. The federal government is seeking to use a nationwide unified rule to replace the current patchwork of state-level AI legislation. In exchange for states refraining from independently legislating to constrain AI model development for three years, the White House has proposed pairing preemption with the passage of several popular laws: the Kids Online Safety Act, or KOSA, the NO FAKES Act, and mandatory age verification.
The committee advancement of NO FAKES is the first part of this package to make real progress. The most critical provision — the “freeze” on state AI legislation — has not yet taken shape. The same route was attempted once in 2025, when a proposal for a ten-year moratorium on state AI laws was defeated in the Senate by a 99-to-1 vote. The current version shortens the period to three years and returns with child safety legislation attached.
For companies and individuals, if the bill ultimately becomes law, social platforms would face real financial penalties for allowing deepfakes to remain unaddressed. The content and platform industries would need to build deepfake detection, complaint, and takedown processes early. However, the “single national rule” that many companies expect is unlikely to arrive in the short term. State laws remain effective for now. For example, Colorado’s AI law, originally scheduled to take effect on June 30, 2026, has been delayed to 2027 and substantially narrowed.
Whether this package can be negotiated successfully will depend on whether its proponents can keep together two groups with different priorities: those concerned with state authority and those focused on child safety. Last time, it was precisely this coalition that voted the moratorium down.
On June 19, 2026, Section 103 and Schedule 10 of the UK Data (Use and Access) Act 2025, or DUAA, came into force. These provisions require data controllers to establish complaint handling procedures for data subjects in situations where individuals believe that the processing of their personal data violates the UK General Data Protection Regulation, or UK GDPR, or the Data Protection Act 2018, or DPA 2018. The UK’s No. 6 Commencement Regulations make clear that the new complaint handling obligations apply to complaints received by controllers on or after that date.
The core mechanism of Section 103 of the DUAA is the introduction of a formal procedure under the UK data protection regime for data subjects to first complain to the controller. Section 103 inserts a new Section 164A into the DPA 2018, providing that a data subject may complain to a data controller if the data subject believes there has been an infringement of the UK GDPR or the DPA 2018 in connection with the processing of their personal data. Controllers must facilitate the submission of complaints, for example by providing a complaint form that can be completed electronically, and must acknowledge receipt within 30 days of receiving a complaint.
The provision also requires controllers to take appropriate steps to respond to complaints without undue delay. This includes investigating the subject matter of the complaint, updating the complainant on progress, and informing the complainant of the outcome. This is not an ordinary customer service complaint. It is a personal data complaint handling obligation written into data protection law. The same provision also introduces a new Section 164B, authorizing the Secretary of State to make regulations requiring controllers to report to the Information Commissioner the number of data subject complaints received during a specified period. That reporting mechanism still requires further regulations before becoming operational.
This change mainly affects the data, operations, compliance, and audit stages of the enterprise AI lifecycle. For companies that use AI to process customer data, employee data, user behavior data, automated decision-making data, or training and inference logs, dissatisfaction from data subjects can no longer be treated merely as ordinary feedback submitted through a privacy inbox or customer service channel. It must enter an identifiable, recordable, and traceable statutory complaint process.
Enterprises need to adjust three categories of mechanisms. First, they should set up clear data protection complaint entry points in privacy notices, product pages, or user centers. Second, they should separately record AI-related complaints alongside data subject access requests, erasure requests, rectification requests, and objections to automated decision-making. Third, they should establish investigation, response, and escalation pathways for complaints involving erroneous model outputs, unfair AI decisions, data used for training, excessive log retention, or misuse of personal data.
Viewed within the broader trajectory of UK data protection reform, the DUAA does not create a separate AI law. Instead, it preserves the main framework of the UK GDPR and the DPA 2018 while clarifying certain operational procedures. The UK government has previously explained that the DUAA does not replace the UK GDPR, the DPA 2018, or the Privacy and Electronic Communications Regulations 2003, or PECR. Rather, it amends these rules to simplify organizational operations, support responsible data use, and maintain data protection standards.
The complaints provisions that took effect on June 19, 2026 sit in the later stage of this reform line. Most data protection and privacy provisions had already commenced on February 5, 2026, while Section 103 was scheduled to commence approximately 12 months later because it requires organizations to establish internal complaint processes facing data subjects.
Horizontally, the UK’s approach differs from the EU AI Act’s high-risk AI classification-based regulation, and also from the more fragmented state-level and sectoral approach in the United States. The UK change does not directly prescribe which AI systems are “high-risk.” Instead, it moves common data disputes in AI deployment into internal enterprise handling at an earlier stage. For example, when a user challenges an AI-based credit refusal, an employee questions an AI recruitment screening result, or a customer disputes the retention or training use of chatbot records, the enterprise must first have an internal complaint channel and processing record. Only then will regulators have a clearer factual basis for intervention.
On June 19, 2026, the European Commission hosted the first meeting of the AI Act Advisory Forum. The forum is an advisory body established under Article 67 of the Artificial Intelligence Act, or AI Act, and is responsible for providing technical expertise and implementation advice to the European Commission and the European Artificial Intelligence Board, or AI Board.
The core mechanism of the AI Act Advisory Forum is to bring industry, start-ups, SMEs, academia, and civil society into the implementation process of the AI Act and provide technical input to the European Commission and the AI Board. Article 67 of the AI Act provides that members of the Advisory Forum should represent a balanced mix of stakeholders, including industry, start-ups, SMEs, civil society, and academia. The European Commission’s page shows that 174 members were selected from more than 700 applications, with a two-year term that may be renewed once.
The mechanism of this first meeting focused on three points. First, it introduced the rules of procedure of the Advisory Forum and organized the election of co-chairs. Second, the European Commission presented the Code of Practice on Transparency of AI-Generated Content to the Forum. Third, it sought initial views on standardization issues and the draft guidelines on the classification of high-risk AI systems. The Forum is not an enforcement body, but it will participate in shaping guidance, standardization, and implementation interpretations under the AI Act.
This change mainly affects the model, deployment, operations, compliance, and audit stages of the enterprise AI lifecycle. For companies providing or deploying AI systems in the EU, AI Act compliance is no longer only a matter of reading the legal text. They also need to track implementation positions developed by the Advisory Forum, the AI Office, the AI Board, the scientific panel of independent experts, and standards organizations.
In particular, high-risk AI classification, labeling of AI-generated content, transparency requirements for general-purpose AI models, or GPAI models, and technical documentation requirements may all be further specified through guidelines, codes of practice, and standardization documents. Enterprises need to establish a tracking mechanism that connects “legal text — draft guidance — standards — internal controls,” translating external interpretive changes into updates to model registration, risk classification, technical documentation, vendor questionnaires, and launch approval processes.
Viewed within the EU AI Act implementation timeline, the first meeting of the Advisory Forum took place during the preparation stage after the regulation entered into force but before full application. The AI Act entered into force on August 1, 2024. The European Commission has explained that the Act will generally become fully applicable on August 2, 2026, while prohibited AI practices and AI literacy obligations applied from February 2, 2025, and governance rules and GPAI model obligations applied from August 2, 2025.
The significance of this meeting is not that it creates a new enterprise obligation, but that the EU has begun to operationalize the external expert input mechanism required for implementation. Horizontally, the EU’s path differs from the UK’s use of data protection law to adjust automated decision-making and from the U.S. approach of parallel state-level and federal discussions on AI risks. The EU relies more on a combination of “regulation + guidance + standards + expert bodies” to translate high-risk classification, transparency, technical documentation, and conformity assessment into operational documents.
For cross-regional enterprises, the same AI system deployed in the EU cannot be assessed only against an internal global AI governance policy. The company must also determine whether the system is classified as high-risk under EU guidance, and whether additional technical documentation, transparency explanations, and conformity assessment are required.
On June 19, 2026, the European Commission announced that it had selected the EUROPA consortium, led by the Italian company Domyn, as the winner of the Frontier AI Grand Challenge to build an open European frontier AI model covering all 24 official EU languages.
The core mechanism of this event is that the EU is using a competition and the allocation of compute resources to support a European consortium in training an open frontier AI model. The European Commission stated that the EUROPA project will develop an open-source AI model covering all 24 official EU languages and strengthen advanced AI development capacity on Europe’s own infrastructure.
The Frontier AI Grand Challenge was launched in February 2026 and required European AI innovators to propose model projects exceeding 400 billion parameters. This scale is typically used to describe model capabilities at the level of the world’s most advanced AI systems. Under the challenge rules, the selected project may use up to 2.5% of the total compute resources of the European High Performance Computing Joint Undertaking, or EuroHPC JU, over one year, and run on one or more AI-optimized European supercomputers.
This change mainly affects the model, deployment, compliance, and audit stages of the enterprise AI lifecycle. For companies operating in the EU, model selection will no longer be limited to comparing performance and price among U.S. closed-source models, global open-source models, and enterprise self-developed models. European local models, EU language coverage, infrastructure location, and public-sector procurement preferences will also need to be included in the assessment.
The project itself does not require enterprises to immediately replace their models, but it will change the future composition of enterprise model suppliers. In public-sector, healthcare, manufacturing, research, and multilingual service scenarios, enterprises may need to prepare a “European model option” and compare model origin, training and deployment infrastructure, open licensing, data processing location, and compliance documentation in supplier due diligence.
Viewed within the EU’s broader AI industrial policy trajectory, EUROPA is not an isolated model project. It is part of the EU’s effort to advance “trustworthy AI regulation” and “local AI supply” in parallel. When the European Commission launched the Frontier AI Grand Challenge in February 2026, it placed the initiative in the context of the Apply AI Strategy and the AI Continent Action Plan, with the objective of supporting sovereign, large-scale European AI model development through European high-performance computing resources.
Compared with the Artificial Intelligence Act, which primarily constrains AI systems through risk classification, transparency, and conformity assessment, EUROPA addresses the other side of the equation: whether European companies and public institutions have access to usable, controllable, multilingual local model supply.
Horizontally, this differs from the U.S. approach of expanding frontier capabilities through large private model companies, China’s promotion of “AI+” industry applications, and Singapore’s refinement of generative AI guidance around personal data processing. The EU places greater emphasis on combining rules, compute, models, and public-sector demand into a single policy package.
For enterprises, the tension lies in balancing model performance, deployment convenience, and regional compliance. Global models may be more mature in capability, but European public-sector or sensitive industry projects may place greater weight on model origin, language coverage, infrastructure location, and supply chain explainability.
Cite as · AI Governance Weekly · 25 June 2026
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.