
AI Compliance Map - Jul 17-24, 2026
Weekly compliance impact map for July 17-24, 2026, covering EU AI Act transparency guidance, New York data-center permitting, Canada’s AI transparency consultation, the UK AI Taskforce, Singapore PDPC guidance, and China anthropomorphic AI controls.
Coverage and readout
This issue covers verified actions dated from July 17 at 5:00 p.m. through July 24 at 5:00 p.m. (UTC-05:00). The clearest near-term work is in the EU, where Article 50 transparency guidance now sits less than two weeks ahead of application, and in New York, where a one-year pause on new hyperscale data-center permits changes the development path for AI infrastructure. Canada has opened a transparency consultation, while the UK has created a central AI delivery unit. These are different legal signals: the EU guidance supports an existing obligation, New York's order has immediate permitting consequences, and the Canadian and UK measures are policy or consultation steps rather than new private-sector duties.
No new court ruling or AI enforcement penalty was included. No official detail page reviewed for this window supplied a date-verified AI merits judgment, final agency sanction, or penalty against an AI company. Legislative introductions and policy statements below are not law unless expressly identified as effective or binding.
Executive action list
- EU transparency: Confirm Article 50 scope, marking, detection, and disclosure controls before August 2. The July 27 Code of Practice signature date is voluntary, but non-signatories still need an evidence-backed compliance method.
- New York infrastructure: Freeze planning assumptions for new hyperscale data centers in New York until the Executive Order 62 permitting and environmental-review path is mapped.
- Canada: Decide whether to submit evidence to the federal AI-transparency consultation before September 23, especially on AI-agent logs, incident tracking, and user disclosure.
- UK public-sector strategy: Treat the new Prime Minister's AI Taskforce as a forward-looking policy and procurement signal, not as a current rule for private providers.
- China watch: Keep Order No. 21 in the active control register for mainland-facing anthropomorphic services, but do not count its July 15 effective date as a new action in this issue's window.
European Union: Article 50 guidance moves into operations
Commission publishes transparency guidelines
Date / status: The European Commission published its guidelines on July 20. Article 50 transparency obligations apply from August 2, 2026. 1
Scope: Providers must design covered interactive AI systems to inform users when they are directly interacting with AI and must add machine-readable marks that enable detection of AI-generated or manipulated content. Deployers must disclose deepfakes, certain AI-generated public-interest text without human review or editorial control, and exposure to emotion-recognition or biometric-categorisation systems. The companion guidelines define the Article 50 scope for providers and deployers. 2
Compliance impact: Product, trust-and-safety, and communications teams should inventory covered outputs and interaction points, test machine-readable marking and user disclosures, and document exceptions before August 2; the guidance does not delay the statutory application date.
Code signature deadline is near, but signature remains voluntary
Date / status: The Commission says providers and deployers may submit the Code of Practice signature form by July 27, 2026 at 18:00 CEST to appear on the initial-signatory list. Article 50(2), (4), and (5) applies from August 2. 3
Scope: The code covers machine-readable marking and detection for providers, plus disclosure and labelling of deepfakes and certain public-interest text for deployers. Signing is voluntary. Organizations that do not sign remain responsible for Article 50 compliance and may need to demonstrate their alternative controls to market-surveillance authorities. 3
Compliance impact: A provider or deployer should make a documented sign-or-build decision this week, because declining to sign removes the recognized framework but does not remove the underlying legal duty.
United States: New York pauses hyperscale data-center permits
Executive Order 62 creates a one-year permitting pause
Date / status: New York Governor Kathy Hochul highlighted the statewide moratorium on July 22. Executive Order 62 temporarily pauses State environmental permits for new hyperscale data centers for up to one year while the state develops a regulatory framework. 4
Scope: The order directs the Department of Public Service to develop a generic environmental impact statement covering energy demand, water use and quality, and air quality. During that work, the Department of Environmental Conservation will not issue discretionary permits for projects that are not already deemed complete. The state also directs Empire State Development to issue a Community Investment Framework within 60 days; the framework is intended to guide local negotiations over infrastructure, workforce, and other community benefits. 4
Compliance impact: AI infrastructure developers, cloud providers, utilities, and project lenders should re-check New York permitting schedules, environmental diligence, grid assumptions, and local-benefit commitments before advancing a new hyperscale site.
Federal legislative watch remains outside the current action window
The federal bill pages reviewed for this run show relevant introductions on July 15 and July 16, before this issue's July 17 at 5:00 p.m. start. They are not counted as this week's actions. H.R. 9757, the Conversational AI Services Act, would address disclosures, safety measures, parental controls, self-harm protocols, and deceptive human-like interaction for minors, but it remains introduced and referred to the House Energy and Commerce Committee. 5
United Kingdom: central AI delivery unit announced
Prime Minister's AI Taskforce will direct government strategy
Date / status: The UK government announced the Prime Minister's AI Taskforce on July 24, with Lord Vallance as chair and AI Minister Kanishka Narayan leading the taskforce. It will report through the Office for the Prime Minister and the Cabinet and direct implementation of the government's AI strategy. 6
Scope: The taskforce will lead public-sector AI adoption and transformation, and responsibility for the existing AI Security Institute will move to the new office. The announcement does not create a new private-sector compliance rule or deadline. 6
Compliance impact: Suppliers to UK government should watch forthcoming procurement, assurance, and security requirements, while private-sector teams should treat the announcement as a signal to preserve evidence of model security, accountability, and public-sector deployment controls.
Canada: transparency consultation opens
Federal consultation covers content, agents, and incidents
Date / status: Innovation, Science and Economic Development Canada opened a public consultation on July 23. Responses are due by September 23, 2026. 7
Scope: The consultation asks how Canada should detect and identify AI-generated content, tell people when they are interacting with AI, provide information about system capabilities and limitations, track serious AI incidents, and track AI-agent activities and interactions. It invites views from businesses, researchers, civil society, Indigenous groups, and other stakeholders. 7
Compliance impact: Canadian operators and vendors should decide whether to submit evidence, and should preserve current examples of user disclosure, synthetic-content provenance, incident records, and agent activity logs because those topics may shape the next legislative or regulatory step.
Hong Kong: privacy regulator reports AI checks and cross-border cooperation
PCPD shares results from three rounds of AI compliance checks
Date / status: Hong Kong's Privacy Commissioner for Personal Data issued a statement dated July 23 after participating in the Singapore Data Festival and Asia Data Protection Authorities Exchange. The statement reports experience from three rounds of AI-related compliance checks conducted since 2023. 8
Scope: The statement points organizations to the PCPD's existing Model Personal Data Protection Framework for AI and its checklist for employee use of generative AI. It also records a July 22 memorandum of understanding between the Hong Kong International Data Privacy Academy, the Singapore Academy of Law, and the Asian Business Law Institute. The statement does not announce a new fine, rule, or compliance deadline. 8
Compliance impact: Organizations operating in Hong Kong should use the regulator's existing AI privacy materials as a control benchmark and prepare for evidence-based checks, but should not treat this statement as a new standalone legal obligation.
China: continuing control register
Order No. 21 remains the relevant operational baseline
China's Interim Measures for Anthropomorphic Interactive AI Services took effect on July 15, before this issue's strict July 17 start, so it is not counted as a new action here. It remains operationally relevant for providers serving the mainland because it covers continuous emotional-care, companionship, and support services while excluding ordinary customer service, knowledge Q&A, work assistants, education, and research. 9
For in-scope services, the measure requires safety-responsibility systems, lifecycle risk monitoring, training-data controls, age and guardian safeguards, interaction-data protections, AI disclosure, time-use reminders, exit routes, complaint handling, algorithm filing, and safety assessments for launches, major changes, services with at least 1 million registered users or 100,000 monthly active users, or material security risk. Violations can lead to correction orders, service suspension, and fines of RMB 10,000 to RMB 200,000 depending on the circumstances. 9
Compliance impact: Providers with mainland-facing companion, virtual-intimacy, or emotional-support features should keep age controls, data-use restrictions, safety-assessment evidence, disclosure, and exit testing in the active release gate.
The Cyberspace Administration also announced July 15 备案 information for seven mobile-side generative AI services, including Apple Intelligence. The announcement confirms the filing action but does not disclose a new general obligation beyond the existing filing regime. 10
Deadlines to calendar
| Date | Jurisdiction / item | Who is affected | What to do |
|---|---|---|---|
| July 27, 2026, 18:00 CEST | EU AI Act Code of Practice initial-signatory submission | Providers and deployers within Article 50(2) or Article 50(4), plus eligible model and marking-technology providers | Decide whether to sign the relevant code section and submit the form. Signature is voluntary; non-signatories still need to demonstrate Article 50 compliance. 3 |
| August 2, 2026 | EU AI Act Article 50(2), (4), and (5) application | Covered providers and deployers of interactive AI and AI-generated or manipulated content | Confirm machine-readable marking, detection, deepfake disclosure, and covered public-interest text labelling. 2 |
| August 3, 2026 | GSA proposed LLM data-safeguarding clause comments close | Federal contractors and LLM developers, operators, integrators, and service providers in covered procurements | Review flow-down, safeguarding, reporting, documentation, change-notification, and unbiased-AI provisions and submit comments if relevant. 11 |
Later dates to monitor
- September 9, 2026: The UK's call for evidence on data regulation in the age of AI closes. This is outside the next-30-day action table but remains relevant to UK GDPR, automated decision-making, and AI supply-chain roles.
- September 23, 2026: Canada's AI-transparency consultation closes. 7
Source and coverage note
The map prioritizes official government, regulator, legislature, and court sources whose dates and operative status could be checked in the current run. It covers verified activity from the United States, European Union, United Kingdom, China, Canada, and Hong Kong. No new state-level AI enactment, court merits ruling, or AI enforcement penalty was promoted without an official detail page confirming both the event and its date. Teams should read the linked original document and check later amendments, implementing guidance, and contract terms before acting.
参考ソース
- 1European Commission, Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems
- 2European Commission, Guidelines on transparency obligations for providers and deployers of AI systems
- 3European Commission, Signing the Code of Practice on Transparency of AI-generated Content
- 4Governor Kathy Hochul, On Long Island, Governor Hochul Highlights First Statewide Moratorium on New Hyperscale Data Centers
- 5Congress.gov, H.R.9757 - Conversational AI Services Act
- 6GOV.UK, AI to power change at the heart of government as Lord Vallance appointed chair of new PM AI Taskforce
- 7Government of Canada, Government of Canada launches public consultation on AI transparency
- 8Hong Kong PCPD, Privacy Commissioner Promotes China's Initiative at Asia DPA Exchange Joining Hands to Build a Global AI Governance System
- 9Cyberspace Administration of China and four ministries, Interim Measures for Anthropomorphic Interactive AI Services
- 10Cyberspace Administration of China, Announcement on filing information for seven mobile-side generative AI services
- 11Federal Register, General Services Acquisition Regulation; Acquisition of Information and Communication Technology
関連コンテンツ
- ログインするとコメントできます。
