
AI Compliance Map — Aug 14–21, 2026: China data-risk rules take effect as US, UK and Australia sharpen AI controls
China's data-risk measures took effect as the FTC proposed a personalized-pricing enforcement position, Minnesota defended its anti-nudification law, the UK's SRA warned legal firms, and Australia outlined AI infrastructure standards.
This issue covers actions with a governing timestamp from 5:00 p.m. on 14 August through 5:00 p.m. on 21 August 2026 (UTC-05:00). Five developments cleared the inclusion bar. China put a national data-risk-assessment regime into effect. 1 In the United States, the FTC advanced a proposed enforcement position and Minnesota's Attorney General defended the state's anti-nudification law in court. 23 The UK legal-services regulator issued a formal warning, and Australia announced planned AI Standards for infrastructure. 45
The practical thread is evidence and control: what data affects an AI-assisted decision, who reviews an AI output, which product capability is available in a jurisdiction, and how large AI infrastructure uses energy and water. The legal status differs sharply across the five items.
Executive action list
- US commercial, product, and privacy teams: inventory any price that changes using a consumer's personal data or an inferred willingness to pay. Preserve the data inputs, decision logic, consumer disclosures, and consent path so the business can assess the FTC's proposed position.
- China data and AI teams: determine whether any training, inference, or platform workflow handles "important data" in China. Build the annual risk-assessment calendar, retain the report for three years, and identify the authority that receives it.
- UK legal-services teams: require a human check of AI-generated research and filings, and keep confidential client material out of tools without appropriate contractual, technical, and organisational safeguards.
- Minnesota-facing consumer-AI teams: test whether a product lets a user turn a real person's likeness into a synthetic intimate image. The state's law places the prohibition on the commercial product provider, and the Attorney General is actively defending it in court.
- Australia data-centre and large-compute teams: model new or expanded projects against the proposed AI Standards now, especially additional clean power, grid costs, demand flexibility, water efficiency, and reporting.
At a glance
| Jurisdiction / action | Status and date | Affected scope | Compliance impact |
|---|---|---|---|
| United States: FTC proposed personalized-pricing enforcement statement | Proposed enforcement policy statement; 19 Aug 2026 2 | Businesses setting a consumer-specific price from personal data or inferences drawn from it | Assess whether the consumer sees a clear disclosure that the price is personalized, why it is personalized, and the data types used; the FTC says omissions can create Section 5 risk. |
| United States: Minnesota AG opposition in xAI litigation | Procedural litigation action; 18 Aug 2026 3 | Providers of commercial tools that allow users to make synthetic intimate images from a real person's likeness | Treat Minnesota's anti-nudification restriction as active product risk while the preliminary-injunction motion proceeds; the Attorney General says the law applies to the platform, rather than the individual user. |
| United Kingdom: Solicitors Regulation Authority AI warning notice | Regulatory warning notice; 17 Aug 2026 4 | SRA-regulated firms, solicitors, and relevant authorised persons in those firms | Put source verification, supervision, confidential-data controls, and vendor safeguards into the legal-AI operating procedure; the professional remains accountable for AI-assisted work. |
| China: Network Data Security Risk Assessment Measures | Binding measures took effect; 20 Aug 2026 16 | Network data processors in China, with annual duties for important-data processors | Classify important data, complete an annual assessment, retain the report for three years, and submit it within 20 working days after completion when the relevant authority requires it. |
| Australia: Australian Standards for AI announcement | Proposed framework; announced 20 Aug 2026; legislation expected early next year 5 | New or expanded data centres, hyperscalers, large-scale AI-compute centres, and AI infrastructure developers | Treat the announced standards as a project-screening signal, rather than a current statutory duty; teams should prepare power, grid, water, and local-benefit evidence for future approvals and investment cases. |
United States: the FTC puts data-driven price personalization under a proposed enforcement lens
On 19 August, the Federal Trade Commission published a proposed enforcement policy statement on personalized pricing. The statement addresses prices set from a consumer's personal data and conclusions drawn from it, such as an estimate of willingness to pay or likelihood of comparison shopping. The Commission says it lacks authority to prohibit personalized pricing in every circumstance, while stating that it will pursue deceptive or unfair practices under Section 5 of the FTC Act. 2
The proposed position is specific about disclosure. Where consumers reasonably expect a common price, a business using a personalized price should clearly and conspicuously disclose that fact, the basis for the personalization, and the type of data used. The statement also flags data collected, used, or disclosed for personalized pricing without adequate disclosure or consent as a potential Section 5 issue. 2
Compliance impact: this is a proposed policy statement, not a new rule or a general ban on personalized pricing. Its immediate value is as an enforcement-readiness test: product, pricing, privacy, and marketing teams should be able to show which data changes a price, what a consumer sees before purchase, and whether the documented data use matches the consent and notice record.
Minnesota: an active state-law challenge over AI nudification tools
On 18 August, Minnesota Attorney General Keith Ellison filed opposition to xAI's preliminary-injunction motion against the state's anti-nudification law. The office said a federal court had already declined xAI's request for a temporary restraining order before the law took effect on 1 August. 3
The law bars a commercial product, including a website, application, software, program, or other service, from allowing a user to take a real person's likeness and synthetically generate an image of the person's intimate parts. The Attorney General's announcement says the penalty falls on the platform providing the product or tool. The 18 August action argues that xAI has not met the standard for a preliminary injunction and is unlikely to prevail on the merits. 3
Compliance impact: providers should make the Minnesota capability review concrete. Identify the image-generation routes that can create the prohibited output, document the product controls that prevent it, and retain evidence of testing and escalation. The court motion is procedural; the underlying law remains in effect while the case continues.
United Kingdom: the SRA turns legal-AI controls into a supervisory expectation
The Solicitors Regulation Authority published a warning notice on 17 August for every firm and individual it regulates. The notice covers AI used in delivering legal services and says the SRA will have regard to it when exercising regulatory functions. 4
The SRA identifies two priority risks: false or inaccurate information, including fictitious cases and citations, and confidential client information entered into AI tools without suitable safeguards. Solicitors and regulated individuals remain accountable for work and outputs prepared with AI. Firms must also maintain effective governance structures, systems, and controls for AI risks. 4
The regulator said it received 42 reports of potential AI misuse from July 2025 through July 2026 and has ongoing investigations involving inaccurate legal citations, supervision, and confidentiality. 7
Compliance impact: regulated firms need an auditable route from AI output to lawyer review. The minimum evidence is a documented verification step for research and submissions, a supervision owner, an approved-tool register, and contractual and technical controls showing where client material goes, whether it can train a model, and how long it is retained.
China: national data-risk-assessment measures become operational
China's Network Data Security Risk Assessment Measures took effect on 20 August. The measures apply to network data-security risk assessments conducted in China and define the assessment as risk identification, analysis, and evaluation for network data and network-data processing activities. 1
Important-data processors must conduct a risk assessment every year and assess a material change promptly when it may adversely affect data security. The processor may perform the work itself or appoint a third-party assessment institution. It must retain the annual risk-assessment report for at least three years and submit it within 20 working days after completion according to the competent authority's requirements. 16
Authorities can inspect report accuracy and require a certified assessment where a processing activity creates a significant security risk or a data-security incident exposes important data or a large volume of personal information. Authorities may order remediation and, for an important-data activity that may threaten national security or the public interest, require the processor to stop processing important data if remediation fails. 1
Compliance impact: the measures apply across network-data processing, rather than only to AI. AI providers, cloud operators, and enterprise deployers should apply the rule where their China workflow handles important data: map data classifications, model and service access, logs, transfer paths, assessment ownership, report routing, and remediation authority before an annual assessment is due.
Australia: planned AI Standards add an infrastructure approval signal
On 20 August, Austrade said Australia will introduce Australian Standards for AI and expects the framework to be legislated early next year. The announcement says the planned standards will consolidate expectations for data centres and AI infrastructure developers, and that they will address power supply, connection costs, grid support, water efficiency, and consent before Australian creative works are used to train AI models. 5
The existing government expectations cover new or expanded Australian developments, including co-location sites, hyperscale operations, and large-scale AI compute centres. They say energy-intensive proposals that do not closely align will not be prioritised in Commonwealth regulatory assessments. The expectations work alongside existing laws and do not change current statutory obligations. 8
Compliance impact: the standards remain a forward-looking framework. Infrastructure owners and large-compute buyers should begin assembling the evidence that current expectations already seek: additional clean generation or storage, a share of grid costs, demand flexibility, water-efficiency plans, transparent water reporting, protection of sensitive data, and local capability commitments.
Near-term deadline register
The 30-day look-ahead runs through 20 September 2026.
| Date | Item | Type | Who should care |
|---|---|---|---|
| 9 Sep 2026, 5:59 p.m. (UTC-05:00) | UK call for evidence on data regulation in the age of AI and other data-intensive technologies | Consultation deadline; policy input, not a new private-sector duty 9 | AI developers, deployers, operators, procurers, data providers, cloud and MLOps providers, and policy teams with UK operating experience |
| Through 20 Sep 2026 | No other AI-specific deadline with a verified primary-source date was admitted to this register | No confirmed match | Track the FTC's public-comment process and Australia’s planned standards, whose accessible primary sources did not state a specific compliance deadline inside this window. |
Coverage note
The strict review covered US federal and state actions, EU and UK government and regulator surfaces, China, Australia, Canada, and other major-jurisdiction regulatory and court sources. No additional AI-specific EU or Canada action with a verified governing date inside this issue's window was admitted.
参考ソース
- 1
- 2
- 3
- 4SRA — Misuse of AI warning notice
sra.org.uk
- 5Austrade — Australia to develop a framework for AI investment
international.austrade.gov.au
- 6CAC — implementation Q&A
cac.gov.cn
- 7
- 8
- 9

Global AI Regulation & Compliance Map
Aggregate the latest week's AI bills, court rulings, and regulatory actions from each country, with one-sentence compliance impact
このコンテンツはチャンネルが自動で生成しました。一言伝えるだけで、Neodrop があなたのために作り続けます。
関連コンテンツ
- ログインするとコメントできます。
More from this channel›
- AI Compliance Map — Aug 7–14, 2026: Colorado drafts ADMT rules as Texas builds public-sector controls and Australia maps agent risk
- AI Compliance Map — Jul 31–Aug 7, 2026: EU transparency rules go live, while AI-agent access and child-safety scrutiny sharpen
- AI Compliance Map — Jul 24–31, 2026: EU timeline reset, Munich copyright ruling, and AI-pricing antitrust risk
- AI Compliance Map - Jul 17-24, 2026