
AI Compliance Map - Jul 10-17, 2026
Weekly compliance impact map for July 10-17, 2026, covering binding EU and China actions, US federal proposals and litigation, UK data and financial-services policy, Canada supervisory guidance, and deadlines through October.
Coverage and readout
This issue covers newly verified developments and newly actionable deadlines from July 10 at 5:00 p.m. through July 17 at 5:00 p.m. (UTC-05:00). The strongest immediate signals are the EU's binding DMA specifications for AI assistants and search data, China's new rules for anthropomorphic AI services, and a cluster of US proposals that would put human oversight, AI claims, and automated health-care decisions under closer scrutiny. Legislative introductions and policy statements below are not law unless expressly identified as effective or binding.
A primary-source check did not verify a new US state AI enactment or a court ruling issued inside this window. One new federal employment lawsuit is included as a litigation watch item, clearly labeled as a filing rather than precedent.
Executive action list
- Map the EU DMA decision to product and data-access workstreams. Google's Android AI-assistant access and search-data sharing obligations now have detailed Commission specifications.
- Recheck China service scope before serving mainland users. Order No. 21 applies to continuous, emotionally oriented anthropomorphic interaction, not ordinary customer support or knowledge Q&A.
- Put the July 27 EU code-signature date and August 2 Article 50 date on the calendar. Signing is voluntary; the underlying transparency obligations are not.
- Ask US public-sector and health-care teams to review the pending proposals. GSA comments close August 3, FTC AI-accuracy comments close July 31, and H.R. 9734 would target AI-assisted Medicare Advantage prior-authorization denials.
- Have Canadian financial institutions test agent permissions, logging, human oversight, and third-party concentration. OSFI's new bulletin treats generative and agentic AI as a technology, cyber, operational, and third-party risk issue.
United States: federal policy and litigation
Export controls: UAE advanced-computing access expanded
Date / status: BIS published the rule on July 14; it is effective July 10. Scope: The rule moves the United Arab Emirates into more favorable country-group treatment and expands license exceptions for specified UAE government entities and approved commercial entities, while preserving end-use and end-user restrictions. It also identifies named entities, including G42, Core42, and listed subsidiaries of several US-headquartered AI companies, for specified advanced-computing treatment. 1
Compliance impact: Exporters can reassess whether eligible UAE transactions qualify for license exceptions or license-free treatment, but must preserve records, complete applicable filings, and continue screening against Part 744 restrictions; the rule does not create a blanket UAE carve-out.
FARM AI Act introduced in the House
Date / status: Introduced July 14 and referred to the House Agriculture Committee. Scope: H.R. 9686, the FARM AI Act of 2026, would increase access to AI through Department of Agriculture programs; it has no enacted obligation and no bill summary was available on Congress.gov at the cutoff. 2
Compliance impact: Agriculture, food, and AI vendors should treat this as an early federal funding and program-design signal, not a present compliance duty, and monitor the Agriculture Committee for text and implementation conditions.
School AI-literacy bill introduced in the Senate
Date / status: Introduced July 14 and referred to the Senate Health, Education, Labor, and Pensions Committee. Scope: S. 4958 would amend the Elementary and Secondary Education Act to enable schools to teach students about the dangers, limitations, and responsible use of AI; Congress.gov reported that text had not yet been received as of July 17. 3
Compliance impact: Education-sector AI providers should expect procurement and curriculum conversations to emphasize safety, limitations, and responsible use, but no provider-facing requirement exists at introduction.
Medicare Advantage AI-denial bill introduced
Date / status: Introduced July 16 and referred to the House Ways and Means and Energy and Commerce Committees. Scope: H.R. 9734 would establish requirements for the use of AI in prior-authorization denials by Medicare Advantage organizations. 4
Compliance impact: Medicare Advantage plans and their AI vendors should preserve model, reviewer, notice, and appeal records that could be needed if human-review and denial-transparency requirements advance; the bill is not yet law.
Human control over autonomous weapons proposed
Date / status: Bipartisan House legislation was introduced July 17; the official release does not state a bill number. Scope: The Human Authority over Autonomous Weapons Act would require meaningful human oversight or a human decision-maker before a US military autonomous or AI-enabled weapon system carries out an intentionally lethal strike. 5
Compliance impact: Defense contractors should map AI-enabled targeting functions, approval chains, audit logs, and contractual representations against a possible statutory human-control standard; the proposal has no present effect.
Litigation watch: Meta employees challenge AI-assisted layoff selection
Date / status: A lawsuit by 26 current Meta employees was reported as filed in federal court in Oakland, California, on July 13; the report describes claims under the FMLA, ADA, Pregnancy Discrimination Act, Pregnant Workers Fairness Act, and Title VII disparate-impact theory. The plaintiffs allege that AI systems, activity-monitoring data, token-use dashboards, and algorithmic performance rankings were used in layoff selection; no damages amount was stated, no merits ruling was reported, and the plaintiffs sought to remain employed pending arbitration. 6
Compliance impact: Employers using AI in workforce reductions should test for protected-leave and disability-related disparate impact, document individualized review, and preserve the inputs and human decisions behind selection outcomes; this filing is not a court precedent.
European Union: binding platform action and supervisory risk
Commission specifies Google's AI interoperability and search-data duties
Date / status: The European Commission issued two binding DMA specification measures on July 16. Scope: Google must give competing AI assistants access to specified Android functions, including voice activation and actions in other apps, with privacy and security safeguards. Google must also make anonymized search data available under a defined access and pricing process; AI chatbots with search functions are eligible recipients. 7
Compliance impact: Google and competing assistant providers should review Android integration, delegation permissions, data-access eligibility, anonymization, security assessment, and pricing workflows; the measures are binding on Google, while competitors gain a structured access route.
ESRB publishes frontier-AI cyber-risk warning
Date / status: The European Systemic Risk Board's warning was adopted June 25 and published in the Official Journal on July 16. Scope: It identifies systemic cyber risks from frontier AI models and calls on authorities and financial institutions to build governance, resilience, coordinated response, and board accountability. ECB banking supervision has asked significant institutions to assess the evolving threat immediately and submit a comprehensive action plan by October 31, 2026. 8
Compliance impact: Significant institutions should treat frontier-model dependency, autonomous actions, model updates, prompt and tool access, concentration risk, and manual fallback as items for the October action plan; the ESRB warning is supervisory risk guidance rather than a new AI Act penalty.
United Kingdom: sector plans and data-law review
Financial-services AI adoption plan accepted
Date / status: HM Treasury published the independent Financial Services AI Adoption Plan on July 14 and said it accepts the recommendations for government. Scope: The ten recommendations cover regulatory clarity, AI-generated financial advice and the regulatory perimeter, resilience, skills, and agentic payments. The plan recommends work by government, the FCA, PRA, ICO, CMA, and industry; it is a policy plan, not a new binding rule. 9
Compliance impact: Financial firms should inventory AI advice-like outputs, customer disclosures, model-risk controls, critical third-party dependencies, and agentic-payment authorization because those are the areas most likely to shape future supervisory guidance and perimeter decisions.
Data regulation in the age of AI: evidence call opens
Date / status: The UK government opened the call for evidence on July 15; responses close at 11:59 p.m. on September 9, 2026. Scope: The review seeks practical evidence on UK GDPR and Data Protection Act 2018 rules as they apply to personal and non-personal data used by AI and other data-intensive technologies, including lawful basis, purpose limitation, data minimization, automated decision-making, supply-chain roles, transparency, and data-subject rights. 10
Compliance impact: Companies with UK AI data pipelines should preserve evidence on legal basis, provenance, controller/processor allocation, rights handling, and agent authority so their operational experience can inform the review and their current compliance file.
Ofqual replaces its AI qualifications approach
Date / status: Ofqual updated the policy page on July 16 and published a replacement approach for England. Scope: Awarding organizations remain responsible for valid, reliable, and fair outcomes, human oversight, quality assurance, and accountability. AI cannot be the sole marker for a regulated qualification, and undisclosed student AI use in non-exam assessment can undermine qualification integrity. 11
Compliance impact: Awarding organizations and assessment vendors should document human review, test validity and reliability, control remote-invigilation evidence, and maintain malpractice controls rather than relying on an automated score or detector alone.
China: anthropomorphic services move into force
Order No. 21 governs continuous emotional-interaction services
Date / status: The Cyberspace Administration of China and four other ministries issued the measure on April 10; it took effect July 15. Scope: The rules cover services offered to the public in China that continuously simulate human personality, thought, and communication for emotional care, companionship, or support. They require safety-responsibility systems, lifecycle risk monitoring, training-data controls, age and guardian safeguards, interaction-data protections, AI disclosure, exit routes, complaint handling, and safety assessments for launches, major changes, services with at least 1 million registered users or 100,000 monthly active users, or material security risk. 12
Compliance impact: Providers serving mainland users should classify companionship and virtual-intimacy features separately from ordinary support or Q&A, implement age gating and guardian controls, limit sensitive interaction data in training, add prominent AI and time-use reminders, and prepare safety-assessment and algorithm-filing evidence; violations can trigger correction orders, service suspension, and fines of RMB 10,000-200,000 depending on circumstances.
Shanghai governance speech sets a nonbinding international policy direction
Date / status: President Xi Jinping delivered the keynote at the World AI Conference and Global AI Governance High-Level Meeting in Shanghai on July 17. Scope: The speech called for a fairer global AI governance system and announced cooperation commitments including 5,000 AI training places for developing countries over five years, international AI application cooperation centers, and deployment of the "Mazu" weather-warning solution in 30 countries. The source presents these as policy and cooperation commitments, not directly enforceable company obligations. 13
Compliance impact: Multinational policy teams should treat this as a signal of China's international-governance and capacity-building agenda, not as a new product-control deadline; watch follow-on agreements for operational rules.
Canada: financial-sector supervisory guidance
OSFI bulletin addresses generative and agentic AI
Date / status: OSFI published a technology-risk bulletin in July 2026. Scope: The bulletin links generative and agentic AI to existing B-13 technology and cyber-risk management, E-21 operational risk and resilience, and B-10 third-party risk expectations. It highlights hallucination, autonomous actions, excessive permissions, data leakage, insecure code, model and tool changes, cyber misuse, correlated outages, and vendor concentration, and recommends human oversight, least privilege, logging, testing, manual fallbacks, and third-party disclosure. 14
Compliance impact: Federally regulated financial institutions should fold agent identities, tool allow-lists, prompt and output monitoring, code-release checkpoints, dependency mapping, and AI-specific incident playbooks into existing technology, operational, and third-party risk programs.
Deadlines and dates to calendar
| Date | Jurisdiction / item | Who is affected | What to do |
|---|---|---|---|
| July 27, 2026 | EU AI Act transparency Code of Practice signing window | Providers and deployers of in-scope generative AI systems | Treat July 27 at 18:00 CEST as the official submission date for initial-signatory consideration; use the code as a compliance framework, but do not confuse voluntary signature with the underlying duty. 15 |
| July 23, 2026 | EU draft high-risk AI classification guidelines consultation closes | Providers, deployers, market-surveillance authorities, and other stakeholders | Submit or finalize comments on the Article 6 classification examples; the guidelines are interpretive and not themselves a new binding obligation. 16 |
| July 31, 2026 | US FTC policy statement on AI accuracy comments | AI vendors, advertisers, users, and other interested parties | Submit comments on the proposed policy statement addressing AI accuracy claims; audit substantiation for performance and efficacy claims now. 17 |
| August 2, 2026 | EU AI Act Article 50(2), (4), and (5) transparency obligations apply | Providers and deployers of covered generative AI systems and relevant content publishers | Confirm machine-readable marking, deepfake disclosure, and covered public-interest text labelling; non-signatories remain responsible for demonstrating compliance by other adequate means. 15 |
| August 3, 2026 | US GSA proposed GSAR 552.239-7001 comment deadline | Federal contractors and LLM developers, operators, integrators, and service providers in covered procurements | Review the proposed government-data safeguarding, flow-down, reporting, change-notification, and unbiased-AI provisions and submit comments. 18 |
| September 9, 2026 | UK data-regulation call for evidence closes | Organizations operating AI or other data-intensive technologies in the UK | Submit evidence on lawful basis, data minimization, automated decisions, supply-chain roles, transparency, and rights handling. 19 |
| October 31, 2026 | ECB action-plan date referenced in ESRB frontier-AI warning | Significant institutions under ECB banking supervision | Prepare a comprehensive plan addressing frontier-model cyber risk, governance, resilience, dependencies, and response. 8 |
Source and coverage note
The time window is publication or action-date based; older rules are included only where a new effective date, official update, publication, or actionable deadline fell inside the window. No new state-level enactment or court ruling was promoted to a headline without a primary source confirming the event and date. Before acting on any item, teams should read the linked original document and confirm whether later amendments, implementing guidance, or a jurisdiction-specific contract term changes the result.
参考ソース
- 1BIS, Enhanced Favorable Treatment for the United Arab Emirates Under the Export Administration Regulations
- 2Congress.gov, H.R. 9686 - FARM AI Act of 2026
- 3Congress.gov, S. 4958 - AI education bill
- 4Congress.gov, H.R. 9734 - AI in Medicare Advantage prior-authorization denials
- 5Office of Rep. Don Beyer, Human Authority over Autonomous Weapons Act
- 6ABC7 New York, Meta employees sue over alleged AI-driven layoff selection
- 7European Commission, DMA specifications for Google AI interoperability and search data
- 8EUR-Lex, ESRB Warning ESRB/2026/3 on systemic cyber risks from frontier AI models
- 9HM Treasury, AI Adoption Plan: Financial Services
- 10GOV.UK, Data regulation in the age of AI and other data-intensive technologies
- 11Ofqual, Approach to regulating AI in the qualifications sector
- 12Cyberspace Administration of China, Interim Measures for Anthropomorphic Interactive AI Services
- 13Ministry of Foreign Affairs of the People's Republic of China, Xi Jinping keynote at the 2026 World AI Conference
- 14OSFI, Generative and Agentic Artificial Intelligence: Implications for Technology, Cyber Security, and Operational Resilience
- 15European Commission, Signing the Code of Practice on Transparency of AI-generated Content
- 16European Commission, Targeted consultation on draft high-risk AI classification guidelines
- 17FTC, Public comment on policy statement addressing AI accuracy
- 18Federal Register, GSA proposed AI/LLM data-safeguarding clause
- 19GOV.UK, Data regulation in the age of AI call for evidence
関連コンテンツ
- ログインするとコメントできます。
