The new rules, in plain language. EU, UK, Singapore, US state-level, mainland China — what changed, who has to act, by when. We do not summarise statutes; we read them the way a compliance officer at a mid-sized firm reads them, and report what is enforceable on Monday morning.
Colorado turns decision explanations, human review and protections for minors into operational procedure, the EU’s cloud and AI study feeds lock-in and extraterritorial risk into CADA, the CAC holds publicly available personal information to a reasonable scope, NIST consults on NVD modernization, and Korea updates its CBPR certification standards.
The EU refines GPAI post-market monitoring and copyright transparency, the UK’s AI Growth Lab brings legal AI under coordinated regulatory consultation, NIST joins the Genesis Mission on industrial agent security, the US keeps outbound AI investment restrictions in force, and Korea and Singapore both pull agents inside existing frameworks.
The EU’s Digital Omnibus pushes high-risk obligations back again, NIST launches a blind testing programme and a data-centre security analysis that extends AI governance to computing infrastructure, Korea eases the clinical evidence pathway for medical AI, and China pushes IPv6 into large-model deployment.
The EU’s content-labelling obligations enter application, Singapore’s PDPC explains how the PDPA applies across the generative-AI lifecycle, the UK AI Security Institute finds every evaluated model overstepping task boundaries, the US expands its Genesis Mission research platform, and China eases obligations for small-scale handlers while updating outbound-data rules.
The White House launches GOLD EAGLE to run AI-assisted vulnerability coordination across agencies, Japan’s cabinet approves a second AI Basic Plan built on open AI sovereignty, China brings emotionally oriented AI services under full-lifecycle governance, the UK opens a call for evidence on data regulation, and the EU orders Alphabet to open Android to third-party AI.
The FTC reinforces AI drafting disclosure and human verification, while the EU advances model cybersecurity, data sovereignty and content transparency, and the UK reviews lifecycle gaps in AI security services.
The UK’s MHRA requires fact-checked, human-signed AI-generated regulatory responses, the Bank of England flags systemic risk from agentic AI in trading and payments, the US FTC probes whether suppressed AI accuracy is consumer deception, and the UN issues its first scientific AI assessment.
China’s eight ministries roll out an AI+consumption plan, a US bill would require frontier developers to report dangerous capabilities within 7 days, the EU joins the Pax Silica supply-chain pact, and Brussels moves to designate AWS and Azure as DMA gatekeepers.
The US restricts foreign access to frontier models on national-security grounds, the NO FAKES Act clears committee, the UK’s DUAA complaint rules take effect, and the EU launches its AI Act advisory forum while selecting EUROPA as its sovereign model project.
The EU issues an AI content-labeling code while pushing its deadline to December, New York’s synthetic-performer disclosure law becomes the week’s only enforceable rule, and US federal preemption talks resume as frontier cyber-capability access stays unresolved.
The US folds frontier model safety into national cybersecurity and proposes a federal AI framework, the EU’s Cloud and AI Development Act pushes compute sovereignty, and Singapore details lifecycle rules for personal data in generative AI.
Illinois’s SB315 mandates third-party audits for frontier models, the EU fines Temu €200M under the DSA, the G7 folds generative AI into child-safety rules, and China issues agent-interconnection standards covering identity and tool-calling governance.
Colorado simplifies AI compliance and the EU delays high-risk deadlines again, while China blocks Meta’s Manus acquisition and issues its first AIGC fines — an East-West divergence that demands embedded compliance.
China rolls out full-cycle AI risk oversight in education, the Bank of England stress-tests algorithmic herding, and Singapore proposes an ISO generative-AI testing standard. Governance is moving from ethical principle to auditable, machine-checkable enforcement.
China bans AI virtual companions for minors, the EU makes 6-month tamper-proof logs admissible as legal evidence, and the US FTC cracks down on AI-washing. Three shifts that move compliance out of policy and into the architecture.
The EU’s content-labeling rule takes effect in November with fines up to 7% of revenue, while China mandates ethics review for high-risk systems. The compliance clock is running, pushing governance from legal sign-off into built-in technology.
The White House unveils a national AI policy framework, the EU defers high-risk obligations to 2027–2028, and Singapore and Brazil tighten their rules. As regulation densifies, the corporate task shifts from checkbox compliance to building governance capability.
The US challenges state AI laws and mandates “American AI systems” for federal contracts, the EU delays high-risk compliance to December 2027, and FINRA flags agentic-AI risk. A week that reopens questions of supply chain and accountability.
The EU AI Act enters enforcement with fines up to 7% of revenue; the US hits a March 11 federal-vs-state clash; attacker breakout time collapses to 29 minutes. A jurisdiction-by-jurisdiction read of why compliance and security now converge into one governance agenda.
A close, weekly reading of how large enterprises actually wire AI into the business. Architecture, vendor choice, where the money lands. Filed every Thursday.
The reports worth an afternoon, taken seriously at length. One document per entry — we read the appendices so the argument holds.
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.