Welcome to AI View, Simmons & Simmons’ fortnightly round-up of key AI legislative, regulatory, and policy updates from around the world.
AI x Dispute Resolution Webinar Series
Our AI x Dispute Resolution webinar series is now well underway, bringing together lawyers from across our global disputes and AI teams to unpack how AI-related risk is translating into real-world litigation and regulatory exposure.
Across the first sessions, we have explored how disputes are already emerging in practice, from regulatory enforcement and collective actions to negligence, and what organisations should be doing now to prepare.
The series continues after the summer with a focus on some of the most complex and fast-evolving areas of AI risk, including:
- AI and IP - protecting rights and managing risk
- AI incident response and product liability
- Evidence in AI disputes
- Futureproofing against AI disputes through contracting and governance
Each session is designed to be practical and digestible, combining expert insight with clear takeaways for in-house legal, risk and compliance teams navigating this rapidly developing landscape.
If you have not already registered, you can sign up once to attend the remaining sessions and access recordings from those you may have missed here.
This edition brings you:
European Commission introduces action plan on cybersecurity and AI
Australian PM announces national AI framework with legislation expected in 2027
Vietnam designates official categories of high-risk AI systems
Singapore unveils safeguards framework for AI agents in finance
US Congress introduces People-First Chatbot Act for AI safety
1. Illinois enacts AI Safety Measures Act
On 6 July 2026, Governor of Illinois J.B. Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act (the Act), into law. The Act takes effect on 1 January 2027, with some obligations applying from 1 January 2028. Illinois has become the third US state to enact comprehensive frontier AI legislation, and the first to require independent third-party safety audits of frontier AI models.
The Act applies to developers of frontier models, which are defined as foundation models trained using computing power greater than 1026 integer or floating-point operations, including material modifications to an existing model. Enhanced obligations apply to large frontier developers, meaning frontier developers whose annual gross revenue, together with their affiliates, exceeded US$500 million in the preceding calendar year.
From 1 January 2027, large frontier developers may not develop, deploy or operate a frontier model in whole or in part in Illinois without filing a current disclosure statement with the Illinois Emergency Management Agency and Office of Homeland Security.
From 1 January 2028, or 90 days after first qualifying as a large frontier developer, in-scope developers must write, implement, comply with and publish a frontier AI framework. That framework must address, among other things, catastrophic risk thresholds, mitigations, third-party risk assessment, cybersecurity protections for unreleased model weights, internal governance, and the identification and response to critical safety incidents. The framework must be reviewed at least annually, with material changes published within 30 days together with a justification. A particularly notable feature of the Act is the requirement for annual independent third-party audits. From 2028, large frontier developers must retain an auditor with demonstrated competence in frontier model safety to assess compliance with the Act’s framework requirements.
Read the press release here.
2. European Commission introduces action plan on cybersecurity and AI
On 7 July 2026, the European Commission presented a new action plan on cybersecurity and AI, aimed at strengthening the EU’s cyber resilience as advanced AI systems become more capable and more widely used.
Rather than proposing new legislation, the action plan builds on the EU’s existing regulatory framework, including the AI Act, the Network and Information Security 2 Directive (NIS2), the Cyber Resilience Act, the Digital Operational Resilience Act (DORA) and the Cyber Solidarity Act. It is intended to coordinate the work of Member States, EU institutions and industry around the practical implementation of AI-related cybersecurity safeguards.
A central element of the action plan is the proposed creation of a dedicated EU evaluation capacity for advanced AI models, focused on cybersecurity risks. This capability, expected to become operational in 2027, will support the AI Office by carrying out independent assessments of advanced AI models’ capabilities and associated risks before or as they are placed on the EU market.
The action plan also places emphasis on existing cybersecurity fundamentals. The Commission highlights the continued importance of cyber hygiene, risk management and security-by-design, and encourages organisations to make greater use of AI tools, including open-source models, to improve vulnerability detection and cyber defence. The European Union Agency for Cybersecurity is expected to support this work through guidance, best-practice sharing and initiatives aimed at improving the security of critical open-source software.
Alongside these operational measures, the Commission has signalled further support for European AI innovation through a proposed EU Grand Challenge on AI for Cybersecurity and continued investment in sovereign AI infrastructure, including AI Factories and future Gigafactories.
Read the action plan here.
3. Australian PM announces national AI framework with legislation expected in 2027
On 15 July 2026, Australian Prime Minister Anthony Albanese announced a new national policy direction on AI, signalling a clear shift away from Australia’s previous reliance on voluntary AI governance tools. In a keynote speech titled AI in Australia’s interests, the Prime Minister said the Government will develop mandatory national AI Standards, supported by a new Office of AI within the Department of the Prime Minister and Cabinet, with legislation expected to follow in 2027.
The proposed standards are intended to create a single national framework covering the economic, social, national security and environmental dimensions of AI. In particular, the announcement suggests that the framework will extend beyond core questions of AI safety and accountability to address the infrastructure needed to support AI deployment at scale. This includes potential obligations for large AI data centres in areas such as energy efficiency, renewable power supply, grid connection costs and water usage. In parallel, the Government has signalled a firm position on copyright, stating that Australian works should not be used to train AI systems without rightsholder control, and continuing to rule out a text and data mining exemption.
This is a significant policy change. Australia had previously favoured voluntary standards and existing technology-neutral laws, but the Government now appears to have concluded that AI requires a more tailored and mandatory regulatory framework. Effective from 15 July 2026, the new Office of AI will coordinate the design of the standards across government. National Cabinet is expected to consider the proposed framework next month, underlining that enforceable AI-specific obligations may now be on the near-term horizon for businesses operating in or into Australia.
Read the official media release here.
4. Vietnam designates official categories of high-risk AI systems
On 30 June 2026, Vietnam published an official list of high-risk AI systems under Prime Ministerial Decision No. 33/2026/QD-TTg (Decision 33). The measure identifies AI systems that may cause significant harm to life, health, rights and legitimate interests of organisations and individuals, as well as to national interests, public interests and national security.
Prior to Decision 33, Vietnam's AI Law, adopted by the National Assembly in 2025, established a regulatory framework for high-risk AI systems but did not specify in detail which AI systems would fall within that category. Decision 33 fills that gap by identifying the AI systems that are classified as high-risk and therefore subject to enhanced regulatory requirements.
The list covers six sectors:
- Education: including AI used to provide self-study content based on educational curricula where uncontrolled data sources are used, systems that automatically test, evaluate and rank learners, and systems used to monitor and analyse learner behaviour.
- Ethnic and religious affairs: including systems used to score, classify or rank profiles for the purposes of determining beneficiaries or eligible regions, verify and decide on the validity of information relating to ethnicity and religion, or approve, reject, renew or revoke applications and state management decisions.
- Healthcare: including AI-assisted surgical systems and surgical robots, as well as other AI-controlled medical machinery, equipment and robotic systems.
- Banking: including systems that automatically perform electronic banking transactions and AI systems used to make credit-granting decisions. [S&S1.1]
- Judicial sector: including large-scale biometric identification systems used in resolving public civil cases.
- Transport: 31 high-risk systems, including high-level autonomous driving systems, AI systems controlling or automatically operating road and railway traffic signals, and AI systems used to manage and control transport infrastructure and other critical technical infrastructure.
Under Vietnam’s AI Law, high-risk AI systems must undergo a conformity assessment before being placed into service, and ongoing compliance obligations.
Decision 33 takes effect on 15 August 2026. For most new and existing AI systems within scope, compliance will be required by 1 March 2027. However, certain healthcare, education and financial AI systems already in operation before 15 August 2026 will benefit from a longer transition period, with compliance required by 1 September 2027.
Read Decision 33 here (only available in Vietnamese).
5. Singapore unveils safeguards framework for AI agents in finance
On 3 July 2026, Singapore’s Monetary Authority of Singapore (MAS), together with a group of financial institutions and fintech firms, published an industry white paper on safeguards for the use of AI agents in financial services. The paper, titled “Safeguards for Agentic Finance at Runtime” (the Paper), sets out a framework intended to help ensure that AI agents carry out financial tasks safely, securely and reliably as they take on more autonomous roles.
The Paper reflects growing regulatory and industry focus on the shift from AI as a decision-support tool to AI as an active participant in financial workflows. MAS said the framework is designed to address the risks that arise where AI agents operate autonomously and at speeds beyond practical human intervention. The Paper therefore proposes a set of governance checkpoints that verify and record an AI agent’s proposed actions before execution, with the aim of keeping those actions within predefined mandates, policies and risk limits.
MAS said the Paper focuses more specifically on how safeguards can be applied at runtime, which is at the point where an agent acts, rather than only at the design, testing or review stage. According to MAS, industry participants have already tested the framework across a number of use cases, including payments and treasury operations, wealth management and advisory workflows, compliance reviews, and client engagement. These pilots suggest that the framework is intended to support deployment in areas where AI agents may execute routine transactions, review documents, generate structured outputs, or assist with customer-facing materials, while remaining subject to defined task boundaries and oversight mechanisms.
Read the Paper here.
6. US Senator releases draft bill on safe use of AI agents
On 29 June 2026, US Senator Mark Warner released a discussion draft of the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act of 2026 (the Draft Bill).
The Draft Bill would establish a federal framework for AI agents acting on behalf of users online. In particular, it is aimed at protecting user choice, promoting competition and preventing large online platforms from favouring their own in-house AI agents over competing third-party agents. The Draft Bill refers to such user-designated agents as Custodial User Agents (CUAs).
Under the Draft Bill, individuals would be able to designate one or more CUAs to act on their behalf in online interactions, including in areas such as e-commerce, user-generated content and account settings. CUAs are defined as software-based agents expressly authorised by a user to interact with large online platforms in a transparent, documented, scope-limited and revocable manner.
The Draft Bill would impose obligations both on CUAs and their providers and on large online platform providers. CUA providers would be required to register with the Federal Trade Commission (FTC) before acting as a user’s representative. CUAs would also be required to safeguard user privacy and security, maintain real-time records of actions taken on a user’s behalf, and implement reasonable measures to ensure compliance. CUAs and CUA providers would be prohibited from acting in ways that benefit the agent to the detriment of the user, using user data beyond what is reasonably necessary to provide the service, or delegating authority to another entity without the user’s express and revocable consent.
Large online platforms, which are defined as those with at least 50 million US customers or subscribers in any of the previous 12 months, would be required to maintain an interoperable interface allowing authorised CUAs to act on behalf of users on fair, reasonable and non-discriminatory terms.
The Draft Bill has not yet been formally introduced in Congress and is intended to invite stakeholder feedback.
Read the Draft Bill here.
7. US Congress introduces People-First Chatbot Act for AI safety
On 9 July 2026, US lawmakers introduced the People-First Chatbot Act (the Bill), aimed at establishing a federal framework for the safety, transparency and accountability of AI chatbots. The Bill focuses on consumer-facing chatbot services and seeks to address concerns around deceptive design, harmful data practices, over-reliance, and the use of chatbots in sensitive contexts.
The Bill would require companies operating AI chatbots to provide clear disclosures that users are interacting with AI rather than a human, and to notify consumers where a chatbot is used in customer service. It would also give users the right to request transfer to a human operator in those contexts.
A central feature of the Bill is its focus on data privacy and user protections. The proposal would prohibit companies from using minors’ chat logs or personal data to train AI chatbots, and from using adults’ input data for training without affirmative consent. It would also restrict the use of chat logs and personal data for practices such as targeted advertising and other potentially manipulative uses, including companion-style features designed to encourage emotional dependence. Users would also be given rights to access and delete retained chat logs and personal data.
The Bill also proposes substantive restrictions on chatbot design and deployment. It would prohibit chatbots from representing that they can provide qualified medical, financial or legal advice, and would require providers to carry out monthly assessments of risks including covered harms, emotional dependency and compulsive usage. Companies would also be required to disable harmful chatbot design features for minors.
Read the Bill here.
8. Malaysia launches consultation on AI governance bill
On 10 July 2026, Malaysia’s National AI Office (NAIO) released a public consultation paper on its proposed AI Governance Bill (the Bill).
The Bill would regulate AI systems across the entire AI lifecycle, from early development through to withdrawal.
To establish clearer accountability, the Bill distinguishes between two principal regulated actors: Developers and Deployers. A Developer is any person or organisation that materially shapes what an AI system can do, how it functions, how well it performs, what limits are built into it, or what risks it may create. A Deployer is the person or organisation that causes the AI system to operate in the real world, including by deciding whether, where, how and under what conditions it is used. Depending on their role, organisations may be regulated as a Developer, a Deployer, or both.
The proposed territorial scope is also wide. The Bill is intended to apply to AI systems that are placed on the market or put into service within Malaysia, designed, developed or used in Malaysia, or used by a Deployer established in Malaysia, regardless of where the system is physically hosted.
A central feature of the proposal is the creation of a new Central AI Authority, intended to provide a centralised governance architecture and reduce regulatory fragmentation. The Authority would be expected to oversee and operationalise national baseline standards and to perform three core functions: AI safety, including maintaining a risk framework and incident reporting mechanisms; investigation and enforcement, including technical fact-finding where AI incidents occur; and AI enablement, including guidance, templates, training and sandbox oversight.
The consultation paper also sets out a harm-anchored AI risk framework. Four categories of harm are proposed as the base threshold for assessing risk: death, bodily injury, unlawful deprivation of fundamental liberty anchored to the Federal Constitution, and contravention of written law. AI systems would then be classified into three tiers: Tier 1 (Unacceptable Risk), covering systems developed or deployed with intent to cause harm and therefore prohibited; Tier 2 (High Risk), covering systems that create a risk of harm even without harmful intent; and Tier 3 (Low Risk), covering systems that do not show foreseeable material AI harm. The Central AI Authority may then impose mandatory or voluntary requirements depending on the class of system, sector or deployment context.
The consultation will remain open until 31 July 2026.
Read the consultation here.







.jpg?crop=300,495&format=webply&auto=webp)
.jpg?crop=300,495&format=webply&auto=webp)




.jpg?crop=300,495&format=webply&auto=webp)



.jpg?crop=300,495&format=webply&auto=webp)
_11zon.jpg?crop=300,495&format=webply&auto=webp)