Global AI rules shift toward practical oversight
Global regulators are sharpening AI oversight around lifecycle governance, cybersecurity and sector-specific risk. IOSCO published a final supervisory toolkit for AI use in capital markets, while Hong Kong’s SFC warned licensed firms and virtual asset service providers about AI-enabled intrusion, phishing, deepfake impersonation and supply-chain threats. Hong Kong’s privacy regulator expanded compliance checks and Singapore updated its Model AI Governance Framework for Agentic AI, adding focus on multi-agent risks, third-party dependencies, logging and liability allocation.
EU policymakers moved to simplify AI Act compliance, including delayed high-risk AI timelines of December 2027 or August 2028, while EIOPA sought clearer treatment for insurers. The UAE advanced a national AI healthcare policy covering data governance, safety, licensing, liability and patient rights. In the UK, regulators focused on agentic AI adoption, copyright licensing and retail financial services, while a financial services skills report found that 30% to 50% of tasks in most roles will see significant automation.
US developments reflected an innovation-first federal stance alongside sharper platform and state-level obligations. The administration issued an Executive Order promoting AI innovation and security, the FTC began enforcing TAKE IT DOWN Act requirements for removal of nonconsensual intimate imagery within 48 hours, and Colorado, Connecticut and Illinois advanced major state AI measures, including independent audits for frontier AI safety in Illinois.