Regulators sharpen AI oversight across markets, finance and safety
Global AI regulation is shifting toward more targeted supervision, with IOSCO publishing a final toolkit for AI use in capital markets and Asian regulators expanding scrutiny of cyber, privacy and agentic AI risks. Hong Kong’s Securities and Futures Commission warned that frontier models are lowering the cost and expertise needed for cyberattacks, while Singapore updated its governance framework to address multi-agent systems, third-party dependencies, oversight, logging and liability questions.
European policymakers advanced efforts to simplify AI Act compliance while clarifying high-risk classifications and sector overlap for insurers. The Council of the EU and European Parliament agreed to delay some high-risk AI timelines to December 2027 or August 2028, extend relief for smaller companies, tighten rules on non-consensual sexual or intimate content, and shorten the transparency grace period for AI-generated content to three months.
The UAE adopted a national AI healthcare policy covering data governance, safety, quality, licensing, liability and patient rights. In the UK, regulators focused on workforce change, AI copyright licensing, agentic AI adoption risks and the FCA’s Mills Review on retail financial services by 2030. In the US, federal policy favored innovation and security, while the FTC began TAKE IT DOWN Act enforcement requiring removals within 48 hours and exposing platforms to civil penalties of up to $53,088 per violation.