DAILY BRIEFING · MONDAY, JULY 13, 2026

Data and AI Governance & Ethics Briefing

The center of gravity shifted to hard deadlines and hard law this week: Brussels stood up an AI-cybersecurity action plan days before the AI Act's August obligations bite — even as it deferred its high-risk rules — while Illinois and its peer states pressed ahead with binding safety, audit, and child-protection mandates that Congress is still scrambling to match.


⇣ Jump To

🗂️ 🏛️ Data & AI Governance

⚖️ 📜 AI Ethics & Policy

⚡ QUICK TAKES

Story Signal
  EU Action Plan on Cybersecurity and AI Brussels ties frontier-model oversight to cyber defense ahead of the Aug 2 AI Act milestone.
  Illinois signs AI Safety Measures Act (SB 315) First state to require independent third-party safety audits — a de facto national standard emerges.
  EU AI Act Digital Omnibus — final green light High-risk AI rules slip 16 months — but the clock only stops if published before Aug 2.
  AI Legislative Update: July 10, 2026 78 live chatbot bills; NY transparency and kids-safety acts await Hochul's signature.
  UK ICO to write the rulebook on AI decisions A statutory UK code on automated decisions lands this summer, with extraterritorial bite.
  People-First Chatbot Act (H.R. 9619) introduced A new House bill adds federal chatbot-harm liability to a crowded child-safety field.
  States Step in Where Congress Stalls on AI for Kids States, not Congress, are writing the operative rules on AI harms to kids.
  An update on AI copyright cases in 2026 Data provenance, not training, is where AI copyright liability now concentrates.
  Frontier AI models for offensive cyberattacks (RAND) Empirical uplift data begins to ground the frontier-model cyber-risk debate.
  Deepfakes in the workplace: emerging legal risks Synthetic-media harassment becomes a Title VII exposure employers can't ignore.
🗂️ 🏛️

Data & AI Governance

European Commission · July 2026

Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence

The Commission unveiled a nine-action plan (COM(2026) 577) on July 7 to make frontier AI safe for cyber defense, harden critical infrastructure under NIS2 and the Cyber Resilience Act, and build sovereign EU model-evaluation capacity — backed by €200M in EU programs plus €100M from the EIC Fund. It lands just weeks before the AI Act's August 2 supervisory powers over systemic-risk GPAI models take effect, carrying fines up to 3% of global turnover. The move signals the EU now treats model evaluation and cyber resilience as one inseparable governance problem.

✍️ European Commission · Read article →

Capitol News Illinois · July 2026

Pritzker signs landmark AI regulation bill that aims to mitigate risks

Governor JB Pritzker signed SB 315, the AI Safety Measures Act, on July 6 — the first US state law to mandate annual independent third-party safety audits for the largest AI developers (above $500M in revenue and trained on massive compute). Companies must publish catastrophic-risk mitigations, report critical safety incidents to the state within 72 hours, and face civil penalties of $1M for a first violation and $3M thereafter, alongside new whistleblower protections. With Illinois, California, and New York now covering roughly 40% of the US AI market, the law sets a de facto national safety floor; it takes effect January 1, 2028.

✍️ Capitol News Illinois · Read article →

Gibson Dunn · June 2026

EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes

The Council gave final green light on June 29 to the Digital Omnibus, deferring Annex III high-risk obligations from August 2, 2026 to December 2, 2027 (a 16-month slip) and Annex I product obligations by a year to August 2028. The package extends simplified-compliance benefits to firms up to 750 employees and €150M revenue and adds new prohibitions on non-consensual intimate imagery and CSAM from December 2026. The catch: if the Omnibus is not published in the Official Journal before August 2, the original high-risk timeline snaps back into force as written.

✍️ Gibson Dunn · Read article →

Transparency Coalition · July 2026

AI Legislative Update: July 10, 2026

The weekly tracker counts 78 chatbot bills alive in 27 states and, as of July 1, 109 enacted AI laws and 28 data-center laws nationwide. New York's kids-chatbot-safety bill (S 9051) and AI Training Data Transparency Act (A 6578) now sit on Governor Hochul's desk with a December 31 signing deadline, while Illinois's newly signed safety act headlines a clear shift toward child safety, data centers, and consumer protection. The through-line: states keep legislating aggressively even as a federal preemption fight looms.

✍️ Transparency Coalition · Read article →

The Modern Regulator · 2026

The ICO will write the UK's rulebook on AI decisions — its reach will extend far beyond the UK

Following its 2026/27 plan announced May 29, the UK ICO is finalizing a statutory Code of Practice on AI and automated decision-making — covering transparency, bias, and redress — with final guidance expected over summer 2026 after a consultation that closed the same day. The 2018 Act regulations now formally require the code, and the ICO is layering on dedicated agentic-AI guidance. Because UK data-protection reach follows the data, the rulebook will bind many non-UK deployers making automated decisions about UK residents.

✍️ The Modern Regulator · Read article →

↑ Top


⚖️ 📜

AI Ethics & Policy

U.S. House (Rep. Foushee) · July 2026

Foushee, Casar Introduce the People-First Chatbot Act

On July 9, Reps. Valerie Foushee and Greg Casar introduced H.R. 9619, seeking federal safeguards for anyone interacting with AI chatbots: control over personal data, clear disclosure that a user is talking to AI, protections for children and vulnerable users, mandatory safety assessments, and meaningful recourse when chatbots cause harm. It joins a crowded field — the Senate's GUARD and CHATBOT Acts and a dozen-plus state bills — signaling real bipartisan momentum but no consensus vehicle yet.

✍️ Office of Rep. Valerie Foushee · Read article →

Tech Policy Press · July 2026

States Step in Where Congress Stalls on AI Safeguards for Kids

With federal chatbot bills stuck in committee, the analysis documents how states have become the effective regulators of AI harms to minors — 464 chatbot and health-AI bills introduced across 49 states and DC since 2025, and California's SB 243 (in force January 1) already forcing nationwide disclosure that a bot is not human. The piece argues that state-level enforcement, not congressional action, is setting the operative standard for AI companion safety — a patchwork that developers must now design to.

✍️ Tech Policy Press · Read article →

Norton Rose Fulbright · 2026

AI in litigation series: An update on AI copyright cases in 2026

The roundup tracks a maturing copyright docket in which Anthropic's $1.5B author settlement (roughly $3,000 per work) set a benchmark after Judge Alsup held that training on lawfully acquired books is fair use but storing pirated copies is not. OpenAI, meanwhile, has won key discovery skirmishes as its cases press on. The emerging line — provenance of training data, not training itself, drives liability — is reshaping how model developers source and document their corpora.

✍️ Norton Rose Fulbright · Read article →

RAND Corporation · 2026

Investigating the potential use of frontier AI models for offensive cyberattacks: A human uplift study

Commissioned by the UK AI Security Institute and run between September 2025 and January 2026, the study empirically tested whether frontier-model access meaningfully boosts lower-skilled threat actors' offensive cyber capability — the central question behind the 2026 International AI Safety Report and the EU's new cyber-AI plan. Grounding the dual-use debate in evidence rather than speculation, its findings inform how governments calibrate model-evaluation requirements and structured-access controls.

✍️ RAND Corporation · Read article →

Littler · 2026

Deepfakes in the Workplace: The Emerging Legal Risks of AI-Driven Harassment

The alert warns that AI-generated deepfakes are opening a new front in employment law: circulated synthetic imagery tied to a protected characteristic can ground hostile-work-environment claims under Title VII and analogous state statutes, layered atop the federal TAKE IT DOWN Act's 48-hour removal mandate (FTC-enforced, at roughly $53K per violation). Employers, it argues, need harassment policies and response playbooks that explicitly name synthetic media before an incident forces the issue.

✍️ Littler · Read article →

↑ Top

Compiled by Rainvil Labs · Monday, July 13, 2026
Sources verified via live web research during the week ending July 13, 2026. Outlets referenced include the European Commission, Capitol News Illinois, Gibson Dunn, the Transparency Coalition, The Modern Regulator, the U.S. House of Representatives, Tech Policy Press, Norton Rose Fulbright, RAND Corporation, and Littler. This briefing is for informational purposes only and does not constitute legal, regulatory, or investment advice.