July 20, 2026 · Policy, Regulation & AI Industry Developments
POLICY & REGULATION
Tags: News | European Union
Date: July 20, 2026
European Commission publishes AI Act transparency guidelines for providers and deployers ahead of August 2 application date
The European Commission published guidelines on transparency obligations for providers and deployers of certain AI systems on July 20, 2026, clarifying how organizations must comply with Article 50 of the EU AI Act before its transparency rules take effect in August. The guidelines address the obligations that apply when people interact with AI systems, including chatbots, and when AI generates or manipulates content such as deepfakes and synthetic text, image, audio, and video. The publication is part of a sequence of Commission guidance issued in July, following the July 7 EU Action Plan on Cybersecurity and Artificial Intelligence and the finalized AI Omnibus regulation that entered into force earlier in the month.
The transparency obligations require that AI systems intended to interact directly with people be designed so users are informed they are interacting with an AI system, unless it is obvious from context. Providers of systems that generate synthetic content must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Deployers of systems that generate deepfakes must disclose that the content is artificially generated. These obligations apply broadly across sectors and are not subject to the deadline extension that the AI Omnibus granted to high-risk system obligations, which moved to December 2027 and August 2028.
Organizations that deploy chatbots, generate synthetic media, or produce AI-generated content for EU users must treat the August 2, 2026 transparency deadline as operative and imminent. Unlike the high-risk obligations, these transparency requirements were not deferred by the Omnibus, which creates a compliance trap for organizations that assumed all AI Act obligations were pushed to 2027. Organizations should review the new guidelines against their disclosure mechanisms and content-marking systems now, as the transparency rules reach a far broader set of deployed AI systems than the high-risk provisions.
Tags: News | United States
Date: July 14, 2026
Hawaii Governor signs two AI chatbot safety laws as state enactments continue through mid-July
Hawaii Governor Josh Green signed the state’s two AI-related bills into law on July 13, 2026, including SB 3001, a chatbot safety measure that requires AI operators to issue disclosures to account holders and users, develop protocols to prevent the production of suicidal ideation content, and establish protections for minor account holders of conversational AI services. The enactment continued a steady cadence of state AI lawmaking through mid-July, with the Transparency Coalition’s July 17 update also noting Illinois Governor Pritzker’s signing of the AI Safety Measures Act the prior week and Massachusetts lawmakers advancing bills to protect minors from addictive social media algorithms and enact a bell-to-bell cellphone ban in public schools.
The Hawaii laws reflect the dominant theme of 2026 state AI legislation: chatbot safety, particularly for minors, has become the most active area of state-level AI regulation. The disclosure requirements and self-harm prevention protocols in SB 3001 track the model established by California and New York in 2025 and now replicated across numerous states. The mid-year picture shows this activity is not slowing; larger states including California, Massachusetts, Pennsylvania, and Michigan continued to move AI bills through their legislatures as many smaller-state sessions concluded.
Organizations operating conversational AI services accessible to Hawaii residents must assess their products against SB 3001’s disclosure obligations and self-harm prevention protocol requirements. The consistent pattern across states means organizations operating conversational AI or companion products nationally should build to the emerging common standard of AI-status disclosure, crisis-intervention routing, and enhanced protections for minors, rather than adapting jurisdiction by jurisdiction. The concentration of these requirements around minor safety also signals elevated enforcement and liability exposure for any product accessible to users under 18.
Tags: Alert | Security | United States
Date: July 14, 2026
CISA urges SharePoint hardening after new active exploitation; federal agencies face July 17 remediation deadline
CISA issued an alert on July 14, 2026 warning of active exploitation of multiple Microsoft SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, that enable attackers to gain unauthorized access to on-premises SharePoint Server instances. The vulnerabilities affect all supported self-hosted SharePoint Server versions, including the Subscription Edition. Attackers are exploiting the flaws to bypass authentication, gain remote code execution, and conduct post-exploitation activity including stealing Internet Information Services machine keys and establishing persistence to deploy malware. CISA updated the alert on July 16 to add a further vulnerability, CVE-2026-58644, to its Known Exploited Vulnerabilities catalog.
Federal Civilian Executive Branch agencies faced a July 17 deadline to secure SharePoint servers affected by CVE-2026-56164 under Binding Operational Directive 26-04, or to discontinue the systems if mitigations could not be applied. The security watchdog group Shadowserver tracked nearly 10,000 internet-exposed SharePoint servers at the time of the alert, with over 800 unpatched. Since November 2021, CISA has flagged 11 SharePoint vulnerabilities exploited in attacks, seven of which were also used in ransomware campaigns, underscoring that on-premises SharePoint remains a persistent and heavily targeted enterprise attack surface.
Federal agencies were bound by the July 17 remediation deadline. All other organizations running self-hosted SharePoint Server should treat the KEV additions as urgent and apply patches or mitigations immediately, given confirmed active exploitation and the demonstrated use of these flaws in ransomware operations. Organizations should also audit for post-exploitation indicators, including stolen IIS machine keys and persistence mechanisms, since authentication bypass and remote code execution may already have occurred on unpatched internet-facing instances. Organizations unable to patch should isolate affected servers from internet exposure as an interim measure.
AI INDUSTRY
Tags: News | Industry
Date: July 16, 2026
Google delays and rebuilds Gemini 3.5 Pro after enterprise testing reveals coding and reasoning shortfalls
Alphabet’s Google delayed the broader release of Gemini 3.5 Pro, its flagship frontier model, after internal testing revealed the system fell short of expectations in coding performance and complex, long-horizon reasoning, according to reporting on July 16 and 17, 2026. The model, previewed at Google I/O earlier in 2026 and expected to launch around June, remained in limited enterprise preview as engineers worked to improve its capabilities. Reports indicated Google scrapped the base model and rebuilt it after structural failures surfaced in Vertex AI enterprise testing, including problems with recursive tool-calling, SVG generation, and mathematical reasoning. The delay pushed the broader release to at least September, with Google reportedly exploring a stopgap Gemini 3.6 Flash release.
The delay is significant in the context of intensifying frontier model competition. Gemini 3.5 Pro had been positioned against OpenAI’s GPT-5.6 and Anthropic’s Fable and Opus lines, and the repeated slippage, missing an anticipated July 17 target, highlights the difficulty of achieving frontier-tier reliability on coding and agentic reasoning benchmarks that enterprise customers now scrutinize closely. The failures identified in enterprise testing, particularly around tool-calling and long-horizon reasoning, are precisely the capabilities that matter most for the agentic deployments organizations are increasingly building.
For organizations, the Gemini delay reinforces that frontier model release timelines are unreliable and that announced capabilities do not always survive enterprise-grade testing. Organizations building agentic workflows should validate any model against their own representative tasks rather than relying on preview announcements or vendor benchmarks, particularly for tool-calling and multi-step reasoning where the reported Gemini shortfalls occurred. Organizations that had planned deployments around a mid-2026 Gemini 3.5 Pro availability should adjust timelines and maintain alternative model options, since the release is now delayed by a full quarter or more.
Tags: News | Security | Industry
Date: July 15, 2026
Anthropic scales Project Glasswing to 150 organizations across 15 countries, expanding Mythos deployment for critical infrastructure defense
Anthropic expanded Project Glasswing, its initiative deploying the restricted Claude Mythos cybersecurity model, from 50 initial partners to 150 organizations across 15 countries, according to reporting in mid-July 2026. The model, which identifies and fixes software vulnerabilities in critical codebases, now covers sectors including power, water, healthcare, and communications. Mythos remains restricted from general availability due to the same security concerns that triggered the June export control episode, in which its underlying capabilities prompted temporary federal suspension of both Mythos 5 and the public Fable 5 model.
The expansion reflects the dual-use tension at the center of frontier AI cybersecurity policy. Mythos is powerful enough at discovering and exploiting software vulnerabilities that Anthropic and the US government have agreed to keep it out of general release, yet that same capability makes it valuable for hardening the critical infrastructure it could otherwise be used to attack. Scaling to 150 organizations across 15 countries represents a controlled expansion of access to defensive users while maintaining the restrictions that keep the model from broad availability. The structure functions as a de facto model for how governments and labs may manage the most capable dual-use models going forward: restricted distribution to vetted defenders rather than public release or complete withholding.
For organizations that operate critical infrastructure, the Glasswing expansion signals that access to frontier defensive AI capability is becoming available through vetted partnership programs rather than commercial channels. Organizations in power, water, healthcare, and communications should assess whether participation in such programs aligns with their vulnerability management strategy. More broadly, the controlled-distribution model demonstrated by Glasswing indicates that the most capable security-relevant AI models will likely remain outside standard procurement, which organizations should factor into their expectations about which capabilities will be commercially available.

