Covering Information Security, Banking, Data Sovereignty, Frontier AI, Amendment. Explore the latest regulatory updates impacting Information Security, Banking, Data Sovereignty, Frontier AI, and Amendment efforts worldwide including new AI risk management frameworks and cyber resilience mandates.
Weekly news, analysis, and insights from AI regulation updates the world over
Welcome to This Week in AI Regulations for June 21, 2026.
Starting with Russia, the Bank of Russia has published its first comprehensive document addressing AI adoption risks in the financial sector. This guidance outlines cyberattack tactics targeting AI systems and recommends protection measures, including mandatory human confirmation for high-risk AI operations in payment transactions. Financial institutions are required to develop internal threat models and information security policies specifically for AI use. Responsibility for these documents must be assigned to the deputy head for information security.
Turning to China, the National Financial Regulatory Administration issued guidance on June 18, 2026, for the safe development and application of artificial intelligence in banking and insurance. This comprehensive framework mandates the establishment of AI governance structures with board-level oversight and cross-functional coordination. It requires full lifecycle management of AI applications, covering development, deployment, monitoring, and retirement. The guidance also calls for classification and management of AI risks based on application scenarios and complexity, with special controls for high-risk AI uses.
Also in China, the Beijing Municipal Development and Reform Commission has launched a pilot project application process for “Artificial Intelligence plus” energy integration. The initiative focuses on 51 high-value AI energy application scenarios and targets energy enterprises and AI technology providers in Beijing. Applicants must form innovation consortia between energy and AI companies and submit applications online by June 26, 2026. Recommended projects are to be submitted by recommending units by July 30, 2026.
In the European Union, the European Data Protection Supervisor, or EDPS, released its latest newsletter highlighting multiple initiatives related to AI regulation and data protection. Key points include formal comments on AI systems used at EU external borders, data transfer frameworks for medicine safety, and opinions on budget tracking privacy. The EDPS emphasizes clarifying roles and responsibilities for AI systems under the European Union’s AI Act, particularly for public authority use. It also stresses transparency, accountability, and rigorous testing for AI chatbots deployed in visa application platforms.
Additionally, the European Union has issued guidance on frontier AI systems and cyber risk. The emergence of these advanced AI models significantly increases cyber threats by enabling rapid identification and exploitation of IT vulnerabilities. Entities within the European Union are required to reassess their cyber risk profiles and comply with the Digital Operational Resilience Act, or DORA. Key requirements include identifying and inventorying ICT assets, protecting them with updated security measures such as access controls, patching, backups, network segmentation, and penetration testing. Organizations must also detect and respond quickly to ICT incidents with defined responsibilities and incident management procedures, including incident reporting.
In the Netherlands, regulators have noted that advanced AI models accelerate the identification and exploitation of vulnerabilities, reducing response times and increasing pressure on institutions, especially smaller ones, to improve security measures. The Dutch guidance calls for accelerated implementation of critical security updates, preferably automated, enhanced visibility through logging and monitoring to detect anomalies quickly, and rapid incident response capabilities including system segregation and reliable backups.
That wraps up today’s regulatory updates. Visit carveragents.ai for more information.