This Week in AI Regulations

Covering Bidding, Artificial Intelligence, Cybersecurity, AI Standards, Mortgage Subrogation. Explore key regulatory updates in Bidding, AI, Cybersecurity, AI Standards, and Mortgage Subrogation sectors, including EU systemic cyber risk warnings, AI interoperability mandates, and Australia’s new AI standards for data centers.

Show Notes

This episode covers critical regulatory developments across bidding, artificial intelligence, cybersecurity, AI standards, and mortgage subrogation sectors.

The European Systemic Risk Board (ESRB) issued a warning about systemic cyber risks associated with frontier AI models, urging financial institutions in the EU to enhance their cybersecurity frameworks and develop action plans to mitigate such risks. Additionally, the European Commission has introduced binding measures requiring Google to ensure AI interoperability on Android and share anonymized search data with third-party AI assistants, emphasizing user privacy and data security.

In Australia, new AI standards have been introduced for large data centers, mandating legal obligations related to power supply, connection costs, and resource efficiency, alongside the establishment of the Office of AI within the Department of Prime Minister and Cabinet.

For more information, visit the Carver Agents website.

Articles mentioned:
  1. ESRB/2026/3 - Warning on systemic cyber risks stemming from frontier AI models
  2. AI-00496-2024
  3. AI-00549-2024
  4. CM 3558 2026 INIT
  5. AI in Australia's interests from Assistant Minister Charlton
  6. AI in Australia's interests from Minister Ayres
  7. Bowman, Modernizing Financial Regulation
  8. EDPB komt met 3 nieuwe guidelines over scraping, anonimiseren en blockchain
  9. Commission provides guidance to Google for AI interoperability on Android and sharing of Google Search data under the Digital Markets Act
  10. 《公共资源交易中心招标投标现场管理暂行办法》 2026年第43号令

What is This Week in AI Regulations?

Weekly news, analysis, and insights from AI regulation updates the world over

Welcome to This Week in AI Regulations.

Starting in the European Union, the European Systemic Risk Board issued a warning about systemic cyber risks stemming from frontier AI models. The ESRB highlighted that the increased speed, scale, and sophistication of cyberattacks enabled by these AI models significantly raise the likelihood and severity of systemic cyber incidents in the financial sector. Financial institutions within the European Union are required to assess and update their cybersecurity frameworks to address vulnerabilities exposed by frontier AI models. Furthermore, significant institutions must prepare detailed action plans to mitigate these risks.

Also in the European Union, there was a presentation and discussion on the EU cybersecurity and AI action plan, including AI cybersecurity risk assessment guidelines and a proposal to update the Cybersecurity Act with an emphasis on information and communications technology supply chain security. Public sector entities are expected to adopt and implement AI cybersecurity risk assessment guidelines and comply with the proposed regulatory framework for cybersecurity certification and ICT supply chain security under the updated Cybersecurity Act.

The European Data Protection Board published three new guidelines covering web scraping for AI training, data anonymisation, and blockchain processing of personal data. These guidelines emphasize compliance with the General Data Protection Regulation, especially given the privacy risks associated with large-scale personal data processing for AI training. Organizations must understand and apply GDPR principles to web scraping activities, including establishing lawful bases, ensuring transparency, data minimisation, and accuracy. They are also required to implement technical and organizational measures to mitigate risks, particularly when processing special categories of personal data. Additionally, anonymisation techniques must effectively prevent re-identification, with documentation of these processes maintained.

In another European Union update, the European Commission issued binding specification measures to Google concerning AI interoperability on Android and the sharing of Google Search data under the Digital Markets Act. Google must provide equal access to Android features for third-party AI assistants, including voice activation and app task delegation. Google is also required to share anonymised search data with eligible third-party search engines, including AI chatbots, using a multi-layered anonymisation method. The measures include safeguards to protect user privacy, device security, and data integrity.

Turning to Australia, the government has introduced Australian Standards for AI, as announced by Assistant Minister Charlton and Minister Ayres. These standards establish legal obligations for large data centres regarding power supply, connection costs, energy and water efficiency, and community engagement. Large data centres must underwrite their own new power supply and pay full connection costs. They are also required to reduce power usage when needed to support grid stability and maximize water efficiency. Additionally, the Office of AI has been established within the Department of Prime Minister and Cabinet.

That wraps up today's regulatory updates. Visit carveragents.ai for more information.