AI Policy & Governance, European Policy
CDT Europe’s AI Bulletin: July 2026
Welcome to the last edition of the AI Bulletin before the summer break! As Brussels starts emptying for the summer, the risks of frontier AI models continue to capture the attention of policymakers as a key chapter of the AI Act becomes enforceable, and disclosure rules around the use of AI systems and AI-generated content are further clarified.
Frontier AI Remains in the Eye of the Storm
Beginning of the month, the European Commission published an Action Plan on Cybersecurity and AI to support the safe and responsible use of AI while strengthening Europe’s cybersecurity. Amongst others, the plan includes commitments of the EU to step up its capacity to evaluate frontier AI before its release, to create a blueprint for structured access to advanced AI capabilities for cybersecurity purposes and to develop a secure testing platform.
In a separate effort, the AI Office released a report outlining key findings of the Expert Forum on Frontier AI, a group of over 100 experts convened to reflect on the EU’s competitiveness, sovereignty and security in frontier AI. Experts raised the need to increase computing and energy infrastructure. They also cited the uncertainty regarding the lawfulness of AI model training, particularly in relation to data protection and copyright law, as a key obstacle to large-scale private investments in European computing infrastructure. Permits and grid access were identified as bottlenecks for increased compute capacity.
The increased attention towards frontier models coincides with the entry into application of the AI Office’s enforcement powers related to general-purpose AI models on 2 August. In view of this approaching deadline, several organisations and MEPs have called on the European Commission to make full use of its enforcement powers, and to focus its resources on the systemic risks of cyber-offense, biology and loss of control.
Advanced cyber capabilities have continued to raise concerns in Brussels since Anthropic’s frontier model Mythos was released. During an exchange of views with the company in the European Parliament’s Internal Market and Consumer Protection Committee on safety and cyber security risks posed by advanced AI models, several MEPs criticised Anthropic’s decision to send a junior, technical employee, linking this to Anthropic’s lack of interest in European issues.
Guidelines on Transparency Obligations under the AI Act
The European Commission published guidelines to define the scope of transparency obligations under the AI Act, supplementing the recently published Code of Practice on AI-generated content. The guidelines – which solely focus on the interpretation of Article 50 in the AI Act – clarify the conditions under which people interacting with AI systems or AI-generated outputs must be notified of this, including requirements regarding the format and substance of the notification as well as exceptions to the obligation. Public interest stakeholders have welcomed the explicit application of transparency requirements to AI agents, both when they interact with the person instructing them and with other natural persons during the execution of their tasks. Crucially, the guidelines require for agents to be built in a way that such a disclosure is possible even where a provider cannot know in advance whether an agent will interact with other humans. While a single, prominent notification before the first interaction of the AI system is likely to suffice in most instances to ensure compliance, the guidelines stress that this may not be enough depending on the context.
The guidelines also detail the scope of the AI Act’s marking and labelling obligations for AI-generated content, building on the requirements laid out in the Code of Practice. Under the Act, marking obligations apply to providers of AI systems generating synthetic content to ensure the content is identifiable as having been artificially generated or manipulated. Labelling obligations apply to deployers of AI-generated content, but are much narrower in scope and are required only in relation to AI-generated or manipulated content rising to the status of “deep fakes”, or text to inform the public on matters of public interest. The guidelines develop these concepts, provide examples of content within and out of scope, and elaborate on applicable exceptions.
While the transparency obligations will apply from 2 August onwards, the AI Omnibus introduced a grandfathering rule with regard to the marking and labelling obligations for systems placed on the market before 2 August 2026.
In other news:
- After 30 MEPs across the political spectrum called for a European Council summit dedicated to AI to comprehensively cover issues related to security, ethics, societal, environmental and geopolitical dimensions, Council President Antonio Costa confirmed that he will propose a discussion around this subject as part of one of the next scheduled EU summits to take place in 2026.
- The Dutch government launched its international AI strategy, where it lays out actions to work together with like-minded partners to ensure that AI is used safely, fairly and with respect for people. This includes contributing to effective and workable European AI regulation as well as strengthening the European AI capacity and infrastructure.
- The French data protection authority published a paper on the implications of agentic AI on data protection. The Commission Nationale de l’Informatique et des Libertés (CNIL) notes agentic AI’s expansion of the data protection risk surface, while underscoring the challenges involved in operationalising principles and rights set out in the General Data Protection Regulation. The CNIL calls for recommendations targeted to agentic AI providers and deployers, including traceability mechanisms for data subjects, greater data subject choice towards data shared with agents, as well as technical control mechanisms such as ringfencing agentic memory, and developing a risk-based approach to classify possible actions taken by AI agents.
- The Independent International Scientific Panel on AI published its preliminary report on the opportunities, risks and impacts of artificial intelligence. The report highlights that AI risks as well as the capacity to govern them are unevenly distributed across populations and countries, while the wealth it creates is highly concentrated.
- 60 academics called on Ireland to recuse itself from chairing negotiations on digital and fiscal files during its Council’s Presidency, given its lack of enforcement of digital rules as well as concerns regarding the independence of its data protection authority. Two MEPs from the European People’s Party also expressed their concerns in a letter to Commissioner McGrath, pointing out Ireland’s shortcomings in enforcing the GDPR and urging the Commission to ensure that this failure does not compromise upcoming EU legislative negotiations impacting the Digital Single Market.
- The European Data Protection Board published guidelines on web scraping in the context of generative AI. The guidelines provide information on how to comply with GDPR principles including transparency, data minimisation and accuracy. They also reiterate the conditions under which legitimate interest can serve as a basis for lawful processing and reflect on the incidental and residual collection of special category data — both issues being currently discussed under the Digital Omnibus.
- The Italian data protection authority fined character.ai due to several violations of the GDPR, including a delayed preparation of the data protection impact assessment and a lack of transparency. It also identified shortcomings regarding the company’s measures to protect minors and its age verification procedures.
- The European Commission adopted a delegated act exempting wearable devices from EU requirements on the removability and replaceability of portable batteries. Consequently, this exception now also covers smart glasses. The call for this exception was expressed by Meta in the context of the consultation on the digital omnibus where it argued that the EU’s battery requirements were fundamentally misaligned with the realities of AI wearables. This step now removes a barrier for Meta to advance the roll-out of its widely criticised AI glasses.
- The European Commission issued binding specification measures to Google in an antitrust case on AI interoperability. While previously third-party AI assistants only had limited access to the Google Android operating system, the imposed measures aim to ensure that users can rely on third-party AI assistants to the same extent as Google’s own AI services. Google is required to implement the changes until July 2027.
Content of the Month 📚📺🎧
CDT Europe presents our freshly curated recommended reads and works for the month. For more on AI, take a look at CDT’s work.
- European Correspondent, Chat Are We Cooked
- Arvind Narayanan, ICML 2026 Keynote: What will be left for us to work on?
- The Guardian, The Reverse Centaur’s Guide to Life After AI By Cory Doctorow review
- Humanist Review, AI and Democracy: the right to resist optimization
Facts Only
* The European Commission published guidelines defining transparency obligations under the AI Act, supplementing the Code of Practice on AI-generated content.
* These guidelines focus solely on the interpretation of Article 50 in the AI Act.
* Guidelines clarify conditions for notifying people interacting with AI systems or outputs regarding disclosure, format, substance, and exceptions.
* Guidelines detail marking and labelling obligations for AI-generated content under the AI Act, building on the Code of Practice.
* Marking obligations apply to providers generating synthetic content.
* Labelling obligations apply to deployers concerning AI-generated or manipulated content deemed "deep fakes" or matters of public interest.
* Transparency obligations apply from August 2, 2025.
* An AI Omnibus grandfathering rule applies to marking and labelling obligations for systems placed on the market before August 2, 2026.
* Guidelines require agents to be built so disclosure is possible even if a provider cannot know if an agent will interact with other humans.
Executive Summary
Full Take
Sentinel — Human
This text demonstrates the structure and synthesis characteristic of high-level policy journalism, weaving together regulatory updates with expert concerns regarding frontier AI governance in Europe.
