July 26, 2026
🇪🇺 EU Adopts Digital Omnibus on AI
The European Union has adopted the Digital Omnibus on AI (Regulation (EU) 2026/1744), published in the Official Journal on 24 July 2026. The Regulation amends the AI Act (Regulation (EU) 2024/1689), as well as the Aviation Safety Regulation and the Machinery Regulation, with the stated objective of reducing implementation burdens, improving legal certainty, and facilitating compliance without lowering the level of protection for health, safety, and fundamental rights.
The Omnibus introduces targeted changes addressing practical implementation concerns identified by businesses, national authorities, and standardization bodies.
Perhaps the most consequential change is the postponement of the application of the AI Act’s obligations for high-risk AI systems. Requirements for Annex III high-risk AI systems will now apply from 2 December 2027, while obligations for high-risk AI systems regulated under sectoral product legislation (Annex I) are deferred until 2 August 2028. The Regulation explains that delays in harmonized standards, conformity assessment infrastructure, and national governance arrangements made the original implementation timeline increasingly difficult to achieve.
The Regulation also substantially expands support for small mid-cap enterprises (SMCs), extending several simplification measures that previously applied only to SMEs. SMCs will now benefit from simplified technical documentation, proportional quality management requirements, priority access to regulatory sandboxes, reduced administrative burdens, and capped administrative fines similar to those available to SMEs. This reflects the EU’s broader policy of recognizing that growing companies often face compliance challenges comparable to smaller businesses.
The original AI Act required providers and deployers to ensure a sufficient level of AI literacy. The Omnibus replaces this with a more flexible obligation requiring organizations to take measures supporting AI literacy, without guaranteeing any particular competency level for individual employees. The Commission and Member States are tasked with supporting organizations through guidance, training resources and practical examples, while the AI Board will develop recommendations establishing common objectives.
The Regulation also clarifies several concepts that had generated uncertainty during implementation planning. In particular, it narrows the definition of a “safety component”, making clear that AI systems used solely for user assistance, performance optimisation, automation, convenience or non-safety quality control should generally not be treated as safety components merely because they are integrated into regulated products. This clarification is expected to reduce the number of AI systems classified as high risk solely due to broad interpretations of product safety legislation.
The Omnibus introduces an entirely new prohibited AI practice targeting AI systems that generate non-consensual intimate imagery (”nudification”) and AI-generated child sexual abuse material. Providers are prohibited from placing such systems on the market where these capabilities are either the intended purpose or a reasonably foreseeable outcome without adequate safeguards. Deployers are prohibited from using AI systems for those purposes. The provisions are drafted to distinguish unlawful uses from legitimate applications such as medical imaging or systems incorporating appropriate technical safeguards. These prohibitions will apply from 2 December 2026.
Several amendments aim to reduce duplication between the AI Act and sector-specific legislation. The Regulation creates mechanisms allowing certain AI Act requirements to be limited where equivalent protections already exist under harmonized product legislation, subject to future delegated acts. It also strengthens coordination with the Cyber Resilience Act and introduces simplifications for conformity assessment procedures, allowing greater reliance on existing sectoral assessment frameworks where appropriate.
The AI Office may establish a Union-level AI regulatory sandbox, complementing national sandboxes and giving priority access to SMEs, start-ups and SMCs. Real-world testing is expanded to additional categories of high-risk AI systems, including AI-enabled products regulated under sector-specific legislation, subject to appropriate safeguards.
The Regulation further strengthens the institutional role of the AI Office, granting it exclusive supervisory competence over certain AI systems built on general-purpose AI models developed within the same undertaking, as well as AI systems integrated into Very Large Online Platforms and Very Large Online Search Engines in specified circumstances. To support these responsibilities, the AI Office receives extensive investigative and enforcement powers, including the ability to conduct inspections, request information, impose fines and periodic penalty payments, and accept binding commitments from operators.
🇪🇺 European Commission Publishes AI Act Transparency Guidelines
The European Commission has published guidelines on the implementation of Article 50 AI Act, providing practical interpretation of the transparency requirements for providers and deployers of AI systems. AI Act’s transparency obligations begin to apply on 2 August 2026.
The Commission emphasizes that Article 50 contains four distinct obligations, each applying to different categories of AI systems, with responsibility divided between providers and deployers. The obligations may also apply cumulatively to the same system.
1. AI systems interacting directly with people (Article 50(1))
Providers must design AI systems so that users are informed they are interacting with AI unless this is already obvious or a narrow law-enforcement exception applies. The guidelines make clear that this obligation covers not only traditional chatbots but also: AI voice assistants, AI customer service systems, AI companions, AI avatars, AI-powered social media bots, coding agents; and AI agents capable of acting autonomously on behalf of users.
The Commission states that AI agents should disclose both their artificial nature and the person on whose behalf they are acting, particularly when negotiating, making purchases, booking services or communicating with third parties. Where providers cannot predict every deployment scenario, AI agents should be architected to identify themselves whenever interaction with humans is reasonably likely.
The guidance also narrows the “obviousness” exception. Merely because users know AI exists does not mean disclosure is unnecessary. Human-like chatbots, realistic avatars and conversational AI will generally still require explicit disclosure, particularly where children, elderly persons or individuals with lower AI literacy may interact with the system.
2. Machine-readable marking of AI-generated content (Article 50(2))
Providers of AI systems generating synthetic text, images, audio or video must embed technical measures allowing outputs to be identified as AI-generated or AI-manipulated. The Commission explains that compliance requires machine-readable marking (such as metadata, watermarks or cryptographic provenance) and publicly available means for detecting those markings. The guidance introduces extensive discussion of what constitutes effective technical solutions, emphasizing four quality criteria: effectiveness, interoperability, robustness, and reliability.
Providers are expected to follow the evolving state of the art and update their technical measures over time.
The Commission recognizes that not every AI-generated output presents the same level of risk. Certain industrial applications, closed enterprise workflows and purely technical outputs may benefit from limited exceptions where public deception risks are minimal. Likewise, routine editing functions - grammar correction, color adjustment, transcription, noise reduction and similar technical modifications - generally fall outside Article 50. Conversely, AI summaries, realistic voice cloning, object replacement, facial manipulation and substantial rewriting remain within scope.
3. Emotion recognition and biometric categorization (Article 50(3))
Deployers using emotion recognition or biometric categorization systems must inform individuals that such systems are operating. The Commission stresses that this obligation complements - not replaces - the requirements applicable to high-risk AI systems and existing GDPR transparency obligations.
4. Deep fakes and AI-generated public-interest content (Article 50(4))
A deep fake is not limited to impersonating real people. Content may qualify whenever AI-generated or manipulated images, audio or video closely resemble real persons, objects, places, entities or events and could falsely appear authentic or truthful. Examples likely requiring disclosure include:
realistic AI videos depicting politicians;
cloned voices of podcast presenters;
AI-generated advertisements featuring realistic celebrities;
realistic synthetic corporate executives; and
product imagery capable of misleading consumers about the product’s appearance.
Conversely, fantasy creatures, clearly fictional cartoons, obviously fictional game environments and stylized artistic works generally fall outside the definition.
The Commission also clarifies the special regime for artistic, satirical and fictional works. These remain subject to transparency obligations, but disclosure may be implemented in a way that does not interfere with artistic enjoyment. Documentaries, commercial advertising and informational content are considerably less likely to benefit from this lighter regime.
The guidance also addresses AI-generated text published to inform the public on matters of public interest. This concept includes news articles, public warnings, corporate reports, policy summaries and similar publications intended to inform society about matters of public concern. Disclosure is not required where two cumulative conditions are met:
the content undergoes genuine human review or editorial control; and
a natural or legal person assumes editorial responsibility.
The guidelines emphasize that superficial proofreading or grammar checking is insufficient. Human review requires substantive assessment, including factual verification where appropriate. Likewise, AI modifications introduced after editorial approval invalidate the exemption and trigger disclosure obligations.
The Commission devotes considerable attention to how transparency should be implemented. Examples of acceptable disclosure include:
chatbot greetings stating users are interacting with AI;
voice assistants announcing their AI nature at the start of conversations;
persistent AI labels within interfaces;
visual indicators or standardized icons; and
multimodal combinations of text, audio and graphics.
The Commission specifically discourages relying solely on:
terms and conditions;
privacy notices;
generic website statements such as “this service uses AI”;
technical descriptions referring only to LLMs; or
machine-readable metadata invisible to users.
The information must be clear, distinguishable and presented no later than the first interaction or exposure. In longer or more sensitive interactions - such as AI companions, legal advice, healthcare or financial services - the guidance suggests repeated contextual reminders may be appropriate.
The guidance also reflects the recently adopted AI Omnibus amendments, introducing a limited grandfathering period for the Article 50(2) marking obligations applicable to generative AI systems already placed on the market before 2 August 2026. Those providers have until 2 December 2026 to implement compliant marking and detection mechanisms.
This transitional relief does not extend to chatbot disclosure obligations under Article 50(1). Interactive AI systems must comply from 2 August 2026. Existing deep fake content generated before that date also does not require retroactive labelling, although newly published AI-generated public-interest texts after 2 August must comply regardless of when they were created.
🇪🇺 ENISA Publishes SME Cyber Resilience Maturity Model
On 13 July 2026, the European Union Agency for Cybersecurity (ENISA) published the SME Cyber Resilience Maturity Assessment Model, accompanied by a practical Excel-based self-assessment tool, to help small and medium-sized enterprises prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The guidance is intended primarily for manufacturers of products with digital elements, but it is also relevant for importers, distributors, system integrators and service providers involved throughout the product lifecycle.
The model is designed as a maturity assessment framework. ENISA emphasizes that achieving an “advanced” maturity level should not be interpreted as demonstrating legal compliance with the CRA. Instead, the framework helps organizations understand their current capabilities, identify weaknesses and prioritize improvements in a structured manner.
The framework assesses organizations across five domains that reflect the operational capabilities required to implement the CRA effectively:
Governance and documentation;
Risk management and security by design and by default;
Vulnerability and patch management;
Product lifecycle management; and
Awareness, competence and skills.
Each domain contains five assessment criteria scored on a five-level maturity scale ranging from Level 1 (not implemented) to Level 5 (measured, monitored and continuously improved). Organizations calculate an average score for each domain and an overall maturity score, which places them into one of three maturity profiles:
Basic (1.0–2.5): largely reactive and informal practices;
Intermediate (2.6–3.9): documented processes that are not yet consistently applied;
Advanced (4.0–5.0): structured, consistently implemented and continuously improved practices.
Governance criteria include clearly assigned product security responsibilities, management-approved security policies, technical documentation, awareness of applicable conformity assessment procedures, and knowledge of the relevant market surveillance authority responsible for enforcing the CRA.
Organizations are expected to integrate cybersecurity risk assessments into product design, implement security-by-design and security-by-default principles, maintain Software Bills of Materials (SBOMs), establish coordinated vulnerability disclosure processes, verify security updates before release, define product support periods and communicate end-of-life arrangements to customers.
The guidance adopts a proportionality principle. ENISA acknowledges that many SMEs lack dedicated security teams and extensive compliance resources. Rather than prescribing enterprise-grade governance structures, it encourages smaller organizations to implement lightweight but repeatable processes, prioritize the highest-risk products and components, and rely on external expertise where internal capabilities are insufficient.
🇵🇱 Poland Completes AI Act Implementation
On 24 July 2026, Polish President Karol Nawrocki signed the Act on Artificial Intelligence Systems, completing Poland’s legislative framework for implementing the EU AI Act. The law establishes the national governance, supervision, and enforcement mechanisms required under the Regulation, including the creation of a new market surveillance authority - the Commission for the Development and Security of Artificial Intelligence (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji, KRiBSI).
The new authority will be responsible for supervising compliance with the AI Act across Poland. Individuals and organizations will be able to submit complaints regarding AI systems, and the Commission will have investigative powers as well as authority to impose administrative sanctions for violations.
KRiBSI will be empowered to establish regulatory sandboxes allowing selected organizations to test innovative AI systems under regulatory supervision with exemptions from certain legal requirements where permitted by the AI Act. Participation will be free for SMEs, while large enterprises will pay a one-time fee equal to three times the national minimum wage. T
Organizations will be able to request formal opinions from KRiBSI on the legality of planned or existing AI deployments. The Commission will also be supported by an advisory Social Council on Artificial Intelligence.
🇫🇷 CNIL and AI Council Examine GDPR Challenges of Agentic AI
On 20 July 2026, the French data protection authority (CNIL) and the Conseil de l’IA et du Numérique (CIANum) published a joint exploratory note examining how agentic AI systems challenge the application of the GDPR. Unlike generative AI systems that primarily respond to prompts, agentic AI can autonomously plan and execute multi-step tasks, interact with third-party services, retain persistent memories, and act on behalf of users. The paper concludes that while the GDPR already applies to these systems, their architecture and capabilities create new practical difficulties in implementing core data protection principles.
The note characterizes agentic AI as a “change of scale” rather than simply another evolution of generative AI. Because these systems coordinate multiple specialized agents, access numerous connected services, and continuously enrich persistent user profiles, they create significantly more complex data flows than traditional AI assistants. Personal data may circulate between multiple agents, memories, APIs, databases, cloud services, and external applications, making it increasingly difficult for users to understand where their information travels and how it is used. According to the authors, this growing opacity risks undermining users’ control over their personal data, placing pressure on several core GDPR principles.
The paper systematically analyzes the impact on the GDPR’s fundamental principles. Purpose limitation becomes harder to enforce because a single agentic system may perform an open-ended range of tasks across multiple domains. Lawfulness may become more difficult to demonstrate where autonomous agents initiate additional processing activities beyond the original user request. Data minimization is challenged because agents often access broad datasets, including emails, calendars, documents, browsing history, and connected applications, to complete tasks, even where not all information is strictly necessary. Accuracy also becomes more problematic as hallucinations or erroneous outputs may propagate across multiple agents and persistent memory stores, affecting future decisions. Transparency is similarly weakened because users may be unable to identify which agents processed their data, what external services were involved, or why specific processing operations occurred. Persistent memories and distributed storage architectures complicate compliance with storage limitation obligations and make deletion or correction of personal data substantially more difficult.
A central concern is the creation of increasingly detailed user profiles. Unlike conventional AI assistants that largely operate within a single conversation, agentic systems continuously accumulate information through persistent memory and by combining data obtained from external services. The note explains that users may grant an agent access to email, calendars, document repositories, collaborative platforms, or other workplace systems. The agent may then consult much more information than is strictly necessary to complete the immediate task, retain that information in memory, and reuse it during future interactions. Over time, this enables highly personalized profiles that substantially increase both functionality and privacy risks.
The authors also highlight the gradual shift from AI-assisted decision-making toward AI delegation. As agentic systems become capable of independently executing complex workflows, users may increasingly rely on them to make operational decisions or carry out actions without continuous supervision. The note warns that errors, misunderstandings, or cascading hallucinations may therefore have much greater consequences than in conventional generative AI systems. It cites examples of autonomous agents deleting large numbers of business emails following an incorrect interpretation of user instructions and notes that interrupting such processes may itself be difficult once execution has begun.
This evolution also raises important questions under Article 22 GDPR concerning solely automated decision-making. The CNIL emphasizes that the mere existence of nominal human review does not necessarily remove processing from Article 22. Consistent with the Court of Justice’s SCHUFA judgment, human intervention must be genuine, meaningful, and capable of influencing the final decision rather than amounting to a purely formal validation. The increasing autonomy of agentic systems therefore requires careful assessment of when meaningful human oversight actually exists.
The note identifies governance and accountability challenges. Modern agentic AI systems typically involve model providers, orchestrator agents, specialized agents, software developers, deployers, third-party applications, and users. When an autonomous action causes harm - for example by disclosing confidential information or sending information to the wrong recipient - determining which actor bears legal responsibility becomes significantly more complex. Although the GDPR continues to require an identifiable controller, the distributed nature of agentic AI makes governance, allocation of responsibilities, and demonstration of accountability considerably more difficult. At the same time, connecting multiple agents and external services expands the attack surface and creates additional cybersecurity risks through continuous exchanges of personal data.
The CNIL focuses on practical safeguards that could make existing law more effective. It recommends stronger transparency mechanisms that would allow users to reconstruct the complete decision process, including which agents participated, what personal data were accessed, which third-party services were contacted, and in what sequence. Users should also have more granular control over the data available to agents, particularly where sensitive information is involved. The note further suggests developing sector-specific guidance on automated decision-making under Article 22 as applied to agentic AI.
The paper also outlines a number of privacy-by-design technical measures. These include filtering and monitoring mechanisms to detect misuse, compartmentalized memory architectures to prevent unnecessary accumulation of personal data, isolated execution environments (sandboxing), automatic expiration of stored information, synchronization controls between agent memories, human approval for higher-risk actions, and emergency “kill switch” capabilities allowing users to interrupt autonomous processes. The CNIL additionally recommends independent evaluations of both privacy and cybersecurity protections in agentic AI systems to improve transparency and user confidence.
🇪🇸 Spain’s AEPD Reinterprets GDPR Accuracy Principle for AI Data Quality
Spain’s Data Protection Authority (AEPD) has published a technical note on data quality, accuracy and data minimization in AI systems, together with a detailed 23-page analysis aimed at controllers, processors, data protection officers and AI developers. The document provides regulatory analyses of how the GDPR’s principles of accuracy and data minimization should be interpreted in the context of artificial intelligence.
The AEPD argues that Article 5(1)(d) GDPR should be interpreted in light of the purpose of the processing. The authority concludes that personal data are sufficiently “accurate” where they are suitable for achieving the intended purpose of the processing and adequately protect individuals’ rights.
The guidance distinguishes between data quality and the GDPR principle of accuracy. Data quality is presented as a broader concept that applies to both personal and non-personal data and encompasses characteristics such as completeness, representativeness, statistical properties, bias, relevance, precision and context. GDPR accuracy, by contrast, remains a legal principle focused on ensuring that personal data are appropriate for the purpose of the processing. The AEPD stresses that imposing unnecessarily high standards of accuracy could itself conflict with the GDPR’s data minimization principle by requiring controllers to collect or maintain more data than necessary.
One of the most significant aspects of the paper is its emphasis on dataset quality rather than individual record quality when developing machine learning systems. According to the AEPD, many AI models depend far more on the representativeness, absence of harmful bias and statistical properties of an entire dataset than on the perfect accuracy of every individual record. A dataset could therefore satisfy GDPR requirements even if some individual values are estimated, transformed or synthetic, provided the dataset remains suitable for the intended purpose and does not adversely affect individuals. The paper illustrates this distinction through examples involving biased datasets, missing values and statistical imputation techniques.
The guidance also explicitly addresses several AI-specific techniques. It concludes that synthetic data generation, anonymization, differential privacy, bias correction and statistical imputation may all be compatible with the GDPR’s accuracy principle where they improve the suitability of a dataset for its intended purpose. Although these techniques may intentionally produce values that do not correspond to an individual’s actual characteristics, they may nevertheless increase overall dataset quality and better satisfy the GDPR if they reduce bias or improve model performance without producing adverse effects for data subjects. However, where AI outputs directly affect identifiable individuals—such as decisions, profiles or predictions—the resulting outputs themselves must satisfy a significantly higher standard of accuracy and should not generate distorted or misleading representations of the person concerned.
The document treats AI development and AI deployment as distinct processing activities. The AEPD argues that data quality requirements during model development are different from those applicable once a model is deployed in operational environments. The required quality of training, validation and testing datasets should be determined by the intended operational context, expected safeguards and the performance requirements of the eventual AI system. Controllers should therefore establish data quality requirements “backwards”- starting from the required quality of outputs and determining what level of input data quality is necessary to achieve them.
The paper further rejects the notion of a “perfect” AI system. Instead, controllers should design AI-supported processing operations around known model limitations, incorporating technical and organizational safeguards, human oversight, monitoring, validation and documented performance metrics. Data governance should extend throughout the entire AI lifecycle, including continuous monitoring for changes in context, data drift and model performance.
AEPD also links data quality to the GDPR’s accountability principle. Organizations should document objective data quality requirements, maintain governance processes covering both personal and non-personal data, establish measurable quality metrics, document dataset provenance and continuously monitor whether processing continues to meet its intended purpose. The authority recommends multidisciplinary governance involving both data scientists and privacy specialists throughout the lifecycle of AI systems.
🇳🇱 Dutch DPA Publishes GDPR Guidance for Generative AI Models
The Dutch Data Protection Authority has published its final guidance on the development and deployment of generative AI models under the GDPR.
The guidance focuses specifically on closed-weight generative AI models and addresses only the lawfulness of model training and deployment under the GDPR. It does not analyze downstream application-specific processing or open-source/open-weight models. According to the AP, a generative AI model trained on personal data should not automatically be regarded as anonymous merely because personal data are encoded in model parameters rather than remaining directly readable.
The AP distinguishes between five stages: data collection, data curation, parameter training, fine-tuning and deployment. It stresses that GDPR compliance must be assessed throughout the lifecycle rather than only when the model is deployed. In particular, data curation is described as a critical safeguard because it represents the final stage at which unnecessary personal data can realistically be removed before becoming embedded in model parameters. Once personal data have been incorporated into the model, current technology generally cannot reliably remove them without retraining.
The guidance concludes that consent will rarely be a viable legal basis for training foundation models. Although consent is theoretically possible where data are collected directly, the AP considers it practically impossible in most cases to satisfy GDPR requirements that consent be sufficiently specific and informed. Organizations currently cannot reliably honor subsequent withdrawal of consent because machine unlearning techniques remain immature and retraining a foundation model is generally infeasible. The same concerns apply when datasets obtained from third parties rely on consent.
The AP identifies legitimate interest as the legal basis most likely to support model development, but only after a rigorous three-part assessment. Developers must demonstrate a legitimate interest, prove that processing personal data is necessary for achieving that interest, and show that the interests or fundamental rights of data subjects do not override those interests. The guidance emphasizes that necessity cannot simply be assumed because large language models benefit from large datasets. Developers must demonstrate that comparable results cannot reasonably be achieved with datasets containing fewer or no personal data and must document this assessment before processing begins.
The AP also devotes significant attention to web scraping. It rejects the idea that large-scale scraping automatically becomes lawful merely because information is publicly accessible online. Organizations must assess whether individuals could reasonably expect their personal data to be used for AI training and whether the collection is genuinely necessary. Large-scale indiscriminate scraping will therefore make a successful legitimate interest balancing exercise significantly more difficult, particularly where extensive personal data are collected unnecessarily. Developers are expected to minimize personal data collection wherever possible and remove unnecessary personal data before training.
The guidance takes a particularly detailed position on special category data. Recognizing that web scraping inevitably captures some sensitive personal data, the AP draws on the CJEU’s GC and Others v CNIL judgment concerning search engines and argues that developers should be assessed within the limits of their responsibilities, powers and technical capabilities rather than being subject to an absolute prohibition. However, this flexibility is conditional upon extensive safeguards. Developers should proactively exclude high-risk sources such as health forums, deploy technical filtering before training, remove or anonymize detected sensitive data, implement output filters to prevent reproduction, conduct red-team testing before release, and continuously monitor deployed models. If sensitive personal data are nevertheless reproduced, organizations are expected to take immediate corrective measures and ultimately migrate to models from which those data have been eliminated altogether.
The guidance also addresses organizations deploying third-party AI models, placing substantial due diligence obligations on model users. Before deploying a foundation model, organizations should verify that it was lawfully trained and should not assume that compliance rests solely with the model provider. The AP recommends obtaining evidence such as documentation describing the origin of training data, legal bases relied upon, legitimate interest assessments, training protocols, privacy safeguards, and, where applicable, compliance with the AI Act General-Purpose AI Code of Practice and DPIA findings. Contractual commitments alone are considered insufficient without supporting evidence.
The AP notes that its guidance is intended as an interim national interpretation pending forthcoming EDPB guidance on generative AI and possible amendments arising from the Digital Omnibus package.
🇺🇸 White House Launches GOLD EAGLE Cyber Vulnerability Coordination Initiative
On 14 July 2026, the White House announced the launch of GOLD EAGLE, a new public-private cybersecurity initiative intended to accelerate the identification, prioritization, and remediation of software vulnerabilities across U.S. critical infrastructure. The initiative was established pursuant to President Trump’s Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security”, issued on 2 June 2026, and is presented as a central component of the Administration’s broader AI and cybersecurity strategy.
According to the announcement, GOLD EAGLE functions as a centralized vulnerability coordination clearinghouse involving the White House, the Department of the Treasury, the Cybersecurity and Infrastructure Security Agency (CISA), the Department of Homeland Security, the Department of War, and private-sector technology companies, including open-source software partners. The initiative aims to receive vulnerability reports, verify findings, prioritize remediation efforts, and distribute actionable information to both government agencies and private-sector defenders more rapidly than existing coordination mechanisms.
GOLD EAGLE is intended to use frontier AI models to support vulnerability management. The Administration envisions AI-assisted prioritization, exploit detection, and coordinated response activities. The stated objectives include:
reducing duplicative vulnerability scanning;
accelerating verification of reported vulnerabilities;
prioritizing remediation based on operational risk; and
distributing actionable mitigation guidance across government and industry.
The announcement emphasizes that the initiative relies on existing statutory authorities and federal resources rather than creating a new regulatory regime. Officials describe GOLD EAGLE as an operational coordination platform designed to improve information sharing between federal agencies and private organizations while leveraging AI capabilities to shorten the time between vulnerability discovery and remediation. The Administration also states that the initiative has already begun accepting vulnerability reports from multiple sectors and coordinating scanning verification activities.
OECD Calls for More Structured AI Experimentation Across Government
The OECD has published a new working paper, Generative AI Experimentation in Government: Learning from Emerging Guidelines (Working Papers on Public Governance No. 93), examining how governments are testing and adopting generative AI across the public sector. The paper surveys guidance from 14 countries and identifies common governance gaps, offering a practical framework for governments seeking to move from isolated AI pilots to systematic, accountable deployment.
The report observes that generative AI is already being used extensively by public servants, often without formal approval or governance. This “shadow AI” phenomenon has emerged faster than public sector governance frameworks, creating a disconnect between high-level AI strategies and day-to-day operational use. According to the OECD, governments increasingly recognize that experimentation is not simply an innovation exercise but an essential governance mechanism for understanding AI capabilities, identifying risks, and determining whether particular use cases should proceed to production.
A central finding is that most governments have published ethical principles or responsible AI guidance, but relatively few provide practical instructions on how agencies should design, evaluate, and document AI experiments. Existing guidance varies significantly in scope and maturity, leading to inconsistent practices, duplicated effort across agencies, and uncertainty among public servants about acceptable uses of generative AI. The OECD argues that structured experimentation should serve as the bridge between national AI strategies and operational deployment.
The paper places particular emphasis on experimentation because generative AI systems behave probabilistically rather than deterministically. Unlike traditional software, identical prompts may produce different outputs, making it difficult to predict performance or risks before deployment. For this reason, governments are increasingly relying on pilots, regulatory sandboxes, and controlled testing environments before introducing AI into higher-risk public services. The report highlights examples including Australia’s Microsoft Copilot trial across government agencies, Estonia’s AI-powered search initiatives, and experimental AI chatbots tested in the United Kingdom.
The OECD also concludes that monitoring and evaluation remain among the weakest aspects of current government AI governance. Most public sector organisations measure basic indicators such as user adoption or satisfaction but rarely assess broader questions, including whether AI systems improve public value, remain compliant with applicable legal requirements, or introduce new operational risks. Without consistent evaluation criteria, governments struggle to compare projects, identify unsuccessful experiments, or decide which initiatives should be scaled nationally.
To address this gap, the report proposes a structured evaluation framework built around five areas:
performance and quality of AI outputs;
public value and expected impact;
cost, feasibility, and organizational integration;
usability and user acceptance; and
risk management, including legal and regulatory compliance.
The report also identifies several governance practices emerging across leading jurisdictions. These include requiring impact assessments before deployment, documenting system use, assigning clear accountability to responsible officials, maintaining auditability, and implementing technical safeguards such as secure AI sandboxes, access controls, automated redaction of sensitive information, and privacy-enhancing technologies before information reaches external AI models. The UK AI Playbook is highlighted as distinguishing between three complementary dimensions of accountability: answerability, auditability, and legal liability.
From a regulatory perspective, the paper positions experimentation as complementary to emerging legal frameworks such as the EU AI Act rather than an alternative to compliance. It notes that governments increasingly need operational governance capable of satisfying requirements relating to risk management, transparency, human oversight, documentation, and accountability throughout the AI lifecycle. Successful experimentation therefore becomes part of regulatory readiness rather than merely an innovation activity.
***
Direct your questions to groundcontrol@kepler.consulting.
Until the next transmission, stay secure and steady on course. Ground Control, out.

