Hintze Law’s Global AI Update provides a curated overview of key AI-related legal and regulatory updates. We spotlight new developments and emerging trends to help organizations that are developing, deploying, or relying on AI technologies to stay ahead of what’s next.
Please also check out our latest Global Privacy Updates post.
To receive email alerts for our blog posts, sign up here.
U.S. Updates
Hawaii Passes the Artificial Intelligence Disclosure and Safety Act
On July 14, 2026, Hawaii passed the Artificial Intelligence Disclosure and Safety Act. The law requires operators of AI companion services to clearly disclose to users that they are interacting with AI rather than a human, with more frequent and persistent disclosures required when the operator knows or has reasonable certainty a user is a minor. Operators must also adopt protocols to respond to user expressions of suicidal ideation or self-harm by directing users to crisis services, such as suicide hotlines and crisis text lines, and must prohibit their systems from representing themselves as licensed mental health professionals.
Beginning January 1, 2028, operators must submit annual reports to the Behavioral Health Administration of the Department of Health detailing crisis referral counts and safety protocols. Violations are treated as unfair or deceptive acts or practices enforceable by the Attorney General, with civil penalties of up to $1,000 per violation capped at $1,000,000 per operator, but the law expressly forecloses a private right of action, distinguishing Hawaii from Oregon and Washington, which both grant individuals the right to sue directly.
The law is effective immediately.
New Jersey Passes the Fair Price Protection Act
On July 23, 2026, New Jersey passed the Fair Price Protection Act. The law prohibits the use of for "surveillance pricing or any other pricing strategy that determines or varies the sale price of groceries and other foodstuffs based, in whole or in part, on personal data," with exceptions for reasonable costs associated with providing such goods to different consumers, bona fide discounts for disclosed conditions or criteria, or bona fide discounts offered as a part of loyalty program.
The law also establishes a one-year moratorium on the new use of "electronic shelf labels," meaning a "electronic display that presents the product and pricing information for groceries and other foodstuffs including, but not limited to, labels that are visible to the consumer only after the consumer has scanned a quick-response (QR) code, barcode, or other code."
The Attorney General may bring a civil action for the violation of this act and any regulations adopted pursuant to it.
The moratorium takes effect on February 1st, 2027, and the remaining provisions take effect on August 1st, 2027.
Illinois Enacts AI Safety Measures Act
On July 6, 2026, the Illinois passed the Artificial Intelligence Safety Measures Act. The law applies to certain frontier AI model developers and includes requirements for: establishing and publishing an AI framework that addresses specific matters; transparency; obtaining third party compliance audits; reporting certain safety incidents, and filing an annual disclosure statement with the state before deploying or operating a frontier model in Illinois.
Most provisions will take effect January 1, 2027 (framework and audit requirements become effective January 1, 2028). The law is enforced by the Attorney General with penalties not to exceed $1M for first violations or $3M for subsequent violations.
Rhode Island Passes a Companion Chatbot Law
On June 22, 2026, Rhode Island joined the states that have enacted a companion chatbot law. Its requirements include establishing protocols for addressing ideation of suicide and harm to others; filing annual reports with the office of the attorney general which include safety protocol metrics; and notifying the user at the beginning of and at least every three hours during AI companion that the user is not communicating with a human.
The law takes effect January 1, 2027.
CSA Publishes Draft Post-Mortem Report on OpenAI – Hugging Face Incident
On July 27, 2026, the Cloud Security Alliance (CSA) published a draft post-mortem report of the OpenAI – Hugging Face Incident. The response follows an incident where OpenAI tested one of its agentic AI models (a model not deployed into production) in a closed environment without access to the open internet. Nonetheless, the model was able to break into Hugging Face production systems. The report highlights the incident as the first documented case of a fully autonomous attack and outlines some of the tell-tale signs of this kind of attack. Additionally, the report offers several key takeaways: proactively test and operationalize cyber-capable models, liberally deploy deception technology, and govern under the assumption that rogue agent behavior is the norm, not the exception.
FTC Publishes Proposed Policy Statement "Concerning the Suppression of Accuracy in Artificial Intelligence Systems"
On July 1, 2026, the U.S. Federal Trade Commission published a proposed policy statement "Concerning the Suppression of Accuracy in Artificial Intelligence Systems." The document suggests that the FTC is considering its powers under Section 5 of the FTC Act to investigate whether AI companies are altering their AI systems output to comply with state laws (like the Colorado AI Act) in a deceptive or unfair manner.
Washington State AI Task Force Releases Final Report
On July 1, 2026, the Washington Attorney General's Office released the final report of the state's AI Task Force: the capstone of a two-year effort by the 19-member body created under SB 5838.
Across its three reports, the task force advanced 11 policy recommendations; during the 2025–2026 biennium the Legislature took up 8 and has already enacted 4 in whole or in part (including companion AI chatbots, transparency in healthcare prior-authorization decisions, disclosure of AI use by law enforcement, and enforcement against AI-generated CSAM). Furthermore, the final report outlines three policy recommendations pending legislative action: establishing an Emerging Technology Advisory Body, investing in K-12 STEM and higher education, and adopting the NIST Ethical AI Principles.
Global Updates
European Commission Publishes Implementing Regulation on GPAI Model Enforcement
On July 20, 2026, the European Commission published Implementing Regulation 2026/1755 as part of the harmonized rules on artificial intelligence in relation to the EU AI Act. The Regulation concerns the evaluation of general purpose artificial intelligence (GPAI) models (per EU AI Act Article 92) and the fines for providers (EU AI Act Article 101). The Regulation takes effect August 10, 2026. It details the arrangements and conditions for GPAI evaluations, including the involvement of independent experts to conduct evaluations, how the experts will be selected, opening and closing of evaluation proceedings, procedural safeguards, and the protection of confidential information that may be obtained during evaluations. For the enforcement of penalties, the Regulation details limitation periods both for the imposition of penalties (5 years from the date of the prohibited conduct) and the enforcement of penalties (5 years from the decision adopting the penalty). Both limitation periods may be interrupted by a variety of actions on the part of the Commission.
European Commission Publishes Guidelines on Transparency Obligations for Providers and Deployers of Certain AI Systems
On July 20, 2026, the European Commission published guidelines defining the scope of transparency obligations under Article 50 of the EU AI Act. Among its subsections, the document provides guidance on:
Requirements for providers of AI systems which are intended to interact directly with natural persons, such as voice assistants and chatbots, to design and develop such systems “in such a way that they disclose both their artificial nature and the person on whose behalf they are acting.”
Requirements for providers of AI systems generating synthetic content to be marked so that natural persons can detect it as AI-generated or manipulated and verify its origin.
Requirements for deployers of emotion recognition systems and biometric categorization systems to inform natural persons of their exposure to such systems by the first interaction with them.
Requirements for deployers of generative AI systems to “clearly and distinguishably” disclose deep fakes and AI-generated or manipulated text “published with the purpose of informing the public on matters of public interest.”
European Commission Publishes Action Plan on Cybersecurity and Artificial Intelligence
On July 7, 2026, the European Commission published the Action Plan on Cybersecurity and Artificial Intelligence, focusing on complementary objectives:
Promoting the safe and responsible use of advanced AI
Reinforcing the EU's cybersecurity and resilience
Scaling up Europe's AI capabilities for cybersecurity
The plan promotes and reinforces existing legal frameworks, including the NIS2 Directive, the Cyber Resilience Act, the NIS2 Directive, the Digital Operational Resilience Act (DORA) and the Cyber Solidarity Act.
Slovenian Information Commission Publishes FAQs on Deepfakes
On July 16, 2026, the Slovenian Information Commissioner published FAQs about privacy and data protection risks and obligations regarding deepfakes and generative AI content under the GDPR and EU AI Act.
German DPA Publishes AI Assessment Framework
On July 6, 2026, Germany's Federal Office for Information Security (BSI) announced a community draft of its Artificial Intelligence (AI) Audit and Assurance Assessment Architecture (A5). This assessment is meant for AI providers, operators, and developers to comply with assessment obligations under the EU AI Act, the Cyber Resilience Act and future standards, including those expected for the public sector.
Feedback can be submitted to aisecurity@bsi.bund.de by filling the official form until August 31, 2026.
Netherlands DPA Issues Generative AI GDPR Compliance Guide
On July 13, 2026, the Dutch data protection authority, Autoriteit Persoonsgegevens (AP), has published its first substantive GDPR interpretation for generative AI: a guidance document (handreiking) for organizations developing generative AI models or putting them into use, and a step-by-step checklist (hulpmiddel) for those deciding whether to deploy. There is currently no English version of either the guidance or the checklist.
The guidance addresses which legal bases can support model training, how to handle indirectly collected data, and what data cleaning, enrichment, and retention require. The checklist also covers compliance requirements such as data minimization, DPIAs, Automated decision-making, and periodic reassessments.
Since 2023, the AP has served as the national coordinating authority for AI and algorithm supervision and is expected to become the Dutch AI Act market surveillance authority. Given this role, its interpretation is likely to serve as a leading indicator.
Singapore PDPC Publishes Guide on Federated Learning
Singapore's Personal Data Protection Commission (PDPC) published a Guide on Federated Learning on July 20, 2026. The guide is intended to help organizations understand federated learning techniques and use cases, and navigate practical considerations for exploring and implementing federated learning as a Privacy Enhancing Technology (PET). The Guide is part of their PET Sandbox, which is intended for organizations to explore pilot use cases.
China Finalizes Anthropomorphic AI Rules
China’s Interim Measures for the Administration of Anthropomorphic AI Interaction Services took effect July 15, 2026. The final rule was jointly issued by five agencies (CAC, NDRC, MIIT, the Ministry of Public Security, and SAMR). It applies to AI services that provide continuous emotional interaction while simulating a natural person's personality traits, thinking patterns, or communication style. Ordinary smart customer service, Q&A tools, work assistants, education tools, and research tools are outside scope if they do not involve continuous emotional interaction.
The final rules go beyond content moderation to add substantial user protection requirements: clear AI-human disclosure, dependency and addiction warnings, special protections for minors and older adults, limits on virtual intimate relationship services for minors, crisis-response obligations, user rights to copy and delete interaction data, and restrictions on using interaction data and sensitive personal information for model training without separate consent. Compliance obligations also include security assessments and algorithm filing. Potential penalties include fines of ¥10,000–100,000 for general violations, and ¥100,000–200,000 for violations involving harm to users' life or health safety.
This is part of a broader China AI-governance push (IAPP). In May 2026, TC260 released the voluntary Ethics-Safety Guidelines for Artificial Intelligence Applications 1.0, effective July 1, 2026, which sets baseline expectations for AI developers, service providers, and users. Also in May, CAC, NDRC, and MIIT jointly issued the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents, effective July 15, 2026, which focuses on AI-agent oversight, authorization boundaries, traceability, risk controls, standards, and use cases. The AI agents document is structured as a policy implementation framework. It identifies 19 application scenarios and guides standards development, rather than directly imposing individual penalty provisions. Its specific compliance obligations will instead be implemented over time through sector-specific standards and filing requirements.
Vietnam Issues List of High-Risk AI Systems
On July 2, 2026, Deputy Prime Minister Ho Quoc Dung signed Decision No. 33/2026/WD-TTg, setting out the official list of high-risk AI systems, as outlined in the earlier Law on AI. The decision sets out the scope of application, criteria for identifying high-risk AI systems, responsibilities for implementation, and transitional provisions. The effective date of the decision is August 15, 2026.
The annex attached to the decision lists designated kinds of high-risk AI systems, categorized by sector, and the kind of conformity assessment required as per the Law on AI. High-risk systems will either have to get a conformity certification before deployment, or suppliers may conduct their own conformity assessment or hire an external accredited vendor to conduct the assessment.
The compliance date for AI systems in scope varies based on the sector. For any AI systems put into operation before August 15, 2026, AI systems in the healthcare, education, and finance sectors must be compliant before September 1, 2027. Any other AI systems in scope (in the ethnicity and religion, banking, litigation, and transportation sectors) that are put into operation before August 15, 2026, those systems must be compliant before March 1, 2027. For any other AI systems put into operation within six months of August 15, 2026, those systems must also be compliant before March 1, 2027.
Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on AI, privacy, and data security. Hintze attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of AI, privacy, and data security.
