ARTICLE
17 August 2026

Two-Minute Recap - IT Law Matters Around The Globe July 2026

GT
Gen Temizer

Contributor

Gen Temizer is a leading independent Turkish law firm located in Istanbul's financial centre. The Firm has an excellent track record of handling cross-border matters for clients and covers the full bandwidth of most complex transactions and litigation with its cross-departmental, multi-disciplinary and diverse team of over 30 lawyers. The Firm is deeply rooted in the local market with over 80 years of combined experience of the name partners while providing the highest global standards of legal services.
On 7 July 2026, the European Commission presented an EU Action Plan on Cybersecurity and Artificial Intelligence to address cybersecurity risks arising from advanced AI models while promoting their use for cyber defence.
Turkey Technology
Ebru Temizer’s articles from Gen Temizer are most popular:
  • in Turkey
Gen Temizer are most popular:
  • within Strategy, Tax and International Law topic(s)

European Commission Unveils Action Plan on AI and Cybersecurity

On 7 July 2026, the European Commission presented an EU Action Plan on Cybersecurity and Artificial Intelligence to address cybersecurity risks arising from advanced AI models while promoting their use for cyber defence. The plan includes the creation of an EU capacity to evaluate advanced AI models, expected to become operational in 2027, as well as a secure testing platform developed by European Union Agency for Cybersecurity (“ENISA”) and the Commission’s Joint Research Centre to support critical sectors including finance, energy, health, transport and public administration.

The Commission also plans to develop a European framework for structured access to advanced AI models, promote the use of AI to identify and remediate software vulnerabilities, and launch an EU Grand Challenge on AI for cybersecurity to support European AI-based cybersecurity solutions. The initiative builds on the EU’s existing regulatory framework, including the AI Act, NIS2 Directive, Cyber Resilience Act and Cyber Solidarity Act - purpose AI models set to be enforced from 2 August 2026.

EDPB Issues New Guidelines on Anonymisation and AI Web Scraping and

Finalises Blockchain Guidelines

On 8 July 2026, the EDPB adopted new guidelines on anonymisation and web scraping in the context of generative AI, while also adopting the final version of its guidelines on processing personal data through blockchain technologies. The anonymisation guidelines introduce a practical framework under which data may be considered anonymous where individuals cannot be isolated from a dataset, their data cannot be linked across datasets, and information about them cannot be inferred.

The web scraping guidelines clarify when and how personal data may be collected from the web and used for generative AI development, addressing issues such as the legal grounds for processing, transparency, data minimisation and accuracy. The EDPB also stresses that stricter conditions apply where web scraping captures sensitive personal data, such as health information or data revealing racial or ethnic origin. Both the anonymisation and web scraping guidelines are open for public consultation until 30 October 2026.

UNESCO Outlines Nine Emerging Approaches to AI Regulation

UNESCO published Governing AI: Nine Emerging Approaches for Lawmakers Worldwide, a policy brief aimed at helping legislators translate global AI principles into workable national governance frameworks. The document outlines nine regulatory approaches, principles-based, standards-based, agile and experimental, facilitating and enabling, transparency-focused, adaptation of existing laws, risk-based, rightsbased and liability-based, and illustrates how these approaches are reflected in laws and legislative proposals across different jurisdictions.

The brief emphasises that these approaches are not mutually exclusive and may be combined depending on a country’s regulatory needs and institutional context. Rather than recommending a single model, UNESCO encourages lawmakers to tailor their approach while considering human rights, digital divides, inclusive policymaking, regulatory flexibility and implementation capacity

European Commission

Unveils Action Plan on AI and Cybersecurity

On 7 July 2026, the European Commission presented an EU Action Plan on Cybersecurity and Artificial Intelligence to address cybersecurity risks arising from advanced AI models while promoting their use for cyber defence. The plan includes the creation of an EU capacity to evaluate advanced AI models, expected to become operational in 2027, as well as a secure testing platform developed by European Union Agency for Cybersecurity (“ENISA”) and the Commission’s Joint Research Centre to support critical sectors including finance, energy, health, transport and public administration.

The Commission also plans to develop a European framework for structured access to advanced AI models, promote the use of AI to identify and remediate software vulnerabilities, and launch an EU Grand Challenge on AI for cybersecurity to support European AI-based cybersecurity solutions. The initiative builds on the EU’s existing regulatory framework, including the AI Act, NIS2 Directive, Cyber Resilience Act and Cyber Solidarity Act - purpose AI models set to be enforced from 2 August 2026.

EDPB Issues New Guidelines on Anonymisation and AI Web Scraping and Finalises Blockchain Guidelines

On 8 July 2026, the EDPB adopted new guidelines on anonymisation and web scraping in the context of generative AI, while also adopting the final version of its guidelines on processing personal data through blockchain technologies. The anonymisation guidelines introduce a practical framework under which data may be considered anonymous where individuals cannot be isolated from a dataset, their data cannot be linked across datasets, and information about them cannot be inferred.

The web scraping guidelines clarify when and how personal data may be collected from the web and used for generative AI development, addressing issues such as the legal grounds for processing, transparency, data minimisation and accuracy. The EDPB also stresses that stricter conditions apply where web scraping captures sensitive personal data, such as health information or data revealing racial or ethnic origin. Both the anonymisation and web scraping guidelines are open for public consultation until 30 October 2026.

UNESCO Outlines Nine Emerging Approaches to AI Regulation

UNESCO published Governing AI: Nine Emerging Approaches for Lawmakers Worldwide, a policy brief aimed at helping legislators translate global AI principles into workable national governance frameworks. The document outlines nine regulatory approaches, principles-based, standards-based, agile and experimental, facilitating and enabling, transparency-focused, adaptation of existing laws, risk-based, rightsbased and liability-based, and illustrates how these approaches are reflected in laws and legislative proposals across different jurisdictions.

The brief emphasises that these approaches are not mutually exclusive and may be combined depending on a country’s regulatory needs and institutional context. Rather than recommending a single model, UNESCO encourages lawmakers to tailor their approach while considering human rights, digital divides, inclusive policymaking, regulatory flexibility and implementation capacity

Council of Europe Investigates Alleged 300 GB Data Breach

The Council of Europe is investigating a potential cyberattack after extortion group ShinyHunters claimed to have stolen nearly 300 GB of data comprising more than 429,000 files from the organisation’s network. The group alleges that the compromised information spans several departments and includes payroll records, CVs, contracts, bank account details, performance evaluations and sensitive employee information, including identification, social security and medical data.

The group threatened to publish the allegedly stolen data unless the Council of Europe entered into negotiations by 16 June 2026. The Council of Europe has confirmed that it is investigating the incident but has not confirmed that a breach occurred or verified the nature or volume of the data allegedly obtained.

Singapore issues draft guidance on personal data use in generative AI

Singapore’s Personal Data Protection Commission proposed non-binding guidelines applying the Data Protection Act across the entire generative AI supply chain. The proposed framework addresses web scraping, consent, transparency, data minimisation, and accountability, while clarifying that organisations relying on personal data for AI development must adopt appropriate safeguards and provide AI-specific privacy notices where required. The consultation reflects Singapore’s continued efforts to promote responsible AI innovation alongside strong data protection standards.

Anthropic shuts down top AI Models Over US Cybersecurity Concern

Anthropic has suspended global access to its most advanced AI models, Claude Fable 5 and Mythos 5, following an urgent US government directive restricting their use by foreign nationals over cybersecurity jailbreaking concerns. Although the Trump administration and the UK’s AI Security Institute raised concerns about the models’ potential to exploit cyber defences, Anthropic maintains that the identified vulnerability is minor, can be addressed through technical improvements, and is not unique to its systems, noting that similar capabilities exist on competing platforms such as ChatGPT. The decision has fuelled renewed calls within Europe for greater technological sovereignty to reduce dependence on US-based AI providers, while cybersecurity experts have warned that restricting global access to advanced AI tools could hinder international collaboration on cyber defence and limit the testing necessary to strengthen resilience against increasingly sophisticated AI-enabled threats.

The Council of Europe is investigating a potential cyberattack after extortion group ShinyHunters claimed to have stolen nearly 300 GB of data comprising more than 429,000 files from the organisation’s network. The group alleges that the compromised information spans several departments and includes payroll records, CVs, contracts, bank account details, performance evaluations and sensitive employee information, including identification, social security and medical data.

The group threatened to publish the allegedly stolen data unless the Council of Europe entered into negotiations by 16 June 2026. The Council of Europe has confirmed that it is investigating the incident but has not confirmed that a breach occurred or verified the nature or volume of the data allegedly obtained.

Singapore issues draft guidance on personal data use in generative AI

Singapore’s Personal Data Protection Commission proposed non-binding guidelines applying the Data Protection Act across the entire generative AI supply chain. The proposed framework addresses web scraping, consent, transparency, data minimisation, and accountability, while clarifying that organisations relying on personal data for AI development must adopt appropriate safeguards and provide AI-specific privacy notices where required. The consultation reflects Singapore’s continued efforts to promote responsible AI innovation alongside strong data protection standards.

Anthropic shuts down top AI Models Over US Cybersecurity Concern

Anthropic has suspended global access to its most advanced AI models, Claude Fable 5 and Mythos 5, following an urgent US government directive restricting their use by foreign nationals over cybersecurity jailbreaking concerns. Although the Trump administration and the UK’s AI Security Institute raised concerns about the models’ potential to exploit cyber defences, Anthropic maintains that the identified vulnerability is minor, can be addressed through technical improvements, and is not unique to its systems, noting that similar capabilities exist on competing platforms such as ChatGPT. The decision has fuelled renewed calls within Europe for greater technological sovereignty to reduce dependence on US-based AI providers, while cybersecurity experts have warned that restricting global access to advanced AI tools could hinder international collaboration on cyber defence and limit the testing necessary to strengthen resilience against increasingly sophisticated AI-enabled threats.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More