Last Update: 08/01/2026 at 1:34 PM EST

Morning Briefing: AI Governance

Thursday, June 25, 2026

June 25, 2026

RBI Draft Rules Put Bank AI Controls On The Board Agenda

The day’s clearest hard-policy movement came from financial supervision rather than from a broad AI statute. The Reserve Bank of India’s draft rules for banks made the practical direction of AI governance visible: inventory every model, classify risk, keep humans reachable, preserve board accountability, and be able to shut a system down when it goes wrong.

Elsewhere, yesterday was mostly a continuation day. In the US, state attorneys general and campaign spending kept filling the space left by unsettled federal AI law; in Europe, lawyers continued to parse delayed EU AI Act deadlines without treating HR AI as low risk; and institutions from local governments to universities kept writing internal rules for ordinary AI use. The day was less about a new grand bargain than about AI concern being converted into operating controls.

India’s central bank moved the most concretely. The Reserve Bank of India released draft AI governance guidelines for banks and other regulated financial entities, with requirements for board-approved AI governance, model inventories, risk classifications, human oversight, high-risk model approval by a board-level Risk Management Committee, customer disclosure for AI-facing systems, an option to reach a human, and kill switches for harmful or erroneous outputs. The proposal also keeps banks accountable for third-party AI systems, including independent validation and cybersecurity controls for generative AI used with customers. Public comments are open until July 24.

The importance of the RBI draft is that it treats AI failures as supervisory risk, not just technology risk. In banking, that distinction matters: a model that misclassifies customers, produces erroneous advice, or fails under adversarial conditions can become a governance, conduct, cybersecurity, and board-accountability problem at once. The draft does not merely ask banks to be responsible; it describes the machinery responsibility would require.

In the US, yesterday’s strongest enforcement point came from Kevin Frankel’s analysis in Mondaq: state attorneys general are already acting as primary AI enforcers under existing consumer protection, civil rights, privacy, biometric, and professional-licensing laws. The examples matter because they do not depend on a future federal AI statute: a Texas investigation into generative AI healthcare claims, a Florida criminal investigation involving a chatbot and a violent incident, and Pennsylvania efforts tied to alleged chatbot licensing misrepresentations all show how AI conduct is being pulled into familiar legal authorities.

AI regulation also continued to move through politics. Axios reported that more than $5.5 million in outside spending flowed into Colorado’s 8th Congressional District Democratic primary in support of Manny Rutinel, with money tied to figures and employees from the AI and technology world. The race is not proof of a national realignment, but it is another concrete example of AI governance leaving the specialist-policy lane and becoming part of electoral competition over how strict state and federal rules should be.

EU AI Act timing remained an implementation story, not a rollback story. Morgan Lewis noted that selected high-risk obligations are expected to move later, with some requirements landing in late 2027 or 2028, but HR and employment tools remain within the high-risk category when used for recruitment, CV screening, candidate assessment, performance management, promotion, discipline, dismissal, or monitoring. AI literacy duties and prohibitions on unacceptable-risk practices are already in force, and GDPR Article 22 still matters for solely automated decision-making and profiling.

Key Points

  • Sector regulators and institutions are getting more specific before broad legal regimes are fully settled. The RBI draft, HR-focused EU AI Act guidance, manufacturing governance advice, local-government chatbot policies, and CMU’s campus roadmap all point toward the same practical control set: inventories, risk tiers, documented oversight, approved tools, audit trails, vendor scrutiny, and escalation paths.
  • Accountability is moving upward inside organizations. Banks would need board-level approval for high-risk models under the RBI proposal; manufacturers are being advised to create cross-functional governance committees; Bend and Deschutes County have used internal policies and steering or oversight structures for chatbot use; CMU’s roadmap calls for an AI Governance & Innovation Council with decision authority and dedicated staffing. The governing question is becoming who has authority to approve, stop, or explain AI use.
  • Public-facing AI is increasingly being treated as a disclosure and handoff problem. RBI’s draft would require banks to tell customers when an AI model is being used and give them access to a human. Central Oregon local-government policies require human fact-checking and disclosure for AI-generated images and documents. In employment, EU-facing organizations still need transparency and, where relevant, works-council consultation. The recurring point is simple: AI use is harder to defend when affected people cannot tell it is happening or reach a responsible human.
  • China’s latest public positioning stayed diplomatic rather than operational. Coverage from Let’s Data Science reported that Premier Li Qiang told the World Economic Forum meeting in Dalian that China would continue participating in global AI governance, alongside a new Chinese whitepaper and calls for a global AI cooperation organization. That matters as geopolitical messaging, but the practical question remains whether these statements turn into engagement with existing multilateral processes or new institutional commitments.

Implications

For banks and financial-technology vendors serving India, the RBI draft is a near-term compliance planning document even before it is final. Firms should be able to identify every AI model in use, classify its risk, document human oversight, test shutdown procedures, and explain how third-party systems are validated and monitored.

For US companies, the absence of a single federal AI law is not a safe harbor. State attorneys general can investigate AI products through older statutes, especially where the facts involve health claims, child or consumer harm, discrimination, privacy, biometric data, or professional licensing. Multistate-ready documentation, auditing, and vendor controls are becoming practical defenses, not just governance niceties.

For employers and HR technology providers, EU timing relief should not be read as permission to wait. The delayed high-risk obligations may change sequencing, but the systems remain legally sensitive because they affect hiring, monitoring, promotion, discipline, and dismissal. Existing privacy law, bias controls, transparency duties, and AI literacy requirements still shape what responsible deployment looks like.

For public-sector and education leaders, yesterday’s local and campus examples show a quieter route by which AI governance becomes real: procurement limits, approved-tool lists, sensitive-data prohibitions, training, disclosure rules, and review of AI tools before deployment. These measures rarely attract the attention of a statute, but they are often what employees and users actually experience first.

For policy teams, the Colorado spending story reinforces that AI governance is now part of political strategy. That does not mean every race is an AI referendum, but it does mean regulatory posture, state-law preemption, and safety reporting duties are becoming issues around which money and candidate positioning can organize.

Watchpoints

Watch

Whether RBI revises or strengthens the bank AI draft after the July 24 comment deadline, especially around kill switches, third-party validation, and board-level approval.

Watch

Whether state attorneys general bring more coordinated AI actions under consumer protection, civil rights, privacy, biometric, healthcare, or professional-licensing laws.

Watch

Whether AI-linked political spending becomes visible in additional congressional races and whether candidates take clearer positions on federal preemption of state AI laws.

Watch

Whether forthcoming EU AI Act standards and guidance give employers enough detail to operationalize high-risk HR obligations before later deadlines arrive.

Watch

Whether China’s calls for global AI governance cooperation produce concrete engagement, a new organization, or continued high-level positioning without binding follow-through.

Fallout

Yesterday’s meaningful movement was concentrated in three larger subjects: sector-specific AI controls, US state enforcement and political pressure, and international governance positioning. The strongest change was practical rather than rhetorical, with regulators and institutions specifying who must approve AI use, how systems must be documented, and when humans must remain reachable.

Sector AI Rules Become More Operational

AI governance is increasingly being built through sector rules and institutional policies rather than only through broad national statutes. Financial services, employment, manufacturing, local government, and education each face different legal settings, but the operational expectations are becoming more recognizable across them.

Fresh developments

The RBI draft gave this issue its clearest hard edge, proposing board-approved AI governance for banks, model inventories, risk tiers, human oversight, customer disclosures, third-party accountability, and kill switches. Morgan Lewis’s EU AI Act analysis kept HR AI in the high-risk category despite expected delays, while Foley & Lardner’s manufacturing guidance emphasized sandbox testing, drift monitoring, audit trails, and emergency shutdown mechanisms for agentic supply-chain systems.

Why we noticed

These developments matter because they describe the controls organizations will actually have to build. The legal forms differ, but the emerging baseline is concrete: know what AI systems exist, classify their risk, monitor them after deployment, preserve evidence, assign human authority, and have a way to stop harmful operation.

Watch for:

  • Final RBI requirements after the comment period closes.
  • EU standards and guidance that clarify high-risk HR AI obligations.
  • Whether shutdown, monitoring, and audit-trail expectations become standard in procurement and vendor contracts.

US State Enforcement And AI Politics Fill The Federal Gap

The US AI governance debate remains unsettled at the federal level, leaving states, state attorneys general, and campaign politics to shape many of the practical pressures companies face. That makes enforcement exposure and political incentives part of the same operating environment.

Fresh developments

Mondaq’s analysis highlighted how state attorneys general are using existing laws to investigate AI-related conduct without waiting for AI-specific federal rules. The Future of Privacy Forum’s DC Privacy Forum write-up showed federal privacy and AI governance debates continuing around centralized enforcement, consumer protection, youth safety, workplace AI, and state-federal coordination. Axios added a more political dimension, reporting heavy outside spending in a Colorado congressional primary where candidate records intersected with state AI guardrail debates.

Why we noticed

The practical lesson is that companies cannot treat US AI compliance as a future federal event. State investigations can begin under old authorities, state legislatures continue to set guardrails, and AI policy preferences are becoming relevant to campaign funding and candidate positioning.

Watch for:

  • New or coordinated state attorney general investigations involving chatbots, health claims, biometric data, or discrimination.
  • Federal proposals that would centralize enforcement or preempt state AI laws.
  • Further campaign spending tied to AI safety, transparency, or state-law preemption.

Institutional AI Adoption Needs Internal Rules

AI governance is also developing inside public agencies, universities, and other institutions that are adopting tools before comprehensive external rules arrive. These policies often determine day-to-day use more directly than national legislation.

Fresh developments

Local coverage in Central Oregon showed Bend and Deschutes County using chatbots and Microsoft 365 Copilot under internal controls, including approved-tool limits, sensitive-data restrictions, human fact-checking, disclosure rules, training, and steering structures. CMU’s roadmap called for AI literacy education, role-based training, secure institutional infrastructure, a tool-review process, and a governance body with authority and staffing.

Why we noticed

These are modest developments individually, but they show how AI governance is entering ordinary administration. The key questions are not only whether an institution permits AI, but which tools are approved, what data is off-limits, who checks outputs, and how users are trained.

Watch for:

  • Whether local governments expand from internal chatbot use to public-facing permitting, services, or website assistants.
  • Whether universities make AI literacy and tool review mandatory across students, faculty, and staff.
  • Whether disclosure rules for AI-generated public documents become more consistent.

Global AI Governance Remains More Diplomatic Than Binding

International AI governance continues to involve declarations, whitepapers, summit statements, and proposals for coordination. These can shape norms, but they matter most when they lead to specific institutions, standards, or supervisory commitments.

Fresh developments

Chinese Premier Li Qiang told the World Economic Forum meeting in Dalian that China would continue participating in global AI governance, while related reporting noted a Chinese AI governance whitepaper and calls from senior diplomats for a global AI cooperation organization. The Future of Privacy Forum’s coverage also reflected continuing discussion of global AI coordination alongside privacy and digital-sovereignty debates.

Why we noticed

China’s posture matters because global AI governance is inseparable from geopolitical competition over standards, market access, safety norms, and technology control. But yesterday’s evidence remained largely declaratory. The important distinction is between participation language and concrete participation.

Watch for:

  • Whether China proposes specific terms, membership, or authority for a global AI cooperation organization.
  • Whether existing multilateral AI processes incorporate or resist China’s proposals.
  • Whether global governance language is linked to concrete standards, audits, or incident-reporting practices.

Final Thought

Yesterday’s developments were not dramatic, but they were revealing. AI governance is becoming less a debate over whether oversight should exist and more a contest over where it will be embedded: in bank supervision, state enforcement files, campaign spending, HR compliance, procurement rules, and internal operating policies. The shape of AI regulation is increasingly being drawn in the places where organizations must prove they can manage systems after they are deployed.