🌐 Top 1 — The Mythos Affair
The biggest governance story of June was a model. Anthropic’s frontier system, Fable 5, sat at the centre of an intensifying and very volatile geopolitical dispute about who controls access to the most capable AI systems – applying Export Control logic to AI models and making global dependencies in the tech world at large and the AI-accelerated version of it painfully visible.
Two main moments defined this: 1: Within 5 days of its deployment, Fable was ordered to be retrieved from access for non-US citizens for, as the Anthropic statement said “national security concerns”. Anthropic chose to do so globally but the possibility of the already leading US market to get more time than others to implement this particular but potentially all future top AI models… The world lived with this state for 2.5 weeks, before 2: access was globally restored after additional safety layers (using classifiers) were built in.
Not receiving the deserved attention during these discussions: After lengthy negotiations (lobbying?), the EU, more specifically its Cyber Security Agency ENISA, can now benefit from Project Glasswing participation and access Mythos.
🔗Anthropic restores Claude Fable 5 after US restrictions lifted
🔗Anthropic invites EU to access Mythos hacking tech – POLITICO
🔗 Anthropic to offer EU access to its advanced Mythos model — CNBC
📋 Top 2 — The EU AI Act’s Enforcement Architecture Takes Shape
Two institutional developments in June confirmed that the EU AI Act is moving from text to reality.
First, the Scientific Panel of Independent Experts and the AI Advisory Forum were formally constituted — the two bodies that will underpin enforcement and provide technical guidance to the AI Office and national authorities. This matters because good enforcement requires credible expertise, and the composition of these bodies will shape what the Act actually does in practice.
Second, the Council gave its final green light to the simplification and streamlining package on 29 June — formally closing the legislative cycle on the Omnibus amendments – in – for the EU – a record time.
Together, these developments mark the transition from legislative politics to administrative reality. The interesting governance questions now live in the enforcement space: how national market surveillance authorities coordinate, how the AI Office exercises its powers, and whether the Scientific Panel becomes a genuinely independent voice.
The revised timelines and narrowed scope of obligations are now finalised – what organisations make of this (from delaying to actually making robust plans with now reliable timelines attached to them) remains to be seen!
🔗 AI Act enforcement gets independent expert support — European Commission
🔗 Council gives final green light to simplify and streamline AI rules — Council of the EU
🇩🇪 Top 3 — Germany Builds Its Own AI Safety Institute
On 9 June, the German Nationale Sicherheitsrat decided to establish a dedicated KI-Sicherheitsinstitut — a national AI safety institute modelled on the UK’s AI Safety Institute. The mandate: evaluate AI models for risk, covering both KI-Security (protection against attacks, cybersecurity) and KI-Safety (ensuring AI systems do not produce dangerous or harmful outputs).
The institute will initially operate as a virtual institution, drawing on existing structures at the Bundesnetzagentur and the BSI, before finding a permanent home. Digital Minister Karsten Wildberger has committed to staffing it with world-class expertise — though when and where that will materialise remains open.
The timing is notable. Germany is moving simultaneously with the EU’s enforcement architecture (Top 2) and in the context of an intensifying global race to build national AI safety capacity. The UK, US, and Japan already have equivalents. France is advancing its own – making one wonder whether within the EU it would not be more promising (and possibly more cost-effective) to have one strong, well-funded AI Safety Institute bundling brains (instead of making the member states compete for already sparse talent) while researching and guardrailing a technology in which all EU member states should have similar if not identical stakes…
🔗 KI: Bund plant KI-Sicherheitsinstitut für bessere Risikoanalyse — Handelsblatt
🔏 Top 4 — EU-US Data Transfers: Another House of Cards
In late June, the US Supreme Court issued a ruling on FTC enforcement powers that — according to noyb’s analysis — fundamentally undermines the legal basis for EU-US data transfers under the current Data Privacy Framework.
The argument: the DPF relies on the FTC being able to enforce data protection commitments made by US companies to EU citizens. If the FTC’s enforcement powers are curtailed, the adequacy decision underpinning the DPF is called into question. The European Commission will need to assess whether the framework still holds.
The direct AI governance implication: most major AI systems rely on transatlantic data flows for training, inference, and product delivery. Legal uncertainty around data transfers should be treated as an infrastructure risk and hence deserves close attention in the coming months.
🔗 US Supreme Court just blew up EU-US Data Transfers — noyb
🇺🇸 Top 5 — The White House AI Executive Order
President Trump signed a new Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security in June — framing AI primarily as a competitiveness and national security instrument, with a secondary nod to safety.
The EO focuses on reducing regulatory barriers for US AI development, accelerating federal AI adoption, and establishing a voluntary framework for frontier model developers around security and export controls (see Top 1). The human oversight provisions are notably lighter than those in the Biden-era EO it partially supersedes.
Read alongside the Pentagon’s parallel move to revise human-control rules for AI weapons systems, a pattern emerges: the US is deliberately loosening governance constraints on AI in strategic domains while tightening access controls at the geopolitical frontier. Deregulate domestically, restrict externally.
🔗 Promoting Advanced Artificial Intelligence Innovation and Security — The White House
⚠️ Top 6 — Prioritising AI Risks: What 272 Experts Say
The MIT AI Risk Initiative published its risk prioritisation study — a structured expert elicitation across 272 researchers and practitioners, asking which AI risks deserve the most policy attention and why. This builds on the MIT AI Risk Repository which has grown to cover over 1700 AI-related risks, which – I can tell from project experience – is difficult to track, prioritise and systematically select from.
The two most relevant findings are: 1. experts consistently flag misuse risks (deliberate weaponisation of AI capabilities) and 2. structural risks (concentration of power, erosion of accountability mechanisms) were marked as higher priority than many mainstream narratives suggest. Speculative long-term risks score lower than the discourse around them might imply, which might be explained by the rather practical and near-term focus of the experts consulted.
🔗 Priority AI Risks — MIT AI Risk Initiative
🔗 Prioritization of Risks from Artificial Intelligence — Full Paper (PDF)
🔄 Top 7 — When AI Builds Itself
Anthropic again: Anthropic’s Institute published a piece on recursive self-improvement — the scenario in which AI systems meaningfully contribute to the development of more capable AI systems, potentially accelerating capability gains beyond human ability to track or control.
The piece is careful and worth reading in full. It does not claim recursive self-improvement is imminent or inevitable. It does argue that the governance implications of even partial recursive improvement are underexplored — and that the window for developing adequate oversight mechanisms may be shorter than most institutional timelines assume.
The uncomfortable structural question this raises: our frameworks are built around human review of AI outputs. If AI systems begin to shape the training and evaluation of successor systems in non-trivial ways, what does meaningful human oversight even look like?
🔗 When AI Builds Itself — Anthropic Institute
📜 Top 8 — Labelling AI-Generated Content: The Code of Practice
Published on 10 June, the Code of Practice on Transparency of AI-Generated Content is a multi-stakeholder instrument developed under the AI Office that helps providers and deployers comply with their Article 50 obligations — applicable from 2 August 2026.
The Code has two sections: one for providers (machine-readable marking and detection of AI-generated content) and one for deployers (labelling of deepfakes and AI-generated text on matters of public interest). Adherence is voluntary, but Article 50 obligations are not — and just as with e.g. the Code of Practice on General Purpose AI, published almost a year ago, signatories benefit from a compliance presumption; non-signatories must demonstrate equivalence to national authorities individually.
🔗 Code of Practice on Transparency of AI-Generated Content — European Commission
🏷️ Top 9 — Seeing is Believing: The EU’s AI Content Icons
Alongside the Code of Practice, the EU published a standardised set of icons for labelling AI-generated content — a small but symbolically meaningful step. The ambition: consistent, recognisable visual signals across Member States, platforms, and content types, so that users across the EU encounter the same indicators regardless of where they encounter AI-generated material.
Consistency in labelling matters for user trust and market functioning. But effective transparency is ultimately a design and literacy challenge, not just a legal one. A standardised icon – solves the coordination problem – in theory at least. In practice, many organisations have long established icons either motivated from a UX-perspective or an AI Governance-view which did not want to wait until one month before Article 50 obligations become applicable… I remain curious how wide their distribution will be a year from now – and whether the AI Office monitors actual uptake or simply signatories to the Code.
🔗 EU Icons for labelling AI-generated content — European Commission
🏛️ Top 10 — A Bipartisan AI Draft in Congress
Politico reported in early June that Representatives Obernolte and Trahan were circulating a bipartisan AI legislative draft — a rare signal of movement on US federal AI governance, which has remained largely stalled at the legislative level despite significant executive activity.
Details remain sparse. Noteworthy though is the bipartisan framing: AI legislation in the US has struggled to find cross-aisle traction, with Republicans tending to resist federal preemption of state laws and Democrats pushing harder on safety and civil rights protections. A joint draft from both sides suggests at least some appetite for a negotiated baseline.
Why does this matter for EU practitioners? A functioning US federal AI framework would matter enormously for regulatory coherence – would we end up with closer coordination or a competing standard?
