Back to Daily Brief

Public Policy & Governance

12 sources analyzed to give you today's brief

Top Line

The European Commission has formally designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act, triggering binding compliance obligations including algorithmic audits, risk assessments, and content moderation transparency requirements — the most consequential regulatory classification of a generative AI product to date.

A federal judge has ruled that the Department of Defense unlawfully retaliated against Anthropic in violation of the First Amendment, finding that the Pentagon's 'supply chain risk' designation was punishment for Anthropic refusing to permit its technology for mass surveillance of U.S. persons — a significant constraint on executive branch discretion over AI procurement.

The top Pentagon official overseeing military AI policy, Emil Michael, sold between $5m and $25m in Perplexity stock months after reaping up to $24m from xAI holdings, raising acute conflicts-of-interest questions about the integrity of U.S. military AI governance at the senior official level.

Bank of England Governor Andrew Bailey, writing as FSB Chair, has formally warned G20 finance ministers and central bank governors that frontier AI poses systemic financial stability risks, elevating the issue from national regulatory concern to a coordinated international supervisory agenda.

Guardian Australia analysis finds AI-generated hallucinations and misinformation are infiltrating parliamentary submissions across the political spectrum, with fabricated citations and misrepresented research entering the formal evidentiary record of government inquiries.

Key Developments

EU Formally Designates ChatGPT Under the Digital Services Act — A Regulatory Landmark

The European Commission has designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act, alongside Reddit and Roblox as Very Large Online Platforms (VLOPs). The VLOSE classification is significant: it is not merely a labelling exercise. Under DSA Articles 33–43, OpenAI now faces mandatory annual systemic risk assessments, independent algorithmic audits, transparency reporting, data access obligations for vetted researchers, and the threat of fines up to 6% of global annual turnover for non-compliance. The Commission's enforcement directorate, not a national Digital Services Coordinator, retains direct supervisory authority over VLOSE-designated entities. European Commission

This designation is distinct from, and runs parallel to, obligations under the EU AI Act, which enters phased application through 2027. ChatGPT now sits at the intersection of two major regulatory regimes. The DSA designation is immediately operative — there is no extended implementation runway. OpenAI has 30 days to acknowledge the designation and four months to file its first risk assessment. The Commission's track record on DSA enforcement — including ongoing proceedings against X and Meta — signals this is not a symbolic gesture. The designation also sets a precedent: any AI system functioning as a search interface reaching DSA thresholds can expect equivalent classification, which has direct implications for Google's Gemini products and Microsoft's Copilot-integrated search.

Why it matters

This is the first time a generative AI product has been bound by the DSA's most demanding compliance tier, establishing a concrete regulatory template that other jurisdictions — including the UK's forthcoming AI and digital regulation reforms — will watch closely.

What to watch

Whether OpenAI contests the VLOSE classification through EU courts, and how the Commission's first systemic risk assessment for a generative AI product is scoped and enforced in practice.

Federal Court Rules DoD's Retaliation Against Anthropic Unconstitutional — Constraining Executive AI Procurement Power

A federal district judge has ruled that the Department of Defense's designation of Anthropic as a 'supply chain risk' constituted unlawful retaliation in violation of the First Amendment, after the company declined to permit its technology for mass surveillance of U.S. persons. The Electronic Frontier Foundation, which joined an amicus coalition, confirmed the ruling via its legal blog. EFF The Lawfare podcast separately confirmed a judge 'found the Pentagon's supply chain risk designation of Anthropic unlawful,' contextualising it within broader Trump administration legal vulnerabilities. Lawfare

The ruling has immediate practical consequence: it invalidates the DoD designation and potentially opens the department to injunctive relief and damages claims. More structurally, it establishes that the executive branch cannot weaponise procurement and security-designation processes to coerce AI companies' policy positions. This matters beyond Anthropic — it signals that AI developers who decline certain government use cases on ethical or policy grounds retain constitutional protection against administrative retaliation. The ruling lands in the context of wider tension between the Trump administration's expansive interpretation of executive authority over the technology sector.

Why it matters

The decision creates a judicially enforced boundary on how the executive branch can use national security and procurement mechanisms to discipline AI companies for protected speech, with significant implications for the independence of AI developers contracting with the federal government.

What to watch

Whether the DoD appeals, and whether Congress moves to clarify the statutory basis for supply chain risk designations in a way that either insulates or constrains future executive action.

Pentagon AI Chief's Stock Sales Expose Structural Governance Failures at the Top of U.S. Military AI Policy

Emil Michael, the senior Pentagon official responsible for military AI policy, has now sold holdings in two AI companies — xAI (up to $24m profit earlier this year) and Perplexity ($5m–$25m) — while holding authority over policy affecting those sectors. Federal financial disclosure records reviewed by The Guardian confirm the transactions. The Guardian U.S. executive branch ethics rules under 18 U.S.C. § 208 prohibit participation in government matters that have a direct and predictable effect on one's financial interests, and OGE regulations require divestiture or recusal. Whether Michael has formally recused from relevant procurement or policy decisions — and whether any OGE waiver was obtained — is not confirmed in publicly available records.

This is not a peripheral compliance issue. The DoD is the largest single buyer of AI products and services in the U.S. government, and military AI policy decisions — on procurement, interoperability standards, and use-case authorisation — directly affect the market valuations of firms like xAI and Perplexity. The concentration of this decision-making authority in an official with undisclosed or inadequately disclosed financial interests in the sector represents a systemic governance failure, not merely an individual ethics question. Congress has not yet formally requested OGE review or initiated oversight hearings based on publicly available records.

Why it matters

The case illustrates how the U.S. has not yet built adequate institutional safeguards against financial conflicts of interest at the nexus of military AI policymaking and the commercially concentrated AI industry.

What to watch

Whether the DoD Inspector General or Senate Armed Services Committee initiates a formal review of Michael's recusal obligations, and whether OGE has issued any waiver or guidance related to his holdings.

FSB Chair Bailey Elevates AI Financial Stability Risk to G20 Agenda — Signalling a Coordinated Supervisory Response

Bank of England Governor Andrew Bailey, acting in his capacity as Chair of the Financial Stability Board, has sent a formal two-page letter to G20 finance ministers and central bank governors warning that frontier AI models are generating systemic financial stability risks — specifically the potential for AI-enabled cyber disruption to propagate rapidly across jurisdictions. The Guardian The FSB has formal standing as the G20's primary international financial regulatory coordination body, meaning this is not political rhetoric — it is the opening of a structured multilateral supervisory process.

The FSB's analytical framing — cross-border contagion risk from AI-enabled cyber incidents — is notable because it moves the governance conversation away from domestic AI regulation (content, bias, transparency) toward systemic resilience and macroprudential frameworks. This maps onto existing FSB work on operational resilience and third-party risk, where the Board has previously issued binding guidance adopted by member jurisdictions. The practical implication is that central banks and financial regulators in G20 members may face pressure to extend their operational resilience frameworks — currently focused on cloud concentration risk — to explicitly cover AI model dependencies in financial market infrastructure.

Why it matters

FSB-level engagement transforms AI financial stability from a national regulatory concern into a coordinated international supervisory agenda with established enforcement pathways through member central banks and finance ministries.

What to watch

Whether the FSB publishes a formal consultation paper or thematic review on AI systemic risk before the next G20 summit, and how member jurisdictions — particularly the U.S. Federal Reserve and ECB — translate this into domestic supervisory expectations.

AI Hallucinations Are Corrupting Parliamentary Evidence — A Governance Integrity Crisis with No Current Remedy

Guardian Australia's analysis of policy submissions to parliamentary inquiries has found that AI-generated content — including fabricated citations, misrepresented research findings, and invented sources — is entering the formal evidentiary record of government inquiries across the political spectrum. The Guardian This is not a hypothetical risk: it is a documented, current failure of the quality controls underpinning evidence-based policymaking in a Westminster system.

Australian parliamentary committees have no standardised mechanism to verify the accuracy of submissions or detect AI-generated content. The problem is structural: the submission process relies on good-faith accuracy by submitters, and committee secretariats lack both the tools and the mandate to conduct citation verification at scale. This is a jurisdiction-specific finding, but the underlying vulnerability is universal — any legislature that accepts written submissions without verification protocols is exposed to the same dynamic. The UK Parliament's petitions and committee systems, the U.S. notice-and-comment rulemaking process (which accepts public comments directly into the administrative record), and EU public consultation mechanisms face identical structural exposure.

Why it matters

If the evidentiary foundations of legislative and regulatory processes are compromised by AI-generated misinformation at scale, the legitimacy and quality of resulting legislation is directly impaired — this is a governance integrity problem, not merely a technology content moderation issue.

What to watch

Whether Australian parliamentary authorities issue guidance on AI-generated submissions and whether any jurisdiction introduces formal verification requirements or submission authenticity declarations as a regulatory response.

Signals & Trends

The 'Revolving Door' Dynamic in AI Governance Is Accelerating — and Moving in Both Directions

Matt Clifford, who designed the UK's AI strategy and advised both Starmer and Sunak, has joined Anthropic in a senior role less than a year after leaving his Downing Street position. The Guardian Simultaneously, Emil Michael — a direct industry hire — sits atop U.S. military AI policy with unresolved financial conflicts. These are not isolated personnel stories. They represent a structural pattern in which the small pool of individuals who understand frontier AI governance is being absorbed by industry at the exact moment governments most need that expertise. The result is a knowledge asymmetry that compounds the already significant information advantages AI companies hold over regulators. For policy professionals, the practical implication is that regulatory bodies need to urgently invest in building durable institutional knowledge — not dependent on individual senior hires — including through technical secondments, regulatory fellowship programmes, and mandatory post-employment cooling-off periods specifically calibrated for AI governance roles.

Congressional Alarm on AI Surveillance Capabilities Is Creating Bipartisan Regulatory Pressure — But No Legislative Vehicle Yet

Capitol Hill demonstrations showing AI's ability to rapidly aggregate commercial database information — gun ownership, religious affiliation, personal habits — have alarmed both Democratic and Republican lawmakers. Politico Bipartisan alarm is a necessary but not sufficient condition for legislation. The U.S. lacks a federal comprehensive data privacy law, and without that foundation, AI-specific surveillance restrictions face significant drafting and enforcement challenges. The more immediate regulatory pathway may be through existing FTC authority over unfair or deceptive practices, or through state-level privacy frameworks — California, Texas, and Virginia have active legislative agendas. The pattern to track: whether this bipartisan concern coalesces around a specific legislative vehicle before the November 2026 midterm cycle begins to crowd out policy bandwidth.

The Line Between AI Safety Governance and National Security Apparatus Is Blurring in Ways That Resist Oversight

Three separate developments this week illuminate a single underlying trend: the Anthropic hacking incidents involving unauthorised access to third-party systems; the DoD retaliation case revealing the military's attempt to impose use-case conditions on commercial AI developers; and the Lawfare discussion of terrorist use of AI alongside government counter-AI measures. Governments are increasingly treating AI safety and national security as overlapping domains, which creates governance structures that are less transparent, less subject to legislative oversight, and more resistant to judicial review. The Pentagon's supply chain risk mechanism — now ruled unconstitutional in the Anthropic case — exemplifies how security-framed regulatory tools can be misapplied. For policy professionals, the risk is that legitimate AI safety governance becomes entangled with national security classifications in ways that hollow out accountability frameworks without improving actual security outcomes.

Explore Other Categories

Read detailed analysis in other strategic domains