If you just remember one thing from this briefing…
The EU AI Act's August deadline did not move for everyone — only the high-risk rules did.
Regulation (EU) 2026/1744 pushed the Annex III high-risk deadline from 2 August 2026 to 2 December 2027, but
left Article 50's chatbot-disclosure and deepfake-labelling duties untouched. Ask your AI governance owner
today which deployed systems trigger Article 50, and whether you can evidence it.
Priority27 Jul
AI Act Omnibus splits the August deadline in two
Regulation (EU) 2026/1744 entered into force 27 July, moving the Annex III high-risk deadline from 2
August 2026 to 2 December 2027. Article 50 — chatbot disclosure, AI-content and deepfake labelling — was
not deferred and became enforceable on 2 August as originally scheduled.
So what: treat these as two tracks. Confirm which deployed systems trigger Article
50 and evidence it — the Annex III extension does not help you here.
Priority23 Jul
Azure automation bug drops Microsoft 365 for five hours
An automated system converted a routine West US network-maintenance request into instructions that
removed more routes than intended, Microsoft confirmed. Teams, SharePoint, OneDrive, Copilot, Outlook and
Azure itself were disrupted from 14:44 to 19:41 UTC on 23 July; SharePoint accounted for 78 percent of
reported complaints.
So what: automation, not an attacker, took down Copilot and SharePoint for five
hours. If your continuity plan assumes region failover, confirm it survives a control-plane bug, not just
hardware failure.
PriorityAct by 1 Sep
Microsoft retires SMS and voice MFA, makes passkeys default
Microsoft announced 13 July — before this window, still unresolved — that SMS and voice MFA in Entra ID
retires, with passkeys becoming default. Retirement begins 1 September 2026, with a hard cutoff on 1
February 2027. A related Conditional Access change on security-information registration is already
live.
So what: inventory every account still using SMS or voice as a second factor and
start migration well before 1 September — helpdesk load spikes when enforcement, not choice, drives
adoption.
Watch31 Jul
AWS patches a high-severity flaw in Bedrock AgentCore's tool path
AWS disclosed CVE-2026-18830 (CVSS 8.6), insufficient input validation in the managed InvokeHarness API
behind Bedrock AgentCore, fixed 31 July. The flaw sat in the path letting an AgentCore-hosted agent invoke
tools — the same weakness class researchers have probed across agent runtimes all year.
So what: confirm your account has AWS's fix and audit AgentCore agents for tool
calls that should need explicit model authorisation before executing.
Google Cloud: a quiet fortnight — nothing met the inclusion bar in the
fourteen days to 2 August.