This website uses cookies

Read our Privacy policy and Terms of use for more information.

This week: 11 regulatory developments across 6 jurisdictions. The EU AI Act's supervisor can now act, two imminent deadlines land within a fortnight, and the FTC opened a health-data enforcement case.

🔎 At a Glance

  • EU AI Act enforcement is live — the AI Office can now supervise and fine GPAI providers (2 Aug).

  • Netherlands NIS2 lands 15 Aug — 8,000+ entities gain registration and incident-reporting duties.

  • China Order No. 24 hits 20 Aug — annual data-security risk assessments become mandatory.

  • EU CRA reporting starts 11 Sep — severe-incident and exploited-vuln reporting for digital products.

  • FTC sues Hims & Hers — health-data sharing and dark-pattern design case opens.

  • OCR fines OSF Healthcare $552,250 — ransomware settlement continues HIPAA risk-analysis push.

🚨 Critical Actions (next 14 days)

🇪🇺 EU AI Act enforcement powers go live; GPAI supervision begins

European Union · AI Governance · CRITICAL · Due 2026-08-02

The EU AI Act reached its general date of application on 2 August 2026, and the AI Office's supervision and fining powers over general-purpose AI (GPAI) model providers became exercisable the same day. The Commission opened complaints, whistleblower and downstream-provider channels. No formal enforcement action against a named provider has yet been published, but the powers are now live.

Action: Confirm whether any product you place on the EU market is a general-purpose AI model or triggers Article 50 transparency duties, and name an owner for AI Office correspondence. (source)

🇨🇳 China's data-security risk-assessment rules (Order No. 24) take effect 20 August

China · Data Security · CRITICAL · Due 2026-08-20

The Network Data Security Risk Assessment Measures (Order No. 24), jointly issued by the Cyberspace Administration of China and other departments, take effect on 20 August 2026. They require network data handlers meeting defined thresholds to conduct and document annual data-security risk assessments.

Action: Determine whether your China data processing crosses the Measures' thresholds and schedule the required annual data-security risk assessment before 20 August. (source)

🇳🇱 Netherlands NIS2 law (Cyberbeveiligingswet) enters into force 15 August

Netherlands · Cybersecurity · CRITICAL · Due 2026-08-15

The Dutch Cyberbeveiligingswet, transposing the NIS2 Directive, is confirmed to enter into force on 15 August 2026, bringing an estimated 8,000+ entities into scope with registration, risk-management and incident-reporting obligations.

Action: If you operate essential or important services in the Netherlands, prepare to register with the supervisory authority and confirm incident-reporting and governance duties before 15 August. (source)

🇺🇸 FTC and two states sue Hims & Hers over health-data sharing and dark patterns

United States · Privacy · CRITICAL

The Federal Trade Commission, joined by Utah and California, sued Hims & Hers, alleging it shared consumers' sensitive health data with advertising platforms and used deceptive 'dark pattern' design in its subscription sign-up and cancellation flows.

Action: Audit any sharing of health or sensitive data with advertising platforms and review subscription and cancellation flows for dark-pattern risk. (source)

🇪🇺 EU Cyber Resilience Act incident-reporting duty applies 11 September

European Union · Cybersecurity · CRITICAL · Due 2026-09-11

Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) — the obligation to report actively exploited vulnerabilities and severe incidents — applies from 11 September 2026. The Commission has published implementation guidance; ENISA's single reporting platform is not yet live.

Action: Map which of your products with digital elements are in scope and stand up a 24-hour/72-hour reporting process before 11 September; note ENISA's single reporting platform may not be live at go-live. (source)

💰 Enforcement Watch

  • FTC and two states sue Hims & Hers over health-data sharing and dark patterns — enforcement action. Source

  • HHS OCR settles OSF Healthcare ransomware investigation for $552,250 — $552,250. Source

🗓️ Deadline Watch (next 30–90 days)

  • 2026-08-02🇪🇺 EU AI Act enforcement powers go live; GPAI supervision begins (European Union)

  • 2026-08-10🇺🇸 FedRAMP 20x Class A pipeline live; Rev5 conversion paths open 10 August (United States)

  • 2026-08-15🇳🇱 Netherlands NIS2 law (Cyberbeveiligingswet) enters into force 15 August (Netherlands)

  • 2026-08-20🇨🇳 China's data-security risk-assessment rules (Order No. 24) take effect 20 August (China)

  • 2026-09-11🇪🇺 EU Cyber Resilience Act incident-reporting duty applies 11 September (European Union)

  • 2027-01-01🇺🇸 Illinois SB 315 confirmed enacted as Public Act 104-0538, effective 1 January 2027 (United States)

🌍 Around the World

  • 🇪🇺 European Union — The EU AI Act reached its general date of application on 2 August 2026, and the AI Office's supervision and fining powers over GPAI model providers became exercisable the same day.

  • 🇨🇳 China — The Network Data Security Risk Assessment Measures (Order No. 24) take effect 20 August 2026, mandating documented annual data-security risk assessments for in-scope handlers.

  • 🇳🇱 Netherlands — The Cyberbeveiligingswet (NIS2 transposition) enters into force 15 August 2026, bringing 8,000+ entities into scope.

  • 🇺🇸 United States — The FTC, with Utah and California, sued Hims & Hers over health-data sharing and dark-pattern design.

  • 🇮🇪 Ireland — Ireland enacted its AI Act implementing law (Act No. 31 of 2026) and stood up the AI Office of Ireland.

  • 🇬🇧 United Kingdom — The FCA published PS26/15 finalising its overhaul of UK MiFIR transaction reporting.

🔬 Deep Dive — EU AI Act Enforcement Goes Live

European Union · AI Governance

The EU AI Act reached its general date of application on 2 August 2026, and the AI Office's supervision and fining powers over general-purpose AI (GPAI) model providers became exercisable the same day. The Commission simultaneously opened its complaints tool, a whistleblower channel, and a downstream-provider channel, and published the first Transparency Code signatory list of roughly 190 organisations.

What changed is not the text of the obligations, most of which have existed on paper since 2024, but the fact that a supervisor can now act on them. Article 50 transparency duties for AI-generated content and the GPAI provider obligations are the near-term focus. As of the first days of enforcement no formal proceeding, decision or penalty against a named provider has been published, and practitioner commentary describes the AI Office's stated preference for opening with technical compliance dialogues rather than formal powers.

For compliance teams the practical gap is identification: many organisations still do not know whether a model they build on, fine-tune or distribute makes them a GPAI provider or a downstream provider with its own duties. The Commission's own AI Act Explorer has continued to serve the pre-Omnibus 2024 text, so teams relying on it for exact timing should instead read Regulation (EU) 2024/1689 together with the Digital Omnibus, Regulation (EU) 2026/1744, which entered into force on 27 July 2026.

Here is what organisations need to do first...

🔒 This analysis continues for CyberEyeQ Pro subscribers, with a GPAI/downstream-provider identification checklist and AI Office correspondence playbook. Contact Us →

What to Do This Week

  1. Confirm whether any product you place on the EU market is a general-purpose AI model or triggers Article 50 transparency duties, and name an owner for AI Office correspondence. — European Union · AI Governance

  2. Determine whether your China data processing crosses the Measures' thresholds and schedule the required annual data-security risk assessment before 20 August. — China · Data Security

  3. If you operate essential or important services in the Netherlands, prepare to register with the supervisory authority and confirm incident-reporting and governance duties before 15 August. — Netherlands · Cybersecurity

  4. Audit any sharing of health or sensitive data with advertising platforms and review subscription and cancellation flows for dark-pattern risk. — United States · Privacy 🔒 (Pro)

  5. Map which of your products with digital elements are in scope and stand up a 24-hour/72-hour reporting process before 11 September; note ENISA's single reporting platform may not be live at go-live. — European Union · Cybersecurity 🔒 (Pro)

CyberEyeQActionable Regulatory Intelligence · cybereyeq.com · [email protected]

This briefing is provided for informational purposes only and does not constitute legal advice.

Keep Reading