This website uses cookies

Read our Privacy policy and Terms of use for more information.

The 2 August Wall

Ten days out, a cluster of hard deadlines converges on the same week. The EU AI Act's Article 50 transparency duties and the Commission's power to fine general-purpose AI providers both switch on 2 August; California's Delete Act deletion-processing clock starts 1 August; FedRAMP Ready retires 28 July. Meanwhile France became the first EU state to definitively adopt a general under-15 social media ban, Washington froze more than a billion dollars in Medicaid matching funds, and Beijing set a five-year IPv6 mandate. Here is the week that matters — and what to do about it.

At a Glance

  • AI labels mandatory 2 August. EU AI Act Article 50 duties and GPAI enforcement (fines to €15M / 3% turnover) begin in 10 days.

  • France bans under-15 socials. Parliament definitively adopted the ban 21 July; new accounts blocked from 1 Sept, existing from 1 Jan 2027.

  • California DROP clock starts. Registered data brokers must process deletion requests every 45 days from 1 August.

  • $1.07B Medicaid frozen. HHS/CMS deferred federal matching funds to California and Minnesota pending high-risk-claims review.

  • FedRAMP Ready retires 28 July. No new Ready submissions; Rev5 holders must convert to full Certification.

  • China sets IPv6 mandate. A 2026–2030 plan ties app-store listing, GenAI filing and type-approval to IPv6 support.

Critical Actions — Next 14 Days

1. EU AI Act Article 50 — mark your AI-generated content before 2 August (10 days). Providers and deployers of chatbots, deepfake/synthetic-media, emotion-recognition and biometric-categorisation systems must meet Article 50 transparency and marking duties from 2 August 2026; the Commission's GPAI enforcement and penalty powers begin the same day (up to €15M or 3% of worldwide turnover). A narrow grace period defers only the Article 50(2) marking duty to 2 December 2026, and only for systems on the market before 2 August. Do this: map each feature to its Article 50(1)/(2)/(4) obligation and confirm marking, disclosure and GPAI documentation now.

2. California Delete Act (DROP) — confirm your 45-day deletion cadence by 1 August (9 days). Registered data brokers must process deletion requests via the CPPA portal at least every 45 days from 1 August 2026. The clock is calendar-driven. Do this: verify DROP integration and stand up the recurring 45-day workflow for every registered entity.

3. FedRAMP Ready designation retires 28 July (5 days). After 28 July no new Ready submissions are accepted; Rev5 Ready holders must reach full Certification by the later of their next annual assessment expiry or 17 November 2026. Do this: file conversion plans this week.

Enforcement Watch

HHS/CMS defer ~$1.07 billion in Medicaid payments (California, Minnesota). On 21 July, HHS and CMS deferred ~$867.5M to California and ~$199M to Minnesota after reviews flagged high-risk claims needing documentation before federal matching-fund release. These are deferrals, not permanent cuts — but HHS also signalled it will broaden CMS/OIG exclusion authority. Affected: state Medicaid agencies, providers in flagged service areas, health compliance teams.

Korea's PIPC fines three firms KRW 706M for elementary security failures. At its 8 July plenary the PIPC sanctioned LocknLock (KRW 503M), Ubase (KRW 168M) and Sunphoto (KRW 30M) after unpatched servers and exposed admin pages leaked ~1.5M people's data. The warning: identical failures after PIPA's 10%-of-turnover punitive-fine regime commences 11 September face a far higher ceiling. Affected: any controller processing Korean personal data.

Deadline Watch — Next 60 Days

Date

Days

Domain

Item

27 Jul

4

Cloud

FSCAC July meeting (first since CR26)

28 Jul

5

Cloud

FedRAMP Ready designation retires

31 Jul

8

Cyber

Germany BSI NIS2 registration grace closes

31 Jul

8

Privacy

Korea PIPC portability pre-consultation closes

31 Jul

8

AI Gov

FTC AI-accuracy policy statement comments close

1 Aug

9

Privacy

California DROP 45-day deletion duty binds

2 Aug

10

AI Gov

EU AI Act Art. 50 + GPAI enforcement apply

2 Aug

10

AI Gov

California SB 942 AI Transparency Act effective

2 Aug

10

China

CAC Internet Information Services rewrite — comments close

3 Aug

11

AI Gov

GSA GSAR LLM clause (552.239-7001) comments close

10 Aug

18

Age Verif

France U15 ban — EU TRIS standstill expiry

15 Aug

23

Cyber

Netherlands Cyberbeveiligingswet (NIS2) in force

20 Aug

28

China

Network Data Security Risk Assessment Measures (Order 24) effective

1 Sep

40

Age Verif

France U15 ban — new accounts effective

11 Sep

50

Cyber

EU CRA Art. 14 vulnerability/incident reporting applies

11 Sep

50

Privacy

Korea PIPA punitive-fine regime commences

14 Oct

83

Financial

UK PRA CP10/26 ring-fencing consultation closes

Around the World

🇫🇷 France — First EU state to definitively adopt a general under-15 social media ban (21 July); see Deep Dive below.

🇨🇳 China — The Central Cyberspace Commission published its IPv6 Implementation Plan 2026–2030 (21 July): 36 tasks tie app-store listing standards, generative-AI filing, cloud defaults and device type-approval to IPv6 support. Structural, not immediate — inventory IPv6 gaps now. CAC's Internet Information Services rewrite closes for comment 2 August.

🇩🇪🇳🇱 Germany / Netherlands — Germany's BSI NIS2 registration grace window closes 31 July; the Netherlands' Cyberbeveiligingswet enters into force 15 August. Confirm transposition status in each jurisdiction you operate in.

🇺🇸 United States — The FCC voted 22 July on a Third Report and Order closing the Covered List "component part loophole," extending equipment-authorization reach to logic-bearing components and online marketplaces. RF device makers should prepare component-level supply-chain attestation once the adopted text and effective dates publish.

Deep Dive 1 — France's Under-15 Social Media Ban

Age Verification · France · CRITICAL

On the evening of 21 July 2026, the Assemblée nationale cast the final vote (279–81; the Sénat approved the joint commission text 243–2 the same day) on the proposition de loi protecting minors from social media risks. A new Article 6-9 in the loi pour la confiance dans l'économie numérique prohibits under-15s from accessing online social network services, with carve-outs for encyclopedias and educational repositories; Arcom supervises within the EU Digital Services Act framework. France becomes the first EU member state to adopt a general prohibition of this kind.

The calendar is concrete: the ban applies to new accounts from 1 September 2026 and to existing accounts from 1 January 2027 — a point-of-creation age gate this autumn followed by a full user-base verification campaign by year-end, touching identity, privacy and UX at once under Arcom's DSA-channel supervision.

But two constraints sit between adoption and enforceability. Promulgation is gated on a likely Conseil constitutionnel referral (privacy and free-expression grounds, ~one-month window). And France adopted the law inside an EU TRIS standstill running to 10 August 2026, despite the Commission's 6 July detailed opinion finding the measure incompatible with the DSA — the Commission's post-standstill response will determine whether an infringement track opens.

🔒 The full playbook — age-gate architecture that satisfies Arcom without over-collecting identity data, sequencing the 1 Sept and 1 Jan obligations, and hedging the TRIS/DSA conflict — continues for CyberEyeQ Pro subscribers. Talk to us: [email protected]

Deep Dive 2 — EU AI Act Article 50 & GPAI Enforcement

AI Governance · European Union · CRITICAL

From 2 August 2026, Article 50 requires that AI systems interacting with people, and AI-generated or manipulated content, be disclosed and marked: chatbots must reveal they are machines, deepfakes and synthetic media must be labelled, and emotion-recognition and biometric-categorisation systems must notify those exposed. The duties bind providers and deployers, and apply to in-scope systems already on the EU market — not just new launches.

On 20 July the Commission adopted its Guidelines on the Article 50 obligations, and the Transparency Code of Practice reached adequacy confirmation. The guidelines are non-binding, but the AI Office and national authorities are expected to apply them closely — so map implementations against the adopted text, not the May draft.

The same date arms enforcement: the Commission's powers over general-purpose AI model providers switch on, with fines up to €15 million or 3% of worldwide annual turnover. One narrow relief: the Article 50(2) marking duty is deferred to 2 December 2026, but only for systems on the market before 2 August. And a caveat on what is not yet in force — the Digital Omnibus amendment package (deferred high-risk timelines, the Article 5 CSAM/NCII prohibition, grandfathering) remained unpublished in the Official Journal this week. Until it is published and in force, only the unamended AI Act text applies; keep high-risk plans anchored to current-law dates.

🔒 The Pro edition maps each Article 50 sub-obligation to owner and artifact, and separates what is genuinely due 2 August from what the Digital Omnibus defers. Talk to us: [email protected]

What to Do This Week

  1. Classify your AI features against Article 50 and confirm marking/disclosure before 2 August.

  2. Confirm California DROP integration and the 45-day deletion cadence before 1 August.

  3. File FedRAMP Ready → Certification conversion plans before the 28 July retirement.

  4. Check NIS2 transposition status in Germany (grace closes 31 July) and every member state where you operate.

🔒 CyberEyeQ Pro subscribers get the full five-step action list, including the France age-gate sequencing plan and the Korea PIPA pre-consultation filing. Upgrade: [email protected]

CyberEyeQ — Actionable Regulatory Intelligence. Questions: [email protected]. This briefing is regulatory intelligence, not legal advice. Verify against the issuing authority before acting.

Keep Reading