The 2 August Wall
Ten days out, a cluster of hard deadlines converges on the same week. The EU AI Act's Article 50 transparency duties and the Commission's power to fine general-purpose AI providers both switch on 2 August; California's Delete Act deletion-processing clock starts 1 August; FedRAMP Ready retires 28 July. Meanwhile France became the first EU state to definitively adopt a general under-15 social media ban, Washington froze more than a billion dollars in Medicaid matching funds, and Beijing set a five-year IPv6 mandate. Here is the week that matters — and what to do about it.
At a Glance
AI labels mandatory 2 August. EU AI Act Article 50 duties and GPAI enforcement (fines to €15M / 3% turnover) begin in 10 days.
France bans under-15 socials. Parliament definitively adopted the ban 21 July; new accounts blocked from 1 Sept, existing from 1 Jan 2027.
California DROP clock starts. Registered data brokers must process deletion requests every 45 days from 1 August.
$1.07B Medicaid frozen. HHS/CMS deferred federal matching funds to California and Minnesota pending high-risk-claims review.
FedRAMP Ready retires 28 July. No new Ready submissions; Rev5 holders must convert to full Certification.
China sets IPv6 mandate. A 2026–2030 plan ties app-store listing, GenAI filing and type-approval to IPv6 support.
Critical Actions — Next 14 Days
1. EU AI Act Article 50 — mark your AI-generated content before 2 August (10 days). Providers and deployers of chatbots, deepfake/synthetic-media, emotion-recognition and biometric-categorisation systems must meet Article 50 transparency and marking duties from 2 August 2026; the Commission's GPAI enforcement and penalty powers begin the same day (up to €15M or 3% of worldwide turnover). A narrow grace period defers only the Article 50(2) marking duty to 2 December 2026, and only for systems on the market before 2 August. Do this: map each feature to its Article 50(1)/(2)/(4) obligation and confirm marking, disclosure and GPAI documentation now.
2. California Delete Act (DROP) — confirm your 45-day deletion cadence by 1 August (9 days). Registered data brokers must process deletion requests via the CPPA portal at least every 45 days from 1 August 2026. The clock is calendar-driven. Do this: verify DROP integration and stand up the recurring 45-day workflow for every registered entity.
3. FedRAMP Ready designation retires 28 July (5 days). After 28 July no new Ready submissions are accepted; Rev5 Ready holders must reach full Certification by the later of their next annual assessment expiry or 17 November 2026. Do this: file conversion plans this week.
Enforcement Watch
HHS/CMS defer ~$1.07 billion in Medicaid payments (California, Minnesota). On 21 July, HHS and CMS deferred ~$867.5M to California and ~$199M to Minnesota after reviews flagged high-risk claims needing documentation before federal matching-fund release. These are deferrals, not permanent cuts — but HHS also signalled it will broaden CMS/OIG exclusion authority. Affected: state Medicaid agencies, providers in flagged service areas, health compliance teams.
Korea's PIPC fines three firms KRW 706M for elementary security failures. At its 8 July plenary the PIPC sanctioned LocknLock (KRW 503M), Ubase (KRW 168M) and Sunphoto (KRW 30M) after unpatched servers and exposed admin pages leaked ~1.5M people's data. The warning: identical failures after PIPA's 10%-of-turnover punitive-fine regime commences 11 September face a far higher ceiling. Affected: any controller processing Korean personal data.
Deadline Watch — Next 60 Days
Date | Days | Domain | Item |
|---|---|---|---|
27 Jul | 4 | Cloud | FSCAC July meeting (first since CR26) |
28 Jul | 5 | Cloud | FedRAMP Ready designation retires |
31 Jul | 8 | Cyber | Germany BSI NIS2 registration grace closes |
31 Jul | 8 | Privacy | Korea PIPC portability pre-consultation closes |
31 Jul | 8 | AI Gov | FTC AI-accuracy policy statement comments close |
1 Aug | 9 | Privacy | California DROP 45-day deletion duty binds |
2 Aug | 10 | AI Gov | EU AI Act Art. 50 + GPAI enforcement apply |
2 Aug | 10 | AI Gov | California SB 942 AI Transparency Act effective |
2 Aug | 10 | China | CAC Internet Information Services rewrite — comments close |
3 Aug | 11 | AI Gov | GSA GSAR LLM clause (552.239-7001) comments close |
10 Aug | 18 | Age Verif | France U15 ban — EU TRIS standstill expiry |
15 Aug | 23 | Cyber | Netherlands Cyberbeveiligingswet (NIS2) in force |
20 Aug | 28 | China | Network Data Security Risk Assessment Measures (Order 24) effective |
1 Sep | 40 | Age Verif | France U15 ban — new accounts effective |
11 Sep | 50 | Cyber | EU CRA Art. 14 vulnerability/incident reporting applies |
11 Sep | 50 | Privacy | Korea PIPA punitive-fine regime commences |
14 Oct | 83 | Financial | UK PRA CP10/26 ring-fencing consultation closes |
Around the World
🇫🇷 France — First EU state to definitively adopt a general under-15 social media ban (21 July); see Deep Dive below.
🇨🇳 China — The Central Cyberspace Commission published its IPv6 Implementation Plan 2026–2030 (21 July): 36 tasks tie app-store listing standards, generative-AI filing, cloud defaults and device type-approval to IPv6 support. Structural, not immediate — inventory IPv6 gaps now. CAC's Internet Information Services rewrite closes for comment 2 August.
🇩🇪🇳🇱 Germany / Netherlands — Germany's BSI NIS2 registration grace window closes 31 July; the Netherlands' Cyberbeveiligingswet enters into force 15 August. Confirm transposition status in each jurisdiction you operate in.
🇺🇸 United States — The FCC voted 22 July on a Third Report and Order closing the Covered List "component part loophole," extending equipment-authorization reach to logic-bearing components and online marketplaces. RF device makers should prepare component-level supply-chain attestation once the adopted text and effective dates publish.
Age Verification · France · CRITICAL
On the evening of 21 July 2026, the Assemblée nationale cast the final vote (279–81; the Sénat approved the joint commission text 243–2 the same day) on the proposition de loi protecting minors from social media risks. A new Article 6-9 in the loi pour la confiance dans l'économie numérique prohibits under-15s from accessing online social network services, with carve-outs for encyclopedias and educational repositories; Arcom supervises within the EU Digital Services Act framework. France becomes the first EU member state to adopt a general prohibition of this kind.
The calendar is concrete: the ban applies to new accounts from 1 September 2026 and to existing accounts from 1 January 2027 — a point-of-creation age gate this autumn followed by a full user-base verification campaign by year-end, touching identity, privacy and UX at once under Arcom's DSA-channel supervision.
But two constraints sit between adoption and enforceability. Promulgation is gated on a likely Conseil constitutionnel referral (privacy and free-expression grounds, ~one-month window). And France adopted the law inside an EU TRIS standstill running to 10 August 2026, despite the Commission's 6 July detailed opinion finding the measure incompatible with the DSA — the Commission's post-standstill response will determine whether an infringement track opens.
🔒 The full playbook — age-gate architecture that satisfies Arcom without over-collecting identity data, sequencing the 1 Sept and 1 Jan obligations, and hedging the TRIS/DSA conflict — continues for CyberEyeQ Pro subscribers. Talk to us: [email protected]
Deep Dive 2 — EU AI Act Article 50 & GPAI Enforcement
AI Governance · European Union · CRITICAL
From 2 August 2026, Article 50 requires that AI systems interacting with people, and AI-generated or manipulated content, be disclosed and marked: chatbots must reveal they are machines, deepfakes and synthetic media must be labelled, and emotion-recognition and biometric-categorisation systems must notify those exposed. The duties bind providers and deployers, and apply to in-scope systems already on the EU market — not just new launches.
On 20 July the Commission adopted its Guidelines on the Article 50 obligations, and the Transparency Code of Practice reached adequacy confirmation. The guidelines are non-binding, but the AI Office and national authorities are expected to apply them closely — so map implementations against the adopted text, not the May draft.
The same date arms enforcement: the Commission's powers over general-purpose AI model providers switch on, with fines up to €15 million or 3% of worldwide annual turnover. One narrow relief: the Article 50(2) marking duty is deferred to 2 December 2026, but only for systems on the market before 2 August. And a caveat on what is not yet in force — the Digital Omnibus amendment package (deferred high-risk timelines, the Article 5 CSAM/NCII prohibition, grandfathering) remained unpublished in the Official Journal this week. Until it is published and in force, only the unamended AI Act text applies; keep high-risk plans anchored to current-law dates.
🔒 The Pro edition maps each Article 50 sub-obligation to owner and artifact, and separates what is genuinely due 2 August from what the Digital Omnibus defers. Talk to us: [email protected]
What to Do This Week
Classify your AI features against Article 50 and confirm marking/disclosure before 2 August.
Confirm California DROP integration and the 45-day deletion cadence before 1 August.
File FedRAMP Ready → Certification conversion plans before the 28 July retirement.
Check NIS2 transposition status in Germany (grace closes 31 July) and every member state where you operate.
🔒 CyberEyeQ Pro subscribers get the full five-step action list, including the France age-gate sequencing plan and the Korea PIPA pre-consultation filing. Upgrade: [email protected]
CyberEyeQ — Actionable Regulatory Intelligence. Questions: [email protected]. This briefing is regulatory intelligence, not legal advice. Verify against the issuing authority before acting.