CyberEyeQ · Actionable Regulatory Intelligence
The Wall Hits This Weekend
Weekly Issue #30 · Thursday, 30 July 2026
Last issue we flagged an August wall ten days out. It is now three days away — and it is no longer a single wall but a cluster of hard gates across five jurisdictions. Tomorrow closes Germany's BSI NIS2 registration expectation, the UK Online Safety Act risk-assessment records window, and the FTC's AI-accuracy comment docket. Saturday the California Delete Act's DROP deletion-processing duty and Connecticut's profiling impact-assessment duty bind. Sunday the EU AI Act's Article 50 transparency layer and GPAI fining powers switch on. Monday the FedRAMP 20x Class A pipeline opens. Behind the deadlines, three brand-new laws landed: Ireland enacted its AI Act implementing statute, New Jersey criminalised algorithmic rent-setting, and CISA added an actively-exploited Cisco firewall flaw to the KEV catalog.
At a Glance
AI labels mandatory Sunday. EU AI Act Article 50 duties and GPAI fining powers (up to €15M / 3% turnover) apply from 2 August.
California DROP duty binds Saturday. Every registered data broker must process deletion requests on a 45-day cycle — $200/day per unhandled request.
Germany NIS2 registration due tomorrow. BSI expects in-scope entities registered by 31 July; §65 BSIG fines reach €500,000 plus management personal liability.
Ireland enacts its AI Act law. Act No. 31 of 2026, signed 21 July, creates the AI Office of Ireland nine days before the AI Act applies.
New Jersey bans algorithmic rent-setting. The FAIR Act makes rent-pricing "coordinating functions" a state antitrust violation, effective 1 July 2027.
FedRAMP 20x opens Monday. With Ready retired, the Class A Program Certification pipeline is the first authorization on-ramp under CR26.
Critical Actions (next 4 days)
1. Germany BSI NIS2 — register by 31 July (1 day).
The NIS2 Implementation Act (BSIG) had a statutory registration deadline of 6 March 2026; BSI now expects in-scope entities registered by 31 July, after which non-registration becomes an enforcement priority. Non-registration is an administrative offence punishable by up to €500,000 under §65 BSIG, with personal liability on management bodies.
Do this: complete BSI registration for every German in-scope entity, and document management-body approval of your NIS2 risk measures.
2. California Delete Act (DROP) — confirm your 45-day cadence by 1 August (2 days).
From 1 August every registered California data broker must process deletion requests through DROP: access at least every 45 days, match and delete relevant PI including inferences, cascade to service providers, and report status within the window. Non-compliance is $200 per day, per request, plus investigation costs.
Do this: verify your DROP account is approved and stand up the pull-match-delete-report workflow before Saturday.
3. EU AI Act Article 50 — mark and disclose AI content by 2 August (3 days).
Interactive systems must disclose the AI interaction, generative outputs must be machine-readably marked, deepfakes and public-interest AI text must be labelled, and emotion/biometric-categorisation systems must notify exposed persons. The same date arms Commission fines on GPAI providers up to €15M or 3% of turnover. A narrow grace defers only Art. 50(2) marking for pre-market systems to 2 December 2026.
Do this: map each AI feature to its Article 50(1)/(2)/(4) obligation and confirm marking, disclosure and GPAI documentation are live.
Enforcement Watch
A week of exposure switching on more than fines going out — three penalty clocks now start: Germany NIS2 (€500,000 + personal liability), California DROP ($200/day per request), EU AI Act GPAI (€15M or 3% of turnover). Two actual actions landed:
DOJ moves against an alleged HSR "gun-jumping" structure (Edwards Lifesciences / Genesis MedTech). On 23 July DOJ Antitrust filed a Proposed Final Judgment alleging Edwards' acquisition of JC Medical was structured to stay below the Hart-Scott-Rodino threshold (~$119.5M) and avoid premerger review; 60-day Tunney Act comment period closes ~21 September.
OCC orders BSA/AML remediation at United Texas Bank. A consent Cease-and-Desist Order (AA-ENF-2026-29) for BSA/AML program deficiencies, entered alongside the bank's conversion to a national charter — a reminder that AML obligations follow an institution through a change of charter or regulator.
Deadline Watch (next 60 days)
Date | Days | Domain | Item |
|---|---|---|---|
31 Jul | 1 | Cyber | Germany BSI NIS2 registration expectation closes |
31 Jul | 1 | Age Verif | UK OSA risk-assessment records submission (1 Apr notices) |
31 Jul | 1 | AI Gov | FTC AI-accuracy comments close (FTC-2026-0859) |
1 Aug | 2 | Privacy | California Delete Act DROP deletion duty binds |
1 Aug | 2 | Privacy | Connecticut CTDPA profiling impact-assessment duty |
1 Aug | 2 | Healthcare | FDA FY2027 VQIP importer user fee effective |
2 Aug | 3 | AI Gov | EU AI Act Art. 50 + GPAI fining powers apply |
2 Aug | 3 | AI Gov | California SB 942 AI Transparency Act effective |
2 Aug | 3 | China | CAC Internet Information Services rewrite — comments close |
3 Aug | 4 | Cloud | FedRAMP 20x Class A pipeline opens |
5 Aug | 6 | Privacy | EDPB GDPR breach-notification template consultation closes |
12 Aug | 13 | Financial | ESMA + EBA Taxonomy disclosure simplification close |
14 Aug | 15 | Cyber | US CMMC Reform Task Force RFI responses due |
20 Aug | 21 | China | Network Data Security Risk Assessment Measures effective |
24 Aug | 25 | Age Verif | France under-15 ban — Conseil constitutionnel decision |
11 Sep | 43 | Cyber | EU CRA Art. 14 reporting applies (ENISA SRP) |
11 Sep | 43 | Privacy | South Korea PIPA overhaul takes effect (~10% turnover fines) |
Around the World
🇮🇪 Ireland — The Regulation of Artificial Intelligence Act 2026 (Act No. 31 of 2026) was signed 21 July, establishing the AI Office of Ireland and amending the Central Bank, Communications Regulation, CCPC and FOI Acts to slot sectoral regulators into AI Act enforcement. Read the Act for the competent-authority split before assuming which regulator supervises you.
🇺🇸 New Jersey — The FAIR Act (signed 20 July) makes it a state antitrust violation to run competitively sensitive nonpublic data from two or more rental owners through an algorithm to set prices, terms or occupancy. Effective 1 July 2027; a close analogue to California's AB 325.
🇨🇳 China — CAC's rewrite of the Internet Information Services Measures (6 chapters, 94 articles) closes for comment 2 August, forcing AI providers to disclose model/training-data basics, label synthetic content, and offer recommendation opt-outs, and defining a "large platform" at ≥50M users / ≥10M MAU. TC260 also opened drafting on eight new national standards on 30 July.
🇪🇺 European Union — Parallel ESMA and EBA consultations to simplify EU Taxonomy disclosures both close 12 August. Comment — but avoid over-building processes a likely simplification would render redundant.
PRIVACY · CALIFORNIA · CRITICAL
Deep Dive 1 — California's Delete Act: The DROP Duty Goes Operational
For eighteen months the California Delete Act has been a registration-and-fees regime. On 1 August 2026 it becomes an operational one. From that date every registered California data broker must honour deletion requests submitted through DROP — the portal the CPPA has run for consumers since 1 January 2026. Over 300,000 Californians have enrolled and 600+ brokers are registered; the mechanism connecting them now switches on.
The duty is procedural and unforgiving. A broker must access DROP at least once every 45 days, download the deletion list, hash-match its own records, delete every matching piece of personal information — including inferences and derived profiles, not just raw identifiers — and report each request's status within the same window. Unverifiable requests must be treated as opt-outs from sale/sharing, and the deletion instruction must cascade to service providers and contractors. Miss any of it and the penalty is mechanical: $200 per day, per deletion request, plus the CPPA's cost of investigation. A single missed 45-day cycle can multiply into a five- or six-figure exposure before a regulator ever sends a letter.
🔒 The full playbook — architecting the 45-day pull-match-delete-report cycle, the inference-and-derived-profile scope trap, and a defensible service-provider cascade — continues for CyberEyeQ Pro subscribers. Talk to us →
Pro recommendations:
(Privacy/DPO) Confirm your DROP account is approved and credentialed before 1 August — a pending account is non-compliant once the duty binds.
(Engineering/Data) Build the 45-day cycle as a scheduled job across every data store, deleting inferences and derived profiles, with status write-back.
(Legal/Vendor) Map every service provider that received broker data and wire the deletion cascade into your DPAs with evidence of transmission.
(Compliance) Treat unverifiable requests as opt-outs by default and log the $200/day exposure per open request.
CLOUD SECURITY · UNITED STATES · CRITICAL
Deep Dive 2 — FedRAMP 20x Class A: The First On-Ramp Since Ready Retired
The authorization path most cloud providers knew is gone. FedRAMP Ready — the pre-assessment designation signalling readiness for an agency sponsor — was retired to Legacy on 28 July. In its place, on 3 August, the PMO opens the 20x Class A pipeline: the first on-ramp under the Consolidated Rules for 2026 (CR26), and a structurally different route.
Class A is the Program Certification path, and its defining feature is that it needs no agency sponsor — historically the chicken-and-egg barrier that kept smaller providers out. The PMO assesses the provider directly against 25 mandatory rules, with a current SOC 2 Type II as the evidentiary spine. That lowers the barrier but front-loads the burden: with no sponsor to shape scope, the SOC 2 boundary and the mapping to the 25 rules must be right before submission. Providers not Class A-ready aren't shut out — Class B and C, leaning on existing commercial certifications, open 31 August — and two CR26 touchpoints follow: the Rev5 Community Update (5 August) and the Agency Liaison Meeting (11 August).
🔒 The Pro edition maps the 25 mandatory rules to the SOC 2 Type II control set, flags where Class A scoping goes wrong without a sponsor, and helps you choose between the A/B/C pipelines. Talk to us →
Pro recommendations:
(Compliance/Security) Confirm your SOC 2 Type II is current and its boundary matches the service you intend to authorize before 3 August.
(GRC) Map your control set to the 25 mandatory rules and close gaps before assessment — no sponsor will negotiate scope.
(Strategy) If not Class A-ready, assess Class B/C eligibility against existing certifications ahead of 31 August.
(Regulatory) Monitor the 5 Aug Rev5 Community Update and 11 Aug Agency Liaison Meeting for transition detail.
What to Do This Week
Register for BSI NIS2 (Germany in-scope entities) — before 31 July. (Free)
Stand up the DROP 45-day deletion cycle (registered California data brokers) — before 1 August. (Free)
Ship Article 50 disclosures and marking (chatbot/GenAI/deepfake/biometric systems) — before 2 August. (Free)
🔒 Two more priority actions for Pro subscribers — the Connecticut profiling impact-assessment build and the FedRAMP 20x pipeline decision, with owners and timelines. Talk to us →
CyberEyeQ — Actionable Regulatory Intelligence
Questions or corrections: [email protected]
Compiled from primary regulatory sources; for information only, not legal advice. Verify every item against the issuing authority before acting.
Unsubscribe · Manage preferences