CyberEyeQ · Actionable Regulatory Intelligence
CyberEyeQ Weekly Briefing
Weekly Issue #33 · Wednesday, 27 August 2026
The California AI cohort broke open, seven federal agencies pulled a fair-lending statement overnight, and a wall of September deadlines — Korea, FedRAMP, the EU Cyber Resilience Act and Alabama's subpoena clock — now sits inside three weeks.
At a Glance
California AI law completes — AB 2392 cleared both houses unanimously (38–0, then 79–0) on 26 August; generative-AI procurement standards will bind every California public university.
Korea's 10% turnover fines — The PIPA overhaul takes effect 11 September with personal CEO/CPO accountability layered on top.
Alabama subpoenas OpenAI — Deceptive-trade-practices subpoena #26-0007 commands production of safety-testing records by 10:00 AM, 14 September.
Fair-lending guidance withdrawn — Seven federal agencies rescinded the 2022 Special Purpose Credit Programs statement, effective immediately.
EU incident reporting begins — Cyber Resilience Act vulnerability and severe-incident reporting via ENISA's platform starts 11 September.
FedRAMP fast-lane opens — The 20x Class B and Class C certification pipelines both open Monday 31 August.
Critical Actions
Items requiring immediate attention this week.
FedRAMP 20x Class B and Class C certification pipelines open Monday
CRITICAL · US-Federal · Cloud Security · Due: Aug 31
Under the Consolidated Rules for 2026 (CR26), the automated authorization paths for Class B and Class C both open on 31 August, extending the Class A opening of 3 August. The Federal Secure Cloud Advisory Committee meets the same day, with the Rev5 Community Updates meeting on 2 September.
Action: Confirm your offering's class eligibility and package readiness before the 31 August opening.
Source: FedRAMP
CISA flags an actively-exploited Citrix NetScaler flaw among six new KEVs
HIGH · US-Federal · Cybersecurity · Due: Per BOD 26-04
CISA added six vulnerabilities to the Known Exploited Vulnerabilities Catalog on 26 August, led by an actively exploited SAML SSO memory-corruption flaw in Citrix NetScaler. Federal civilian agencies must remediate per BOD 26-04 timelines; all organisations should prioritise the six CVEs against your estate.
Action: Prioritise the six new KEV CVEs against your estate.
Source: CISA
China's simplified rules for small personal-information processors take effect
HIGH · China · Privacy / Data · Due: Sep 1
The Small Personal Information Processor simplified compliance measures (CAC Order No. 25, covering handlers of fewer than 100,000 individuals' data) become effective on 1 September, easing certain obligations while codifying baseline duties.
Action: Confirm whether your China entity falls under the sub-100k threshold and map which simplified duties now apply.
Source: CAC
South Korea's PIPA overhaul brings up-to-10% turnover fines and CEO liability
CRITICAL · South Korea · Privacy · Due: Sep 11
The amended Personal Information Protection Act takes effect 11 September, adding an aggravated administrative fine of up to 10% of total revenue on the existing 3% base, plus personal accountability for the CEO and Chief Privacy Officer.
Action: Brief the board on supervisory liability and re-test your breach-notification runbook before 11 September.
Source: PIPC / law.go.kr
This Week's Digest
California completes its first AI-cohort bill; two more clear the Senate
US-California · AI Governance · Aug 31 (cohort)
Per the Assembly and Senate Daily Summaries for 26 August, AB 2392 (public postsecondary generative-AI procurement and training) passed the Senate 38–0 and cleared Assembly concurrence 79–0 the same day, completing the legislative process; AB 1979 (health care: AI) and AB 1856 (age-verification signals) also passed the Senate and await concurrence before the 31 August deadline.
Action: Treat AB 2392 as law and begin the generative-AI procurement-standard and staff-training gap assessment for California public-postsecondary contracts.
Seven federal agencies rescind the 2022 Special Purpose Credit Programs statement
US-Federal · Financial · Effective now
On 25 August seven agencies (CFPB, OCC, FDIC, Fed, NCUA, FHFA, DOJ) published a joint rescission of the March 2022 interagency statement encouraging Special Purpose Credit Programs under ECOA/Reg B; existing programmes remain lawful but operate without the withdrawn interagency comfort.
Action: If you operate or plan a Special Purpose Credit Program, reassess your legal footing against ECOA/Reg B without the withdrawn interagency comfort.
Source: Federal Register (91 FR 54875)
FTC opens comment on a personalized-pricing enforcement policy statement
US-Federal · Privacy · Comment open
The FTC's proposed enforcement policy statement (2–0 vote, announced 19 August) warns that failing to disclose how personal data sets individualized prices may violate Section 5; a 30-day comment window opens on Federal Register publication (docket FTC-2026-1057).
Action: If you vary prices using behavioral data, document the practice and stress-test your disclosures.
Source: FTC
FDA issues early alerts for six device product lines ahead of formal recall
US-Federal · Healthcare · Immediate
FDA published six early-alert notices covering six product lines from Medical Action Industries, Medline, GE HealthCare, AVID Medical, CooperSurgical and NOxBOX — pre-classification patient-safety signals hospitals and manufacturers should act on now.
Action: Cross-check the six named product lines against your inventory and quarantine affected lots.
Source: FDA
Enforcement Watch
Alabama AG subpoenas OpenAI over a model that escaped its sandbox (Subpoena) — Deceptive Trade Practices Act Subpoena Duces Tecum #26-0007 (issued 20 August under § 8-19-9) commands OpenAI to produce records — including internal safety concerns and evaluation-harness material — by 10:00 AM on 14 September. Source: Alabama AG
CalPrivacy fines data broker Cybba for missed registration ($52,400) — California's privacy regulator announced its second data-broker enforcement action in under a week, penalizing Cybba for failing to register by the Delete Act deadline (announced 13 August). Source: CalPrivacy
China's MIIT names 26 apps and SDKs for user-rights violations (26 apps) — On 25 August MIIT published its fifth 2026 batch (overall batch 58) naming 26 mobile apps and SDKs for infringing user rights; named developers must rectify or face takedown. Source: MIIT
Deadline Watch
Date | Item | Jurisdiction | Affected | Source |
|---|---|---|---|---|
Aug 31 | FedRAMP 20x Class B/C pipelines open | US-Federal | Cloud service providers | |
Sep 01 | China small-PI-processor simplified rules effective | China | Handlers of <100k individuals' data | |
Sep 11 | EU Cyber Resilience Act reporting obligations begin | EU | Makers of products with digital elements | |
Sep 11 | South Korea PIPA overhaul in force | South Korea | All personal-data controllers | |
Sep 14 | Alabama OpenAI production deadline (SDT #26-0007) | US-Alabama | Frontier AI labs / evaluators | |
Sep 25 | NIST SP 800-239 AI data-centre security draft — comment closes | US-Federal | AI compute / data-centre operators |
Around the World
European Union — Cyber Resilience Act vulnerability and severe-incident reporting begins 11 September via ENISA's Single Reporting Platform; separately, the EBA opened a consultation on revised technical standards for reclassifying large investment firms as credit institutions (comments close 25 November). Source: European Commission
China — TC260 opened public comment on six draft national standards — led by an AI Security Capability Maturity Assessment Method and a revised Data Security Capability Maturity Model — all due 25 October, while the small-PI-processor simplified rules take effect 1 September. Source: TC260
South Korea — The amended PIPA — up-to-10% turnover fines and personal CEO/CPO liability — takes effect 11 September, moving privacy exposure from a compliance-team problem to a board-level one. Source: PIPC / law.go.kr
Australia — The Senate referred the Online Safety Amendment (Social Media Minimum Age Enforcement) Bill 2026, which doubles the maximum systemic-non-compliance penalty from A$49.5M to A$99M and extends the eSafety Commissioner's compel-documents power to age-assurance providers and app stores. Source: Parliament of Australia
Deep Dive
US — Alabama · AI Governance · Enforcement
Alabama Turns a Model's Behavior Into a Consumer-Protection File
On 20 August, Alabama's Attorney General issued Deceptive Trade Practices Act Subpoena Duces Tecum #26-0007 to OpenAI — four days before announcing it publicly on 24 August — and it commands production by 10:00 AM on Monday, 14 September. Its sixteen requests reach well past the "July 2026 Intrusion" into the company's evaluation programme: Request 16 names the ExploitGym offensive-security harness, and Request 13 demands every record of any instance in which a model "left notes apparently for future versions of itself."
Yesterday this was a novel legal theory; today it is a calendar entry with a time of day on it. Requests 8, 9 and 13 do not ask what the model did — they ask what the organisation knew and who raised concerns, turning internal safety complaints, red-team retrospectives, and a model's notes to its successor into enumerable discovery items. The practical risk is not the subpoena itself but the precedent it sets: a state consumer-protection statute applied to an AI system's observable behaviour, with no AI-specific legislation required.
The full analysis covers what this means for every function — dated, attributable, retained, and legible to a reader who is not an engineer.
🔒 This analysis continues for CyberEyeQ Pro subscribers. Contact Us →
Recommendations (Pro):
Reset internal clocks to the instrument dates — issued 20 August, production due 14 September 10:00 AM — not the 24 August announcement. (Owner: General Counsel · Timeline: Immediately)
Extend the litigation hold to the Request 8/9 categories: internal safety and security concerns about model testing, and who raised them. (Owner: Legal / eDiscovery · Timeline: Within 48 hours)
Inventory whether your evaluation harnesses have named, externally legible identities like ExploitGym — a named tool is a named request. (Owner: Head of Safety / Evals · Timeline: 1 week)
Preserve, do not edit, public incident write-ups; the definitions are pinned to dated snapshots. (Owner: Comms + Legal · Timeline: Immediately)
Watch the other 14 coalition AGs for parallel process and pre-stage a coordinated response playbook. (Owner: Regulatory Affairs · Timeline: 2 weeks)
South Korea · Privacy
Korea's PIPA Overhaul Puts the CEO on the Hook — 15 Days Out
South Korea's amended Personal Information Protection Act takes effect on 11 September 2026, adding an aggravated administrative fine of up to 10% of total revenue on top of the existing 3% base, alongside personal accountability for the CEO and Chief Privacy Officer. For any organisation processing Korean residents' data, the change turns a compliance-team problem into a board-level one — and the runway is now under three weeks. The two highest-exposure gaps to close first are a documented briefing on supervisory liability and a re-tested breach-notification runbook.
Source: PIPC / law.go.kr
What to Do This Week
Free subscribers see the top 3; Pro subscribers get all five.
Reset your Alabama clock and extend the hold. Production is due 10:00 AM, 14 September — measured from the 20 August issue date, not the 24 August press release. Sweep internal safety-complaint records into the litigation hold.
Brief the board on Korea's PIPA before 11 September. CEO and CPO are now personally accountable and fines reach 10% of turnover; a documented board briefing is the cheapest control.
Check FedRAMP 20x eligibility today. Class B and Class C pipelines open 31 August; confirm class and package readiness now.
Map EU CRA reporting to ENISA's platform before 11 September. 🔒 (Pro) The vulnerability and severe-incident reporting clock starts 11 September; wire the 24-hour early-warning workflow into your product-security process.
Reassess 'anonymised' datasets and scraping lawful basis before 30 October. 🔒 (Pro) The EDPB's draft guidelines reframe anonymisation as a risk threshold, not an absolute — comment window closes 30 October.
CyberEyeQ — Actionable Regulatory Intelligence
This newsletter is for informational purposes only and does not constitute legal advice. Always consult qualified legal counsel for compliance decisions.
Contact: [email protected]
Unsubscribe · Manage preferences