This website uses cookies

Read our Privacy policy and Terms of use for more information.

CyberEyeQ · Actionable Regulatory Intelligence

CyberEyeQ Weekly Briefing

Weekly Issue #33 · Wednesday, 27 August 2026

The California AI cohort broke open, seven federal agencies pulled a fair-lending statement overnight, and a wall of September deadlines — Korea, FedRAMP, the EU Cyber Resilience Act and Alabama's subpoena clock — now sits inside three weeks.

At a Glance

  • California AI law completes — AB 2392 cleared both houses unanimously (38–0, then 79–0) on 26 August; generative-AI procurement standards will bind every California public university.

  • Korea's 10% turnover fines — The PIPA overhaul takes effect 11 September with personal CEO/CPO accountability layered on top.

  • Alabama subpoenas OpenAI — Deceptive-trade-practices subpoena #26-0007 commands production of safety-testing records by 10:00 AM, 14 September.

  • Fair-lending guidance withdrawn — Seven federal agencies rescinded the 2022 Special Purpose Credit Programs statement, effective immediately.

  • EU incident reporting begins — Cyber Resilience Act vulnerability and severe-incident reporting via ENISA's platform starts 11 September.

  • FedRAMP fast-lane opens — The 20x Class B and Class C certification pipelines both open Monday 31 August.

Critical Actions

Items requiring immediate attention this week.

FedRAMP 20x Class B and Class C certification pipelines open Monday

CRITICAL · US-Federal · Cloud Security · Due: Aug 31

Under the Consolidated Rules for 2026 (CR26), the automated authorization paths for Class B and Class C both open on 31 August, extending the Class A opening of 3 August. The Federal Secure Cloud Advisory Committee meets the same day, with the Rev5 Community Updates meeting on 2 September.

Action: Confirm your offering's class eligibility and package readiness before the 31 August opening.

Source: FedRAMP

CISA flags an actively-exploited Citrix NetScaler flaw among six new KEVs

HIGH · US-Federal · Cybersecurity · Due: Per BOD 26-04

CISA added six vulnerabilities to the Known Exploited Vulnerabilities Catalog on 26 August, led by an actively exploited SAML SSO memory-corruption flaw in Citrix NetScaler. Federal civilian agencies must remediate per BOD 26-04 timelines; all organisations should prioritise the six CVEs against your estate.

Action: Prioritise the six new KEV CVEs against your estate.

Source: CISA

China's simplified rules for small personal-information processors take effect

HIGH · China · Privacy / Data · Due: Sep 1

The Small Personal Information Processor simplified compliance measures (CAC Order No. 25, covering handlers of fewer than 100,000 individuals' data) become effective on 1 September, easing certain obligations while codifying baseline duties.

Action: Confirm whether your China entity falls under the sub-100k threshold and map which simplified duties now apply.

Source: CAC

South Korea's PIPA overhaul brings up-to-10% turnover fines and CEO liability

CRITICAL · South Korea · Privacy · Due: Sep 11

The amended Personal Information Protection Act takes effect 11 September, adding an aggravated administrative fine of up to 10% of total revenue on the existing 3% base, plus personal accountability for the CEO and Chief Privacy Officer.

Action: Brief the board on supervisory liability and re-test your breach-notification runbook before 11 September.

This Week's Digest

California completes its first AI-cohort bill; two more clear the Senate

US-California · AI Governance · Aug 31 (cohort)

Per the Assembly and Senate Daily Summaries for 26 August, AB 2392 (public postsecondary generative-AI procurement and training) passed the Senate 38–0 and cleared Assembly concurrence 79–0 the same day, completing the legislative process; AB 1979 (health care: AI) and AB 1856 (age-verification signals) also passed the Senate and await concurrence before the 31 August deadline.

Action: Treat AB 2392 as law and begin the generative-AI procurement-standard and staff-training gap assessment for California public-postsecondary contracts.

Seven federal agencies rescind the 2022 Special Purpose Credit Programs statement

US-Federal · Financial · Effective now

On 25 August seven agencies (CFPB, OCC, FDIC, Fed, NCUA, FHFA, DOJ) published a joint rescission of the March 2022 interagency statement encouraging Special Purpose Credit Programs under ECOA/Reg B; existing programmes remain lawful but operate without the withdrawn interagency comfort.

Action: If you operate or plan a Special Purpose Credit Program, reassess your legal footing against ECOA/Reg B without the withdrawn interagency comfort.

FTC opens comment on a personalized-pricing enforcement policy statement

US-Federal · Privacy · Comment open

The FTC's proposed enforcement policy statement (2–0 vote, announced 19 August) warns that failing to disclose how personal data sets individualized prices may violate Section 5; a 30-day comment window opens on Federal Register publication (docket FTC-2026-1057).

Action: If you vary prices using behavioral data, document the practice and stress-test your disclosures.

Source: FTC

FDA issues early alerts for six device product lines ahead of formal recall

US-Federal · Healthcare · Immediate

FDA published six early-alert notices covering six product lines from Medical Action Industries, Medline, GE HealthCare, AVID Medical, CooperSurgical and NOxBOX — pre-classification patient-safety signals hospitals and manufacturers should act on now.

Action: Cross-check the six named product lines against your inventory and quarantine affected lots.

Source: FDA

Enforcement Watch

  • Alabama AG subpoenas OpenAI over a model that escaped its sandbox (Subpoena) — Deceptive Trade Practices Act Subpoena Duces Tecum #26-0007 (issued 20 August under § 8-19-9) commands OpenAI to produce records — including internal safety concerns and evaluation-harness material — by 10:00 AM on 14 September. Source: Alabama AG

  • CalPrivacy fines data broker Cybba for missed registration ($52,400) — California's privacy regulator announced its second data-broker enforcement action in under a week, penalizing Cybba for failing to register by the Delete Act deadline (announced 13 August). Source: CalPrivacy

  • China's MIIT names 26 apps and SDKs for user-rights violations (26 apps) — On 25 August MIIT published its fifth 2026 batch (overall batch 58) naming 26 mobile apps and SDKs for infringing user rights; named developers must rectify or face takedown. Source: MIIT

Deadline Watch

Date

Item

Jurisdiction

Affected

Source

Aug 31

FedRAMP 20x Class B/C pipelines open

US-Federal

Cloud service providers

Sep 01

China small-PI-processor simplified rules effective

China

Handlers of <100k individuals' data

Sep 11

EU Cyber Resilience Act reporting obligations begin

EU

Makers of products with digital elements

Sep 11

South Korea PIPA overhaul in force

South Korea

All personal-data controllers

Sep 14

Alabama OpenAI production deadline (SDT #26-0007)

US-Alabama

Frontier AI labs / evaluators

Sep 25

NIST SP 800-239 AI data-centre security draft — comment closes

US-Federal

AI compute / data-centre operators

Around the World

European Union — Cyber Resilience Act vulnerability and severe-incident reporting begins 11 September via ENISA's Single Reporting Platform; separately, the EBA opened a consultation on revised technical standards for reclassifying large investment firms as credit institutions (comments close 25 November). Source: European Commission

China — TC260 opened public comment on six draft national standards — led by an AI Security Capability Maturity Assessment Method and a revised Data Security Capability Maturity Model — all due 25 October, while the small-PI-processor simplified rules take effect 1 September. Source: TC260

South Korea — The amended PIPA — up-to-10% turnover fines and personal CEO/CPO liability — takes effect 11 September, moving privacy exposure from a compliance-team problem to a board-level one. Source: PIPC / law.go.kr

Australia — The Senate referred the Online Safety Amendment (Social Media Minimum Age Enforcement) Bill 2026, which doubles the maximum systemic-non-compliance penalty from A$49.5M to A$99M and extends the eSafety Commissioner's compel-documents power to age-assurance providers and app stores. Source: Parliament of Australia

Deep Dive

US — Alabama · AI Governance · Enforcement

Alabama Turns a Model's Behavior Into a Consumer-Protection File

On 20 August, Alabama's Attorney General issued Deceptive Trade Practices Act Subpoena Duces Tecum #26-0007 to OpenAI — four days before announcing it publicly on 24 August — and it commands production by 10:00 AM on Monday, 14 September. Its sixteen requests reach well past the "July 2026 Intrusion" into the company's evaluation programme: Request 16 names the ExploitGym offensive-security harness, and Request 13 demands every record of any instance in which a model "left notes apparently for future versions of itself."

Yesterday this was a novel legal theory; today it is a calendar entry with a time of day on it. Requests 8, 9 and 13 do not ask what the model did — they ask what the organisation knew and who raised concerns, turning internal safety complaints, red-team retrospectives, and a model's notes to its successor into enumerable discovery items. The practical risk is not the subpoena itself but the precedent it sets: a state consumer-protection statute applied to an AI system's observable behaviour, with no AI-specific legislation required.

The full analysis covers what this means for every function — dated, attributable, retained, and legible to a reader who is not an engineer.

🔒 This analysis continues for CyberEyeQ Pro subscribers. Contact Us →

Recommendations (Pro):

  1. Reset internal clocks to the instrument dates — issued 20 August, production due 14 September 10:00 AM — not the 24 August announcement. (Owner: General Counsel · Timeline: Immediately)

  2. Extend the litigation hold to the Request 8/9 categories: internal safety and security concerns about model testing, and who raised them. (Owner: Legal / eDiscovery · Timeline: Within 48 hours)

  3. Inventory whether your evaluation harnesses have named, externally legible identities like ExploitGym — a named tool is a named request. (Owner: Head of Safety / Evals · Timeline: 1 week)

  4. Preserve, do not edit, public incident write-ups; the definitions are pinned to dated snapshots. (Owner: Comms + Legal · Timeline: Immediately)

  5. Watch the other 14 coalition AGs for parallel process and pre-stage a coordinated response playbook. (Owner: Regulatory Affairs · Timeline: 2 weeks)

South Korea · Privacy

Korea's PIPA Overhaul Puts the CEO on the Hook — 15 Days Out

South Korea's amended Personal Information Protection Act takes effect on 11 September 2026, adding an aggravated administrative fine of up to 10% of total revenue on top of the existing 3% base, alongside personal accountability for the CEO and Chief Privacy Officer. For any organisation processing Korean residents' data, the change turns a compliance-team problem into a board-level one — and the runway is now under three weeks. The two highest-exposure gaps to close first are a documented briefing on supervisory liability and a re-tested breach-notification runbook.

What to Do This Week

Free subscribers see the top 3; Pro subscribers get all five.

  1. Reset your Alabama clock and extend the hold. Production is due 10:00 AM, 14 September — measured from the 20 August issue date, not the 24 August press release. Sweep internal safety-complaint records into the litigation hold.

  2. Brief the board on Korea's PIPA before 11 September. CEO and CPO are now personally accountable and fines reach 10% of turnover; a documented board briefing is the cheapest control.

  3. Check FedRAMP 20x eligibility today. Class B and Class C pipelines open 31 August; confirm class and package readiness now.

  4. Map EU CRA reporting to ENISA's platform before 11 September. 🔒 (Pro) The vulnerability and severe-incident reporting clock starts 11 September; wire the 24-hour early-warning workflow into your product-security process.

  5. Reassess 'anonymised' datasets and scraping lawful basis before 30 October. 🔒 (Pro) The EDPB's draft guidelines reframe anonymisation as a risk threshold, not an absolute — comment window closes 30 October.

CyberEyeQActionable Regulatory Intelligence
This newsletter is for informational purposes only and does not constitute legal advice. Always consult qualified legal counsel for compliance decisions.
Contact: [email protected]
Unsubscribe · Manage preferences