Speak naturally. Send without fixing.
Wispr Flow turns your voice into clean, professional text you can send the moment you stop talking. Not rough transcription you have to clean up. Actual polished text — ready for email, Slack, or any app.
Speak the way you think. Go on tangents. Change your mind mid-sentence. Flow strips the filler, fixes the grammar, and gives you text that reads like you spent five minutes writing it.
89% of messages sent with zero edits. Millions of professionals use Flow daily, including teams at OpenAI, Vercel, and Clay. Works on Mac, Windows, and iPhone.
Issue #31 · August 13, 2026
This week: 12 regulatory developments across 7 jurisdictions. A $942M child-safety ruling rewrites platform liability, the Dutch NIS2 enters force Friday, California's AI slate faces a mass survival vote today, and China tightens both ends of the data-processor spectrum. Estimated read: 9 minutes.
🔎 At a Glance
Meta hit with $942M and 5-year child-safety injunction — New Mexico court rejects Section 230 defense; platforms face new design-default standards.
Netherlands NIS2 enters force Friday (15 Aug) — no transition period for 8,000+ entities.
California suspense day today (13 Aug) — 482 measures on file including ~14 AI bills; survival or death for the 2026 AI slate.
CMMC Reform Task Force RFI closes tomorrow (14 Aug) — defense contractors' window to shape post-Phase 2 cybersecurity requirements.
China Order No. 24 effective 20 Aug — annual data-security risk assessments for important-data processors become mandatory in one week.
FinCEN's record $125M UBS penalty — largest-ever BSA fine on a broker-dealer; recidivist AML failures front and center.
🚨 Critical Actions (next 14 days)
🇺🇸 Meta ordered to pay $942M with 5-year child-safety reforms
United States · Privacy / Age Verification · CRITICAL
On 6–7 August 2026, a New Mexico court entered final judgment in State of New Mexico v. Meta Platforms, ordering $942M total ($375M jury penalty + $567M court-ordered abatement fund), rejecting Meta's Section 230 defense, and imposing a five-year injunction requiring default privacy protections for minors, rigorous age verification, an overnight push-notification blackout for under-18s, anti-sextortion safeguards, mandatory time-use limits (90 hours/month), and semiannual compliance reports.
Action: Platforms serving minors: benchmark your teen-account default privacy settings, age-assurance methods, and notification policies against the NM order's standard. Track Meta's appeal and NM AG Torrez's announced age-verification bill.
🇳🇱 Netherlands NIS2 (Cyberbeveiligingswet) enters into force 15 August
Netherlands · Cybersecurity · CRITICAL · Due 2026-08-15
The Dutch Cyberbeveiligingswet, transposing the NIS2 Directive, enters into force on 15 August 2026 with no transition period. From day one: duty of care, 24-hour early-warning / 72-hour full-notification incident reporting, board-level governance duties, and NCSC-NL registration all apply. Fines reach €10M / 2% of turnover for essential entities; €7M / 1.4% for important entities.
Action: Confirm Dutch in-scope status and register with NCSC-NL via mijn.ncsc.nl (EH3+) by 15 August. Stand up 24h/72h incident-reporting workflow before Friday.
🇺🇸 CMMC Reform Task Force RFI closes 14 August (12:00 pm ET)
United States · Cybersecurity / Cloud Security · CRITICAL · Due 2026-08-14
Following the 13 July suspension of CMMC Phase 2, the Reform Task Force RFI closes tomorrow at 12:00 pm ET. It seeks defense-industrial-base input on cost drivers, which NIST SP 800-171 controls reduce risk versus create burden, and how commercial cybersecurity tools and managed services might substitute for separate assessments. The Task Force reports around mid-September.
Action: Cloud/MSP providers and defense contractors: submit RFI input by 14 August. Maintain NIST SP 800-171 self-assessment, SPRS score, and annual affirmation — only the 3PAO certification mandate is paused.
🇨🇳 China Network Data Security Risk Assessment (Order No. 24) effective 20 August
China · Cybersecurity / Data Security · CRITICAL · Due 2026-08-20
The CAC/MIIT/MPS Network Data Security Risk Assessment Measures take legal effect 20 August 2026. Important-data processors must conduct an annual risk assessment (Art. 5), file the report within 20 working days (Art. 16), retain for ≥3 years (Art. 15); third-party bodies may not serve the same processor for more than 3 consecutive years; authorities may order stop-processing on refusal to remediate.
Action: Confirm whether your holdings include "important data" against published catalogues. Stand up annual risk-assessment + 20-working-day filing process with ≥3-year retention before 20 August.
🇪🇺 EU Cyber Resilience Act Art. 14 reporting applies 11 September
European Union · Cybersecurity · CRITICAL · Due 2026-09-11
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents — 24-hour early warning, 72-hour full notification, 14-day final report — via ENISA's Single Reporting Platform (SRP), which is still under development. The Commission published implementation guidance on 27 July.
Action: Map in-scope products and identify your main-establishment CSIRT. Build the 24h/72h reporting channel before 11 September; plan for SRP unavailability at go-live.
💰 Enforcement Watch
New Mexico court orders Meta $942M with 5-year child-safety injunction — $942M ($375M penalty + $567M abatement). Section 230 defense rejected; five-year injunction mandates default teen privacy, age verification, and notification blackout. First US ruling treating a social-media platform as a public nuisance. Meta will appeal. Source
FinCEN assesses record $125M BSA penalty against UBS Financial Services — $125M. Largest-ever BSA penalty on a broker-dealer. UBSFS admitted willful AML violations: failure to monitor more than $10B in foreign-currency wires and timely file hundreds of SARs, including on Russia- and LatAm-linked customers. Recidivist case (second action after 2018 consent order for same failures). Source
NYDFS fines Order Express $250K under Part 500 — $250K. Money transmitter penalized for inadequate patch policies and risk assessments under 23 NYCRR Part 500. Confirms NYDFS will enforce even against limited-exemption entities. Source
🗓️ Deadline Watch (next 30–90 days)
Date | Jurisdiction | Item |
|---|---|---|
2026-08-13 (today) | 🇺🇸 California | Senate Appropriations suspense day — 482 measures incl. ~14 AI bills |
2026-08-14 | 🇺🇸 US | CMMC Reform Task Force RFI closes (12:00 pm ET) |
2026-08-14 | 🇺🇸 US | CISA BOD 26-04 Cisco ASA/FTD (CVE-2026-20349) FCEB remediation due |
2026-08-15 | 🇳🇱 Netherlands | NIS2 (Cyberbeveiligingswet) enters into force — no transition |
2026-08-20 | 🇨🇳 China | Network Data Security Risk Assessment Measures (Order No. 24) effective |
2026-08-20 | 🇬🇧 UK | PSR CP26/2 Confirmation of Payee (SD17 extension) comment closes |
2026-08-21 | 🇺🇸 US | Stablecoin CIP NPRM (GENIUS Act) comment closes |
~2026-08-24 | 🇫🇷 France | Conseil constitutionnel ruling on under-15 social-media ban |
2026-08-28 | 🇨🇳 China | Draft Anti-Cyber Violence Law comment closes |
2026-08-31 | 🇺🇸 US | FedRAMP 20x Class B/C pipelines open |
2026-09-01 | 🇫🇷 France / 🇨🇳 China | France Phase 1 under-15 ban (conditional on CC); China Small PI Processor Measures effective |
2026-09-07 | 🇨🇳 China | Large PI Processor draft comment closes |
2026-09-11 | 🇪🇺 EU / 🇰🇷 Korea | EU CRA Art. 14 reporting applies; South Korea PIPA overhaul in force |
🌍 Around the World
🇺🇸 United States — California — Today's Appropriations suspense hearing disposes of 482 measures in bulk, including roughly 14 AI-related bills covering companion chatbots (SB 300/1119/867), agentic AI (SB 1106), employment automated-decision systems (SB 947), a state AI Safety Commission (SB 813), and a deepfake bill (AB 686) missed by AI-keyword filters.
🇪🇺 EU — EDPB — The EDPB formally asked the Commission to re-examine the EU–US Data Privacy Framework adequacy decision following the US Supreme Court's Trump v. Slaughter ruling on FTC commissioner removal protections. DPF remains valid unless formally amended or withdrawn; organisations should maintain SCC fallbacks.
🇨🇳 China — CAC opened public consultation (closes 7 Sep) on draft Large Personal Information Processor rules — a 50-article framework that triggers at processing PI of ≥10M people, requiring in-China data localization with PRC-national controllers, a PI Protection Supervision Committee, biennial audit, and annual social-responsibility report. TC260 issued four AI-security national-standard drafting solicitations in a single week.
🇰🇷 South Korea — The PIPA overhaul takes effect 11 September with fines up to 10% of total turnover for serious cases and personal CEO liability for systemic compliance failures.
🇫🇷 France — The Conseil constitutionnel's ruling on the under-15 social-media ban is expected ~24 August. This is the true promulgation gate for the 1 September Phase 1 effective date.
🔬 Deep Dive — The August Deadline Wall: Four Jurisdictions, One Fortnight
Cross-Domain · Cybersecurity / Data Security / Privacy
This week's newsletter could have featured any single development as its lead, but the real story is the convergence: between 13 and 20 August, four major jurisdictions simultaneously impose or close substantive compliance obligations. This kind of multi-jurisdictional pile-up is where organisations make mistakes — not because any single requirement is unmanageable, but because teams allocate attention sequentially while deadlines arrive in parallel.
The cluster:
The Netherlands enters NIS2 on 15 August with no transition — an estimated 8,000 organisations gain immediate registration, incident-reporting and board-governance duties. China's Order No. 24 follows five days later, imposing annual data-security risk assessments with 20-working-day filing requirements and stop-processing sanctions. The US CMMC Reform Task Force RFI closes 14 August, and while it's a comment window rather than a compliance date, what the defense-industrial base files this week will shape whether the 80,000-contractor CMMC regime is reformed or merely postponed. And today, California's suspense hearing will silently kill or advance the largest state-level AI regulatory package in the country.
What this means operationally:
The temptation is to triage sequentially — handle the Netherlands first because it's Friday, then China the following week, then CRA in September. But the compliance tasks overlap: NIS2's 24-hour early warning and CRA's 24-hour vulnerability reporting are structurally identical obligations from different EU regulations. China's risk-assessment filing cadence mirrors DORA's Register of Information requirement. Organisations that build these as separate workstreams will duplicate effort; those that recognise the pattern — mandatory risk assessment, mandatory incident reporting, mandatory board accountability — can build once and deploy across.
The Meta $942M judgment adds a different dimension. It is the first US ruling treating a social-media platform as a public nuisance and the first to reject Section 230 as a defense against state consumer-protection claims involving minors. Combined with KOSA clearing the Senate Commerce Committee and France's under-15 ban awaiting constitutional approval, the trajectory is clear: age verification, default privacy for minors, and design-accountability are no longer theoretical — they are becoming enforceable obligations across the US, EU, and APAC simultaneously.
🔒 This analysis continues for CyberEyeQ Pro subscribers, with a multi-jurisdictional compliance-overlap matrix mapping NIS2, CRA, DORA, and China Order No. 24 obligations into a single workstream, plus a 30-day action calendar. Contact Us →
📊 Regulatory Frontline — Enforcement Budgets Are the New Policy Signal
The enforcement tape this week — $942M (Meta, NM), $125M (UBS, FinCEN), $250K (Order Express, NYDFS) — spans three regulators, three sectors, and penalty amounts ranging across four orders of magnitude. But the consistent signal is in what drove each: recidivism. UBS was penalized for the same AML failures it consented to fix in 2018. Order Express was fined despite holding a limited exemption. Meta's penalty was amplified by findings that the platform knew about harms and chose not to act.
For compliance teams, the operational takeaway is that regulators are now treating unremediated findings as an enforcement multiplier. Documenting a gap is no longer sufficient; documenting its closure — and being able to prove it when the same regulator returns — is the difference between a routine examination and a headline penalty.
✅ What to Do This Week
Register with NCSC-NL if you operate essential or important services in the Netherlands; stand up 24h/72h incident-reporting workflow before 15 August. — Netherlands · Cybersecurity
File CMMC Reform Task Force RFI input by 12:00 pm ET 14 August if you are a cloud/MSP provider or defense contractor. — United States · Cybersecurity
Confirm "important data" classification and stand up annual risk-assessment + filing process before China's Order No. 24 takes effect 20 August. — China · Data Security
Benchmark teen-account defaults — privacy settings, age-assurance, notification policies — against the NM Meta order's standard. — United States · Privacy 🔒 (Pro)
Map CRA-in-scope products and build 24h/72h CSIRT/ENISA reporting channel before 11 September. — European Union · Cybersecurity 🔒 (Pro)
CyberEyeQ — Actionable Regulatory Intelligence · cybereyeq.com · [email protected]
This briefing is provided for informational purposes only and does not constitute legal advice.

