This website uses cookies

Read our Privacy policy and Terms of use for more information.

Wednesday, August 5, 2026

Today's Focus: AI Governance

Today's Top Story

The EU AI Act Enforcement Era Is Here — Fines and Transparency Rules Now Live

Three days in, the EU AI Act's enforcement infrastructure is operational. As of August 2, the European Commission's AI Office can investigate general-purpose AI model providers, request technical documentation, conduct model evaluations, and impose fines of up to €15 million or 3% of worldwide annual turnover — whichever is higher.

Article 50 transparency obligations are also now enforceable. Chatbots must disclose their AI nature at the start of interactions. Deepfakes and other synthetic content must carry machine-readable labels. Emotion-recognition and biometric-categorization systems must notify affected individuals. These are not high-risk-system requirements — they apply to any covered system regardless of risk classification.

Meanwhile, the Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on July 27, reshaping the compliance calendar. Standalone Annex III high-risk obligations now defer to December 2, 2027; product-embedded high-risk AI to August 2, 2028. A new prohibition on AI systems generating CSAM or non-consensual intimate imagery kicks in December 2, 2026. For GPAI providers who placed models on the market before August 2, 2025: you have until August 2, 2027 to reach compliance — but the enforcement mechanism is live now.

What to do: Confirm Article 50 marking and disclosure is deployed for all chatbots, synthetic-content generators, and emotion-recognition systems serving EU users. Close any remaining GPAI documentation gaps immediately — the AI Office is not waiting.

Also Today

Illinois Enacts First US Mandatory Frontier AI Audit Law

Governor Pritzker signed the AI Safety Measures Act (SB 315) on July 6, creating the first US requirement for annual independent third-party audits of frontier AI developers. The law also mandates critical-safety-incident reporting and whistleblower protections, with penalties up to $3 million per violation. Coverage is scoped to large frontier developers by revenue and training compute. Core obligations take effect January 1, 2027, with some audit requirements beginning January 1, 2028.

Review now: Assess whether your organization meets the "large frontier developer" thresholds and begin third-party auditor selection. Sources: Governor Pritzker press release · Norton Rose Fulbright

China Issues First Fines Under Anthropomorphic AI Rules

China's Interim Measures for Anthropomorphic AI Interaction Services, which took effect July 15, are seeing early enforcement activity. Reports indicate the CAC has issued initial fines under the framework, which imposes penalties of RMB 10,000–100,000 per violation (with additional RMB 100,000–200,000 where conduct causes actual harm to citizens). The rules prohibit emotional manipulation, addiction inducement, and virtual-intimate-relationship services to minors, and require algorithm filing, security assessments, and AI-disclosure labeling.

Act now: If your AI products serve Chinese users with conversational or companion features, confirm minor-mode, consent, and disclosure compliance. Sources: Bird & Bird · IAPP

EDPB Sets GDPR Ground Rules for GenAI Training Data

The EDPB adopted Guidelines 03/2026 on web scraping for generative AI training on July 7 — the first comprehensive GDPR framework addressing large-scale data extraction for model training. Key takeaway: consent at scale is generally not viable; legitimate interest is the primary avenue but requires a rigorous three-part balancing test. The guidelines treat robots.txt, ai.txt, and login walls as relevant indicators of data subjects' reasonable expectations. Consultation closes end of October 2026.

File feedback: Review the guidelines against your training-data pipelines and submit comments. Source: EDPB

Deadline Alert

Date

What

Action

Now

EU AI Act GPAI enforcement + Art 50 transparency

Close documentation and disclosure gaps

Aug 28

Missouri SB 1019 AI-therapy advertising ban

Review AI mental-health marketing claims

Oct 2026

EDPB GenAI web-scraping guidelines consultation

Submit comments

Dec 2, 2026

EU Omnibus CSAM/NCII prohibition

Scope technical safeguards

Jan 1, 2027

Illinois SB 315 core obligations

Begin auditor selection

One Thing to Do Today

Audit your Article 50 disclosures. Every chatbot, deepfake generator, and emotion-recognition system serving EU users must now disclose AI involvement — and the Commission has the power to fine you for non-compliance. If you haven't deployed these disclosures, today is the day.

Tomorrow's Focus: Thursday is weekly newsletter day — look for the CyberEyeQ Weekly Roundup covering all domains.

CyberEyeQ — Actionable Regulatory Intelligence

Keep Reading