Wednesday, August 5, 2026
Today's Focus: AI Governance
Today's Top Story
The EU AI Act Enforcement Era Is Here — Fines and Transparency Rules Now Live
Three days in, the EU AI Act's enforcement infrastructure is operational. As of August 2, the European Commission's AI Office can investigate general-purpose AI model providers, request technical documentation, conduct model evaluations, and impose fines of up to €15 million or 3% of worldwide annual turnover — whichever is higher.
Article 50 transparency obligations are also now enforceable. Chatbots must disclose their AI nature at the start of interactions. Deepfakes and other synthetic content must carry machine-readable labels. Emotion-recognition and biometric-categorization systems must notify affected individuals. These are not high-risk-system requirements — they apply to any covered system regardless of risk classification.
Meanwhile, the Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on July 27, reshaping the compliance calendar. Standalone Annex III high-risk obligations now defer to December 2, 2027; product-embedded high-risk AI to August 2, 2028. A new prohibition on AI systems generating CSAM or non-consensual intimate imagery kicks in December 2, 2026. For GPAI providers who placed models on the market before August 2, 2025: you have until August 2, 2027 to reach compliance — but the enforcement mechanism is live now.
What to do: Confirm Article 50 marking and disclosure is deployed for all chatbots, synthetic-content generators, and emotion-recognition systems serving EU users. Close any remaining GPAI documentation gaps immediately — the AI Office is not waiting.
Also Today
Illinois Enacts First US Mandatory Frontier AI Audit Law
Governor Pritzker signed the AI Safety Measures Act (SB 315) on July 6, creating the first US requirement for annual independent third-party audits of frontier AI developers. The law also mandates critical-safety-incident reporting and whistleblower protections, with penalties up to $3 million per violation. Coverage is scoped to large frontier developers by revenue and training compute. Core obligations take effect January 1, 2027, with some audit requirements beginning January 1, 2028.
Review now: Assess whether your organization meets the "large frontier developer" thresholds and begin third-party auditor selection. Sources: Governor Pritzker press release · Norton Rose Fulbright
China Issues First Fines Under Anthropomorphic AI Rules
China's Interim Measures for Anthropomorphic AI Interaction Services, which took effect July 15, are seeing early enforcement activity. Reports indicate the CAC has issued initial fines under the framework, which imposes penalties of RMB 10,000–100,000 per violation (with additional RMB 100,000–200,000 where conduct causes actual harm to citizens). The rules prohibit emotional manipulation, addiction inducement, and virtual-intimate-relationship services to minors, and require algorithm filing, security assessments, and AI-disclosure labeling.
Act now: If your AI products serve Chinese users with conversational or companion features, confirm minor-mode, consent, and disclosure compliance. Sources: Bird & Bird · IAPP
EDPB Sets GDPR Ground Rules for GenAI Training Data
The EDPB adopted Guidelines 03/2026 on web scraping for generative AI training on July 7 — the first comprehensive GDPR framework addressing large-scale data extraction for model training. Key takeaway: consent at scale is generally not viable; legitimate interest is the primary avenue but requires a rigorous three-part balancing test. The guidelines treat robots.txt, ai.txt, and login walls as relevant indicators of data subjects' reasonable expectations. Consultation closes end of October 2026.
File feedback: Review the guidelines against your training-data pipelines and submit comments. Source: EDPB
Deadline Alert
Date | What | Action |
|---|---|---|
Now | EU AI Act GPAI enforcement + Art 50 transparency | Close documentation and disclosure gaps |
Aug 28 | Missouri SB 1019 AI-therapy advertising ban | Review AI mental-health marketing claims |
Oct 2026 | EDPB GenAI web-scraping guidelines consultation | Submit comments |
Dec 2, 2026 | EU Omnibus CSAM/NCII prohibition | Scope technical safeguards |
Jan 1, 2027 | Illinois SB 315 core obligations | Begin auditor selection |
One Thing to Do Today
Audit your Article 50 disclosures. Every chatbot, deepfake generator, and emotion-recognition system serving EU users must now disclose AI involvement — and the Commission has the power to fine you for non-compliance. If you haven't deployed these disclosures, today is the day.
Tomorrow's Focus: Thursday is weekly newsletter day — look for the CyberEyeQ Weekly Roundup covering all domains.
CyberEyeQ — Actionable Regulatory Intelligence
Questions? [email protected]