This website uses cookies

Read our Privacy policy and Terms of use for more information.

🎙️ Episode 33 is live

EU AI Act Enforcement Goes Live

~8 minutes · Alex & Sarah break down this week's regulatory intelligence

This week's briefing

Eleven regulatory developments across six jurisdictions. The EU AI Act's supervisor can now act on general-purpose AI providers, two deadlines land within a fortnight, and the FTC opened a health-data enforcement case.

Top stories

  • EU AI Act enforcement powers go live (2 Aug) — the AI Office's supervision and fining powers over general-purpose AI (GPAI) providers became exercisable; complaints, whistleblower and downstream-provider channels opened.

  • Netherlands NIS2 law enters into force (15 Aug) — the Cyberbeveiligingswet brings an estimated 8,000+ entities into scope with registration, risk-management and incident-reporting duties.

  • China Order No. 24 takes effect (20 Aug) — the Network Data Security Risk Assessment Measures require in-scope handlers to conduct and document annual data-security risk assessments.

  • EU Cyber Resilience Act reporting duty applies (11 Sep) — Article 14 of Regulation (EU) 2024/2847 requires reporting of actively exploited vulnerabilities and severe incidents; ENISA's single reporting platform is not yet live.

  • FTC sues Hims & Hers — the FTC, with Utah and California, alleges sensitive health-data sharing with ad platforms and deceptive subscription flows.

Compliance action items

  • By 15 Aug — Netherlands: prepare to register with the supervisory authority and confirm incident-reporting and governance duties.

  • By 20 Aug — China: determine whether your data processing crosses the Order No. 24 thresholds and schedule the annual data-security risk assessment.

  • By 11 Sep — EU CRA: map in-scope products and stand up a 24h/72h incident-reporting process.

  • Now — EU AI Act: confirm whether any product you place on the EU market is a GPAI model or triggers Article 50 transparency duties, and name an owner for AI Office correspondence.

  • Now — Audit any sharing of health or sensitive data with ad platforms and review subscription/cancellation flows for dark-pattern risk.

This briefing is provided for informational purposes only and does not constitute legal advice.

Keep Reading