This website uses cookies

Read our Privacy policy and Terms of use for more information.

🎙️ Episode 25 is live

Canada's under-16 social ban; CISA's 72-hour patch clock · ~12 min listen

Top 5 stories this week

  1. Canada tables Bill C-34, the Safe Social Media Act — 16-year minimum age for social media, mandatory age verification for upload-enabled porn sites, statutory AI-chatbot safety duties, and a new Digital Safety Commission. Second-reading debate begins within weeks. Sources: Canada.ca news release · Parliament of Canada — C-34 first reading

  2. CISA Binding Operational Directive 26-04 starts a 72-hour patch clock — risk-scored remediation for federal agencies (four criteria: exposure, KEV listing, exploit automation, post-exploitation impact). FedRAMP-hosted systems are in scope. Agencies have 60 days to update processes, 180 days to meet the timelines. Sources: CISA — BOD 26-04 · CISA press release

  3. EU publishes final Code of Practice for labelling AI-generated content — the practical bridge to AI Act Article 50 transparency duties (apply August 2, 2026). Voluntary, but signing brings a presumption-of-conformity pathway. Pre-August-2026 systems' marking grace period cut from six months to three (lands December 2, 2026). Sources: Commission publication · Commission press release

  4. The five-week deadline corridor — a dozen-plus hard compliance dates land between June 13 and July 18, including the July 1 quadruple wall: MiCA CASP hard stop, four US state age-verification laws (NE/CT/CO/LA), China outbound-investment regs, and TC260 personal-information standards.

  5. Enforcement watch — FTC finalises the Illuminate Education order (10.1M students affected); CNIL fines IQVIA €5M over health-data warehouses; California's record $12.75M CCPA settlement with GM/OnStar is the first enforcement of the data-minimization rule; Ofcom's age-assurance enforcement push widens.

Compliance action items

  • File Basel III “Endgame, Take Two” comment letters (Fed/OCC/FDIC) — June 18

  • Deploy UK DUAA data-protection complaints-handling procedure (no SME exemption) — June 19

  • EU AI Act high-risk classification guidelines — consultation closes June 23

  • Australian search engines deploy age assurance (eSafety Phase 2) — June 27

  • NIS2 first compliance audit deadline · FedRAMP CR26 finalization — June 30

  • MiCA CASP hard stop — confirm licence or execute orderly EU client exit — July 1

  • Review generative-AI pipelines against EU marking Code; sign-or-alternative decision — by August 2

  • Federal CSPs: map CONMON/vulnerability feeds to BOD 26-04's four risk criteria — before August 9

Resources

CyberEyeQ — Actionable Regulatory Intelligence. This episode is for informational purposes only and does not constitute legal advice.

Keep Reading