This website uses cookies

Read our Privacy policy and Terms of use for more information.

🎙️ Episode 38 is live

EU KIDS Act Reaches AI Chatbots · ~5 min

▶️ Listen on the web  ·   🎧 Direct MP3  ·   📡 Subscribe (RSS)

This week Brussels turned a State-of-the-Union soundbite into a formal bill — the EU KIDS Act, the first EU measure to pull AI chatbots and companion apps into child-safety law — as a wall of hard deadlines lands: FedRAMP's machine-readable package mandate, NIS2 going live in Austria and Poland, and China's expanded police cyber-inspection powers.

Top stories

  • EU tables the KIDS Act. The Commission's proposal would bar under-15s from autonomously creating social and video-sharing accounts and, for the first time at EU level, reaches AI chatbots and companion apps. It is still only a proposal — the age-15 floor may move toward the Parliament's age-16 resolution.

  • FedRAMP OSCAL mandate hits 30 September. Every Rev5 cloud provider — not just 20x pilot participants — must submit new authorization packages in machine-readable form; a grace period to 30 September 2027 covers converting existing authorizations.

  • NIS2 deadlines land in weeks. Austria's NISG 2026 enters full force 1 October; Poland's essential/important-entity registration closes 3 October; Italy's basic-security milestone follows 31 October. Obligations attach through each Member State's transposition law, so dates differ by country.

  • China widens police cyber checks. MPS Order No. 176 replaces the 2018 Order No. 151 and, from 1 October, authorises online patrol, remote vulnerability-probing and penetration-testing of non-critical (non-CII) systems.

  • Ireland opens its first Online Safety Code probe — into X. Coimisiún na Meán is investigating X's age-assurance measures; a breach can draw up to 10% of relevant annual turnover or €20 million, whichever is greater.

Enforcement watch

  • FinCEN's Alert FIN-2026-Alert005 ties roughly $12.7 billion in Bank Secrecy Act–reported activity to overseas scam-center investment fraud; examiners will expect the red-flag typologies folded into transaction monitoring and SAR narratives.

  • Alabama's enforcement clock against OpenAI — the first US clock aimed at what a model did autonomously, on a consumer-protection statute — fell due 14 September.

On the calendar

26 Sep — EU IVDR legacy class C written-agreement deadline · 29 Sep — CISA discontinues the weekly Vulnerability Summary Bulletin · 30 Sep — FedRAMP OSCAL requirement (all Rev5) · 1 Oct — Austria NISG 2026; China MPS Order 176; Connecticut SB 5 · 3 Oct — Poland NIS2 registration closes · 25 Oct — China TC260 AI/data-security drafts comment close.

Full analysis in this week's CyberEyeQ Weekly Briefing (Issue #36). Informational only; not legal advice.