🎙️ Episode 38 is live
EU KIDS Act Reaches AI Chatbots · ~5 min
▶️ Listen on the web · 🎧 Direct MP3 · 📡 Subscribe (RSS)
This week Brussels turned a State-of-the-Union soundbite into a formal bill — the EU KIDS Act, the first EU measure to pull AI chatbots and companion apps into child-safety law — as a wall of hard deadlines lands: FedRAMP's machine-readable package mandate, NIS2 going live in Austria and Poland, and China's expanded police cyber-inspection powers.
Top stories
EU tables the KIDS Act. The Commission's proposal would bar under-15s from autonomously creating social and video-sharing accounts and, for the first time at EU level, reaches AI chatbots and companion apps. It is still only a proposal — the age-15 floor may move toward the Parliament's age-16 resolution.
FedRAMP OSCAL mandate hits 30 September. Every Rev5 cloud provider — not just 20x pilot participants — must submit new authorization packages in machine-readable form; a grace period to 30 September 2027 covers converting existing authorizations.
NIS2 deadlines land in weeks. Austria's NISG 2026 enters full force 1 October; Poland's essential/important-entity registration closes 3 October; Italy's basic-security milestone follows 31 October. Obligations attach through each Member State's transposition law, so dates differ by country.
China widens police cyber checks. MPS Order No. 176 replaces the 2018 Order No. 151 and, from 1 October, authorises online patrol, remote vulnerability-probing and penetration-testing of non-critical (non-CII) systems.
Ireland opens its first Online Safety Code probe — into X. Coimisiún na Meán is investigating X's age-assurance measures; a breach can draw up to 10% of relevant annual turnover or €20 million, whichever is greater.
Enforcement watch
FinCEN's Alert FIN-2026-Alert005 ties roughly $12.7 billion in Bank Secrecy Act–reported activity to overseas scam-center investment fraud; examiners will expect the red-flag typologies folded into transaction monitoring and SAR narratives.
Alabama's enforcement clock against OpenAI — the first US clock aimed at what a model did autonomously, on a consumer-protection statute — fell due 14 September.
On the calendar
26 Sep — EU IVDR legacy class C written-agreement deadline · 29 Sep — CISA discontinues the weekly Vulnerability Summary Bulletin · 30 Sep — FedRAMP OSCAL requirement (all Rev5) · 1 Oct — Austria NISG 2026; China MPS Order 176; Connecticut SB 5 · 3 Oct — Poland NIS2 registration closes · 25 Oct — China TC260 AI/data-security drafts comment close.
Full analysis in this week's CyberEyeQ Weekly Briefing (Issue #36). Informational only; not legal advice.