This website uses cookies

Read our Privacy policy and Terms of use for more information.

California licenses AI auditors as EU & Korea deadlines land in the same 72 hours

Twelve developments across eight jurisdictions this week, with one through-line: California became the first jurisdiction anywhere to license the people who audit AI — arriving alongside two of the year's hardest EU and Korean compliance deadlines and a $13B FinCEN money-laundering signal.

At a Glance

  • California licenses AI auditors — Newsom signed SB 813 and AB 1405, the first US laws to regulate who may assess AI systems.

  • EU incident-reporting clock starts — CRA Article 14 duties become binding 11 September via ENISA's new Single Reporting Platform.

  • Korea ties fines to the CEO — amended PIPA takes effect 11 September with statutory CEO accountability and 10%-of-turnover penalties.

  • $13B in crypto scam flows flagged — a FinCEN alert maps overseas scam-center fraud and presses 314(b) information sharing.

  • China widens police cyber checks — MPS Order 176 authorises online patrol and remote probing from 1 October.

  • FDA opens eight 510(k) lanes — eight novel device types classified into Class II, effective on publication.

Critical Actions

  1. EU Cyber Resilience Act — Article 14 reporting goes live 11 September (1 day). Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents on a 24h / 72h / 14-day clock via ENISA's Single Reporting Platform, which launches the same day; the duty reaches products already on the market, so cloud and SaaS suppliers inherit the timelines. Action: Confirm in-scope products, secure ENISA SRP access, and name the reporting owner before Friday. European Commission — CRA reporting

  2. South Korea — amended PIPA takes effect 11 September (1 day). The law names the CEO as ultimately responsible for compliance and adds a fine track up to 10% of total annual turnover for the most serious systemic failures (the 3% baseline remains); CPO appointment/dismissal now needs board approval and a PIPC report. Action: Get written CEO/board sign-off and verify CPO governance records. PIPC

  3. EU Data Act — data-access-by-design attaches 12 September (2 days). Article 3(1) of Regulation (EU) 2023/2854 requires connected products newly placed on the EU market to make in-use and readily available data directly accessible to the user by default. Action: Confirm newly placed products meet Art. 3(1); review egress-fee and portability terms against Arts. 23–31. EUR-Lex — Data Act

Enforcement Watch

  • FinCEN / $12.7B — Alert FIN-2026-Alert005 (3 Sep) maps nearly $13B tied to overseas digital-asset scam-center fraud from BSA filings (Sep 2023–Dec 2025); no new obligation, but examiners will expect the red-flag typologies in monitoring and SARs. FinCEN

  • Spain AEPD / €950K — Resolución PS/00164/2025 (€500K Art. 9 biometrics + €200K invalid consent + €250K excessive retention); Yoti pulled its Digital ID app from Spanish stores on 10 Sep rather than add a non-biometric path. Under appeal. AEPD

  • France CNIL / €500K — Deliberation SAN-2026-009 against Hôpital Privé de la Loire under GDPR Arts. 32/34 after a 2025 intrusion reached ~524,867 patient records via remote access with no VPN and no MFA. CNIL

Deadline Watch

  • 11 Sep — EU CRA Art. 14 vulnerability/incident reporting mandatory; ENISA SRP live (EU).

  • 11 Sep — Amended PIPA in force: CEO liability, 10%-turnover fines (South Korea).

  • 12 Sep — EU Data Act Art. 3(1) data-access-by-design trigger (EU).

  • 13 Sep — ENISA EUMSS certification scheme public review closes (EU).

  • 14 Sep — Alabama AG subpoena: OpenAI production due, 10:00 CT (US-AL).

  • 16 Sep — FDA ISH companion-diagnostic reclassification to Class II takes effect (US).

  • 30 Sep — UK cryptoasset authorization window opens, to 28 Feb 2027 (UK).

  • 1 Oct — China MPS Order 176 police cyberspace-inspection in force; Connecticut PA 26-15 effective (China / US-CT).

  • 13 Nov — India DPDP Rule 4 Consent Manager registration opens (India).

Around the World

  • New York — A sweep found five more AI bills that cleared both chambers and were never delivered to Governor Hochul: companions for minors, training-data transparency, synthetic-content provenance, GenAI accuracy notices (passed 9 March), and a surveillance-pricing ban. None has an effective date yet. NY Senate

  • China — MPS Order 176 expands police cyberspace inspection (online patrol, remote probing, penetration testing of non-critical systems) from 1 October, repealing the 2018 Order 151; TC260 opened comment (to 25 Oct) on AI/data-security maturity models. MPS

  • Spain — Yoti pulled its Digital ID app rather than comply with the AEPD's Article 9 reading — a warning that a DPA exit can create overnight continuity risk for platforms built on a single biometric vendor. Yoti

  • United Kingdom — FCA cryptoasset authorization window opens 30 September (to 28 Feb 2027); the Cyber Security and Resilience Bill remains in Lords committee, Royal Assent not expected before spring 2027. FCA

Deep Dive

California · AI Governance

California builds the first US assurance layer for AI

On the evening of 9 September 2026, Governor Newsom signed Senate Bill 813 (McNerney) and Assembly Bill 1405 (Bauer-Kahan) — the first two AI bills of California's 2026 session to be acted on, and the first US statutes anywhere to build a licensed third-party assurance layer around artificial intelligence. SB 813 creates a framework for independent verification organizations that can assess AI systems for compliance with state law; AB 1405 establishes a state registry for AI auditors with statutory standards for independence, transparency and integrity. Both were on our watch list as signature-deadline risks, discharged three weeks ahead of the 30 September constitutional outer bound.

What makes the pair structurally new is who it regulates. Nearly every AI law to date — the EU AI Act, Colorado's SB 26-189, California's own SB 53 — imposes a duty on the developer or deployer of a model. SB 813 and AB 1405 instead regulate the auditor: the accredited party who checks whether those duties have been met. It is the missing complement to SB 53's transparency regime, which makes frontier developers publish safety frameworks but says little about who is qualified to attest to them. California has effectively decided that an AI assurance market needs licensing before it needs volume. Here's what that means for the organizations that will have to live inside it, and the dates that turn it from principle into a hard gate…

The analysis continues for CyberEyeQ Pro subscribers. Unlock the full deep-dive recommendations, all five weekly action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk