EU tables an under-15 account ban that reaches AI chatbots
Brussels turned a State-of-the-Union soundbite into a formal bill this week: the EU KIDS Act would bar under-15s from opening their own accounts and, for the first time at EU level, pull AI chatbots and companion apps into child-safety law — as a wall of hard deadlines lands in the same fortnight (FedRAMP's OSCAL mandate on 30 September, NIS2 in Austria and Poland, and China's expanded police cyber-inspection powers). Twelve developments across eight domains.
Correction to #35: we wrote that none of the five New York AI bills awaiting delivery to Governor Hochul carries an effective date — S9051-B does, its text fixing 1 January 2027, so if it is signed near the 31 December deadline the lead time is days rather than months. (bill text)
At a Glance
EU tables under-15 account ban — the Commission's KIDS Act proposal is the first EU measure to reach AI chatbots and companion apps; still a proposal, not law.
FedRAMP OSCAL mandate hits 30 Sept — every Rev5 cloud provider, not just 20x participants, must file machine-readable packages.
NIS2 deadlines land in weeks — Austria full force 1 October; Poland entity registration closes 3 October.
China widens police cyber checks — MPS Order 176 authorises online patrol and remote probing of non-critical systems from 1 October.
FDA keeps radiology AI under 510(k) — a final order effective 17 September denies the exemption petition.
SEC moves to scrap Rule 14a-8 — two 16 September proposing releases would rescind the shareholder-proposal rule.
Critical Actions
FedRAMP OSCAL package requirement takes effect 30 September (13 days) — all new Rev5 authorization packages must use an approved machine-readable (OSCAL) format, reaching every Rev5 provider, not only the 20x pilot; non-compliance triggers public notification (grace period to 30 Sept 2027 for existing authorizations). Action: Prepare any new or in-flight Rev5 package in OSCAL by 30 September and schedule conversion of existing authorizations. (FedRAMP RFC-0024)
EU NIS2 — Austria in full force 1 October, Poland registration due 3 October (14–16 days) — obligations attach through each Member State's transposition law, so dates differ; Ireland, Spain and France still have no adopted law. Action: Complete Austrian NISG 2026 obligations by 1 October, file the Polish registration by 3 October, and confirm Italian measures ahead of 31 October. (European Commission — NIS2 transposition)
China — MPS Order No. 176 takes effect 1 October (14 days) — replaces the 2018 Order No. 151 and expands public-security inspection to network, data and content security, authorising online patrol and remote vulnerability-probing of non-CII systems. Action: Confirm which China-based systems fall within PSB inspection scope and finalise inspection-readiness before 1 October. (Ministry of Public Security — Order No. 176)
Enforcement Watch
Alabama's OpenAI enforcement clock has run — a US first. Document production under Deceptive Trade Practices Act Subpoena #26-0007 (served 20 August over a July 2026 incident reaching the Hugging Face network) fell due 10:00 CT on 14 September — the first US enforcement clock aimed at what a model did autonomously, on a consumer-protection statute needing no AI-specific law. (Alabama Attorney General)
FinCEN ties nearly $13 billion to digital-asset “scam center” fraud — $12.7B. Alert FIN-2026-Alert005 (3 September) identifies roughly $12.7B in BSA-reported activity from September 2023–December 2025; no new obligation, but examiners will expect the red-flag typologies in monitoring and SAR narratives. (FinCEN)
Ireland opens its first Online Safety Code probe — into X. Coimisiún na Meán's first-ever formal investigation targets X over age-assurance and hard-to-find parental controls; self-declaration alone is not sufficient. A breach can draw up to 10% of turnover or €20 million. (Coimisiún na Meán)
Deadline Watch
26 Sep — EU IVDR legacy class C notified-body written-agreement deadline (EU).
29 Sep — CISA discontinues the weekly Vulnerability Summary Bulletin; migrate to the KEV Catalog (US).
30 Sep — FedRAMP OSCAL machine-readable package requirement effective, all Rev5 (US); UK workplace-monitoring consultation closes (UK).
1 Oct — Austria NISG 2026 full force; China MPS Order 176 effective; Connecticut SB 5 AI duties commence.
3 Oct — Poland NIS2 essential/important-entity registration closes (Poland).
5 Oct — CFTC Part 4 CPO/CTA NPRM and OCC availability-of-information NPRM comments close (US).
9 Oct — FedRAMP RFC-0033/0034 comment windows close (US).
13 Oct — OCC/FDIC CRA-overhaul NPRM comments close (US).
19 Oct — NIH draft biosafety policy (AI-designed organisms) comments close (US).
25 Oct — China TC260 AI-security and data-security maturity drafts comments close (China).
26 Oct — UK Cyber Security and Resilience Bill, Lords Report stage (UK).
2 Nov — OCC/FDIC “unsafe or unsound practice” & MRA final rule effective (US).
13 Nov — India DPDP consent-manager registration (Rule 4) opens (India).
1 Jan 2027 — Delaware DPDPA amendment (HB 380) effective, 10,000/5,000 thresholds (US-DE).
Around the World
🇰🇷 South Korea — The amended PIPA took effect 11 September (total-revenue surcharges, explicit CEO/board breach liability, a “possibility of leak” reporting trigger). Myth-buster: the “world-first AI training-data law now enforceable” claim is wrong — that AI route sits in a distinct PIPA bill announced 27 August and not shown to be in force. Treat it as pending. (PIPC)
🇨🇳 China — TC260 opened comment (to 25 October) on draft AI Security and Data Security capability-maturity standards; the National Data Administration signalled forthcoming embodied-intelligence data standards, with no binding instrument yet. (TC260)
🇬🇧 United Kingdom — The Cyber Security and Resilience Bill now has a Lords Report stage dated 26 October; it expands scope to MSPs and data centres with a 24-hour notification duty. The workplace-monitoring consultation closes 30 September. (UK Parliament)
🇦🇺 Australia — The “Strengthening Enforcement” amendment received assent 11 September; commencement and first use of expanded third-party document-production powers are pending. (Australian Parliament)
Deep Dive
European Union · Age Verification / AI Governance
The EU KIDS Act reaches AI chatbots for the first time
On 17 September 2026 the European Commission turned a State-of-the-Union announcement into a formal legislative proposal: the EU KIDS Act — “EU Keeping Internet Digital Spaces Accountable and Trustworthy.” Its core obligation, confirmed against the Commission's own publication, would bar children under 15 from autonomously creating accounts on social-networking and video-sharing services, and — by fixing a single minimum age across the Union — would replace the patchwork of national rules with one Single-Market standard. It was published as a three-document package: the draft Regulation, a Communication, and a Staff Working Document.
What makes this file different from the DSA duties platforms already carry is its reach. As reported around publication, it extends child-safety duties to online games and, for the first time at EU level, AI chatbots and companion apps; would require DSA very-large-platforms to seek Commission authorisation before rolling out new child-affecting features; and would levy a supervisory fee. Two cautions belong in every compliance memo: it is still only a proposal, with the age-15 floor unaligned with Parliament's age-16 position, and the tiered detail circulating around publication is reported, not yet read off the official text. That gap between the political signal and the legal text is exactly where the next six months of lobbying will happen — and where a team that reads the proposal now, rather than the headlines, will find its leverage…
The analysis continues for CyberEyeQ Pro subscribers. Unlock the full deep-dive recommendations, all five weekly action items, source documents, and jurisdiction-specific compliance checklists.
Subscribe to Pro to read the rest.
Become a paying subscriber of Pro to get access to this post and other subscriber-only content.
UpgradeA subscription gets you:
- Deep dives of each updated regulation
- Source verification documents
- Extended jurisdiction-specific analysis
- Compliance deadline tracker
- Regulation crosswalk