AI Act3 Aug 2026Art. 53, Art. 55
Detected guidance relating to AI Act: “Fourth GPAI Signatory Taskforce meeting”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
AI Act31 Jul 2026Art. 50
European Commission communication marking the start of enforcement of the AI Act from 2 August 2026 — including the Article 50 transparency obligations for chatbots and AI-generated content and the general-purpose AI (GPAI) obligations. See the primary source for scope and detail.
What to do: If you operate chatbots, generate AI content or provide/deploy general-purpose AI, confirm your Article 50 transparency measures and GPAI obligations are in place — they now apply.
AI Act31 Jul 2026Art. 50(2), Art. 50(4)
European Commission announcement of strong stakeholder backing for the Code of Practice on the transparency of AI-generated content, which supports the Article 50 marking and disclosure obligations. See the primary source for detail.
What to do: If you generate or deploy AI-generated content, review the Code of Practice as a route to demonstrate compliance with the Article 50 transparency duties.
GDPR27 Jul 2026Art. 2, Art. 5, Art. 6, Art. 9, Art. 10
Court of Justice (Grand Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): material scope (Article 2), the principles relating to processing and its lawfulness (Articles 5 and 6), the concept of data concerning health (Article 9) and personal data relating to criminal convictions (Article 10). See the primary source for the Court's operative findings.
What to do: If you process health data or data on criminal convictions under the GDPR, read this ruling against your lawful-basis and special-category analysis and record whether any change is needed.
GDPR27 Jul 2026
Court of Justice (Fifth Chamber) preliminary ruling on the GDPR (Regulation (EU) 2016/679): its scope where information on criminal convictions is made available to the public online in return for remuneration, and reconciling the right to protection of personal data with the right to freedom of expression and information. See the primary source for the Court's operative findings.
What to do: If your service publishes personal data, including data on criminal convictions, weigh this ruling against your data-protection and freedom-of-expression balancing and record whether any change is needed.
Cyber Resilience Act27 Jul 2026
European Commission guidance to help businesses implement the Cyber Resilience Act (Regulation (EU) 2024/2847). See the primary source for the full guidance.
What to do: If you make products with digital elements in scope of the CRA, read this guidance against your implementation plan and record whether any change is needed.
Digital Services Act24 Jul 2026
Preliminary finding by the European Commission that TikTok breaches the Digital Services Act by failing to ensure safe accounts for minors. This is a preliminary finding, not a final decision; TikTok can respond before the Commission concludes. See the primary source for details.
What to do: If you operate an online platform under the DSA, note this enforcement direction on the safety of minors and review your own measures.
GDPR23 Jul 2026Art. 33
The EDPB adopted a common data breach notification template to harmonise GDPR Article 33 breach notifications across the EU.
What to do: If you process personal data, align your breach-notification process with the common template. Review the primary source.
GDPR23 Jul 2026
Detected guidance relating to GDPR: “EDPB calls for legal basis for cross-regulatory information sharing”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether this affects your personal-data processing and record the source in your compliance dossier.
Digital Services Act23 Jul 2026
Detected guidance relating to Digital Services Act: “Commission accepts X's corrective measures to terminate breaches of the DSA”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
Digital Services Act23 Jul 2026
Detected guidance relating to Digital Services Act: “Commission accepts X’s action plan to comply with Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Review this item against your compliance dossier and record whether action is needed.
AI Act21 Jul 2026
Commission Implementing Regulation (EU) 2026/1755 sets detailed procedural arrangements for how the Commission conducts certain proceedings under the AI Act (Regulation (EU) 2024/1689). Published in the Official Journal.
What to do: Relevant if the Commission may open proceedings on your AI systems. Note the procedural rules and review the primary source.
AI Act20 Jul 2026Art. 50
Detected guidance relating to ai act: “Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: Check whether your AI systems fall within scope of this update and record the source in your compliance dossier.
Digital Services Act20 Jul 2026
Detected enforcement relating to Digital Services Act: “Commission fines AliExpress €550 million for breaching the Digital Services Act”. Summarised automatically from the primary source; open the source link for the authoritative text.
What to do: No direct compliance change follows from this enforcement action against a platform. Review it for DSA enforcement context and note any implications relevant to your services.
GDPR17 Jul 2026Art. 6, Art. 9(2)
On 8 July 2026 the EDPB published guidance on when data counts as anonymous and how the GDPR applies to web scraping used to train generative AI. Data is anonymous only if individuals cannot be singled out, linked across records, or inferred - and that assessment can differ per recipient. Scraping personal data must respect purpose limitation, transparency, accuracy and data minimisation, and special-category data still needs both an Article 6 lawful basis and an Article 9(2) exception. The anonymisation and web-scraping guidelines are open for public consultation until 30 October 2026 and may still change; the accompanying blockchain guidelines were adopted in final form.
What to do: If you train or fine-tune generative AI on scraped or web-sourced data, document the Article 6 lawful basis and confirm no special-category data is used without an Article 9(2) exception. Re-test any data you treat as anonymised against the singling-out, linkability and inference criteria. Keep records of purpose limitation, source reliability (timestamps), accuracy validation and data-minimisation measures for your scraping pipeline.
NIS29 Jul 2026
An enforcement action related to NIS2/cybersecurity regulation: “Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity”. See the primary source for the authoritative text.
What to do: No direct action for your own systems — this is an enforcement step against a Member State, not a new obligation. Note it for awareness only.
NIS29 Jul 2026
ENISA published NIS2 implementation guidance: NIS2 Technical Implementation Guidance plus a companion on cybersecurity roles and skills for essential and important entities.
What to do: If you are an essential or important entity under NIS2, use this guidance to shape your implementation. Review the primary source.
AI Act9 Jul 2026Art. 50(2), Art. 50(4)
The Commission published a Code of Practice on marking and labelling AI-generated content. It supports the Article 50 transparency obligations: machine-readable marking and detectability of synthetic content by providers (Art. 50(2)) and disclosure/labelling of AI-generated or manipulated content by deployers (Art. 50(4)).
What to do: If you provide or deploy generative AI, review this Code against your Article 50(2) marking duty (providers) and your Article 50(4) disclosure duty (deployers) and record how you meet them.
AI Act2 Feb 2025
The ban on AI emotion recognition in the workplace and education applies since 2 February 2025 (Art. 5 AI Act). Enforcement is still nascent — no major formal case yet. Fines for prohibited practices are the highest in the regulation.
What to do: Confirm no system implements an Art. 5 prohibited practice; the penalty ceiling is up to EUR 35 million or 7 percent of worldwide turnover.
ECHR / fundamental rights5 Feb 2020
The SyRI welfare-fraud risk system breaches Article 8 ECHR: insufficiently transparent and not proportionate. Use prohibited.
What to do: If you run automated risk-profiling on individuals, test it against fundamental-rights safeguards (proportionality, transparency); the court struck down SyRI for lacking them.
GDPR1 Dec 2021
Years of unlawful and discriminatory processing of applicants' (dual) nationality for childcare benefits; nationality wrongly used as a risk indicator.
What to do: Review automated profiling for unlawful or discriminatory use of personal data; ensure necessity, proportionality and a clear lawful basis.
GDPR3 Sep 2024
Unlawful database of billions of facial images scraped from the internet for facial recognition, without a valid legal basis; processing of biometric personal data.
What to do: Do not use facial-recognition data obtained by untargeted scraping; where you process biometric data, confirm a valid basis and carry out a DPIA.
GDPR20 Dec 2024
ChatGPT trained on personal data without a valid legal basis, breach of transparency duties, failure to report a data breach (March 2023) and missing age verification.
What to do: If you process personal data through a generative-AI service, verify your lawful basis, your transparency notice to users, and any age checks.
AI Act19 Nov 2025Art. 6, Annex III
Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. The binding high-risk application dates are 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
What to do: Re-baseline affected systems and contracts against Regulation (EU) 2026/1744, keep non-high-risk workstreams on their applicable dates, and preserve the decision trail from before entry into force.
AI Act10 Jul 2025art. 53, art. 55
Voluntary code of practice for providers of general-purpose AI models (Art. 53/55), with three chapters: transparency, copyright and safety/security. Signatories (incl. Anthropic, Google, Microsoft, OpenAI, IBM) use it to demonstrate compliance; Meta did not sign.
What to do: If you build on a general-purpose AI model, obtain and keep the provider transparency and copyright information you rely on (Art. 53), and check whether your provider signed the Code.
AI Act4 Feb 2025art. 5
The Commission's official guidance on the prohibited practices (Art. 5): manipulation, exploitation of vulnerabilities, social scoring, untargeted facial scraping, emotion recognition at work/education, biometric categorisation and certain real-time biometric identification. Non-binding; the CJEU has the final say.
What to do: Check that none of your AI systems fall under the Art. 5 prohibitions (e.g. social scoring, untargeted facial scraping, emotion recognition at work or school); record that assessment.