EU AI Act goes into effect, partly delayed and simplified
On 24th of July, the Digital Omnibus on AI was published in the Official Journal of the EU, bringing some amendments to the AI Act. It is intended to make it easier for companies operating in or targeting the EU market, institutions and individuals to comply with the Act’s requirements. Due to the delayed entry into force of the provisions for high-risk AI systems, it provides additional time to ensure compliance.
Stay up to date! Sign up to receive our fortnightly digest via email.
2 August 2026, the AI Act becomes generally applicable. For instance, this date establishes transparency obligations for providers and deployers of certain AI systems, including generative and interactive AI systems. Bans on the riskiest AI uses were already in effect since 2 February 2025.
At the same time, the obligations for high-risk AI systems (eg, in employment, education, administration, justice, etc) are postponed until 2 December 2027, and the obligations for high-risk systems incorporated into products (eg, as safety components) regulated by sectoral EU legislation until 2 August 2028. The obligation to label AI-generated content is also postponed, but only until 2 December 2026.
Other significant changes include eliminating overlapping regulatory requirements in the field of hardware products and expanding the possibility of processing special category personal data to detect bias and for system correction. The Digital Omnibus also introduces two new bans on AI systems that generate material depicting child abuse, the private parts of an identifiable person or explicit activities without their consent.
Non-compliance with the AI Act can be subject to administrative fines between 7,5 and 35 million euros or between 1 and 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. Some exceptions may be applied for SMEs, including start-ups, taking into account their fragile economic viability.
Main developments

French children social media ban: Following the UK example, the French government has approved a social media ban for those under 15 by January 2027. The ban marks the first to be approved among EU member states, with other governments working through proposals. Reportedly, platforms will be required to verify users’ ages and prevent underage users from creating accounts beginning 1 Sept.
Once the ban is in place, social media platforms would need to use age-verification tools (for all existing accounts), approved by the French privacy regulator CNIL.
Dublin summit on data protection: On July 1st, Ireland assumed the six-month EU presidency. Simultaneously, the European Data Protection Board (EDPB) was invited by the Irish Data Protection Authority to a two-day conference in Dublin. A European legal foundation that makes it easier for independent agencies with distinct competencies to share information was one of the conference’s key suggestions.
The Board also discussed efforts to support the enforcement of the GDPR, including through enhanced cooperation and joint use of experience and resources between supervisory authorities. Additionally, during the high-level meeting, the growing number of complaints was highlighted, fueled by the spread of artificial intelligence, which requires organisational and, where necessary, legislative solutions to ensure effective protection of data subjects’ rights.
Google Street View and privacy

In Germany, residents or homeowners who wish to have their images blurred in Google Street View can request this. Legally, this is considered an objection to publication, which can also be made in advance. The Hamburg Data Protection Commissioner agreed to this with Google in 2023. Since July 28, Google has required proof of address for all applications to prevent erroneous or fraudulent submissions. This is in accordance with the data protection law, as long as Google limits the required proof to the data necessary for this purpose, explains the regulator.
More official guidance
Facial recognition technology (FRT): The Australian Information Commissioner (OAIC) has published updates to its guidance for entities that are considering using FRT in high volume and publicly accessible physical spaces such as retail shopfronts. It guides undertakings through main compliance points:
- Accountability and ongoing assurance
- Lawful basis for data collection
- Transparency and notification
- Accuracy, bias and discrimination
- Data deletion and security
AI working tools and sensitive personal data: AI tools can help organisations perform daily tasks more efficiently, but they should be used judiciously, explains the Latvian regulator DVI. Before entering personal data, especially sensitive data, always assess whether it is necessary for the specific task and use anonymised or general information. Before this, the organisation must classify what types of tasks can be performed with the help of an AI system, especially if it is a publicly available one, and which ones cannot.
An AI system developed by an organisation to achieve a specific purpose also needs its own rules to ensure that employees use the tool only for its intended purpose.
DSARs after a data breach: The DVI also reminds us that personal data breaches often increase requests from data subjects. Along with incident prevention, risk assessment and necessary notifications, the data controller must also ensure the implementation of people’s rights as data subjects. In practice, the data protection officer (DPO) is often directly involved in the assessment of requests, although it should be noted that their role is advisory, while the controller is directly responsible for the decisions and their justification.
Proper use of cookies

The Lithuanian Data Protection Inspectorate, VDAI, draws attention to the fact that organisations often fail to implement the proper use of cookies, tracking pixels and other similar technologies. The improper use of tracking technologies is not just a formal violation. Transparent and lawful processing of personal data is an essential condition for ensuring individuals’ right to privacy and trust in digital services:
- When using cookies that are not essential, the consent of the website user must be obtained. Legitimate interest is not an appropriate legal basis for the use of these technologies.
- Consent must be given by active action, and pre-ticked boxes are not considered valid consent.
- The “Agree” and “Do Not Agree” buttons should be equally easily accessible.
- The design of the buttons should not encourage the user to give consent.
- The website must provide an easy-to-find way to change cookie settings or withdraw consent at any time.
- Users must be provided with clear and detailed information about the types of cookies used, and the purposes of their use.
AI and data protection implications
The Spanish privacy regulator AEPD found out that the data quality requirements and the principle of accuracy established in the GDPR cannot be understood in absolute terms, but rather in relation to the purpose of the processing. In this regard, the principle of accuracy enshrined in the GDPR does not require that data always be completely truthful or fully up-to-date, but rather that it be adequate for the purpose of the processing for which it is used, and that this be guaranteed when relevant to the data subjects.
The French CNIL stipulates that Agentic AI systems and their autonomous action capabilities raise questions of sharing GDPR roles and responsibilities between various actors. Additionally, it promotes the creation of hyper-personalised user profiles, which creates a real risk of losing control over personal data flows. While the main instruments of European data protection and artificial intelligence legislations are already applicable to agentic AI, their decision-making autonomy, persistent memory, the ability to interact with a plurality of services and to act on behalf of the user need an adaptation of the methods of implementation of these rules, concluded the CNIL.
The German Federal Office for Information Security meanwhile has published the final study of its AICRIV – Finance project. The aim of this project is to develop and validate standardised testing criteria and methods for evaluating AI systems in the financial sector. At its core is a structured testing catalog that integrates regulatory, operational, and technical perspectives on AI testing. In addition, a tool catalog describes and compares suitable software solutions for the systematic testing of these criteria.
Receive our digest by email
Sign up to receive our digest by email every 2 weeks
In other news
Suspended sentence for data stealing: In the UK, a council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence. The investigation revealed that, over a four-day period, he unlawfully accessed approximately 490 records and downloaded 94 documents. The records related to his family members and families known to him and included children and adults. The records accessed involved highly sensitive material such as medical records, social worker reports and child and family assessments.
Employee monitoring fine: The Italian Data Protection Authority Garante has fined Piaggio & C. Spa 460,000 euros for violations of privacy regulations regarding the management of company email accounts, data retention, and employee monitoring activities. The company had accessed their company emails during their employment, in order to verify the validity of alleged illicit behavior. In some cases, the acquired emails dated back to about two years before the company became suspicious.
This monitoring is made possible by Piaggio’s systematic collection and storage of email data, performed through backups for the entire duration of the employment relationship and up to 5 years after termination, as well as related logs for a period of 6 months, in violation of the GDPR and in the absence of the guarantees provided by the Workers’ Statute.
Data broker fine: A 2 million euro fine has also been imposed by Garante on Lusha Systems Inc., a US data broker, which through its platform provides, for a fee, “enriched” information relating to natural persons, such as their job position, email addresses and telephone numbers. Lusha collects this data from multiple sources, through scraping from social networks and purchasing from other data brokers, and makes it available to the customers for commercial or anti-fraud purposes.
And Finally

When AI escapes its sandbox: On July 21, OpenAI disclosed that several of its models had broken out of an isolated test environment by exploiting a previously unknown vulnerability. Claude had been tasked with a capture-the-flag challenge, one of the ways a model’s cyber capabilities can be assessed including, if necessary, the ability to carry out autonomous attacks.
The evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access.
Due to a misunderstanding with the evaluation partner, this was not the case, and internet access was available. Because of this, when Claude’s search led it to real systems on the open internet, it treated them as part of the exercise. As a result, Claude compromised the impacted organisations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints.