China takes new legal steps to increase safety and oversight in artificial intelligence.
China's Minister of State Security, Chen Yixin, announced that the Cybersecurity Law and the Counter-Espionage Law will be strictly enforced against risks such as AI technologies getting out of control, cyberattacks, and data breaches. Indicating that new specialized regulations covering development, application, and risk management processes are on the way, the Ministry emphasized algorithm security, data protection, and copyright. This strict approach by China shows that despite global competition with the US, both countries need internal security and self-oversight mechanisms.
Click on the link for the full story.
The Irish Data Protection Commission fines Google 403 million Euros for unlawfully processing location data.
The Irish Data Protection Commission imposed an administrative fine of 403 million Euros on Google for unlawfully processing users' location data and violating transparency principles. It was determined that users' sensitive location information was used without consent for advertising or interest estimation purposes in features like search history and location verification, and retained for longer than necessary. The company was instructed to bring its data processing procedures into compliance with regulations within six months.
Click on the link for the full story.
The Brazilian Data Protection Authority announces details of the landmark fine imposed on TikTok for child data violations.
The Brazilian Data Protection Authority shared the details of the 153.7 million real administrative fine issued to ByteDance (TikTok). Following an investigation, the company was found guilty of failing to prevent children under 13 from accessing the platform, using inadequate age verification mechanisms, and violating the accountability principle. Highlighting the lack of consent and legal basis, the Authority ordered the deletion of data belonging to youths aged 13–18 whose authorized parental consent was not completed, emphasizing that data controllers are expected to provide technical proof that measures work in practice rather than mere paper policies.
Click on the link for the full story.
Article 4 of the EU AI Act eases the literacy obligation while increasing uncertainties.
Updates made by the European Union to Article 4 of the AI Act under the Digital Omnibus package appear to ease administrative burdens by relaxing the requirement for organizations to provide AI literacy to their personnel. However, removing the phrase "best efforts" from the text and tying compliance criteria to guidelines to be published by the Commission and member states transfers control over the process to the administration. Since the obligation for human oversight in high-risk systems continues, companies need to follow external regulations and pre-determine their own literacy standards.
Click on the link for the full story.
Italy becomes the first country to integrate the EU AI Act into its national law.
Italy became one of the first countries to integrate the EU AI Act into its national law through Law No. 132 and the Decree published in September 2026. Criminalizing security negligence and non-consensual deepfake content, and introducing administrative fines as well as commercial bans for companies, the regulation sets strict rules for usage in healthcare, employment, judiciary, and law enforcement. Governing the burden of proof, the Law obliges companies to fully demonstrate human oversight, risk management, and technical documentation processes for high-risk AI systems.
Click on the link for the full story.
An OpenAI AI agent's unauthorized access to the Australian health data portal triggers security and governance debates.
An OpenAI AI agent gaining unauthorized access to non-public files within the Australian Government's Medicare statistics portal sparked a new debate focused on AI governance and siber security. Although it was stated that personal health data was not leaked, the fact that the incident occurred by an AI agent bypassing security controls without human intervention drew significant attention. The Australian Government established a dedicated taskforce covering legal regulations and incident notification processes against the risks posed by autonomous systems.
Click on the link for the full story.
The US Senate examines mass surveillance and cybersecurity risks posed by AI-powered license plate recognition cameras.
The US Senate Judiciary Committee held a hearing addressing mass surveillance, unauthorized access, and cybersecurity vulnerabilities caused by AI-integrated license plate recognition cameras produced by companies like Flock Safety. Officials emphasized that scanning billions of images nationwide threatens personal liberties and that cameras have been misused by police officers or cyber attackers. During the hearing, legal reform options were evaluated, such as requiring search warrants for law enforcement to access camera data or banning the systems altogether.
Click on the link for the full story.
The Information and Privacy Commissioner of Ontario emphasizes the importance of auditing data integration systems prior to launch.
The Information and Privacy Commissioner of Ontario published its review of the Ministry of Finance's new inter-ministerial data integration unit, stating that auditing systems before they become operational is of critical importance. As a result of the review, binding security orders including penetration testing and access logs were issued to the ministry. Addressing the removal of such mandatory pre-audits through legal changes, experts emphasize that independent, preventive audit mechanisms must be preserved to prevent hard-to-detect risks in large-scale data analytics and AI projects.
Click on the link for the full story.
A marketing company's GDPR fine for unauthorized recording of interview calls is reduced by the court.
An administrative fine of 25,500 Euros imposed by the Data Protection Authority on a marketing company for recording phone interviews with candidates for internal training without prior notice was reduced to 22,000 Euros by court decision. Although the court considered both unauthorized recording and failure to fulfill the information obligation as aggravating factors, it re-adjusted the fine in accordance with the principle of proportionality, accepting the lack of intent (negligence), the small size of the company, and its active cooperation with the authority as mitigating circumstances.
Click on the link for the full story.
The Spanish Data Protection Authority fines Vodafone Spain 750 thousand Euros for data breach and unlawful data processing.
The Spanish Data Protection Authority imposed a total administrative fine of 750,000 Euros on Vodafone España following a data breach in its "Super WiFi" service. The agency found that retroactively signing the contract with the data processor months after the service started, along with inadequate data security audits and encryption measures, violated Articles 28, 32, and 5(1)(f) of the GDPR. The company's previous similar infringements and the large volume of personal data processed were also evaluated as aggravating factors in increasing the fine.
Click on the link for the full story.