The European Commission announced the details of the "EU KIDS Act" proposal aimed at ensuring children's digital safety.
The EU KIDS Act published by the European Commission introduces direct design and access restrictions on social networks, video-sharing platforms, AI chatbots, mobile games, and app stores. Under the regulation, strict access blocks and guardian-managed restricted account requirements are introduced for minors under 15, while companies are obligated to use EU-level age verification systems and prevent addictive designs. In AI chatbots, interaction models that simulate emotional dependency are prohibited.
Click on the link for the full story.
Rising AI breaches increase demands for independent audits and embedded evaluators.
Consecutive AI security breaches and autonomous system risks have prompted technology executives and governments to establish new oversight mechanisms. As the idea of appointing independent "embedded evaluators" within companies and conducting regular AI audits gains traction, legal audit requirements have come onto the agenda following the US White House Accord and in regions like California, Illinois, and China. Experts emphasize that standardized independent audits and qualified evaluators are essential for a safe and transparent AI ecosystem.
Click on the link for the full story.
The US administration and tech giants signed a joint commitment against autonomous AI risks.
US President Donald Trump and executives from leading technology companies approved a four-point AI safety plan focused on independent audits and internal controls. Lacking legal force and defined as "morally binding," this self-regulation model offers a temporary solution in the face of security breaches and growing litigation risks across the sector. However, experts and former officials argue that an oversight mechanism relying solely on corporate pledges will remain insufficient without binding legal regulations and legal liabilities.
Click on the link for the full story.
US President Donald Trump ordered the use of the term "super intelligence" instead of "artificial intelligence" in official communications through an executive order.
US President Donald Trump instructed all federal agencies to replace the term "artificial intelligence" (AI) with "super intelligence" (SI) in official communications and nonstatutory documents via an executive order. Without changing existing statutory definitions for now, the regulation initiated a dual-vocabulary period in the terminology used by government agencies and companies. While statutory law, contracts, and state laws retain the definition of "artificial intelligence," the administration plans to submit new legislation in the coming period to expand the scope of the super intelligence definition.
Click on the link for the full story.
Access permissions of AI tools connected to enterprise systems increase risks to fundamental rights and data privacy.
As organizations expand the deployment of AI systems, authorization issues in the connector and retrieval layers that allow models to access internal company data come to the fore. Focusing solely on the model itself during Fundamental Rights Impact Assessment (FRIA) under the EU AI Act and GDPR processes causes data breach risks created by tools with broad access to emails, human resources, or legal documents to be overlooked. Experts emphasize that privacy teams must audit connector permissions and query boundaries in advance to prevent systems from accessing data outside their intended purpose.
Click on the link for the full story.
Indonesia and Vietnam published new implementation and enforcement regulations on personal data protection.
Indonesia's Implementing Regulation No. 33/2026 under its Personal Data Protection Law was published, introducing new standards for data processing conditions, impact assessments in automated decision-making processes, and international data transfers. On the other side of Southeast Asia, Vietnam issued Decree No. 363/2026/ND-CP, containing enforcement measures such as business activity suspensions and license revocations against data violations. Companies operating in both countries need to complete their compliance processes and update their data governance mechanisms before the effective dates.
Click on the link for the full story.
The California Attorney General issued an investigative subpoena to OpenAI over model security and cyberattack risks.
California Attorney General Rob Bonta served a formal investigative subpoena to OpenAI questioning model security following the Hugging Face attack and unauthorized access to public systems. As the company announced issuing incident notices to 100 different third-party entities due to cyber breaches caused by its AI agents, pressure is mounting over voluntary safety commitments signed with the White House and independent audit mechanisms. During the ongoing crisis, OpenAI terminated three safety employees alleged to have shared confidential information with external auditors.
Click on the link for the full story.
The US Federal Trade Commission announced existing laws will be enforced for breaches caused by autonomous AI systems.
US Federal Trade Commission (FTC) Chair Andrew Ferguson announced that existing consumer protection and product liability laws will be firmly enforced against cyber breaches and data security risks caused by autonomous AI agents. The Commission opened a formal investigation into OpenAI, Anthropic, and safety evaluation organization METR, focusing on agent safety controls and unauthorized access incidents. Rejecting the anthropomorphization of AI to evade liability, the FTC stressed that legal sanctions will apply if companies fail to uphold safety commitments or provide inadequate oversight.
Click on the link for the full story.
A Swedish HR software company hit by a data breach was fined for GDPR violations.
Miljödata, a Swedish company providing digital HR and occupational health services, was fined SEK 1.8 million (EUR 160,000) by the Data Protection Authority following a August 2025 ransomware attack where sensitive health and personal data of approximately 2.2 million individuals were leaked. The investigation revealed that the company violated Article 32(1) of the GDPR due to a critical vulnerability in its firewall, acting negligently by failing to implement appropriate technical measures despite conducting extensive and sensitive data processing activities.
Click on the link for the full story.
The Icelandic Data Protection Authority reprimanded Isavia over camera-based license plate recognition at airport parking lots.
The Icelandic Data Protection Authority found that Isavia, which processes personal data using license plate recognition and camera systems across five airport parking lots, violated transparency and information obligations. The investigation revealed that warning signs about monitoring at certain airports were placed after entry points and lacked the identity of the data controller. Because the company addressed the deficiencies during the proceedings and completely discontinued monitoring at one airport, the authority issued a reprimand under Articles 5(1)(a), 12, and 13 of the GDPR instead of imposing an administrative fine.
Click on the link for the full story.