This week was dominated by AI and online-safety governance, led by Australia’s full commencement of the Age-Restricted Material Codes, which now force real age-assurance and access controls for children-facing services, including AI companions. In Europe, the AEPD reinforced GDPR limits on solely automated decisions, while the AP and CNIL continued building supervisory guidance around algorithms and AI under the EU AI Act. In Switzerland, the FDPIC clarified when DPIAs and regulator consultation are required, and in the US HHS confirmed that Part 2 compliance deadlines for SUD records are now in force. For regulated digital products, the message is clear: controls, human oversight, and documented risk assessments are moving from policy language to operational expectation.
Other jurisdictions / frameworks
Australia’s age-restriction codes fully commence
Australia’s Age-Restricted Material Codes have fully commenced, introducing age-assurance and content-access controls for online services used by children. The eSafety Commissioner says AI companions that can generate sexually explicit, high-impact violence or self-harm material must verify a user is 18 or older before granting access.
Why it matters: Services with child-facing or mixed-audience products now need working age assurance and content gating, not just policy statements. eSafety also says it will monitor compliance and take enforcement action where there is systemic non-compliance, raising the stakes for weak implementations.
Read source →eSafety sets AI transparency baseline for public use
eSafety published an AI transparency statement describing its internal approach to AI use, including human oversight, risk assessment, staff training, and periodic review. The agency says it will not use AI in ways inconsistent with legal obligations, public trust responsibilities, or Australian Government policy, and will not let AI make final regulatory decisions without accountable human judgment.
Why it matters: This is a useful benchmark for any regulated organization deploying AI in customer service, moderation, or enforcement workflows. It signals that documented risk review, staff training, and human sign-off are becoming the expected control set for high-stakes AI use.
Read source →eSafety urges safer recommender design
eSafety updated its position on recommender systems and algorithms, warning that these systems can amplify harm if not designed with safety in mind. The agency says industry should adopt Safety by Design, give users more control over algorithm settings, and improve transparency about how systems are designed and used.
Why it matters: Platforms that rely on ranking or recommendation engines should expect greater scrutiny of user controls and explanation layers. The practical compliance implication is to document safety-by-design decisions and be ready to show how harmful amplification risks are mitigated.
Read source →eSafety updates generative AI safety stance
eSafety’s generative AI position statement describes key risks and harms and calls for Safety by Design, transparency, and accountability measures for content-generating services. The page says safety controls should be built in across the product lifecycle.
Why it matters: Providers of generative AI tools should treat safety review as an ongoing lifecycle obligation, not a launch checklist item. The signal here is that content generation systems will be expected to show layered safeguards, not just usage warnings.
Read source →Swiss FDPIC details DPIA and consultation triggers
The FDPIC clarified when Swiss controllers must conduct a data protection impact assessment for processing likely to create a high risk to personality or fundamental rights. The guidance also explains that if residual high risk remains after mitigation, the controller must obtain the FDPIC’s opinion.
Why it matters: Teams using new technologies or high-risk processing in Switzerland need a documented DPIA that describes the processing, evaluates risks, and records mitigations. If residual risk stays high, the process does not end internally, because regulator consultation becomes mandatory.
Read source →GDPR / Data Protection Enforcement
AEPD tightens rules on automated decisions
The AEPD explained the right not to be subject to decisions based solely on automated processing, subject to limited exceptions and safeguards. It says organizations must provide human intervention, allow individuals to express a point of view, and let them challenge the decision where the contract or consent exceptions are used.
Why it matters: Any decisioning workflow that has legal or similarly significant effects needs a clear human-review path and contestability process. The guidance also warns against relying on the exceptions for special-category data unless Article 9(2)(a) or (g) conditions are met and safeguards are in place.
Read source →CNIL keeps AI compliance resources in view
The CNIL’s AI topic page points readers to its AI compliance materials and says it has an action plan for deploying privacy-respecting AI systems. The page is informational rather than a new obligation, but it consolidates the regulator’s AI-focused guidance.
Why it matters: French-facing teams should treat the CNIL page as a routing hub for compliance expectations around AI and privacy. It is a reminder to keep internal AI governance aligned with existing GDPR obligations while monitoring CNIL guidance.
Read source →US Federal & State Regulation
HHS confirms Part 2 compliance deadlines passed
HHS’s HIPAA Part 2 overview states that the 2024 final rule became effective on April 16, 2024 and that compliance was required by February 16, 2026. The page also explains that Part 2 protects substance use disorder patient records and limits disclosure except in narrow circumstances such as written patient consent or a court order and subpoena.
Why it matters: Covered programs should already have updated consent, disclosure, breach reporting, and notice practices for Part 2 records. If these changes are not operationalized yet, the compliance gap is now overdue rather than prospective.
Read source →HHS maps health apps to applicable laws
HHS OCR released guidance for mobile health app developers explaining that HIPAA, FTC, FDA, and other laws may apply depending on the app’s functions and data handling. The tool walks developers through questions about function, data collected, and services provided, then points them to potentially relevant federal laws.
Why it matters: Health app teams need a jurisdiction-by-jurisdiction and function-by-function legal assessment, not a one-size-fits-all privacy notice. The practical takeaway is to classify the app’s role in the data flow early so the right compliance regime is applied before launch.
Read source →New Jersey tax case touches cookie-data and support activity
In American Catalog Mailers Association v. Director, Division of Taxation, the New Jersey Tax Court upheld regulations treating certain interactive technical support as in-state business activity for tax purposes. The court declined to rule on the cookie-data provision because the factual record was not clear enough.
Why it matters: While this is a tax case, it may matter to privacy and adtech teams because it shows courts scrutinizing how data-related and support activities are characterized for state-law purposes. Companies relying on remote support or data monetization models should watch for downstream compliance implications, especially where state definitions hinge on operational facts.
Read source →EU AI Act
Dutch regulator links AI oversight to AI Act prep
The AP said its coordination directorate focuses on algorithm and AI risk analysis, cooperation with other supervisors, and guidance to clarify expectations for organizations. The page says this work is being carried out since 2023 and is intended to prepare for new tasks arising from the AI Act.
Why it matters: Organizations operating in the Netherlands should expect more coordinated supervisory attention on AI risks and clearer expectations around algorithm governance. This is a signal to tighten documentation, escalation paths, and cross-functional oversight before enforcement matures.
Read source →On Our Radar
AI safety-by-design hardening: Australia’s eSafety updates, together with EU supervisory guidance, point to a broader shift toward demonstrable safety controls, not just policy commitments. Expect more pressure for human oversight, transparency, and lifecycle review in AI systems.
Automated decision contestability: The AEPD’s guidance reinforces a growing expectation that automated decisions must be explainable, challengeable, and backed by human review where required. Teams using AI for eligibility, moderation, or risk scoring should check whether contestation workflows are already in place.
High-risk DPIAs under new tech: The FDPIC’s guidance underscores that new technologies can trigger high-risk assessments and, in some cases, regulator consultation. Data teams should review whether their current DPIA triggers capture AI, recommender, and other novel processing activities.
Part 2 operational cleanup: HHS has now marked the Part 2 compliance date as passed, so organizations handling substance use disorder records should be checking that consent, breach reporting, and notice obligations are fully embedded in operations.