AI Compliance Weekly — 2026-10-04

weekly roundup11 regulations4 frameworks

This week was dominated by AI and online-safety governance, led by Australia’s full commencement of the Age-Restricted Material Codes, which now force real age-assurance and access controls for children-facing services, including AI companions. In Europe, the AEPD reinforced GDPR limits on solely automated decisions, while the AP and CNIL continued building supervisory guidance around algorithms and AI under the EU AI Act. In Switzerland, the FDPIC clarified when DPIAs and regulator consultation are required, and in the US HHS confirmed that Part 2 compliance deadlines for SUD records are now in force. For regulated digital products, the message is clear: controls, human oversight, and documented risk assessments are moving from policy language to operational expectation.

Other jurisdictions / frameworks

critical

Australia’s age-restriction codes fully commence

Australia’s Age-Restricted Material Codes have fully commenced, introducing age-assurance and content-access controls for online services used by children. The eSafety Commissioner says AI companions that can generate sexually explicit, high-impact violence or self-harm material must verify a user is 18 or older before granting access.

Why it matters: Services with child-facing or mixed-audience products now need working age assurance and content gating, not just policy statements. eSafety also says it will monitor compliance and take enforcement action where there is systemic non-compliance, raising the stakes for weak implementations.

Read source →
medium

eSafety sets AI transparency baseline for public use

eSafety published an AI transparency statement describing its internal approach to AI use, including human oversight, risk assessment, staff training, and periodic review. The agency says it will not use AI in ways inconsistent with legal obligations, public trust responsibilities, or Australian Government policy, and will not let AI make final regulatory decisions without accountable human judgment.

Why it matters: This is a useful benchmark for any regulated organization deploying AI in customer service, moderation, or enforcement workflows. It signals that documented risk review, staff training, and human sign-off are becoming the expected control set for high-stakes AI use.

Read source →
medium

eSafety urges safer recommender design

eSafety updated its position on recommender systems and algorithms, warning that these systems can amplify harm if not designed with safety in mind. The agency says industry should adopt Safety by Design, give users more control over algorithm settings, and improve transparency about how systems are designed and used.

Why it matters: Platforms that rely on ranking or recommendation engines should expect greater scrutiny of user controls and explanation layers. The practical compliance implication is to document safety-by-design decisions and be ready to show how harmful amplification risks are mitigated.

Read source →
medium

eSafety updates generative AI safety stance

eSafety’s generative AI position statement describes key risks and harms and calls for Safety by Design, transparency, and accountability measures for content-generating services. The page says safety controls should be built in across the product lifecycle.

Why it matters: Providers of generative AI tools should treat safety review as an ongoing lifecycle obligation, not a launch checklist item. The signal here is that content generation systems will be expected to show layered safeguards, not just usage warnings.

Read source →
medium

Swiss FDPIC details DPIA and consultation triggers

The FDPIC clarified when Swiss controllers must conduct a data protection impact assessment for processing likely to create a high risk to personality or fundamental rights. The guidance also explains that if residual high risk remains after mitigation, the controller must obtain the FDPIC’s opinion.

Why it matters: Teams using new technologies or high-risk processing in Switzerland need a documented DPIA that describes the processing, evaluates risks, and records mitigations. If residual risk stays high, the process does not end internally, because regulator consultation becomes mandatory.

Read source →

GDPR / Data Protection Enforcement

high

AEPD tightens rules on automated decisions

The AEPD explained the right not to be subject to decisions based solely on automated processing, subject to limited exceptions and safeguards. It says organizations must provide human intervention, allow individuals to express a point of view, and let them challenge the decision where the contract or consent exceptions are used.

Why it matters: Any decisioning workflow that has legal or similarly significant effects needs a clear human-review path and contestability process. The guidance also warns against relying on the exceptions for special-category data unless Article 9(2)(a) or (g) conditions are met and safeguards are in place.

Read source →
low

CNIL keeps AI compliance resources in view

The CNIL’s AI topic page points readers to its AI compliance materials and says it has an action plan for deploying privacy-respecting AI systems. The page is informational rather than a new obligation, but it consolidates the regulator’s AI-focused guidance.

Why it matters: French-facing teams should treat the CNIL page as a routing hub for compliance expectations around AI and privacy. It is a reminder to keep internal AI governance aligned with existing GDPR obligations while monitoring CNIL guidance.

Read source →

US Federal & State Regulation

high

HHS confirms Part 2 compliance deadlines passed

HHS’s HIPAA Part 2 overview states that the 2024 final rule became effective on April 16, 2024 and that compliance was required by February 16, 2026. The page also explains that Part 2 protects substance use disorder patient records and limits disclosure except in narrow circumstances such as written patient consent or a court order and subpoena.

Why it matters: Covered programs should already have updated consent, disclosure, breach reporting, and notice practices for Part 2 records. If these changes are not operationalized yet, the compliance gap is now overdue rather than prospective.

Read source →
medium

HHS maps health apps to applicable laws

HHS OCR released guidance for mobile health app developers explaining that HIPAA, FTC, FDA, and other laws may apply depending on the app’s functions and data handling. The tool walks developers through questions about function, data collected, and services provided, then points them to potentially relevant federal laws.

Why it matters: Health app teams need a jurisdiction-by-jurisdiction and function-by-function legal assessment, not a one-size-fits-all privacy notice. The practical takeaway is to classify the app’s role in the data flow early so the right compliance regime is applied before launch.

Read source →
medium

New Jersey tax case touches cookie-data and support activity

In American Catalog Mailers Association v. Director, Division of Taxation, the New Jersey Tax Court upheld regulations treating certain interactive technical support as in-state business activity for tax purposes. The court declined to rule on the cookie-data provision because the factual record was not clear enough.

Why it matters: While this is a tax case, it may matter to privacy and adtech teams because it shows courts scrutinizing how data-related and support activities are characterized for state-law purposes. Companies relying on remote support or data monetization models should watch for downstream compliance implications, especially where state definitions hinge on operational facts.

Read source →

EU AI Act

low

Dutch regulator links AI oversight to AI Act prep

The AP said its coordination directorate focuses on algorithm and AI risk analysis, cooperation with other supervisors, and guidance to clarify expectations for organizations. The page says this work is being carried out since 2023 and is intended to prepare for new tasks arising from the AI Act.

Why it matters: Organizations operating in the Netherlands should expect more coordinated supervisory attention on AI risks and clearer expectations around algorithm governance. This is a signal to tighten documentation, escalation paths, and cross-functional oversight before enforcement matures.

Read source →

On Our Radar

AI safety-by-design hardening: Australia’s eSafety updates, together with EU supervisory guidance, point to a broader shift toward demonstrable safety controls, not just policy commitments. Expect more pressure for human oversight, transparency, and lifecycle review in AI systems.

Automated decision contestability: The AEPD’s guidance reinforces a growing expectation that automated decisions must be explainable, challengeable, and backed by human review where required. Teams using AI for eligibility, moderation, or risk scoring should check whether contestation workflows are already in place.

High-risk DPIAs under new tech: The FDPIC’s guidance underscores that new technologies can trigger high-risk assessments and, in some cases, regulator consultation. Data teams should review whether their current DPIA triggers capture AI, recommender, and other novel processing activities.

Part 2 operational cleanup: HHS has now marked the Part 2 compliance date as passed, so organizations handling substance use disorder records should be checking that consent, breach reporting, and notice obligations are fully embedded in operations.

Frameworks Covered

Other jurisdictions / frameworksGDPR / Data Protection EnforcementUS Federal & State RegulationEU AI Act

Weekly digest

Leave your email to get each issue in your inbox. Free, no account required.

We use your email only for the digest. Privacy policy