Category: Regulations

AI regulations EU organisations need to follow, including enforcement updates, guidance, and compliance deadlines

Europe’s First Uber Robotaxi Still Has A Safety Operator France excludes OpenAI from cyber work Ten Days To Answer A European Production Order Your Vendor Can Leave You Holding The Provider Obligations UK growth: AI vendors, not AI users Two clouds. One jurisdiction. No regulator paused Astra. OpenAI did. US productivity up 1.4%, cause unproven Moldova’s GDPR law lands on 23 August

Stay ahead of AI change. Get practical updates from Future Prep direct to your inbox.

By subscribing you agree to receive Future Prep news. Unsubscribe any time.

AI generated image - an open letterbox holding a sealed envelope, representing a production order served on an EU addressee

Ten Days To Answer A European Production Order

The e-Evidence Regulation applies from 18 August 2026. A European production order can now compel your cloud or AI vendor to produce prompts, logs and account data within ten days, and your organisation is unlikely to be the addressee or to hear about it first.
AI generated image - a padlocked iron gate standing alone in a field with a worn footpath curving around it, illustrating how an AI agent attack bypasses frontier model controls

The AI Agent Attack Built From Public Parts

Taiwan confirmed AI agent-assisted attacks on government agencies in July. A security vendor separately documented one campaign built from open-source frameworks. No frontier model gate was crossed, which is why vendor safety cases were never going to cover it.
AI generated image - matching inspection huts on both banks of a river, illustrating cloud sovereignty rules

Cloud Sovereignty Rules Now Point Both Ways

Nigeria signed three cloud instruments on 5 August, sorting government data into four levels and pinning the top two inside the country. The architecture mirrors CADA almost exactly. What changes for EU providers when the sovereignty test is pointed at them, and what October 2026 decides.
AI generated image - filing cabinet with two open drawers and two inspection stamps, representing split AI supervision

AI Supervision Started Before the Deadline

Germany's BaFin started supervising AI in banks and insurers on 29 July, two days after the Digital Omnibus softened the AI literacy duty. Fines reach €35 million, the sampling is risk-based, and the supervisor depends on what the system is used for.
AI generated image - a signpost with three arms removed and one still fixed, illustrating the AI Act transparency deadline that did not move.

AI Act Transparency: The Deadline That Did Not Move

The Digital Omnibus delayed the AI Act, so many roadmaps now say 2027. Article 50 was not part of that delay. AI Act transparency duties apply from 2 August 2026, they reach chatbots and synthetic content regardless of risk tier, and most of the work lands on deployers.
AI generated image - a closed playground gate with a blank inspection tag, representing safety by design and restricted access for under-13s

Safety by Design: The EU Flips the Burden of Proof

A special EU expert panel wants to flip the burden of proof for online child safety. Providers would have to show a service is safe by design before children under 13 could use it, and the same design features the Commission just cited against Meta are in scope.
Scroll to Top