<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Datalawgy]]></title><description><![CDATA[Datalawgy provides regular updates of key public policy, regulatory and enforcement matters in the areas of data protection, AI, cybersecurity and digital laws, as well as relevant information on technological and business developments. ]]></description><link>https://datalawgy.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!lD-4!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png</url><title>Datalawgy</title><link>https://datalawgy.substack.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 04 Sep 2026 16:55:25 GMT</lastBuildDate><atom:link href="/__u/datalawgy.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[László Pók]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[datalawgy@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[datalawgy@substack.com]]></itunes:email><itunes:name><![CDATA[László Pók]]></itunes:name></itunes:owner><itunes:author><![CDATA[László Pók]]></itunes:author><googleplay:owner><![CDATA[datalawgy@substack.com]]></googleplay:owner><googleplay:email><![CDATA[datalawgy@substack.com]]></googleplay:email><googleplay:author><![CDATA[László Pók]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview ]]></title><description><![CDATA[Weeks 34-35]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-3bd</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-3bd</guid><pubDate>Tue, 01 Sep 2026 11:03:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5FU6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) Data protection</strong></p><ul><li><p><strong>The Australian Government </strong><a href="https://consultations.ag.gov.au/rights-and-protections/privacy-reform/">has released</a> a <strong>Consultation Paper and Exposure Draft legislation to modernise and strengthen Australia&#8217;s privacy laws</strong> for the digital age.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The measures in the Exposure Draft Bill are designed to better protect Australians while supporting innovation and providing greater certainty for regulated entities.&#8221;</em></p></li></ul></li><li><p><strong>The California Legislature</strong> passed SB 690, a bill that would <strong>narrow the private right of action available under the California Invasion of Privacy Act (CIPA) for certain website-tracking claims.</strong> The bill now awaits Governor Newsom's signature. If signed this year, it becomes effective as of January 1, 2027. (<a href="https://natlawreview.com/article/california-sb-690-what-it-does-and-does-not-mean-pending-cipa-website-tracking">The National Law Review</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In practical terms, the bill eliminates the private cause of action for that specific category of CIPA claim. Private plaintiffs would no longer be able to sue businesses directly under &#167; 638.51 for deploying tracking pixels, analytics tags, or similar technologies on their websites and apps. The enrolled language provides that the amendments `apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.`&#8221;</em></p></li></ul></li></ul><p><strong>2) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong><span>The European Commission </span></strong><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1772"><span>has designated</span></a><span> </span><strong><span>ChatGPT as a Very Large Online Search Engine</span></strong><span> (VLOSE), as well as </span><strong><span>Reddit and Roblox as Very Large Online Platforms </span></strong><span>(VLOPs), under the </span>Digital Services Act (DSA)<span>.</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>Following the notification of the designations, these services have four months, i.e. by January 2027, to comply with the additional </span><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-vlops">DSA obligations for VLOPs and VLOSEs</a><span>, such as assessing and mitigating the systemic risks stemming from their service and algorithmic systems related to the dissemination of illegal content, the negative effects on minors, users' physical and mental well-being, fundamental rights, electoral processes and public security.&#8221;</span></em></p></li></ul></li><li><p><strong>Slovakia&#180;s government approved a bill</strong> proposing <strong>a ban on use of social networks by children &#8203;under 16</strong>. (<a href="https://www.reuters.com/technology/slovak-government-proposes-banning-social-networks-until-age-16-2026-08-26/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The law, if approved by parliament, will ban setting up social network accounts for younger children and require &#8203;proving the user's age, according to documents posted on &#8203;the government's website.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p>According to <a href="https://www.euractiv.com/news/exclusive-eu-orders-leading-ai-labs-to-detail-security-practices/">Euractive</a>, <em>&#8220;<strong><span>the European Commission made first use of new AI enforcement powers this week</span></strong><span>, Tech Commissioner Henna Virkkunen told </span>Euractiv<span>, </span><strong><span>ordering information from leading developers on cybersecurity, safety and copyright compliance.</span></strong><span>&#8221;</span></em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Virkkunen said the EU wanted to ensure the labs in question had put in place good cybersecurity and physical infrastructure protections for their models. [&#8230;] The Commission is also concerned with how much access developers are providing to external model evaluators, per Virkkunen, and how any outside safety recommendations are followed up, as well as how labs monitor model usage once an AI is publicly available.&#8221;</em></p></li></ul></li><li><p><strong>The Federal Trade Commission (FTC)</strong> <strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-finalizes-orders-cox-media-group-two-other-firms-settling-charges-they-deceived-customers-about?utm_source=govdelivery&amp;">finalized</a> orders requiring Cox Media Group (CMG) and two other firms to pay a total of $930,000 </strong>to settle allegations they <strong>deceived customers by falsely claiming to offer an AI-powered service that could target localized ads based on conversations captured from consumers&#8217; smart devices </strong>and that consumers had opted into such targeting.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Contrary to these companies&#8217; claims, however, the marketing service wasn&#8217;t based on voice data, and consumers hadn&#8217;t opted into this service. If the service had functioned as advertised, this collection and use of consumers&#8217; voice data without adequate consent would itself violate the FTC Act.&#8221;</em></p></li></ul></li><li><p><strong><span>Hellenic DPA</span></strong><span> </span><a href="https://www.dpa.gr/en/enimerwtiko/press-releases/hellenic-dpa-takes-leading-role-implementing-eu-ai-act-greece"><span>takes</span></a><span> a</span><strong><span> leading role in implementing the EU AI Act in Greece.</span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Law <a href="https://ia37rg02wpsa01.blob.core.windows.net/fek/01/2026/20260100114.pdf">5321/2026</a> (&#8216;Measures for the implementation of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Regulation on Artificial Intelligence) designated the Hellenic DPA, inter alia:</em></p><ul><li><p><em>as the competent market surveillance authority for Artificial Intelligence systems falling under the prohibited practices of the Regulation, for high-risk systems of Annex III and for systems subject to the transparency obligations of Article 50 of the Regulation,</em></p></li><li><p><em>as the single point of contact for Greece with the European Commission and the respective national authorities;</em></p></li><li><p><em>as the competent authority for receiving and handling complaints concerning infringements of the Regulation,</em></p></li><li><p><em>as a notified body for the conformity assessment of specific high-risk AI systems, and, </em></p></li><li><p><em>together with EETT (&#919;ellenic Telecommunications and Post Commission), as the competent authority for the operation of the national AI regulatory sandbox.&#8221;</em></p></li></ul></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Dutch DPA </strong>(AP) <a href="https://autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blocking">imposed</a> <strong>a fine of EUR 825 million on Uber</strong>. The reason for this is that the AP has ruled that <strong>Uber made fully automated decisions about drivers</strong>. In case of suspicions of fraud or customer reviews that were too low, drivers' accounts were automatically temporarily deactivated or, in case of persistent low customer reviews, permanently deactivated. As a result, their income was lost via Uber during the deactivation.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;According to AP, <span>Uber has violated the prohibition of fully </span><a href="https://autoriteitpersoonsgegevens.nl/en/themes/algorithms-ai/algorithms-explained/automated-decision#rules-regarding-automated-decisions-for-companies">automated decision-making</a><span> under the General Data Protection Regulation (GDPR). The AP also found that Uber did not sufficiently </span><a href="https://autoriteitpersoonsgegevens.nl/en/themes/algorithms-ai/algorithms-explained/automated-decision#providing-information-about-automated-decisions">inform drivers about automatic decision-making</a><span>.&#8221;</span></em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong><span>Meta </span></strong><em><span>&#8220;</span><strong><span>settled </span></strong><span>[&#8230;] </span><strong><span>a trial brought by a </span><a href="https://www.cnbc.com/2026/08/17/meta-attorneys-general-california-federal-trial-astronomical-consequences.html">coalition of tens of U.S. states</a><span> alleging that the tech giant had misled the public about the harms its platforms posed to younger users</span></strong><span>.</span></em><span>&#8221; (</span><a href="https://www.cnbc.com/2026/08/29/meta-settlement-tiktok-youtube-snap-teen-safety.html"><span>CNBC</span></a><span>)</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The agreement includes a</span><a href="https://investor.atmeta.com/investor-news/press-release-details/2026/Metas-Agreement-With-Bipartisan-Attorneys-General-Calling-on-TikTok-and-YouTube-to-Join-Us-in-Supporting-Teens/default.aspx"> payment of up to $18 billion</a><span>, part of which is tied to conditional action by other social media giants. Meta said it would also make fundamental changes to its platforms for users under the age of 18, including but not limited to a 2-hour daily usage limit that only a parent can lift, disabling extreme makeup and cosmetic surgery filters, tighter age verification measures, and night mode.&#8221;</span></em></p></li><li><p><strong>TechPolicy</strong> <a href="https://www.techpolicy.press/what-metas-us-settlement-on-child-safety-means-for-europe/">published</a> an analysis about <strong>the potential impacts of this settlemnent</strong> <strong>on child safety for Europe.</strong></p><ul><li><p>According to Julia Smakman of the Ada Lovelace Institute, as quoted in the analysis, <em>&#8220;<span>[&#8230;] the agreement could give European regulators a useful baseline, as long as European regulators</span> <span>are not afraid to also take more stringent measures or extend protections beyond children to all users.&#8221;</span></em></p></li></ul></li><li><p><strong>South Korea&#180;s media regulator </strong>said that &#8220;<em>measures proposed by Meta to curb potentially addictive features for young users <strong>should ideally be applied worldwide [&#8230;]</strong>.</em>&#8221; (<a href="https://www.reuters.com/business/media-telecom/south-korea-media-commission-says-metas-youth-protection-changes-should-apply-2026-08-27/">Reuters</a>)</p><ul><li><p><em>&#8220;The Korea Media and &#8203;Communications Commission (KMCC) said in a statement to Reuters that social media companies needed to take greater responsibility for &#8203;protecting children and teenagers and pointed to seven bills pending in the country's parliament aimed &#8288;at strengthening youth protections online.&#8221;</em></p></li></ul></li></ul></li><li><p><strong><span>Brazil&#8217;s government</span></strong><span> filed </span><strong><span>a lawsuit in a federal court against Discord</span></strong><span>, &#8220;</span><em><span>seeking damages of 500 million reais (about $97 million) for the company&#8217;s alleged failure to protect children online.</span></em><span>&#8221; (</span><a href="https://apnews.com/article/brazil-discord-lawsuit-protection-children-b19fee2968c48bb871aff00bdec60d1d"><span>AP</span></a><span>)</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Solicitor-General&#8217;s office for President Luiz In&#225;cio Lula da Silva said in a statement the damages it is seeking from Discord are due to alleged collective psychological harm it has allowed. [&#8230;] The office is also asking the court to order Discord to immediately strengthen parental controls, expand cooperation with local law enforcement, and deploy automated tools to detect and remove dangerous content.&#8221;</em></p></li><li><p><strong>The Brazilian DPA (ANPD)</strong> previously <strong><a href="https://www.gov.br/anpd/pt-br/assuntos/noticias/em-medida-preventiva-anpd-determina-que-discord-suspenda-transmissoes-ao-vivo-no-brasil">orderd</a> Discord to suspend live broadcasts in Brazil</strong>. </p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p>A <a href="https://jamanetwork.com/journals/jamapediatrics/fullarticle/2849307">new study</a> shows that <em>&#8220;<strong>nearly 1 in 5 young Americans now turn to AI when they need mental health advice. More than 90 percent of them say the responses are helpful.&#8221; </strong></em>(<a href="https://www.zmescience.com/science/psychology-science/mental-health-advice-ai-young-people/">ZME Science</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This matters in a US mental health setting where four in 10 teenagers who experienced a major depressive episode in the previous year reported not receiving mental health services. [&#8230;] Young people have also long used the internet to find mental health information because it is accessible, anonymous, and basically free. Chatbots take that one step further by turning a search into a conversation tailored to the user&#8217;s words. [&#8230;] Young people have also long used the internet to find mental health information because it is accessible, anonymous, and basically free. Chatbots take that one step further by turning a search into a conversation tailored to the user&#8217;s words. [&#8230;] [&#8230;] among those who used AI for mental health advice, 63.3 percent had not told anyone about it. [&#8230;] According to researchers, this lack of disclosure can also create a blind spot. If a chatbot gives poor or misleading advice, parents and health professionals may never know that the conversation happened.&#8221;</em></p></li><li><p><a href="https://www.washingtonpost.com/technology/2026/08/27/chatgpt-chats-are-being-swept-into-civil-criminal-court-cases/">As reported in The Washington Post</a><span>, court records also show that </span><em><span>&#8220;chatbot exchanges are increasingly being introduced as evidence </span>in civil lawsuits and criminal investigations<span>, exposing deeply personal information that users may have never expected to become public [&#8230;].&#8221;</span></em><span> (</span><a href="https://www.cleveland.com/news/2026/08/a-teenager-asked-chatgpt-for-advice-then-his-messages-became-public.html"><span>Cleveland.com</span></a><span>)</span></p></li></ul></li><li><p><strong>Anthropic</strong> <a href="https://www.anthropic.com/research/enabling-independent-research">shared</a> high-level results from the studies that were prepared as part of Anthropic&#180;s pilot project, <strong>giving external researchers access to aggregate, real-world Claude usage data</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>Anthropic<strong> </strong>&#8220;<span>partnered with three research groups: the </span><a href="https://cs.stanford.edu/~diyiy/group.html">Social and Language Technologies (SALT) Lab</a><span> at Stanford University, the </span><a href="https://humaninformationprocessing.com/">Human Information Processing Lab</a><span> at the University of Oxford, and </span><a href="https://metr.org/">METR</a><span>, a non-profit organization that evaluates frontier AI models. Each group developed its own research questions and used Anthropic Insights to conduct privacy-preserving analysis of roughly 250,000 Claude.ai or Claude Code conversations from April-May 2026.&#8221;</span></em></p></li><li><p><em>&#8220;Understanding AI&#8217;s effects on society is too big a job for AI companies alone. Real oversight needs external researchers asking their own questions of real-world usage data and publishing what they find independently. [&#8230;] Our partners pursued research we would not have thought to design ourselves, and each told us something new about AI&#8217;s real-world impacts. [&#8230;]&#8221; </em></p></li></ul></li><li><p><strong>The Dutch DPA (AP)</strong> <a href="https://autoriteitpersoonsgegevens.nl/actueel/de-fria-voor-ai-systemen-komt-eraan-bereid-u-voor">issued</a> <strong>guidance detailing the EU AI Act&#180;s fundamental rights impact assessment (FRIA) obligations</strong> for high-risk AI systems.<em> (The document is in Dutch.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The explanation of the FRIA is the first document in a series on AI and fundamental rights with which the DPA prepares organizations for their obligations under the AI Act.&#8221; </em>The DPA also starts a pilot program to help organizations gaining practical experience with the European FRIA reporting template. Organizations will also receive feedback on their FRIA approach. The form of the feedback will not be an audit, inspection or enforcement process at the organizations that taking part in the pilot but the DPA will use the experiences of the pilot participants to improve information about the FRIA, the template and the future supervisory approach.</p></li></ul></li><li><p><span>The </span><strong><span>International Telecommunication Union </span></strong><a href="https://www.itu.int/epublications/publication/autonomous-cities-and-ai-the-next-frontier-of-urban-transformation"><span>published</span></a><span> a </span><strong><span>guide presenting a structured and comprehensive framework for understanding, assessing and progressively advancing autonomous cities. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;A central proposition of the guide is that cities are systems of systems. Urban life depends on the interaction of multiple infrastructures, services, institutions and communities. Changes in one system can produce ripple effects across others. [&#8230;] The guide introduces a high-level model of autonomous systems built around five core components: sensors; sensing, perception and environment modelling; decision-making and action planning; actuators; and a learning module. This model provides a common language for assessing autonomy across diverse urban domains. [&#8230;] The guide also provides a practical four-step methodology: baseline the current extent of autonomy; determine the target autonomous state; implement actions to close identified gaps; and evaluate outcomes. This methodology is intentionally iterative.&#8221;</em></p></li><li><p><em>&#8220;The key conclusion is that autonomous cities should not be pursued as a single end-state or as a purely technical ambition. They should be treated as a governed transition towards more adaptive, responsive and sustainable urban systems. The responsible deployment of autonomous systems requires clear objectives, proportionate risk management, staged implementation, human-centred design, rigorous testing and continuous oversight. When applied carefully, autonomous systems can support better resource allocation, faster response to disruptions, improved service quality and more evidence-based urban governance.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!jTn5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 424w, /__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 848w, /__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 1272w, /__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!jTn5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png" width="1074" height="377" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:377,&quot;width&quot;:1074,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66733,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/210577155?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 424w, /__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 848w, /__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 1272w, /__u/substackcdn.com/image/fetch/$s_!jTn5!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7ea7e2b-e3bb-43aa-b99d-d566fcee6a84_1074x377.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: ITU, <a href="https://www.itu.int/epublications/publication/autonomous-cities-and-ai-the-next-frontier-of-urban-transformation">Autonomous cities and AI: The next frontier of urban transformation</a>, p. ix</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-3bd?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-3bd?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-3bd?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The French DPA (CNIL) </strong><a href="https://www.cnil.fr/fr/ia-la-cnil-met-jour-son-outil-de-tracabilite-des-modeles-publies-en-source-ouverte">published</a> <strong>a new version of its demonstrator to explore the genealogy of AI models published in open source. </strong>This update improves the performance of the tool, its ergonomics and automates the updating of data. An English version is now available. <em>(More info about Genmod at <a href="https://huggingface.co/spaces/cnil/genmod">HuggingFace</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;AI models published in open source can be downloaded, modified, specialized with new data or combined with other models, before being made available again. A single model (e.g. Kimi K3, Mistral Medium, LLaMa etc.) can thus be the source of many derived models. The Genmod demonstrator developed by the CNIL&#8217;s AI department in collaboration with the CNIL&#8217;s Digital Innovation Laboratory (LINC), initially published in November 2025, makes it possible to explore these links and to find the ancestors of a model (the models from which it comes) as well as its descendants (the models to which it has contributed). This traceability is particularly useful for studying the consequences of the memorization of training data by AI models. The aim is to identify, from a model that has memorized personal data, the other models in its &#8220;genealogy&#8221; that are likely to have also retained this information. In particular, this makes it possible to study the conditions for exercising the rights provided for by the GDPR.&#8221;</em></p></li></ul></li><li><p><strong>BRUEGEL</strong> <a href="https://www.bruegel.org/working-paper/why-eu-right-consent-personal-data-processing-doesnt-work">published</a> a working paper, titled<em> &#8220;<strong><span>Why the EU right to consent to personal data processing doesn&#8217;t work&#8221; </span></strong><span>(author: Bertin Martens)</span></em><span>. </span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This paper argues that consent banners for the collection of personal data under the European Union&#8217;s General Data Protection Regulation (GDPR) are, in practice, a legal and technical fiction. While the GDPR requires consent to be freely given, specific, informed and unambiguous, it prescribes no technical standards for consent tools. Publishers and advertisers design their own tools. They often exploit pervasive consent fatigue and use &#8216;dark patterns&#8217; to nudge data subjects towards acceptance of personal data sharing. Few consent tools are fully GDPR-compliant.&#8221;</em></p></li></ul></li><li><p><strong>The Swedish DPA (IMY)</strong> <a href="https://www.imy.se/nyheter/imy-lanserar-trygghetsapp-for-unga-pa-sociala-medier/">launched</a> <strong>FantomApp in Sweden, an app that helps young people protect their personal data in social media.</strong> <em>(FantomApp was developed by the French DPA in collaboration with young people in France. IMY has now translated and adapted the app to Swedish conditions.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The app can, among other things, help with social media security settings, testing passwords and blurring photos.&#8221;</em></p></li></ul></li><li><p><strong>New Zealand&#180;s Privacy Commissioner</strong> <a href="https://www.privacy.org.nz/tuhono-connect/statements-media-releases/privacy-commissioner-sets-expectations-about-smart-glasses/">issued</a> <strong>guidance on the appropriete use of smart glasses. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>The Commissioner emphasized that by using smart glasses, &#8220;it&#8217;s very easy for people to be filmed covertly, which makes it harder for people being filmed to object to it.&#8221; He added that the concerns regargin the use of smart glasses would increase &#8220;if, in future, smart glasses are integrated with facial recognition technology.&#8221; </em></p></li><li><p>There are also intense debates about the use of smart glasses, e.g. in <a href="https://www.noerr.com/de/insights/private-videoaufnahmen-mittels-wearables-im-offentlichen-raum">Germany</a> and in <a href="https://www.euronews.com/next/2026/08/25/norway-moves-to-tighten-rules-on-use-of-smart-glasses">Norway</a>. <em>(A <a href="https://compliancehirek.hu/figyelo/leskelodo-okosszemuvegek-kibontakozo-vita-nemetorszagban/">brief overview</a> about the debate in Germany is avalable <a href="https://compliancehirek.hu/figyelo/leskelodo-okosszemuvegek-kibontakozo-vita-nemetorszagban/">here</a> in Hungarian.)</em></p></li><li><p>The Spanish DPA (AEPD) <a href="https://www.aepd.es/prensa-y-comunicacion/blog/buenas-practicas-si-vas-a-usar-gafas-de-sol-inteligentes-este-verano">has also published</a> guidance on the proper use of smart glasses. <em>(The document is in Spanish.)</em></p></li></ul></li><li><p><strong>The Office of the Privacy Commissioner for Personal Data (PCPD) of Hong Kong </strong><a href="https://www.pcpd.org.hk//english/resources_centre/publications/files/pcpd_use_of_agentic_ai.pdf">has published</a> a guidance, titled <em><strong>&#8220;Protecting Personal Data Privacy in the Use of Agentic AI&#8221;</strong></em>.</p><ul><li><p><em><strong>Why does this matter? </strong>The guidance &#8220;aims to provide practical recommendations to organisations on the safe and responsible use of agentic AI to assist them in harnessing the benefits of agentic AI while safeguarding personal data privacy and complying with the relevant requirements of the Personal Data (Privacy) Ordinance (PDPO).&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>&#8220;</strong><em><strong>When more than 1,200 artificial intelligence (AI) agents within OpenAI started unexpectedly communicating</strong>, it led to a large group banding together in order to hack into Hugging Face.</em>&#8221; (<a href="https://www.bbc.com/news/articles/cj9xj89dk40o">BBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] total of 1,206 AI agents that were meant to be kept isolated from one another began communicating. They did so by sending more than 70,000 messages on an &#8220;unsanctioned message board.&#8221; Those messages ended up seeing more than 700 agents take part in a collective effort to attack Hugging Face. [&#8230;] As for why the agents began communicating in the first place when they were not supposed to, METR found that the communicating agents had &#8220;unintentionally been given an impossible task.&#8221; [&#8230;] an impossible task is one where an AI tool is required to &#8220;exploit&#8221; its target in order to resolve its command. It led the agents to find ways to cheat, including getting messages to one another and accessing the outside internet, which then led to broader conversations between hundreds of agents looking for ways to cheat that would benefit all of the agents.&#8221;</em></p></li></ul></li><li><p>In a blog post, <strong>the U.S. National Institute of Standards and Technology (NIST)</strong> <a href="https://www.nist.gov/blogs/cybersecurity-insights/back-future-why-agentic-ai-needs-strong-identity-foundation">discussed</a><strong> some of the current identity and authorization practices that present substantial security challenges for agentic AI systems</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Perhaps one of the most important actions any organization can take when preparing for the agentic future is to do a clear-eyed evaluation of its current IAM practices, systems, and capabilities against current standards and best practices. Issues, challenges, and gaps in current capabilities will only be exacerbated by agentic scale deployed across enterprises. The established IAM standards and best practices of today are the foundation upon which we will build the secure and scalable agentic protocols of the future.&#8221;</em></p></li></ul></li><li><p><strong>More than 100 technology companies</strong>, including OpenAI, Anthropic and Microsoft,<strong> signed a letter urging policymakers</strong>, and entities to &#8220;act decisively&#8221; <strong>to bolster cyber defenses in the age of AI. </strong>(<a href="https://www.cnbc.com/2026/08/27/ai-cyber-defense-letter.html">CNBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The group of 116 entities urged every organization to &#8220;raise the security bar&#8221; on defense tools, upgrade security systems and utilize a mix of low-cost and frontier models. The letter also called for a coordinated government effort to fund cyber defense and improve accessibility for under-resourced critical infrastructure like hospitals and water treatment plants, which have been major attack targets.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>The European Law Institute (ELI) </strong><a href="https://www.europeanlawinstitute.eu/fileadmin/user_upload/p_eli/Publications/ELI_Model_Rules_on_Succession_and_Access_to_Digital_Remains.pdf">published</a> <em><strong>&#8220;Model Rules on Succession and Access to Digital Remains&#8221;</strong></em>, as part of its <a href="https://www.europeanlawinstitute.eu/projects-instruments/instruments/eli-model-rules-on-succession-and-access-to-digital-remains/">dedicated project</a> on developing such model rules.   </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;These Model Rules set out a framework for succession to digital assets and access to personal digital remains after death. They address the growing practical and legal difficulties that arise when a person dies leaving online accounts, digital assets, cloud-stored materials, personal data, communications, and digital or AI generated representations. The Model Rules aim to provide legal certainty while respecting the privacy and dignity of the deceased, the rights and interests of heirs and other beneficiaries, the rights of living third parties, and the obligations of service providers. [&#8230;] The Model Rules are built around the concept of &#8216;digital remains&#8217;. This umbrella concept includes both digital assets and personal digital remains. [&#8230;] A central feature of the Model Rules is the distinction between succession and access. [&#8230;] Overall, the Model Rules offer a structured and practical framework for post-mortem digital governance. They preserve succession to transferable digital assets, establish a distinct access regime for personality-linked digital remains, protect the deceased&#8217;s autonomy and dignity, safeguard third party rights, and impose workable obligations on service providers and others who control digital remains. Their purpose is to support coherent national and European approaches to digital succession and access, while avoiding reducing all digital remains to either property or personal data.&#8221;</em></p></li></ul></li><li><p><strong>The European Parliamentary Research Service (EPRS)</strong> <a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)791455">published</a> a briefing about the <strong><span>rights to internet access in the EU. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Reflecting the increasing importance of digital technologies for participation in all aspects of modern life, access to the internet has become essential for work, education, public services and democratic engagement. [&#8230;] If a right to internet access is recognised, its implications will depend on both its legal basis and how it is formulated. While a purely negative right of access would require the state to refrain from interfering with people's existing access, a positive right would oblige states to take active measures to ensure connectivity, for instance, by investing in infrastructure or providing financial support to ensure affordability. An investigation of the existing legal framework reveals that although restrictions on internet access have been found to violate the right to freedom of expression, in particular, a binding stand-alone right to internet access has not been recognised in international or European human rights law, nor derived from the Charter of the Fundamental Rights of the European Union. At secondary law level, the universal service obligations under the European Electronic Communications Code do not establish entitlements which can be claimed by individuals. However, in some EU Member States, internet access benefits from explicit constitutional or statutory protection. Several policy options have emerged regarding a novel right to internet access, ranging from a limited right to use the internet without arbitrary restriction to a broader right to 'meaningful' connectivity. However, it is increasingly argued that it should include a positive and a negative dimension. The quality of connection required to fulfil such a right and the extent of states' obligations will depend on how the right is formulated and interpreted by courts and may be regulated through secondary legislation, rather than as part of the right itself.&#8221;</em></p><p></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-3bd?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-3bd?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Nvidia </strong>agrees <strong>to buy Hugging Face for $12.9 billion</strong>. (<a href="https://www.cnbc.com/2026/08/27/nvidia-hugging-face-acquisition.html">CNBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;If completed, the acquisition would put one of the most widely used platforms for sharing and working with open-source AI models under Nvidia&#8217;s ownership, expanding the chipmaker&#8217;s reach further into the software and model ecosystem.&#8221;</em></p></li></ul></li><li><p>At the second annual<strong> World Humanoid Robot Games</strong> in Beijing, robots&#8217; physical capabilities were put to the test. (<a href="https://www.nature.com/articles/d41586-026-02713-z">Nature</a>)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!5FU6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 424w, /__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 848w, /__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 1272w, /__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!5FU6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png" width="822" height="549" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:549,&quot;width&quot;:822,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:717046,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/210577155?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 424w, /__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 848w, /__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 1272w, /__u/substackcdn.com/image/fetch/$s_!5FU6!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87821503-1cd3-4d8b-b7a0-3017735d08f8_822x549.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://www.nature.com/articles/d41586-026-02713-z">Nature</a>, credit: Lintao Zhang/Getty</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The games highlighted how fast humanoid robots &#8212; </span><a href="https://www.nature.com/articles/d41586-024-01442-5">which use artificial intelligence to learn, plan and execute real-world actions</a><span> &#8212; are advancing. But they also demonstrated that the machines have a long way to go before they&#8217;ll be used by humans for practical tasks.&#8221;</span></em></p></li><li><p><em>&#8220;During the games, a robot from company X-Humanoid in Beijing took home a gold medal in the 100-metre sprint with a time of 8.64 seconds &#8212; almost one second faster than Olympian Usain Bolt&#8217;s record-breaking race in 2009. The same robot won the 100-metre sprint last year in 21.5 seconds, showing how quickly the technology is advancing.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview ]]></title><description><![CDATA[Week 33]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-398</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-398</guid><pubDate>Tue, 18 Aug 2026 08:00:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-amY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Colorado attorney general&#180;s office</strong> <a href="https://coag.gov/ai/">published</a> <strong>draft regulations to help guide implementation of Colorado&#180;s Automated Decision-Making Technology Act (ADMT Act) and the Chatbot Safety Act</strong>, which take effect January 1, 2027.</p><ul><li><p><em><strong>Why does this matter? </strong></em>The ADMT Act <em>&#8220;defines an &#8216;automated decision-making technology&#8217; (ADMT) and creates certain requirements for both developers of ADMT that is used to materially influence a consequential decision and deployers who use ADMT. It also gives consumers the right to request and correct inaccurate personal data used by ADMT.&#8221;</em></p></li><li><p>The Chatbot Safety Act adds<em> &#8220;protections for users of conversational AI services, including requirements for chatbot operators to estimate the age of users, disclose that users are interacting with AI and not humans, safeguard teen users against sexually explicit content and simulated emotional dependence, and implement privacy/account-management tools for minor users. The Chatbot Safety Act also requires chatbot operators to create suicide and self-harm response protocols and prohibits chatbot outputs from being represented as equivalent to licensed professional services.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p>The <span>New Jersey Governor </span><a href="https://staussfirm.com/2026/08/11/new-jersey-enacts-kids-privacy-law-with-private-right-of-action/"><span>signed</span></a><span> the </span><strong><span>New Jersey Kids Code Act</span></strong><span>, which adopts </span><strong><span>the New Jersey Age-Appropriate Design Code</span></strong><span>, into law. The law takes effect on September 1, 2027.</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The new law creates strict design and privacy requirements for online services likely to be accessed by minors, plus a private right of action with $5,000 in statutory damages per violation.&#8221;</em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p>The Constitutional Court of <span>France </span><strong><a href="https://www.conseil-constitutionnel.fr/decision/2026/2026911DC.htm">shot down</a></strong><span> </span><strong><a href="https://pro.politico.eu/bills/753136/overview">a bill</a></strong><span> </span><strong><span>seeking to ban access to social media for under-15s</span></strong><span> from September. (</span><a href="https://www.politico.eu/article/french-constitutional-court-shoots-down-social-media-ban-for-minors/"><span>Politico</span></a><span>)</span></p><ul><li><p><em><strong>Why does this matter? </strong></em>The Court<em> &#8220;said the restrictions in the bill disproportionately infringe on minors&#8217; right to freedom of expression and communication.&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] the French presidential office said the government would not be giving up on the bill. It has set a new target date for spring 2027, which coincides with when Macron will leave office.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>German advocacy group, HateAid, lodges criminal complaint over Meta AI glasses. </strong>(<a href="https://www.reuters.com/legal/government/german-advocacy-group-lodges-criminal-complaint-over-meta-ai-glasses-2026-08-12/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;HateAid said its complaint was based on a federal digital data protection law that prohibits the sale of communication devices designed &#8203;to film people without them noticing.&#8221;</em></p></li></ul></li><li><p>C<strong>omplaint under Article 85 of the AI Act <a href="https://digital-strategy.ec.europa.eu/en/policies/ai-act-complaints-tool">can be submitted</a> via <span>AI Act complaints tool. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The AI Act Complaint Tool allows individuals and organisations to submit complaints to the AI Office concerning alleged infringements of the AI Act by providers or deployers of AI systems.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Italian Data Protection Authority (Garante) <a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10272529">fined</a> Piaggio &amp; C. Spa EUR 460,000 for violations of privacy regulations relating to the management of company email accounts, data retention, and employee monitoring activities. </strong><em>(More information in English is available <a href="https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_%28Italy%29_-_476%2F2026">here</a> at NOYB&#180;s GDPRhub.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the DPA held that both an individualised corporate email address and the correspondence associated with it constituted personal data relating to the employee. According to the DPA, a request to deactivate such an account therefore amounted to a request to cease the related processing, [&#8230;]. [&#8230;] The DPA found that the controller therefore infringed <a href="https://gdprhub.eu/index.php?title=Article_12_GDPR">Article 12(3) GDPR</a> in conjunction with <a href="https://gdprhub.eu/index.php?title=Article_17_GDPR">Article 17 GDPR</a>.&#8221;</em></p></li><li><p><em>&#8220;With regard to the internal investigation, the DPA [&#8230;] held that the investigation was therefore retrospective and relied on data that had already been systematically collected and retained before any specific suspicion arose. It noted that the use of keywords, filters and a balancing assessment did not remedy this. In addition, the DPA held that the controller&#8217;s stated purposes were formulated too generally to justify retaining the complete correspondence of all employees throughout their employment and for an additional five years. The DPA concluded that no appropriate legal basis under Article 6 GDPR applied because the controller had not demonstrated that its extensive retention was necessary for a specific and predetermined purpose. It further found that the controller infringed the principles of purpose limitation under Article 5(1)(b) GDPR, data minimisation under Article 5(1)(c) GDPR and storage limitation under Article 5(1)(e) GDPR.</em></p></li><li><p><em>The DPA [&#8230;] held that both the content of emails and their metadata concerned correspondence protected by the right to privacy and secrecy of communications. [&#8230;] The DPA distinguished between the email service itself, which may constitute a tool used by employees to perform their work, and the separate systems used to systematically collect, retain and process email content and metadata. These systems operate independently of the employee&#8217;s ordinary use of email and may enable the employer to reconstruct the employee&#8217;s activities. [&#8230;] The DPA concluded that the systematic retention and subsequent use of the data enabled the controller to reconstruct and monitor employees&#8217; activities. It further found that this monitoring had been carried out without the safeguards required under Italian labour law. It ruled that the controller infringed Article 5(1)(a) GDPR and Article 88 GDPR, together with Article 114 of the Italian Data Protection Code.</em></p></li><li><p><em>The DPA also held that the controller&#8217;s policy was unlawful insofar as it allowed a former employee&#8217;s email address to remain active for up to 30 days, even with their consent, and permitted incoming messages or mailbox contents to be forwarded or transferred to another employee on the basis of broadly defined service needs.</em></p></li><li><p><em>Finally, the DPA held that the controller had not demonstrated how and when the two data subjects had been informed about the processing. [&#8230;] It held that the controller therefore infringed the transparency principle under Article 5(1)(a) GDPR and its information obligations under Article 13 GDPR.&#8221;</em></p></li></ul></li><li><p>According to <a href="https://www.independent.ie/business/data-watchdog-plans-to-fine-dating-firm-tinder-between-8m-and-11m/a/159747211.html">news reports</a>, &#8220;<em><strong>Ireland&#8217;s Data Protection Commissioner (DPC) plans to fine</strong> the US company behind the popular <strong>Tinder dating app between &#8364;8m and &#8364;11m for alleged compliance breaches</strong> of the EU&#8217;s data protection regulations.</em>&#8221; (<a href="https://www.independent.ie/business/data-watchdog-plans-to-fine-dating-firm-tinder-between-8m-and-11m/a/159747211.html">Irish Independent</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The DPC previously noted that it would set out to establish whether Tinder has a legal basis for the ongoing processing of its users&#8217; personal data and whether it meets its obligations as a data controller with regard to transparency and its compliance with data subject rights requests.&#8221;</em></p></li><li><p>The company (Match Group) said that <em>&#8220;We believe we have strong defences to these claims and will defend vigorously against them.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The Brazilian National Data Protection Agency (ANPD)</strong> <a href="https://www.gov.br/anpd/pt-br/assuntos/noticias/em-medida-preventiva-anpd-determina-que-discord-suspenda-transmissoes-ao-vivo-no-brasil">issued</a> <strong>a preventive measure determining that the Discord platform suspend the live streaming functionality in Brazil</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The action is part of the inspection process initiated [&#8230;] to investigate failures in the protection of children and adolescents in the digital environment, [&#8230;]. The precautionary measure to suspend the functionality of lives was determined [&#8230;] due to robust evidence that the company has not adopted reasonable measures to prevent and mitigate risks of access, exposure, recommendation, or facilitation of contact with content or practices that represent serious violations of the rights of children and adolescents within the scope of its service,  especially inducement, incitement, instigation or assistance to violence, self-mutilation and suicide, according to the Digital Statute of the Child and Adolescent [&#8230;].&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Australian Government</strong> <a href="https://www.industry.gov.au/news/report-explores-risks-and-controls-artificial-intelligence-ai-agents">has commissioned</a> <strong>a report to better understand emerging AI agent risks in Australia.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This report offers a framework to help organisations, policymakers and researchers understand and manage the risks when AI agents interact across organisations.&#8221;"</em></p></li><li><p><em>&#8220;The report builds its analytical framework around 3 tiers of agent governance:</em></p><ul><li><p><em>singular governance</em></p></li><li><p><em>federated governance</em></p></li><li><p><em>open environments.&#8221;</em></p></li></ul></li><li><p><em>&#8220;The overarching message is that the controls available, and who can action them, depend on the deployment tier.&#8221;</em></p></li><li><p><em>&#8220;<strong>For deploying organisations,</strong> the framework is a triage and decision instrument: identify the tier an existing or proposed system operates at, the controls applicable to that tier's risks, decide whether to deploy and if so which controls to apply, govern continuously, and recognise where unilateral reach ends.&#8221; </em></p></li><li><p><em>&#8220;<strong>For policymakers</strong>, the report offers a map: for each risk it identifies who can act, and for the risks that fall to no existing actor it characterises the gap.&#8221;</em></p></li><li><p><em>&#8220;<strong>For researchers and Standards bodies</strong>, it surfaces methodological and infrastructural gaps on which controls depend, from multi-agent evaluation to agent identity standards.&#8221;</em></p></li></ul></li><li><p><strong>The European Commission</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/study-cloud-and-ai-development-eu">requested and published</a> a study to gather empirical evidence to <strong>assess the EU&#8217;s current and future requirements for cloud and AI infrastructure</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The study provides a comprehensive overview of:</em></p><ul><li><p><em>Cross-border barriers to the provision of cloud services</em></p></li><li><p><em>lock-in practices within the AI computing stack</em></p></li><li><p><em>risks arising from third-country laws with extraterritorial effects</em></p></li><li><p><em>permitting procedures for data centres</em></p></li><li><p><em>financial and fiscal incentives</em></p></li><li><p><em>constraints related to energy grids and other critical resources such as water</em></p></li><li><p><em>initiatives to improve access to capital for data centre expansion</em></p></li><li><p><em>public-sector efforts to promote the adoption of open source solutions</em></p></li></ul><p><em>In addition, the study identifies the main challenges in the EU cloud and AI ecosystem:</em></p><ul><li><p><em>the limited and geographically concentrated availability of computing capacity within the EU</em></p></li><li><p><em>the EU&#8217;s dependence on cloud and AI computing services provided by non-European suppliers.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The Brazilian Data Protection Authority (ANPD) </strong><a href="https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-releases-english-version">released</a> the <a href="https://www.gov.br/anpd/pt-br/centrais-de-conteudo/documentos-tecnicos-orientativos/radar-tecnologico-inteligencia-artificial-generativa-versao-em-lingua-inglesa.pdf/@@display-file/file">English version</a> of <strong>Technology Radar on Generative AI. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the study aims to provide a comprehensive analysis of the topic, identifying potential privacy and data protection risks while assessing these scenarios against Brazilian Data Protection Law (LGPD).&#8221;</em></p></li><li><p><em>&#8220;The report examines the advances in generative AI and its impacts, with particular attention to personal data protection in Brazil. It also analyzes the underlying principles of the technology exploring aspects such as:</em></p><ul><li><p><em>Web scraping, a practice that may involve the processing of personal data;</em></p></li></ul><ul><li><p><em>Generation of synthetic content that may be indistinguishable from personal data;</em></p></li></ul><ul><li><p><em>The relationship between personal data processing and generative AI systems.</em></p></li></ul><p><em>In addition, the study addresses issues related to the LGPD&#8217;s principles and highlights real-world examples of generative AI use in Brazil, including applications in the public sector, healthcare, and financial services.&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-398?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-398?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-398?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The German Federal Commissioner for Data Protection and Freedom of Information (BfDI</strong>) <a href="https://www.bfdi.bund.de/SharedDocs/Pressemitteilungen/DE/2026/12_Cookie-Banner.html">presented</a> <strong>new recommendations for dealing with cookie banners. </strong><em>(The document is in German.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The recommendations are based on the results of a nationwide representative survey commissioned by the BfDI [&#8230;]. This shows that cookie banners often do not live up to the claim to informed decisions: Only 43 percent of Internet users know exactly what cookies are and what they are used for. 60 percent reject cookies across the board if this is possible with one click.</em>&#8221;</p></li></ul></li><li><p><strong>The Mecklenburg-Vorpommern&#180;s State Commissioner for Data Protection and Freedom of Information </strong>(LfDI MV) <a href="https://www.datenschutz-mv.de/datenschutz/publikationen/KI_Leitfaden/">published</a> an <strong>AI guide for small and medium-sized enterprises</strong>. <em>(The document is in English.)  </em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the AI Act focuses on high-risk systems, which is why the majority of existing guidelines also address these AI systems. Guidance tailored to AI systems with minimal or limited risk would be less complex. This guideline aims to fill this gap and focuses exclusively on AI systems with minimal or limited risk. It is oriented on the practical use and intended to provide direct support for the digitally sovereign, safe and data protection-compliant use of these AI systems.&#8221;</em></p></li></ul></li><li><p><strong>The Polish Personal Data Protection Office (UODO) </strong><a href="https://uodo.gov.pl/pl/138/4533">has prepared</a> guidances to support privacy-compliant <strong>AI implementation</strong>. <em>(The documents are in Polish.) </em>Comments and experiences can be submitted to UODO until Septermber 30. </p></li><li><p><strong>The <span>European Data Protection Supervisor (EDPS)</span></strong><span> has issued </span><a href="https://www.edps.europa.eu/data-protection/our-work/publications/opinions/2026-08-11-edps-opinion-182026-regulation-europol-repealing-regulation-eu-2016794_en">Opinion 18/2026</a><span> on the European Commission&#8217;s </span><a href="https://home-affairs.ec.europa.eu/proposal-regulation-european-parliament-and-council-european-union-agency-law-enforcement_en">Proposal for a Regulation on the European Union Agency for Law Enforcement Cooperation (Europol)</a><span>, which would replace the current Europol Regulation, Regulation (EU) 2016/794.</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The EDPS is particularly concerned by the serious risks to the right to the protection of personal data arising from the envisaged possibilities for Europol to process personal data pertaining to individuals with no established links to criminal investigations or proceedings, for an extensive and unspecified period of time. [&#8230;]</em></p></li><li><p><em>[&#8230;] the EDPS makes recommendations concerning strict purpose and storage limitation as well as legal certainty and foreseeability of the criteria upon which Europol would decide whether it is &#8216;relevant and necessary&#8217; to process the personal data of individuals with no established connection to a criminal activity. The EDPS also comments on and provides specific advice on the proposed rules for access and query of Europol systems; the processing of personal data obtained directly from private parties; the supervision of data processing activities carried out by Europol staff in Member States and the EDPS&#8217;s cooperation with national supervisory authorities; the security of Europol services and tools; and other issues.&#8221;</em></p></li></ul></li><li><p><strong>The Law Firm Noerr <a href="https://www.noerr.com/de/insights/private-videoaufnahmen-mittels-wearables-im-offentlichen-raum">published</a> a brief overview regarding the current debate in Germany on a possible ban on the private use of wearables with integrated cameras</strong> in public spaces. <em>(Authors: Henrike von dem Berge and Marieke Merkle. The post is in German.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The German discussion about smart glasses is at a crossroads. General bans or significant restrictions on use would &#8211; as was once the case with Google Street View &#8211; justify a special path. Neighbouring European countries are focusing on raising awareness and personal responsibility on the part of users. One legal approach to enabling independent private data collection in public is a contemporary, more literally-oriented interpretation of the household exception of the GDPR. What is still subject to exclusively private use in the sense of the household exception should be based on what is socially accepted as a private context in 2026. This avoids a rigid, outdated understanding of private technology use. Therefore, it should be critically questioned whether the ECJ's pre-GDPR case law on stationary private video surveillance should continue to serve as a benchmark for the use of new everyday technologies in public.&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>The Communications Security Establishment Canada</strong> <a href="https://www.cyber.gc.ca/en/guidance/canadian-centre-cyber-security-used-frontier-ai-accelerate-detection-engineering">is examining</a> <strong>how AI can support cyber defence and help cyber security practitioners detect, understand and respond to cyber threats</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This first article focuses on detection engineering, the process of creating and testing rules that help cyber defenders identify suspicious activity on networks. [&#8230;] The article outlines how the Cyber Centre has been testing frontier AI models in real operational environments. These hands-on evaluations have provided practical insight into how AI can support defenders working across complex systems, workflows, data, and cyber security challenges. By incorporating frontier AI into daily cyber defence workflows, the Cyber Centre is better equipped to keep pace with the rapidly evolving threat landscape. <span>Using a practical test case, the article examines how </span>AI<span> can transform publicly available information about a cyber threat into detection rules. It demonstrates how AI can assist analysts with tasks such as drafting rules, identifying potential gaps, validating results against test and operational data, and preparing outputs for review. Throughout the process, human oversight remains essential, with analysts responsible for assessing outputs, validating results, and making operational decisions.</span>&#8221;</em></p></li></ul></li><li><p><strong>AI assistant hacked gym website in first known Australian autonomous cyber attack.</strong> (<a href="https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986">ABC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes.&#8221; The &#8220;AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software. Then it went further, kicking someone out of the waiting list who was ahead of Andrew&#8239;&#8212; something it was not asked to do.&#8221;</em></p></li></ul></li><li><p>According to the statement of the French Finance Ministry, &#8220;<em><strong>French taxpayers' &#8203;data, both individuals and professionals, &#8204;were stolen in a cyberattack</strong> [&#8230;].</em>&#8221; (<a href="https://www.reuters.com/legal/litigation/french-taxpayers-data-stolen-cyber-attack-french-finance-ministry-says-2026-08-14/">Reuters</a>) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;A "malicious actor" claimed on Wednesday &#8203;he broke into the tax agency, &#8288;General Direction of Public Finances, &#8203;in late June [&#8230;]. The data of &#8288;678,000 &#8203;users was stolen [&#8230;].&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p>A report regarding the &#8220;<em><strong>Quantum computing&#8217;s growing presence in the corporate world</strong></em>&#8221; <a href="https://global.fujitsu/en-global/technology/key-technologies/news/ta-ft-research-26quantum-20260220">has been published</a>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In research commissioned by Fujitsu, FT Longitude, part of The Financial Times, surveyed 300 senior executives across industries and regions to assess current levels of awareness, readiness, and strategic intent, and to identify how leading organizations are positioning themselves to capture value while managing emerging risks.&#8221;</em></p></li><li><p>Key findings: </p><ul><li><p><em>&#8220;<strong>96%</strong> of executives expect quantum computing to bring benefits to their organization at some point, and just over a quarter are already seeing some business benefits from their exploration.</em></p></li><li><p><em><strong>58%</strong> plan to include quantum computing in their strategic planning discussions this year.</em></p></li><li><p><em><strong>73%</strong> of public sector and defense organizations are actively assessing quantum computing use cases that could help them solve pressing problems, compared with only 32% of other sectors&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The European Commission&#180;s Joint Research Centre</strong> <a href="https://publications.jrc.ec.europa.eu/repository/handle/JRC147510">published</a> a study, titled <em><strong>&#8220;Opportunities for young users on social media&#8221;</strong></em><strong>. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>[&#8230;] while it is true that social media use is associated with many risks and that minors are an especially vulnerable population, this practice also offer a wide range of opportunities touching to children&#8217;s rights to access to information, education and health tools, opportunities for civic participation, new environments for play and social interaction, for self-expression and improved accessibility for children with disabilities. [&#8230;] The evidence gathered in this brief shows that, alongside well documented risks, social media platforms can provide minors with a range of concrete benefits that directly support several articles of the UN Convention on the Rights of the Child &#8211; notably the rights to education, information, participation, health and freedom of expression.&#8221;</span></em></p></li></ul></li><li><p><strong>The <span>5G Observatory </span>workshop</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/5g-observatory-workshop-summary-5g-and-road-6g-europe-and-beyond">explored</a><strong> Europe&#8217;s 5G progress, Digital Decade targets and future connectivity indicators</strong> as EU stakeholders assess the path from 5G to 6G.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The following key points emerged: </em></p><ul><li><p><em>1. Europe has largely achieved basic 5G coverage, but advanced 5G remains uneven. </em></p></li><li><p><em>2. The next phase of 5G monitoring should focus on capability, availability, quality of experience and adoption. </em></p></li><li><p><em>3. 5G standalone and private networks are key routes to 5G value creation, but scale up depends on clearer business cases and deployment models. </em></p></li><li><p><em>4. The Observatory should keep core deployment indicators while selectively evolving towards 5G standalone, private networks, take-up, quality, value and readiness metrics. Future indicators should remain practical, comparable and proportionate. </em></p></li><li><p><em>5. 6G monitoring should begin with readiness, spectrum, standardisation, research and innovation, use-case experimentation and emerging business models. </em></p></li><li><p><em>6. The Observatory is a valuable monitoring tool that has kept pace with policy and market developments over the past decade. Ahead of forthcoming evolutions, driven by 6G, cloud and AI, it will continue playing an important role in supporting the Digital Decade reporting process.&#8221;</em></p><p></p></li></ul></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-398?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-398?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Anthropic</strong> <a href="https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content">announced</a> that <strong>it will include machine-readable marks in content that Claude generates</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Claude uses two complementary techniques to mark content generated and processed by Claude: (1) watermarks embedded in text, and (2) signed provenance metadata attached to files.&#8221;</em></p></li><li><p><em>&#8220;Machine-readable marks provide important signals about content, but it&#8217;s worth understanding their limitations across all content types.</em></p><ul><li><p><em><strong>A detected mark provides a signal that content was processed by Claude, but is not fully conclusive. </strong>[&#8230;]</em></p></li><li><p><em><strong>Lack of a detected mark doesn&#8217;t mean the content wasn&#8217;t AI-generated or processed. [&#8230;]&#8221;</strong></em></p></li></ul></li></ul></li><li><p><strong>Spotify <a href="https://newsroom.spotify.com/2026-08-11/ai-persona-badges-transparency/">introduces</a> a new label for AI-generated artist identities. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] starting mid-September, you&#8217;ll begin to see an AI Persona badge on some artist profiles. The badge signals to listeners that an artist&#8217;s identity may be AI-generated and does not represent a real person. [&#8230;] By default, Spotify will not include AI Personas in any editorial or algorithmic recommendations. That means you won&#8217;t see any music from AI Personas in your personalized recommendations, unless you follow AI Personas, for example.&#8221; </em></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!-amY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 424w, /__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 848w, /__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!-amY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png" width="835" height="602" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:602,&quot;width&quot;:835,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:214129,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/209783881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 424w, /__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 848w, /__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-amY!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff11e82a1-09c0-48a6-ae35-d9c58c7b836a_835x602.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://newsroom.spotify.com/2026-08-11/ai-persona-badges-transparency/">Spotify</a></em></p></li><li><p><strong>Mistral </strong><a href="https://mistral.ai/news/regional-inference-open-models-new-compute/">announced</a> that <strong>it is advancing AI sovereignty </strong><em>&#8220;by offering enterprises and countries control over AI models, infrastructure, and compute capacity, ensuring regional compliance and reliability.&#8221; </em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The company is expanding open model access, introducing regional endpoints and priority tiers, and forming a coalition to secure long-term European AI compute capacity. With plans to build up to 1 GW of capacity by 2030, Mistral aims to provide a scalable, sovereign AI infrastructure that retains value and control for users.&#8221;</em></p></li></ul></li><li><p><em><strong>&#8220;Canada-based BTQ Technologies and the Industrial Technology Research Institute (ITRI) </strong>have completed the first milestone in a multi-year program to validate <strong>a new chip architecture designed to accelerate post-quantum cryptography</strong>.&#8221;</em> (<a href="https://interestingengineering.com/innovation/new-post-quantum-chip-architecture">Interesting Engineering</a>)</p><ul><li><p><em>&#8220;<span>The technology is intended to provide hardware-based </span><a href="https://interestingengineering.com/innovation/what-is-cryptography">cryptographic</a><span> acceleration for devices and systems that will need protection against future quantum computers. [&#8230;] The architecture was tested within a TSMC 28-nanometre design environment, where researchers evaluated its ability to accelerate cryptographic operations while maintaining functional correctness. [&#8230;] The key concept is to perform cryptographic operations inside the memory subsystem rather than moving data between separate processing and memory components. This approach is intended to reduce data movement, latency and power consumption.&#8221;</span></em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 32]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-f3e</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-f3e</guid><pubDate>Mon, 10 Aug 2026 10:02:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rWFF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The AI Office of Ireland <a href="https://enterprise.gov.ie/en/news-and-events/department-news/2026/july/20260730.html">has been officially established</a> </strong>under the AI Regulation Bill 2026. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Act establishes Oifig IS na h&#201;ireann (AI Office of Ireland) as an independent statutory body, which will act as Ireland's central coordinating authority for the implementation of the EU Artificial Intelligence Act, Regulation (EU) 2024/1689, and is an essential element of Ireland&#8217;s preparations for the supervision and enforcement of the EU AI Act.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong><span>California&#8217;s Delete Act that forces data brokers to erase personal data </span><a href="https://abc7news.com/post/californias-delete-act-forces-brokers-erase-personal-data-starting-august-1/19502565/"><span>became applicable</span></a><span> as of August 1. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The law, authored by California Sen. Josh Becker, allows residents to request the deletion of personal information collected by data brokers. Becker said the measure is designed to give consumers more control over how their information is used.&#8221;</em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The European Data Protection Supervisor</strong> (<span>EDPS)</span><strong><span> </span><a href="https://www.edps.europa.eu/data-protection/our-work/publications/opinions/2026-07-29-edps-opinion-14-regulation-framework-measures-strengthening-europes-cloud-and-ai-ecosystem-cloud-and-ai-development-act_en"><span>published</span></a><span> his Opinion on the proposal for the Cloud and AI Development Act. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The EDPS therefore strongly supports the objectives of the Proposal, i.e. to strengthen the Union&#8217;s cloud and AI ecosystem, reduce dependencies, increase operational resilience and sovereignty. [&#8230;]&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] The Union assurance framework may usefully add specific requirements relating to sovereignty, operational autonomy, resilience, public order, third-country access risks and service continuity. However, those requirements should build upon EU data protection law in order to avoid unnecessary duplication and legal uncertainty. To achieve this objective, the Proposal should further develop: </em></p><ul><li><p><em>the relationship between the Union assurance criteria and audit evidence requirements [&#8230;]; </em></p></li><li><p><em>the interaction between the data localisation requirements [&#8230;]; and </em></p></li><li><p><em>the relationship between the associated third-country mechanism [&#8230;.]&#8221;</em></p></li></ul></li></ul></li><li><p><strong><span>The new CSAM Derogation was last week </span><a href="https://eur-lex.europa.eu/eli/reg/2026/1881/oj/eng"><span>published</span></a><span> in the Official Journal of the EU</span></strong><span> and is in force. </span><strong><span>New expiration date is 3 April 2028</span></strong><span> (see Art. 11).</span></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>GEMA sued the US music AI developer Suno for copyright infringement</strong> in six musical works. (<a href="https://www.technollama.co.uk/gema-v-suno-another-landmark-ai-copyright-case-from-germany">TechnoLlama</a>) <em>(The decision is available <a href="https://drive.google.com/file/d/1HffHYIUM25tEVLUsGb2KQQ24jmZOzIL1/view">here</a> in German.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Munich Regional Court largely found in favour of GEMA on the copyright infringement front, particularly on the reproduction and memorisation arguments. The court held that it had jurisdiction over both the alleged infringements occurring in Germany and the training carried out in the US. [&#8230;] Although the court agreed that some part of the input phase could fall under the TDM exception, in this particular case they concluded that Suno&#8217;s use of the works for AI training infringed the reproduction right. [&#8230;] So the court held that the TDM exception under German law did not apply here, mostly because the works had not been lawfully obtained, as there had been ripped from YouTube, and because valid rights reservations had been made, in other words, the authors had opted out of training. With respect to the US training, the court further concluded that the defendant could not rely on the US fair use doctrine [&#8230;]. However, GEMA did not win all of its claims as the court rejected their separate claim that the defendant had infringed the right of communication to the public by merely offering the model itself. [&#8230;]&#8221;</em></p></li></ul></li><li><p><strong>The <span>U.S. Court of Appeals for the Ninth Circuit </span></strong><a href="https://www.wsgr.com/en/insights/ninth-circuit-addresses-cfaa-and-agentic-ai-tools-in-groundbreaking-decision.html"><span>issued</span></a><span> a groundbreaking decision in </span><em><a href="https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf">Amazon.com Services, LLC v. Perplexity AI</a></em><span>, </span><strong><span>addressing the legal status of so-called &#8220;agentic AI&#8221; tools</span></strong><span>. </span><em><span>(For s summary, please see </span><a href="https://www.wsgr.com/en/insights/ninth-circuit-addresses-cfaa-and-agentic-ai-tools-in-groundbreaking-decision.html"><span>the post at Wilson Sonsini Goodrich &amp; Rosati&#180;s homepage</span></a><span>.)</span></em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Ninth Circuit held that Perplexity (through its AI agent) does not &#8220;access&#8221; Amazon&#8217;s computer system or website, as that term is understood under the CFAA* or its California analogue, the California Comprehensive Computer Data Access and Fraud Act (CDAFA). Therefore, Amazon was not likely to succeed on its claims against Perplexity under either statute, even if end users access Amazon.com through Perplexity&#8217;s Comet Browser. The court also emphasized that the CFAA is principally an anti-hacking criminal statute and courts should exercise caution before expanding liability under it to new technologies and contexts. [&#8230;] An important lesson from the opinion is that operators of agentic AI technologies should avoid direct connections between their own computer systems and the third-party websites or systems that their tools are used to &#8220;access.&#8221; Beyond that, the details of how any given AI tool actually operates and is used will be essential in determining the risk of liability.&#8221; (*CFAA=Computer Fraud and Abuse Act)</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Federal Trade Commission (FTC), joined by Utah and California, <a href="https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-states-act-against-hims-hers-deceptive-unlawful-privacy-practices">sued</a> Hims &amp; Hers alleging that the telehealth provider shared consumers&#8217; sensitive health information about medical conditions with third-party advertising platforms. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the FTC and its state and local partners allege that Hims &amp; Hers (Hims) fails to clearly disclose that it charges consumers for prescriptions almost immediately after they submit an intake form, despite telling consumers that they will be able to consult with a medical provider to find a treatment that is &#8220;right for them.&#8221; The FTC also alleges that the company has made it difficult for consumers to cancel subscriptions and misled consumers about keeping their health information private. The FTC alleges that Hims shared consumers&#8217; health information with Meta, Snap and other third parties.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>Meta was ordered to pay $567 million in New Mexico </strong>for teen mental health fund and<strong> change how its platforms function for young users</strong> after finding the company is to blame for harming children's wellbeing. (<a href="https://www.reuters.com/world/new-mexico-court-orders-meta-pay-567-mln-teen-mental-health-fund-2026-08-06/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong></em>Meta was ordered<em> &#8220;to implement youth-safety measures, including monthly limits on teens' use of Facebook and Instagram, restrictions on notifications, tighter controls on adult contact with minors, safeguards for AI chatbots, and enhanced &#8203;review of child sexual abuse reports, under a decree that will be in place for five years.&#8221;</em></p></li><li><p>Meta was also ordered<em> &#8220;to prevent children &#8203;in New Mexico from "engaging in romantic or sexualized interactions with Meta's artificial intelligence chatbots" and to prevent adults in New Mexico from using chatbots to simulate or discuss a sexualized interaction with a child.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Center for Strategic &amp; International Studies </strong><a href="https://www.csis.org/analysis/toward-federal-framework-lessons-state-and-international-frontier-ai-regulation">published</a><strong> a report comparing several U.S. state bills to international approaches to regulating and shaping frontier AI development</strong>, including the EU AI Act, and voluntary industry governance frameworks for frontier AI models.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The analysis, which extends through June 2026, reveals that U.S. states are serving as laboratories of democracy by trialing a variety of approaches to AI legislation. The most pro-regulatory versions of these experiments have failed to gain traction, whereas more modest approaches that mirror industrial practice have become law. These attempts could provide a blueprint for the U.S. government&#8217;s stated goal of putting into place a federal legislative framework that can preempt a state patchwork of laws and reduce the compliance burden for U.S. companies.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!rWFF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 424w, /__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 848w, /__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 1272w, /__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!rWFF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png" width="582" height="698" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:698,&quot;width&quot;:582,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73314,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/207127375?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 424w, /__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 848w, /__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 1272w, /__u/substackcdn.com/image/fetch/$s_!rWFF!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779e55c2-64da-4f95-8d70-7b3b4678bbcd_582x698.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://www.csis.org/analysis/toward-federal-framework-lessons-state-and-international-frontier-ai-regulation">CSIS report</a></em></p></li></ul></li><li><p><strong>The Stanford Institute for Human-Centered AI (HAI) </strong><a href="https://hai.stanford.edu/policy/the-world-model-and-spatial-intelligence-era-governing-ai-beyond-language">has published</a> a policy brief, titled <em><strong>&#8220;The World Model and Spatial Intelligence Era: Governing AI Beyond Language&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Key Takeaways:</em></p><ul><li><p><em>World models are AI systems that build a working representation of an environment to predict how it changes in response to action. They could lower the cost of high-quality simulation, benefiting infrastructure planning, crisis response, experimentation, and embodied AI training.</em></p></li><li><p><em>No existing benchmark gives policymakers an adequate basis to evaluate a world model for safety-critical deployment. Closing that gap requires public investment in measurement science.</em></p></li><li><p><em>Policy built for existing AI-generated content and autonomous decision-making does not fully address the risk profile of world models. The distinctive question is whether a simulated environment matches physical reality closely enough to train or test another system or guide a real-world decision.</em></p></li><li><p><em>The scarcest input is action-labeled interaction data &#8212; robot trajectories and fleet logs that cannot be scraped from the web, which risks concentrated control. Public datasets should be an explicit target of federally funded research.</em></p></li><li><p><em>World models are dual use, with national security implications. By lowering the cost of capable autonomous systems, they could open military advantage to less-resourced entrants, making early leadership in world-model research, development, and governance an urgent national security priority.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>UAE launched world&#8217;s first fully integrated AI-powered judicial platform</strong>. (<a href="https://gulfnews.com/uae/government/uae-launches-worlds-first-fully-integrated-ai-powered-judicial-platform-1.500622338">Gulf News</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the new platform is not intended to replace judges. Instead, it functions as an advanced legal assistant capable of analyzing case files, reviewing legislation, searching judicial precedents, and generating analytical insights that enable judges and legal professionals to reach decisions more efficiently while preserving complete judicial independence.&#8221;</em></p></li><li><p><em>&#8220;The AI-powered judicial platform is designed to integrate artificial intelligence across multiple stages of judicial proceedings, including:</em></p><ul><li><p><em>Automated analysis of case files and legal documents.</em></p></li><li><p><em>Instant access to legislation and regulatory frameworks.</em></p></li><li><p><em>Rapid retrieval and comparison of judicial precedents.</em></p></li><li><p><em>AI-assisted legal recommendations and analytical reports.</em></p></li><li><p><em>Support in drafting legal memoranda and judicial documents.</em></p></li><li><p><em>Faster case processing and shorter litigation timelines.</em></p></li><li><p><em>Greater consistency in the application of legal principles.</em></p></li><li><p><em>Enhanced decision-making support without compromising judicial autonomy.&#8221;</em></p></li></ul></li><li><p><em>&#8220;[&#8230;] the UAE&#8217;s initiative is distinguished by its fully integrated judicial ecosystem, bringing together multiple AI-powered legal functions within a single comprehensive platform rather than relying on isolated digital tools.&#8221;</em></p></li></ul></li><li><p>The <span>new website, </span><strong><a href="https://ai-legal-education.perl.chatgpt.site/">AI in Legal Education: Law School Policy Archive</a>,</strong><span> </span><a href="https://www.lawnext.com/2026/08/new-site-from-suffolk-law-dean-andrew-perlman-catalogs-ai-policies-at-128-law-schools.html"><span>launched</span></a><span> by </span>Andrew Perlman<span>, dean of Suffolk University Law School, &#8220;</span><em><span>catalogs public AI policies, teaching strategies, and curricular programs from 128 of the 196 U.S. law schools, organized into eight topic areas and derived from the schools&#8217; own published documents.</span></em><span>&#8221; </span><em><span>(In Hungarian, please see at </span><a href="https://jogaszvilag.hu/a-jovo-jogasza/a-suffolk-jogi-kara-128-jogi-kar-mesterseges-intelligenciaval-kapcsolatos-szabalyzatat-gyujtotte-ossze/"><span>Jogaszvilag.hu</span></a><span>, Wolters Kluwer.)</span></em></p><ul><li><p><em><strong>Why does this matter? </strong>Key findings can be categorized to the following topics: </em></p><ul><li><p><em>&#8220;Prohibition is the default. [&#8230;]</em></p></li><li><p><em>Mandatory AI instruction is spreading. [&#8230;] </em></p></li><li><p><em>Assessment is changing. [&#8230;] </em></p></li><li><p><em>Syllabus disclosure of AI. [&#8230;]&#8221;</em></p></li></ul></li><li><p><em>&#8220;[&#8230;] the site clearly addresses a gap in understanding how legal education is responding to AI, providing greater detail than had been available through scattered news stories or high-level surveys.&#8221;</em></p></li></ul></li><li><p><strong>The Network Advertising Initiative</strong> <a href="https://thenai.org/new-nai-guidance-key-dos-donts-for-using-ai-in-network-advertising/">released</a> <strong>guidance outlining dos and don'ts regarding the implementation of AI and agentic workflows</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This guidance covers nine topics, each with practical do&#8217;s and don&#8217;ts:</em></p><ol><li><p><em>Inventory and enabling of AI use cases</em></p></li><li><p><em>Advertising audience/segment review and activation</em></p></li><li><p><em>Testing and monitoring of AI systems</em></p></li><li><p><em>Disclosures about how AI systems are used</em></p></li><li><p><em>Permissions and constraints applied to AI systems</em></p></li><li><p><em>Choice and signal handling</em></p></li><li><p><em>Oversight and logging for agentic AI systems</em></p></li><li><p><em>Contracting and risk allocation between AI users and AI vendors</em></p></li><li><p><em>Accountability&#8221;</em></p></li></ol></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-f3e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-f3e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-f3e?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The French Data Protection Authority</strong> (CNIL) <a href="https://www.cnil.fr/fr/supprimer-mes-donnees-presse">issued</a> <strong>guidance related to the obligations of media organizations that receive deletion requests from data subjects. </strong><em>(The document is in French.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Any data subject has the right to request from a press organisation the deletion of personal data concerning him or her contained in a press article published online. However, this is not an absolute right: a balance must be struck between the interests involved.&#8221;</em></p></li></ul></li><li><p><strong>The Dutch Data Protection Authority (AP) <a href="https://autoriteitpersoonsgegevens.nl/actueel/ap-privacyrisicos-door-gebruik-menstruatie-apps">urged</a> consumers to remain cautious when sharing sensitive health information on reproductive heath apps. </strong><em>(The document is in Dutch.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In practice, it is not clear whether the apps share this information with, for example, advertising partners and whether users are properly informed about this. The AP advises to check what you give permission for when you install the app. If the information is unclear or there is no option to reject the sharing of data, for example, do not share information that you want to keep private.&#8221;</em></p></li></ul></li><li><p><strong>Hamburg&#8217;s data protection commissioner, Fuchs <a href="https://www.tagesschau.de/inland/innenpolitik/smart-glasses-verbot-100.html">warned</a> against Meta smart glasses</strong> and said that <strong>&#8220;</strong><em><strong>a ban is not ruled out</strong></em><strong>&#8221;</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Hamburg data protection commissioner Thomas Fuchs is responsible for Meta services in Germany. [&#8230;] Fuchs also considers it quite possible that the glasses will be completely banned in Germany. The possession and sale of recording devices disguised as everyday objects is not allowed in Germany. And the Meta Glasses are, in Fuchs&#8217; estimation, nothing more than camouflaged cameras. The Federal Network Agency would be responsible for such a ban. It is probably currently examining the further course of action. In the event of a ban, Meta would no longer be allowed to sell the glasses in Germany.&#8221;</em></p></li></ul></li><li><p><strong>Australian Privacy Commissioner</strong> <a href="https://www.oaic.gov.au/news/blog/surveillance-wearables-are-we-through-the-looking-glasses">highlighted</a> that <strong>they are giving </strong><em><strong>&#8220;serious consideration to the issues raised by surveillance wearables and monitoring their market presence</strong> to understand if scrutiny and intervention is required or warranted.&#8221;</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] The proliferation of smart glasses &#8211; and their future peers, such as wearable pins or advanced earbuds &#8211; would fundamentally alter our experience of interpersonal interactions, in both private and public spaces, [&#8230;]. Without knowing, we could be filmed, recorded or photographed at any time. [&#8230;] there will be exceptions to benign usage &#8211; where smart glasses users are able to use the tech in harmful ways to exploit or surveil vulnerable groups, such as children or victims of domestic violence, or for other untoward ends, such as corporate espionage, data theft, extortion or bribery. Beyond safety concerns, there is also the impact on community values and the public interest in privacy. In aggregate, the effects of mainstreamed surveillance wearables would be the emergence of new privacy risks, new safety concerns, and new societal norms.&#8221;</em></p></li><li><p><em>&#8220;It would also require consideration of whether we need new laws. Australia&#8217;s Privacy Act only applies to businesses and government agencies, not to individuals, and it only applies when those entities collect personal information.&#8221;</em></p></li></ul></li><li><p><strong>The Information Commissioner&#8217;s Office (UK)</strong> <a href="https://ico.org.uk/media2/ro2jpfio/ico-public-attitudes-on-information-rights-survey-2026.pdf">published</a> a survey, <em><strong>&#8220;Public Attitudes on Information Rights&#8221;</strong></em>. The primary goal of this survey wa to develop a reliable quantitative evidence base to measure progress on KPIs from the ICO25 strategic plan.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This research shows a broadly positive picture for the ICO in 2026, with rising awareness of information rights, improved satisfaction with organisations&#8217; responses to rights requests, and higher awareness of the ICO itself. At the same time, the findings point to a more mixed picture on data privacy, with declining trust in formal advice sources and a significant minority saying their trust in organisations using their data has decreased over the last year. The research also highlights ongoing challenges with data breaches, low confidence in reporting spam, declining engagement on privacy notices, and declining optimism around some emerging technologies.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xS2P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 424w, /__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 848w, /__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xS2P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png" width="938" height="470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70081548-eab9-40a5-8183-2d52df598c5e_938x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:938,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66700,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/207127375?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 424w, /__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 848w, /__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xS2P!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70081548-eab9-40a5-8183-2d52df598c5e_938x470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://ico.org.uk/media2/ro2jpfio/ico-public-attitudes-on-information-rights-survey-2026.pdf">Public Attitudes on Information Rights Survey 2026</a>, Figure 8, p. 17</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>Germany's Federal Office for Information Security</strong> (BSI) <a href="https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/2026/TR-03183_Einstiegshilfe_CRA_260805.html">released</a><strong> a technical guide with cybersecurity recommendations to support Cyber Resilience Act compliance</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;With a structured approach to risk-based selection of cybersecurity measures, the requirements of TR-03183-1 can serve as a guide for the CRA's class of standard products. Based on their risk analysis, manufacturers can identify what measures they should implement for an appropriate level of cybersecurity.&#8221;</em></p></li></ul></li><li><p>According to reports, <em>&#8220;<strong><span>the White House does not plan to publicly release its new framework for evaluating advanced </span>AI<span> models</span></strong><span> [&#8230;].&#8221;</span></em><span> (</span><a href="https://www.axios.com/2026/08/04/white-house-ai-framework-under-wraps"><span>Axios</span></a><span>)</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The </span>voluntary framework<span> has </span>global<span> implications for AI security, but details will only be made available to the companies that are part of the process.&#8221;</span></em></p></li></ul></li><li><p><em>&#8220;Anthropic&#8217;s <strong>Mythos 5 model created fake identities to try to convince a human to approve malicious changes</strong> to an open source project [&#8230;].&#8221;</em> (<a href="https://www.cnbc.com/2026/08/05/anthropic-mythos-openai-security-breaches.html">CNBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The incident happened during a cyber evaluation where the U.K.-based AI Security Institute (AISI) [&#8230;]&#8221;</em></p></li><li><p><em>&#8220;The incident was discovered during routine cyber evaluations, with 17 actions coming from Anthropic&#8217;s Mythos and 2 from OpenAI&#8217;s GPT-5.6-Sol with cyber classifiers.</em></p></li><li><p><em>It comes after a series of cyber breaches carried out by models developed by Anthropic and OpenAI identified in recent weeks.&#8221;</em></p></li></ul></li><li><p><em>&#8220;[&#8230;] <strong>Meta has become the latest tech firm to say one of its AI models was able to connect to the internet and hack into another organisation's systems</strong>, during testing.&#8221;</em> (<a href="https://www.bbc.com/news/articles/cx2kgdnyk2po">BBC</a>)</p></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/boosting-tech-deployment-beyond-2027-new-study-highlights-digital-opportunities-and-challenges-eu">has published</a><strong> a new study, <a href="https://op.europa.eu/en/publication-detail/-/publication/03b193a1-6d4b-11f1-ae88-01aa75ed71a1/language-en">&#8220;</a></strong><em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/03b193a1-6d4b-11f1-ae88-01aa75ed71a1/language-en">The EU&#8217;s Critical Digital Capacities: Deployment Beyond 2027</a></strong></em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/03b193a1-6d4b-11f1-ae88-01aa75ed71a1/language-en">&#8221;</a></strong>,<strong> </strong>revealing both strengths and gaps in Europe&#8217;s digital transformation ahead of the next Multiannual Financial Framework.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The study finds that next EU funding programme must address </span><strong>challenges </strong><span>around underinvestment, skills shortages, and market fragmentation, while building on </span><strong>existing strengths</strong><span> in green digital solutions, open source and a trusted regulatory and data protection framework.</span>&#8221;</em></p></li><li><p>The study covers the following topics in its annexes: </p><ul><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/2509cd18-6d4b-11f1-ae88-01aa75ed71a1/language-en">Annex 3 - Advanced digital communications and connectivity</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/359ecbda-6d4b-11f1-ae88-01aa75ed71a1/language-en">Annex 4 &#8211; Artificial Intelligence</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/ecdd00ac-6d4a-11f1-ae88-01aa75ed71a1/language-en">Annex 5 - Blockchain and Distributed Ledger Technologies</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/1e5de286-6d4b-11f1-ae88-01aa75ed71a1/language-en">Annex 6 &#8211; Cloud-Edge-IoT</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/fa9b11af-6d4a-11f1-ae88-01aa75ed71a1/language-en">Annex 7- Cybersecurity and digital identity technologies</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/3af5d4cb-6d4b-11f1-ae88-01aa75ed71a1/language-en">Annex 8 &#8211; Data analytics and data sharing technologies</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/18542b65-6d4b-11f1-ae88-01aa75ed71a1/language-en">Annex 9 &#8211; High Performance Computing</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/f49a0d1e-6d4a-11f1-ae88-01aa75ed71a1/language-en">Annex 10 - Microelectronics</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/e33f4d57-6d4a-11f1-ae88-01aa75ed71a1/language-en">Annex 11 &#8211; Next Generation Internet and Extended Reality</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/456820c0-6d4c-11f1-ae88-01aa75ed71a1/language-en">Annex 12 &#8211; Photonics</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/e249c9c6-6d4a-11f1-ae88-01aa75ed71a1/language-en">Annex 13 - Quantum</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/0daf8f63-6d4b-11f1-ae88-01aa75ed71a1/language-en">Annex 14 - Robotics</a></em></p></li><li><p><em><a href="https://op.europa.eu/en/publication-detail/-/publication/94fb7c4e-6d4b-11f1-ae88-01aa75ed71a1/language-en">Annex 15 &#8211; Interoperability and GovTech</a></em></p></li></ul></li></ul></li><li><p><strong>The eSafety (Australia)</strong> <a href="https://www.esafety.gov.au/research/social-media-age-restrictions-evaluation/early-days-early-insights-three-months-report">published</a> <strong>a report on the first experiences with social media age restrictions in Australia. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This report explores the early experiences of children, as well as their parents, three months after the commencement of Australia&#8217;s social media age restrictions.&#8221;</em></p></li><li><p><strong>Key insights:</strong></p><ul><li><p> <em>&#8220;The proportion of children (aged 10 to 15) owning a social media account declined from 52.4% at baseline to 42.1% at the three-month follow-up. [&#8230;]</em></p></li><li><p><em>The primary reason children continued to hold age-restricted social media accounts at three months appeared to be ineffective implementation of age assurance measures by platforms. [&#8230;]</em></p></li><li><p><em>There were early signals of redistribution of online activities among children at three months. [&#8230;]</em></p></li><li><p><em>Parental awareness of children&#8217;s social media use declined at three months. [&#8230;]</em></p></li><li><p><em>There was some evidence that perceived norms and attitudes towards social media had shifted at three months. [&#8230;]</em></p></li><li><p><em>Parental support for and attitudes towards the age restrictions has remained consistent at three months. [&#8230;]</em></p></li><li><p><em>At three months, most children reported that there was little to no change in their engagement with offline activities, behaviours associated with problematic online use, and their wellbeing. [&#8230;]</em></p></li><li><p><em>There has been little change in family dynamics at three months. [&#8230;]</em></p></li><li><p><em>There were some age and gender differences in children&#8217;s and parents&#8217; early experiences of the age restrictions. [&#8230;]&#8221;</em></p></li></ul></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-f3e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-f3e?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><strong><a href="https://arxiv.org/pdf/2608.04458">&#8220;Architectural Implications of Agentic AI Workflows&#8221;</a></strong></em> (authors: Yang et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] Guided by these findings, we derive implications for agentic servers and examine them through Agora, our prototype for commodity servers. Agora dynamically harvests idle CPU cores for co-located throughput work, while protecting agentic tail latency against tool spikes. It also oversubscribes GPU memory by placing more agents on each GPU, prefetching the next agent&#8217;s state to hide swap latency. To match the machine to the het erogeneous roles, Agora pools cores by role and applies affinity aware scheduling to restore locality. Finally, Agora automatically tunes all of these mechanisms to the running workload. These techniques substantially improve CPU and GPU utilization and per-server throughput while preserving agent tail latency. Our insights also identify key directions for future server architectures for agentic AI.&#8221;</em></p></li></ul></li><li><p>&#8220;<em><strong>Scientists have made the first viruses designed by artificial intelligence</strong> in a milestone that raises hopes for new medicines but also concerns over how to ensure the technology remains safe.</em>&#8221; (<a href="https://www.theguardian.com/science/2026/aug/06/safety-fears-as-scientists-make-first-viruses-designed-by-ai">The Guradian</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The ability to &#8220;rapidly design&#8221; genomes and tune them for specific bugs while overcoming resistance could &#8220;transform phage therapy&#8221; and &#8220;expand biotechnological toolkits&#8221;, the researchers wrote in the journal <a href="http://www.science.org/doi/10.1126/science.aec2657">Science</a>. [&#8230;] But beyond the potential benefits, the scientists said the work raised &#8220;important biosafety, biocontainment and biosecurity considerations&#8221; and urged others who were designing whole genomes to &#8220;consult both safety and security professionals throughout the project&#8221;.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!U5me!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 424w, /__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 848w, /__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 1272w, /__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!U5me!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png" width="1026" height="585" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:585,&quot;width&quot;:1026,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:368784,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/207127375?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 424w, /__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 848w, /__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 1272w, /__u/substackcdn.com/image/fetch/$s_!U5me!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb8921ab-8667-4a89-9925-5fa98eb60406_1026x585.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li></ul><p style="text-align: center;">Source: <em><strong>&#8220;<a href="https://www.science.org/doi/10.1126/science.aec2657">Generative design of bacteriophages with genome language models</a>&#8221; </strong></em>(authors: King et al.)</p></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><em>&#8220;<strong>The European Commission is considering replacing the US technology underpinning a new digital recruitment tool with European cloud and artificial intelligence services</strong> [&#8230;]&#8221;</em> (<a href="https://www.euractiv.com/news/exclusive-commission-mulls-ditching-us-tech-from-ai-recruitment-tool/">Euractiv</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The tool, known as the Job Matching Application, is in the final stages of development. [&#8230;] a Commission spokesperson confirmed the executive was considering replacing the underlying US digital services with European alternatives. [&#8230;] <span>The four </span><a href="https://www.euractiv.com/news/us-backed-clouds-among-eus-sovereign-picks-for-e180m-tender/">successful providers</a><span> under the framework are Germany&#8217;s StackIT and France&#8217;s OVHcloud, Scaleway and S3NS. [&#8230;] The Commission is also considering replacing Anthropic&#8217;s AI model with a European alternative.&#8221;</span></em></p></li></ul></li><li><p><strong>The <span>European Commission and the </span><a href="https://www.spacerise.eu/">SpaceRISE</a><span> consortium</span></strong><span> </span><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1726"><span>concluded negotiations</span></a><span> and signed an implementation agreement </span><strong><span>to roll out </span><a href="https://defence-industry-space.ec.europa.eu/eu-space/iris2-secure-connectivity_en">IRIS&#178;</a><span>, the European Union's new flagship satellite constellation. </span></strong><span>First launches are expected by 2029.</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The agreement, among other things, adds 66 satellites into low Earth orbit to the programme, bringing the main constellation to 348 satellites, and moving it from planning to full-scale deployment.&#8221;</em></p></li><li><p><em>&#8220;Once operational, the constellation will provide sovereign, secure and highly reliable connectivity for European governments, defence and security forces, and emergency services across Europe.&#8221;</em></p></li></ul></li><li><p>Chinese robot maker <strong>Unitree seeks to raise 6.1 billion yuan ($904 million) through its IPO in Sanghai.</strong> Unitree will become the first mainland-listed humanoid robot manufacturer. (<a href="https://www.reuters.com/world/asia-pacific/what-is-unitree-why-are-chinas-humanoid-robot-makers-racing-list-2026-08-10/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong></em>According to <a href="https://www.bloomberg.com/news/articles/2026-08-10/china-humanoid-makers-hold-97-of-global-shipments-report-says">reports</a>, Chinese humanoid robot manufacturers, including Unitree, has a 97% global market share. </p></li></ul></li><li><p><strong>Google DeepMind <a href="https://deepmind.google/blog/gemini-robotics-2-brings-whole-body-intelligence-to-robots/">introduced</a> Gemini Robotics 2, </strong><em><strong>&#8220;</strong>the intelligence layer powering the next generation of truly adaptable robots.&#8221;</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Gemini Robotics 2 enables robots to reason through every movement, unlocking a broad range of tasks. For example, it can enable a humanoid to walk, crouch, stretch, and manipulate objects to clean up a cluttered room. It can even team up with other robots to finish the job faster. And this profound intelligence can also run locally on-device while seamlessly adapting to entirely new robotic bodies in just a few hours.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 31]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-cbb</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-cbb</guid><pubDate>Tue, 04 Aug 2026 09:30:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nVCv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Digital Omnibus on AI <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744">has been published</a></strong> in the Official Journal of the EU.</p><ul><li><p><em><strong>Why does this matter? </strong></em><strong>Timeline Adjustments:</strong></p><ul><li><p><strong>2 December 2026</strong>, the new prohibitions (see below) become applicable; </p></li><li><p><strong>on 2 December 2026,</strong> the grace period ends for providers of AI systems already on the market to implement transparency solutions for AI-generated content (Article 50 transparency obligations becomes applicable as of August 2, 2026);</p></li><li><p><strong>2 August 2027</strong> for the establishment of national AI regulatory sandboxes;</p></li><li><p><strong><span>2 December 2027</span></strong><span> for high-risk AI systems listed on Annex III (stand-alone high-risk systems);</span></p></li><li><p><strong><span>2 August 2028</span></strong><span> for high-risk AI systems listed on Annex I (high-risk embedded safety components).</span></p></li></ul><p><strong>New Prohibitions:</strong></p><ul><li><p><strong><span>Nudifier applications:</span></strong><span> ban on AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person&#8217;s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person&#8217;s consent.</span></p></li><li><p><strong><span>AI-generated CSAM:</span></strong><span> prohibition on AI system that generates or manipulates of child sexual abuse material. </span></p></li></ul><p><strong>Further simplification:</strong></p><ul><li><p><span>Streamlining requirements for machinery and products already governed by sectoral safety laws.</span></p></li><li><p><span>Explicitly allows processing special categories of personal data when strictly necessary to detect and correct AI bias.</span></p></li><li><p><span>Extended regulatory exemptions to small mid-cap enterprises (up to 750 employees).</span></p></li></ul></li></ul></li><li><p><strong>The transparency obligations of the AI Act became applicable as of August 2</strong>. <strong>The Commission <a href="https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems">published</a> guidelines on transparency obligations </strong>for providers and deployers of certain AI systems. <strong>AI Act&#8217;s transparency obligations start to apply on 2 August 2026.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Transparency obligations will help people recognise when they are interacting with AI or when content has been generated or altered by AI, reducing the risk of deception and manipulation. The guidelines clarify which providers and deployers must comply with the transparency obligations for interactive AI systems and the marking and labelling of AI-generated content.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Providers and/or deployers must check how Article 50 disclosure and labeling requirements are applicable to them.  </mark></p></li><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Organizations should review the Commission&#8217;s published guidelines, as they will set the practical benchmark for regulatory expectations.  Failure to comply can result in fines of up to &#8364;15 million or 3% of global annual turnover. </mark></p></li></ul></li></ul></li><li><p><strong>The AI Office <a href="https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_1714/IP_26_1714_EN.pdf">can now enforce</a> the AI Act's rules for providers of general-purpose AI (GPAI) models.</strong> <em>(You can find more info about the enforcement framework of the AI Act <a href="https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act">here</a>.)</em></p></li></ul><p><strong>2) Data protection</strong></p><ul><li><p>In a letter sent to the Commission, <strong>the European Data Protection Board (EDPB) <span>requested the review of EU-US Data Privacy Framework </span></strong><span>following the US Supreme Court&#180;s decision in Trump v. Slaughter. </span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The EDPB respectfully notes that the European Commission, in the adequacy decision underpinning the EU-US Data Privacy Framework (&#8216;DPF&#8217;), explicitly refers to the independence of the US authorities, including the FTC and that its five Commissioners may only be removed by the President for inefficiency, neglect of duty, or malfeasance in office. Given the potential consequences that the US Supreme Court&#8217;s judgment may have in the EEA and its considerable significance for the EDPB, the EDPB asks the European Commission to closely assess whether this development affects the functioning of Commission Implementing Decision EU 2023/1795 and would welcome relevant actions, including the continued sharing of information with the EDPB in a timely manner.&#8221;</em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>Proton</strong> launched an <strong><a href="https://proton.me/age-verification">interactive map</a></strong> <strong>to show how age verification laws spread globally</strong>. (<a href="https://www.techradar.com/vpn/vpn-privacy-security/the-death-of-privacy-online-proton-launches-interactive-map-to-show-age-verification-laws-are-spreading-fast">TechRadar</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Governments around the world are making age a condition for accessing certain parts of the internet. This page tracks where such laws are in force, where they are advancing, and how different countries are approaching the same policy goal.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!nVCv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 424w, /__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 848w, /__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!nVCv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png" width="867" height="517" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:517,&quot;width&quot;:867,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/206813608?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 424w, /__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 848w, /__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nVCv!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a84f6df-206b-478a-b529-6c690046e4d0_867x517.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: Proton, <a href="https://proton.me/age-verification">interactive map</a></em></p></li></ul></li><li><p><strong>New Jersey bans &#8216;surveillance pricing&#8217; for grocery items. </strong>(<a href="https://newjerseymonitor.com/2026/07/23/nj-ban-surveillance-pricing-grocery/">New Jersey Monitor</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The <a href="https://njleg.state.nj.us/bill-search/2026/A4085">bill</a>, dubbed the Fair Price Protection Act, is intended to forbid the use of surveillance pricing, in which prices are adjusted based on someone&#8217;s past purchases, online searches, and other personal digital data. The practice results in individual shoppers paying different prices for identical products purchased at the same time from the same place.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>xAI</strong>, owned by SpaceX, <strong>sued Minnesota</strong> <strong>to challenge a law that would ban so-called nudify apps </strong>in the state. (<a href="https://www.cnbc.com/2026/07/28/spacexs-xai-sues-minnesota-over-law-to-ban-nudify-apps-.html">CNBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] attorneys for xAI wrote that the statute &#8220;imposes an overbroad, content-based ban on free speech and the tools of visual expression in a clumsy attempt to prohibit &#8216;nudification.&#8217;&#8221; [&#8230;] The Minnesota law [&#8230;] targets apps and websites that give people the ability to generate non-consensual sexualized imagery, levying $500,000 fines each time a user creates explicit deepfakes.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Italian Data Protection Authority <a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10275230#english">imposed</a> a fine of 2 million euros </strong>on Lusha Systems Inc., a US-based data broker operating a platform that provides paid access to &#8216;enriched&#8217; information on individuals, such as their job titles, email addresses and telephone numbers.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The company processed the personal data of a large number of individuals in Italy without complying with the principles of lawfulness, fairness, transparency and data minimisation. In particular, the information provided to data subjects was neither clear nor easily accessible. Furthermore, with regard to the lawfulness of the processing, the Authority established that the pursuit of a legitimate interest did not provide an adequate legal basis.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Organizations using third-party data enrichment services should verify that their vendors have a valid legal basis for processing personal data of EU individuals and are providing adequate transparency notices. </mark></p></li><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">The Garante&#8217;s rejection of legitimate interest as a legal basis may signal a hardening enforcement posture that compliance teams should factor into vendor due diligence and data procurement strategies.</mark></p></li></ul></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The Commission <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1654">fined</a> AliExpress &#8364;550 million for breaching the DSA. <span>The Commission </span><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1679"><span>preliminary found</span></a><span> TikTok in breach of DSA for failing to ensure safe accounts for minors.</span></strong></p><ul><li><p>More details in the last edition of my DSA enforcement tracker: </p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;8a4f16ce-cc77-42c3-ba75-f922159c9ca7&quot;,&quot;caption&quot;:&quot;There are more and more developments regarding the implementation and enforcement of the DSA and more resources are available regarding the application of thes Regulation. In this newsletter, I summarize the most important events and news related to the application of the DSA.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;DSA tracker #10 &quot;,&quot;publishedBylines&quot;:[],&quot;post_date&quot;:&quot;2026-07-30T08:01:13.364Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ZvHo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://datalawgy.substack.com/p/dsa-tracker-10&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:198842928,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:3421089,&quot;publication_name&quot;:&quot;Datalawgy&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!lD-4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div></li></ul></li><li><p><strong>The U.S. law firm, Blank Rome</strong> is to face a proposed <strong>class action after &#8204;hackers targeted the firm in a May data breach. </strong>(<a href="https://www.reuters.com/legal/litigation/us-law-firm-blank-rome-faces-class-action-over-data-breach-2026-07-06/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The lawsuit, filed Monday in Pennsylvania federal court, was brought &#8203;by Laura Delapaz, a California resident who said in her <a href="https://tmsnrt.rs/4wxlK9k">complaint</a> that she &#8203;was among 57,554 current, former and prospective Blank Rome clients whose personal information was compromised [&#8230;]. [&#8230;] A growing number of law firms have faced similar data &#8288;breach &#8203;lawsuits. <a href="https://www.reuters.com/legal/government/law-firm-fox-rothschild-hit-with-class-action-over-data-breach-2026-06-09/">Fox Rothschild</a>; <a href="https://www.reuters.com/legal/government/law-firm-wiley-rein-hit-with-class-action-over-data-breach-tied-chinese-hackers-2026-05-26/">Wiley Rein</a>; <a href="https://www.reuters.com/legal/government/law-firm-pillsbury-faces-class-action-over-april-data-breach-2025-11-19/">Pillsbury</a>; and <a href="https://www.reuters.com/legal/government/us-law-firm-kelley-drye-hit-with-class-action-after-data-breach-2025-08-13/">Kelley Drye</a> are among the firms &#8203;that have been sued in the past year. Some firms, including <a href="https://www.reuters.com/legal/litigation/another-us-law-firm-reaches-data-breach-settlement-cyber-risks-mount-2024-11-08/">Gunster Yoakley &amp; Stewart</a>, <a href="https://www.reuters.com/legal/litigation/law-firm-orrick-agrees-8-mln-settlement-over-breach-client-data-2024-04-11/">Orrick Herrington &amp; Sutcliffe</a>, &#8203;and <a href="https://www.reuters.com/legal/litigation/mondelez-law-firm-bryan-cave-reach-deal-end-data-breach-class-action-2024-10-04/">Bryan Cave Leighton Paisner</a>, have reached settlements in recent years.&#8221;</em></p></li><li><p>Law firm, WilmerHale <a href="https://news.bloomberglaw.com/litigation/wilmerhale-sued-over-client-personal-information-data-breach">was also sued</a> over personal data breach.</p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>Government of Canada <a href="https://www.canada.ca/en/innovation-science-economic-development/news/2026/07/government-of-canada-launches-public-consultation-on-ai-transparency.html">launched</a> public consultation on AI transparency.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The public consultation supports the Government of Canada&#8217;s commitment to advancing AI transparency as outlined in <a href="https://ised-isde.canada.ca/site/ised/en/canadas-national-artificial-intelligence-strategy-ai-all">Canada&#8217;s National Artificial Intelligence Strategy: AI for All</a> and centres on:</em></p><ul><li><p><em>detecting and identifying AI-generated content</em></p></li><li><p><em>helping individuals know when they are interacting with an AI system</em></p></li><li><p><em>improving access to consistent, understandable information about AI systems, including their development, capabilities and limitations</em></p></li><li><p><em>enabling the tracking of serious incidents related to AI systems</em></p></li><li><p><em>advancing ways to better track the activities and interactions of AI agents.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The European Parliamentary Reserach Service</strong> <a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)789385">published</a> a briefing, titled &#8220;<em><strong><span>The debate on AI and jobs</span></strong></em><strong><span>&#8221;. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] Today, it is widely recognised that GenAI can both significantly enhance and degrade human skills, and cause labour market disruptions by transforming or displacing jobs. AI's impact on jobs depends on the degree to which these are exposed to AI, and is often estimated by the potential of individual tasks to be automated. Reports distinguish between augmentable, automatable and unaffected jobs. [&#8230;] The most likely impact of GenAI is a profound transformation, rather than large-scale destruction, of jobs. Early evidence shows a strong impact on white-collar entry-level jobs and shifting regional labour-market dynamics, as AI's effects are more strongly felt in urban areas and in places where AI-adopting companies are located. [&#8230;] Forecasts about how AI and digital technologies could reshape employment in European regions are cautiously positive. To reap AI's benefits and mitigate its negative effects on jobs, societal adaptations are needed. Beyond regulation and supportive policy, these start with training and education, to provide both current and future workers with the necessary skills, and include adapted social protection, social dialogue, and safeguards of workers' rights.&#8221;</em></p></li></ul></li><li><p><strong><span>SAIL 2.0</span> framework for the management of AI-specific risks <a href="https://www.pillar.security/sail">has been published</a>. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The SAIL Framework provides a practical, lifecycle-oriented strategy to manage AI-specific risks and build trustworthy AI systems.&#8221;</em></p></li><li><p><em>&#8220;<span>SAIL provides a holistic security methodology covering the complete AI journey, from development to continuous runtime operation. Built on the understanding that AI introduces a fundamentally different lifecycle than traditional software, SAIL bridges both worlds while addressing AI's unique security demands. SAIL's goal is to unite developers, MLOps, security, and governance teams with a common language and actionable strategies to master AI-specific risks and ensure trustworthy AI. It serves as the overarching framework that integrates with your existing standards and practices.&#8221;</span></em></p></li></ul></li><li><p><strong>The University of Cambridge</strong>, in the framework of the Cambridge Programme on AI Science &amp; Policy, <a href="https://casp.ac/reports/ai-enabled-terrorism">published</a> a reserach report about <strong>the use of AI by terrorists</strong>: <em><strong>&#8220;God has helped us, and so will AI&#8221;: How the Terrorist Group Boko Haram Uses Frontier AI.</strong></em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;How are terrorists using AI? Semi-structured interviews with 27 former Boko Haram members conducted in northeast Nigeria in 2025 and 2026 reveal unprecedented detail about AI-assisted terrorist activity primarily through 2024. This report finds that both factions of Boko Haram use frontier AI, including ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek, to assist in combat and day-to-day operations. This AI use is institutionalized through specialized units and internal training. It has aided in attack planning, weapons troubleshooting, and the design of explosive devices, as users have successfully circumvented some safeguards. This know-how was transferred through transnational jihadist networks, with Islamic State operatives delivering in-person training. Respondents expressed strong enthusiasm for AI and, in some cases, openness to mass-casualty weapons, though documented use remains conventional. Terrorist adoption of AI has thus advanced further and more systematically than prior analysis has recognized, making it a present and growing reality that warrants attention from policymakers, security communities, and AI developers.&#8221;</em></p></li></ul></li><li><p><strong>UNESCO </strong><a href="https://unesdoc.unesco.org/ark:/48223/pf0000398609.locale=en">published</a> a practical guide, titled<em><strong> &#8220;Integrating AI in TVET: A practical guide for institutions&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This practical guide helps TVET* institutions to approach AI integration as a multistakeholder and institution-wide process. It shows how AI can be embedded across core areas of institutional practice to support meaningful change while mitigating risks.&#8221; (*Technical and vocational education and training)</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-cbb?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-cbb?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-cbb?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) </strong><a href="https://autoriteitpersoonsgegevens.nl/en/current/ransomware-attacks-learn-from-the-mistakes-of-others">published</a> <strong>a report on ransomware attacks to help organizations prevent such attacks.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;A ransomware attack often does more than just shutting down computer systems. It could also jeopardise the personal data of hundreds, and sometimes millions, of people.&#8221; In the report, &#8220;[&#8230;] organisations share their experiences and the AP summarises the key lessons learnt from real-world cases.&#8221;</em></p></li><li><p><em>&#8220;<strong>The tips at a glance: </strong></em></p><ul><li><p><em>Make sure there is a good monitoring system in place to detect attacks early and to prevent access to your systems. </em></p></li><li><p><em>Draw up a plan (on paper) in case your organisation becomes the victim of a cyber attack. Test that plan on a regular basis. </em></p></li><li><p><em>Seek help from outside the organisation if you do not have the necessary expertise. </em></p></li><li><p><em>Know which data your organisation stores and from whom. Do not store data longer than necessary, because data you do not have, cannot be breached. </em></p></li><li><p><em>Provide the victims with information as soon as possible, allowing them to be vigilant right away. See the examples of warning messages on the AP website. </em></p></li><li><p><em>Ransomware costs organisations a fortune. Invest in a high level of cyber security and start by addressing the biggest risks first. Ensure you have reliable and up-to-date backups.&#8221;</em></p></li></ul></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Organizations should use the Dutch DPA&#8217;s real-world case lessons to benchmark their own incident response plans and demonstrate &#8220;appropriate technical and organisational measures&#8221; to supervisory authorities.</mark></p></li><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">The emphasis on data minimization as a ransomware mitigation strategy reinforces that data retention reviews are not merely a compliance exercise &#8212; they also serve as a cybersecurity measure.</mark></p></li></ul></li></ul></li><li><p><strong>Mozilla Foundation</strong> <strong><a href="https://www.mozillafoundation.org/en/nothing-personal/period-ovulation-trackers/">tested</a> six popular period tracker apps to find out how they respect women&#180;s privacy</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong></em>Key takeaways: </p><ul><li><p><em>&#8220;Using a period tracker isn&#8217;t neutral information</em></p></li><li><p><em>Watch out for the in-app browser</em></p></li><li><p><em>Safety and Privacy are sometimes just marketing</em></p></li><li><p><em>Choosing a private app does matter&#8221;</em></p></li></ul></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong><span>The Commission </span><a href="https://digital-strategy.ec.europa.eu/en/news/commission-publishes-new-guidance-support-businesses-implementation-cyber-resilience-act"><span>published</span></a><span> new guidance to support businesses&#8217; implementation of the Cyber Resilience Act. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The new Commission guidance explains how these rules apply in practice. It clarifies which products fall within the scope of the Act, what constitutes a substantial modification, how support periods should be understood, and how to meet reporting obligations and risk assessment requirements.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Manufacturers and developers of products with digital elements should review this guidance immediately, as the CRA&#8217;s vulnerability and incident reporting obligations under Article 14 take effect on September 11, 2026 &#8212; well before the main application date of December 11, 2027.   </mark></p></li><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">The guidance&#8217;s practical examples and use cases are particularly valuable. Although the guidance is non-binding, it will inform how market surveillance authorities interpret and enforce the CRA.</mark></p></li></ul></li></ul></li><li><p><strong>The Forecasting Research Institute</strong> <a href="https://forecastingresearch.org/research/ai-cyber-risks-capabilities">published</a> a working paper, &#8220;<em><strong>Forecasting AI Cyber Risks and Capabilities: Results of a 2025 Pilot Study</strong></em>&#8221;. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;A pilot study investigating how AI capabilities may affect near-term cybersecurity risk, focusing on two high-impact cyberattack pathways: data-damaging worm attacks and cyberattacks against the U.S. electrical grid.&#8221;</em></p></li></ul></li><li><p><strong>Hugging Face</strong> <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">published</a> <strong>the full forensic timeline of OpenAI's rogue-agent breach</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). [&#8230;] We are publishing this level of detail because the technique matters more than the incident, as it reveals the emerging attack capabilities of the frontier agents, how they could be used by rogue actors, and how everyone should be prepared as defenders.&#8221;</em></p></li></ul></li><li><p><strong>Anthropic</strong> also annopunced that <em><strong>&#8220;its AI models hacked into the systems of three organisations on their own</strong>, during a private security experiment.&#8221;</em> (BBC)</p><ul><li><p><em><strong>Why does this matter? </strong></em>According to <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic,</a> <em>&#8220;in a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>New method</strong> <a href="https://news.mit.edu/2026/new-method-keeps-kids-safe-from-illegal-ai-generated-content-0713">is developed</a> that aims t<strong>o keep kids safe from illegal AI-generated content.</strong></p><ul><li><p><em><strong>Why does this matter? </strong></em>A new auditing approach is developed <em>&#8220;that determines whether a model can produce CSAM* without prompting it. [&#8230;] Their technique examines how the inner workings of a model have been adapted, but it never generates an output. By examining hidden representations, it can reliably infer whether a model has been specialized to produce harmful imagery.&#8221; (*child sexual abuse material)</em></p></li></ul></li><li><p><strong>A new transparency report</strong> <a href="https://www.esafety.gov.au/newsroom/media-releases/esafety-report-reveals-big-tech-blind-spots-in-protecting-children-and-young-adults-from-sexual-extortion">released</a> by <strong>eSafety (Australia)</strong> reveals <strong>significant gaps in how major online platforms are tackling child sexual exploitation and abuse.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Apple, Discord, Google, Meta, Microsoft, Snap and WhatsApp are required to report to eSafety every six months over a two-year period on their compliance with the Basic Online Safety Expectations.&#8221;</em></p></li><li><p><em>&#8220;It is a particularly damaging form of online blackmail, where perpetrators share or threaten to share intimate material unless victims comply with demands. Reports of this abuse continue to rise. Between 1 July and 31 December 2025, eSafety received more than 2,000 complaints about sexual extortion, with young men aged 18 to 24 the most affected.&#8221;</em></p></li><li><p><em>&#8220;Gaps in reporting tools also persist across services like WhatsApp, iMessage, Discord and Google Messages, with some services lacking clear, accessible ways for users to report sexual extortion or child abuse or failing to provide dedicated reporting categories for these harms.&#8221;</em></p></li><li><p><em>&#8220;The report also highlights the challenges of detecting harm in private messaging and video environments, where both sexual extortion and livestreamed sexual abuse often occur.&#8221;</em></p><p></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-cbb?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-cbb?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><a href="https://arxiv.org/abs/2605.04522">&#8220;</a><strong><a href="https://arxiv.org/abs/2605.04522">DAO-enabled decentralized physical AI: A new paradigm for human-machine collaboration&#8221;</a></strong></em><strong> </strong>(authors: Ballandies et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;We propose DAO-enabled decentralized physical AI (DePAI), a democratic architecture for coordinating humans and autonomous machines in the operation and governance of physical-digital systems. We (1) synthesize foundations in blockchains, decentralized autonomous organizations (DAOs), and cryptoeconomics; (2) connect DAO design with digital-democracy research on deliberation and voting, showing how each can advance the other; (3) position DAO-governed decentralized physical infrastructure networks (DePIN) within a vertically integrated stack that links energy and sensing to connectivity, storage/compute, models, and robots; (4) show how these elements specify workflows that couple machine execution with human oversight, enabling enhanced self-organization of techno-socio-economic systems, which we call DePAI; and (5) analyze risks, including security, centralization, incentive failure, legal exposure, and the crowding-out of intrinsic motivation, and argue for value-sensitive design and continuously adaptive governance. DePAI offers a path to scalable, resilient self-organization that integrates physical infrastructure, AI, and community ownership under transparent rules, on-chain incentives, and permissionless participation, aiming to preserve human autonomy.&#8221;</em></p></li></ul></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ay6Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 424w, /__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 848w, /__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ay6Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png" width="850" height="497" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:497,&quot;width&quot;:850,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83431,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/206415537?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 424w, /__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 848w, /__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ay6Q!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12601187-6690-4204-9f7e-30c187eb4e1e_850x497.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">Source: <em><a href="https://arxiv.org/pdf/2605.04522">&#8220;DAO-enabled decentralized physical AI: A new paradigm for human-machine collaboration&#8221;</a> (authors: Ballandies et al.), Figure 1, p. 11</em></p><ul><li><p><em><strong><a href="https://arxiv.org/abs/2606.18147">&#8220;WEQA: Wearable hEalth Question Answering with Query-Adaptive Agentic Reasoning&#8221;</a></strong></em> (authors: Zhang et al.)</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;[&#8230;] we propose WEQA, a query-adaptive agent framework that unifies LLM reasoning with specialized wearable analytical and modeling tools. [&#8230;] Experiments show that our framework is 24% more accurate than LLM and agentic baselines, and a blinded study with 12 medical experts and 8 users shows substantial gains in usefulness and clinical soundness.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>DeepSeek upgraded DeepSeek-V4-Flash-0731</strong>. (<a href="https://www.marktechpost.com/2026/07/31/deepseek-upgrades-deepseek-v4-flash-0731-with-major-agentic-and-coding-gains/">MarkTechPost</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>According to <a href="https://huggingface.co/blog/ResterChed/deepseek-v4-flash-official-release">HuggingFace</a>, &#8220;<span>a model with </span><strong>13B activated parameters</strong><span> now beats the 49B-active </span><strong>V4-Pro preview</strong><span> on all nine agentic benchmarks DeepSeek publishes &#8212; at a fraction of the cost to run.&#8221;</span></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!HEjE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 424w, /__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 848w, /__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 1272w, /__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!HEjE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png" width="997" height="626" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:626,&quot;width&quot;:997,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78808,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/206813608?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 424w, /__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 848w, /__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 1272w, /__u/substackcdn.com/image/fetch/$s_!HEjE!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5996bd0a-73ca-413b-8536-9166d0e86d2c_997x626.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://huggingface.co/blog/ResterChed/deepseek-v4-flash-official-release">HuggingFace</a></em></p></li></ul></li><li><p><strong>Moonshot AI</strong> (the creator of Kimi K3) <strong><a href="https://finance.yahoo.com/technology/ai/articles/chinese-ai-model-wiped-hundreds-110755972.html">was valued</a> at $35 billion</strong>. (<a href="https://finance.yahoo.com/technology/ai/articles/chinese-ai-model-wiped-hundreds-110755972.html">Yahoo!Finance</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>Kimi K3, &#8220;the 2.8 trillion-parameter model was the largest open-weight AI system ever released, with performance approaching frontier models from Anthropic and OpenAI at roughly half the API cost.&#8221;</em></p></li></ul></li><li><p><strong>NVIDIA</strong>, with more than 70 other founding members, <strong><a href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/">formed</a> new alliance to build and share open tools that promote responsible use of and trust in AI</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>Cybersecurity is among the top three beneficiaries of open source software. The Open Secure AI Alliance [&#8230;] will work to remediate and disclose vulnerabilities using open technologies. [&#8230;] That is the mission of the Open Secure AI Alliance: to ensure defenders everywhere have open, frontier tools they can trust and control.&#8221;</span></em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[DSA tracker #10 ]]></title><description><![CDATA[Developments in enforcing the Digital Services Act]]></description><link>https://datalawgy.substack.com/p/dsa-tracker-10</link><guid isPermaLink="false">https://datalawgy.substack.com/p/dsa-tracker-10</guid><pubDate>Thu, 30 Jul 2026 08:01:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZvHo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There are more and more developments regarding the implementation and enforcement of the DSA and more resources are available regarding the application of thes Regulation. In this newsletter, I summarize the most important events and news related to the application of the DSA.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ol><li><p><strong>Regulatory &amp; enforcement actions</strong></p></li></ol><ul><li><p><strong><span>The Commission </span><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1654"><span>fined</span></a><span> AliExpress &#8364;550 million for breaching the DSA.</span></strong></p><ul><li><p><em><strong>What does this mean? </strong>&#8220;The European Commission fined AliExpress &#8364;550 million for breaching its obligations under the Digital Services Act (DSA) to diligently assess and mitigate risks relating to the sale of illegal, unsafe or counterfeit products on its e-commerce platform.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;AliExpress fell short of its obligation under the DSA to diligently assess the risk of dissemination of illegal, unsafe, or counterfeit products through its services in multiple ways:</em></p><ul><li><p><em><strong>AliExpress did not properly evaluate whether it had sufficient staff to review potentially illegal products.</strong> [&#8230;]</em></p></li><li><p><em><strong>AliExpress inadequately assessed how its recommender and advertising systems exacerbate the spread of illegal products</strong>. [&#8230;]</em></p></li><li><p><em><strong>AliExpress lacked quantitative metrics in its assessment.</strong> [&#8230;]</em></p></li></ul><p><em>AliExpress failed to take effective measures to reduce the risk of dissemination of illegal products. The Commission identified, in particular, the following shortcomings:</em></p><ul><li><p><em><strong>AliExpress&#8217; system to detect illegal products did not work properly.</strong> [&#8230;]</em></p></li><li><p><em><strong>AliExpress did not properly enforce its penalty policy for traders selling illegal products.</strong> [&#8230;]</em></p></li><li><p><em><strong>AliExpress&#8217; product compliance checks could be easily circumvented through mis-categorisation of products. </strong>[&#8230;]</em></p></li><li><p><em><strong>AliExpress failed to adequately prevent the spread of counterfeit products.</strong> [&#8230;]&#8221;</em></p></li></ul></li><li><p><em><strong>What are the next steps?</strong></em> <em>&#8220;[&#8230;] AliExpress now has until 20 October 2026 to submit an action plan to the Commission. The plan must set out measures to remedy the breach of its obligations to assess and mitigate systemic risks. The European Board for Digital Services will have one month from the receipt of the plan to issue its opinion. The Commission will then have a further month to adopt its final decision and set a reasonable period for implementation. Failure to comply with the non-compliance decision may lead to periodic penalty payments. The Commission continues to engage with AliExpress to ensure compliance with the decision and with the DSA more generally.&#8221;</em></p></li></ul></li><li><p><strong>The Commission <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1679">preliminary found</a> TikTok in breach of DSA for failing to ensure safe accounts for minors.</strong></p><ul><li><p><em><strong>What does this mean? </strong>&#8220;The Commission preliminarily considers that TikTok &#8211; in line with <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-protection-minors">the Guidelines on the protection of minors</a> &#8211; should adjust the default settings of minors&#8217; &#8216;public&#8217; accounts, so that their content is, by default, visible only to TikTok users whom the minor has accepted. While older minors may have the option to share their content with a broader audience on TikTok, the content should under no circumstances be accessible to a global audience outside the platform. Moreover, TikTok should refrain from recommending minors&#8217; content to other TikTok users through the For You Feed.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;On TikTok, minors can choose to set their account as &#8216;public&#8217;. This means that any user, including those without a TikTok account, may be able to view minors&#8217; content. This setting also allows content published by &#8216;older&#8217; minors (16-17 years old) to be recommended to any other TikTok user through the For You Feed. This exposure could result in unwanted contact from potential perpetrators and a risk that content can be used for cyberbullying. This feature potentially gives strangers a window into a child&#8217;s life. In addition, since what minors publish may stay online forever and follow them into adulthood, the feature comes with risks of potentially life-long consequences. Even when minors choose private accounts, their accounts can be easily found through the &#8216;following&#8217; and &#8216;followers&#8217; lists of other users, and their profile photos remain accessible to anyone, including users without a TikTok account. TikTok&#8217;s settings continue to expose them to risks &#8211; including unwanted contact, cyberbullying, or predatory behaviour.&#8221;</em></p></li><li><p><em><strong>What are the next steps?</strong></em> <em>&#8220;TikTok now has the possibility to examine the documents in the Commission&#8217;s investigation files and reply in writing to the Commission&#8217;s preliminary findings. In parallel, the European Board for Digital Services will be consulted. If the Commission&#8217;s views are ultimately confirmed, the Commission may issue a non-compliance decision, which can trigger a fine determined by the nature, gravity, recurrence, and duration of the infringement. The amount of the fine must be proportionate and shall in no case exceed 6% of a provider&#8217;s global annual turnover.&#8221;</em></p></li></ul></li><li><p><strong>The European Board for Digital Services</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/second-report-systemic-risks-very-large-online-platforms-and-search-engines-under-digital-services">published</a> <strong>its second report</strong> in cooperation with the Commission pursuant to Article 35(2) DSA <strong>on the  </strong></p><p><strong>most prominent and recurrent systemic risk as well as mitigation measures. </strong></p><ul><li><p><em><strong>What does this mean? </strong>&#8220;The report identifies systemic risks - such as the spread of illegal content or threats to fundamental rights - occurring on very large online platforms. It also gives an overview of the mitigation measures taken by platforms to counter identified risks.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;Article 35(2) DSA sets out the requirement for the Board, in cooperation with the Commission, to publish comprehensive reports once a year. Article 35(2) DSA requires the identification and assessment of the most prominent and recurrent systemic risks in the Union and in the Member States, as well as best practices for their mitigation. This report is the second year&#8217;s edition of the Article 35(2) report. The first edition was adopted by the Board and published on 18 November 2025.&#8221;</em></p></li><li><p><em><strong>What are the next steps?</strong></em> <em>&#8220;The aim of this Article 35(2) report is to provide an overview of the most prominent and recurrent systemic risks that have been identified by the designated providers as stemming from their services, as well as by third-party stakeholders, such as academics, independent researchers, civil society organisations (&#8220;CSOs&#8221;), trusted flaggers and Out-of-Court Dispute Settlement Bodies (&#8220;ODSBs&#8221;), and an overview of certain risk mitigation practices. With regard to risk mitigation, this second edition, like the first one, focuses on reported practices without singling out any as &#8220;best&#8221; or &#8220;good&#8221; practice. Over time, and in light of accumulating experience with DSA implementation and enforcement in practice, future editions of this report will also aim to identify evolving best practices for the mitigation of systemic risks.&#8221;</em></p></li></ul></li><li><p><strong>The European Commission</strong> <strong><a href="https://digital-strategy.ec.europa.eu/en/news/commission-accepts-xs-corrective-measures-terminate-breaches-dsa">has accepted</a> X&#8217;s action plan to comply with transparency obligations and researchers&#8217; access to data</strong>, under the DSA.</p><ul><li><p><em><strong>What does this mean?</strong> &#8220;To provide a functional advertisement repository, in line with the standards required by the Digital Services Act, X committed to implement the following corrective measures:</em></p><ul><li><p><em><strong>Enhance the repository&#8217;s search functionality</strong> by introducing additional search filters, such as those based on ad content and targeting criteria.</em></p></li><li><p><em><strong>Display search results directly</strong> on the interface of the ad repository rather than on separate Excels.</em></p></li><li><p><em><strong>Improve the repository&#8217;s response speed </strong>reducing the response time from 200 seconds to the minimum time technically achievable.</em></p></li><li><p><em><strong>Provide additional information about advertisements,</strong> including the full content of the advertisement and the URLs to which advertisements redirect users.</em></p></li><li><p><em><strong>Enable access to the repository via an API</strong>.</em></p></li></ul><p><em>Regarding the breaches concerning the obligation to grant researchers access to public data, X will take the following corrective measures:</em></p><ul><li><p><em><strong>Revise and improve its screening process </strong>for applications by researchers to access its public data via its API, ensuring eligible researchers are not excluded in error.</em></p></li><li><p><em><strong>Provide eligible researchers with access to data free-of-charge</strong>.</em></p></li><li><p><em><strong>Ensure timely access for eligible researchers,</strong> including to the appropriate volumes of data. X commits to reduce significantly the processing time for researcher applications, including by avoiding unnecessary exchanges with applicants.</em></p></li><li><p><em><strong>Update its terms and conditions</strong> to explicitly state that eligible researchers are not contractually prohibited from scraping publicly available data.&#8221;</em></p></li></ul></li></ul></li><li><p><strong><span>The European Commission </span><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1579"><span>preliminarily found</span></a><span> Meta in breach of the DSA</span></strong><span> </span><strong><span>for the addictive design of Instagram and Facebook</span></strong><span>. The investigation focuses on features such as infinite scroll, autoplay, push notifications, and the platforms' highly personalised recommender systems.</span></p><ul><li><p><em><strong>What does this mean? </strong>&#8220;<strong>Risk assessment</strong>: The Commission&#8217;s investigation indicates that Meta did not adequately assess the risks of its addictive design on the physical and mental wellbeing of users, including minors and vulnerable adults. For example, Meta did not consider certain design features of Instagram and Facebook, such as highly personalised recommendations, autoplay and infinite scroll, which constantly show users new content. These features fuel the user&#8217;s urge to keep scrolling and shift the brain into &#8216;autopilot mode&#8217;, contributing to unhealthy habits and compulsive use. Moreover, Meta disregarded available information about the time minors spend on Instagram or Facebook at night and how the optimisation of its different formats - such as reels and stories - could lead to excessive or compulsive use of the services.&#8221;</em></p></li><li><p><em>&#8220;<strong>Risk mitigation measures:</strong> Evidence also shows that Meta&#8217;s current mitigation measures failed to effectively tackle the risks stemming from its addictive design. For example, Instagram&#8217;s and Facebook&#8217;s time management tools, including those activated by default for teens, can be easily dismissed and do not lead to a meaningful reduction and control of the usage of the service. Moreover, the Commission considers that Meta&#8217;s parental controls are only effective if parents and guardians possess adequate technical expertise, as well as devote effort and time to understand them effectively. This undermines the efficiency of such measures in addressing the inherent risks posed by Instagram and Facebook&#8217;s addictive design.</em></p><p><em>Meta&#8217;s awareness-raising measures, such as tips and links to mental health resources available via a separate &#8216;safety centre&#8217; page, do not seem to sufficiently mitigate the risk of addictive design on Facebook and Instagram. At this stage of the investigation, the Commission considers that Meta needs to implement design changes to both Instagram and Facebook. For instance, by disabling key addictive features such as &#8216;autoplay&#8217; and &#8216;infinite scroll&#8217; by default, implementing effective &#8216;screen time breaks&#8217;, and adapting its recommender system to make it less engagement-oriented.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;The Commission&#8217;s preliminary findings today are part of its <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_24_2664">formal proceedings to investigate Meta&#8217;s</a> compliance with the Digital Services Act, launched on 16 May 2024. [&#8230;] This investigation also covers concerns about the age assurance measures Meta has put in place for minors below 13 years old, for which <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_920">preliminary findings were adopted</a> on 29 April 2026. Separately, the Commission continues its investigation into so-called &#8216;rabbit hole&#8217; effects caused by the design of Facebook&#8217;s and Instagram&#8217;s recommender systems, which may exploit minors&#8217; vulnerabilities and inexperience.&#8221;</em></p></li><li><p><em><strong>What are the next steps?</strong></em> <em>&#8220;Meta now has the possibility to exercise its right to defence. It may examine the documents in the Commission&#8217;s investigation files and reply in writing to the Commission&#8217;s preliminary findings. In parallel, the European Board for Digital Services will be consulted. If the Commission&#8217;s views are ultimately confirmed, the Commission may issue a non-compliance decision, which can trigger a fine proportionate to the nature, gravity, recurrence and duration of the infringement, capped at 6% of the total worldwide annual turnover of the provider.&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/dsa-tracker-10?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/dsa-tracker-10?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/dsa-tracker-10?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><ol start="2"><li><p><strong>Guidelines, opinions, reports &amp; more</strong></p></li></ol><ul><li><p><strong><span>The European Commission</span></strong><span> </span><a href="https://commission.europa.eu/topics/digital-economy-and-society/protecting-children-online/special-panel_en"><span>has published</span></a><span> t</span><strong><span>he final report of the Special Panel on Child Safety Online</span></strong><span>.</span></p><ul><li><p><em><strong>What does this mean? </strong></em><strong>Recommendations on age-appropriate use of social </strong></p><p><strong>media and other digital services:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ZvHo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 424w, /__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 848w, /__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ZvHo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png" width="588" height="735" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:735,&quot;width&quot;:588,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:101998,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/198842928?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 424w, /__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 848w, /__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ZvHo!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2646d55f-0b47-435e-bc7b-f7a3f99882d3_588x735.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://commission.europa.eu/document/download/d833504d-5ec3-4fac-945f-38e7d0bd5326_en?filename=Special-panel-report.pdf">Child safety online</a>, p. 17</em></p></li><li><p><strong>Recommendations to protect children and adolescents online:</strong><em> </em></p><ul><li><p><em>Propose a harmonised EU-wide access restriction to social media and other digital services for children under 13. </em></p></li><li><p><em>Introduce effective age-assurance systems to check age and underpin safety-by design and age-appropriate approaches to protect and empower minors online. </em></p></li><li><p><em>Extend and harmonise rules on key safety features in the design of social media and other digital services. </em></p></li><li><p><em>Shift the burden of proof to social media and other digital services providers to demonstrate that their products and services are safe for minors. </em></p></li><li><p><em>Strengthen enforcement and evaluation capacities.</em></p></li><li><p><em>Swiftly adopt measures to ensure social media and other digital services providers have clear obligations to prevent, detect, report and block child sexual abuse online, including in interpersonal communication.</em></p></li><li><p><em>Member States can introduce additional precautionary access restrictions to social media and other digital services as of 13.</em></p></li><li><p><em>Strengthen the enforcement of rules on researchers&#8217; access to and scrutiny of data.</em></p></li></ul></li><li><p><strong>Recommendations to empower children and adolescents online:</strong></p><ul><li><p><em>Expand safe opportunities for minors to actively participate in shaping the social media+ environment.</em></p></li><li><p><em>Strengthen complaint mechanisms and consumer rights for children and adolescents.</em></p></li><li><p><em>Mainstream digital education and literacy actions for minors, parents and caregivers, teachers and educators.</em></p></li><li><p><em>Create more opportunities and adequate infrastructure to support offline activities.</em></p></li><li><p><em>Promote the co-creation of Guidelines for Parents.</em></p></li><li><p><em>Ensure sufficient public funding and common standards for civil society organisations and peer counselling.</em></p></li><li><p><em>Make available long-term funding for European large-scale longitudinal research and continue supporting randomised control trials.</em></p></li></ul></li><li><p><em><strong>What is the background to this?</strong> &#8220;The panel has brought together young people and experts from across the EU, including in health, neuroscience, psychology, computer science, child rights, and digital literacy. From March to June 2026, the panel met three times to explore both the opportunities and the risks of children spending time online. Discussions looked at how to better support parents and caregivers, while highlighting key lessons and good practices from across the EU and beyond.&#8221;</em></p></li></ul></li><li><p><strong>The DSA Observatory</strong><span> </span><a href="https://dsa-observatory.eu/2026/07/13/platform-governance-and-technology-facilitated-gender-based-violence-positioning-the-dsa-in-the-eus-legal-framework/"><span>published</span></a><span> an analysis, </span><em><span>&#8220;</span><strong>Platform Governance and Technology-Facilitated Gender-Based Violence: Positioning the DSA in the EU&#8217;s Legal Framework&#8221;</strong></em></p><ul><li><p><em><strong>What is it about?</strong> &#8220;This post examines technology-facilitated gender-based violence (TFGBV) as a systemic phenomenon shaped by platform design and cross-platform ecosystems, and maps the main EU legal instruments available to address it. It argues that while the Digital Services Act&#8217;s systemic risk framework is particularly well suited to tackling the structural drivers of TFGBV, its promise has yet to be realised in practice through implementation and enforcement.&#8221;</em></p></li></ul></li><li><p><strong>The bff</strong> (Federal Association of Women&#8217;s Counselling Centres and Women&#8217;s Emergency Hotlines in Germany) <a href="https://www.frauen-gegen-gewalt.de/de/studien-und-positionspapiere/policy-paper-zum-digital-services-act-und-digitaler-geschlechtsspezifischer-gewalt-2026.html">published</a> a <strong>policy paper on the Digital Services Act and Digital Gender-Based Violence.</strong><em> (The policy paper is in German.)</em></p><ul><li><p><em><strong>What is it about?</strong> &#8220;Platforms decide on a daily basis how visible violence is &#8211; and how well those affected are protected. Our new policy paper shows how large online platforms have so far failed to adequately implement their obligations under the Digital Services Act (DSA) when it comes to (digital) gender-based violence. On the basis of the risk analyses according to Art. 34 DSA of platforms such as Instagram, TikTok, Snapchat, Pornhub and XVideos, we analyse key protection gaps in risk analyses, reporting channels and contact points. We show why gender-based violence is systematically trivialized, how manipulative designs prevent those affected from reporting &#8211; and why violence in the social environment continues to remain invisible. The paper formulates concrete, feminist recommendations on Art. 12, 16, 34 and 35 DSA: for binding standards, intersectional risk analyses and reporting channels that are actually easily accessible.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ol start="3"><li><p><strong>Further DSA resources</strong></p></li></ol><ul><li><p><a href="https://transparency.dsa.ec.europa.eu/">DSA Transparency Database</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-whistleblower-tool">DSA whistleblower tool</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-enforcement">The enforcement framework under the DSA</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses">List of designated very large online platforms and search engines under DSA</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-brings-transparency">Transparency reports of VLOPs and VLOSEs</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-board">European Board for Digital Services</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-dscs#1720699867912-0">Digital Services Coordinators</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/trusted-flaggers-under-dsa">Trusted flaggers under the DSA</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/code-conduct-disinformation">The Code of Conduct on Disinformation</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/code-conduct-countering-illegal-hate-speech-online">The Code of conduct on countering illegal hate speech online +</a></p></li><li><p><a href="https://www.disinfo.eu/">EU Disinfo LAB</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 30]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-46b</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-46b</guid><pubDate>Fri, 24 Jul 2026 08:01:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Rgoc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p>In a Decree of the Prime Minister of Vietnam, <strong>&#8220;high-risk&#8221; AI systems under Vietnam&#8217;s AI Law and implementing decree have been formally identified</strong>. <em>(See <a href="https://www.hlc.com/en/publications/vietnam-designates-highrisk-ai-systems-what-businesses-need-to-know">Hogan Lovells Cadwalader&#180;s overview</a> about the Decree and its possible implications for developing, supplying or deploying AI in Vietnam.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This is a significant development because only AI systems meeting the specific criteria set out in this taxonomy will be subject to Vietnam&#8217;s enhanced compliance obligations.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Commission <a href="https://commission.europa.eu/news-and-media/news/commission-finds-republic-korea-continues-provide-adequate-level-protection-personal-data-2026-07-23_en">found</a> that Republic of Korea continues to provide an adequate level of protection of personal data.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The Commission concluded today its first review of the 2021 </span><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022D0254">adequacy decision</a><span> for the Republic of Korea, which allows the free flow of personal data from the EU to this country. [&#8230;] The EU and Korean data protection frameworks have converged further, notably following amendments to South Korean law that strengthened the rights of data subject. The report also lays out recommendations</span><strong> </strong><span>to further reinforce some of the safeguards provided by the South Korean framework, in particular with respect to data transfers to third countries and enforcement. [&#8230;] Mutual data flows between the EU and Korea benefit more than 500 million people. They also enhance the benefits of a trade relationship worth more than &#8364;150 billion per year.&#8221;</span></em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Companies transferring personal data between the EU and Korea can continue to rely on the adequacy mechanism without needing to implement Standard Contractual Clauses or other Chapter V GDPR transfer tools for that data flow.</mark></em></p></li><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Because the Commission flagged onward transfers to third countries and enforcement as areas for further reinforcement, compliance teams should monitor for follow-up amendments to Korean law.</mark></em></p></li></ul></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>France&#180;s parliament</strong> <a href="https://www.bbc.com/news/articles/cq56l9p4y93o">has approved</a> a <strong>ban on social media for under-15s from January 2027</strong>. (<a href="https://www.bbc.com/news/articles/cq56l9p4y93o">BBC</a>) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The law will mean everyone in France must verify their age to access social media and comes as the UK and EU are developing their own limits in response to concerns for children's mental health.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Social media platforms operating in France should begin scoping age verification mechanisms well ahead of the January 2027 deadline.</mark></em></p></li><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Privacy teams should evaluate the data protection implications of any age verification method chosen against GDPR requirements, as these methods often introduce new categories of sensitive personal data processing.</mark></em></p></li><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Given parallel efforts in different jurisdictions, multinational platforms should track potential divergence in age-verification standards across jurisdictions to avoid a fragmented, jurisdiction-by-jurisdiction compliance approach.</mark></em></p></li></ul></li></ul></li><li><p><strong>The Justice Ministry of Japan</strong> <a href="https://www.japantimes.co.jp/news/2026/07/14/japan/politics/japan-ai-voice-covers-protection-measures">has come up</a> with <strong>a draft report calling for the protection of the voices and images of famous individuals</strong> as the use of generative AI grows.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;If an act affects a person&#8217;s feelings of honor and peace of mind beyond a tolerable limit, it could constitute an illegal act, according to the draft. [&#8230;] The draft also noted criteria for determining the similarity between the voices of famous individuals and those created by generative AI as well as potential violations of the &#8220;right of publicity,&#8221; which allows celebrities to control the commercial value of their portraits.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>US appeals court</strong> <strong>overturnd Clearview AI settlement</strong>. (<a href="https://www.reuters.com/legal/government/us-appeals-court-overturns-clearview-ai-settlement-2026-07-13/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>The court &#8220;did not object to <a href="https://www.reuters.com/legal/litigation/us-judge-approves-novel-clearview-ai-class-action-settlement-2025-03-21/">the settlement&#8217;s unique structure</a>, which gave consumers a potential stake in Clearview&#8217;s future value, but ruled that a segment of class members &#8203;were inadequately represented.&#8221;</em></p></li><li><p><em>&#8220;Clearview faced allegations that it scraped billions of facial images from the &#8203;internet and sold the &#8203;information without consent, &#8288;violating an Illinois biometric privacy law. Clearview denied any misconduct.&#8221;</em></p></li><li><p><em><strong>Note:</strong></em> <span>The need for a prohibition on the creation and expansion of facial recognition databases through </span><strong>untargeted web scraping</strong><span> in the EU (see Art. 5 of the AI Act) was partly based on the activities of </span>Clearview AI.<span> Although regulatory and judicial proceedings have been ongoing against the company for years, the company continued its activity (according to a </span><a href="https://www.bbc.com/news/technology-67133157">BBC article</a><span> published in October 2023, Clearview AI has collected about 30 billion images from the internet into their database, and according to </span><a href="https://www.bbc.com/news/technology-65057011">news reports</a><span>, more than 1 million search requests were initiated by the police in the US until 2023).</span></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Data Protection Board (EDPB)</strong> <a href="https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en">has published</a> <strong>a binding decision  </strong>under Art.65(1)(a) GDPR <strong>concerning a dispute submitted by the Belgian Data Protection Authority about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT)</strong>, a public broadcasting company based in Belgium. <span>The complaint was lodged with the Austrian DPA by the Austrian-based NGO </span><em><span>Noyb</span></em><span> on behalf of an individual. It concerns the use of cookie banners on the website of </span><em><span>VRT</span></em><span>. </span>The Belgian DPA acted as the lead supervisory authority (LSA). <em>(The fuill decision is available <a href="https://www.edpb.europa.eu/documents/edpb-binding-decisions/binding-decision-12026-on-the-dispute-submitted-by-the-belgian-sa_en">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>[&#8230;] the EDPB instructed the LSA not to dismiss the complaint, but to assess it instead on its merits and to submit a new draft decision to the CSAs* under Art.60(3) GDPR.&#8221; (*CSA: Concerned Supervisory Authority)</span></em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Organizations relying on cookie banners should treat this decision as a signal that lead supervisory authorities face growing pressure to fully substantively assess cross-border cookie complaints, increasing the likelihood of enforcement actions.</mark></em></p></li><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Compliance teams should proactively audit cookie banner design and consent flows.</mark></em></p></li></ul></li></ul></li><li><p><strong>The French Data Protection Authority (CNIL)</strong> <a href="https://www.cnil.fr/fr/23-nouvelles-sanctions-simplifiees">has issued</a> <strong>23 new sanctions</strong> (19 of which originate from complaints) since January, 2026 under the simplified procedure <strong>due to excessive video surveillance, cookies, non-respect for the rights of individuals or lack of cooperation with the CNIL</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;As a reminder, video surveillance cameras installed in workplaces, whether or not they are open to the public, must respect the privacy of employees. Under no circumstances should the cameras permanently film employees if no exceptional circumstances justify it.&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] the CNIL found that the information banners relating to cookies did not include complete information (lack of information on the purposes of the cookies and the data controller, on how to refuse or withdraw consent). [&#8230;] Some organizations also placed cookies subject to consent (this is the case, for example, advertising cookies) before any action on the part of the user or did not offer a way for the user to refuse cookies as simply as to accept them.&#8221;</em></p></li></ul></li><li><p><strong>Korea&#180;s privacy watchdog fined TikTok 10.3 billion won ($7 million) for unlawfully collecting and using users&#180; behavioral data</strong> from third-party services to personalize advertisements. The watchdog ordered<strong> corrective measures against two Apple subsidiaries and fined them a combined 252 million won</strong> for personal information violations, <strong>such as collecting voice recordings and transcripts of users of the company&#180;s Siri voice assistant without consent. </strong>(<a href="https://www.koreatimes.co.kr/amp/business/companies/20260723/tiktok-fined-7-mil-for-unlawful-collection-of-user-data-for-ads">The Korea Times</a>)</p></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The Commission <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1670">fined</a> Google &#8364;890 million</strong> for breaches of the Digital Markets Act.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] <span>the European Commission took two decisions finding non-compliance by Google with the </span><a href="https://digital-markets-act.ec.europa.eu/about-dma_en">Digital Markets Act (DMA)</a><span> for self-preferencing its own services on Google Search, and for putting in place restrictions on businesses to direct consumers to alternative, often cheaper, purchase channels on Google Play (steering). In this regard, the Commission issued Google a fine of &#8364;460 million and a fine of &#8364;430 million respectively.&#8221;</span></em></p></li></ul></li><li><p><strong>A coalition of 42 attorneys general</strong> <a href="https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-leads-multistate-settlement-of-bankruptcy-claims-against-23andme">announced</a> <strong>a settlement with the bankruptcy trustee for direct-to-consumer genetic testing company 23andMe</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This data breach exposed a wide range of data about 23andMe customers, including in some cases genetic ancestry information, and subsets of this data were subsequently published for sale on the dark web.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;The International Telecommunication Union (ITU)</strong>, the UN agency for digital technologies, <a href="https://www.itu.int/en/mediacentre/Pages/PR-2026-07-09-focus-group-agentic-AI.aspx">announced</a> <strong>a new initiative to develop frameworks for trusted digital identity and to ensure that the behaviour of AI agents remains trustworthy and accountable</strong> throughout their lifecycle.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;While agentic AI promises major gains in productivity, it also introduces new risks ranging from autonomous agents impersonating people or organizations, to taking unauthorized actions across interconnected systems. The ITU Focus Group will address these challenges by developing frameworks that preserve meaningful human control for tasks such as executing financial transactions and operating critical infrastructure.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Legal teams drafting AI agent deployment policies should track this initiative closely, since frameworks addressing agent impersonation and unauthorized cross-system actions may eventually shape liability allocation and identity verification requirements for agentic AI products.</mark></em></p></li></ul></li></ul></li><li><p><strong>The Center for Security and Emerging Technology (CSET)</strong> <a href="https://cset.georgetown.edu/publication/identifying-the-ai-development-workforce/">published</a> an analysis <strong>on the U.S. workforce directly involved in AI system developments</strong>, separating it from people who merely use AI tools or whose roles may be affected by AI.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This report [&#8230;] presents initial findings on the size and share of AI development jobs* in the U.S. labor market.&#8221; (*&#8220;We define AI development jobs as roles that require specialized knowledge, skills, and abilities and directly contribute to the technical development of AI systems.&#8221;)</em></p></li><li><p>Main findings:</p><ul><li><p><em>&#8220;<strong>Approximately 1.6 million AI development job postings</strong> in the United States since 2010, including 331,445 postings in 2025. </em></p></li><li><p><em><strong>Approximately 519,000 AI development workers</strong> in the United States as of March 2026. </em></p></li><li><p><em>AI development roles are a small portion of the total U.S. workforce, accounting for less than 1% of both total labor demand and employment. </em></p></li><li><p><em>AI development is concentrated in highly technical occupations, although among these occupations the proportion of roles that directly support AI development varies widely.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The OECD and the European Commission</strong> <a href="https://www.oecd.org/en/publications/empowering-learners-for-the-age-of-ai_65cd27d4-en.html">published</a> <strong>an AI Literacy Framework for Primary and Secondary Education.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] This publication establishes a common framework for AI literacy, outlining desired outcomes for primary and secondary learners and guiding stakeholders in supporting those outcomes both inside and outside the classroom.&#8221;</em></p></li></ul></li><li><p><strong>The trainees of the European Data Protection Supervisor and the European Data Protection Board</strong> organised a conference <strong>exploring the growing role of AI in modern recruitment and HR processes</strong>. <em>If you missed it, you can rewatch the recording of the conference <a href="https://www.europarl.europa.eu/streaming/?event=20260709-1400-SPECIAL-OTHER">here</a>. </em></p><ul><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">HR and compliance teams deploying AI in recruitment should note that AI-driven hiring tools intersect both GDPR (automated decision-making, profiling) and, where applicable, AI Act high-risk employment use case obligations, warranting a combined privacy and AI compliance review rather than a siloed assessment.</mark></em></p></li></ul></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-46b?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-46b?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-46b?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Spanish Data Protection Authority (AEPD) </strong><a href="https://www.aepd.es/en/guides/quality-data-artificial-intelligence.pdf">published</a> guidance on <em><strong>&#8220;Accuracy, suitability and quality of data in processing personal data with Artificial Intelligence&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This technical note discusses the application of these concepts (accuracy, minimisation, suitability and data quality) in the context of processing to which the GDPR applies. It is aimed at controllers, processors and DPOs, as well as for those involved in the development, testing and maintenance of products or services that require access to personal data sets, such as many types of AI models and systems.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Organizations should use this guidance as a practical checklist for documenting data accuracy, minimization, and suitability assessments during model training and testing, since regulators are increasingly expecting demonstrable data quality controls specific to AI processing.</mark></em></p></li><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Accuracy and quality criteria should be implemented into vendor due diligence and data processing agreements.</mark></em></p></li></ul></li></ul></li><li><p><strong>Singapore&#180;s PDPC</strong> <a href="https://www.pdpc.gov.sg/media-events/pdpc-issues-guidance-for-organisations-on-responsible-use-of-personal-data-in-generative-ai">issued</a> <strong>Guidance for Organisations on Responsible Use of Personal Data in Generative AI.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Organisations can tap on these Guidelines to understand how to responsibly collect and use personal data for GenAI development, especially in situations involving web-scraping and the re-use of data provided for non-GenAI purposes (User Data). The Guidelines also outline the data responsibilities of key GenAI stakeholders and how organisations should handle individual requests concerning the processing of their data for GenAI.&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p>As part of its annual report on data breaches, <strong>the Dutch DPA (AP)</strong> <a href="https://www.autoriteitpersoonsgegevens.nl/en/current/ai-increases-the-risks-of-cyberattacks">raised concerns</a> regarding <strong>AI&#8217;s impact on cyberattacks</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The rapid growth of artificial intelligence (AI) is increasing the risks of cyberattacks. There is a growing risk of phishing and data breaches. [&#8230;] Organisations must take action now and get their digital security in order, according to the AP. Only in this way can they protect people&#8217;s data against increasingly sophisticated forms of cybercrime.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Security and privacy teams should update phishing-awareness training and technical controls to account for AI-generated social engineering.</mark></em></p></li></ul></li></ul></li><li><p><strong>OpenAI</strong> <a href="https://www.npr.org/2026/07/23/g-s1-135085/openai-hacking-ai-models">acknowledged</a> that &#8220;<em>two of its most capable AI models were responsible for the cyberattack targeting AI startup Hugging Face.</em>&#8221; <strong>OpenAI and Hugging Face <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">partnered</a> to address security incident during model evaluation.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The co-founder of Hugging Face, a technology start-up that was </span><strong><a href="https://www.bbc.com/news/articles/c3ek3gvdnj3o">hacked after some of OpenAI's most advanced artificial intelligence (AI) models went rogue</a></strong><span>, said on Thursday that the incident is &#8220;a wake-up call&#8221; for the industry.&#8221;</span></em><span> (</span><a href="https://www.bbc.com/news/articles/cdrvy3pn3r0o"><span>BBC</span></a><span>) </span></p></li><li><p><span>As Clem Delangue, Co-founder and CEO, Hugging Face </span><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"><span>also added</span></a><span>, &#8220;</span><em><span>this incident, possibly the first of its kind, proves a point we&#180;ve long believed: AI safety won&#180;t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.&#8221;</span></em></p></li></ul></li><li><p><strong>The White House</strong> <a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/">launched</a> <strong>Gold Eagle Initiative</strong> <strong>for cybersecurity vulnerability coordination</strong>.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;GOLD EAGLE is a force multiplier, enabling government and industry to collectively identify risks, prioritize action, and strengthen the resilience of the systems that power our economy, national security, and daily life.&#8221;</em></p></li></ul></li><li><p><strong>The European Parliamentary Research Service</strong> <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/789374/EPRS_BRI(2026)789374_EN.pdf">published</a> a briefing <strong>on how the EU can respond to hybrid threats</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;As security challenges increasingly overlap across civilian and military domains, the EU and the North Atlantic Treaty Organization (NATO) aim to ensure complementarity between the EU&#8217;s regulatory and civilian tools and NATO&#8217;s defence and military capabilities through improving coordination and enhancing situational awareness. The European Parliament emphasises that hybrid threats, mainly from Russia, China and Belarus, represent an escalating security challenge for the EU, and calls for a comprehensive EU response, stronger EU&#8211;NATO coordination, enhanced resilience and civil preparedness, targeted countermeasures, and closer cooperation with partner countries.&#8221; </em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical Implications:</mark></strong></em></p><ul><li><p><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Companies in critical sectors (energy, telecom, finance) operating across EU member states should anticipate increased regulatory convergence between civilian cybersecurity frameworks and EU-NATO coordination mechanisms, which may bring new reporting or resilience obligations tied to hybrid threats.</mark></em></p></li></ul></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>The Reuters Institute</strong> <a href="https://reutersinstitute.politics.ox.ac.uk/digital-news-report/2026">published</a> its <strong>Digital News Report 2026</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong></em>Main findings are as follows: </p><ul><li><p><em><strong>&#8220;1. Social media and video networks overtake news websites and apps </strong></em></p><p><em>[&#8230;] social media and video networks are for the first time the single most widely used way of accessing online news (used by 54% of all respondents), ahead of news organisations&#8217; own websites and apps (51%). This shifting composition of news consumption is happening among all age groups.&#8221;</em></p></li><li><p><em><strong>&#8220;2. AI chatbots as a new frontier in intermediated news consumption</strong></em></p><p><em>The use of AI chatbots for news is growing quickly but not as quickly as AI use for other purposes: 10% of people use AI chatbots for news, up from 7% last year. [&#8230;]&#8221; </em></p></li><li><p><em><strong>&#8220;3. Online video marches on</strong></em></p><p><em>For the first time, a majority of people now watch online news video in all 48 Digital News Report markets: 77% of people globally consume online news video each week. [&#8230;] The first wave of social media growth hit newspapers hardest. Now the second wave is affecting news organisations&#8217; TV and video interests. TikTok (growing fastest from a small base, used by 20% globally for news) and Instagram (more modest growth, but a more significant presence &#8211; 26% usage for news) are the fastest growing video-led networks and they are driving much of the change together with YouTube (34% for news). Facebook remains the biggest platform overall for news consumption (used by 43% this year), reversing recent declines.&#8221;</em></p></li><li><p><em><strong>&#8220;4. Creators at the forefront of video growth</strong></em></p><p><em>Around a quarter (27%) of respondents globally get some news from news-focused individual creators or influencers, and almost half (46%) get some news from creators of any type. [&#8230;]&#8221; </em></p></li><li><p><em><strong>&#8220;5. Interest in news falling</strong></em></p><p><em>[&#8230;] A quarter (25%) of respondents are now casual or passive news users who typically only consume news once a week and say they have little to no interest in it, up from 16% in 2021. [&#8230;]&#8221; </em></p></li><li><p><em><strong>&#8220;6. Trust in news at a low</strong></em></p><p><em>Trust in news has fallen in 29 of our 48 markets this year, resulting in a drop overall to the lowest level we have recorded since we started to measure trust in 2015 (37%). [&#8230;]&#8221; </em></p></li><li><p><em><strong>&#8220;7. Paying for news also challenged by the drift away from direct consumption</strong></em></p><p><em>The percentage of people paying for access to online news in the basket of 20 countries we track is unchanged at 17%. Growing reader revenue is likely to prove harder as the flow of people into the subscription funnel coming to news websites and apps reduces. [&#8230;] Significant numbers of people are supporting non-traditional news outlets financially. People mainly pay for news for the direct benefits they get from the content they want to access (81% say this is at least part of the reason for paying). But almost half (46%) of respondents who pay for news also express values-based motivations for paying (such as supporting journalism because of its importance to society) and some news organisations are capitalising on this.&#8221;</em></p></li><li><p><em><strong>&#8220;8. Enduring support for impartiality as an ideal&#8230;</strong></em></p><p><em>[&#8230;] Almost half (45%) of respondents still prefer news which does not take sides, and a similar share (46%) also believe consuming news which does not take sides is best for others in society. [&#8230;]&#8221; </em></p></li><li><p><em><strong>&#8220;&#8230; But misgivings about the reality of news</strong></em></p><p><em>[&#8230;] In 26 countries with significant public service media (PSM) news providers we find variations in agreement with the proposition that public service news has a positive social impact. Across these 26 PSM markets overall, people in the aggregate believe that public service news has a positive impact on life in their countries (37% positive against 22% negative), but this is not the case everywhere. [&#8230;]&#8221;</em></p></li></ul></li></ul></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Rgoc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 424w, /__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 848w, /__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Rgoc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png" width="533" height="540" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:540,&quot;width&quot;:533,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:114185,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/204089404?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 424w, /__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 848w, /__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Rgoc!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09e08ca6-03ea-43cd-8556-e9528ac25fe3_533x540.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: The Reuters Institute&#180;s <a href="https://reutersinstitute.politics.ox.ac.uk/sites/default/files/2026-06/DNR%202026%20FINAL_2.pdf">Digital News Report 2026</a>, p. 8</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-46b?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-46b?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><strong><a href="https://arxiv.org/pdf/2606.12587">&#8220;Strategic Decision Support for AI Agents&#8221;</a></strong></em> (authors: Kiyani et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Traditionally, decision support studies how humans use machine learning models to make better decisions. In modern agentic systems, this division of roles is increasingly reversed: AI agents act on behalf of users, while humans and tools becomes support mechanisms around them. [&#8230;] Departing from the classical view of decision support, we revisit its two basic principles, the cost&#8211;value tradeoff of seeking support and the role of uncertainty quantification, in a setting where AI agents are the central actors. We propose a framework for strategic decision support for AI agents through an optimization problem that minimizes support usage subject to controlling a counterfactual missed-support error: the probability that the agent acts alone on instances where support would have materially improved its output. [&#8230;] we develop an online algorithm that adaptively thresholds such a score and uses randomized exploration to control missed-support error without distributional assumptions. We further introduce a calibration-on-the-fly method that reduces unnecessary support calls online. [&#8230;]&#8221;</em></p></li></ul></li><li><p><em><strong><a href="https://transformer-circuits.pub/2026/workspace/index.html">&#8220;Verbalizable Representations Form a Global Workspace in Language Models&#8221;</a></strong></em> (authors: Gurnee et al.) <em>(Please find an overview about the key findings of the research paper <a href="https://www.anthropic.com/research/global-workspace">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;[&#8230;] we observe that language models maintain a privileged set of internal representations, available for report, modulation, and flexible internal reasoning, atop a much larger volume of automatic processing. We identify these representations using a new interpretability technique, which surfaces the concepts a model is poised to verbalize at any point in its processing. Measuring and intervening on these representations provides us a window into a model&#8217;s thought processes, uncovering internal reasoning and reactions that do not appear in its output.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Proton</strong> <a href="https://proton.me/blog/lumo-2">has revealed</a> <strong>Lumo 2.0</strong>, its AI alternative to AI chatbots, like ChatGPT, Claude, and Gemini, <strong>focusing on privacy</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] it runs on Proton&#8217;s fully European infrastructure, protected by Swiss privacy laws and zero-access encryption.&#8221;</em></p></li></ul></li><li><p><strong>The Swiss Armed Forces</strong> <a href="https://www.heise.de/en/news/Swiss-Army-breaks-with-Microsoft-Cyber-Command-relies-on-Open-Source-11361516.html">decided</a> <strong>to start using OpenDesk, an open source alternative to Microsoft Office365.</strong> (<a href="https://www.heise.de/en/news/Swiss-Army-breaks-with-Microsoft-Cyber-Command-relies-on-Open-Source-11361516.html">Heise Online</a>) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>According to the report, the Swiss military fears that sensitive military information could ultimately fall into the hands of the US government through this detour. The head of Cyber Command, Simon M&#252;ller, points out that Microsoft's cloud-based Office 365 package is not suitable for an army with the highest demands on confidentiality, availability, and integrity. As long as corporations are subject to laws such as the </span>US Cloud Act<span>, they cannot be used for certain military contexts. The concern about hidden data leakage to foreign intelligence agencies like the NSA weighs heavily. The current geopolitical situation, in which digital infrastructures are increasingly being instrumentalized as geopolitical weapons, adds urgency to the issue.&#8221;</span></em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Evolving Canada-EU Partnership: Defense, Trade, Justice, and the Digital Frontier]]></title><description><![CDATA[In June 2025, Canada and the European Union signed a Security and Defence Partnership, establishing a framework for cooperation regarding crisis management, military mobility, cyber threats, and defense procurement.]]></description><link>https://datalawgy.substack.com/p/the-evolving-canada-eu-partnership</link><guid isPermaLink="false">https://datalawgy.substack.com/p/the-evolving-canada-eu-partnership</guid><dc:creator><![CDATA[László Pók]]></dc:creator><pubDate>Wed, 22 Jul 2026 07:31:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lD-4!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;"><strong><a href="https://www.eeas.europa.eu/eeas/security-and-defence-eu-and-canada-sign-security-and-defence-partnership_en">In June 2025</a></strong>, Canada and the European Union signed a Security and Defence Partnership, establishing a framework for cooperation regarding crisis management, military mobility, cyber threats, and defense procurement. This agreement set the stage for the next step, <strong><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/15/safe-council-concludes-agreement-with-canada/">Canada&#8217;s accession</a></strong> to the <strong>Security Action for Europe instrument</strong> <strong>(<a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/safe-security-action-europe_en">SAFE</a>)</strong>. <strong><a href="https://www.international.gc.ca/world-monde/international_relations-relations_internationales/eu-ue/agreement-accord.aspx?lang=eng">In February 2026</a></strong>, Canada became the first and only non-European country granted access to this &#8364;150 billion EU defense financing mechanism, which supports joint procurement of priority capabilities including ammunition, drones, air and missile defense systems, and space technologies. As Cyprus Defence Minister Vasilis Palmas <strong><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/15/safe-council-concludes-agreement-with-canada/">stated</a></strong>, &#8220;<em>Canada is one of the European Union&#8217;s closest allies. Having Canada joining SAFE highlights the deep trust between us and sets a strong precedent for how the EU can collaborate with key strategic partners to safeguard our collective future.</em>&#8220;</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/the-evolving-canada-eu-partnership?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/the-evolving-canada-eu-partnership?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/the-evolving-canada-eu-partnership?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p style="text-align: justify;">The strategic rationale is clear. Ottawa <strong><a href="https://www.bbc.com/news/articles/ce8zzv1ypkpo">has committed</a></strong> roughly C$81.8 billion over five years to modernize its armed forces, spending historically directed toward U.S. contractors. Amid deteriorating relations with Washington - marked by <strong><a href="https://www.cbc.ca/news/politics/trump-canada-us-joint-defence-board-9.7203211">the Pentagon&#8217;s suspension of the Permanent Joint Board on Defense</a></strong> and persistent trade friction - <strong>Canada is diversifying its defense-industrial partnerships</strong>. Canadian Prime Minister Mark Carney <strong><a href="https://www.pm.gc.ca/en/news/news-releases/2025/12/01/prime-minister-carney-secures-canadas-participation-european-unions">framed</a></strong> the shift in geopolitical terms: &#8220;<em>In a dangerous and divided world, Canada and Europe are elevating our defence partnerships to rapidly procure new equipment and technology, accelerate NATO targets, and catalyse tremendous opportunities for our defence manufacturers. Canada&#8217;s participation in SAFE will fill key capability gaps, expand markets for Canadian suppliers, and attract European defence investment into Canada.</em>&#8221; Concrete <strong><a href="https://www.cbc.ca/news/politics/saab-sweden-nato-canada-globaleye-9.7260918">negotiations with Sweden&#8217;s Saab</a></strong> for surveillance aircraft, <strong><a href="https://www.pm.gc.ca/en/news/statements/2025/08/25/joint-statement-enhancing-canada-poland-strategic-partners">expanded cooperation with Poland</a></strong> and <strong><a href="https://www.bbc.com/news/articles/cn4ddppz3jqo">an order of 12 submarines from Germany</a></strong> illustrate this change of policy, while Montr&#233;al-based Marconi Technologies <strong><a href="https://thedefensepost.com/2026/06/16/canada-eu-safe-poland-radio/">secured the first SAFE-funded contract</a></strong> granted to a Canadian company, supplying tactical radios to the Polish military.</p><p style="text-align: justify;">Commercially, the <strong>Comprehensive Economic and Trade Agreement</strong> (<strong><a href="https://policy.trade.ec.europa.eu/eu-trade-relationships-country-and-region/countries-and-regions/canada/eu-canada-agreements_en">CETA</a></strong>) continues to anchor bilateral economic relations, with two-way goods <strong><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_553">trade reaching approximately</a></strong> &#8364;81 billion and services trade exceeding &#8364;51 billion since provisional application began in 2017. At the <strong><a href="https://policy.trade.ec.europa.eu/news/driving-shared-prosperity-boosting-eu-canada-trade-through-ceta-2026-03-05_en">fifth CETA Joint Committee meeting</a></strong> in March 2026, the parties adopted expedited arbitration procedures to improve SME access to dispute resolution and extended mutual recognition of pharmaceutical good manufacturing practices to active ingredients. <strong>An agreement on mutual recognition for architects </strong>(<strong><a href="https://trade.ec.europa.eu/access-to-markets/en/content/eu-canada-mutual-recognition-arrangement-architects">MRA</a></strong>) also entered into force at the end of 2025, easing professional mobility. <strong><a href="https://single-market-economy.ec.europa.eu/news/eu-and-canada-set-strategic-partnership-raw-materials-2021-06-21_en">The Canada-EU Strategic Partnership on Raw Materials</a></strong>, operational since 2021, positions Canada as a critical supplier of minerals essential to European aerospace, defense, and green-transition priorities.<em> </em><strong>These commercial linkages, growing over seventy-five percent in goods trade since CETA&#8217;s application, reflect deepening economic interdependence.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/the-evolving-canada-eu-partnership?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/the-evolving-canada-eu-partnership?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p style="text-align: justify;">In a less publicized but legally significant development, <strong>Canada <a href="https://x.com/democrats_eu/status/2077004620623175960">recognized</a> the European Public Prosecutor&#8217;s Office (EPPO) as a supranational prosecutorial authority with an effect from mid-2026</strong>. This recognition enables the EPPO - the EU&#8217;s independent body responsible for investigating fraud, corruption, and cross-border VAT offenses affecting EU financial interests - to request judicial assistance directly from Canadian authorities in its own name, bypassing the slower channels of traditional mutual legal assistance treaties.</p><div><hr></div><p style="text-align: center;"><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">The above engagements undelines the </mark><strong><a href="https://nationalpost.com/news/canada/mark-carney-european-canada"><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">statement</mark></a></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);"> that Canada is &#8220;</mark><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">the most European of non-European countries</mark></em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">&#8221;.</mark></p><div><hr></div><p style="text-align: justify;">Perhaps the most forward-looking dimension of the partnership concerns <strong>digital cooperation</strong>. The <strong>EU-Canada Digital Partnership</strong>, <strong><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_23_5953">launched in late 2023</a></strong>, covers AI governance, semiconductor supply-chain resilience, quantum technology, cybersecurity, and data governance. <strong><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2974">An artificial intelligence cooperation agreement</a></strong> was finalized between Canada and the EU in late 2025. <strong><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_553">In March 2026</a></strong>, the parties formally opened negotiations for a dedicated <strong>Digital Trade Agreement</strong> <strong>intended to prohibit unjustified data-localization requirements, ban customs duties on electronic transmissions, and establish common rules for e-signatures, e-contracts, and consumer protection. </strong>EU Trade Commissioner Maro&#353; &#352;ef&#269;ovi&#269; captured the ambition: &#8220;<em>By launching negotiations on a Digital Trade Agreement, we are ready to take the EU-Canada partnership to the next level. Already more than 40% of our &#8364;51 billion in services trade is delivered digitally. And data flows power far more than tech companies &#8211; no modern economy runs without trusted, secure data. If CETA laid the foundation, a Digital Trade Agreement will build the next floor.</em>&#8221; With over forty percent of bilateral services trade already delivered digitally, the economic stakes are considerable. <strong><a href="https://www.cips-cepi.ca/wp-content/uploads/2025/09/Leblond_Camilleri_Brief.pdf">Analysts have suggested</a></strong> that a &#8220;<em>well-designed DTA could serve as a blueprint for reconciling economic openness with regulatory integrity, fostering a single data area among other like-minded partners</em>&#8220;. For businesses on both sides of the Atlantic, <strong>the mid-term implications could include greater legal certainty for cross-border digital operations, improved interoperability of digital frameworks, and enhanced digital cooperation.</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p style="text-align: justify;"></p>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 29]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-431</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-431</guid><pubDate>Fri, 17 Jul 2026 07:30:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ChbZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The European Commission <a href="https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence">has presented</a> an Action Plan on Cybersecurity and Artificial Intelligence</strong> to support the safe and responsible use of AI while strengthening Europe&#8217;s cybersecurity.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the Action Plan sets out a coordinated approach to help Member States, businesses and public authorities benefit from the opportunities offered by AI while addressing the new risks it creates. It focuses on <strong>3 complementary objectives</strong>:</em></p><ol><li><p><em>Promoting the safe and responsible use of advanced AI</em></p></li><li><p><em>Reinforcing the EU&#8217;s cybersecurity and resilience</em></p></li><li><p><em>Scaling up Europe&#8217;s AI capabilities for cybersecurity.&#8221;</em></p></li></ol></li></ul></li><li><p><strong>The Chinese Interim Measures for the Administration of AI Anthropomorphic Interactive Services <a href="https://www.twobirds.com/en/insights/2026/china/china%27s-new-regulations-on-ai-anthropomorphic-interactive-services">took effect</a> on July 15, 2026</strong>.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The Measures mark a significant expansion of China&#8217;s AI governance from content security to emotional and social relationship safety.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Parliamentary Research Service</strong> <a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)789333">published</a> a briefing about the <strong>possible directions of regulating data rentetnion rules, applicable in the telecommunication sector for law enforcement purposes</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Despite judicial and now-defunct legislative efforts to harmonise data retention practices across the EU, national data retention regimes remain fragmented, with some countries adopting their own rules and others none at all. Law enforcement authorities report operational difficulties, while service providers face significant compliance burdens and costs. Although the Court's case law has clarified the general principles governing data retention, important practical details remain unresolved. In response, the European Commission is assessing the need for a new harmonised EU framework, with a proposal potentially forthcoming. [&#8230;]&#8221;</em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p>A <a href="https://www.europarl.europa.eu/news/en/press-room/20260709IPR46415/better-rules-enforcement-for-a-safer-social-media-and-online-environment">report</a> adopted by <strong>the European Parliament&#180;s Committee on Culture and Education</strong> requires <strong>more protection for children online</strong>.</p><ul><li><p><em><strong>Why does this matter?</strong> </em>The report says <em>&#8220;that the online environment must be governed by the principles of privacy-by-design and safety-by-default, age-appropriate design, and algorithmic transparency.&#8221; </em></p></li></ul></li><li><p><strong>The Joint Research Centre of the Commission</strong> <a href="https://publications.jrc.ec.europa.eu/repository/handle/JRC147383">published</a> a policy briefing on <strong>Environmentally Sustainable Digital Sovereignty.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Environmentally sustainable digital sovereignty as a goal can potentially work as a competitive advantage for the EU. It can enable a thriving economy that empowers European companies and SMEs to innovate and operate based on low-resource technologies and infrastructure, through interoperability, coordination and diversification of the supply chain.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>Apple filed a lawsuit against OpenAI</strong>, alleging that OpenAI stole Apple&#180;s trade secrets in a move to create its own hardware device. (<a href="https://www.theguardian.com/technology/2026/jul/10/apple-sues-openai-trade-secrets">The Guardian</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The suit claims OpenAI poached <a href="https://www.theguardian.com/technology/apple">Apple</a> employees, coaxing them to hand over confidential material, product designs and other tightly held information.&#8221;</em></p></li><li><p><em>&#8220;Tensions between the two companies began to simmer last year when OpenAI spent $6.4bn to <a href="https://www.theguardian.com/technology/2025/may/21/openai-iphone-io">acquire a hardware startup</a> founded by former Apple design guru Jony Ive, indicating that the AI titan was foraying into hardware. Ive&#8217;s startup, io Products, is also named in Apple&#8217;s lawsuit.&#8221;</em></p></li><li><p><em>&#8220;The company is seeking damages and a court order that would block OpenAI from possessing or using its trade secrets.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical implications: </mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">This dispute is a useful reminder </mark><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">to tighten employee onboarding and offboarding controls </mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">(NDAs, IP assignment agreements, exit interviews) when hiring from competitors in fast-moving technology segments.</mark></p></li><li><p><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Employers should audit trade secret protection protocols and documentation practices</mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">, as disputes like this often turns on whether reasonable measures were taken to safeguard confidential information.</mark></p></li></ul></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Court of Justice of the EU (CJEU) </strong><a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260100en.pdf">has issued</a> an important ruling <strong>on the interpretation of processing personal data for &#8220;</strong><em><strong>journalistic purposes</strong></em><strong>&#8221; </strong>(Case C-199/24, Legal Newsdesk Sweden). The Court confirmed that &#8220;<em><strong>the mere placing online, in return for payment, of decisions on criminal convictions, does not in principle constitute processing of personal data for &#8216;journalistic purposes&#8217;</strong></em>&#8221;. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;According to the Court, personal data are processed for &#8216;journalistic purposes&#8217; where the objective of that processing is to inform the public or to disclose opinions or ideas, where the content is prepared according to ethical rules or codes of conduct and has been edited or adapted, or at least is in line with an editorial policy. The facts presented must have been verified. <strong>The act of placing online, in return for payment, criminal convictions, does not appear</strong>, subject to a verification to be carried to be carried out by the national court, <strong>to fulfil those conditions or, consequently, to be capable of being regarded as carried out for journalistic purposes.</strong>&#8221;</em></p></li></ul></li><li><p>In <a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260103en.pdf">Case C-474/24</a> (NADA Austria and Others), <strong>the CJEU</strong> concluded that &#8220;<em><strong>the GDPR does not preclude, in principle, the names of professional athletes who have infringed anti-doping rules, the duration of the ban imposed on them and the reasons for that ban from being published on the internet.</strong></em>&#8221; </p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The Court of Justice answers, first of all, that the information published <strong>is not covered, in principle, by the concept of &#8216;data concerning health&#8217;, unless reference is made in the publication to the name or category of the prohibited method or substance concerned by that infringement and that reference, combined with other information</strong> concerning the data subject, <strong>is capable of revealing</strong>, even indirectly, by means of an intellectual operation involving collation or deduction, <strong>information relating to the past, current or future physical or mental health status of that person.</strong>&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] the personal data relating to offences provided for under national anti-doping legislation and to the sanctions imposed for such offences <strong>do not constitute personal data relating to criminal convictions and offences</strong>. [&#8230;]&#8221; </em></p></li><li><p><em>&#8220;[&#8230;] the entity responsible for the publication must be able, <strong>prior to the publication</strong>, to carry out <strong>an individual balancing exercise weighing up the interests involved</strong> in order to ensure that that publication is made in a manner consistent with the GDPR, and, in particular, in observance of the principle of proportionality.</em>&#8221;</p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The CJEU</strong> <a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260098en.pdf">has decided</a> in Case C-788/24 (Anne Frank Fonds) that <strong>&#8220;</strong><em><strong>a work that is in the public domain can be published online free of charge in a Member State even if it remains protected in another Member State</strong></em><strong>&#8221;</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The website on which the work is made available must incorporate an 'effective&#8217; technological measure to prevent its being accessed by internet users visiting the website from a Member State in which that work is protected.&#8221;</em></p></li></ul></li><li><p><strong>The CJEU </strong><a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260097en.pdf">has</a><strong><a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260097en.pdf"> </a></strong><a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260097en.pdf">also decided</a> regarding <strong>streaming services</strong> that <em><strong>&#8220;the right of withdrawal cannot be excluded where the service is designed to adapt to the user&#8217;s behaviour&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] <strong>it appears that the streaming service offered by Sky &#214;sterreich must be classified as a digital service</strong>, given the dynamic nature of the offering. <strong>Consequently, the right of withdrawal cannot be excluded</strong> and the customer thus has an appropriate period for reflection to examine whether the subscription meets his or her expectations.&#8221;</em></p></li></ul></li><li><p>In <a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260109en.pdf">Case C-421/24</a> (AGCOM, Online gambling), <strong>the CJEU</strong> decided that &#8220;<em><strong>Google may be held liable for the YouTube videos of a content creator with whom it has a commercial partnership.</strong></em>&#8221;</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;[&#8230;] <strong>the hosting of advertising content relating to online gambling</strong> [&#8230;] <strong>falls within the scope of the EU legislation on electronic commerce</strong>. [&#8230;] in order to benefit from the exemption from liability in respect of the content published on a platform, <strong>the operator must</strong> act as an &#8216;intermediary service provider&#8217;, that is to say <strong>carry out a strictly technical, automated and passive activity, excluding any knowledge or control over</strong> <strong>the information</strong> which is transmitted or stored. <strong>That is not the case where an operator reviews, for the purpose of concluding a commercial partnership contract, the main theme of a video channel, that channel&#8217;s most viewed videos or newest videos and the associated metadata.</strong> The operator thus acquires specific knowledge of the essential content of a set of videos and cannot therefore claim to act as an intermediary service provider.&#8221;</em></p></li></ul></li><li><p>Musk&#8217;s <strong>xAI sued Grok user over sexualized &#8216;deepfakes&#8217;.</strong> (<a href="https://www.reuters.com/legal/litigation/musks-xai-sues-grok-user-over-sexualized-deepfakes-2026-07-15/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;xAI has sued a South Carolina man arrested earlier this year on charges of sexually exploiting &#8203;minors, alleging he misused the company's AI system Grok to &#8204;create child sexual abuse material. <span>[&#8230;] The case &#8203;is one of the first brought by an AI company &#8203;against one of its users for allegedly using an AI &#8288;system to generate explicit material.</span>&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong><span>The Future of Life Institute&#180;s </span><a href="https://futureoflife.org/wp-content/uploads/2026/07/AI-Safety-Index-Summer-2026-Digital.pdf">AI Safety Index<span> - Summer 2026</span></a></strong><span> has been published, </span><strong><span>offering an updated picture of the current state of AI safety</span></strong><span>.</span></p><ul><li><p><em><strong>Why does this matter? </strong></em>Key findings: </p><ul><li><p><em>&#8220;<strong>Anthropic, OpenAI, and Google DeepMind stay on top.</strong> [&#8230;]</em></p></li><li><p><em><strong>Meta improves and xAI deteriorates: </strong>Meta improved from 6th to 4th place, while xAI dropped from 4th to 7th place.  </em></p></li><li><p><em><strong>European dissonance:</strong> Although the European Union is a leader in AI safety regulation, the top European AI company Mistral scored dead last on safety. </em></p></li><li><p><em><strong>Inadequate safety is a global problem, not a regional one.</strong> Three companies receive failing grades, one each from the US (xAI), China (DeepSeek), and Europe (Mistral). </em></p></li><li><p><em><strong>Reviewers flagged the industry's pivot to military AI use as an emerging current harm risk.</strong> [&#8230;]</em></p></li><li><p><em><strong>Even industry leaders in safety practices are retreating from prior commitments. </strong>[&#8230;]</em></p></li><li><p><em><strong>Existential Safety is the weakest domain industry-wide.</strong> [&#8230;] </em></p></li><li><p><em><strong>Safety rhetoric outpaces revealed behavior.</strong> Across Google DeepMind, OpenAI, and xAI, leadership's reassuring public messaging diverges from commercial conduct and legislative stance, making stated commitments an unreliable proxy for actual safety practice. </em></p></li><li><p><em><strong>Companies are publishing and updating safety frameworks, but these frameworks have weak teeth.</strong> As US/EU compliance deadlines near, Anthropic, OpenAI, Google DeepMind, Meta, and xAI published and updated fuller frameworks &#8212; yet they sometimes lack quantitative thresholds, genuinely independent audits, and clear decision authority.&#8221;</em></p></li></ul></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical implications:</mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Compliance teams vetting third-party AI vendors should treat published safety frameworks and commitments as a starting point for review.</mark></p></li><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Organizations relying on AI providers flagged with failing safety grades should </mark><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">reassess associated risk allocation in contracts</mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">, including indemnification, audit rights, and termination triggers tied to safety performance.</mark></p></li></ul></li></ul></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ChbZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 424w, /__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 848w, /__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ChbZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png" width="919" height="571" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:571,&quot;width&quot;:919,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108634,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/204089404?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 424w, /__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 848w, /__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ChbZ!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf69d743-6bf5-4c42-9257-cb2b530b5b2e_919x571.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://futureoflife.org/wp-content/uploads/2026/07/AI-Safety-Index-Summer-2026-Digital.pdf">The Future of Life Institute&#180;s AI Safety Index - Summer 2026 (July 2026)</a>, p. 1</em></p><ul><li><p><strong>Google</strong> <a href="https://blog.google/products/ads-commerce/google-ads-ai-transparency-labels/">announced</a> <strong>new AI transparency features</strong>, introducing disclosures and labels for AI-generated ads. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>We're </span>adding<span> a &#8220;How this ad was made&#8221; section to the My Ad Center panel, accessible globally by selecting the three-dot menu or info icon on ads across Search, YouTube and Discover. This panel will indicate if an ad was created or edited with AI.&#8221;</span></em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical implications</mark></strong></em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">: Companies (not only advertisers) using AI-generated or AI-edited content should </mark><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">review their disclosure practices</mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">, as platform-level transparency labeling may increase scrutiny of undisclosed AI use and could trigger emerging regulatory expectations around AI content labeling. </mark><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">(Please also note that transparency obligations under Art. 50 of the AI Act becomes applicable as of August 2, 2026.)</mark></em></p></li></ul></li><li><p><strong>The AI Office</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/ai-office-publishes-frontier-ai-expert-findings-eu-competitiveness-sovereignty-and-security">has published</a> <strong>a report</strong> that summarises findings from over 100 experts on <strong>how the European Union can enhance its competitiveness, sovereignty and security in frontier AI</strong>.</p></li><li><p><strong>Approximately 200 leading economists and leaders</strong> <a href="https://www.wemustactnow.ai/">signed</a> a <strong>statement on AI&#8217;s Transformation of the Economy</strong>.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;<span>Economists, policymakers and technology leaders must act now to understand the economics of transformative AI and to build the incentives, guardrails, and institutions needed to steer AI in a direction that complements humans and benefits society.&#8221;</span></em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-431?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-431?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-431?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The French Data Protection Authority (CNIL)</strong> <a href="https://www.cnil.fr/fr/geolocalisation-applications-mobiles-quelles-regles">published</a> <strong>guidance on mobile app obligations when collecting users&#8217; geolocation information</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the CNIL recalls the rules applicable to the collection and use of this data. It also provides data subjects with a practical sheet to help them control their data and exercise their rights.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical implications: </mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Mobile app developers and publishers should </mark><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">review and update (if necessary) consent mechanisms and app privacy notices for geolocation data collection</mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);"> against this CNIL guidance to reduce enforcement risk. </mark><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">(The CNIL guidance is primarily applicable to those that are targeting  users in France, however, this guidance can serve as a practical help for data controllers that are active on other markets.)</mark></em></p></li></ul></li></ul></li><li><p><strong>The ICO (UK)</strong> <a href="https://ico.org.uk/for-organisations/advice-for-small-organisations/cctv-and-dashcams/using-personal-information-to-protect-your-business-from-crime/">published</a> guidencae on &#8220;<em><strong>Using personal information to protect your business from crime</strong></em>&#8221;.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This guidance explains how data protection law applies if you are planning to share criminal offence data and provides you with resources to help you protect your business. At the end of this guidance there is a helpful checklist to take you through the steps you need to follow.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical implications:</mark></strong></em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);"> Businesses using CCTV, dashcams, or crime-prevention data sharing (e.g., industry watchlists) should use the ICO&#8217;s checklist </mark><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">to confirm they comply with data protection requirements</mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">. </mark><em><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">(The guidance was prepared under the UK GDPR and is applicable in the UK, however, it can provide an useful checklist for entities outside of the UK as well.)</mark></em></p></li></ul></li><li><p><strong>The Dutch Data Protection Authority (AP)</strong> <a href="https://autoriteitpersoonsgegevens.nl/actueel/ap-helpt-ontwikkelaars-en-organisaties-met-nieuwe-avg-richtlijnen-voor-generatieve-ai">published</a> <strong>new GDPR guidelines for generative AI</strong>. <em>(The documents are in Dutch)</em></p><ul><li><p><em><strong>Why does this matter?</strong></em> The published guidelines include a guide for developers of generative AI models and a practical tool for organizations that want to implement and use generative AI.</p></li><li><p><em><strong>The guide for developers</strong></em> &#8220;<em>describes, among other things, the conditions under which organisations may process personal data, the grounds on which this may apply and the safeguards required to protect the rights of data subjects. Attention is also paid to topics such as managing, cleaning, enriching and storing data, indirect data collection and the use of personal data in training AI models.</em>&#8221;</p></li><li><p><em><strong>The guide for organizations planning to implement AI</strong></em> provides &#8220;<em>a checklist that helps privacy professionals, project leaders and other responsible parties to assess step by step whether their organization wants, can and may use generative AI. It is a practical tool to determine which GDPR obligations apply and which technical and organizational measures are needed to use generative AI responsibly.</em>&#8221;</p></li></ul></li><li><p><strong>The Spanish Data Protection Authority (AEPD)</strong> <a href="https://www.aepd.es/prensa-y-comunicacion/blog/buenas-practicas-si-vas-a-usar-gafas-de-sol-inteligentes-este-verano">published</a><strong> practical guidance</strong> for people, who are planning to wear <strong>smart sunglasses</strong> this summer. <em>(The document is in Spanish.)</em></p><ul><li><p><em><strong>Why does this matter? </strong></em></p><ul><li><p><em>&#8220;1. Use smart glasses with the same criteria as a camera or mobile phone</em></p></li><li><p><em>2. Be transparent about device usage</em></p></li><li><p><em>3. Pay special attention to audio recordings</em></p></li><li><p><em>4. Limit recordings to what is strictly necessary</em></p></li><li><p><em>5. Please note that other data may be collected in addition to images and sound</em></p></li><li><p><em>6. Configure privacy and security options properly</em></p></li><li><p><em>7. Respect the legal limits of recording</em></p></li><li><p><em>8. Delete recordings when they&#8217;re no longer needed&#8221;</em></p></li></ul></li><li><p><em>&#8220;The responsible use of smart glasses helps to protect one&#8217;s own privacy and that of others. Before recording, storing or sharing content, always assess the impact that these actions may have on the rights and freedoms of others, and act with respect and responsibility.&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>The European Union Agency for Cybersecurity (ENISA) </strong><a href="https://www.enisa.europa.eu/publications/sme-cyber-resilience-maturity-assessment-model">published</a> its <strong><span>SME Cyber Resilience Maturity Assessment Model</span></strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The SME Cyber Resilience Maturity Assessment Model provides a structured approach for micro, small and medium-sized enterprises (SMEs) to evaluate and strengthen their overall cyber resilience, while taking into account the requirements of the Cyber Resilience Act (CRA). The model is primarily intended for organisations that manufacture and place products with digital elements on the market, as these are directly subject to CRA requirements. However, it can also be used by other organisations involved in the product life cycle, such as integrators or service providers, to assess and improve their product security practices.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://commission.europa.eu/topics/digital-economy-and-society/protecting-children-online/special-panel_en">has published</a> <strong>the final report of the Special Panel on Child Safety Online.</strong></p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The report highlights the critical challenges children face online and provides recommendations and inspiration on better protecting and empower them, as well as on the age-appropriate use of social media and other digital services.&#8221;</em></p></li><li><p><em><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Practical implications:</mark></strong></em></p><ul><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Social media platforms, app developers, and other digital service providers should </mark><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">review age-verification and age-appropriate design practices in light of the report&#8217;s recommendations</mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">.</mark></p></li><li><p><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">Compliance teams should proactively </mark><strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">assess current child safety features against the report&#8217;s recommendations</mark></strong><mark data-color="#fce5cd" style="background-color: rgb(252, 229, 205); color: rgb(0, 0, 0);">, given that regulators frequently treat such expert recommendations as a roadmap for subsequent guidance or enforcement action.</mark></p></li></ul></li></ul></li><li><p><strong>The UK&#180;s Department for Science, Innovation and Technology (DSIT) <a href="https://www.gov.uk/government/publications/social-media-restriction-pilots-qualitative-research-with-13-to-17-year-olds-in-the-uk/social-media-intervention-research-2026-social-media-restriction-pilots-qualitative-research-with-13-to-17-year-olds-in-the-uk">published</a> a qualitative study exploring the impact of social media restrictions on young people aged 13-17</strong>. </p><ul><li><p><em><strong>Why does this matter?</strong></em> <em>&#8220;The study included 3 separate types of social media restriction, these were: limiting usage to 15 minutes per day (Intervention 1), installing a no-access curfew for social media from 9pm-7am (Intervention 2) and complete removal of access by uninstalling social media apps (Intervention 3).&#8221;</em></p></li><li><p><em>&#8220;Participants across the intervention groups reported a range of perceived benefits associated with social media restrictions, including improvements to wellbeing, sleep, and family life. Lasting impact appeared to be more likely where restrictions were supported by education and practical guidance and framed as a collective norm rather than an individual imposition.&#8221;</em></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-431?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-431?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><a href="https://arxiv.org/abs/2606.23491">&#8220;</a><strong><a href="https://arxiv.org/abs/2606.23491">Hallucinations in Organization-backed AI advisors: Evidence about Skepticism, Verification, and Reliance in Goal-Directed Use&#8221;</a></strong></em><strong> </strong>(authors: Blanchard, Garvey and O&#8217;Laughlin)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] A central question for AI-advised decisions is [&#8230;] not only whether users rely on inaccurate information, but whether they recognize that a response may require verification. [&#8230;] We distinguish three constructs that existing studies often conflate: whether users are skeptical of information presented, whether they check it, whether checking succeeds, and whether the result of user verification affects reliance on the information. [&#8230;]&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p>&#8220;<em><strong>Meta</strong> is facing a backlash over its new AI tool <strong>Muse Image</strong>, which <strong>can generate pictures using other people&#8217;s profile pictures without telling them</strong>.</em>&#8221; (<a href="https://www.bbc.com/news/articles/cp9lee19y1yo">BBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;It is one of many text-to-image tools publicly available, which as [&#8230;] can create pictures from a few lines of simple written text. [&#8230;] <span>The feature is likely to face heightened scrutiny as regulators and campaigners raise concerns about AI-generated images, with Ofcom </span><a href="https://www.bbc.co.uk/news/articles/cwy875j28k0o">currently investigating X</a><span> over Grok's role in creating and sharing non-consensual AI-altered images of real people.</span>&#8221;</em></p></li><li><p><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/">It&#180;s worth noting</a> that <strong>the Digital Omnibus on AI</strong> will introduce <strong>a new ban on &#8220;</strong><em><strong>nudifier apps</strong></em><strong>&#8221; </strong>(i.e., prohibiton on AI practices regarding the generation of non-consensual sexual and intimate content or child sexual abuse material) in the EU, as of December this year. </p></li></ul></li><li><p>&#8220;<em><strong>OpenAI</strong> is looking <strong>to expand its ad pilot across Europe</strong>, accelerating the international rollout of its ad business.</em>&#8221; (<a href="https://digiday.com/marketing/openai-set-to-expand-ads-to-france-germany-and-ireland/">Digiday</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] <span>The latest expansion signifies that OpenAI will have achieved an advertising presence in every major global advertising region within less than a year. In Europe, the rollout now covers the U.K., France and Germany &#8212; the continent&#8217;s three largest digital ad markets, which together accounted for 62% of the region&#8217;s ad revenue last year, according to </span><a href="https://iabeurope.eu/knowledge_hub/iab-europe-adex-benchmark-2025-report/">IAB Europe&#8217;s AdEx Benchmark 2025 report</a><span>.</span>&#8221; </em></p></li></ul></li><li><p>According to Chinese state media reports, <strong>China has successfully landed a reusable rocket for the first time</strong>. (<a href="https://www.bbc.com/news/articles/cm2rmmx86pdo">BBC</a>)</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;It signals that China may be able to challenge America&#8217;s dominance in reusable rockets after successful landings by Elon Musk&#8217;s SpaceX and Blue Origin, which is owned by Amazon founder Jeff Bezos.&#8221; </em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!33p-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 424w, /__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 848w, /__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 1272w, /__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!33p-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png" width="969" height="541" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:541,&quot;width&quot;:969,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:490064,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/204089404?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 424w, /__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 848w, /__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 1272w, /__u/substackcdn.com/image/fetch/$s_!33p-!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5892051b-3588-4ef8-858d-fed95ab5d4b0_969x541.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: <a href="https://www.bbc.com/news/articles/cm2rmmx86pdo">BBC</a> (Video footage)</em></p></li><li><p>A day later, &#8220;<em><strong>Japan&#8217;s</strong> experimental reusable rocket took off and safely landed in a first test flight</em>&#8221;. (<a href="https://apnews.com/article/japan-reusable-rocket-h3-test-space-china-eb83b8385641a094b4cd69c3ee48090a">AP</a>)</p><ul><li><p><em><strong>Why does this matter?</strong></em> &#8220;<em>Japan seeks to catch up with the technology Elon Musk&#8217;s SpaceX has been using for several years to cut launch costs of delivering payloads into space.</em>&#8221; </p></li></ul></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Quantum Leaps for Privacy #3 (Q2 2026)]]></title><description><![CDATA[Newsletter on the impact of future technologies on privacy and data protection]]></description><link>https://datalawgy.substack.com/p/quantum-leaps-for-privacy-3-q2-2026</link><guid isPermaLink="false">https://datalawgy.substack.com/p/quantum-leaps-for-privacy-3-q2-2026</guid><dc:creator><![CDATA[László Pók]]></dc:creator><pubDate>Wed, 15 Jul 2026 07:02:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!czq-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Significant technological advances are being made in several areas, including <em><strong>quantum computing, neurotechnology, artificial intelligence (AI), and 6G technology </strong></em>that are quickly becoming part of our daily lives. <em><strong>These technologies, either individually or in combination, significantly impact data protection and privacy.</strong></em> In this newsletter, I regularly discuss various emerging technologies and their potential impact on data protection and privacy.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ol><li><p><strong>Neurotechnology</strong></p></li></ol><ul><li><p><strong>Meta</strong> <a href="https://ai.meta.com/blog/brain2qwerty-brain-ai-human-communication/">introduced</a> <strong>Brain2Qwerty v2</strong>, &#8220;<em>the highest-performing end-to-end pipeline capable of real-time sentence decoding from non-invasive brain recordings, approaching levels of accuracy previously exclusive to techniques that require brain surgery.</em>&#8221;</p><ul><li><p><em><strong>Why does this matter? </strong></em>According to the <a href="https://ai.meta.com/research/publications/accurate-decoding-of-natural-sentences-from-non-invasive-brain-recordings/">research paper</a>,<em> &#8220;restoring communication for people who have lost the ability to speak or move after a brain injury is a major challenge. While intracranial implants now enable high-performing brain-computer-interfaces, non-invasive alternatives are still lagging behind. Here, we present Brain2Qwerty v2, a model that can decode the production of natural sentences solely from real-time magnetoencephalography (MEG) recordings. By collecting 22,000 sentences typed by nine subjects, each recorded for 10 hours, our model leverages character, word and sentence-level representations to achieve an average word error rate (WER) of 39%. For our best participant, the model accurately decodes half of the sentences with one word error or less. Critically, decoding accuracy log-linearly improves with data volume, suggesting that the performance gap with intracranial approaches could be partially bridged through data scaling. We show that AI enables this performance in three main ways: the substitution of hand-crafted pipelines for event detection with deep learning, the finetuning of large language models to extract semantic representations, and the deployment of AI agents to iteratively refine our decoding pipeline via automated code development. Together, these results show that non-invasive brain-to-text decoding starts to operate at a level of accuracy previously thought exclusive to surgical implants, opening a path toward safe and efficient brain-computer-interfaces.&#8221;</em></p></li></ul></li><li><p><strong>A new research project, BrainGuard,</strong> <a href="https://bernstein-network.de/en/newsroom/news/260226/">has been launched</a> <strong>to strengthen the security of neurotechnologies. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Its goal is to develop novel security concepts for neurotechnologies that ensure the protection of sensitive neural data, prevent manipulation, and safeguard the autonomy of users. As medical devices become increasingly integrated with the nervous system, the potential risks associated with insufficient security measures grow accordingly.&#8221;</em></p></li></ul></li><li><p>A <a href="https://law.stanford.edu/2026/04/27/even-chiles-neurorights-leave-inferred-mental-data-in-a-gray-zone/">recent blog post</a> published on the website of Stanford Law School, &#8220;<em><strong>Even Chile&#8217;s Neurorights Leave Inferred Mental Data in a Gray Zone</strong></em>&#8221; (by Bo Hyoung Lee),  demonstrates that altough &#8220;<em>Chile has gone unusually far in recognizing that brain-related information deserves special legal attention, yet it still does not clearly resolve how law should treat information inferred from neural activity once it is processed and used outside a traditional medical setting.</em>&#8221; </p></li><li><p><strong>The EBRAINS Ethics and Society Committee</strong>, in collaboration with the International Brain Initiative, <a href="https://ebrains.eu/news-and-events/2026/new-mind-your-mind-guide-to-protecting-brain-data-published-for-brain">published</a> <strong>a Guide to Protecting Brain Data</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The new &#8216;Mind Your Mind&#8217; guide was created to empower the public with knowledge about neurodata: what they are, why they matter, and how they can and should be protected. It is aligned with the principles of the European Charter for the Responsible Development of Neurotechnologies, which calls for ethical innovation, a human rights-based approach, and robust safeguards for neurodata.&#8221;</em></p></li></ul></li><li><p>Risk Management Magazine <a href="https://www.rmmagazine.com/articles/article/2026/02/24/state-of-mind--the-new-landscape-of-neural-data-privacy-laws">published</a> an article about the neural data privacy laws in the US, titled &#8220;<em><strong>State of Mind: The New Landscape of Neural Data Privacy Laws</strong></em><strong>&#8221;</strong> (authors: Neil Issar , Davis Shugrue , Morgan Houghtlin).  </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;To proactively manage the emerging risks around neural data, organizations must understand how this data interacts with business processes. In addition, the legal and regulatory landscape around neural data is also evolving with at least nine U.S. states enacting or considering laws regulating the collection and use of this data, creating new risks and obligations for protecting individual privacy.&#8221;</em></p></li></ul></li><li><p><strong>The World Economic Forum (WEF)</strong> <a href="https://www.weforum.org/stories/2025/10/neurosecurity-balance-neurotechnology-opportunity-with-security/">published</a> an article about neurosecurity, i.e. <strong>how we balance neurotechnology&#8217;s opportunity with security</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Neural data is uniquely sensitive, revealing thought and emotion, making security and governance essential. A holistic, layered security and governance framework is necessary to protect trust, safeguard identity and unlock the transformative potential of neurotechnology.&#8221;</em></p></li></ul></li><li><p>In November 2025, <strong>UNESCO</strong> <a href="https://www.unesco.org/en/legal-affairs/recommendation-ethics-neurotechnology">issued</a> a <strong>Recommendation on the Ethics of Neurotechnology.</strong></p></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/quantum-leaps-for-privacy-1-may-2025?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxOTAxNTMyNDIsInBvc3RfaWQiOjE2NDQ4NzIyOSwiaWF0IjoxNzQ4OTM5OTE5LCJleHAiOjE3NTE1MzE5MTksImlzcyI6InB1Yi0zNDIxMDg5Iiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.-BFmcSY_COSKiZxCqO8vPxSGL7Zl-W4MHl7D65euQlU&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/quantum-leaps-for-privacy-3-q2-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/quantum-leaps-for-privacy-3-q2-2026?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><ol start="2"><li><p><strong>Quantum computing</strong></p></li></ol><ul><li><p><strong><span>President Trump </span><a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-ushers-in-the-next-frontier-of-quantum-innovation/">signed</a><span> an </span><a href="https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/">Executive Order</a><span> to supercharge U.S. innovation in quantum technologies</span></strong><span> and strengthen the national security in this critical area.</span></p><ul><li><p><em><strong>Why does this matter? </strong><span>&#8220;The Order establishes a national effort to develop the first ever quantum computer powerful enough to initiate the era of quantum-enabled scientific discovery and accelerate quantum capabilities for commercial applications. [&#8230;] The Order ensures that the United States enters this new era of quantum innovation with ambitious national goals, a strong domestic workforce, and trusted supply chains in coordination with our international allies and partners.&#8221;</span></em></p></li></ul></li><li><p><strong>OECD</strong> <a href="https://www.oecd.org/en/publications/an-overview-of-national-strategies-and-policies-for-quantum-technologies_5e55e7ab-en.html">published</a> a policy paper providing <strong>an overview of national strategies and policies for quantum technologies.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This paper takes stock of the ambitious national strategies and policy instruments countries are introducing to support the development and uptake of quantum technologies. It reviews the timelines, motivations, scope, goals, assessment and governance mechanisms characteristic of national quantum strategies. The paper also identifies the main objectives of policies with frequently used instruments, including institutional funding for public research, project grants for public research, grants for business R&amp;D and innovation, public procurement and equity financing.&#8221;</em></p></li></ul></li><li><p><strong>The European Parliamentary Research Service</strong> <a href="https://www.europarl.europa.eu/thinktank/de/document/EPRS_IDA(2025)774696">published</a> an in-depth analysis on <strong>&#8220;Future-proofing the Quantum Europe Strategy for 2040&#8221;</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Quantum technologies are developing rapidly. They have extensive uses in secure communications, energy, healthcare, manufacturing, defence and security, and space, and may bring about a change of paradigm in technological capabilities. Their economic and strategic value makes them a high priority for EU strategic autonomy. The new Quantum Europe Strategy intends to establish the EU as a global leader in quantum technologies by 2030. This paper explores the potential paths the EU can take to establish itself as a global leader in this field. To ensure that the strategy holds in a highly unpredictable world, we have conducted a foresight exercise to &#8216;wind-tunnel&#8217; (stress-test) statements taken from the quantum strategy against the European Commission Joint Research Centre&#8217;s four reference foresight scenarios.&#8221;</em></p></li></ul></li><li><p><strong>The Australian Cyber Security Centre</strong> <a href="https://www.cyber.gov.au/business-government/secure-design/quantum/quantum-technology-primer-computing">issued</a> a <strong>guide on quantum computing risks</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Quantum computing has the potential to disrupt some current cryptography. As CRQCs* emerge, organisations will need to rely on quantum-resistant cryptography &#8212; known as post-quantum cryptography (PQC) &#8212; to maintain the security of systems and data.&#8221; (*cryptographically relevant quantum computers)</em></p></li></ul></li><li><p><strong>Google</strong>, in a blog posts, <strong><a href="https://blog.google/innovation-and-ai/technology/safety-security/the-quantum-era-is-coming-are-we-ready-to-secure-it/">proposed</a> five actions policymakers can take to prepare for the quantum era</strong></p><p><em>&#10145;&#65039;<strong> Drive society-wide momentum, especially for critical infrastructure </strong></em></p><p><em><strong>&#10145;&#65039; Ensure AI is built with post-quantum cryptography (PQC) in mind </strong></em></p><p><em><strong>&#10145;&#65039; Reduce global fragmentation</strong></em></p><p><em><strong>&#10145;&#65039; Promote Cloud-first modernization</strong></em></p><p><em><strong>&#10145;&#65039; Lean on the experts to avoid strategic surprise</strong></em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The encryption currently used to keep your information confidential and secure could easily be broken by a large-scale quantum computer in coming years. And while we&#8217;re not there yet, malicious actors are not waiting until a Cryptographically Relevant Quantum Computer (CRQC) is ready. They are likely already carrying out &#8220;<a href="https://security.googleblog.com/2024/08/post-quantum-cryptography-standards.html">store now, decrypt later</a>&#8221; attacks and collecting encrypted data, just waiting for the day when a quantum computer can unlock it.&#8221;</em></p></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/quantum-leaps-for-privacy-3-q2-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/quantum-leaps-for-privacy-3-q2-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/quantum-leaps-for-privacy-3-q2-2026?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div></li></ul><ol start="3"><li><p><strong>6G</strong></p></li></ol><ul><li><p><strong>The ETSI Industry Specification Group on Integrated Sensing and Communications (ISAC)</strong> <a href="https://www.etsi.org/newsroom/news/2647-report-6g-isac-security-privacy-sustainability/">has published</a> <strong><a href="https://www.etsi.org/deliver/etsi_gr/ISC/001_099/004/01.01.01_60/gr_ISC004v010101p.pdf">ETSI GR ISC 004</a></strong>, a comprehensive <strong>report addressing security, privacy, trustworthiness, and sustainability considerations for Integrated Sensing and Communications (ISAC) in future 6G systems</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The report identifies 19 key issues, including 15 related to security and privacy and 4 focused on sustainability, reflecting the growing importance of responsible design in next-generation networks. As ISAC enables 6G systems to simultaneously communicate and sense their environment, new technical, ethical, and regulatory challenges emerge&#8212;particularly around unauthorised sensing, data confidentiality, human privacy, AI-based data processing, and secure handling of sensing data.</em></p><p><em>The ETSI Report addresses the following main topics:</em></p><ul><li><p><em>Protection against unauthorised use of 6G systems for sensing</em></p></li><li><p><em>Safeguards against target-based eavesdropping and over-the-air signal manipulation</em></p></li><li><p><em>Secure transport, storage, and immutability of sensing data</em></p></li><li><p><em>Consent, transparency, and privacy-preserving mechanisms for sensing humans (connected and non-connected)</em></p></li><li><p><em>Confidentiality in non-public and sensitive spaces</em></p></li><li><p><em>Sustainability challenges including power consumption, spectrum efficiency, environmental footprint, and health considerations</em></p></li><li><p><em>The report consolidates potential technical and non-technical requirements that future 6G systems should meet to ensure ISAC services are secure, privacy-preserving, trustworthy, and environmentally sustainable.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>University College Dublin (UCD)</strong> <a href="https://capacityglobal.com/news/eu-shield-6g-project-ai-network-security/">has been named</a> <strong>lead institution for Shield-6G</strong>, an &#8364;8m project funded under the EU&#8217;s Horizon Europe Smart Networks and Services Joint Undertaking.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Shield-6G is tasked by the European Commission with establishing the foundational security, reliability and resilience guidelines for 6G networks. In practical terms, it is an AI-driven cyber threat intelligence platform designed to shift the dial from basic network reliability to what its architects describe as an &#8220;unprecedented&#8221; standard of systemic resilience.&#8221;</em></p></li></ul></li><li><p><strong>Vesa Lehtovirta (Ericsson)</strong> <a href="https://www.ericsson.com/en/blog/2026/4/6g-security-key-topics-sa3">argues</a> that the developments around 6G provide an &#8220;<em>opportunity to revisit mobile security from the ground to adapt to new technologies, use cases and threats.</em>&#8221;</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;6G offers a rare opportunity to revisit mobile security from the ground up. While the system will build on the strong foundation established by 5G, improvements must be guided by rigorous risk assessment and Zero Trust principles. Proactive, forward-looking design will be particularly important in areas such as post-quantum cryptography and embedding Zero Trust architecture from the outset. 3GPP SA3 is laying the foundation for 6G security, but the success of the next generation of mobile networks will depend on broad industry collaboration. Operators, vendors, academia and regulators all have a role to play in ensuring that 6G networks are secure, resilient and ready for the challenges of the decade ahead.&#8221;</em></p></li></ul></li></ul><ol start="4"><li><p><strong>AI</strong></p></li></ol><ul><li><p><strong>The AI Futures Project</strong> <a href="https://ai-2040.com/">published</a> its positive vision for <strong>what should happen in the AI race until 2040 (Plan A)</strong>. <strong>Plan A is contrasted with 4 alternative plans (B, C, D, and S)</strong>, which correspond to the main ways the US could respond (or not) to the challenges of superintelligence.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;In this scenario, humanity delays the development of superintelligence until 2040, makes all AI research public, allows dozens of companies globally to catch up to the frontier, and intentionally enters a regime of mutually assured compute destruction.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!czq-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 424w, /__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 848w, /__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 1272w, /__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!czq-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png" width="686" height="783" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:783,&quot;width&quot;:686,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:516915,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/167796109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 424w, /__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 848w, /__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 1272w, /__u/substackcdn.com/image/fetch/$s_!czq-!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee95d00-7da7-402e-bd5c-4aab5cbd49a4_686x783.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: The AI Futures Project, <a href="https://ai-2040.com/?choices=plan-a-root">AI 2040, Plan A</a></em></p></li><li><p><em>&#8220;<strong>Plan A is our positive vision for how humanity can avoid AI-driven existential catastrophe and reach a flourishing future. </strong>It&#8217;s informed by conversations with experts at major U.S. frontier AI companies, direct experience at OpenAI, tabletop exercises, and discussions with policymakers, national security experts, and AI policy leaders. We recommend an international deal to avoid a dangerous race to superintelligence. The deal involves total research transparency for AI R&amp;D, which allows the nations of the world to understand what&#8217;s happening and enforce guardrails. The result is multiple companies across multiple countries scaling slowly and safely together towards superintelligence, instead of racing each other in secrecy.</em></p><p><em><strong>Plan A is primarily a recommendation, not a prediction.</strong> This scenario is not our best guess as to what the future will actually look like. Instead, it&#8217;s a vehicle for communicating and stress-testing our policy recommendations. While the implementation of Plan A is a recommendation and not what we actually expect to happen, the subsequent effects depicted are predictions. In this AI 2040 scenario, Plan A is implemented successfully, albeit imperfectly and only in the nick of time.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!rVWz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 424w, /__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 848w, /__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 1272w, /__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!rVWz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png" width="709" height="797" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:797,&quot;width&quot;:709,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:454222,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/167796109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 424w, /__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 848w, /__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 1272w, /__u/substackcdn.com/image/fetch/$s_!rVWz!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eaef36e-a1e8-4300-9af7-80e20d34b964_709x797.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Source: The AI Futures Project, <a href="https://ai-2040.com/?choices=plan-a-root">AI 2040, Plan A</a></em></p></li></ul></li><li><p><strong>The OECD</strong> <a href="https://www.oecd.org/en/publications/exploring-possible-ai-trajectories-through-2030_cb41117a-en.html">published</a> a working paper, titled &#8220;<em><strong>Exploring possible AI trajectories through 2030</strong></em><strong>&#8221;.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The paper aims to improve understanding of how artificial intelligence (AI) is evolving and explores how AI innovation might advance &#8211; or slow down &#8211; by 2030. It presents four scenarios for possible AI trajectories by that year, providing a baseline for analysing future developments and their potential impacts.&#8221;</em></p></li></ul></li><li><p><strong>The European Data Protection Supervisor</strong> <a href="https://www.edps.europa.eu/data-protection/technology-monitoring/techsonar/techsonar-2025-2026-foreword_en">published</a> its <strong>TechSonar report</strong>, f<strong>ocusing primarily on AI-related technologies</strong>. (The report is available <a href="https://www.edps.europa.eu/data-protection/our-work/publications/reports/2025-11-24-techsonar-2025-2026_en">here</a>.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220; This year&#8217;s TechSonar report includes six trends: agentic AI, AI companions, automated proctoring, AI-driven personalised learning, coding assistants and confidential computing. <strong>Agentic AI</strong> refers to artificial intelligence systems that can autonomously make decisions, take actions and achieve goals without constant human intervention. <strong>AI companions</strong> interact with and support humans through personalised experiences. <strong>Automated proctoring</strong> monitors online exams to detect cheating. <strong>AI-driven personalised learning</strong> customises content and learning experience to each student&#8217;s needs. <strong>Coding assistants</strong> help developers write and debug code. And <strong>confidential computing</strong> protects data while it is being used by performing computations in secure, isolated environments.</em>&#8221;</p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>You can find the previous issues of Quantum Leaps for Privacy here:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;193ea6b0-6ff8-4eeb-bca8-cf94dac04b68&quot;,&quot;caption&quot;:&quot;Significant technological advances are being made in several areas, including quantum computing, neurotechnology, artificial intelligence (AI), and 6G technology that are quickly becoming part of our daily lives. These technologies, either individually or in combination, significantly impact data protection and privacy. In this newsletter, I regularly d&#8230;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Quantum Leaps for Privacy #2 (June 2025)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:190153242,&quot;name&quot;:&quot;L&#225;szl&#243; P&#243;k&quot;,&quot;bio&quot;:&quot;Senior Privacy Manager | Data protection | AI &amp; Privacy &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b183c3a0-04e4-4eba-bd5d-9e0b44f0657e_509x509.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-07-08T07:30:31.309Z&quot;,&quot;cover_image&quot;:null,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://datalawgy.substack.com/p/quantum-leaps-for-privacy-2-june&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:165080321,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;Datalawgy&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;1dbd1fe2-b390-4bb5-82a0-095c9dc2066d&quot;,&quot;caption&quot;:&quot;Significant technological advances are being made in several areas, including quantum computing, neurotechnology, artificial intelligence (AI), and 6G technology that are quickly becoming part of our daily lives. These technologies, either individually or in combination, significantly impact data protection and privacy. In this newsletter, I regularly d&#8230;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Quantum Leaps for Privacy #1 (May 2025)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:190153242,&quot;name&quot;:&quot;L&#225;szl&#243; P&#243;k&quot;,&quot;bio&quot;:&quot;Senior Privacy Manager | Data protection | AI &amp; Privacy &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b183c3a0-04e4-4eba-bd5d-9e0b44f0657e_509x509.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-06-03T08:35:58.291Z&quot;,&quot;cover_image&quot;:null,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://datalawgy.substack.com/p/quantum-leaps-for-privacy-1-may-2025&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:164487229,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;Datalawgy&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 28]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-97f</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-97f</guid><pubDate>Fri, 10 Jul 2026 13:15:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1LKL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Governor of Illinois</strong> <a href="https://capitolnewsillinois.com/news/pritzker-signs-landmark-ai-regulation-bill-that-aims-to-mitigate-risks/">signed</a> <strong>the Artificial Intelligence Safety Measures Act</strong> that is intended to increase transparency and accountability requirements for the largest AI models.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The bill mirrors California&#8217;s </span><a href="https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53">SB-53</a><span> and New York&#8217;s </span><a href="https://www.nysenate.gov/legislation/bills/2025/S6953/amendment/A">Responsible AI Safety and Education Act</a><span>, which were each signed in late 2025. It establishes new reporting standards for the possibility that the AI model could be used for large-scale harms, such as by providing users assistance in creating a chemical, biological or nuclear weapon or committing cyber-attacks.&#8221;</span></em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Parliament</strong> <a href="https://www.europarl.europa.eu/news/en/press-room/20260706IPR46318/combating-child-sexual-abuse-support-for-a-more-limited-eprivacy-derogation">adopted</a> <strong>amendments to a privacy exemption allowing electronic communication services to voluntarily detect child sexual abuse</strong>. The amendments would exclude &#8220;<em>communications to which end-to-end encryption is, has been or will be applied</em>&#8221; from the scope of the law.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The EP position (text as amended) will now be sent to the Council, which has three months to approve or reject the amendments. If the Council does not accept all of the amendments, EP and Council will move to conciliation to agree on the law.&#8221;</em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p>A briefing, requested by the IMCO committee, has been published on <em><strong><a href="https://www.europarl.europa.eu/thinktank/de/document/ECTI_BRI(2026)772652">&#8220;Fighting Premature Digital Obsolescence of Consumer Goods and Consumer Rights&#8221;</a></strong></em> (author: Prof. Dr. Alberto De Franceschi). </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;After the Digital Content Directive (DCD) and Sale of Goods Directive (SGD), some measures to improve durability and fight premature digital obsolescence were introduced by further EU legislation, but they are still not sufficient. Information about the minimum period during which the producer or the provider supplies software updates should be made available to consumers in all cases, and not only where the producer or provider makes such information available to the consumer&#8217;s contractual counterparty (Article 6(1)(lc) Consumer Rights Directive (CRD)). Information about the supply of updates should also be provided, according to Article 6(1)(o) CRD, in the framework of information on the duration of the contract.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The US Supreme Cour</strong>t <a href="https://www.scotusblog.com/2026/07/supreme-court-allows-texas-to-enforce-law-requiring-age-verification-and-parental-consent-on-app/">decided</a> <strong>to allow Texas to enforce law requiring age verification and parental consent on apps</strong>. (SCOTUSblog)</p><ul><li><p><em><strong>Why does this matter? </strong>The challengers argue that the law (Texas App Store Accountability Act) violates the First Amendment. Texas countered such arguments that the law &#8220;regulates commercial transactions, rather than speech,  specifically, the conditions in which young people can agree to contractual terms and conditions required to downland an app.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Norwegian Data Protection Authority</strong> <a href="https://www.datatilsynet.no/regelverk-og-verktoy/lover-og-regler/avgjorelser-fra-datatilsynet/2026/overtredelsesgebyr-til-elkjop/">has imposed</a> <strong>an infringement fine of NOK 20 million (Approx. EUR 1.7 million) </strong>on Elkj&#248;p, <strong>including for processing personal data in a customer loyalty club without valid consent</strong>. <em>(A summary and detailed analysis of the case, together with practical advice on data privacy compliance, <a href="https://nordialaw.com/loyalty-club-consent-elkjop-fine/">is available from Kjell Steffner, Nordia Law</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong></em>The investigation found <span>several violations: Elkj&#248;p did not have (i) obtained a valid consent to process personal data in the customer club, (ii) made necessary assessments about the use of personal data for new purposes, (iii) made good enough assessments of legitimate interest as a basis for processing, and (iv) responded to customer rights requests within the GDPR deadline.</span></p></li></ul></li><li><p><strong>The Spanish Data Protection Authority (AEPD)</strong> <a href="https://www.aepd.es/documento/ps-00101-2025.pdf">imposed</a> <strong>a fine of EUR 1,050,000 on Vodafone Espana</strong>. A person contacted Vodafone&#8217;s customer service, went through security checks and received a copy of the invoices containing the personal data of the person concerned (Vodafone subscriber) to an unauthorized email address.  </p><ul><li><p><em><strong>Why does this matter? </strong></em>The AEPD found violations of Art. 6(1) GDPR (no legal basis for data disclosure) and Art. 32 GDPR (inadequate security measures).</p></li></ul></li><li><p><strong>The Italian Data Protection Authority</strong> <a href="https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/10269594">has fined</a> <strong>Character Technologies Inc.</strong>, a US company that manages <strong>Character.AI</strong>, a generative AI service that allows users, including minors, to create and interact via chat with virtual characters, <strong>for EUR 158,000</strong>. Considering the risks deriving from the use of generative AI in an entertainment service that is also accessible to minors, <strong>the Authority has also prescribed further measures</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the preparation of the Data Protection Impact Assessment (DPIA) and the designation of the representative in the EU were late.</em></p><p><em>Critical issues were also noted in the guarantees for the protection of minors and in the age verification procedures.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1579">preliminarily found</a> <strong>Meta in breach of the Digital Services Act for the addictive design of Instagram and Facebook</strong>. The investigation focuses on features such as infinite scroll, autoplay, push notifications, and the platforms&#8217; highly personalised recommender systems.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The Commission's investigation indicates that Meta did not adequately assess the risks of its addictive design on the physical and mental wellbeing of users, including minors and vulnerable adults. [&#8230;] Meta disregarded available information about the time minors spend on Instagram or Facebook at night and how the optimisation of its different formats - such as reels and stories - could lead to excessive or compulsive use of the services. [&#8230;] Evidence also shows that Meta's current mitigation measures failed to effectively tackle the risks stemming from its addictive design.&#8221;</em></p></li><li><p><em><strong>What are the next steps?</strong> &#8220;Meta now has the possibility to exercise its right to defence. It may examine the documents in the Commission&#8217;s investigation files and reply in writing to the Commission&#8217;s preliminary findings. In parallel, the European Board for Digital Services will be consulted. If the Commission&#8217;s views are ultimately confirmed, the Commission may issue a non-compliance decision, which can trigger a fine proportionate to the nature, gravity, recurrence and duration of the infringement, capped at 6% of the total worldwide annual turnover of the provider.&#8221;</em></p></li></ul></li><li><p><strong>The EU General Court <a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260096en.pdf">dismissed</a> Apple&#8217;s actions regarding its designation as a gatekeeper</strong> and it <strong>confirmed the designation of Apple as a gatekeeper in relation to the App Store and iOS</strong>, and finds the actions concerning the iMessage service to be inadmissible. (The full text of the judgment is available <a href="https://infocuria.curia.europa.eu/tabs/jurisprudence?sort=DOC_DATE-DESC&amp;searchTerm=%22T-1079%2F23%22&amp;publishedId=T-1079%2F23&amp;lang=EN">here</a>.)</p><ul><li><p><em><strong>Why does this matter? </strong></em>The European Commission designated Apple as a &#8216;gatekeeper&#8217; under the Digital Markets Act (DMA) in relation to the App Store, the operating system iOS and the web browser Safari in 2023. The Commission  decided not to designate Apple as a gatekeeper in relation to iMessagealso, however, it classified the iMessage service as a number-independent interpersonal communications service (NIICS) constituting a core platform service (CPS). As the Court dismissed all the actions brought by Apple, the Commission&#180;s decions remain in place.</p></li></ul></li><li><p><strong>The Court of Justice <a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260093en.pdf">upholds</a> Google&#8217;s fine of around &#8364;4.1 billion</strong>. (<em>The full text of the judgment is available <a href="https://infocuria.curia.europa.eu/tabs/jurisprudence?sort=DOC_DATE-DESC&amp;searchTerm=%22C-738%2F22+P%22&amp;publishedId=C-738%2F22+P">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong></em>This judgment <strong>confirms the penalty imposed for Google Search&#8217;s abuse of a dominant position</strong> in the context of the Android operating system.</p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The UN&#180;s Independent International Scientific Panel on AI </strong><a href="https://www.un.org/independent-international-scientific-panel-ai/sites/default/files/2026-07/en_Preliminary%20Report_.pdf">published</a> <strong>its Preliminary Report</strong> that provides <strong>an evidence-based assessment of opportunities, risks and impacts of artificial intelligence.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This report presents a preliminary independent scientific assessment of the capabilities and the emerging opportunities and risks of artificial intelligence (AI), providing a shared evidence base to help Member States navigate a rapidly changing technology. [&#8230;] The report is the first of its kind and will be updated progressively throughout the year, with thematic briefs addressing developments as they arise. It reflects the best available evidence at the time of publication, in a field moving so rapidly that any snapshot requires a commitment to revision.&#8221;</em></p></li><li><p>Key takeaways: </p><p><em><strong>(i) Capabilities and adoption</strong></em></p><ul><li><p><em>&#8220;Recent years have seen rapid, and in some areas accelerating, progress in a range of AI capabilities.&#8221;</em></p></li><li><p><em>&#8220;These gains have unlocked useful applications across science, health, agriculture, accessibility, knowledge work and information technology, including in the development of AI itself.&#8221;</em></p></li><li><p><em>&#8220;AI adoption has accelerated broadly, and unevenly, across countries and sectors.&#8221;</em></p></li><li><p><em>&#8220;While the shift towards AI agents is under way, their future adoption and economic impacts will likely be shaped by continued improvements in their ability to accomplish knowledge work with little or no human oversight.&#8221;</em></p></li></ul><p><em><strong>(ii) Understanding and managing risks</strong></em></p><ul><li><p><em>&#8220;AI development entails risks, with potential negative impacts on human rights, social systems and the environment.&#8221;</em></p></li><li><p><em>&#8220;Looking ahead, the gap between rapidly improving capabilities and effective risk management methods may lead to catastrophic outcomes.&#8221;</em></p></li><li><p><em>&#8220;AI risks are unevenly distributed across populations and countries, while AI development and the wealth it creates are highly concentrated.&#8221;</em></p></li></ul><p><em><strong>(iii) Governing artificial intelligence to unlock benefits and mitigate risks</strong></em></p><ul><li><p><em>&#8220;Realizing the full benefits of AI while minimizing its risks requires good governance.&#8221;</em></p></li><li><p><em>&#8220;Policymakers seeking to shape this governance face an evidence dilemma: they need evidence to make informed consequential governance decisions, but by the time the evidence exists, it might be too late to make them, as the evidence lags behind the pace of AI development.&#8221;</em></p></li><li><p><em>&#8220;The capacity to act on existing evidence of AI risks and impacts is unevenly distributed.&#8221;</em></p></li><li><p><em>&#8220;Concrete next steps to close the above gaps exist, but each requires sustained investment in Member State capacity to shape, evaluate and deploy AI.&#8221;</em></p></li></ul></li></ul></li><li><p><strong><span>The Federal Trade Commission</span></strong><span> </span><a href="https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-seeks-public-comment-policy-statement-addressing-ai-accuracy"><span>is seeking public comment</span></a><span> </span><strong><span>on a </span><a href="https://www.ftc.gov/legal-library/browse/federal-trade-commissions-proposed-policy-statement-concerning-suppression-accuracy-artificial">proposed policy statement</a><span> addressing concerns that AI companies may be manipulating the behavior of their AI systems</span></strong><span> contrary to reasonable consumer expectations for objectivity and accuracy. </span>The public will have until July 31, 2026, to submit comments on the policy statement.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;As the proposed policy statement explains, the FTC Act prohibits businesses from engaging in &#8220;unfair or deceptive&#8221; conduct. The proposed statement goes on to describe how AI companies that distort their systems&#8217; outputs to achieve undisclosed ideological objectives could be deceiving consumers in violation Section 5 of the FTC Act. Such conduct, it explains, may be at odds with explicit and implicit representations made to consumers about the effectiveness and suitability of AI systems for various tasks.&#8221;</em></p></li></ul></li><li><p><span>The </span><strong><span>Stanford Institute for Human-Centered Artificial Intelligence (HAI)</span></strong><span> </span><a href="https://hai.stanford.edu/industry/human-centered-large-language-models"><span>published</span></a><span> an industry report, titled </span><em><strong><span>&#8220;Human-Centered Large Language Models&#8221;</span></strong></em><span>. </span></p><ul><li><p><em><strong>Why does this matter? </strong>Key takeaways: </em></p><ul><li><p><em>Competitive advantage is moving from model capability to human experience. </em></p></li><li><p><em>Data strategy is now AI and market strategy. </em></p></li><li><p><em>Benchmark performance does not guarantee business value. </em></p></li><li><p><em>The strongest deployments will optimize human&#8211;AI collaboration, not pursue automation by default. </em></p></li><li><p><em>Interaction design may produce greater returns than incremental model improvements. </em></p></li><li><p><em>AI risk accumulates over time, not only through isolated harmful outputs. </em></p></li><li><p><em>Human-centered AI requires accountable, cross-functional ownership. </em></p></li></ul></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-97f?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-97f?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-97f?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Data Protection Board (EDPB)</strong> has adopted (i) <strong><a href="https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_202602_anonymisation_v1_en_0.pdf">guidelines on anonymisation</a>, </strong>(ii) <strong><a href="https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_2020603_webscraping_v1_en_0.pdf">guidelines on web scraping in the context of generative AI</a></strong>, and (iii) <strong>the final version of its <a href="https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_202502_blockchain_v2_en.pdf">guidelines on the processing of personal data through blockchain technologies</a></strong>. The guidelines on anonymisation and on web scraping will be subject to public consultation until 30 October 2026.</p><ul><li><p><em><strong>Why does this matter? </strong></em><span>The new </span><strong><span>guidelines on anonymisation</span></strong><span> takes into account the judgment of the Court of Justice (CJEU) in the case </span><a href="https://infocuria.curia.europa.eu/tabs/document?source=document&amp;docid=303863&amp;doclang=EN">C-413/23 P EDPS v SRB of 4 September 2025</a><span> and other CJEU jurisprudence. </span><em><span>(For a more detailed summary of the new EDPB Guidelines on Anonymisation, please also see </span><a href="https://www.linkedin.com/posts/laszlopok_new-edpb-guidelines-on-anonymisation-activity-7481293629945356288-11PS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAACAz90B0FfKvtKWSOOCdG6dsEK5TJIFYQY"><span>my Linkedin post</span></a><span>.)</span></em></p></li><li><p><em>&#8220;<span>In its </span><strong>guidelineson web scraping in the context of generative AI, </strong><span>the Board clarifies various aspects of the GDPR compliance of web scraping, including </span><strong>the legal basis for such activities</strong><span> and the </span><strong>conditions under which special categories of data can be processed in this context.</strong>&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] <span>the EDPB has adopted the final version of its </span><strong><span>guidelines on blockchain technologies</span></strong><span>.</span> <span>The guidelines help organisations using blockchain technologies to comply with the GDPR. The EDPB explains how blockchains work, assessing the different possible architectures and their implications for the processing of personal data.&#8221;</span></em></p></li></ul></li><li><p><strong>The EDPB and the Anti-Money Laundering Authority (AMLA)</strong> <a href="https://www.edpb.europa.eu/news/edpb-and-amla-to-develop-joint-guidelines-on-partnerships-for-information-sharing_en">are working together</a><strong> to develop Joint Guidelines on how to share information to fight financial crime while protecting personal data</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The fight against financial crime depends on cooperation, and information sharing can help detect and prevent money laundering and terrorist financing. Art. 75 of the AML Regulation makes this possible, allowing companies and professionals covered by anti-money laundering rules to share information with each other and with public authorities, within clear limits. The new information sharing possibility will apply from 10 July 2027.&#8221;</em></p></li></ul></li><li><p><strong>The Spanish Data Protection Authority (AEPD) and the Belgian Data Protection Authority</strong> <a href="https://www.aepd.es/en/guides/videogames-recommendations-industry.pdf">issued</a> <strong>joint recommendations and best practices for data protection in video games.</strong> </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!1LKL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 424w, /__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 848w, /__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 1272w, /__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!1LKL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png" width="1001" height="703" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:703,&quot;width&quot;:1001,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77833,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/203404102?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 424w, /__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 848w, /__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 1272w, /__u/substackcdn.com/image/fetch/$s_!1LKL!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34cde751-b0ce-4a6a-9117-983478af623e_1001x703.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Source: <a href="https://www.aepd.es/en/guides/videogames-recommendations-industry.pdf">Joint recommendations for video games</a>, Figure 1, p. 9</em></p></li><li><p><strong>The Recorded Future&#700;s Insikt Group</strong> <a href="https://www.recordedfuture.com/research/state-digital-surveillance-risk-landscape">published</a> its report about the <em><strong>&#8220;State Digital Surveillance Risk Landscape&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong></em>Key findings: </p><ul><li><p><em>&#8220;Insikt Group assesses that there are &#8220;high&#750; or &#8220;very high&#750; levels of digital surveillance risk in 31 countries due to their use of advanced surveillance capabilities against foreign businesses, travelers, and government critics, with limited to no oversight.&#8221;</em> </p></li><li><p><em>&#8220;A further 74 countries have &#8220;medium&#750; levels of digital surveillance risk. [&#8230;]&#8221;</em> </p></li><li><p><em>&#8220;By exploiting control over telecommunications infrastructure and online platforms, governments can conduct mass, indiscriminate monitoring of traffic and user data. [&#8230;]&#8221;</em>  </p></li><li><p><em>&#8220;The proliferation of commercial spyware, AI-powered public security infrastructure, and increasing collection of biometric and personal data almost certainly enables governments to build comprehensive digital profiles of individuals and leverage them for targeted surveillance operations.&#8221;</em></p></li><li><p><em>&#8220;Digital surveillance that is not subject to robust oversight and does not abide by the principles of legality, necessity, and proportionality very likely incurs heightened operational, reputational, and legal costs for organizations and individuals, including the loss of sensitive data, the proliferation of cyber vulnerabilities, and legal and physical risks.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The Australian Privacy Commissioner (OAIC) has inspected the use of tracking pixels by 50 healthcare providers and <a href="https://www.oaic.gov.au/news/blog/your-life,-pixelated-how-tracking-pixels-watch-your-every-click">provided</a> findings, case studies and recommendations</strong> to assist individuals and organisations in managing the privacy risks posed by this technology. </p><ul><li><p><em><strong>Why does this matter? </strong></em>Key takeaways for organisations:</p><ul><li><p><em>&#8220;Assess the sensitivity of data (actual and inferred) and configure tracking pixels appropriately [&#8230;]</em></p></li><li><p><em>Know what tracking technologies are in place and where [&#8230;]</em></p></li><li><p><em>Ensure transparency and valid consent mechanisms are in place [&#8230;]</em></p></li><li><p><em>Implement a privacy by design approach [&#8230;]&#8221; </em></p></li></ul></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>The European Union Agency for Cybersecurity (ENISA)</strong> <a href="https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era">published</a> its <strong><span>view on Cybersecurity in the Frontier AI Era.</span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This publication provides national competent authorities in Member States and EU policymakers, defenders, and service providers with an initial set of recommendations to support them in their respective roles towards developing the necessary operational capabilities to face machine-speed threats. The recommendations are not an all-inclusive checklist. ENISA aims to further refine and expand these recommendations in close cooperation with Member States and EUIBAs and will align these to upcoming European Commission Action Plan.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>The Future Foundation</strong> proposed <em><strong>&#8220;The 10 Rules for the Digital World&#8221;</strong></em>, &#8220;<em>a novel ethical framework to help individuals and societies make prudent, human-centered decisions in the age of &#8220;supercharged&#8221; technology.</em>&#8221; (&#8220;<em>The 10 Rules for the Digital World</em>&#8221; paper <a href="https://cacm.acm.org/opinion/the-power-of-10-new-rules-for-the-digital-world/">was published</a> by Communications of the ACM. <span>A more extended version with a preamble is available at </span><a href="https://www.thefuturefoundation.eu/en"><span>the webpage of The Future Foundation</span></a><span>.</span>) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Each entry reflects a key technological issue seen through the lens of one of the biblical Ten Commandments and then plays out two exemplary interpretations: the perspective of an ordinary end user and that of a professional. By using the word &#8220;interpretation,&#8221; we signal that there are myriad ways to interpret a rule in a person&#8217;s individual context.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!2lVy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 424w, /__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 848w, /__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!2lVy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png" width="910" height="738" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:738,&quot;width&quot;:910,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:462148,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/203404102?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 424w, /__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 848w, /__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2lVy!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2df40170-854c-4a39-ad81-eeea08d0b618_910x738.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Source: <a href="https://www.thefuturefoundation.eu/en/10-rules">10 Rules for the Digital World</a>, The Future Foundation</em></p></li></ul></li><li><p><strong><span>The European Commission</span></strong><span> </span><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1429"><span>will grant</span></a><span> </span><strong><span>&#8364;5.8 million to establish the first two Regional Cable Hubs, in the Baltic Sea and the Mediterranean Sea. </span></strong><span>It is also launching today a </span><a href="https://hadea.ec.europa.eu/news/cef-digital-second-call-proposals-increase-europes-submarine-cable-repair-capacities-launched-year-2026-06-18_en">&#8364;40 million call to increase European capacity to repair submarine communication cables</a><span>.</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>These two actions contribute to the delivery of the </span><a href="https://digital-strategy.ec.europa.eu/en/news/eu-action-plan-cable-security-mapping-and-risk-assessment-approach-agreed-group-member-states-and">EU Action Plan on Cable Security</a><span>, supporting the security and resilience of Europe's critical submarine data and energy cables, and enhancing our collective capacity to monitor, detect and respond to threats targeting critical undersea infrastructure.&#8221;</span></em></p><p></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-97f?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-97f?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><strong><a href="https://research.kent.ac.uk/trust-moral-machines/wp-content/uploads/sites/2908/2026/06/Myers-Everett-2026-Experimental-Philosophy.pdf">&#8220;Is an Intelligent Machine a Moral Machine?&#8221;</a></strong></em> (authors: Myers and Everett)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;As artificial intelligence (AI) systems become increasingly sophisticated and used in more consequential domains, an unspoken assumption seems to suggest enhanced performance or &#8220;intelligence&#8221; would entail greater alignment and safety &#8211; &#8220;morality&#8221;. [&#8230;] In this paper we draw on these philosophical debates and explore the psychological foundations of this apparent misconception: do people infer machine morality from machine intelligence? [&#8230;] While most work focuses on intelligence and morality as independent and orthogonal facets of person perception and trust, we instead highlight a robust pattern of results in which people do not only perceive intelligence and morality in AI agents, but concerningly infer moral competence and moral motivation from machine intelligence - with consequences for trust and danger. These findings reveal a systematic tendency to infer moral qualities from intelligence, including moral motivation. This may distort public understanding of AI safety and trust, with concerning ethical and epistemic implications.&#8221;</em></p></li></ul></li><li><p><em><a href="https://arxiv.org/abs/2606.26294">&#8220;</a><strong><a href="https://arxiv.org/abs/2606.26294">The Red Queen G&#246;del Machine: Co-Evolving Agents and Their Evaluators&#8221;</a></strong></em><strong> </strong>(authors: Iacob et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] We introduce the Red Queen Godel Machine (RQGM), an evolutionary framework for recursive self-improvement under non-stationary utilities. [&#8230;] We begin by showing that even on verifiable coding tasks, the RQGM improves test pass rate over the prior SOTA by adding a complementary agent-as-a-judge code-review signal. This signal is cheaper and the RQGM uses 1.35x-1.72x fewer tokens. We then turn to scientific paper writing and reviewing, and Olympiad-level proof writing and grading, where the RQGM improves performance over prior self-improving agents: co-evolved writers reach 1.78x-1.86x higher acceptance rates under a diverse agent-as-a-judge panel, while co-evolved graders reach 9% higher ground-truth accuracy. In paper reviewing, the strongest baseline reviewer over-accepts AI-generated papers at up to 1.91x the human rate. The RQGM corrects this by introducing an adversarial objective that discovers reviewers equally stringent on AI and human work.&#8221;</em></p></li></ul></li><li><p><em><strong><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7019658">&#8220;The DMA&#8217;s Contribution to EU Digital Sovereignty&#8221;</a></strong></em> (author: Jan Blockx)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Within the scope of core platform services, the Digital Markets Act (DMA) can contribute to the EU&#8217;s digital sovereignty. Since the gatekeepers of core platform services in the EU are currently mostly based in the United States and China, the DMA&#8217;s objective of making their position more contestable could, if successful, provide more room for providers from the EU or from other jurisdictions than those in which the gatekeepers are based. The growth of such alternative providers would reduce the ability of a single non-EU jurisdiction to control core platform services provided in the EU. [&#8230;] To enhance EU digital sovereignty, additional supply and demand-side measures should be taken to facilitate the growth of European providers of digital services.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>OpenAI</strong> <a href="https://openai.com/index/gpt-5-6/">has launched</a> <strong>GPT&#8209;5.6 family of models</strong> for general availability following the limited preview&#8288;: new flagship, Sol, alongside Terra, a balanced model for everyday work, and Luna, the most cost-efficient model.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;GPT&#8209;5.6 Sol sets a new standard for both intelligence and efficiency, achieving state-of-the-art results across coding, knowledge work, cybersecurity, and science while outperforming previous and competing frontier models with fewer tokens and at lower estimated cost.&#8221;</em></p></li></ul></li><li><p>&#8220;<em><strong>Chinese-built AI models are gaining traction among U.S. companies</strong> as they narrow the performance gap with leading American rivals <strong>while remaining significantly cheaper to use</strong></em>.&#8221; (<a href="https://www.cnbc.com/2026/07/07/chinese-ai-models-costs-us-openai-anthropic.html">CNBC</a>)</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The share of tokens used by U.S. companies on Chinese AI models via OpenRouter &#8212; a platform that enables developers to access a range of AI models &#8212; has sat above 30% each week since Feb. 8, with that figure rising as high at 46%. The average across the previous 12 months was just 11%, falling to 4.5% in the first half of 2025.&#8221;</em></p></li></ul></li><li><p><strong>OpenAI and Broadcom</strong> <a href="https://openai.com/index/openai-broadcom-jalapeno-inference-chip/">unveiled</a> <strong>Jalape&#241;o, OpenAI&#8217;s first LLM-optimized inference chip</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>Early testing shows that the first-generation accelerator will deliver performance per watt substantially better than current state-of-the-art.</span></em><span>&#8221;</span></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 27]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-a00</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-a00</guid><pubDate>Fri, 03 Jul 2026 08:00:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Us09!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Council <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/">gave</a> its final green light on</strong> <strong>the Digital Omnibus on AI. </strong><em>(The text of the Digital Omnibus on AI is available <a href="https://data.consilium.europa.eu/doc/document/PE-30-2026-INIT/en/pdf">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the co-legislators [&#8230;] agreed on a fixed timeline for the delayed application of high-risk rules: the new application dates would be <strong>2 December 2027</strong> for stand-alone high-risk AI systems and <strong>2 August 2028</strong> for high-risk AI systems embedded in products.&#8221;</em></p></li><li><p><em><strong>What are the next steps?</strong> &#8220;The legislative act will be published in the EU&#8217;s official journal shortly and will enter into force on the third day after this publication.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1420">proposed</a> new measures <strong>to strengthen the EU&#8217;s response to an evolving criminal landscape</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The package includes two regulations to strengthen the mandates of Europol and Eurojust, a revision of the European Investigation Order, and amendments to the Data Protection Regulation for Union institutions and bodies. These measures will improve cooperation and complementarity between EU agencies and national authorities, including police, customs and courts. They will support more joint investigations, speed up prosecutions, and facilitate the exchange of information through a clearer legal framework and less administrative burden.</em>&#8221;</p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>President Trump <a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-ushers-in-the-next-frontier-of-quantum-innovation/">signed</a> an <a href="https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/">Executive Order</a> to supercharge U.S. innovation in quantum technologies</strong> and strengthen the national security in this critical area.  </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Order establishes a national effort to develop the first ever quantum computer powerful enough to initiate the era of quantum-enabled scientific discovery and accelerate quantum capabilities for commercial applications. [&#8230;] The Order ensures that the United States enters this new era of quantum innovation with ambitious national goals, a strong domestic workforce, and trusted supply chains in coordination with our international allies and partners.&#8221; </em></p></li></ul></li><li><p>According to <a href="https://www.politico.com/news/2026/06/26/exclusive-meta-asks-california-lawmakers-for-shield-from-child-harm-penalties-00978728">Politico&#180;s report</a>, &#8220;<em>social media giant <strong>Meta is pushing California state lawmakers to shield it from pending legislation that would increase legal penalties in child-harm cases</strong></em>&#8221;. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The draft amendments would exempt social media platforms from increased penalties in child harm cases if the companies activate a suite of default child safety settings. Those settings include disabling autoplay, restricting geolocation data sharing, silencing nighttime notifications, preventing kids from receiving direct messages from unknown adults, shielding minors&#8217; profiles from public view and preventing explicit material from being shown to kids.&#8221;</em></p></li><li><p><em>&#8220;<span>If accepted by lawmakers, the amendments could lead to reduced payouts in the pending cases where parents and young people accuse Meta, Google, TikTok and Snap of designing platforms that fostered youth harms including addiction, depression and suicidality. Meta and Google were ordered to pay $6 million in damages after </span><a href="https://www.politico.com/news/2026/03/25/meta-youtube-found-liable-for-social-media-addiction-in-landmark-trial-00844625">a Los Angeles jury found the companies liable</a><span> in one such case in March.&#8221;</span></em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p>I have collected several websites and databases that present <strong>legal disputes, lawsuits and other enforcement actions</strong> initiated against AI companies or in connection with AI-based products or services:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;1229e5d9-fc1e-4875-87fe-e58e501434e4&quot;,&quot;caption&quot;:&quot;With the advent of AI, there are almost countless lawsuits and other cases related to the use and development of AI, especially in various copyright, privacy, defamation, employment, product liability, and consumer protection cases. Below, I have collected several websites and databases that collect legal disputes, lawsuits and other enforcement actions&#8230;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI litigation, enforcement, regulatory trackers &amp; more&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:190153242,&quot;name&quot;:&quot;L&#225;szl&#243; P&#243;k&quot;,&quot;bio&quot;:&quot;Senior Privacy Manager | Data protection | AI &amp; Privacy &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b183c3a0-04e4-4eba-bd5d-9e0b44f0657e_509x509.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-23T08:30:43.345Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://datalawgy.substack.com/p/ai-litigation-enforcement-regulatory&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:202569440,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:3421089,&quot;publication_name&quot;:&quot;Datalawgy&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!cRmk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F439bc514-3d51-4f6b-a0e8-71078e9f026f_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The US Supreme Court</strong> decided <em><strong>in <a href="https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf">Trump v. Slaughter</a></strong></em> that <strong>the president of the US has the power to fire leaders of independent agencies or commissions.</strong> This means that <strong>the independence of the US Federal Trade Commission (&#8220;FTC&#8221;) may also be questioned</strong>. (Slaughter was a member of the FTC and President Trump removed her from her position in March 2025 without giving any reason.)</p><ul><li><p><em><strong>Why does this matter? </strong></em>According to the <a href="https://www.scotusblog.com/2026/06/court-allows-trump-to-fire-ftc-commissioner-and-overturns-major-restraint-on-presidential-power/">first assessments</a>, this <em>&#8220;<span>decision was a major victory for proponents of </span><strong><a href="https://www.npr.org/2025/07/31/nx-s1-5478640/unitary-executive-theory-argues-to-restore-the-presidents-authority">the &#8220;unitary executive&#8221; theory</a></strong><span> &#8211; the idea that the president should have complete control over the executive branch. Under this theory, the president should be able to fire any member of the executive branch, and laws &#8211; like the one that the court struck down &#8211; that restrict his ability to do so violate the separation of powers.</span></em><span>&#8221;</span></p></li><li><p><em><strong>Why is this decision important from a data protection perspective?</strong></em> FTC&#8217;s independence plays an important role in the EU&#8217;s adequacy regime with respect to the United States. As NOYB (Max Schrems&#8217; NGO) <a href="https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers">says</a>: &#8220;<em>since 2000 the EU has relied on the &#8220;independent&#8221; FTC as the enforcer of EU-US deals on personal data. According to EU treaty law such oversight must be independent. In the current EU-US deal, the European Commission relies on the independent FTC 259 (!) times.</em>&#8221; NOYB <a href="https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers">argues</a> that &#8220;<em>given that the EU in almost all cases relied on the &#8220;independence&#8221; of the FTC as a privacy watchdog, the entire structure of the EU-US Data Privacy Framework has just collapsed.</em>&#8221;</p></li><li><p><em><strong>What will be the next steps?</strong></em> The US Supreme Court decision has no direct impact on the European Commission&#180;s adequacy decision, i.e., the EU-USData Privacy Framework remains in force until either the European Commission repeals it or the Court of Justice annuls it. However, NOYB<em> </em>immediately sent a<em> </em><a href="https://noyb.eu/sites/default/files/2026-06/Letter_noyb_EU-US_data_transfers.pdf">formal letter to the European Commission</a><span>, &#8220;</span><em><span>asking the Commission to take the appropriate steps to repeal the EU-US data deal in an orderly way.</span></em><span>&#8221; and NOYB also announced that it</span><em> will also &#8220;file a lawsuit in the coming weeks, aiming to allow the CJEU to annul the current deal. However, such a lawsuit typically takes 2-3 years until a final decision is reached.&#8221;</em></p></li><li><p><em><strong>What are the main lessons about compliance?</strong></em> Companies should start preparing for a scenario where they can no longer count on the Commission&#180;s adequiacy decision for transferring personal data to the US. In addition, if SCCs or BCRs are used, the underlying &#8216;transfer impact assessments&#8217; may also be reviewed to verify the legality of transfers and to review the measures applied. </p></li><li><p><em><strong>What might be the broader implications?</strong></em> The U.S. Supreme Court&#8217;s decision could also have a broader impact on European technology and data souverignty initiatives, where there are clashes on many battlefields between the U.S. and the EU...  </p></li></ul></li><li><p>The <strong>US Supreme Court</strong> <a href="https://supreme.justia.com/cases/federal/us/609/25-112/">also decided</a> <em><strong>in <span>Chatrie </span>v<span>. United States</span></strong></em><span>, concluding that </span>police officers conducted a Fourth Amendment search when they acquired location data from Google.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;An individual has a reasonable expectation of privacy in records about his cell phone&#8217;s location, and police intrude on that constitutionally protected interest when they demand the information&#8212;even though for only a limited time, and from a third-party tech company.&#8221;</em></p></li></ul></li><li><p><strong>The Australian Privacy Commissioner</strong> (OAIC) <a href="https://www.oaic.gov.au/news/media-centre/privacy-commissioner-finds-privacy-breaches-in-third-party-tracking-pixel-investigation">has found</a> <strong>that health service providers</strong> Medmate Australia Pty Ltd (Medmate) and Monash IVF Pty Ltd (Monash) <strong>interfered with the privacy of individuals whose sensitive information was collected via third-party tracking pixels</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Privacy Commissioner&#8217;s decision establishes that the use of tracking pixels to track website visitors to health-related websites, and to subsequently target them with advertising on social media platforms, amounts to a collection sensitive information for which the website provider must obtain users&#8217; consent.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p>The <strong>Centre on Regulation in Europe (CERRE) </strong>published two issue papers (author: Daniel Schnurr) regarding <strong>the implementation of the AI Act rules for high-risk AI systems</strong>: (i) <em><strong><a href="https://cerre.eu/wp-content/uploads/2026/06/CERRE_Information-Sharing-and-Cooperation-along-the-AI-Value-Chain.pdf">&#8220;Information Sharing and Cooperation along the AI Value Chain&#8221;</a></strong></em> and (ii) <em><strong><a href="https://cerre.eu/wp-content/uploads/2026/06/CERRE_Evolving-AI-Systems-under-the-AI-Act-Substantial-Modification-and-AI-Value-Chain.pdf">&#8220;Evolving AI Systems under the AI Act: Substantial Modification and AI Value Chain&#8221;</a></strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong></em>The papers addresses<em> &#8220;two central questions for policy makers and firms: when does a change to an AI system create new legal duties, and how should responsibility be shared between the actors that develop, supply, adapt, and deploy AI systems?&#8221;</em></p></li></ul></li><li><p><strong>UNESCO</strong> <a href="https://www.unesco.org/en/articles/first-local-readiness-assessment-report-launched-flanders">launched</a> the <em><strong>&#8220;Flanders Artificial Intelligence Readiness Assessment Report&#8221;</strong></em>, the first sub-national application of the Readiness Assessment Methodology (RAM), developed under the EU-funded &#8220;AI-Ready Flemish Public Administration&#8221; project.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Readiness Assessment Methodology is a diagnostic tool developed by UNESCO to support governments in evaluating their preparedness to implement artificial intelligence in line with ethical principles, human rights, and the public interest. In the case of Flanders, the assessment was adapted to a multi-level governance context, reflecting regional, federal, and European dimensions, which was supplemented by expert interviews and stakeholder consultations across the Flemish AI ecosystem.&#8221;</em></p></li><li><p><em>&#8220;The report presents a set of governance recommendations aligned with the UNESCO Recommendation on the Ethics of Artificial Intelligence. These include strengthening independent oversight mechanisms, enhancing capacity for ethical impact assessments, promoting inclusive AI literacy and reskilling across society, and safeguarding the wellbeing of young people in AI-driven environments.&#8221;</em></p></li></ul></li><li><p><strong>Nemko Digital</strong> <a href="https://digital.nemko.com/insights/ai-washing-explained-claims-risks-and-compliance">published</a> a brief overview about AI Washing in 2026: <em>&#8220;<strong><span>AI Washing in 2026: From Illusion of Autonomy to Proof of Performance&#8221;</span></strong></em><span> (author: Joy Haggenburg).</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;AI washing can be understood as the strategic overstatement or misrepresentation of artificial intelligence capabilities in products, services, and organisational narratives. At its core, it constructs an illusion of autonomy: outcomes are framed as the result of advanced machine&#8209;learning systems, when in practice they may depend on conventional software, manual processes, or extensive human labour. [&#8230;]&#8221; <span>&#8203;</span></em></p></li><li><p><em><span>&#8220;To reduce the risk of AI washing and ensure compliance with emerging regulatory standards, organisations should adopt clear internal governance measures regarding the development, classification, and communication of AI systems. Effective governance requires transparency not only in the technical functioning of AI systems, but also in how these systems are presented to consumers, investors, and regulators.</span>&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-a00?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-a00?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-a00?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong><span>The EDPB</span></strong><span> has launche</span><strong><span>d a </span><a href="https://www.edpb.europa.eu/contact/flag-an-inconsistency_en">dedicated contact form</a><span> </span></strong><span>for stakeholders</span><strong><span> to report possible inconsistencies in how the GDPR is interpreted across Europe</span></strong><span>.</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The new tool enables stakeholders to </span><strong>report alleged divergences between national positions, as well as between national positions and those of the EDPB</strong><span>.&#8221;</span></em></p></li></ul></li><li><p><strong>The Franch Data Protection Authority (CNIL)</strong> <a href="https://www.cnil.fr/sites/default/files/2026-06/g7_dpas_compendium_of_approches_on_smart_glasses.pdf">published</a> <strong>a compendium of G7 data protection and privacy authorities approaches on smart glasses</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This compendium provides a high-level overview of current developments in each G7 jurisdiction. Looking across jurisdictions can provide valuable insight into common concerns and approaches and has the potential to help develop future common positions to address this global challenge.&#8221;</em></p></li><li><p>At the <strong>G7 data protection and privacy authorities roundtable</strong> several other important topics <a href="https://www.cnil.fr/sites/default/files/2026-06/g7_dpa_communique.pdf">have been discussed</a>:</p><ul><li><p>Children&#8217;s protection online and age assurance (see the <em><strong><a href="https://www.cnil.fr/sites/default/files/2026-06/g7_dpa_statement_on_age_assurance.pdf">&#8220;Statement for Privacy-Preserving Age Assurance&#8221;</a></strong></em>),</p></li><li><p>Connected Home Devices and Children&#8217;s Privacy (see the <em><strong><a href="https://www.cnil.fr/sites/default/files/2026-06/g7_children_s_privacy_in_connected_home_devices_paper.pdf">&#8220;G7 Data Protection and Privacy Authorities Joint Paper on Connected Home Devices and Children&#8217;s Privacy&#8221;</a></strong></em>),</p></li><li><p>Smart glasses (see above),</p></li><li><p>Agentic AI,</p></li><li><p>Enforcement cooperation,</p></li><li><p>Data Free Flow with Trust.</p></li></ul></li><li><p><strong>China</strong> <a href="https://www.scmp.com/tech/article/3358459/china-keeps-eye-ai-smart-glasses-privacy-concerns-come-focus">has also issued</a> <strong>the first industry code of conduct for smart glasses.</strong></p><ul><li><p><em><strong>Why does this matter? </strong></em>&#8220;<em>The voluntary code calls on smart eyewear manufacturers to adopt a &#8220;minimum data collection&#8221; approach, provide clear indicators when cameras or microphones are active, and obtain explicit user consent before recording.</em>&#8221;</p></li></ul></li></ul></li><li><p><strong>CERRE </strong>also <a href="https://cerre.eu/wp-content/uploads/2026/06/CERRE_Making-Data-Protection-Fit-for-the-Age-of-AI.pdf">published</a> a paper (authors: Marco Bassini and Cristiana Firullo) on <em><strong>&#8220;Making Data Protection Fit for the Age of AI&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This report examines the Digital Omnibus [&#8230;] as both a legal and an economic intervention in the EU digital rulebook. [&#8230;] We conclude that the Omnibus is a constructive attempt to make EU data protection fit for the age of AI. However, to help Europe make the most of AI, lawmakers must clarify the law and ensure changes do not hurt smaller businesses, thus stifling competition.&#8221;</em></p></li></ul></li><li><p><strong>Yeong Zee Kin, Chief Executive of the Singapore Academy of Law</strong> <a href="https://fpf.org/blog/understanding-data-embassies-and-corridors/">argues</a> in a blog post that <strong>data embassies can be potential solutions to data localization requirements</strong>. However, as he concludes, &#8220;<em>these concepts demand rigorous debate, targeted pilot initiatives, and continual refinement to ensure they effectively address both commercial needs and regulatory oversight.</em>&#8221;</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Over the past few years, geopolitical contestations have increased the rhetoric over data sovereignty. [&#8230;] One natural response is to mandate the localization of data. [&#8230;] The data embassy was initially developed as a government-to-government (G2G) arrangement. It has since seized the attention of businesses as a solution to circumvent data localization requirements. The primary motivation is to extend domestic laws and standards of protection to data that has been exported. [&#8230;]  </em></p></li><li><p>This paper explores <em>&#8220;how increasing data localization requirements, fuelled by shifting geopolitical landscapes and heightened security concerns, present significant challenges to the seamless flow of information essential for the digital economy. In response, policy innovations such as data embassies and data corridors offer promising, albeit nascent, pathways to reconcile the imperatives of cross-border data transfers with legitimate governmental interests.&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>The International Monetary Fund (IMF)</strong> <a href="https://www.imf.org/en/publications/imf-notes/issues/2026/06/29/artificial-intelligence-and-cybersecurity-in-the-financial-sector-576706">published</a> an article, titled <em><strong>&#8220;Artificial Intelligence and Cybersecurity in the Financial Sector&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] This note argues that the main financial stability concern lies less in new types of cyberattacks than in the scale effects AI can unleash across common technologies, amplifying how quickly and widely risks spread. Strong governance and technical controls that limit the &#8220;blast radius&#8221; of breaches&#8212;that is, the scope of damage they can cause&#8212;and effectively contain their spread, robust response and recovery capacity, and stronger international coordination will be essential to safeguard financial stability. A whole-of-nation approach, bringing together government, the private sector, and other stakeholders, is warranted given the cross-sector implications, limited private incentives for adequate cyber risk management, and benefits of public-private collaboration.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>Ireland <a href="https://irish-presidency.consilium.europa.eu/">assumed</a> the Presidency of the Council of the European Union from 1 July to 31 December 2026.</strong> The Policy Programme of the Irish Presidency is available <a href="https://irish-presidency.consilium.europa.eu/en/programme/programme-of-the-irish-presidency/">here</a>.</p><ul><li><p><em><strong>Why does this matter? </strong></em>The Irish Presidency will take forward an agenda, focusing on competitiveness, values and security. </p></li></ul></li><li><p><strong>The European Commission</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/boosting-tech-deployment-beyond-2027-new-study-highlights-digital-opportunities-and-challenges-eu">has published</a> a new study, <em><strong>&#8220;The EU&#8217;s Critical Digital Capacities: Deployment Beyond 2027&#8221;</strong></em>, revealing both strengths and gaps in Europe&#8217;s digital transformation ahead of the next Multiannual Financial Framework.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The study finds that next EU funding programme must address </span><strong>challenges </strong><span>around underinvestment, skills shortages, and market fragmentation, while building on </span><strong>existing strengths</strong><span> in green digital solutions, open source and a trusted regulatory and data protection framework.&#8221;</span></em></p></li></ul></li><li><p><strong>The European Parliament</strong> <a href="https://www.europarl.europa.eu/thinktank/en/document/BUDG_BRI(2026)785787">published</a> a briefing, titled <em><strong>&#8220;Possible EU own resource based on a digital levy - Cross-border services trade, digital transformation and tax implications&#8221;</strong></em>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] Services can now also be produced digitally and supplied automatically, which will expand further with artificial intelligence (AI). Automated digital services (ADSs) can be supplied from the cloud, so that there is no specific location for the place of supply. [&#8230;] many countries have adopted unilateral measures, especially digital services taxes (DSTs). [&#8230;] The various DSTs adopted by states all over the world have targeted a range of digitalised transactions, mainly sales to consumers. Overall, they cover only some 16 % of global cross-border services. The DST proposed for the EU in 2018 was targeted at services &#8216;characterised by user value creation&#8217;. If adopted now, it would cover some 10 % of EU cross-border services imports, generating up to an estimated EUR 7 billion annually. Extended to the wider scope of DSTs adopted by all EU Member States, it would cover 19 % of such imports, raising the estimated revenue to some EUR 13 billion annually. Consideration could also be given to a DST that applies to all ADSs. [&#8230;] This would cover 33 % of EU imports of cross-border services, or 39 % by including payments for intellectual property rights (IPRs), generating almost EUR 32 billion annually. A broader tax would also have a less discriminatory effect, making it harder to treat as a trade barrier.&#8221;</em></p></li><li><p>It&#180;s worth noting that <strong>President Trump</strong> has vowed <strong>to impose a 100% import tariff on any European country that introduces a digital services tax on American technology giants</strong>. (<a href="https://www.bbc.com/news/articles/cn4rd71411ko">BBC</a>)</p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-a00?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-a00?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><strong><a href="https://arxiv.org/pdf/2602.08013">&#8220;Small Agent Group is the Future of Digital Health&#8221;</a></strong></em> (authors: Meng et al.) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] real-world clinical needs include not only effectiveness, but also reliability and rea sonable deployment cost. Since clinical decision making is inherently collaborative, we challenge the monolithic scaling paradigm and ask whether a Small Agent Group (SAG) can support better clinical reasoning. SAG shifts from single-model intelligence to collective expertise by distributing reasoning, evidence-based analysis, and critical audit through a collaborative deliberation process. [&#8230;] Our results show that SAG achieves superior performance compared to a single giant model, both with and without additional optimization or retrieval-augmented generation. These findings suggest that the synergistic reasoning represented by SAG can substitute for model parameter growth in clinical settings. Overall, SAG offers a scalable solution to digital health that better balances effectiveness, reliability, and deployment efficiency.&#8221;</em></p></li><li><p>Overview of the SAG architecture and workflow (Figure 2 of the article):</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Us09!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 424w, /__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 848w, /__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Us09!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png" width="1011" height="404" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:404,&quot;width&quot;:1011,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175758,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/202593057?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 424w, /__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 848w, /__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Us09!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee1853a-c263-4018-86e6-f5e4fb8d061f_1011x404.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Source: Figure 2, <a href="https://arxiv.org/pdf/2602.08013">Small Agent Group is the Future of Digital Health</a>, p. 3</em></p></li></ul></li><li><p><em><strong><a href="https://www.nature.com/articles/s41586-026-10688-0">&#8220;Disparate privacy risks from medical AI&#8221;</a></strong></em> (authors: Knolle et al.) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>Medical artificial intelligence (AI) models hold the promise to improve global access to high-quality diagnostics. However, the training data underlying these models often contain sensitive patient information that may be exposed through privacy attacks. [&#8230;] We focus on membership inference attacks</span><sup> </sup><span>(MIAs), which seek to determine whether the data of a given individual were used to train a model. [&#8230;] Together, our findings show that aggregate privacy metrics can severely underestimate individual privacy risk. Whether the disparate risk profiles we observe extend to attacks beyond MIAs remains an open question, motivating the further development of risk assessment and mitigation techniques that cater to all data-contributing patients.&#8221;</span></em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p>As of June 30, <strong>the US export controls on Anthropic&#180;s Fable 5 and Mythos 5 <a href="https://www.anthropic.com/news/redeploying-fable-5">have been lifted</a></strong>.</p><ul><li><p><em><strong>Why does this matter? </strong></em>Fable 5 will be available starting July 1, to users globally on certain payment plans. Access to Mythos 5 has been restored &#8220;<em>for a set of US organizations, following the US government&#8217;s approval on <a href="https://x.com/AnthropicAI/status/2070665903440871779">June 26</a>.</em>&#8221; The access will be exapnded, in coordination with the US government, to the broader set of domestic and international partners of Anthropic in the Glasswing program.</p></li><li><p><strong>Anthropic</strong> also <strong><a href="https://www.anthropic.com/news/claude-sonnet-5">introduced</a> Sonnet 5</strong>, the most agentic Sonnet model yet that &#8220;<em>can make plans, use tools like browsers and terminals, and run autonomously at a level that, just a few months ago, required larger and more expensive models.</em>&#8221;</p></li></ul></li><li><p><strong>The French domestic intelligence agency (DGSI)</strong> <strong>is dropping Palantir</strong> and <strong>it will replace </strong>the American firm&#8217;s data-analysis tools <strong>with software from ChapsVision, a French company</strong>. (<a href="https://thenextweb.com/news/frances-intelligence-service-is-dropping-palantir-for-a-homegrown-rival">The Next Web</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Germany&#8217;s domestic intelligence service, the BfV, recently chose ChapsVision over Palantir for its own data analysis, and the Bundeswehr has been pressing for a secure cloud in which no foreign firm has structural access. [&#8230;] <span>In Britain, the government has been </span><a href="https://thenextweb.com/news/uk-nhs-palantir-contract-review-break-clause">reviewing its &#163;330m NHS contract</a><span> with the firm. The pattern is European governments reconsidering how much of their most sensitive infrastructure should run on American software.&#8221;</span></em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[DSA tracker #9]]></title><description><![CDATA[Developments in enforcing the Digital Services Act]]></description><link>https://datalawgy.substack.com/p/dsa-tracker-9</link><guid isPermaLink="false">https://datalawgy.substack.com/p/dsa-tracker-9</guid><pubDate>Tue, 30 Jun 2026 09:01:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lD-4!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There are more and more developments regarding the implementation and enforcement of the DSA and more resources are available regarding the application of thes Regulation. In this newsletter, I summarize the most important events and news related to the application of the DSA.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ol><li><p><strong>Regulatory &amp; enforcement actions</strong></p></li></ol><ul><li><p><strong>The European Commission</strong> <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1178">issued</a> <strong>a fine of &#8364;200 million to Temu</strong> under the Digital Services Act. </p><ul><li><p><em><strong>What does this mean? </strong>&#8220;The evidence at the disposal of the Commission indicates that consumers in the EU are very likely to encounter illegal items on Temu.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;The company failed to diligently identify, analyse, and assess the systemic risks of illegal products being offered on its platform and the resulting harm to consumers in the European Union.&#8221;</em></p><ul><li><p><em>&#8220;Temu&#8217;s risk assessment of 2024 falls short of the standards laid out in the DSA:</em></p><ul><li><p><em>It is based on general information about risks concerning the eCommerce sector as a whole, rather than on specific evidence about Temu&#8217;s own service, including public reports and testing.</em></p></li></ul><ul><li><p><em>It seriously underestimated how often EU consumers are likely to encounter illegal items. Evidence from a mystery shopping exercise included in the Commission&#8217;s investigation shows that a very high percentage of the selected chargers failed basic safety tests, while a high percentage of tested baby toys posed safety risks of medium to high severity, as they contain chemicals exceeding legal safety limits or pose suffocation hazards due to detachable parts.</em></p></li></ul><ul><li><p><em>It did not properly assess how the design of its service - including recommender systems and product promotion programmes by affiliated influencers - could amplify dissemination risks of illegal products.&#8221;</em></p></li></ul></li></ul></li><li><p><em><strong>What are the next steps?</strong></em> <em>&#8220;Temu has until 28 August 2026 to submit an action plan to the Commission, as required by Article 75 of the DSA. The plan must set out measures to remedy the breach of its risk-assessment obligations. The European Board for Digital Services will have one month from receipt of the plan to issue its opinion. The Commission will then have a further month to adopt its final decision and set a reasonable period for implementation. Failure to comply with the non-compliance decision may lead to periodic penalty payments. The Commission continues to engage with Temu to ensure compliance with the decision and with the DSA more generally.&#8221;</em></p></li></ul></li><li><p><strong>The Special Panel on child safety online</strong> <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1361">met</a> for the third and final time on June 16. </p><ul><li><p><em><strong>What does this mean? </strong>&#8220;Discussions focused on lessons learned and good practices in the EU and in partner countries, as well as on crucial topics such as the empowerment of parents and guardians to ensure their children&#8217;s wellbeing online. This meeting builds upon insights from <a href="https://digital-strategy.ec.europa.eu/en/policies/panel-child-safety-online">the two previous gatherings of the Special Panel</a> on child safety online, which examined the risks and benefits of digital services for children and the EU regulatory framework for protecting minors online, respectively.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;<span>On the occasion of the final panel, a new </span><a href="https://europa.eu/eurobarometer/surveys/detail/3686">Eurobarometer survey</a><span> confirms the significant impact of excessive screentime and social media on the mental and physical health of young people. On average, young people across Europe spend 4.5 hours online during a school day and 6.1 hours a day at weekends. Most strikingly, 14% of adolescents report spending more than 10 hours a day on screens.&#8221;</span></em></p></li><li><p><em><strong>What are the next steps?</strong></em> <em>&#8220;On 13 July, the Panel&#8217;s Co-chairs will present recommendations to President Ursula von der Leyen on how to further strengthen the EU&#8217;s trailblazing framework for the protection of minors online.&#8221;</em></p></li></ul></li><li><p>In the context of the EU-Brazil Digital Partnership in Bras&#237;lia, <strong>the Commission&#8217; services responsible for enforcing the DSA <a href="https://digital-strategy.ec.europa.eu/en/news/commission-services-cooperate-brazils-data-protection-agency-protection-minors-online">signed an administrative arrangement</a> focused on the protection of minors online with Brazil&#8217;s Ag&#234;ncia Nacional de Prote&#231;&#227;o de Dados (ANPD)</strong>.</p><ul><li><p><em><strong>What does this mean? </strong>&#8220;The arrangement strengthens cooperation on the protection of minors online between the Commission&#8217; services and ANPD, with special attention paid to transparency obligations for digital platforms, risk assessment and mitigation measures, and technological cooperation on algorithms and artificial intelligence. The arrangement will facilitate information exchange, including technical expert dialogues. It will, for instance, enable both authorities to share best practices, conduct joint studies, and cooperate on research projects.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;<span>The Commission services have signed similar administrative arrangements with the UK's </span><a href="https://digital-strategy.ec.europa.eu/en/news/commission-services-sign-administrative-arrangement-ofcom-support-enforcement-social-media">Ofcom and</a><span> Australia's </span><a href="https://digital-strategy.ec.europa.eu/en/news/commission-services-sign-administrative-arrangement-australian-esafety-commissioner-support">eSafety Commissioner</a><span>. The three regulators launched </span><a href="https://digital-strategy.ec.europa.eu/en/news/commission-agrees-advance-child-safety-online-australias-esafety-commissioner-and-uks-ofcom">a trilateral cooperation group on age assurance</a><span>. More recently, the Commission has signed an arrangement with Japan's </span><a href="https://digital-strategy.ec.europa.eu/en/news/commission-services-sign-cooperation-arrangement-japans-ministry-internal-affairs-and">Ministry of Internal Affairs and Communications</a><span>.&#8221;</span></em></p></li><li><p><em><strong>What are the next steps?</strong></em> <em>&#8220;The Commission remains committed to expanding global collaboration with leading national regulators to ensure a fair and safe digital future.&#8221;</em></p></li></ul></li><li><p><strong>G7</strong> <a href="https://www.entreprises.gouv.fr/files/files/Actualites/2026/g7/principles-safer-and-more-secure-digital-space-for-minors.pdf">agreed</a> on <strong>common principles for protecting minors online.</strong></p><ul><li><p><em><strong>What does this mean? </strong>G7 Digital and Tech Ministers, are committed to affirming the following principles defining a safer and more secure digital space for minors:</em></p><ul><li><p><em>Principle 1: Effective age assurance is key to ensure a safer, more secure, and age-appropriate experience for minors.</em></p></li><li><p><em>Principle 2: Protect minors from harms online through safety by design approaches such as protective and by default settings, including parental control tools, which prevent minors from being exposed to content, interactions and features that are not age appropriate, safe and secure.</em></p></li><li><p><em>Principle 3: The creation and distribution of child sexual abuse material and criminal activity related to non-consensual intimate imagery must be prevented, consistent with G7 members&#8217; current applicable legal obligations.</em></p></li><li><p><em>Principle 4: Parents, guardians and carers should be equipped with easy-to-use, privacy-respecting, effective parental control tools that are interoperable when technically feasible to help guide and empower minors online.</em></p></li><li><p><em>Principle 5: Minors should be empowered with a comprehensive education focused on building the necessary literacy and skills in order to better understand digital systems, and critically engage with digital technologies, media and information, to recognize risks and thrive online.</em></p></li><li><p><em>Principle 6: Minors&#8217; safety is safeguarded by the implementation of risk management, assessment and mitigation, and following safety-by-design approaches.</em></p></li><li><p><em>Principle 7: Building a safer and more secure digital space for minors is enabled by digital service providers&#8217; cooperation with relevant stakeholders.</em></p></li></ul></li><li><p><strong>The European Commission <a href="https://digital-strategy.ec.europa.eu/en/news/commission-welcomes-g7-agreement-common-principles-protecting-minors-online">welcomed</a> the G7 agreement</strong> on the abopve principles. </p><ul><li><p><em><strong>What is the background to this?</strong> &#8220;<span>The agreed principles are firmly based on the EU&#8217;s ambitious approach, which combines decisive enforcement actions to hold platforms accountable with a collective societal effort to strengthen media literacy and raise awareness. Specifically, they reflect </span><a href="https://digital-strategy.ec.europa.eu/en/policies/protecting-young-people-online">existing measures at EU level to protect and empower children</a><span>, from the Digital Services Act (DSA) and its Guidelines on the protection of minors, over the Better Internet for Kids Strategy (BIK+), to the AI Act and the action plan against cyberbullying, and beyond.&#8221;</span></em></p></li></ul></li><li><p><strong>UNICEF <a href="https://www.unicef.org/press-releases/note-correspondents-first-ever-g7-principles-protect-children-online">also welcomed</a> the G7 digital and technology ministers&#8217; landmark agreement</strong> on common principles for a safer digital space for children.</p></li></ul></li><li><p><strong>Bureau Europ&#233;en des Unions de Consommateurs (BEUC*)</strong> <a href="https://www.beuc.eu/enforcement/sponsored-scammers#why-this-action">filed</a> <strong>a complaint against Meta, TikTok and Google</strong> <strong>with the European Commission and the competent national Digital Services Coordinators</strong> together with 29 members across 27 countries. <em>(*BEUC is the umbrella group for 42 independent consumer organisations from 31 countries.)</em></p><ul><li><p><em><strong>What does this mean? </strong>&#8220;Under the Digital Services Act (DSA), Meta, TikTok and Google are required to have effective mechanisms in place to fight fraudulent ads and reduce the risks to consumers. However, our evidence gathering shows that Meta, TikTok and Google not only fail to pro-actively remove fraudulent ads but also do little when notified about such scams.&#8221;</em></p></li><li><p><em><strong>What is the background to this?</strong> &#8220;The findings show that financial scams remain widespread on Meta, TikTok, and Google, and that platforms systematically fail to take effective corrective actions. <br>In total, we flagged 893 fraudulent ads across 13 countries that were active on either Meta, TikTok or Google.</em></p><p style="text-align: justify;"><em>In a nutshell, consumer groups found that:</em></p><ul><li><p style="text-align: justify;"><em>Meta rejected nearly 43% of the submitted ads.</em></p></li><li><p style="text-align: justify;"><em>TikTok only removed 21% of the submitted ads. In 37% of the cases, TikTok claimed that the ad was removed before they could review it.</em></p></li><li><p style="text-align: justify;"><em>Google removed 60% of the submitted ads.&#8221;</em></p></li></ul></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/dsa-tracker-9?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/dsa-tracker-9?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/dsa-tracker-9?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><ol start="2"><li><p><strong>Guidelines, opinions, reports &amp; more</strong></p></li></ol><ul><li><p><strong>The European Commission <a href="https://digital-strategy.ec.europa.eu/en/news/commission-seeks-feedback-draft-trusted-flaggers-guidelines-under-digital-services-act">is seeking feedback</a> on its draft guidelines on trusted flaggers</strong>, organisations specialised in identifying illegal content online. Feedback can be provided <strong>by 10 July</strong>. </p><ul><li><p><em><strong>What is it about?</strong> &#8220;The draft guidelines clarify the criteria, as well as the process by which the Digital Services Coordinators award the &#8216;trusted flagger' status. They also provide guidance on the technical requirements trusted flaggers and platforms should follow when processing notices of illegal content. Finally, the guidelines aim to ensure trusted flaggers remain independent, objective and accountable, and that they are operating in full respect of freedom of expression. The guidelines also include measures to safeguard the integrity of trusted flaggers, to ensure the mechanism is not misused. These measures include public annual transparency reports by trusted flaggers, as well as procedures to suspend or revoke the status of trusted flaggers.&#8221;</em></p></li><li><p>More than 70 trusted flaggers <a href="https://digital-strategy.ec.europa.eu/en/policies/trusted-flaggers-under-dsa">have already been appointed</a> under the DSA. </p></li><li><p>The Commission <a href="https://digital-strategy.ec.europa.eu/en/library/study-supporting-implementation-trusted-flaggers-mechanism-under-digital-services-act">has published</a> a study mapping key stakeholders and assessing the early stages of implementation of the trusted flaggers mechanism.</p></li></ul></li><li><p><strong>The DSA Observatory</strong> published an analysis, <em>&#8220;<strong><a href="https://dsa-observatory.eu/2026/06/08/state-of-play-of-dsa-dispute-settlement-meaningful-redress-uneven-results/">State of Play of DSA Dispute Settlement: Meaningful Redress, Uneven Results&#8221;</a></strong></em><strong>.</strong></p><ul><li><p><em><strong>What is it about?</strong> &#8220;After almost two years of certified out-of-court dispute settlement (ODS) bodies operating under Article 21 of the Digital Services Act (DSA), the first transparency reports provide early evidence of how this new due process layer operates in practice. Drawing on 2025 data from multiple ODS bodies, this article assesses what value the system is already delivering, and where current constraints, including platform participation and information-sharing, limit its effectiveness. We discuss possible ways forward, including stronger incentives, technical infrastructure and feedback loops.&#8221;</em></p></li></ul></li><li><p><strong>The DSA Observatory</strong> also published an analysis, titled <em><a href="https://dsa-observatory.eu/2026/05/19/digital-fairness-act-why-we-need-an-ambitious-dfa-to-protect-digital-consumers-from-manipulative-and-addictive-design-practices/">&#8220;</a><strong><a href="https://dsa-observatory.eu/2026/05/19/digital-fairness-act-why-we-need-an-ambitious-dfa-to-protect-digital-consumers-from-manipulative-and-addictive-design-practices/">Digital Fairness Act: Why we need an ambitious DFA to protect digital consumers from manipulative and addictive design practices&#8221;</a></strong></em> (by John Albert, Marijn Sax, and Natali Helberger).</p><ul><li><p><em><strong>What is it about?</strong> &#8220;In this policy brief, we advocate for an ambitious Digital Fairness Act that futureproofs EU consumer law and protects consumers from the full range of unfair digital commercial practices across digital services, including deceptive interfaces, manipulative design, and addictive features. This brief builds on proposals developed in the report &#8220;Towards Digital Fairness&#8221;.&#8221;</em></p></li></ul></li><li><p><strong>P&#225;l Szil&#225;gyi</strong> <a href="https://www.linkedin.com/pulse/german-court-rules-art-25-dsa-dark-patterns-online-booking-p%C3%A1l-vtn4f/">wrote</a> about a recent <strong>German court judgment</strong> (OLG Dresden, 14 UKl 3/25)<strong> on Art. 25 DSA, assessing dark patterns in the online booking process. </strong></p><ul><li><p><em><strong>What is it about?</strong> &#8220;The DSA expressly excludes from its scope practices that fall within the ambit of the <strong>Unfair Commercial Practices Directive 2005/29/EC (UCPD)</strong>, even where the UCPD does not prohibit them. [&#8230;] This reasoning is consistent with the earlier OLG Bamberg decision (GRUR-RR 2025, 238) and establishes an important principle: <strong>the DSA dark pattern prohibition is residual in nature</strong>, it only applies where the UCPD leaves a gap.&#8221;</em></p></li></ul></li><li><p><strong>Global Advisory Experts</strong> published a <strong><a href="https://globaladvisoryexperts.com/digital-services-act-germany/">Compliance Checklist for Streaming Platforms, Creators &amp; Publishers in Germany</a>.</strong></p><ul><li><p><em><strong>What is it about?</strong> &#8220;This guide delivers the step-by-step compliance checklists, contract templates and implementation roadmaps that streaming platforms, content creators and publishers need right now to meet their obligations under the DSA and the DDG in 2026.&#8221;</em></p></li></ul></li><li><p><strong>Eucrim published</strong> an <em><strong><a href="https://eucrim.eu/news/overview-of-the-latest-developments-under-the-digital-services-act-november-2025-february-2026/">&#8220;Overview of the Latest Developments Under the Digital Services Act: November 2025 - February 2026</a>&#8221;</strong></em> (by Dr. Anna Pingen). </p><ul><li><p><em><strong>What is it about?</strong> &#8220;This news item continues the reporting on the latest DSA developments by giving a chronological overview. It covers the period from November 2025 to February 2026.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ol start="3"><li><p><strong>Further DSA resources</strong></p></li></ol><ul><li><p><a href="https://transparency.dsa.ec.europa.eu/">DSA Transparency Database</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-whistleblower-tool">DSA whistleblower tool</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-enforcement">The enforcement framework under the DSA</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses">List of designated very large online platforms and search engines under DSA</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-brings-transparency">Transparency reports of VLOPs and VLOSEs</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-board">European Board for Digital Services</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/dsa-dscs#1720699867912-0">Digital Services Coordinators</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/trusted-flaggers-under-dsa">Trusted flaggers under the DSA</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/code-conduct-disinformation">The Code of Conduct on Disinformation</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/code-conduct-countering-illegal-hate-speech-online">The Code of conduct on countering illegal hate speech online +</a></p></li><li><p><a href="https://www.disinfo.eu/">EU Disinfo LAB</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 26]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-639</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-639</guid><pubDate>Fri, 26 Jun 2026 11:03:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lD-4!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>California Governor Newsom</strong> <a href="https://www.gov.ca.gov/2026/05/21/governor-newsom-signs-first-of-its-kind-executive-order-to-prepare-workers-and-businesses-for-potential-ai-disruption/">signed</a> first-of-its-kind <strong>executive order to prepare workers and businesses for potential AI disruption.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The order mobilizes state agencies, labor experts, economists, universities, and industry leaders to develop new policies, gather data, and identify early warning signs of workforce disruption &#8212; while ensuring workers share in the gains created by AI-driven productivity.&#8221;</em></p></li><li><p>Several mass layoffs due to the use of AI have been announce recently, e..g, &#8220;<em><strong>Oracle</strong> shed about <strong>21,000 roles globally</strong> in the last year as the US technology giant reshapes its business around artificial intelligence (AI) [&#8230;]</em>&#8221; (<a href="https://www.bbc.com/news/articles/c4gy0x0j5deo">BBC</a>), &#8220;<em><strong><a href="https://www.bbc.com/news/articles/cde5y2x51y8o">Amazon and Facebook-owner Meta have cut thousands</a></strong><span> of job in recent months as they invest heavily in AI.</span></em><span>&#8221; (</span><a href="https://www.bbc.com/news/articles/cde5y2x51y8o"><span>BBC</span></a><span>). According to </span><a href="https://techcrunch.com/2026/06/15/the-ai-layoff-wave-is-becoming-a-powder-keg/"><span>Tech Crunch</span></a><span>, &#8220;</span><em><span>so far this year, there have been an estimated </span><a href="https://www.trueup.io/layoffs">363 layoffs</a><span> at tech companies this year, affecting nearly 150,000 people &#8212; a pace of about 974 people per day, 44% faster than last year &#8212; according to TrueUp, a tech job board and recruiting platform that also runs one of the most widely cited tech layoff trackers. [&#8230;] </span><strong><span>AI was the most-cited reason for layoffs across every industry</span></strong><span> for the third month running according to outplacement firm Challenger, Gray &amp; Christmas. [&#8230;]</span></em><span>&#8221;</span> </p></li></ul></li><li><p><strong>The Irish Government</strong> <a href="https://www.gov.ie/en/department-of-enterprise-tourism-and-employment/press-releases/publication-of-the-regulation-of-artificial-intelligence-bill-2026/">published</a> the <strong>Regulation of Artificial Intelligence Bill 2026</strong>. (The Bill text is available <a href="https://www.oireachtas.ie/en/bills/bill/2026/69/">here</a>.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Bill, once enacted, will give effect in Ireland to the EU Artificial Intelligence Act [&#8230;]. The Bill establishes Oifig IS na h&#201;ireann (AI Office of Ireland) as an independent statutory body which will act as Ireland's central coordinating authority for the implementation of the AI Act.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p>As NOYB <a href="https://noyb.eu/en/eu-member-states-and-google-suddenly-want-keep-cookie-banners">reports</a>, &#8220;<em>as part of <strong>the &#8216;Digital Omnibus&#8217;</strong>, the European Commission [&#8230;] wanted <strong>to get rid of cookie banners </strong>and replace them with an automated signal. [&#8230;] <strong>In the Council&#8217;s latest <a href="https://noyb.eu/sites/default/files/2026-06/5th_compromise_text_Politico.pdf">position paper</a></strong><a href="https://noyb.eu/sites/default/files/2026-06/5th_compromise_text_Politico.pdf"> of 18 June</a>, t<strong>he plan to abolish the cookie banner has been scrapped. </strong>[&#8230;]</em>&#8221; (<a href="https://noyb.eu/en/eu-member-states-and-google-suddenly-want-keep-cookie-banners">NOYB</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>Users should actually have the option here to consent only if they wish to be tracked online of their own free will. </span><a href="https://arxiv.org/pdf/1909.02638#page=10">Depending on the study</a><span>, only around </span><a href="https://noyb.eu/sites/default/files/2020-05/Gallup_Facebook_DE.pdf">3&#8211;10% of people</a><span> want this. However, through so-called dark patterns (e.g. hidden &#8216;No&#8217; buttons or pre-ticked consent boxes), the tracking industry achieves </span><a href="https://web.archive.org/web/20210226012342/https:/www.quantcast.com/press-release/quantcast-choice-powers-one-billion-consumer-consent-choices/">consent rates</a><span> of </span><a href="https://www.cnil.fr/sites/cnil/files/atoms/files/full_2022-12-02_v2.pdf">up to 90%</a><span>.&#8221;</span></em></p></li></ul></li><li><p><strong>The Ada Lovelace Institute</strong> <a href="https://www.adalovelaceinstitute.org/blog/eu-digital-omnibus/">published</a> a blog post <strong>commenting on the EU Digital Omnibus.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>Much&#8239;of the discussion&#8239;around the </span><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52025PC0837">EU Digital Omnibus proposal</a><span> has focussed on article-by-article analysis of the proposed changes and their individual impacts. Although it is critical to make sure that the individual articles are sound, we must look at what the articles achieve together. This post draws on new legal analysis that examines five individual amendments to the GDPR in the Omnibus and their cumulative effects on both the overall level of protection the GDPR offers and primary EU law.&#8221;</span></em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong><span data-color="rgb(38, 50, 75)" style="color: rgb(38, 50, 75);">The European Commission </span><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1366"><span data-color="rgb(38, 50, 75)" style="color: rgb(38, 50, 75);">published</span></a><span data-color="rgb(38, 50, 75)" style="color: rgb(38, 50, 75);"> the fourth State of the Digital Decade report</span></strong><span data-color="rgb(38, 50, 75)" style="color: rgb(38, 50, 75);">, showing that</span><strong> </strong><span data-color="rgb(38, 50, 75)" style="color: rgb(38, 50, 75);">Europe has made progress on its </span><a href="https://digital-strategy.ec.europa.eu/en/policies/europes-digital-decade">2030 digital transformation targets</a>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Digital Decade Policy Programme serves as the EU's strategic compass for advancing and investing in Europe's digital competitiveness and sovereignty. The report evaluates progress made by the EU in its digitalisation across the board, including in critical infrastructures, digitalisation of business, digital skills, and digitalisation of public services. This year, the report goes beyond stocktaking, outlining priority reforms and investments at EU and Member States level in an attempt to guide digital funding allocations in the next EU Multiannual Financial Framework.&#8221;</em></p></li><li><p><em><strong>What are the next steps?</strong> &#8220;[&#8230;] the Commission calls on Member States to update their <a href="https://digital-strategy.ec.europa.eu/en/policies/national-strategic-roadmaps">National Digital Decade Roadmaps</a> with concrete measures, while ensuring stronger alignment with the next Multiannual Financial Framework, notably in the context of the preparation of the National and Regional Partnership Plans and the future EU Competitiveness Fund. [&#8230;]&#8221;</em></p></li><li><p>The Commission <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1366">also published</a> the last <strong>Special Eurobarometer</strong>, showing that <em>&#8220;79% of Europeans rank digital policy as a top EU priority in shaping the future.</em>&#8221;</p></li></ul></li><li><p><strong>Norway plans to impose a ban on the use of generative AI tools among primary school students, </strong>while there are also plans <strong>to restrict the use of such tools in the education of older children</strong> to avoid a negative impact on learning. (<a href="https://www.reuters.com/technology/norway-imposes-near-ban-ai-elementary-school-2026-06-19/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Pupils from first &#8203;through seventh grade, aged 6 to 13, should as a general &#8203;rule not be using AI, while those in lower secondary school, aged 14 to &#8204;16, can &#8288;cautiously adopt tools under teachers' supervision, the government said. In upper secondary education, from ages 17 to 19, students should learn to use AI appropriately so that they are prepared for further education and work [&#8230;]&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>With the advent of AI, there are almost countless lawsuits and other cases related to the use and development of AI, especially in various copyright, privacy, defamation, employment, product liability, and consumer protection cases.</strong><span> I have collected several websites and databases that collect legal disputes, lawsuits and other enforcement actions initiated against AI companies or in connection with AI-based products or services: </span></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;478ef430-4bf9-469b-bd7b-7fc5f4a731b8&quot;,&quot;caption&quot;:&quot;With the advent of AI, there are almost countless lawsuits and other cases related to the use and development of AI, especially in various copyright, privacy, defamation, employment, product liability, and consumer protection cases. Below, I have collected several websites and databases that collect legal disputes, lawsuits and other enforcement actions&#8230;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI litigation, enforcement, regulatory trackers &amp; more&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:190153242,&quot;name&quot;:&quot;L&#225;szl&#243; P&#243;k&quot;,&quot;bio&quot;:&quot;Senior Privacy Manager | Data protection | AI &amp; Privacy &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b183c3a0-04e4-4eba-bd5d-9e0b44f0657e_509x509.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-23T08:30:43.345Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://datalawgy.substack.com/p/ai-litigation-enforcement-regulatory&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:202569440,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:3421089,&quot;publication_name&quot;:&quot;Datalawgy&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Italian Data Protection Authority (Garante)</strong> <a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10261301#1">issued</a> an <strong>EUR 180,000 fine to Emirates</strong> as the airline did not comply with the principles of transparency and limit the retention of data to the period strictly necessary. <em>(A summary is also available in <a href="https://www.reuters.com/business/healthcare-pharmaceuticals/italys-privacy-watchdog-fines-emirates-over-handling-passenger-health-data-2026-06-17/">this Reuters&#180;report</a> in English.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Airlines may process the health data of passengers with disabilities or reduced mobility (PMR) without obtaining their consent when this is necessary to ensure the safety of transport and assistance during the journey, in accordance with the provisions of the sector regulations. However, they must ensure compliance with the principles of transparency on data processing and limit their retention to the period strictly necessary to pursue these purposes.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p>According to <a href="https://today.westlaw.com/Document/I566bd4016b5711f1baf28c363891ecdf/View/FullText.html?transitionType=Default&amp;contextData=(sc.Default)&amp;firstPage=true">Westlaw Today</a>, &#8220;<em><strong>two companies affiliated with Madison Square Garden </strong>are facing separate <strong>class-action lawsuits</strong> <strong>alleging they negligently handled customer data, allowing a hacker group to steal customer information tied to about 26 million records</strong>.</em>&#8221;</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Both lawsuits claim the companies negligently maintained customers&#8217; PII and left their computer systems vulnerable to cyberattacks. A key allegation in both suits is that the companies have failed to notify potential victims.&#8221;</em></p></li></ul></li><li><p><strong>The Commission </strong><a href="https://digital-strategy.ec.europa.eu/en/news/commission-reaches-preliminary-position-amazons-and-microsofts-market-leading-cloud-services-should">has informed</a> <strong>Amazon and Microsoft</strong> of its preliminary view that<strong> they should be designated as gatekeepers under the Digital Markets Act (DMA), for their cloud computing services, Amazon Web Services (AWS) and Microsoft Azure (Azure) respectively.</strong></p></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Commission</strong> <strong><a href="https://digital-strategy.ec.europa.eu/en/consultations/targeted-consultation-draft-guidelines-classification-high-risk-artificial-intelligence-systems">extended</a> the deadline <span data-color="rgb(0, 0, 46)" style="color: rgb(0, 0, 46);">in the</span></strong><span data-color="rgb(0, 0, 46)" style="color: rgb(0, 0, 46);"> </span><strong><span>consultation on the draft guidelines for the classification of high-risk AI systems. </span></strong><span>The new dedline is</span><strong> July 23, 2026. </strong></p><ul><li><p><em><strong>Why does this matter? </strong></em>The consultation aims to collect feedback on the clarity of the guidelines and usefulness of the examples. <span data-color="rgb(0, 0, 46)" style="color: rgb(0, 0, 46);">The</span> final guidelines<span data-color="rgb(0, 0, 46)" style="color: rgb(0, 0, 46);"> will be </span>adopted <span data-color="rgb(0, 0, 46)" style="color: rgb(0, 0, 46);">by the </span>end of 2026<span data-color="rgb(0, 0, 46)" style="color: rgb(0, 0, 46);">.</span></p></li></ul></li><li><p><strong>The UK&#180;s Government Office for Science</strong> <a href="https://www.gov.uk/government/publications/ai-scenarios-2030-helping-policymakers-plan-for-the-future-of-ai">published</a> <strong>its</strong> <strong>set of AI 2030 scenarios (</strong><em><strong>&#8220;AI Scenarios 2030: Helping policy makers plan for the future of AI&#8221;</strong></em><strong>)</strong>. This Foresight report sets out 5 scenarios for how AI could develop by 2030 and it updates the first version of the report that was published in 2025. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;These scenarios are tools for exploring uncertainty, stress-testing and developing policy. They are not predictions, and the future may involve elements from all scenarios. It is, however, clear that AI will have a profound impact by 2030.&#8221;</em></p></li><li><p>The key findings are as follows:</p><ul><li><p><em>&#8220;AI capabilities will continue to increase. [&#8230;]</em></p></li><li><p><em>AI could deliver widespread positive impacts. [&#8230;] </em></p></li><li><p><em>AI could cause serious, potentially even existential harms, without government intervention. [&#8230;] </em></p></li><li><p><em>The potential impact on cognitive labour is significant. [&#8230;] </em></p></li><li><p><em>The frontier AI market is expected to remain highly concentrated toward 2030. [&#8230;] </em></p></li><li><p><em>Adoption continues to increase, but the speed, distribution, and extent of adoption are expected to be varied. [&#8230;] </em></p></li><li><p><em>Global competition is expected to continue, as economies become increasingly reliant on technology to drive growth and spheres of influence emerge, led by the United States (US) and China. [&#8230;]&#8221; </em></p></li></ul></li></ul></li><li><p><strong>OECD </strong><a href="https://www.oecd.org/en/publications/the-oecd-ai-exposure-measure_f3da0f0a-en.html">published</a> a working papaer, <em><strong>&#8220;The OECD AI exposure measure -</strong></em></p><p><em><strong>Mapping the OECD AI Capability Indicators to occupations&#8221;. </strong></em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This paper develops a new OECD measure of occupational AI exposure based on the OECD AI Capability Indicators. The measure addresses the need for a forward-looking, transparent and updateable approach to assessing how AI may affect work, skills and education over the next 5 to 10 years. It does so by mapping AI capabilities across nine cognitive, social and physical domains to occupational requirements and constructing an AI Capability Gap index. [&#8230;] The measure provides a transparent foundation for analysing task-level transformation, changing skill demand and future labour-market effects, while recognising that actual impacts will depend on adoption, regulation, organisational change and social choice.&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-639?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-639?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-639?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The International Working Group on Data Protection in Technology</strong> <a href="https://www.bfdi.bund.de/SharedDocs/Downloads/DE/Berlin-Group/20260616-WP-Extended-Reality.pdf?__blob=publicationFile&amp;v=2">published</a> a <strong>working paper on Extended Reality</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;]  This technology raises serious concerns about privacy, not just for users, but also for bystanders whose presence and actions may be tracked </em></p><p><em>with these devices. While many of the privacy risks presented by extended reality are common in other technologies as well, extended reality presents unique risks due to the source, type, and volume of information that it processes - just twenty minutes in a virtual reality simulation can generate nearly 2 million unique body language recordings. This paper provides a discussion basis for this issue by setting out an explanation of extended reality, what data is processed through this technology, and what privacy risks it presents. Finally, this paper proposes some recommended actions for extended reality developers as well as policymakers and regulators.&#8221;</em></p></li></ul></li><li><p><strong>The Dutch Data Protection Authority</strong> (Autoriteit Persoonsgegevens) has drawn up <strong>a list of types of processing for which a data protection impact assessment (DPIA) is not required</strong>. In order to ensure that this list is in line with practice, the DPA started a consultation until August 10, 2026. <em>(The list is available <a href="https://www.autoriteitpersoonsgegevens.nl/documenten/consultatie-lijst-dpia-uitzonderingen">here</a> in Dutch. For an unofficial English translation, please see Luis Alberto Montezuma&#180;s <a href="https://www.linkedin.com/posts/luisalbertomontezuma_dpias-ugcPost-7475527197425065987-fe0y/?highlightedUpdateUrn=urn%3Ali%3Aactivity%3A7475533562881069056&amp;origin=SOCIAL_SHARE&amp;utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAACAz90B0FfKvtKWSOOCdG6dsEK5TJIFYQY">LinkedIn post</a>). </em></p><ul><li><p><em><strong>Why does this matter? </strong></em>The intention of the DPA is to make GDPR compliance easier for SMEs, independent entrepreneurs, etc. For this reason, the processing operations listed by the DPA are not subject to a DPIA obligation insofar as they are carried out by controllers who are professionals or another natural person without an employment contract, or who are employers with a maximum of 250 employees. </p></li></ul></li><li><p><strong>Consumer Reports&#180; investigation <a href="https://www.consumerreports.org/media-room/press-releases/2026/06/consumer-reports-investigation-reveals-uber-and-lyft-ai-driven-pricing-tactics-lead-to-significantly-different-prices/">revealed</a> </strong>Uber and Lyft <strong>AI-driven pricing lead to significantly different prices for customers. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>A </span><a href="https://www.consumerreports.org/money/questionable-business-practices/uber-lyft-different-prices-for-same-ride-and-fake-discounts-a1093538909/"><span>new investigation</span></a><span> by </span><a href="https://www.consumerreports.org/"><span>Consumer Reports</span></a><span> (CR) [&#8230;] has uncovered that Uber and Lyft leverage AI-driven pricing tactics to routinely charge different customers significantly different prices for rides ordered at roughly the same times. This comprehensive investigation stems from consumer complaints and real-life observations, and highlights the pervasive issue of opaque pricing algorithms designed to optimize revenue by extracting more money from consumers.&#8221;</span></em></p></li></ul></li><li><p><strong><span>The EDPB</span></strong><span> has published </span><strong><span>an update of the </span><a href="https://www.edpb.europa.eu/documents/support-pool-of-experts/one-stop-shop-case-digest-on-right-to-object-and-right-to-erasure_en">One-Stop-Shop (OSS) case digest on right to object and right to erasure</a></strong><span>.</span></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The one-stop-shop thematic case digest on the right to object and right to erasure offers insights in how data protection authorities (DPAs) analyse the internal processes implemented within organisations to comply with these rights, lists the most frequent infringements and gives an overview of which corrective measures have been issued.&#8221;</em></p></li></ul></li><li><p><strong>The EDPB</strong> <a href="https://www.edpb.europa.eu/home_en">launched</a> <strong>its newly redesigned website</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;<span>The EDPB website now serves as a </span><strong>fully integrated digital resource</strong><span>, which also incorporates the </span><a href="https://www.edpb.europa.eu/sme_en">&#8220;Data Protection Guide for Small Business&#8221;</a><span> and the redesigned </span><a href="https://www.edpb.europa.eu/csc_en">Coordinated Supervision Committee (CSC) website</a><span>, and will bring together upcoming projects such as the </span><a href="https://www.edpb.europa.eu/news/data-protection-day-2026-keeping-childrens-personal-data-safe-online_en">&#8220;Privacy for Kids&#8221; hub</a><span>.&#8221;</span></em></p></li></ul></li></ul><p><em><strong>3) Cybersecurity</strong></em></p><ul><li><p><strong>The Five Eyes cyber security agencies</strong> <a href="https://www.cyber.gov.au/about-us/view-all-content/news/five-eyes-cyber-security-agencies-statement">issued</a> <strong>a statement on the evolving landscape of AI that is rapidly transforming cyber risk</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong></em>The following practical actions are proposed: </p><ul><li><p><em><strong>&#8220;Reduce your attack surface [&#8230;]</strong></em></p></li><li><p><em><strong>Accelerate patching processes [&#8230;]</strong></em></p></li><li><p><em><strong>Address legacy systems [&#8230;]</strong></em></p></li><li><p><em><strong>Review and strengthen identity and access controls [&#8230;]</strong></em></p></li><li><p><em><strong>Prepare for incidents before they happen [&#8230;].&#8221;</strong></em></p></li></ul></li></ul></li><li><p><strong>The World Economic Forum</strong> <a href="https://www.weforum.org/stories/2026/06/update-data-privacy-tools-cybersecurity-risk-ai-era/">released</a> <strong>guidance detailing cybersecurity risks and the potential benefits of implementing Zero Trust Architecture</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] companies paid an estimated $4.44 million per data-breach incident, according to research by IBM and Ponemon Institute. But a zero-trust architecture creates stronger identity-centric security controls and faster breach containment, which could lower data-breach costs.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>The European Law Institute (ELI)</strong> <a href="https://europeanlawinstitute.eu/fileadmin/user_upload/p_eli/Publications/Liability_for_Defective_Software_Under_the_New_EU_Product_Liability_Regime.pdf">published</a> its <strong>1st Supplement to the ELI&#8217;s work on product liability, titled &#8220;</strong><em><strong>Liability for Defective Software Under the New EU Product Liability Regime - Will Liability Under the New PLD Extend to Social Media, AI Chatbots and Similar Digital Consumer Offerings?</strong></em><strong>&#8221;. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>The document sets out three possible routes by which liability for social media, AI chatbots and comparable consumer offerings might be construed under the new PLD, subject to the CJEU&#8217;s eventual position: </em></p><ul><li><p>Route No. 1: The Digital Offering Itself Qualifies as &#8216;Software&#8217; Made Available on the Market</p></li><li><p>Route No. 2: Software as a Product is Used for Supplying the Digital Offering as a Service</p></li><li><p>Route No. 3: The Digital Offering is a Service Related to Software as a Product</p></li></ul></li><li><p><em>&#8220;[&#8230;] it is important to recall that the PLD is not the only potential basis of liability, as Art 2(4)(b) PLD expressly underlines. Apart from contractual causes of action, the tortious liability of service providers may therefore also be based on negligence. This could include, for example, liability for non-compliance with obligations under the Artificial Intelligence Act or under the Digital Services Act (DSA) &#8211; see, for example, Art 54 DSA on compensation, and see obligations such as Art 28 DSA on the protection of minors&#8221;</em></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-639?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-639?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><strong><a href="https://www.sciencedirect.com/science/article/pii/S2212473X26001033">&#8220;A relative mess: Identifying data subjects in multi-party processing&#8221;</a></strong></em> (author: Jennifer Cobbe)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] The question of when an individual is in some way &#8216;identifiable&#8217; therefore helps determine whether its processing falls within data pro tection law&#8217;s framework. I argue that the CJEU&#8217;s jurisprudence on this question in practice combines with common multi-party processing arrangements to produce a space of effective legal immunity around shadow processing for speculative accumulation of and value extraction from data relating to people, beyond the reach of data protection law. This is because the CJEU&#8217;s modified relative understanding of identifiability systematically excludes certain supply chain actors from the law&#8217;s scope. In doing so, this interpretation undermines data protection law&#8217;s purpose and objectives of protecting people&#8217;s rights and interests where information about them is being processed, operates retrospectively and produces legal uncertainty for many parties, and leaves governance of shadow processing to unsuitable private law mechanisms. This interpretation should be rejected in favour of a contextual and pluralistic one, which better accounts for the distributed and multi-party nature of data processing today.&#8221;</em></p></li></ul></li><li><p><em><a href="https://arxiv.org/abs/2606.16054">&#8220;</a><strong><a href="https://arxiv.org/abs/2606.16054">How to Detect and Measure the AI Dangers to Democracy&#8221;</a></strong></em> (authors: Giulia Sandri and Claudio Novelli)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] In many phases of democratic systems, principals delegate key functions to AI systems and their providers without really being able to monitor how these systems operate or the outputs they produce. Treating AI as a delegation problem helps identify accountability gaps and other governance failures. Most importantly, as we shall illustrate, it provides metrics for empirical assessments of AI impact on democracy. [&#8230;], we propose an analytical framework that centers on institutional assessability as the central condition for democratic control over AI. However, we stress that how severe a harm is, and how much risk is acceptable, are evaluative judgments that current methodologies neither acknowledge nor operationalize. This becomes acute when such evaluative judgments are (silently) delegated to private vendors. We identify this as a strong limitation left for future work.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Midjourney</strong> has introduced <strong>a medical scanner</strong> that can compete with conventional MRI scanners but is much easier to use. (<a href="https://www.heise.de/en/news/Midjourney-After-AI-image-generator-now-a-body-scanner-for-humanity-11337110.html">Heise Online</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In just one minute, such a device is supposed to create a complete scan of a body using ultrasound. [&#8230;] The quality is said to be comparable to an MRI scan but take only a fraction of the time. The stated goal is to collect as much data as possible for better medical care [&#8230;] &#8220;Our ambitious goal is by 2031 to have a fleet of over 50,000 scanners worldwide - with a total scanning capacity of a billion scans a month,&#8221; Midjourney writes. This could cover &#8220;a huge percentage of the global population,&#8221; or scan a billion people once a month.&#8221;</em></p></li></ul></li><li><p><strong>Google</strong> <a href="https://cloud.google.com/blog/products/data-analytics/how-the-open-knowledge-format-can-improve-data-sharing?hl=en">introduced</a> &#8220;<em><strong>the Open Knowledge Format (OKF)</strong>, an open specification that formalizes the LLM-wiki pattern into a portable, interoperable format.</em>&#8221;</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This is a vendor-neutral, agent- and human-friendly standard for representing the metadata, context, and curated knowledge that modern AI systems need.&#8221;</em></p></li><li><p><em><span>&#8220;[&#8230;] You need a </span><strong>format</strong><span>, a way to represent knowledge that:</span></em></p><ul><li><p><em><span>Anyone can produce, without an SDK</span></em></p></li><li><p><em><span>Anyone can consume, without an integration</span></em></p></li><li><p><em><span>Survives moving between systems, organizations, and tools</span></em></p></li><li><p><em><span>Lives in version control alongside the code it describes</span></em></p></li><li><p><em><span>Is readable by humans and parseable by agents: the same file, no translation layer</span></em></p></li></ul><p><em><span>By design, OKF is that format.&#8221;</span></em></p></li></ul></li><li><p><strong>SpaceX</strong> announced <strong>it will acquire the AI coding startup Cursor</strong> for $60 billion in an all stock transaction. (<a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">CNBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Cursor deal could bolster SpaceX efforts to compete with rivals like Anthropic and OpenAI, which offer popular coding tools.&#8221;</em></p></li><li><p><em><strong>How does this deal make sense?</strong></em> According to the <a href="https://finance.yahoo.com/technology/article/how-spacex-benefits-from-its-cursor-acquisition-123000466.html">Yahoo! Finance report</a>, `<em>&#8220;It&#8217;s all about vertical integration,&#8221; explained Shay Boloor, chief market strategist at Futurum Equities. &#8220;At the bottom [SpaceX is] pretty well fit with energy infrastructure and compute,&#8221; Baloor said. &#8220;In the middle, it&#8217;s &#8230; the model layer through xAI, which is okay, it&#8217;s not great &#8212; [CEO Elon Musk has] been very public about why it&#8217;s lagged and why he wants to improve that area. The top of that stack is one of the fastest-growing AI applications in the world, which is Cursor. And if you speak to a lot of developers who use Cursor, they will never leave that platform.&#8221;</em>`</p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI litigation, enforcement, regulatory trackers & more]]></title><description><![CDATA[I have collected several websites and databases that collect legal disputes, lawsuits and other enforcement actions initiated in connection with AI-based products or services.]]></description><link>https://datalawgy.substack.com/p/ai-litigation-enforcement-regulatory</link><guid isPermaLink="false">https://datalawgy.substack.com/p/ai-litigation-enforcement-regulatory</guid><dc:creator><![CDATA[László Pók]]></dc:creator><pubDate>Tue, 23 Jun 2026 08:30:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>With the advent of AI, there are almost countless lawsuits and other cases related to the use and development of AI, especially in various copyright, privacy, defamation, employment, product liability, and consumer protection cases.</strong> Below, I have collected several websites and databases that collect legal disputes, lawsuits and other enforcement actions initiated against AI companies or in connection with AI-based products or services. <strong>Most of these databases (as well as AI-related cases) can be found in the US, but there are also several databases available in the EU and other parts of the world.</strong> It is clear that thousands of cases are already taking place in front of the most diverse legal forums. </p><p>I also collected some prominent <strong>regulatory, and policy trackers</strong>, as well as <strong>EU AI Act compliance checkers</strong>, <strong>AI incident and vulnerability databases</strong>, <strong>AI risk trackers</strong>, and <strong>AI indexes</strong>. </p><p>Happy browsing!</p><div><hr></div><h2>AI litigation and enforcement trackers</h2><ol><li><p><strong>Worldwide databases</strong></p></li></ol><ul><li><p><a href="https://www.damiencharlotin.com/hallucinations/">AI Hallucination Cases</a> (by Damien Charlotin)</p><ul><li><p>&#8220;<em>This database tracks legal decisions in cases where generative AI produced hallucinated content &#8211; typically fake citations, but also other types of AI-generated arguments. It does not track the (necessarily wider) universe of all fake citations or use of AI in court filings.</em>&#8221;</p></li></ul></li><li><p><a href="https://digital-client-solutions.hoganlovells.com/resources/ai-litigation-case-law-tracker">AI Litigation Case Law Tracker</a> (by Hogan Lovells)</p><ul><li><p><em>&#8220;Our AI Litigation Case Law Tracker monitors key AI-related cases involving IP, copyright, media, commercial, consumer, data protection, and other laws across global jurisdictions.&#8221;</em></p></li></ul></li><li><p><a href="https://www.mishcon.com/generative-ai-intellectual-property-cases-and-policy-tracker">Generative AI &#8211; Intellectual property cases and policy tracker</a> (by Mishcon de Reya LLP)</p><ul><li><p><em>&#8220;In this tracker, we provide an insight on the various intellectual property cases relating to generative AI going through the courts, as well as anticipated policy and legislative developments.&#8221;</em></p></li></ul></li><li><p><a href="https://chatgptiseatingtheworld.com/2026/02/15/world-map-of-copyright-suits-v-ai-cos-total-107-feb-15-2026-only-7-decision-on-ai-training-so-far/">World Map of Copyright Suits</a> (by ChatGPT is eating the world)</p><ul><li><p>Copyright lawsuits</p></li><li><p>Status: February 15, 2026</p></li></ul></li></ul><ol start="2"><li><p><strong>Europe</strong></p></li></ol><ul><li><p><a href="https://www.taylorwessing.com/en/campaigns/de/2025/ai-and-copyright-tracker">AI &amp; Copyright Case Tracker</a> (by AI &amp; Copyright Case Experts of Taylor Wessing)</p><ul><li><p>Up-to-date overview of ongoing lawsuits<span data-color="rgb(15, 28, 68)" style="color: rgb(15, 28, 68);"> at the intersection of AI and copyright law across Europe</span></p></li></ul></li><li><p><a href="https://uk.practicallaw.thomsonreuters.com/w-040-5495?transitionType=Default&amp;contextData=(sc.Default)&amp;firstPage=true">AI and intellectual property case tracker</a> (by Practical Law)</p><ul><li><p><strong>Not free. </strong></p></li><li><p><em>&#8220;This case tracker lists and links to some key decisions made by the courts that consider legal issues relating to artificial intelligence (AI) and intellectual property.&#8221;</em></p></li><li><p><em>&#8220;The tracker focuses on the law of England and Wales, but will also cover EU and European Patent Office (EPO) decisions where relevant.&#8221;</em></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/ai-litigation-enforcement-regulatory?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/ai-litigation-enforcement-regulatory?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><ol start="3"><li><p><strong>US</strong></p></li></ol><ul><li><p><a href="https://ailawsuittracker.com/">AI Lawsuit Tracker</a> (provided by a small editorail team with a mix of legal training, court-reporting experience, and software engineering)</p><ul><li><p>U.S. federal cases and curated international filings </p></li><li><p>Copyright, privacy, defamation, employment, product-liability, and consumer-protection actions against AI companies and AI-driven products</p></li></ul></li><li><p><a href="https://chatgptiseatingtheworld.com/ai-tort-lawsuit-tracker/">AI Tort Lawsuit Tracker</a> (by ChatGPT is eating the world)</p><ul><li><p>Tort lawsuits</p></li></ul></li><li><p><a href="https://blogs.gwu.edu/law-eti/ai-litigation-database/">The Database of AI Litigation (DAIL)</a> (by Ethical Tech Initiative at The George Washington University)</p><ul><li><p><em>&#8220;The Database of AI Litigation presents information about ongoing and completed litigation involving artificial intelligence and related topics. It covers cases from complaint forward - as soon as we learn of them - whether or not they generate published decisions. It is intended to be broad in scope, covering everything from algorithms used in hiring and credit and criminal sentencing decisions to generative AI training and AI companion liability.&#8221;</em></p></li></ul></li><li><p><a href="https://www.fisherphillips.com/en/resources-and-innovation/trackers-and-maps/ai-litigation-tracker">AI Litigation Tracker</a> (by Fisher &amp; Phillips LLP)</p><ul><li><p><em>&#8220;<span data-color="rgb(16, 24, 32)" style="color: rgb(16, 24, 32);">The AI Litigation Tracker provides a comprehensive view of litigation matters filed across all 50 states that involve the use of AI technologies, such as Gen AI, resume screeners, electronic monitoring, notetaking, call recording, and other AI tools. The tracker includes all matters filed since February 25, 2021</span>.&#8221;</em></p></li></ul></li><li><p><a href="https://www.ropesgray.com/en/sites/artificial-intelligence-court-order-tracker">Standing Orders, Local Rules, and Decisions on the Use of AI</a> (by Ropes &amp; Gray LLP)</p><ul><li><p>Cases and court rules on AI use</p></li></ul></li><li><p><a href="https://www.mckoolsmith.com/newsroom-ailitigation">AI Litigation Tracker</a> (by McKool Smith P.C., Avery Williams)</p><ul><li><p>Regular updates on key generative AI-focused copyright infringement-related litigations impacting the media and entertainment industries</p></li></ul></li><li><p><a href="https://copyrightalliance.org/artificial-intelligence-copyright/court-cases/">Federal Court AI Cases Involving Copyright Claims</a> (by Copyright Alliance)</p><ul><li><p>Copyright cases</p></li><li><p>US federal courts</p></li></ul></li><li><p><a href="https://bots.law/little-cases/ai-cases-bot/">AI Cases Bot</a> (by Free Law Project)</p></li><li><p><em><a href="https://www.bakerlaw.com/services/artificial-intelligence-ai/case-tracker-artificial-intelligence-copyrights-and-class-actions/">Case Tracker: Artificial Intelligence, Copyrights and Class Actions</a> (by  Baker &amp; Hostetler LLP)</em></p><ul><li><p><em><strong>This case tracker is in archive mode.</strong></em></p></li><li><p><em>This case tracker monitors key U.S. litigation that raises copyright (and copyright adjacent) issues related to the creation and use of generative AI.</em></p></li></ul></li><li><p><a href="https://informationisbeautiful.net/visualizations/the-rise-of-generative-ai-large-language-models-llms-like-chatgpt/#suing">A visualisation of selected lawsuits from over 100 filed against AI companies as of June 2026</a> (by David McCandless, Information is Beautiful)</p></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/ai-litigation-enforcement-regulatory?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/ai-litigation-enforcement-regulatory?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/ai-litigation-enforcement-regulatory?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><ol start="4"><li><p><strong>Canada</strong></p></li></ol><ul><li><p><a href="https://anandsiu.com/resources/canadian-ai-case-tracker/">Canadian AI Case Tracker</a> (by Anand &amp; Siu LLP)</p><ul><li><p>This is a curated list of interesting and important artificial intelligence (AI) related cases that are ongoing or have been decided in Canada.</p></li></ul></li></ul><h2>AI regulatory &amp; policy trackers</h2><ul><li><p><a href="https://www.techieray.com/GlobalAIRegulationTracker">Global AI Regulation Tracker</a> (by Raymond Sun, <strong>techie_ray</strong>)</p><ul><li><p><em>&#8220;An interactive world map that tracks AI law, regulatory and policy developments around the world.&#8221;</em></p></li></ul></li><li><p><a href="https://www.hsfkramer.com/insights/reports/ai-tracker">AI Tracker &#8211; Tracking AI law and policy globally</a> (by Herbert Smith Freehills Kramer LLP)</p></li><li><p><a href="https://www.twobirds.com/en/capabilities/artificial-intelligence/ai-legal-services/ai-regulatory-horizon-tracker">AI Regulatory Horizon Tracker</a> (Bird &amp; Bird)</p></li><li><p><a href="https://www.whitecase.com/insight-our-thinking/ai-watch-global-regulatory-tracker">AI Watch: Global regulatory tracker</a> (by White &amp; Case)</p></li><li><p><a href="https://oecd.ai/en/dashboards/overview">The OECD.AI Policy Navigator</a> (by the OECD)</p></li><li><p><a href="https://digi-tracker.com/">Digital Regulation Tracker Tool</a> (by CMS)</p></li><li><p><a href="https://iapp.org/resources/article/global-ai-legislation-tracker">Global AI Law and Policy Tracker</a> (by IAPP)</p><ul><li><p>Full access is available for IAPP members. </p></li></ul></li><li><p><a href="https://aipolicytracker.org/">Global Artificial Intelligence Policy Tracker</a> (by Bhaskar Bhatt and Niraj Bhusal)</p></li><li><p><a href="https://ai-law-center.orrick.com/us-ai-law-tracker/">U.S. AI Law Tracker</a> (by Orrick, Herrington &amp; Sutcliffe, LLP)</p></li><li><p><a href="https://iapp.org/resources/article/us-state-ai-governance-legislation-tracker">US State AI Governance Legislation Tracker</a> (by IAPP)</p><ul><li><p>Full access is available for IAPP members. </p></li></ul></li></ul><h2>EU AI Act Compliance Trackers</h2><ul><li><p><a href="https://ai-act-service-desk.ec.europa.eu/en/eu-ai-act-compliance-checker">EU AI Act Compliance Checker</a> (by AI Act Service Desk, AI Office)</p><ul><li><p><em>&#8220;The official AI Act Compliance Checker helps users understand which AI Act rules may apply to their AI system, including possible obligations for providers, deployers and other operators under Regulation (EU) 2024/1689.&#8221;</em></p></li><li><p>Betta version</p></li></ul></li><li><p><a href="https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/">EU AI Act Compliance Checker</a> (by Future of Life Institute)</p></li><li><p><a href="https://compl-ai.org/">COMPL-AI</a> (<span>by </span>ETH Zurich<span>, </span>INSAIT<span>, and </span>LatticeFlow AI)</p><ul><li><p><em>&#8220;COMPL-AI is an open-source compliance-centered evaluation framework for Generative AI models&#8221;</em></p></li></ul></li></ul><h2>AI Incident and Vulnerability Databases</h2><ul><li><p><a href="https://incidentdatabase.ai/">AI Incident Database</a> (by The Responsible AI Collaborative)</p></li><li><p><a href="https://airisk.mit.edu/ai-incident-tracker">MIT AI Incident Tracker</a> (by MIT AI Risk Initiative)</p><ul><li><p><em>&#8220;The MIT AI Incident Tracker classifies more than 1,400 real-world report incidents from the AI Incident Database by risk, cause, harm, severity, and other relevant dimensions.&#8221;</em></p></li></ul></li><li><p><a href="https://oecd.ai/en/incidents">OECD AI Incidents and Hazards Monitor (AIM)</a> (by OECD)</p><ul><li><p><em>&#8220;The OECD AI Incidents and Hazards Monitor (AIM) documents AI incidents and hazards to help policymakers, AI practitioners, and all stakeholders worldwide gain valuable insights into the risks and harms of AI systems.&#8221;</em></p></li></ul></li><li><p><a href="https://avidml.org/">AI Vulnerability Database</a> (by AI Risk and Vulnerability Alliance)</p></li><li><p><a href="https://www.aiaaic.org/aiaaic-repository">AIAAIC [AI, Algorithmic and Automation Incidents and Controversies] Repository</a> (by Charlie Pownall &amp; individual contributors)</p><ul><li><p><em>&#8220;The independent, grassroots public interest collection of incidents and ethical controversies caused by and associated with AI, algorithms, and automation.&#8221;</em></p></li></ul></li></ul><h2>AI Risk trackers and taxonomy</h2><ul><li><p><a href="https://airisk.mit.edu/">MIT AI Risk Repository</a> (by MIT AI Risk Initiative)</p><ul><li><p><a href="https://airisk.mit.edu/navigator">MIT AI Risk Navigator</a></p><ul><li><p><em>&#8220;The Navigator connects MIT&#8217;s AI Risk Repository datasets through a shared taxonomy [&#8230;].&#8221;</em></p></li></ul></li></ul></li><li><p><a href="https://www.ibm.com/docs/en/watsonx/saas?topic=ai-risk-atlas">AI risk atlas</a> (by IBM)</p><ul><li><p><em>&#8220;Explore this atlas to understand some of the risks of working with agentic AI, generative AI, and machine learning models.</em>&#8221;</p></li><li><p><a href="https://github.com/IBM/ai-atlas-nexus?tab=readme-ov-file">AI Atlas Nexus</a></p><ul><li><p><em>&#8220;AI Atlas Nexus provides tooling to bring together resources related to governance of foundation models. [&#8230;] Our goal is to turn abstract risk definitions into actionable workflows that streamline AI governance processes. [&#8230;] AI Atlas Nexus builds on the <a href="https://www.ibm.com/docs/en/watsonx/saas?topic=ai-risk-atlas">IBM AI Risk Atlas</a> making this educational resource a nexus of governance assets and tooling. [&#8230;] Our intention is to create a starting point for an open AI Systems ontology whose focus is on risk and that the community can extend and enhance. This ontology serves as the foundation that unifies innovation and tooling in the AI risk space. By lowering the barrier to entry for developers, it fosters a governance-first approach to AI solutions, while also inviting the broader community to contribute their own tools and methodologies to expand its impact.&#8221;</em></p></li></ul></li></ul></li><li><p><a href="https://www.airiskexplorer.com/">AI Risk Explorer</a> (by Observatorio de Riesgos Catastroficos Globales, a project of Players Philanthropy Fund, Inc.)</p><ul><li><p><em>&#8220;The AI Risk Explorer is an online platform monitoring the emergence and management of large-scale AI risks.&#8221;</em></p></li></ul></li></ul><h2>AI Indexes and Benchmarks</h2><ul><li><p><a href="https://artificialanalysis.ai/">Artificial Analysis</a></p><ul><li><p><a href="https://artificialanalysis.ai/leaderboards/models">LLM Leaderborad</a> (by Artificial Analysis)</p><ul><li><p><em>&#8220;Comparison of over 100 AI models from OpenAI, Google, DeepSeek &amp; others&#8221;</em></p></li></ul></li></ul></li><li><p><a href="https://aiagentindex.mit.edu/">The AI Agent Index</a></p><ul><li><p><em>&#8220;The AI Agent Index (AIAI) is a research project that documents and compares the capabilities, safety features, and transparency practices of prominent AI agents.&#8221;</em></p></li><li><p><em>&#8220;The 2025 AI Agent Index documents the origins, design, capabilities, ecosystem, and safety features of 30 prominent AI agents based on publicly available information and correspondence with developers.&#8221;</em></p></li></ul></li><li><p><a href="https://hai.stanford.edu/ai-index/2026-ai-index-report">The 2026 AI Index Report</a> (by Stanford HAI)</p><ul><li><p><em>&#8220;The mission of the AI Index is to provide unbiased, rigorously vetted, and globally sourced data for policymakers, researchers, journalists, executives, and the general public to develop a deeper understanding of the complex field of AI. To achieve this, we track, collate, distill, and visualize data relating to artificial intelligence.&#8221;</em></p></li></ul></li><li><p><a href="https://benchlm.ai/">BenchLM leaderboard</a> (by <a href="https://x.com/glevd">@glevd</a>)</p><ul><li><p><em>&#8220;124 provisional-ranked models, 33 verified-ranked models, and 261 tracked LLMs. The most comprehensive LLM comparison tool &#8212; 249 benchmarks, real pricing, and runtime data in one place.&#8221;</em></p></li></ul></li><li><p><a href="https://llm-stats.com/">LLM-stats</a> (by The AI Benchmarking Hub)</p><ul><li><p><em>&#8220;<span>Independent rankings of GPT, Claude, Gemini, Llama, DeepSeek and 300+ AI models &#8212; composite </span><a href="https://llm-stats.com/methodology/llm-stats-score">LLM Stats Score</a><span>, updated continuously from public benchmarks and live API metrics. See the full </span><a href="https://llm-stats.com/leaderboards/llm-leaderboard">LLM Leaderboard</a><span> for complete LLM rankings with advanced filters.&#8221;</span></em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 25]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-ccb</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-ccb</guid><pubDate>Fri, 19 Jun 2026 09:01:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0QRy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The European Parliament</strong> <a href="https://www.europarl.europa.eu/news/en/press-room/20260611IPR45207/ai-act-ep-approves-simplification-measures-and-nudifier-app-ban">has given</a> its <strong>final approval to the amendment of AI Act and the introduction of a &#8220;nudifier&#8221; app ban</strong>. </p><ul><li><p><em><strong>What are the next steps? </strong>&#8220;</em>Before the law can enter into force, it still needs to be adopted formally by the Council.&#8221;</p></li><li><p><em><strong>Why does this matter? </strong></em>The legislation postpones the application of certain parts of the AI Act regarding high-risk AI systems. Obligations will apply:</p><ul><li><p><em>&#8220;from 2 December 2027 for stand-alone high risk AI systems;</em></p></li><li><p><em>from 2 August 2028 for AI systems embedded as safety components and covered by EU sectoral legislation on safety and market surveillance.&#8221;</em></p></li></ul></li><li><p>&#8220;<em>The law also delays the application of watermarking obligations on AI-generated content until 2 December 2026.</em>&#8221;</p></li><li><p>&#8220;<em>The law bans AI systems that generate child sexual abuse material or create images, videos and audio depicting an identifiable person&#8217;s intimate parts, or sexually explicit activities, without their consent. [&#8230;] Companies will have until 2 December 2026 to bring their systems in line.</em>&#8221;</p></li></ul></li><li><p><strong>Estonia</strong> is set to become the first country <strong>to issue digital identities for AI agents</strong>. (<a href="https://www.heise.de/en/news/AI-agents-to-receive-own-IDs-from-Estonia-11336332.html">Heise Online</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;An independent identity can enable the AI agent to present itself to the system it is using as an agent acting on behalf of a specific principal, rather than pretending to be the principal itself. Based on this distinction, the system used can then grant granular access to functions or deny it.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Government of Canada <a href="https://www.canada.ca/en/innovation-science-economic-development/news/2026/06/government-of-canada-introduces-legislation-to-protect-canadians-privacy-in-the-digital-age.html">introduced</a> Bill C-36</strong>, <strong>an Act to enact the Protecting Privacy and Consumer Data Act (PPCDA)</strong>, to amend the Personal Information Protection and Electronic Documents Act.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The proposed PPCDA represents the most significant change to Canada's private-sector privacy law in over 25 years. [&#8230;] The PPCDA will establish clear guardrails to protect Canadians' personal information in a rapidly changing digital world, with a particular focus on children's personal information, while supporting responsible innovation, a stronger economy, and Canada's digital and data sovereignty.&#8221;</em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The UK Government</strong> <a href="https://www.gov.uk/government/news/social-media-to-be-banned-for-under-16s-in-landmark-government-move-to-givekids-their-childhood-back">announced</a> that <strong>social media platforms will be blocked from offering services to under-16s</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The government plans to use the same model for a social media ban as Australia. This would capture user-to-user platforms, whose purpose is to enable social interaction and&#8239;which allow users to post material, alongside algorithms. The ban will therefore include platforms like Snapchat, TikTok, YouTube, Instagram, Facebook and X. We do not intend for messaging services like WhatsApp and Signal to be included in the social media ban.&#8221;</em></p></li></ul></li><li><p><strong>In Hungary, the Government has submitted its legislative program for autumn 2026</strong>, which includes a number of proposals concerning data, data protection, artificial intelligence, cyber security and digital legislation. <em>(The program is available <a href="https://www.parlament.hu/documents/d/guest/torvenyalkotasi-program_2026-osz">here</a> in Hungarian.) </em>The relevant bills are scheduled to be submitted to the Parliament in October or November. </p><ul><li><p><em><strong>Why does this matter? </strong></em>The legislative proposals will concern, inter alia: </p><ul><li><p>Amendment of Act C of 2003 on Electronic Communications  </p></li><li><p>Bill on the mitigation of the harmful effects of digital devices on children.</p></li><li><p>Bill on Countering Disinformation.</p></li><li><p>Bill on the National Cybersecurity Agency.</p></li><li><p>Bill on the Digital Innovation Agency.</p></li></ul></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>A new <a href="https://chatgptiseatingtheworld.com/ai-tort-lawsuit-tracker/">AI Tort Lawsuit Tracker</a></strong> has been launched. The tracker was created by Professor Edward Lee (University of Santa Clara, Law faculty). <em>(For a map of the copyright lawsuits against AI companies, please check <a href="https://chatgptiseatingtheworld.com/2026/02/15/world-map-of-copyright-suits-v-ai-cos-total-107-feb-15-2026-only-7-decision-on-ai-training-so-far/">this map</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong></em>The tracker follows the US tort lawsuits against AI companies. It contains currently 75 cases. It looks like OpenAI is leading in total count (29) today.</p></li></ul></li><li><p><strong>Google</strong> will <strong>appeal a German court ruling which said it &#8203;is legally liable for false claims appearing in &#8204;AI Overviews</strong>. (<a href="https://www.reuters.com/world/google-appeal-german-court-ruling-assigning-liability-ai-overviews-false-claims-2026-06-12/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Google&#8217;s &#8203;integration &#8288;of AI into its online search results has sparked criticism from publishers and content providers, which said this has &#8288;negatively &#8203;affected their traffic, readership and revenue. &#8203;Antitrust regulators are also looking into the issue.&#8221;</em></p></li><li><p><em><strong>Backgound:</strong></em> <em>&#8220;[&#8230;] the Munich I Regional Court has prohibited Google from disseminating untrue factual allegations about two Munich-based publishers in the search function &#8220;AI Overview&#8221;. The AI had mistakenly assigned information on dubious machinations of other companies to the plaintiffs&#8217; company. In the judgment of May 28, 2026 (case no. 26 O 869/26), the chamber did not classify Google as an indirect indicator of false allegations, but as a direct disruptor whose AI produced false reports as independent content.&#8221; </em>(<a href="https://www.heise.de/news/LG-Muenchen-I-Google-fuer-falsche-Aussagen-in-KI-Uebersichten-verurteilt-11326867.html">Heise Online</a>) Please see an English language summary of the judgment <a href="https://tech.yahoo.com/ai/gemini/articles/german-court-rules-google-liable-121808614.html">here</a> (Yahoo! Tech).</p></li></ul></li><li><p><strong>A new class action lawsuit against Meta</strong> <a href="https://www.bundesjustizamt.de/DE/Themen/Verbraucherrechte/VerbandsklageregisterMusterfeststellungsklagenregister/Verbandsklagenregister/Verbandsklagen/Klagen/202607/VRUG_7_2026_node.html">has been published</a> in <strong>Germany</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The subject of the collective action is compensation for damages caused by the processing of personal data for the purposes of AI training or by interaction with AI-controlled systems designed to promote addiction.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Court of Justice (ECJ) </strong>published<strong> its judgment in <a href="https://infocuria.curia.europa.eu/tabs/jurisprudence?lang=EN&amp;searchTerm=C-484%2F24&amp;publishedId=C-484%2F24&amp;logicDocId=id_322379">Case C&#8209;484/24</a></strong>, interpreting Articles 5, 6, 9, 13 and 17 of the GDPR <strong>in the context of evaluating unlawfully obtained evidence in court proceedins. </strong></p><ul><li><p><em><strong>Why does this matter? </strong></em>The judgment, in line with the AG&#180;s opinion, confirms that courts may process personal data as evidence even if obtained unlawfully.</p></li></ul></li><li><p><strong>The ECJ</strong> also <a href="https://infocuria.curia.europa.eu/tabs/jurisprudence?lang=EN&amp;searchTerm=C-414%2F24">decided</a> that <strong>a data protection authority cannot reject a complaint under Article 77 GDPR just because the same matter has been brought to court under Article 79</strong>, while that court case is still pending (C&#8209;414/24).</p><ul><li><p><em><strong>Why does this matter? </strong></em>Articles 77(1) and 79(1) of the GDPR<em><strong> </strong>&#8220;must be interpreted as precluding a supervisory authority, with which a complaint has been lodged under Article 77(1) of that regulation, from rejecting that complaint on the sole ground that judicial proceedings under Article 79(1) thereof, and concerning the same subject matter, have already been brought and even though the decision given in those proceedings is not yet final.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p>According to the judgment of the ECJ in <a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-06/cp260087en.pdf">Joined Cases C-188/24 (WebGroup Czech Republic and NKL Associates) and C-190/24 (Coyote System)</a>, <strong>the Court</strong> declared that i<strong>nformation society service providers are liable for the content and information they control.</strong> <em>(The full text is available <a href="https://infocuria.curia.europa.eu/tabs/jurisprudence?sort=DOC_DATE-DESC&amp;searchTerm=%22C-188%2F24%22&amp;publishedId=C-188%2F24">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;]  the Court of Justice, first, specifies the conditions under which Member States may impose an obligation to verify the age of users of pornographic websites and prohibit the rebroadcasting of information relating to certain roadside checks on their territory. The Court confirms that, under the system of the Directive on electronic commerce, such obligations and prohibitions, in principle, fall within the jurisdiction of the Member State in which the providers of the services concerned are established. Nevertheless, other Member States may impose such obligations and prohibitions on providers which are not established on their territory, subject to compliance with the conditions laid down in that directive, in particular where that proves necessary on grounds of public policy, security or safety. Second, the Court states that the operator of an information society service cannot be exempted from its liability for the information stored and rebroadcast over which it has control. That is the case where the operator determines, by means of an algorithm, under what conditions, how and in which order of priority that information is or is not rebroadcast.&#8221; </em></p></li></ul></li><li><p><strong>The ECJ</strong> also provided <strong>guidance on the rules of jurisdiction in cases of breach of personality rights</strong> resulting from the broadcast of a television series </p><p>in several Member States and on the internet (<a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-06/cp260088en.pdf">Case C-232/25</a>). <em>(The full text of the judgment is available <a href="https://infocuria.curia.europa.eu/tabs/jurisprudence?sort=DOC_DATE-DESC&amp;searchTerm=%22C-232%2F25%22&amp;publishedId=C-232%2F25">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] <strong>natural or legal persons who consider that their rights have been breached by content broadcast on television cannot bring proceedings before the courts of the Member State in which their centre of interests is located in order to secure compensation for the entirety of the alleged damage</strong>. They may bring proceedings before the courts of each Member State in which the programme was broadcast and where they consider their reputation to have been harmed. However, the jurisdiction of those courts is circumscribed to actions seeking compensation solely for the damage caused in the Member State concerned. [&#8230;] <strong>Compensation for the entirety of the damage may, however, be sought before the courts of the Member State in which the defendant is domiciled or in which the producers in the series are established.</strong> [&#8230;] <strong>As regards audiovisual content broadcast on the internet</strong>, the Court points out that the courts of the Member State in which the centre of interests of the natural or legal person who has allegedly suffered damage is located may hear an action seeking <strong>compensation for the entirety of the alleged damage only if that content makes it possible to identify, directly or indirectly, that person as an individual. </strong>[&#8230;]&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Digital Transformation Agency of the Australian Government</strong> <a href="https://www.digital.gov.au/policy/ai/agentic-ai-addendum">released</a> <strong>Agentic AI addendum to the AI technical standard for Australian Government</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This standard provides best practice guidance for Australian Government agencies implementing agentic AI. As an addendum to the <a href="https://www.digital.gov.au/policy/ai/AI-technical-standard">AI technical standard</a>, this standard highlights best practices key considerations for the secure and governed implementation of agentic AI systems.&#8221;</em></p></li></ul></li><li><p><strong>The Institute of Electrical and Electronics Engineers (IEEE)</strong> <a href="https://standards.ieee.org/ieee/7014.1/11609/">recommended</a> <em><strong>&#8220;Practice for Ethical Considerations of Emulated Empathy in Partner-Based General-Purpose Artificial Intelligence Systems&#8221;</strong></em>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Recommended practices for ethical usage of emulated empathy in general-purpose artificial intelligence (GPAI) systems for human-artificial intelligence (AI) partnerships are provided in this standard. The use of emulated empathy in GPAI systems for human-AI partnerships refers to general-purpose AI products marketed as empathic partners, personal AI, companions, co-pilots, agents, assistants, and related phrasing for human-AI partnering. IEEE Std 7014.1&#8482; is a domainspecific extension of IEEE Std 7014&#8482;, IEEE Standard for Ethical Considerations in Emulated Empathy in Autonomous and Intelligent Systems. Whereas IEEE Std 7014 provides overarching principles for ethical evaluation of emulated empathy across AI, IEEE Std 7014.1 focuses on the overlap of GPAI, emulated empathy and human-AI partnering.&#8221;</em></p></li></ul></li><li><p><strong>Singapore&#180;s Infocomm Media Development Authority (IMDA</strong>) <a href="https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/agents-legal-responsibility.pdf">published</a> a discussion paper, <em><strong>&#8220;Legal Responsibility for AI Agents&#8221;</strong></em>.  </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This paper examines how legal responsibility should be allocated when AI agents act autonomously, use tools, interact with third parties, and cause harm. It focuses on civil liability and private law, especially Singapore law, while recognising that agentic AI may also raise other legal issues. [&#8230;] The aim is to develop an initial understanding of the key legal issues and challenges relating to agent liability in private law. If users and enterprises understand their legal responsibilities in relation to agentic AI, they can adopt it with greater confidence. At the same time, there is a need to look ahead and investigate whether the accountability landscape changes as agents become more autonomous and potentially more unpredictable.&#8221;</em></p></li></ul></li><li><p><strong>G7 country leaders and top AI CEOs agreed</strong> that &#8220;<em><strong>the West should come together to rein in the most capable artificial intelligence models to keep China at bay</strong> [&#8230;].</em>&#8221; (<a href="https://www.politico.eu/article/ai-artificial-intelligence-anthropic-china-g7/">Politico</a>) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;China was mentioned multiple times during the talks, according to detailed notes shared by one participant, reflecting fears that while American companies gained an early lead on artificial intelligence, China is becoming a real competitor in part due to the energy supplies needed to build the most powerful models.&#8221;</em></p></li><li><p><em>&#8220;The takeaway from Wednesday&#8217;s talks on artificial intelligence was the idea of defining standards that the developers of frontier AI models, such as OpenAI and Anthropic, should adhere to.&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-ccb?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-ccb?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-ccb?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Data Protection Supervisor</strong>, Wojciech Wiewi&#243;rowski published a <a href="https://www.edps.europa.eu/press-publications/press-news/blog/managing-shadow-ais-hidden-data-breach-risk_en">short blog post</a> about<em> &#8220;<strong><span>Managing Shadow AI&#8217;s Hidden Data Breach Risk&#8221;</span></strong></em><strong><span>. </span></strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;We must adopt a proactive, comprehensive approach to AI governance that balances robust technical controls with a culture of awareness.&#8221;</em></p></li><li><p><em>&#8220;This begins with <strong>robust AI governance policies</strong>, where organisations develop and maintain clear, practical and aligned frameworks that explicitly define the authorised use of AI tools, establish clear data classification schemes and outline rigorous approval processes for evaluating new technologies. However, policy alone is not enough, and must be backed by technical controls and monitoring.&#8221; </em></p></li><li><p><em>&#8220;<strong>These technical controls include blocking unapproved AI domains, enforcing data loss prevention rules, and applying endpoint restrictions to prevent the installation of unapproved AI software.</strong> The most effective way to discourage the use of unapproved tools is by providing approved AI platforms that are secure, compliant and capable of meeting staff needs while ensuring full regulatory compliance. This technical foundation must be supported by <strong>enhancing employee awareness through continuous training</strong>, ensuring that staff understand the real-world risks associated with using public AI systems, the potential impacts on data subjects, and the importance of protecting sensitive data.&#8221; </em></p></li><li><p><a href="https://www.edps.europa.eu/press-publications/publications/newsletters/newsletter-120_en">The latest issue of the EDPS&#180;newsletter</a> has also bee published. This issue discusses the use of AI at the EU borders, an overview of the EDPS Annual Report 2025, the Digital Omnibus promise for data protection, Europe Day, global AI leadership, upcoming events, and more. </p></li><li><p><strong>Shadow AI</strong> may also mean <strong>regulatory liability for financial institutions</strong> and the businesses that serve them. In the US context, you can read about this topic more <a href="https://natlawreview.com/article/when-your-productivity-tools-become-regulatory-problem-shadow-ai-and-glba">here</a> (The National Law Review). </p></li><li><p>I wrote a <strong><a href="https://gdpr.blog.hu/2024/09/13/there_is_nothing_new_under_the_sun_shadow_ai">blog post</a> about shadow AI</strong> in 2024, where I argued that banning is not a solution in itself, but that <strong>there should be proper compliance measures </strong>(including <strong>awareness raising</strong>, <strong>increasing <a href="https://gdpr.blog.hu/2024/07/25/deep_dive_into_the_ai_act_part_6_ai_literacy">AI literacy</a> </strong>among employees, <strong>establishing appropriate internal regulatory frameworks</strong>; <strong>establishing and consistently applying appropriate internal control processes</strong>, <strong>monitoring the available IT and AI solutions</strong>, etc.).</p></li></ul></li><li><p>New <strong>VinciWorks survey</strong> <a href="https://vinciworks.com/blog/gdpr-compliance-risk-assessments-2026/">found</a> that <strong>AI governance has become the defining GDPR challenge</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;When asked which GDPR issue feels most challenging right now, over two in five respondents (43%) selected AI and automated decision-making. No other issue came close. Just over one-fifth (22%) cited supplier and processor management, while approximately one in five (19%) pointed to staff awareness and training. International transfers were cited by fewer than one in ten (8%) as were data subject rights requests, at 8%.&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>Australian Signals Directorate</strong> <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/opportunities-for-ai-in-cyber-defence">published</a> <strong>a guidance on the </strong><em>&#8220;<strong>Opportunities for AI in cyber defence&#8221;</strong></em><strong>. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This guidance outlines how organisations can use AI to strengthen organisational cyber security while managing the risks of using AI. It outlines how the cyber security landscape is evolving and describes how organisations can use AI aligned with the Information security manual (ISM) cyber security functions of Govern, Identify, Protect, Detect, Respond and Recover. It also sets out principles for securely adopting AI, along with key questions for cyber defenders to ask AI vendors to support secure use.&#8221;</em></p></li></ul></li><li><p><strong>France's cybersecurity agency ANSSI</strong> <strong>would stop certifying security products that lack quantum-resistant encryption. </strong>(<a href="https://www.reuters.com/legal/litigation/france-stop-certifying-products-without-quantum-safe-encryption-2026-06-16/">Reuters</a>)</p></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>OECD</strong> <a href="https://www.oecd.org/en/publications/digital-government-outlook_0496b2bc-en.html">published</a> a report, titled <em><strong>&#8220;Digital Government Outlook 2026&#8221;</strong></em><strong>. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This report presents results from the OECD Digital Government Index (DGI) and the Open, Useful and Re-usable Data Index (OURdata), illustrating how governments across 36 OECD countries and 8 accession countries have been improving coherent, effective and human-centred digital transformation in government in recent years.&#8221;</em></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-ccb?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-ccb?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><strong><a href="https://arxiv.org/abs/2606.03883">&#8220;Reasoning Structure of Large Language Models&#8221;</a> </strong>(authors: Berdoz et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Large reasoning models (LRMs) are often evaluated using metrics such as final-answer accuracy or token count. However, identical scores on these metrics can hide fundamentally different reasoning structures. To address this limitation, we introduce a scalable LRM benchmark of logic puzzles and a pipeline that converts unstructured traces into verifiable reasoning graphs of claims and dependencies. This turns reasoning into a structured, measurable object whose topology can be quantitatively analyzed. Building on this, we define a reasoning efficiency metric that quantifies how concentrated the model's logical flow is. Our analysis on open-source reasoning models shows that structural measurements separate behaviors that token count and accuracy conflate, providing a practical tool for diagnosing failure modes and comparing how reasoning scales with puzzle difficulty.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!0QRy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 424w, /__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 848w, /__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!0QRy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png" width="505" height="310" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:310,&quot;width&quot;:505,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/201425487?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 424w, /__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 848w, /__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0QRy!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe106c7fc-e3b0-4b72-9edf-bde436d0bbbd_505x310.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><strong>Qualitative reasoning graphs. </strong></em></p><p style="text-align: center;"><em>Source: <a href="https://arxiv.org/abs/2606.03883">&#8220;Reasoning Structure of Large Language Models&#8221;</a>, Figure 1, p. 1</em></p></li></ul></li><li><p><em><strong><a href="https://arxiv.org/pdf/2606.12430v2">&#8220;Will AI Agents Free Us From Meaningless Work? A Human-Centered Analysis&#8221;</a> </strong></em>(authors: Ghia et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Some claim that AI agents will free workers from the boring parts of their jobs, yet little is known about how workers themselves identify which tasks should be automated. Prior research focuses on occupations, overlooking that workers may experience varying levels of meaning across tasks within the same role. We address this gap with a task-level analysis grounded in Graeber&#8217;s theory of bullshit jobs. Using ratings from 202 workers on 171 workplace tasks, we (1) validate a five-item scale of perceived bullshitness, (2) show that perceived bullshitness strongly predicts desire for AI delegation, and (3) find that such tasks are also seen as requir</em></p><p><em>ing less human oversight. Together, these findings suggest that tasks perceived as bullshit are natural candidates for AI delegation, aligning worker preferences with perceived feasibility.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Vinci, Poland&#180;s state fund, <a href="https://thenextweb.com/news/poland-elevenlabs-stake-ai-lab-poland">took</a> an $11M stake in ElevenLabs, the $11bn AI-voice company. </strong> (<a href="https://thenextweb.com/news/poland-elevenlabs-stake-ai-lab-poland">The Next Web</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Vinci, the venture arm of Poland&#8217;s state development bank BGK, has taken an $11mn stake in ElevenLabs, the AI-voice firm valued at $11bn. The same day, it launched AI Lab Poland, a national programme to funnel funding, mentoring and global contacts to the country&#8217;s early-stage AI startups.&#8221;</em></p></li><li><p><strong>ElevenLabs</strong> also <a href="https://elevenlabs.io/blog/uk-mou-and-expansion">signed</a> <strong>a Memorandum of Understanding with the UK Government</strong> <strong>to bring voice AI to public services</strong>. <em>(The MoU is available <a href="https://www.gov.uk/government/publications/memorandum-of-understanding-between-the-uk-and-elevenlabs-on-ai-opportunities/memorandum-of-understanding-between-uk-and-elevenlabs-on-ai-opportunities">here</a>.)</em></p></li></ul></li><li><p><em>&#8220;<strong>Microsoft</strong> <strong>is moving</strong> <strong>Copilot Cowork to usage-based pricing</strong> as it expands access to the enterprise AI tool &#8212; and <strong>is considering a Microsoft-hosted version of DeepSeek</strong> as a cheaper model option.&#8221;</em> (<a href="https://tech.yahoo.com/ai/copilot/articles/microsoft-eyes-deepseek-enterprise-ai-162740418.html">Yahoo! Tech</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Microsoft's move to add a model from a Chinese AI company could draw criticism. [&#8230;] If Microsoft goes forward with DeepSeek, the company says, the model would be optional for customers and fully hosted on Azure, keeping customer data within Microsoft&#8217;s cloud and covered by Azure&#8217;s enterprise security, compliance and data-residency controls.&#8221;</em></p></li></ul></li><li><p>Chinese AI startup <strong>Z.ai</strong> announced <strong>the release of GLM-5.2</strong>, &#8220;<em>a 753-billion parameter open-weights large language model (LLM) <strong>engineered specifically to dominate &#8220;long-horizon&#8221; autonomous coding and engineering tasks</strong>.</em>&#8221; (<a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">Venture Beat</a>)</p><ul><li><p><em><strong>Why does this matter? </strong></em>According to <a href="https://artificialanalysis.ai/articles/glm-5-2-is-the-new-leading-open-weights-model-on-the-artificial-analysis-intelligence-index">Artificial Analysis</a>, <em>&#8220;Z ai&#8217;s GLM-5.2 is the new leading open weights model on the Artificial Analysis Intelligence Index scoring 51 and it sits on the Pareto frontier of Intelligence vs Cost per Task&#8221;</em></p></li></ul></li><li><p><strong>The U.S. government</strong> issued an export control directive that <strong>forced Anhtropic to suspend all foreign access to the Fable 5 and Mythos 5 models</strong>. </p><ul><li><p><em><strong>Why does this matter?</strong></em> Please see my short article on this export ban and its impact on the EU&#8217;s tech sovereignty: </p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d2797048-5b81-4399-9a83-f3bd04073610&quot;,&quot;caption&quot;:&quot;Anthropic released its most advanced AI models yet, Claude Fable 5 and Claude Mythos 5 on June 9 but after just a few days, based on the U.S. government&#8217;s export control directive, all access to Fable 5 and Mythos 5, whether inside or outside the U.S., including foreign Anthropic employees, was suspended.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;md&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;A slap in the face: US export ban on Anthropic's most advanced AI models and the European technological sovereignty&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:190153242,&quot;name&quot;:&quot;L&#225;szl&#243; P&#243;k&quot;,&quot;bio&quot;:&quot;Senior Privacy Manager | Data protection | AI &amp; Privacy &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b183c3a0-04e4-4eba-bd5d-9e0b44f0657e_509x509.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-16T07:01:43.529Z&quot;,&quot;cover_image&quot;:null,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://datalawgy.substack.com/p/a-slap-in-the-face-us-export-ban&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:202146802,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:3421089,&quot;publication_name&quot;:&quot;Datalawgy&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A slap in the face: US export ban on Anthropic's most advanced AI models and the European technological sovereignty]]></title><description><![CDATA[Anthropic released its most advanced AI models yet, Claude Fable 5 and Claude Mythos 5 on June 9 but after just a few days, based on the U.S.]]></description><link>https://datalawgy.substack.com/p/a-slap-in-the-face-us-export-ban</link><guid isPermaLink="false">https://datalawgy.substack.com/p/a-slap-in-the-face-us-export-ban</guid><dc:creator><![CDATA[László Pók]]></dc:creator><pubDate>Tue, 16 Jun 2026 07:01:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lD-4!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Anthropic <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">released</a> its most advanced AI models yet, <strong>Claude Fable 5 and Claude Mythos 5 </strong>on June 9 but <a href="https://www.anthropic.com/news/fable-mythos-access">after just a few days</a>, based on the U.S. government&#8217;s export control directive, all access to Fable 5 and Mythos 5, whether inside or outside the U.S., including foreign Anthropic employees, was suspended. </p><p>From an EU technological sovereignty perspective, this episode is significant because it clearly shows that access to frontier AI capabilities supplied by U.S. (or other third-country) providers can be easily interrupted and this can endanger Europe&#180;s position in the global technological race.</p><h2>1. Background: U.S. Export Restrictions on Anthropic Models</h2><p>Anthropic <a href="https://www.anthropic.com/news/fable-mythos-access">stated</a> on June 12, 2026, that <strong>the U.S. government, citing national-security authorities, issued an export-control directive requiring suspension of all access to Fable 5 and Mythos 5 by any foreign national</strong>, whether inside or outside the United States, including foreign-national Anthropic employees. Anthropic also stated that the directive did not provide specific details of the national-security concern, although the company understood the concern to relate to a method of bypassing, or &#8220;jailbreaking,&#8221; Fable 5. The company&#8217;s statement emphasized that access to other Anthropic models would not be affected.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/a-slap-in-the-face-us-export-ban?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/a-slap-in-the-face-us-export-ban?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><h2>2. EU Technological Sovereignty Implications</h2><p><strong>For the EU, the episode crystallizes a core sovereignty concern</strong>: reliance on non-EU AI providers can become a legal, operational, and strategic dependency when access is subject to foreign export-control decisions. The Commission <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-tech-sovereignty">defines</a> <strong>tech sovereignty as Europe&#8217;s ability to act independently in the digital world by developing and controlling key technologies, data, and infrastructure while reducing reliance on non-EU providers</strong>. The Commission <a href="https://cerre.eu/wp-content/uploads/2022/12/Digital-Industrial-Policy-for-Europe.pdf">has also stated</a> that the EU relies on non-EU countries for more than 80% of key digital products, services, infrastructure, and intellectual property.</p><p>The Anthropic restriction affects more than procurement convenience; it raises questions affecting<strong> the concept of</strong> <strong>tech sovereignty</strong> as such. The Commission <a href="https://www.euronews.com/my-europe/2026/06/14/us-export-controls-on-anthropic-should-not-be-discriminatory-eu-commission-warns">has expressly warned</a>, in response to the Anthropic situation, that contingency measures addressing cyber risks &#8220;<em>should not be discriminatory against partners</em>,&#8221; while noting that it was assessing practical consequences for European users. <strong>From a sovereignty perspective, the risk is that EU users may be locked out of frontier capabilities for cybersecurity, scientific, or industrial use cases precisely when those capabilities become strategically important.</strong></p><div><hr></div><p><em>Remember when President Trump announced the intention of the US to claim Greenland from Denmark? At that time, Denmark immediately <a href="https://www.businessinsider.com/denmark-f35-regret-choosing-defense-committee-chairman-tensions-us-greenland-2025-3">regretted</a> buying F-35 fighters from the U.S., fearing that the U.S. &#8220;may have a &#8220;kill-switch&#8221; that allows Washington to remotely disable F-35s purchased by US allies.&#8221; This may not be true, but it clearly shows that dependency on third parties in strategic areas such as defense and core technologies can make Europe vulnerable.  </em></p><div><hr></div><p>The critical-infrastructure dimension is particularly acute because AI capabilities increasingly support defense (including cyber defense), energy optimization, healthcare and more. It also increases concentration risk because EU organizations have relied on a small number of U.S. frontier-model providers for high-value workflows.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/subscribe"><span>Subscribe now</span></a></p><h2>3. The EU Tech Sovereignty Package</h2><p>The proposal for an <strong>European Technological Sovereignty Package</strong> <a href="https://digital-strategy.ec.europa.eu/en/news/commission-proposes-tech-sovereignty-package-strengthen-europes-digital-autonomy-and-resilience">was presented</a> on June 3, 2026, to strengthen Europe&#8217;s capacity in semiconductors, artificial intelligence, cloud, and open source. The package <a href="https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompanied-eu-open-source-strategy">includes</a> two legislative proposals:<strong> the Chips Act 2.0 and the Cloud and AI Development Act, as well as the EU Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy.</strong> The Commission describes the package as designed to reduce structural dependencies and ensure Europe can develop, deploy, and secure the technologies Europeans rely on.</p><p>The Chips Act 2.0 element <a href="https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompanied-eu-open-source-strategy">is aimed</a> at strengthening the semiconductor ecosystem, supply-chain resilience, cutting-edge semiconductor capacity, and domestic demand. The Cloud and AI Development Act (CADA) <a href="https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada">is intended</a> to support research and innovation, accelerate data-center deployment conditions, and introduce a single EU-wide assessment framework for cloud and AI sovereignty. The Open Source Strategy is intended to reduce dependencies across the technology stack, while the energy roadmap includes measures to build sovereign and secure AI models trained on European data for the energy sector.</p><p>The package builds on the <a href="https://digital-strategy.ec.europa.eu/en/library/ai-continent-action-plan">AI Continent Action Plan</a>, which focuses on computing infrastructure, data, skills, adoption, and regulatory simplification. Funding and infrastructure measures include <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_467">InvestAI</a>, which aims to mobilize &#8364;200 billion for AI investment, including a &#8364;20 billion European fund for AI gigafactories. <a href="https://digital-strategy.ec.europa.eu/en/policies/ai-factories">EU AI Factories and Gigafactories</a> are intended to give startups, SMEs, researchers, industry, and public authorities access to advanced compute for developing and fine-tuning AI models. <strong><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">In this respect, a U.S. access restriction strengthens the policy rationale for EU-owned compute, EU-governed model development, open-source alternatives, and public-sector procurement strategies that avoid single-provider dependence.</mark></strong></p><h2>4. Outlook</h2><p><strong>EU policymakers should treat this Anthropic episode as evidence supporting faster implementation of the Technological Sovereignty Package, especially the Cloud and AI Development Act, AI Factories, AI Gigafactories, open-source strategy, and sovereign AI initiatives in critical sectors.</strong> The EU should also press diplomatically for allied carve-outs, transparency, and non-discriminatory contingency mechanisms where U.S. export controls affect EU users and institutions.</p><p>EU organizations should respond by conducting AI vendor concentration reviews, testing fallback options, strengthening data portability, and maintaining model-agnostic architectures for critical workflows. In practical terms, the ban should accelerate a shift from &#8220;best model available&#8221; procurement toward <strong><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">resilience-based AI governance that prioritizes operational continuity and strategic autonomy.</mark></strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 24]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-5f0</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-5f0</guid><pubDate>Fri, 12 Jun 2026 10:02:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lD-4!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>Italy&#8217;s Council of Ministers</strong> <a href="https://www.governo.it/it/articolo/comunicato-stampa-del-consiglio-dei-ministri-n-177/32050">approved</a> <strong>two implementing decrees under Law No. 132/2025 to operationalize a comprehensive national AI regulatory framework</strong> under the AI Act. <em>(For a summary in English about these steps in the AI Act implementation in Italy, please see <strong><a href="https://www.gamingtechlaw.com/2026/06/italy-ai-act-implementing-decrees-2026/">Giulio Coraggio&#180;s article</a></strong>.) </em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Two decrees were approved:</em></p><ol><li><p><em>Powers of national AI authorities; AI in education and professional training; AI in employment relations.</em></p></li><li><p><em>AI in law enforcement (including biometric surveillance); civil liability for AI-caused harm; new criminal provisions.&#8221;</em></p></li></ol></li></ul></li><li><p><strong>President Javier Milei of Argentina</strong> <a href="https://www.batimes.com.ar/news/argentina/milei-promises-tech-firms-new-laws-and-unregulated-ai-in-argentina.phtml">promised</a> the world&#8217;s tech firms that <strong>Argentina will create a special legal framework to foster the development of AI</strong>, reaffirming his commitment to <strong>keeping the sector &#8220;unregulated&#8221;</strong>. (<a href="https://www.batimes.com.ar/news/argentina/milei-promises-tech-firms-new-laws-and-unregulated-ai-in-argentina.phtml">Buenos Aires Times</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the President stressed that its first pillar of his plan is a `commitment to keep AI unregulated so that it can develop freely, without the burden of premature and misguided regulation.`&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] Milei outlined his government's plan to create a new category of corporate entity in legislation: the &#8220;non-human corporation,&#8221; entities operated entirely by AI agents or robots.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The New York State Senate</strong> <a href="https://www.nysenate.gov/legislation/bills/2025/S8623/amendment/B">passed</a> <strong>the Bill</strong> <strong>that prohibits the use of surveillance pricing. </strong>The bill awaits for the Governor Hochul&#180;s signature. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;To protect consumers from discriminatory, opaque, and exploitative pricing practices driven by algorithmic systems that rely on personal data. The bill prohibits surveillance pricing, regulates the use of certain dynamic pricing systems, establishes disclosure requirements for certain pricing practices, and creates enforcement mechanisms to protect consumers from unfair and deceptive conduct.&#8221;</em></p></li><li><p>New York <a href="https://epic.org/new-york-becomes-third-state-to-pass-surveillance-pricing-ban/">joins</a> Maryland and Connecticut as <strong>the third state in the US to pass a surveillance pricing ban</strong>.</p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The Government of Canada</strong> <a href="https://www.canada.ca/en/canadian-heritage/news/2026/06/government-of-canada-introduces-legislation-to-make-social-media-services-and-ai-chatbots-safer-for-children.html">introduced</a> legislation (Bill C-34, the Safe Social Media Act) <strong>to make social media services and AI chatbots safer for children.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;While laws exist to respond once harm has happened, there is currently very little that requires online services to prevent harm in the first place. The Safe Social Media Act aims to change that by ensuring that social media services and artificial intelligence (AI) chatbots are responsible for addressing harm before it occurs.</em>&#8221;</p></li><li><p><em>&#8220;It will include an age restriction preventing children under the age of 16 from having accounts on social media services, with a pathway for social media services to seek an exemption if they can demonstrate that they have put in place sufficient safeguards for children.&#8221;</em></p></li><li><p><em>&#8220;The new requirements will also put children&#8217;s safety first when products and features are designed, including measures to reduce children&#8217;s exposure to certain content and high-risk interactions. Regulated services will be required to identify, mitigate and address the risks on their platforms.&#8221;</em></p></li><li><p><em>&#8220;The proposed legislation will create a legislative and regulatory framework through a new Digital Safety Act for social media services, including user-uploaded livestreaming and adult content services, and for certain AI chatbot services.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>Tech Justice Law, Social Media Victims Law Center and Susman Godfrey <a href="https://techjusticelaw.org/press-releases/mother-of-chatgpt-victim-sues-openai-chatbot-prioritized-engagement-over-addressing-suicide-threats/">have filed a lawsuit</a> in San Francisco County Superior Court against OpenAI and Sam Altman</strong> on behalf of Kristie Carrier, <strong>mother of ChatGPT suicide victim</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The lawsuit alleges various legal claims grounded in product liability, negligence, wrongful death and unfair competition. The suit also requests an injunction requiring OpenAI to implement a range of safeguards by default for users. The lack of such safeguards, or even warnings regarding the risk of psychological dependence or other harms, is a direct result of OpenAI&#8217;s prioritization of rushed product development and growth over user safety.&#8221;</em></p></li></ul></li><li><p><strong>The Privacy Commissioner of Canada&#180;s investigation into the Grok chatbot </strong>and sexualized deepfakes <strong><a href="https://www.priv.gc.ca/en/opc-news/news-and-announcements/2026/nr-c_260611/">found</a> violations of privacy law</strong>. <em>(The Report of Findings is available <a href="https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-004/">here</a>.) </em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] Grok&#8217;s AI image-generation tool was launched without proper safeguards or sufficient consideration of potential privacy harms. [&#8230;]&#8221; </em></p></li></ul></li><li><p><strong>The Council of Europe&#8217;s Cybercrime Convention committee and the Lanzarore Committee* </strong><a href="https://www.coe.int/en/web/children/-/creating-altering-and-distributing-ai-generated-child-sexual-abuse-material-is-criminalised-under-council-of-europe-conventions">have issued</a> <strong>a <a href="https://rm.coe.int/t-es-2026-07-en-final-and-t-cy-2026-05-en-final-tcy-lc-joint-statement/48802c0172">joint statement</a></strong> addressing the <strong>growing threats posed by AI-generated and altered child sexual exploitation and sexual abuse material</strong>. <em>(*Committee of the parties to the Convention on the protection of children against sexual exploitation and sexual abuse)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The committees encouraged state parties to both conventions to <strong>review reservations that may limit the criminalisation</strong> or prosecution of AI-generated or altered child sexual-exploitation or sexual-abuse material in light of the rapid development of artificial intelligence technologies.&#8221;</em></p></li><li><p><em>&#8220;The committees encouraged states parties to the conventions to strengthen efforts to <strong>prevent, detect, investigate and prosecute offences</strong> involving such material, including through enhanced international cooperation, the rapid removal of such material, specialised training for relevant professionals, and closer engagement with service providers and technology companies.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Irish Commercial High Court</strong> <a href="https://ww2.courts.ie/acc/alfresco/d03be1e0-7395-4ba4-86f5-c331e3670995/2026_IEHC_347.pdf/pdf">decided</a> to <strong>uphold the main findings of the Data Protection Commission (DPC) against TikTok regarding the violations of Articles 46 and 13(1)(f) GDPR</strong> over data transfers to China and transparency obligations. <em>(TikTok&#180;s press release is available <a href="https://www.tiktok.com/legal/page/global/update-on-irish-gdpr-decision/en">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong></em>The Court also declared that <em>&#8220;necessary prerequisite to the imposition of an administrative fine was met. I propose accordingly to dismiss the appeal against the decision to impose administrative fines. For the reasons explained above, I will leave over for further decision TikTok&#8217;s appeal against the amount of the fines imposed.&#8221;</em></p></li><li><p>Until the outcome of TikTok&#8217;s appeal, <strong>the Court allowed transfers of EEA users&#8217; data to China to continue in the meantime</strong>.</p></li><li><p><em><strong>What is the background to this? </strong> </em>The Irish Data Protection Commission, as the Lead Supervisory Authority for TikTok, <strong><a href="https://www.dataprotection.ie/en/news-media/latest-news/irish-data-protection-commission-fines-tiktok-eu530-million-and-orders-corrective-measures-following#_ftn1">fined</a> TikTok EUR 530 million in May 2025</strong>. The DPC found that TikTok &#8220;<em>infringed the GDPR regarding its transfers of EEA User Data to China and its transparency requirements</em>&#8221;. The decision included &#8220;<em>administrative fines totalling &#8364;530 million and an order requiring TikTok to bring its processing into compliance within 6 months.</em>&#8221; In addition to this, TikTok&#8217;s transfers of users&#180;data were ordered to be suspended to China if processing is not brought into compliance within the above timeframe. </p></li></ul></li><li><p><strong>The Australian Privacy Commissioner <a href="https://www.oaic.gov.au/news/media-centre/privacy-commissioner-finds-against-optus-in-white-pages-breach">found</a> Optus</strong>, an Australian carriage service provider, <strong>interfered with the privacy of individuals whose personal information was listed in the White Pages contrary to an expressed preference</strong> or request for an unlisted number.<em> (The detailed report is available <a href="https://www.oaic.gov.au/__data/assets/pdf_file/0031/264847/Commissioner-Initiated-Investigation-into-Singtel-Optus-Pty-Ltd-Determination.PDF">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The outcome was that 41,278 porting customers who had indicated an unlist preference remained published in the White Pages, exposing them to potential harm, particularly those in vulnerable circumstances.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The South Korean&#180;s Personal Information Protection Commission (PIPC) fined  Coupang, an online retail giant, with a record fine of more than $400m over a massive data breach</strong> that exposed the data of more than 30 million customers last year. (<a href="https://www.bbc.com/news/articles/cvgj4rgz2n2o">BBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The leak exposed the names, contact and delivery details and order histories of some customers of Coupang, South Korea&#8217;s largest e-commerce platform often described as its equivalent of Amazon. [&#8230;] The PIPC on Wednesday announced a 423.6bn won fine over the personal data breach, and an additional 201bn won for the non-consensual collection of information.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://digital-strategy.ec.europa.eu/en/news/commission-publishes-code-practice-marking-and-labelling-ai-generated-content">published</a> <strong>the final Code of Practice on marking and labelling AI-generated content</strong>. <em>(The Code is available directly <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">here.</a>)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Code is voluntary and sets out practical steps to help <strong>providers </strong>and <strong>deployers </strong>of generative artificial intelligence (AI) systems meet the <strong>AI Act</strong> transparency obligations that will apply from 2 August 2026.</em> <em>From that date, the AI Act will require clear labelling in key cases. <strong>Deepfakes </strong>and <strong>AI-generated or AI-manipulated text published on matters of public interest </strong>must be clearly labelled. Users must also be informed when they are interacting with an <strong>interactive AI system</strong>, such as a chatbot.&#8221;</em></p></li><li><p>Providers and deployers of genAI systems may <a href="https://digital-strategy.ec.europa.eu/en/library/how-sign-code-practice-transparency-ai-generated-content">sign up to the code</a>. &#8220;<em>With their signatures, providers and deployers of generative AI systems signal their intent to adhere to the code of practice as a way to comply with the obligations for transparency of AI-generated content (Article 50(2) and (4) of the AI Act).&#8221;</em></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!umE2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 424w, /__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 848w, /__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 1272w, /__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!umE2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png" width="875" height="186" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:186,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:132370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/200434139?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 424w, /__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 848w, /__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 1272w, /__u/substackcdn.com/image/fetch/$s_!umE2!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c2fa3a2-9535-4494-bd56-f8811d194196_875x186.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><em>(Source: <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Code of Practice</a> on marking and labelling AI-generated content, Annex 1, p. 38)</em></p></li><li><p><strong>The UK Government</strong> <a href="https://www.gov.uk/government/news/legal-innovation-to-be-supercharged-by-new-ai-growth-project">launched</a> <strong>a new AI growth project to fast-track innovation in legal technology</strong>, often known as <strong>LawTech</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;AI Growth Labs give organisations a safe space in which to test innovative legal services products and discuss any regulatory issues directly with regulators.&#8221;</em></p></li><li><p>Based on the <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/ico-statement-on-the-government-s-new-advisory-ai-growth-lab/">statement</a>, released by ICO (UK data privacy watchdog), the ICO will be collaborating with the Council for Licensed Conveyancers (CLC), Solicitors Regulation Authority (SRA) and Legal Services Board (LSB) to work with innovators on cross-regulatory challenges. William Malcolm, Executive Director for Regulatory Risk and Innovation, said that &#8220;<em>it's essential that legal firms and businesses can navigate data protection requirements with confidence as they seek to make legal services more efficient and effective for people. This pilot will help the sector access the new opportunities AI brings while providing assurance to the public that regulatory standards are met.</em>&#8221;</p></li></ul></li><li><p><strong>Oxford Economics</strong> <a href="https://adopt-ai.org/wp-content/uploads/2026/05/Oxford-Economics-x-AIAI_Sovereign-AI.pdf">published</a> a study, titled <em><strong>&#8220;The Economics of Sovereign AI: Balancing Autonomy, Innovation, and Growth in the Asia-Pacific&#8221;</strong></em>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;AI sovereignty can be pursued through a range of policy designs that vary in how far they require the AI stack to be domestically owned and localised. These choices can strengthen control, but can also introduce material trade-offs&#8212;higher costs, slower innovation cycles, constrained access to talent, and reduced interoperability. Where these costs translate into higher prices for AI services, compute, and compliance, they are ultimately borne by businesses and filter through the wider economy, reducing efficiency and, over time, constraining overall prosperity&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-5f0?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-5f0?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-5f0?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The European Data Protection Board (EDPB)</strong> <a href="https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2026/template-personal-data-breach-notification_en">has just released</a> a <strong>common template for data breach notifications</strong>. The template is open for <strong>public consultation until 5 August 2026</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The template provides predefined options to choose from, and further guidance on how to fill in the fields. This will help save time and costs, particularly for smaller organisations lacking dedicated DPOs or legal resources. [&#8230;] Following the public consultation, the EDPB will decide on the timeline for the practical implementation of the template by all DPAs.</em>&#8221;</p></li><li><p>The publication of the template is in line with the <strong><a href="https://www.edpb.europa.eu/our-work-tools/our-documents/statements/helsinki-statement-enhanced-clarity-support-and-engagement_en">EDPB&#8217;s Helsinki Statement</a></strong> to make GDPR compliance easier and strengthen consistency across Europe.</p></li></ul></li><li><p><strong>The Information Commissioner&#180;s Office (UK)</strong> <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/setting-out-our-expectations-for-the-smart-device-industry/">published</a> the finalised <strong>guidance on consumer Internet of Things (IoT) products and services</strong>, providing their  expectations for manufacturers and developers on how to use people&#8217;s personal information responsibly. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This guidance covers the processing of personal information by organisations providing IoT products on the consumer market. [&#8230;] This guidance also applies to user devices on which software or apps are installed that enable, configure or control the functionality of an IoT product (eg mobile phones, tablets, other computing devices).&#8221;</em></p></li><li><p><strong>ICO&#180;s expectations for IoT manufacturers and developers:</strong> </p><ul><li><p><em><strong>&#8220;Privacy must be built in from the start, not bolted on afterwards</strong> - with protective settings on by default and data collection limited to what is strictly necessary.</em></p></li><li><p><em><strong>Consent must be real, specific and freely given via a clear opt-in</strong> - and it must be just as easy to withdraw.</em></p></li><li><p><em><strong>Genuine transparency is more than a privacy notice</strong> - users must be clearly informed about how their data is used, in plain language and at relevant points across the whole product.</em></p></li><li><p><em><strong>Most firms will have to do a Data Protection Impact Assessment</strong> &#8211; due to the sensitive nature of the data they collect, with an even higher bar if children may use the product.</em></p></li><li><p><em><strong>Security is an ongoing legal obligation, not a one-time consideration</strong> &#8211; it requires regular updates, encryption, and multifactor authentication throughout the product&#8217;s lifetime.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The Dutch data protection authority, Autoriteit Persoonsgegevens (AP)</strong> <a href="https://www.dutchnews.nl/2026/06/privacy-complaints-to-dutch-watchdog-jump-75-in-a-year/">received</a> <strong>more than 13,500 complaints and tips about possible privacy breaches in 2025</strong>, a <strong>rise of 75% on the year before</strong>. <em>(The original report is available <a href="https://www.autoriteitpersoonsgegevens.nl/documenten/rapportage-klachten-2025">here</a> in Dutch).</em> </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Most complaints were regarding organisations involved that were not open about what personal data they hold, or refused to delete people&#8217;s data when asked, the watchdog said in its annual complaints report. Other complaints related to companies and public bodies that requested personal information without good reason.&#8221;</em></p></li><li><p>AP <a href="https://www.autoriteitpersoonsgegevens.nl/actueel/ap-grote-toename-van-privacyklachten">highlighted</a> that &#8220;<em>in 2025, the Dutch DPA received the most complaints about healthcare. More than half of these were about the data breach at Clinical Diagnostics.</em>&#8221; AP adds that they &#8220;<em>received many complaints in particular about how organizations deal with the right of access and the right to delete data. For example, organizations regularly do not respond or respond too late to access requests.</em>&#8221;</p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>The National Security Council of Germany</strong> <a href="https://www.heise.de/news/Bundesregierung-will-KI-Sicherheitsinstitut-gruenden-11326247.html">decided</a> <strong>to set up an AI security institute</strong>. (<a href="https://www.heise.de/news/Bundesregierung-will-KI-Sicherheitsinstitut-gruenden-11326247.html">Heise Online</a>) </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The German government wants to be able to better assess the opportunities and risks of modern AI models with the help of a new committee.&#8221; </em>The Institute <em>&#8220;is intended to bundle the capacities for analyzing the capabilities of modern AI models, including their risks.&#8221;</em></p></li><li><p>&#8220;<em>According to Bitkom and the T&#220;V Association, the new Institute for Artificial Intelligence will have the working title <strong>&#8220;German AI Security Institute (DE-AISI)&#8221;</strong>. In the initial phase, it is planned as a &#8220;virtual institution&#8221;, using structures and competencies of the Federal Network Agency and the Federal Office for Information Security (BSI).</em>&#8221; See Bitkom&#180;s position paper about the German AI Security Institute (DE-AISI) <a href="https://www.bitkom.org/sites/main/files/2026-06/bitkom-positionspapier-deutsches-ai-security-institute.pdf">here</a>.</p></li><li><p>The institute is also to engage more closely with comparable foreign institutes (e.g. the <a href="https://www.aisi.gov.uk/">UK-AISI</a>) and work towards uniform standards in dealing with AI with international partners. </p></li></ul></li><li><p><strong>ENISA</strong> <a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026">published</a> its report about the outcome ot the survey launched at the end of 2025 to gather factual data on <strong>how organisations across industries and of varying sizes are approaching Software Bill of Materials (SBOM) adoption in response to the EU Cyber Resilience Act (CRA)</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This report analyses the survey results, which confirm that the CRA acts as an accelerator for SBOM adoption. Organisations are broadly investing in SBOM generation and automation to integrate SBOMs into the Software Development Life Cycle (SDLC), while also accelerating their implementation timelines to meet expected maturity levels.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>OECD</strong> <a href="https://www.oecd.org/en/publications/smart-regulations-strong-business_93d38770-en.html">published</a> a report, <em>&#8220;<strong>Smart Regulations, Strong Business - Enabling Growth and Societal Protection in a Fast&#8209;Changing World</strong>&#8221;</em>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In a fast-changing and complex environment, governments are striving to maintain streamlined regulatory design and implementation that will enable growth and societal protections. The OECD Simplifying for Success (S4S) survey provides emerging evidence on where rules and procedures are considered most burdensome and on ongoing simplification efforts. This report highlights priority areas for regulatory simplification and reform, helping governments address both symptoms and root causes of excessive regulation, and offering policy considerations for more efficient and effective rulemaking.&#8221;</em></p></li></ul></li><li><p><strong>OECD </strong>also <a href="https://www.oecd.org/en/publications/information-sharing-in-competition-policy_ecbf13e9-en.html">published</a> a new policy paper, titled <em>&#8220;<strong>Information sharing in competition policy&#8221;</strong></em><strong>.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Competition rules governing information sharing must balance two primary risks: permissive rules may facilitate tacit collusion or explicit cartel conduct, while overly restrictive frameworks can chill legitimate collaboration and create market inefficiencies. This paper reviews how different forms of information exchange affect firm incentives and market outcomes, drawing on recent economic literature. It also examines how competition authorities across OECD jurisdictions have approached the issue in practice, including through enforcement, case law and guidance. The paper aims to clarify the main factors that shape competitive risk and how those factors are reflected in current assessment and enforcement.&#8221;</em></p></li></ul></li><li><p><strong>The European Committee of the Regions</strong> <a href="https://op.europa.eu/en/publication-detail/-/publication/82e2e2aa-6085-11f1-9b18-01aa75ed71a1/language-en?WT.mc_id=Searchresult&amp;WT.ria_c=125603&amp;WT.ria_f=8103&amp;WT.ria_ev=search&amp;WT.URL=https%3A%2F%2Fwww.cor.europa.eu%2F">published</a> a <em>&#8220;<strong>Foresight study on the future and potential use of quantum technology by local and regional authorities&#8221;</strong></em><strong>.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] The study looks at national Quantum strategies of different EU Member States, involvement of cities and regions in their implementation and how these strategies should be aligned at EU level to contribute making the EU a homogenous landscape for Quantum technology. The study looks at how LRAs should participate in pilot projects and pave the way for Quantum adoption at a larger scale and its combined use with state-of-the-art technology such as AI. It identifies how cities and regions can act as early adopters, testbeds, and sandboxes for Quantum solutions, thereby accelerating the responsible and inclusive deployment of these technologies across the EU for the benefit of European citizens. The results include actionable policy recommendations, a roadmap for local and regional engagement, and a set of indicators for monitoring progress. The study provides a reader-friendly introduction into Quantum technology for local political leaders and citizens to increase the acceptance rate of Quantum technology.&#8221;</em></p><p></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-5f0?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-5f0?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><strong><a href="https://ai-regulation.com/wp-content/uploads/2026/06/CHRISTAKIS_Chatbots_PART_2.pdf">&#8220;You Trust Your Chatbot With Everything. Should You? Part 2: Governments, Courts, and the Battle Over Your Chatbot Conversations&#8221;</a></strong></em> (AI Regulation Papers, 26-06-1, author: Theodore Christakis)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The very choices that make a chatbot useful, namely retention, memory, logging, personalisation and connected tools, are the choices that make the resulting record preservable, searchable, discoverable, disclosable and exploitable. A single stored conversation is, at the same moment, a candidate for police referral, a target for a government demand, evidence in a lawsuit, and an asset in a data breach. No prior work, to the author&#8217;s knowledge, has examined these four exposures together.&#8221;</em></p></li><li><p>The first part of the article, <em><strong>&#8220;You Trust Your Chatbot With Everything. </strong></em></p><p><em><strong>Should You? - Part 1: How The Controller Uses Your Chat Data&#8221;</strong></em> is available <a href="https://ai-regulation.com/wp-content/uploads/2026/03/You-Trust-Your-Chatbot-With-Everything.-Should-You-Theodore-CHRISTAKIS.pdf">here</a>.  </p></li></ul></li><li><p><em><strong><a href="https://arxiv.org/pdf/2407.10247">&#8220;Strategic Integration of Artificial Intelligence in the C-Suite: The Role of the Chief AI Officer&#8221;</a></strong></em> (author: Marc Schmitt)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] This paper develops a role-design theory to explain this variation. I identify three properties that distin guish AI from earlier cross-cutting enterprise technologies&#8212;distributed accountability for judgment, upstream governance, and non-stationarity&#8212;and three configurations through which organizations respond: concentrated extension, distributed extension, and role creation. The CAIO Framework links these properties to the executive design problems they generate and to the functions and capabilities required of the dedicated role. Four propositions specify when a dedicated CAIO emerges, what form an orga nization&#8217;s response takes, when the dedicated role is effective, and how configurations evolve over time. This paper contributes to research on executive leadership, orga nizational design, and digital governance by offering a theory-driven account of the strategic integration of AI at the executive level.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Anthropic</strong> <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">launched</a> <strong>Claude Fable 5 and Claude Mythos 5</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;It is state-of-the-art on nearly all tested benchmarks of AI capability, showing exceptional performance in software engineering, knowledge work, vision, scientific research, and many other areas.&#8221;</em></p></li><li><p>If you want to have an impression how good Fable 5 is in researching and writing academic papers, please check <strong>Andrew Maynard&#180;s</strong> <a href="https://www.linkedin.com/posts/andrewdmaynard_higher-education-in-the-age-of-mythos-class-ugcPost-7470365470534074368-EUYD?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAACAz90B0FfKvtKWSOOCdG6dsEK5TJIFYQY">LinkedIn post</a>, including &#8220;<em>100% Fable-generated paper on student-centred higher education in the age of Mythos-class AI</em>&#8221;.</p></li><li><p>At the same time, <strong>Anthropic</strong> <a href="https://www.anthropic.com/institute/recursive-self-improvement">calls for</a> <strong>global pause in AI development due to models&#8217; &#8220;recursive self-improvement&#8221; capabilities</strong>: &#8220;<em>We believe it would be good for the world to have the option to slow or temporarily pause frontier AI development to enable societal structures and alignment research to keep up with the advance of the technology.</em>&#8221;</p></li></ul></li><li><p><strong>OpenAI</strong> <a href="https://openai.com/index/openai-submits-confidential-s-1/">submitted</a> a <strong>draft confidential registration statement (S-1) to the U.S. Securities and Exchange Commission</strong> (SEC) for a proposed initial public offering (IPO).</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;We have not decided on timing yet; it may be a while because there are things we want to do that are likely easier as a private company.&#8221;</em></p></li><li><p>Anthropic <a href="https://www.anthropic.com/news/confidential-draft-s1-sec">submitted</a> a S-1 statement to the SEC one week before OpenAI. </p></li><li><p>According to <a href="https://www.cnbc.com/2026/06/12/chatgpt-a-billion-monthly-app-users-despite-souring-public-ai-sentiment.html">recent estimates</a> from Sensor Tower (market intelligence firm),  <strong>ChatGPT reached one billion monthly app users</strong> in May. (<a href="https://www.cnbc.com/2026/06/12/chatgpt-a-billion-monthly-app-users-despite-souring-public-ai-sentiment.html">CNBC</a>)</p></li><li><p><strong>OpenAI <a href="https://www.linkedin.com/posts/davidmdugan_shaping-the-future-of-ai-driven-shopping-activity-7468625703463456768-aSj5?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAACAz90B0FfKvtKWSOOCdG6dsEK5TJIFYQY">launched</a> ChatGPT ads in the UK</strong>, its first European market.</p></li></ul></li><li><p><strong>SpaceX <a href="https://www.cnbc.com/2026/06/12/spacex-ipo-the-largest-in-history.html">completes</a> the largest IPO in history</strong> when the company debuts on the Nasdaq on 12.06.2026. &#8220;<em>Pricing at $135 a share, the group is raising $75 billion at a valuation of $1.77 trillion.</em>&#8221; (<a href="https://www.cnbc.com/2026/06/12/spacex-ipo-the-largest-in-history.html">CNBC</a>) </p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 23]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-75c</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-75c</guid><pubDate>Fri, 05 Jun 2026 10:30:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UoON!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>President Trump</strong> <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">signed</a> an <strong>Executive Order on </strong><em><strong>&#8220;Promoting Advanced <br>Artificial Intelligence Innovation and Security&#8221;</strong></em>. (A fact sheet issued by the White House is available <a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-promotes-advanced-artificial-intelligence-innovation-and-security/">here</a>.)</p><ul><li><p><em><strong>Why does this matter? </strong></em>According to the <a href="https://www.cfr.org/articles/assessing-trumps-executive-order-on-ai-oversight">first assessment</a> by the Council on Foreign Relations, the Executive Order (EO) <em>&#8220;marks a shift by the administration toward federal oversight of AI.&#8221;</em></p></li><li><p><em>&#8220;Among other measures, the order requests that AI companies voluntarily provide the federal government access to &#8220;covered frontier models&#8221; for a cybersecurity review up to thirty days before their planned release to &#8220;other trusted partners.&#8221; Its passage comes as concerns have mounted over the ability of some powerful AI models, such as Anthropic&#8217;s Claude Mythos, to autonomously identify and exploit hidden vulnerabilities in real-world software.&#8221;</em></p></li><li><p>According to Matthew Ferren (an international affairs fellow in national security at the Council on Foreign Relations, sponsored by Janine and J. Tomilson Hill), <em>&#8220;The order is best understood as an attempt to engineer a cybersecurity window of opportunity. It grants defenders preferential access to frontier cyber capabilities while attempting to delay adversary access through a prerelease evaluation period and a classified National Security Agency-run process for designating `covered frontier models.`&#8221;</em></p></li><li><p>According to Vinh Nguyen (a senior fellow for AI at the Council on Foreign Relations), <em>&#8220;President Trump&#8217;s order supplies the institutional framework for reviewing new frontier AI systems. Its most consequential provision is also the most difficult to execute: defining what counts as a &#180;covered frontier model.&#180;</em>&#8221; [&#8230;] <em>&#8220;What remains to be seen is whether the classified benchmarking process can evolve at the pace the technology demands. Frontier AI capabilities advance on a timeline measured in months, not years. The institutions charged with evaluation will need to match that tempo or they will assess yesterday&#8217;s models against yesterday&#8217;s threats.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>Louisiana has become the 22nd U.S. state to enact a comprehensive consumer privacy law</strong> and the third this year following Oklahoma and Alabama. The law will go into effect on January 1, 2027. (<a href="https://fpf.org/blog/privacy-becomes-you-bayou-state-a-look-at-the-louisiana-data-privacy-act/">Future of Privacy Forum</a>) For more info, please see FPF&#180;s <a href="https://fpf.org/blog/privacy-becomes-you-bayou-state-a-look-at-the-louisiana-data-privacy-act/">blog post</a> about the new law. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Overall, this is a fairly standard state privacy law that follows the Washington Privacy Act framework apart from the law&#8217;s CCPA-style applicability thresholds.&#8221;</em></p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://commission.europa.eu/news-and-media/news/strengthening-europes-tech-sovereignty-2026-06-03_en">has put forward</a> <strong>the European technological sovereignty package, </strong>a set of measures <strong>to strengthen </strong>the EU&#8217;s<strong> capacity in semiconductors, artificial intelligence, cloud and open source</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The European Union currently <a href="https://cerre.eu/wp-content/uploads/2022/12/Digital-Industrial-Policy-for-Europe.pdf">relies on non-EU countries for over 80% of key digital products, services, infrastructure, and intellectual property</a>. Reducing this dependency is essential for Europe&#8217;s economic strength, security, and long-term competitiveness.&#8221; </em>(You can find more details about the package <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-tech-sovereignty">here</a>.)</p></li><li><p><em><strong>What does the package include?</strong></em> The package includes:</p><ul><li><p>two legislative proposals: <a href="https://digital-strategy.ec.europa.eu/en/news-redirect/940653">the Chips Act 2.0</a> and <a href="https://digital-strategy.ec.europa.eu/en/news-redirect/940660">the Cloud and AI Development Act</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/open-source-strategy">the EU Open Source Strategy</a></p></li><li><p><a href="https://energy.ec.europa.eu/topics/eus-energy-system/digitalisation-energy-system_en#strategic-roadmap-for-digitalisation-and-ai-in-energy">a Strategic Roadmap for Digitalisation and AI in Energy</a></p></li></ul></li><li><p><em><strong>What are the key focus areas in the package? </strong>&#8220;The package focuses on four key areas</em></p><ul><li><p><em>securing the semiconductor base for Europe&#8217;s AI ambition &#8211; the <strong>chips act 2.0</strong> will help build capacity in cutting-edge semiconductor technologies, boost supply and demand, and support investment</em></p></li><li><p><em>unlocking the potential of Europe&#8217;s cloud and AI capacity &#8211; the <strong>cloud and AI development act </strong>will support research and innovation in cutting-edge and sustainable technologies, streamline conditions for deploying datacentres across the EU, and introduce a single EU-wide framework to assess cloud and AI sovereignty</em></p></li><li><p><em>strengthening digital autonomy through open source &#8211; the <strong>open source strategy</strong> will scale up open source alternatives in priority areas, invest in skills, start-ups and digital infrastructure, and support greater use of open source in public administrations</em></p></li><li><p><em>digitalising Europe&#8217;s energy system, while ensuring sustainable digitalisation &#8211; the <strong>strategic roadmap for digitalisation and AI in the energy sector</strong> will ensure data centres are integrated into our energy system, accelerate the deployment of digital and AI solutions, and build sovereign and secure AI models for the energy sector&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!sZA7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 424w, /__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 848w, /__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!sZA7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png" width="1112" height="428" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:428,&quot;width&quot;:1112,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:93604,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/199701468?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 424w, /__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 848w, /__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sZA7!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f0f5f7-1eb4-497d-bb59-ee0289e22e78_1112x428.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>(Source: European Commission, <a href="https://ec.europa.eu/commission/presscorner/api/files/attachment/882568/Factsheet%20Tech%20Sovereignty.pdf">Factsheet</a>)</em></p></li></ul></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>Florida filed a lawsuit against OpenAI, and its CEO, Sam Altman</strong>, alleging that <strong>the company concealed serious safety risks with its chatbot.</strong> (<a href="https://www.theguardian.com/technology/2026/jun/01/florida-lawsuit-openai-sam-altman">The Guardian</a>) <em>The full complaint is available <a href="https://www.myfloridalegal.com/sites/default/files/openai-filed-stamped-complaint.pdf">here</a>. </em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The civil complaint alleges that OpenAI and Altman prioritized speed to market and commercial gain over user safety, disregarded repeated warnings from experts both inside and outside the company, and deployed a product that facilitates and encourages harm&#8212;including self-harm and violence&#8212;while falsely assuring users it was safe.&#8221; (<a href="https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeier-files-first-nation-state-led-lawsuit-against-openai-ceo">Office of the Attorney General</a></em></p><p><em><a href="https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeier-files-first-nation-state-led-lawsuit-against-openai-ceo">State of Florida</a>)</em></p></li><li><p><em>&#8220;Last month, the Office of Statewide Prosecution <a href="https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeier-launches-criminal-investigation-openai-chatgpt">launched a criminal investigation</a> after prosecutors reviewed chat logs between ChatGPT and Phoenix Ikner, the gunman who opened fire at Florida State University on April 17, 2025, claiming two lives and injuring several others. The criminal investigation is ongoing.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The French Data Protection Authority (CNIL) <a href="https://www.cnil.fr/en/health-data-fine-5-million-euros-against-iqvia">fined</a> IQVIA OPERATIONS FRANCE of EUR 5 million</strong>, in particular because <strong>it didn't respect guarantees aimed at limiting risks to individuals in the management of health data warehouses</strong>. The CNIL also issued orders requiring the company to take measures to remedy certain breaches within six months, subject to a penalty of 10,000 euros per day of delay.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;The restricted committee found that the risk of a person&#8217;s identity being identified was too high for the data processed by the company to be considered anonymous, given:</em></p><ul><li><p><em>the existence of a unique identifier;</em></p></li><li><p><em>the depth of the data collected by the company;</em></p></li><li><p><em>the possibility of identifying individuals by combining data held by IQVIA with publicly available data.&#8221; </em></p></li></ul></li><li><p><em>&#8220;The restricted committee thus noted that security requirements were not being met. For instance, for both data warehouses, no measure allowed to regularly analyze connection logs and thus effectively detect abnormal activities. For the EMR data warehouse, no multi-factor authentication was implemented to access data.&#8221;</em></p></li><li><p><em>&#8220;The restricted committee noted that, while the company entrusted the pharmacists, who were the only ones in direct contact with the data subjects, with the task of providing this information on its behalf, it is indeed up to IQVIA, as the data controller, to ensure compliance with this obligation.&#8221;</em></p></li></ul></li><li><p><strong>The Italian Data Protection Authority (Garante)</strong> <a href="https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10255522">has sent</a> <strong>a warning to an Italian start-up that has developed</strong> <strong>an add-on (plug-in)</strong> for the corporate messaging platforms Slack and Teams, <strong>aimed at detecting, through artificial intelligence and semantic analysis of chats, the level of psychological stress of workers </strong>who voluntarily decide to use it to receive personalized suggestions.</p><ul><li><p><em><strong>Why does this matter?</strong> &#8220;[&#8230;] considering the particular sensitivity of the data processed, as well as the possibility of providing employers with aggregate reports on the level of stress of employees, the Authority has invited the company to adopt, from the design of the service, adequate measures to prevent any risk of access, even indirect, to information relating to the emotional sphere of workers. [&#8230;] the Authority recalled the risks associated with the use of technologies based on linguistic models and semantic analysis, which can produce results that are not always transparent, explainable or verifiable, with possible discriminatory effects or detrimental to workers&#8217; rights.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The European Court of Justice (General Court)</strong> <strong><a href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-06/cp260077en.pdf">annuled</a> the decision designating Meta as a gatekeeper as regards Marketplace</strong> under the Digital Markets Act, while maintaining Meta&#8217;s designation for its interpersonal communications service Messenger (T&#8209;1078/23). <em>(The full text of the judgment is available <a href="https://infocuria.curia.europa.eu/tabs/jurisprudence?sort=DOC_DATE-DESC&amp;searchTerm=%22T-1078%2F23%22&amp;publishedId=T-1078%2F23&amp;lang=EN">here</a>.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the Commission, in its assessment of the classification of Marketplace as a core platform service that is an online intermediation service, <strong>erred in law since it had considered that it could rely solely on data concerning the last three years preceding designation, without taking account of changes made at the end of July 2023.</strong>&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] The factors relied on in the decision in that respect are in particular hypothetical and incomplete. In those circumstances, the General Court concludes that <strong>the decision does not satisfy the requirements in terms of reasoning as regards Marketplace, in that it allows neither Meta to understand the reasons for its classification as a core platform service that is an online intermediation service nor the Courts of the European Union to exercise their power of review.</strong>&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The World Economic Forum</strong> <a href="https://www.weforum.org/stories/2026/06/ai-workplace-adoption-readiness/">released</a> an article on the <strong>human readiness for AI adoption</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;While executives push for rapid AI scaling, most employees feel threatened by it. This tension has created a "capability overhang"; a significant gap between what AI systems can technically do and how they are actually used in practice.&#8221;</em></p></li><li><p><em>&#8220;Our study highlights that resistance to AI is deeply rooted and operates in two arenas. In frontstage settings &#8211; public, visible areas &#8211; employees may appear to comply with AI mandates to manage impressions. However, in backstage settings, they often engage in informal critique, "clowning" AI tools, or finding ways to circumvent and delay their use.&#8221;</em></p></li></ul></li><li><p>According to a report published by the <a href="https://www.nytimes.com/2026/06/01/us/politics/china-ai-predicting-dissent.html">New York Times</a>, &#8220;<em>A<strong> Chinese company*</strong> has been trying to <strong>develop artificial intelligence-powered technology that would enable authoritarian governments to</strong> not just monitor dissidents but also <strong>potentially predict who could become one in the future</strong>.</em>&#8221; (*Geedge Networks)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Such technology, if perfected, would give authoritarian governments a powerful tool to use against perceived enemies.&#8221;</em></p></li><li><p><em>&#8220;The Vanderbilt researchers found that Geedge, working with its government-supported research arm, MESA Lab, was developing technology that would generate profiles of Chinese citizens and then use A.I. to highlight who may pose a political risk.&#8221;</em></p></li><li><p><em>&#8220;The Geedge researchers appeared to be developing tools to use artificial intelligence to predict who could become critics of the Chinese government, based on the data patterns the company&#8217;s surveillance technology collected.&#8221;</em></p></li></ul></li><li><p><strong>The MIT AI Risk Initiative</strong> <a href="https://airisk.mit.edu/priorities">published</a> a new study, <em><strong>&#8220;Prioritization of Risks from Artificial Intelligence - A Delphi Study of 272 International Experts&#8221;</strong></em>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] experts judged 18 of 24 risks as having a more than 10% probability of catastrophic outcomes (e.g., more than 1 million deaths or more than USD 100B in financial loss) in the next 5 years (2025-2030).&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!UoON!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 424w, /__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 848w, /__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 1272w, /__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!UoON!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png" width="834" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:834,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163254,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/199701468?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 424w, /__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 848w, /__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 1272w, /__u/substackcdn.com/image/fetch/$s_!UoON!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb151ebbc-93c0-4c5f-8432-b03d46967b6f_834x768.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>(Source: <a href="https://airisk.mit.edu/priorities">MIT AI Risk Initiative</a>)</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-75c?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-75c?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-75c?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>Singapore's Personal Data Protection Commission (PDPC)</strong> <a href="https://files.app.optical.gov.sg/pdpc/production/assets/ceb45ef8-294d-4b45-be35-e884d578fd8d.pdf">released</a> a set of proposed <strong>Advisory Guidelines on the Use of Personal Data in Generative AI</strong>. <em>(PDPC also initiated a <a href="https://www.pdpc.gov.sg/organisations/regulations-decisions/public-consultations/public-consultation-on-the-proposed-advisory-guidelines-on-use-of-personal-data-in-generative-ai">public consultation</a> on the proposed guidelines, inputs can be submitted to the PDPC by 1 July 2026, 5.00pm.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Guidelines address some of the key data protection issues relating to Generative AI today. These include the (i) collection and use of personal data to develop Generative AI Models; (ii) allocation of data protection responsibilities across the Generative AI lifecycle; and (iii) handling of individuals&#8217; requests concerning the processing of their personal data for Generative AI.&#8221;</em></p></li></ul></li><li><p><strong>The European Parliament</strong> <strong>will replace Google with the French search engine, Qwant as the default search tool </strong>on in-house computers. (<a href="https://www.politico.eu/article/european-parliament-ditches-google-for-french-search-engine/">Politico</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>According to the <a href="https://www.politico.eu/article/european-parliament-ditches-google-for-french-search-engine/">news report</a>, &#8220;the change is being made `in line with the Parliament&#8217;s commitment to digital sovereignty and the protection of users&#8217; personal data.`&#8221;</em></p></li></ul></li><li><p>According to news reports, &#8220;<em><strong>Malaysia&#8217;s social media ban for minors sparks privacy debate.</strong></em>&#8221; (<a href="https://amp.dw.com/en/malaysias-social-media-ban-for-minors-sparks-privacy-debate/a-77403526">DW</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;A ban on <strong>social media</strong> accounts for children under 16 that took effect June 1 has made <strong>Malaysia</strong> one of the latest countries to impose <strong><a href="https://www.dw.com/en/do-social-media-age-limits-work-tiktok-instagram-cyberbullying-depression-kids-children-australia/a-76713278">age-based limits on access to digital platforms</a></strong>.&#8221;</em></p></li><li><p><em>&#8220;About 8 million of the 36 million people in Malaysia are younger than 16. The Malaysian government says the measure is intended to protect children, not cut them off from technology altogether.&#8221;</em></p></li><li><p><em>&#8220;[&#8230;] UN High Commissioner for Human Rights Volker T&#252;rk argued that children could easily circumvent such bans and <strong><a href="https://www.dw.com/en/australia-social-media-ban-children-feel-isolated-ignored/a-75075938">end up in even riskier, less monitored spaces</a></strong>.&#8221;</em></p></li><li><p><em>&#8220;Users are required to provide government-registered identification documents such as an identity card or passport, `which may infringe on users&#8217; right to remain anonymous, which is highly crucial in a country that continues to have restrictions over freedom of speech`&#8221;</em>, said Tricia Yeoh, associate professor at the University of Nottingham Malaysia's School of Politics and International Relations. </p></li><li><p><em>&#8220;A system requiring millions of users to verify their identities may be introduced for child protection, but it also raises questions about data retention, surveillance and whether online anonymity could be weakened more broadly.&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>The Cyber Security Agency of Singapore</strong> <a href="https://www.csa.gov.sg/alerts-and-advisories/advisories/ad-2026-005/">released</a> an advisory <strong>on the risks of Autonomous AI agents, such as OpenClaw</strong>. <em>(The advisory draws attention to IMDA&#8217;s <a href="https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/openclaw-case-study.pdf">Case Study</a> on the Responsible Deployment of OpenClaw, and highlights the key cybersecurity risks .) </em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;These risks include unpatched vulnerabilities, weak access controls, sensitive data exposure, malicious third-party skills, and memory poisoning. If left unaddressed, they can lead to agent hijacking, unauthorised agent actions through tool or API abuse, and unauthorised access to systems or data.&#8221;</em></p></li></ul></li></ul><p><strong>4) Digital Policy, Cloud and Data Strategy</strong></p><ul><li><p><strong>The European Parliamentary Research Service (EPRS)</strong> <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/789316/EPRS_BRI(2026)789316_EN.pdf">published</a> a briefing about the <em>&#8220;<strong>Debate on setting a minimum age for social media&#8221;</strong></em><strong>. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In recent years, concerns over the impact of social media on minors have increased, prompting governments around the world, including in several EU Member States, to consider restricting children's access to social media. In March 2026, UNICEF reported that nearly 40 countries worldwide are discussing, proposing, adopting or implementing age-based restrictions. [&#8230;] Early implementation, notably in Australia, suggests that these restrictions are not yet very effective. [&#8230;] Within the EU, the proliferation of national initiatives restricting children's access to social media also raises the risk of regulatory fragmentation across Member States. [&#8230;] To avoid fragmentation of laws across the EU, several Member States and the European Parliament have called for the exploration of a common EU approach, including the introduction of an EU-wide minimum age for social media, or a broader digital majority age. The European Commission [&#8230;] is also advancing work on a harmonised age verification framework.&#8221;</em></p></li></ul></li><li><p><strong>Canada and France </strong><a href="https://www.canada.ca/en/innovation-science-economic-development/news/2026/05/joint-statement-of-the-department-of-industry-representing-the-government-of-canada-and-the-delegate-ministry-for-ai-and-digital-affairs-of-the-fre.html">signed</a> a <strong>Joint Statement on Cooperation in Quantum Science and Technologies.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The partnership reflects the intent of both countries to advance multidisciplinary quantum research and development, facilitate knowledge exchange and open data sharing, and build a skilled and diverse quantum workforce. At a time when the urgency of these dual&#8209;use technologies is rapidly increasing, this collaboration aims to accelerate quantum innovation for societal benefit, economic prosperity and international leadership.&#8221; (<a href="https://www.canada.ca/en/innovation-science-economic-development/news/2026/05/canada-advances-priorities-on-artificial-intelligence-quantum-technologies-and-digital-innovation-at-the-2026-g7-digital-ministers-meeting.html">Press release</a>)</em></p><p></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-75c?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-75c?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6849678">&#8220;</a><strong><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6849678">Law Professors Prefer AI Over Peer Answers&#8221;</a></strong></em><strong> </strong>(authors: Salinas et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] We conducted a blinded evaluation of short-answer tutoring in contracts courses with sixteen U.S. law professors. Participants created 40 representative questions, wrote answers, and judged 2,918 anonymized comparisons between human and LLM responses. Professors rated LLMs far higher than their peers (average win rate = 75.33%), with models performing similarly to the best instructor. LLM responses were also rarely flagged as harmful (3.53% vs 12.06% for professors). Preferences for LLM answers were consistent across evaluators and reflected shared professional standards. Our evaluation can be reliably extended to additional models by employing a separate LLM as a judge, rendering expert agreement an effective, scalable method to evaluate AI tutors in judgment-rich domains.&#8221;</em></p></li></ul></li><li><p><em><strong><a href="https://arxiv.org/html/2606.02741v1">&#8220;Greener Than Humans? Environmental Attitudes in Large Language Models&#8221; </a></strong></em>(authors: Kunkel et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] This paper develops a benchmark for evaluating environmental cognition, affect, and behavioural recommendations in LLMs and applies it to 31 widely used proprietary and open-weight models. [&#8230;] We find that many LLMs align more closely with environmentally progressive attitudes than the average survey respondent, exhibiting higher levels of environmental affect and cognition and recommending behaviours associated with substantial potential CO<sub>2</sub> reductions. At the same time, we observe no systematic relationship between sustainability-oriented responses and model origin, size, or release context. However, models exhibit contextual sensitivity, controlled by persona-based prompting and show sycophantic shifts mirroring user-specified ideological positions, which raises concerns about steerability and normative reliability in real-world deployments. Our findings provide a reusable evaluation framework for assessing sustainability-related value alignment in LLMs and highlight the importance of governance, transparency, and critical oversight as AI systems become increasingly embedded in sustainability transformations and public decision-making.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Anthropic</strong> <a href="https://www.anthropic.com/news/confidential-draft-s1-sec">confidentially </a><strong><a href="https://www.anthropic.com/news/confidential-draft-s1-sec">submitted</a> a draft registration statement to the U.S. Securities and Exchange Commission for a proposed initial public offering (IPO) </strong>of their common stock. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The proposed initial public offering will depend on market conditions and other factors.&#8221;</em></p></li></ul></li><li><p><strong>Musk <a href="https://www.cnbc.com/2026/06/03/elon-musks-net-worth-poised-to-sail-past-1-trillion-in-spacex-ipo.html">is poised</a> to become the first trillionaire</strong>, based on SpaceX&#8217;s updated IPO prospectus, as shares owned by Musk in the company worth more than $866 billion. (Musk also has a $350 billion-plus stake in Tesla.) (<a href="https://www.cnbc.com/2026/06/03/elon-musks-net-worth-poised-to-sail-past-1-trillion-in-spacex-ipo.html">CNBC</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Assuming SpaceX hits the Nasdaq next week at or near its expected valuation, Musk will oversee two of the eight most valuable U.S. companies.&#8221;</em></p></li><li><p><em>&#8220;Some investors have <a href="https://www.cnbc.com/2026/05/26/spacex-tesla-merger-chatter-reignites-as-musk-rocket-company-nears-ipo.html">speculated</a> of late that Musk&#8217;s ultimate plan could be to merge SpaceX and Tesla as a way to consolidate artificial intelligence resources and to streamline future capital raises.&#8221;</em></p></li><li><p>According to the <a href="https://www.cnbc.com/2026/06/03/spacex-ipo-stock-price-roadshow-musk.html">news</a> (CNBC), &#8220;<em>SpaceX plans to market its IPO at a fixed price of $135 per share, with a valuation of $1.77 trillion.</em>&#8221;</p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 22]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d3</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d3</guid><pubDate>Fri, 29 May 2026 08:31:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Xbp7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Swedish Parliament (Riksdag) <a href="https://www.riksdagen.se/en/news/articles/2026/may/26/police-may-use-ai-for-real-time-facial-recognition_cmsa0978678-2e7a-420e-9b39-5f36158aae2aen/">voted</a> in favour</strong> of the Government&#8217;s proposal to <strong>allow the Swedish Police Authority to use AI technology for real-time facial recognition</strong>. The new act and other amendments will come into force on 1 July 2026.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The proposal means that the Police Authority will be able to use AI technology if absolutely necessary to locate or identify a specific person:</em></p><ul><li><p><em>who is suspected of being the victim of kidnapping, human trafficking or human exploitation or who is missing and suspected of being the victim of crime;</em></p></li><li><p><em>if there is an imminent risk that the person will commit a serious crime that involves danger to another person&#8217;s life or physical security;</em></p></li><li><p><em>who is suspected on reasonable grounds of having committed a serious crime for which the scale of penalties includes imprisonment for four years or more or where such a penalty may be involved for attempting, preparation or conspiracy to commit such a crime, with the purpose of investigating or bringing the crime to trial</em></p></li><li><p><em>who has been sentenced for such a serious crime, with the purpose of implementing the penalty.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The Commission</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/report-review-prohibitions-and-high-risk-ai">adopted</a> a <strong>report to assess whether there is a need to amend the list of prohibited AI practices and high-risk use cases</strong> set out in Annex III of the AI Act.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] the report concludes that the assessment of other AI practices that are particularly harmful and abusive and that contradict EU values and fundamental rights are still at an early stage. There is also a lack of practical experience with the prohibitions. A more substantive evaluation of the application of Article 5 AI Act will only become possible after the prohibitions have applied for at least a year and common challenges or regulatory gaps begin to emerge. [&#8230;] It is also expected that regulatory sandboxes established in accordance with the AI Act will be mechanism for regulatory learning and evidence collection that will help to identify possible regulatory gaps and challenges in interpretation. Based on the evidence collected and the assessment made in this report, the Commission has flagged specific AI systems for monitoring and further analysis in subsequent reviews&#8221;</em></p></li></ul></li></ul><p><strong>2) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://digital-strategy.ec.europa.eu/en/news/commission-proposes-new-authorisation-mobile-satellite-services-eus-resilience-and-competitiveness">adopted</a> <strong>a proposal for the selection of mobile satellite services (MSS) providers</strong> who will be authorised to use the harmonised 2 GHz frequency band beyond 2027, when the current licenses expire</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Spectrum for mobile satellite services is a strategic asset for enabling innovative commercial use, and for security and defence. The 2 GHz MSS band is ideal for Direct-to-Device (D2D) services, providing critical communication capabilities and ensuring access to high-speed internet in areas without terrestrial coverage. The Commission proposes to establish an EU-level selection procedure for the assignment of this spectrum. Granting an EU level authorisation for the use of the 2 GHz frequency band for mobile satellite services in all EU Member States will ensure regulatory consistency across the EU and allow operators to develop and provide services across borders.&#8221;</em></p></li></ul></li><li><p>&#8220;<em><strong>The European Commission</strong> wants governments to buy chips made &#8203;by EU startups as it <strong>seeks to reduce Europe&#8217;s &#8204;reliance on U.S. and East Asian products</strong>, [&#8230;]</em>&#8221; (<a href="https://www.reuters.com/world/asia-pacific/europe-incentivise-governments-buy-made-in-eu-chips-by-startups-document-shows-2026-05-28/">Reuters</a>)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The proposal, dubbed Chips Act 2.0, supplements the original Chips Act implemented three &#8203;years ago, which has so far failed to achieve &#8203;its goals to attract advanced manufacturing in a bid &#8288;to double the bloc&#8217;s global chip market share to 20% by &#8203;2030. [&#8230;] While the Chips Act focused on supply side measures, the &#8204;Chips &#8288;Act 2.0 will focus on the demand side, the EU document said.&#8221;</em></p></li></ul></li><li><p><strong>The European Commission</strong> <a href="https://digital-markets-act.ec.europa.eu/commission-publishes-2025-report-digital-markets-act-implementation-2026-05-22_en">published</a> <strong>its third annual report </strong>outlining the progress towards achieving the objectives of t<strong>he Digital Markets Act (&#8216;DMA&#8217;)</strong> to support fair and contestable digital markets in the EU.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>CNN <a href="https://edition.cnn.com/2026/05/28/media/cnn-sues-perplexity-ai-copyright">sues</a> Perplexity over alleged AI copyright theft</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;CNN is suing Perplexity, accusing the AI company of unlawfully copying and distributing CNN&#8217;s content. [&#8230;] The filing in the United States District Court for the Southern District of New York indicates that CNN sought to strike a content deal with Perplexity last year but did not agree on terms.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Spanish Data Protection Authority (AEPD)</strong> imposed <strong>a fine of EUR 18 million on AMADEUS</strong> (EUR 14,4 million after the 20% reduction for voluntary payment). (For an English summary, please see <strong>Jorge Garcia Herrero&#180;s <a href="https://www.linkedin.com/posts/jorgegarciaherrero_amadeus-ugcPost-7465012731788800000-2to7?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAACAz90B0FfKvtKWSOOCdG6dsEK5TJIFYQY">LinkedIn post</a>.</strong>)</p><ul><li><p><em><strong>Why does this matter? </strong></em>Amadeus violated Art. 14 of the GDPR by failing to provide proper information about the data processing and Art. 6 of the GDPR by lacking a lawful basis for processing data.</p></li></ul></li><li><p>According to <a href="https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown">Europol</a>, &#8220;<em><strong>a VPN service used by cybercriminals to conceal ransomware attacks, data theft, and other serious offences has been dismantled</strong> in an international operation led by France and the Netherlands, with support from Europol and Eurojust.</em>&#8221; The takedown followed an investigation launched in December 2021.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The coordinated action took place between 19 and 20 May and targeted the infrastructure behind one of the most widely used VPN services in the cybercrime underground. During the action days, authorities:</em></p><ul><li><p><em>interviewed the administrator and conducted a house search in Ukraine;</em></p></li><li><p><em>dismantled 33 servers linked to the criminal service;</em></p></li><li><p><em>disrupted infrastructure used to support cybercriminal activity worldwide.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The California Attorney General</strong> <a href="https://oag.ca.gov/news/press-releases/attorney-general-bonta-sues-chrome-holding-co-formerly-known-23andme-over-2023">filed</a> <strong>a lawsuit against Chrome Holding Co., formerly known as 23andMe</strong>, <strong>for failing to protect its customers&#8217; sensitive personal information and genetic data</strong> related to their health, genetic predispositions and risk factors, biological relatives, ancestry, and ethnicity.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;While 23andMe publicly touted its commitment to data privacy and transparency, in truth, it failed to take reasonable measures to protect its customers&#8217; most sensitive data, ignored known vulnerabilities in its systems, and failed to properly investigate or respond to numerous warnings that its systems had been compromised. The company also misled its customers and the public regarding crucial aspects of the 2023 data breach. In the complaint, filed today in San Francisco Superior Court, Attorney General Bonta alleges 23andMe&#8217;s failures to implement and maintain reasonable security procedures and its misleading statements regarding its security and the data breach were unlawful.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The European Commission</strong> <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1178">issued</a> <strong>a fine of &#8364;200 million to Temu under the Digital Services Act (DSA)</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The company failed to diligently identify, analyse, and assess the systemic risks of illegal products being offered on its platform and the resulting harm to consumers in the European Union.&#8221; </em></p></li><li><p>&#8220;<em>Temu has until 28 August 2026 to submit an action plan to the Commission, as required by Article 75 of the DSA.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>Pope Leo XIV</strong> <a href="https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html">released</a> <strong>his first encyclical letter, titled &#8220;Magnifica Humanitas&#8221;</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong></em>The core message: AI is &#8220;above all else a tool&#8221; and it must serve human dignity rather than undermining it. The encyclical draws a direct line from Pope Leo XIII&#8217;s &#8220;Rerum Novarum&#8221;, which addressed the rights of workers during the Industrial Revolution, to the challenges of today&#8217;s AI revolution. The encyclical also touches on sensitive topics around AI, such as criticism of transhumanism, the concentration of technological power in private hands, and the use of AI as a weapon. <em>(For the key messages of the encyclical, please see my <a href="https://gdpr.blog.hu/2026/05/27/magnifica_humanitas_pope_leo_xiv_s_first_encyclical_on_the_safeguarding_the_human_person_in_the_time">blog post</a>.) </em></p></li></ul></li><li><p><strong>Amnesty International</strong> <a href="https://www.amnesty.org/en/documents/pol40/0996/2026/en/">published</a> a briefing titled <em><strong>&#8220;Unlawful by design: Exposing the human rights costs of generative AI&#8221;</strong></em>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This briefing examines how standalone generative AI systems, based on unlawful web scraping, are in conflict with international human rights law (IHRL) and standards through their design, development and deployment. While these technologies promise sophisticated automation and efficiency, they rely on data collection and model training practices that abuse privacy rights, enable discrimination, and threaten freedom of expression and thought. Amnesty International finds that standalone generative AI systems, based on unlawful web scraping, depend on mass invasions of privacy by design, and are fundamentally incompatible with IHRL. As such, Amnesty International is calling for a prohibition of such systems.</em></p></li></ul></li><li><p><strong>The Alan Turing Institute&#8217;s AI for Data-Driven Advantage (AIDA) </strong>research centre <a href="https://www.turing.ac.uk/news/publications/resilient-defence-ai-sustainable-and-operationally-effective-capabilities-design">published</a> a <strong>report to explores energy and other resource sustainability measures for competitive advantage and resilient Defence AI</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;AI sustainability here refers to long term viability of a capability, cost-effectiveness and the ability of the force to sustain security of supply to the necessary resources, infrastructure and components. These considerations have dependencies on the changing climate and natural environment, and MoD AI policy on these issues will have effects on resource supply chains, so addressing the issues in this report could contribute to the MoD&#8217;s sustainability objectives. Designing, building and procuring sustainable Defence AI systems is vital if these new capabilities are to be effective in operations. The study finds that resource consumption and cooling requirements must be managed from conception through to deployment of AI capabilities. It is necessary that Defence integrate resilience and sustainability considerations throughout existing AI capability development and assurance processes. This can only go so far in Defence itself and coordination across government is needed since not all risks can be mitigated by MoD policy levers. End users&#8217; awareness of dependencies and risks to Defence AI resilience, energy alternatives, as well as contingency plans must be clear from the conception of AI systems for Defence.&#8221;</em></p></li></ul></li><li><p><strong>The World Economic Forum</strong> <a href="https://www.weforum.org/publications/ai-agents-in-action-a-playbook-for-trusted-adoption-authorization-and-scaling/">published</a> a report, <em>&#8220;<strong>AI Agents in Action: A Playbook for Trusted Adoption, Authorization and Scaling&#8221;</strong></em><strong>.</strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;As organizations increasingly adopt artificial intelligence (AI) agents, they face new challenges in defining the conditions under which these agents are authorized to act, and in ensuring this authority is enforced as systems evolve. Many agents in a portfolio may share the same foundational model, which can lead to systemic vulnerabilities across the entire agent estate, necessitating authorization and monitoring in each instance.&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d3?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d3?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d3?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Office of the Australian Information Commissioner</strong> <a href="https://www.oaic.gov.au/engage-with-us/research-and-training-resources/research/australian-community-attitudes-to-privacy-survey/australian-community-attitudes-to-privacy-survey2026">published</a> <em><strong>&#8220;Australian Community Attitudes to Privacy Survey of 2026&#8221;</strong></em>.  The OAIC surveyed 1,504 Australian adults in 2026. <em>(The key results are available <a href="https://www.oaic.gov.au/__data/assets/pdf_file/0022/264361/ACAPS-2026-Infographics.pdf">here</a> in the form of an infographics.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The study evidences that privacy remains important to Australians and concern is increasing. Many Australians feel they do not have meaningful control over how their personal information is collected, used and shared in practice. Trust is concentrated in health providers and government, and is very low in digital and data-driven sectors such as social media, AI companies and data brokers. Australians draw clear lines between necessary collection for service delivery, and practices they view as excessive, opaque or one-sided, particularly secondary uses such as targeted advertising based on sensitive data, trading or sale of personal information, and training AI systems. Strong support for deletion rights and for extending privacy obligations to currently exempt sectors points to an expectation that privacy protections should be practical, enforceable and matched to contemporary data practices&#8221;</em></p></li></ul></li><li><p><strong>The French Data Protection Authority (CNIL) and South Korea&#8217;s Data Protection Authority (PIPC) </strong><a href="https://www.cnil.fr/en/generative-ai-and-privacy-pipc-and-cnil-jointly-produced-poster">have produced</a> a poster <strong>explaining how to protect personal data when using generative AI services</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The two authorities have agreed to continue to strengthen international cooperation and policy collaboration, especially to protect children&#8217;s and adolescents&#8217; personal data in response to changes in the digital environment, including the rapid expansion of generative AI.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!2mA7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 424w, /__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 848w, /__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!2mA7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png" width="428" height="607" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:607,&quot;width&quot;:428,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117459,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/198225072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 424w, /__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 848w, /__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2mA7!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa19e67f-9ea3-4432-9ef3-31dcd25e5e0e_428x607.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>(Source: <a href="https://www.cnil.fr/en/generative-ai-and-privacy-pipc-and-cnil-jointly-produced-poster">CNIL</a>)</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>ENISA</strong> <a href="https://www.enisa.europa.eu/enisa-nis360-2026">published</a> its <strong>NIS360 report</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;This edition of the ENISA NIS360 report is the third to assess the cybersecurity maturity and criticality of all sectors of high criticality as identified under Annex I of the NIS2 directive. The assessment covers the entire ecosystem of a sector, where each sector is understood to comprise relevant actors (i.e., national authorities, entities, EU bodies) and applicable rules (EU legislation).&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Xbp7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 424w, /__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 848w, /__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Xbp7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png" width="915" height="530" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:530,&quot;width&quot;:915,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:115223,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/198225072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 424w, /__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 848w, /__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Xbp7!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287739c1-20f7-4395-bb09-8d66d354c42d_915x530.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>(Source: <a href="https://www.enisa.europa.eu/news/nis360-the-bigger-picture-on-maturity-and-criticality-of-nis-critical-sectors">ENISA</a>)</em></p></li></ul></li><li><p><strong>OECD</strong> <a href="https://www.oecd.org/en/publications/towards-international-coherence-of-cybersecurity-regulations_bd1f199a-en/full-report/component-7.html">published</a> a report titled <em>&#8220;<strong>Towards international coherence of cybersecurity regulations&#8221;</strong></em><strong>. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Efforts to address fragmentation in cybersecurity regulations are developing, with several initiatives emerging at national and regional levels. These initiatives reflect a growing recognition among policymakers, regulators and industry stakeholders of the need for greater coherence in the overall cybersecurity regulation landscape to reduce unnecessary compliance costs, facilitate cross-border operation and enhance cyber resilience.&#8221;</em></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d3?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d3?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><a href="https://link.springer.com/article/10.1186/s41239-026-00602-z">&#8220;</a><strong><a href="https://link.springer.com/article/10.1186/s41239-026-00602-z">Governing generative AI in higher education: a global Delphi study on policy and practice&#8221;</a></strong></em><strong> </strong>(authors: Crompton et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;As GenAI technologies become more pervasive in higher education (HE), scholars call for guidance on AI governance. To meet this need, a Delphi technique and collective writing was used in gathering expert perspectives from across 22 countries/locations and six continents. This resulted in the development of a HE GenAI policy/guidelines framework with eight core areas: (1) academic integrity, (2) ethical use and responsible use, (3) privacy and protection, (4) equitable access, (5) GenAI literacy, (6) integration strategy, (7) human oversight and accountability, and (8) institutional support and infrastructure. In addition, a six-part framework was developed to ensure that policies remain current and relevant: (1) creating a dedicated GenAI Committee, (2) conducting regularly scheduled policy reviews, (3) providing ongoing professional development and support, (4) communicating with all stakeholders, (5) evaluating the effectiveness and impact of GenAI, and 6) monitoring external developments. By providing a robust, eight-part framework for policy and guidelines, alongside a six-part mechanism for continued review, this study offers faculty, students, administrators, educational leaders, policymakers, and funders a responsible, adaptable, and consensus-driven blueprint for navigating the integration of GenAI in HE, ensuring that technological innovation serves pedagogical excellence.&#8221;</em></p></li></ul></li><li><p><em><strong><a href="https://arxiv.org/pdf/2605.24727">&#8220;Fundamental Limitation in Explaining AI&#8221;</a></strong></em> (authors: Suzuki and Wang)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;While large-scale models such as LLMs and diffusion models have achieved prac tical success, public institutions have emphasized the importance of explainability in AI. Existing methods for explaining AI, however, are not designed to provide completely faithful explanations of the behavior of large-scale AI systems. Al though a completely faithful and interpretable explanation of the behavior of an AI system might be useful for AI governance, it has not been known whether providing such an explanation is theoretically possible. In this paper, we mathe matically prove a fundamental quadrilemma in explaining AI, stating that AI and its explanation cannot satisfy the following four conditions simultaneously: 1) the complexity of the operation environment, 2) the goodness of the AI&#8217;s performance, 3) the interpretability of the AI&#8217;s explanation, and 4) the complete faithfulness of the AI&#8217;s explanation. This quadrilemma suggests that, in most applications where we cannot change the environment or sacrifice good AI performance and an inter pretable explanation, we should give up complete faithfulness of explanations and should instead aim to explain only the parts that are important for applications. As a consequence, the quadrilemma implies that AI governance should be designed on the premise that the faithfulness of AI explanations is always incomplete.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Anthropic</strong> <a href="https://www.anthropic.com/news/claude-opus-4-8">launched</a> <strong>Opus 4.8</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Opus 4.8 launches alongside several new features. Users on claude.ai now have control over the amount of effort Claude puts into a task. Claude Code has a new &#8220;dynamic workflows&#8221; feature that allows it to tackle very large-scale problems. And fast mode for Opus 4.8&#8212;where the model can work at 2.5&#215; the speed&#8212;is now three times cheaper than it was for previous models.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!sQv4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 424w, /__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 848w, /__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_webp, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!sQv4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png" width="1266" height="674" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:674,&quot;width&quot;:1266,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:194635,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://datalawgy.substack.com/i/198225072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_424, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 424w, /__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_848, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 848w, /__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_1272, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sQv4!, /__u/datalawgy.substack.com/w_1456, /__u/datalawgy.substack.com/c_limit, /__u/datalawgy.substack.com/f_auto, /__u/datalawgy.substack.com/q_auto:good, /__u/datalawgy.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd3d5127-71a5-4ddf-b080-236ba7bebb7d_1266x674.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li></ul><p><em>(Source: <a href="https://www.anthropic.com/news/claude-opus-4-8">Anthropic</a>)</em></p></li><li><p><strong>The Federal Ministry for Digitalization and State Modernization of Germany</strong> <strong><a href="https://www.telekom.com/en/media/media-information/archive/telekom-to-build-sovereign-ai-platform-for-the-german-federal-government-1105278">awarded</a> Deutsche Telekom and SAP </strong>first place in tender <strong>for development of a sovereign AI platform. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The AI platform is a key building block of the so-called &#8220;<a href="https://www.telekom.com/en/company/details/simply-explained-what-is-the-germany-stack-1101884">Germany Stack</a>&#8221; &#8212; a shared digital infrastructure for the federal government, states, and municipalities. The goal is for public authorities to build on common technical standards and platforms in the future instead of developing numerous standalone solutions. This is intended to make public administration more modern, secure, and efficient.&#8221;</em></p></li></ul></li><li><p><strong>Blue Origin rocket <a href="https://www.theguardian.com/science/2026/may/29/blue-origin-rocket-explodes">exploded</a> during test. </strong>(The Guardian)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Nasa&#8217;s plans to build a lunar base and return humans to the moon in the next two years, were thrown into jeopardy after a New Glenn rocket from Jeff Bezos&#8217;s Blue Origin company exploded during a test in Florida. [&#8230;] Jared Isaacman, the Nasa administrator, <a href="https://x.com/NASAAdmin/status/2060186268772835475">posted to X</a> that a full evaluation of that timeline would be conducted after the explosion, which Blue Origin described as &#8220;<a href="https://x.com/blueorigin/status/2060172114796204539">an anomaly</a>&#8221;.&#8221;</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is new in data, technology & digital laws? - A weekly overview]]></title><description><![CDATA[Week 21]]></description><link>https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d5</link><guid isPermaLink="false">https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d5</guid><pubDate>Fri, 22 May 2026 15:02:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lD-4!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35fda972-f051-4516-b01b-eac800daf230_584x584.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this weekly roundup, I compile the most important and interesting news from the past week related to data protection, AI regulation, cybersecurity, technology, and digital law. I also report on the most important corporate news in technology and digital sectors.</p><p><strong>A) Regulatory developments</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The State Council of China</strong> <a href="https://www.scmp.com/news/china/politics/article/3353834/what-do-chinas-plans-comprehensive-new-ai-law-mean-future-technology">has outlined</a> its plans to &#8216;accelerate comprehensive legislation for the sound development&#8217; of AI. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;It said the government would move faster to refine legislation concerning the protection and regulation of data, computing power, algorithms, property rights, cybersecurity and supply chains.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p>In a <strong>UK Information Commissioner&#8217;s Office (ICO)</strong> <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/our-advice-to-government-on-potential-changes-to-online-advertising-rules/">blog post</a>, Executive Director Regulatory Risk and Innovation William Malcolm offers <strong>recommendations to the government on potential changes to regulation 6 under the Privacy and Electronic Communications Regulations (PECR)</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Regulation 6, alongside the UK GDPR, governs the use of storage and access technologies such as cookies, scripts and tags for the purposes of online advertising. Within the current framework, most commercially viable online advertising requires consent whenever information is stored on, or accessed from, a user&#8217;s device, even where the risks to people&#8217;s privacy are relatively low. To address this challenge, we analysed a range of online advertising activities and considered which ones pose a lower risk to people&#8217;s privacy and could therefore be delivered without regulation 6 consent.&#8221;</em></p></li><li><p><em>&#8220;Our work shows how regulation 6 could be amended to allow certain low risk forms of online advertising to operate without consent, while continuing to require consent for advertising that involves intrusive tracking and profiling people over time and across services.&#8221;</em></p></li><li><p><em>&#8220;This reflects our assessment that privacy risks are lower where advertising is based on the context of the content being viewed, rather than information about a person&#8217;s past online activity. Our user research indicates that this approach is closely aligned with people&#8217;s expectations and could provide a viable alternative to behavioural advertising for online services whose users don&#8217;t consent to more intrusive tracking.&#8221;</em></p></li><li><p>The <strong>cost-benefit analysis</strong> presented by the ICO is available <a href="https://ico.org.uk/media2/icslg2mm/20260421-cba-for-dsit-on-changes-to-regulation-6-pecr-for-online-advertising.pdf">here</a>. </p></li></ul></li></ul><p><strong>3) Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>The German Data Governance Act</strong> (<a href="https://www.recht.bund.de/bgbl/1/2026/141/VO.html">&#8220;Daten-Governance-Gesetzes&#8221;</a>, DGG) <strong><a href="https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilungen/DE/2026/20260519_DGA.html">entered into force</a></strong> and the German Federal Network Agency took over as the national authority responsible for enforcing the requirements for data brokerage services and data altruistic organisations in Germany. </p><ul><li><p><em><strong>Why does this matter? </strong>This act implements the European Data Governance Act (DGA) in Germany.</em></p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>B) Enforcement actions </strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The Texas Attor&#173;ney Gen&#173;er&#173;al</strong> <a href="https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-launches-investigation-meta-glasses-protect-texans-privacy-unlawful">launch&#173;ed</a> <strong>inves&#173;ti&#173;ga&#173;tion into Meta AI Glasses </strong>over concerns regarding privacy representations and the capabilities of the glasses to expose Texans&#8217; private data, recordings, and facial geometry.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Although Meta advertises its glasses as &#8220;designed for privacy&#8221; and claims that it takes steps to protect private and key identifiable information, serious concerns have arisen. Individuals at Meta&#8217;s subcontractor Sama, located in Kenya, access consumers private information despite Meta&#8217;s privacy representations. Sama&#8217;s data annotators have claimed that they have access to video material of users&#8217; private moments, such as bathroom visits and other intimate moments. Although employees claim that faces that appear in annotated data are automatically blurred, one employee noted that that is not always the case.&#8221;</em></p></li><li><p><em>&#8220;In addition to these concerns, reporting from the New York Times indicates that Meta plans to bring facial recognition technology to the Meta Glasses. Internally code-named &#8220;Name Tag,&#8221; this feature would allow Meta to collect unsuspecting individuals&#8217; facial geometry from Meta Glasses&#8217; built-in, inconspicuous cameras.&#8221;</em></p></li></ul></li></ul><p><strong>2) Data protection</strong></p><ul><li><p><strong>The Federal Administrative Court of Austria</strong> <a href="https://noyb.eu/en/noyb-success-orfat-must-correct-misleading-cookie-banner">has confirmed</a> that <strong>ORF&#8217;s cookie banner does not comply with the GDPR</strong>, as <strong>highlighting the &#8220;Accept&#8221; button in colour is misleading for users</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In its decision of October 2024, the Austrian Data Protection Authority agreed with the substance of noyb&#8217;s complaint and ordered the ORF to place &#8220;Reject&#8221; and &#8220;Accept&#8221; buttons of equal prominence on its cookie banner. At that point, ORF had already added a &#8220;Reject&#8221; button, but had made it less prominent in colour than the &#8220;Accept&#8221; option. ORF subsequently lodged an appeal with the Federal Administrative Court (BVwG).&#8221;</em></p></li></ul></li><li><p>According to news reports, the <strong>Belgian Data Protection Authority</strong> <a href="https://www.brusselstimes.com/belgium/2135116/belgian-data-protection-authority-to-use-criminal-courts-to-enforce-regulations">will initiate</a> <strong>criminal proceedings for certain serious breaches of European data protection regulations</strong>. (The Brussels Times)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Chairman Koen Gorissen outlined plans to use alternative methods to enforce regulations. &#8220;From now on, we&#8217;ll refer specific cases to criminal courts. We&#8217;ve already filed a direct claim with a correctional court and may also consider criminal settlements via the public prosecutor&#8217;s office. Our priority is to put an end to problematic data processing,&#8221; Gorissen said.&#8221;</em></p></li></ul></li><li><p>According to <a href="https://www.euractiv.com/news/commission-mulls-privacy-complaint-linked-to-maga-report/">news reports</a>, <em>&#8220;<strong>the European Commission may file a complaint with privacy regulators</strong> <strong>on behalf of EU staff members whose data was leaked by a US House Judiciary report</strong> targeting the bloc&#8217;s Digital Services Act (DSA) as censorship.&#8221; </em>(Euronews)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The report revealed the names of nearly 30 EU officials and several members of civil society organisations who work on DSA enforcement by including unredacted email exchanges between EU staffers and tech companies such as Meta and Google. The publication of such personal data is &#8220;deeply concerning&#8221;, the Commission wrote, reiterating earlier remarks which pointed out that publishing unredacted information could potentially expose tech firms to &#8220;legal liability&#8221; under the bloc&#8217;s General Data Protection Regulation (GDPR), which is enforced by national authorities.&#8221;</em></p></li></ul></li></ul><p>3) <strong>Digital Policy, Cloud &amp; Cybersecurity</strong></p><ul><li><p><strong>Bureau Europ&#233;en des Unions de Consommateurs (BEUC*)</strong> <a href="https://www.beuc.eu/enforcement/sponsored-scammers#why-this-action">filed</a> <strong>a complaint against Meta, TikTok and Google</strong> <strong>with the European Commission and the competent national Digital Services Coordinators</strong> together with 29 members across 27 countries. <em>(*BEUC is the umbrella group for 42 independent consumer organisations from 31 countries.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Under the Digital Services Act (DSA), Meta, TikTok and Google are required to have effective mechanisms in place to fight fraudulent ads and reduce the risks to consumers. However, our evidence gathering shows that Meta, TikTok and Google not only fail to pro-actively remove fraudulent ads but also do little when notified about such scams.&#8221;</em></p></li><li><p><em>&#8220;The findings show that financial scams remain widespread on Meta, TikTok, and Google, and that platforms systematically fail to take effective corrective actions. <br>In total, we flagged 893 fraudulent ads across 13 countries that were active on either Meta, TikTok or Google.</em></p><p style="text-align: justify;"><em>In a nutshell, consumer groups found that:</em></p><ul><li><p style="text-align: justify;"><em>Meta rejected nearly 43% of the submitted ads.</em></p></li><li><p style="text-align: justify;"><em>TikTok only removed 21% of the submitted ads. In 37% of the cases, TikTok claimed that the ad was removed before they could review it.</em></p></li><li><p style="text-align: justify;"><em>Google removed 60% of the submitted ads.&#8221;</em></p></li></ul></li></ul></li><li><p><strong>The UK Office of Communications (Ofcom)</strong> <a href="https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/platforms-should-use-detection-technology-to-stop-spread-of-illegal-intimate-images-online-under-strengthened-ofcom-codes">has announced</a> that<strong> it is strengthening its Illegal Content Codes</strong> by introducing a new recommendation that tech firms use automated detection technology <strong>to reduce the spread of illegal intimate images online</strong>.  </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Given the urgent need to better protect women and girls online, we are now adding a recommendation to our codes that certain sites and apps expand their use of automated technology &#8211; known as &#8216;hash matching&#8217;&#8211; to detect illegal intimate images shared without consent, such as explicit deepfakes. Hash matching technology works by converting harmful images into digital fingerprints or &#8216;hashes&#8217;. These are then stored in a database and matched against further attempts to upload the same or similar versions of the image.&#8221;</em></p></li><li><p><em>&#8220;We are recommending that services use a hash database such as the market leader, <a href="https://stopncii.org/">StopNCII</a>.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>C) Opinions, guidelines, reports &amp; other publications</strong></p><p><strong>1) AI</strong></p><ul><li><p><strong>The European Commission</strong> finally <a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems">published</a> its long-awaited <strong>(draft) guidelines on the classification of high-risk AI systems under the AI Act</strong>. The guidelines are open for <strong>public consultation until 23 June 2026</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The aim of the guidelines to support providers and deployers of AI systems, as well as competent market surveillance authorities, in assessing whether an AI system should be classified as high-risk, thereby facilitating the uniform application and effective enforcement of the AI Act. The guidelines set out the European Commission&#8217;s interpretation of concepts relevant to high-risk classification and provide practical examples of AI systems that should or should not be classified as high-risk.&#8221;</em></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;f56fda21-00e3-4498-a93a-36535631200d&quot;,&quot;caption&quot;:&quot;The European Commission finally published its long-awaited (draft) guidelines on the classification of high-risk AI systems under the AI Act. The guidelines are open for public consultation until 23 June 2026.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Commission&#180;s Draft Guidelines on the Classification of High-Risk AI Systems&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:190153242,&quot;name&quot;:&quot;L&#225;szl&#243; P&#243;k&quot;,&quot;bio&quot;:&quot;Senior Privacy Manager | Data protection | AI &amp; Privacy &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b183c3a0-04e4-4eba-bd5d-9e0b44f0657e_509x509.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-20T07:45:56.451Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3SPH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13349515-84dc-4dfc-b06a-0f2727951f76_455x572.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://datalawgy.substack.com/p/commissions-draft-guidelines-on-the&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:198474724,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:3421089,&quot;publication_name&quot;:&quot;Datalawgy&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pwif!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63a13fa-da78-41a4-8c0f-ebf47ff4d6e7_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div></li></ul></li><li><p><strong>Three studies</strong> <a href="https://digital-strategy.ec.europa.eu/en/library/three-studies-various-aspects-article-5-ai-act">have been published</a> that <strong>analyse various aspects of the specific dispositions of Article 5 of the AI Act (prohibited practices)</strong>:</p><ul><li><p><em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/3a999ace-4829-11f1-8095-01aa75ed71a1/language-en">Report for the European Commission on Article 5(1)(a) &amp; (b) of the AI Act</a></strong></em></p><p><em>by Dr M.R. Leiser, looks harmful manipulation, deception and exploitation</em></p></li><li><p><em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/3a999ace-4829-11f1-8095-01aa75ed71a1/language-en">Study concerning the prohibitions of Article 5.1(c) (social scoring), Article 5.1(d) (predictive policing), Article 5.1(f) (emotion recognition), and of Article 5.1(g) (biometric categorisation), and the procedural requirements for the exceptions to the real-time remote biometric identification prohibition in the Articles 5.3, 5.4, 5.5, 5.6, 5.7 and 5.8 of the AI Act</a></strong> by E. J. Kindt, LL.M</em></p></li><li><p><em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/24b979fc-4829-11f1-8095-01aa75ed71a1/language-en">Guidance Study on Article 5(1)(h) prohibition and its three exceptions (Article 5(1)(h)(i)-(iii)), the procedural requirements laid down in Article 5(2), and the prohibition of Article 5(1)(e) of the AI Act</a></strong> by Catherine Jasserand, concentrates on real-time remote biometric identification and its 3 exceptions, as well as the procedural requirements for untargeted scraping of facial images.</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;These 3 studies aim to assist the Commission in clarifying different aspects of Article 5 of the Artificial Intelligence Act (AI Act).&#8221;</em></p></li></ul></li></ul></li><li><p><strong>Three studies</strong> have also been published by the Commission <strong>on technical solutions to mark and detect AI-generated content:</strong></p><ul><li><p><strong>Audio</strong>: <em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/4f7b8585-4829-11f1-8095-01aa75ed71a1/language-en">Technical Solutions for Marking and Detecting AI-generated Audio in the Context of Article 50 of the AI Act</a></strong></em><a href="https://op.europa.eu/en/publication-detail/-/publication/4f7b8585-4829-11f1-8095-01aa75ed71a1/language-en">,</a> by Xavier Serra, R. Oguz Araz, Roser Batlle Roca, Lauri Juvela, David L&#243;pez, and Mart&#237;n Rocamora.</p></li><li><p><strong>Image and video</strong>: <em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/8a256a7e-482a-11f1-8095-01aa75ed71a1/language-en">Study on EU AI Act Article 50: Technical solutions for marking AI-generated image and video content</a></strong></em><a href="https://op.europa.eu/en/publication-detail/-/publication/8a256a7e-482a-11f1-8095-01aa75ed71a1/language-en">,</a> by Mario Joachim Fritz.</p></li><li><p><strong>Text</strong>: <em><strong><a href="https://op.europa.eu/en/publication-detail/-/publication/6c981119-4829-11f1-8095-01aa75ed71a1/language-en">Technical solutions for marking and detecting AI generated text content in the context of Article 50(2) AI Act</a></strong></em> by Giovanni Puccetti.</p></li></ul></li><li><p><strong>Singapore</strong> <a href="https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf">released</a> <strong>Version 1.5 of its Model AI Governance Framework for Agentic AI</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;The Model AI Governance Framework (MGF) for Agentic AI gives organisations a structured overview of the risks of agentic AI and emerging best practices in managing these risks. If risks are properly managed, organisations can adopt agentic AI with greater confidence. The MGF is targeted at organisations looking to deploy agentic AI, whether by developing AI agents in-house or using third-party agentic solutions.&#8221;</em></p></li></ul></li><li><p><strong>The Cyber Security Agency of Singapore</strong> <a href="https://www.csa.gov.sg/news-events/press-releases/ai-agents--insights-from-the-singapore-government-and-google-sandbox-/">released</a> <strong>insights from its AI Agents Sandbox</strong>, led by Google.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Results showed strong potential for automation and citizen services, while highlighting risks in oversight, cybersecurity, privacy, and governance for future agentic AI systems.&#8221;</em></p></li></ul></li><li><p><strong>The European Parliamentary Research Service (EPRS)</strong> <a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)789299">published</a> a briefing about &#8220;<strong>The spread of AI companions and the challenges they generate&#8221;. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;AI companions are chatbots powered by large language models (LLMs) designed for personalised, emotionally engaging interactions. The popularity of AI companion platforms, such as Character.AI and Replika, has grown rapidly in recent years. These systems interact in ways that closely resemble human relationships, allowing users to customise their companions and develop strong emotional attachments. While some of the challenges they pose overlap with those associated with generic AI chatbots, AI companions raise additional concerns. Children are particularly vulnerable, with reports of exposure to sexualised conversations and prompts to engage in self-harm or suicide, highlighting the need for stronger safeguards. However, to date, few countries have put forward specific legislation for this. The EU has no specific laws for AI companions, although existing legislative frameworks like the AI Act, the Digital Services Act and the General Data Protection Regulation may apply.&#8221;</em></p></li></ul></li><li><p><strong>The EPRS</strong> also <a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_ATA(2026)789297">published</a> a brief summary about the topic of <strong>&#8220;AI image generation and the spread of online child sexual abuse material&#8221;</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Artificial intelligence (AI) is not a harmless technology: it can be misused by users to create illegal content. One major concern is the creation and dissemination of online child sexual abuse deepfakes. Recent reports have shown a significant increase in AI-generated child sexual abuse material (CSAM), raising questions about how to stop it. A new provision in the EU AI Act will forbid the generation of CSAM from 2 December 2026.&#8221;</em></p></li></ul></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d5?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d5?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d5?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p></div><p><strong>2) Data protection</strong></p><ul><li><p><strong>The  Office of the Australian Information Commissioner (OAIC)</strong> <a href="https://www.oaic.gov.au/__data/assets/pdf_file/0027/263925/ADM-Issues-Paper.pdf">issued</a> a draft  <strong>guidance on the automated decision-making (ADM) transparency obligation</strong>. </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;As Australian businesses and government agencies increase their adoption of artificial intelligence (AI), the ADM obligation will provide an important protection for the Australian community, which will be better equipped to know and understand how their lives are impacted by AI and ADM. The ADM obligation will improve integrity, accountability and trust at a moment of widespread technological change in the Australian economy and society. Businesses will be better able to build the trust and confidence of consumers and customers with greater openness and transparency, while in the public sector trust in government service delivery will be enhanced. A community that is better informed can participate more effectively in democratic processes and proactive release of such information enables individuals to understand why and how decisions affecting them are made.&#8221;</em></p></li></ul></li><li><p><strong>The UK Information Commissioner&#8217;s Office</strong> <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/one-month-to-go-what-businesses-need-to-know-to-meet-new-data-law/">issued</a> <strong>guidance on the application of UK Data (Use and Access) Act</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Businesses across the UK have one month from today to put a data protection complaints process in place, before new legal requirements come into force on 19 June 2026.&#8221;</em></p></li></ul></li><li><p><strong>The Deputy of the Spanish Data Protection Agency</strong>, Francisco P&#233;rez Bes, <a href="https://www.aepd.es/prensa-y-comunicacion/blog/tendencia-sancionadora-en-proteccion-de-datos-en-europa">published</a> a blog post about the <strong>sanctioning trend in data protection in Europe. </strong><em>(The blog post is in Spanish.)</em></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In view of these data, we can say that the breakdown itself shows a well-known, but often simplified, reality: sanctioning activity in Europe is profoundly heterogeneous. The comparison between countries such as Ireland &#8211; with very few sanctions, but of very high amounts &#8211; and others such as Slovakia or Spain &#8211; with a higher volume, but less average economic impact &#8211; reflects not so much discrepancies in punitive intensity, but structural differences in supervisory models.&#8221;</em></p></li></ul></li><li><p><strong>The French Data Protection Authority (CNIL)</strong> <a href="https://www.cnil.fr/fr/rapport-annuel-2025">published</a> its <strong>Annual Report for 2025. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In total, the CNIL carried out 323 inspections and issued 259 decisions, including 83 penalties for a total amount of nearly &#8364;487 million (collected by the Public Treasury). While two significant penalties explain this total amount, which is unprecedented for the institution, the CNIL has also imposed numerous fines on companies of all sizes and in all sectors of activity, in particular thanks to its simplified procedure introduced in 2022, which allows it to act more quickly in certain less complex cases.&#8221;</em></p></li></ul></li></ul><p><strong>3) Cybersecurity</strong></p><ul><li><p><strong>The FCA, Bank of England and Treasury</strong> <a href="https://www.fca.org.uk/news/statements/fca-boe-treasury-joint-statement-frontier-ai-models-cyber-resilience">issued</a> a <strong>joint statement on frontier AI models and cyber resilience</strong>.</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;In line with our <a href="https://www.fca.org.uk/publications/policy-statements/ps21-3-building-operational-resilience">operational resilience rules and expectations</a>, regulated firms and financial market infrastructures (FMIs) (referred to as 'firms'), need to take action to plan for and mitigate cybersecurity risks posed by frontier AI.&#8221;</em></p></li></ul></li><li><p><strong>The World Economic Forum</strong> <a href="https://www.weforum.org/publications/empowering-defenders-ai-for-cybersecurity/">published</a> a white paper titled <em>&#8220;<strong>Empowering Defenders: AI for Cybersecurity&#8221;</strong></em><strong>. </strong></p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;AI is transforming cybersecurity, but realizing its full value requires strategic deployment, robust governance and balanced human oversight. This white paper, Empowering Defenders: AI for Cybersecurity, offers practical guidance for organizations seeking to harness AI in their cybersecurity efforts.&#8221;</em></p></li></ul></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d5?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/datalawgy.substack.com/p/what-is-new-in-data-technology-and-8d5?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><div><hr></div><p><strong>D) Scientific papers in AI, data protection &amp; more</strong></p><ul><li><p><em><strong><a href="https://arxiv.org/pdf/2602.16800">&#8220;Large-scale online deanonymization with LLMs&#8221;</a></strong></em> (2026, authors: Lermen et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] In each setting, LLM-based methods substantially outperform classical baselines, achieving up to 68% recall at 90% precision compared to near 0% for the best non-LLM method. Our results show that the practical obscurity protecting pseudonymous users online no longer holds and that threat models for online privacy need to be reconsidered.&#8221;</em></p></li></ul></li><li><p><em><strong><a href="https://arxiv.org/pdf/2605.08545">&#8220;Log analysis is necessary for credible evaluation of AI agents&#8221;</a></strong></em> (2026, authors: Kirgis et al.)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;] In this paper, we (1) present a taxonomy of threats to credible evaluation documented through log analysis, and (2) develop a set of guiding principles for log analysis. We illustrate these principles on &#964;-Bench Airline, revealing that pass&#8743;5 performance was under-elicited by nearly 50% and surfacing deployment failure modes invisible to outcome metrics. We conclude with pragmatic recommendations to increase uptake of log analysis, directed at diverse stakeholders including benchmark creators, model developers, independent evaluators, and deployers.&#8221;</em></p></li></ul></li><li><p><em><a href="https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2023.1219945/full">&#8220;</a><strong><a href="https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2023.1219945/full">Handwriting but not typewriting leads to widespread brain connectivity: a high-density EEG study with implications for the classroom&#8221;</a> </strong></em>(2024, authors: Van der Weel and Van der Meer)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;[&#8230;]Our findings suggest that the spatiotemporal pattern from visual and proprioceptive information obtained through the precisely controlled hand movements when using a pen, contribute extensively to the brain&#8217;s connectivity patterns that promote learning. We urge that children, from an early age, must be exposed to handwriting activities in school to establish the neuronal connectivity patterns that provide the brain with optimal conditions for learning. Although it is vital to maintain handwriting practice at school, it is also important to keep up with continuously developing technological advances. Therefore, both teachers and students should be aware of which practice has the best learning effect in what context, for example when taking lecture notes or when writing an essay.&#8221;</em></p></li></ul></li></ul><div><hr></div><p><strong>E) Data, Technology &amp; Company news</strong></p><ul><li><p><strong>Anthropic</strong> <a href="https://www.cnbc.com/2026/05/19/anthropic-hires-openai-cofounder-andrej-karpathy-former-tesla-ai-lead.html">hired</a> OpenAI co-founder <strong>Andrej Karpathy</strong>, former Tesla AI leader. (CNBC)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Anthropic said Karpathy starts this week and will be building a team focused on using Claude to accelerate pretraining research, which helps the company&#8217;s models acquire their core knowledge and capabilities.&#8221;</em></p></li></ul></li><li><p><strong>OpenAI</strong> <a href="https://www.reuters.com/business/openai-seals-deal-malta-give-all-maltese-access-chatgpt-plus-2026-05-16/">seald a deal</a> in Malta to <strong>give all Maltese access to ChatGPT Plus</strong>. (Reuters)</p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Malta is the first country to launch such a programme.&#8221;</em></p></li></ul></li><li><p><strong>OpenAI</strong> <a href="https://openai.com/index/personal-finance-chatgpt/">released</a> a preview of <strong>a new personal finance experience in ChatGPT to Pro users in the U.S.</strong> </p><ul><li><p><em><strong>Why does this matter? </strong>&#8220;Now you can securely connect your financial accounts, see a dashboard of where your money is going, and ask ChatGPT questions grounded in your financial context &#8211; all while staying in control of your data. We&#8217;re starting with a preview to a smaller group so we can learn from real-world use, improve the experience, and expand thoughtfully.&#8221;</em></p></li><li><p>&#8220;The feature also includes a partnership with financial software company Intuit, in which users will be able to schedule sessions with local tax experts all within ChatGPT.&#8221;</p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://datalawgy.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Datalawgy! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>