Hello,
the Digital Policy Alert added new events. Please find a brief overview below.
Best regards,
the DPA Team
Aug. 2, 2026
| Law Implementation | Data Governance
On 2 August 2026, the regulation laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act), including data protection measures for "high-risk" AI systems prescribed by Annex III of the Act, enters into force. The AI Act is based on a risk-based management approach and introduces data protection obligations depending on the level of risk associated with the AI system. The Act includes a ban on cognitive behavioural manipulation, the untargeted scrapping of facial images from the internet, social scoring, biometric categorisation to infer sensitive data, such as sexual orientation or religious beliefs, and some cases of predictive policing for individuals. Further, the Act establishes certain data governance practices for training and testing data, such as the fact that they should be relevant, accurate, and sufficiently representative. The Act is generally implemented on 2 August 2026, though some sections are subject to variable implementation periods. For high-risk AI systems according to Article 6(1), the data protection measures only enter into effect from 2 August 2027.
Aug. 2, 2026
| Law Implementation | Authorisation, Registration And Licensing
On 2 August 2026, the regulation laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act) comes into effect for "high-risk AI systems" referred to in Annex III of the Act. The Act includes conformity assessment and business registration requirements for "high-risk AI systems", contingent upon meeting a set of requirements and obligations for entry into the EU market. The Act includes obligations related to data quality and technical documentation with the aim of ensuring that small and medium-sized enterprises are able to demonstrate compliance with the requirements for their high-risk AI systems. Furthermore, the Act empowers individuals by allowing them to file complaints with relevant market surveillance authorities regarding non-compliance with the AI Act. In terms of enforcement, the AI Act introduces fines for violations, calculated as a percentage of the offending company's global annual turnover. The fines are tiered, EUR 35 million or 7% for prohibited AI applications, EUR 15 million or 3% for violations of the Act's obligations, and EUR 7.5 million or 1.5% for supplying incorrect information. For high-risk AI systems as defined by Article 6(1), the Act only applies from 2 August 2027.
Aug. 2, 2026
| Law Implementation | Data Governance
On 2 August 2026, the regulation laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act) comes into effect for "high-risk AI systems" referred to in Annex III of the Act. The Act specifies that high-risk AI systems must be designed in a way that achieves an appropriate level of accuracy, robustness and cybersecurity. High-risk AI systems should further be designed so that they are resilient to third-party attempts to alter their use or performance, for example, through manipulation of datasets, inputs designed to trigger mistakes, model flaws, model poisoning, and confidentiality attacks. The Act is generally implemented on 2 August 2026 after the lapse of the grace period, though some sections are subject to variable implementation periods. For high-risk AI systems as defined by Article 6(1), the Act only applies from 2 August 2027.