BriefBlip Weekly · by Blue Note Logic
BriefBlip Weekly · by Blue Note Logic

The EU AI Act Weekly

24–30 August 2026 · 25 changes · 2 obligations

Every item below links to the source document we read it from — a citation, not model memory.

What changed
Documents we already monitor that moved this week.
Cybersecurity Act (2019/881) [EN]
EU · high · detected 2026-08-30
View source →
Council of Europe — Framework Convention on AI, Human Rights, Democracy and Rule of Law (CETS 225, 2024)
EU · high · detected 2026-08-30
The entire text of the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law—along with the European Commission's proposal for a Council Decision to conclude it on behalf of the EU—has been removed and replaced with generic Official Journal navigation/indexing content (dates and series references). This means the substantive legal framework establishing AI governance principles related to human rights, democracy, and the rule of law is no longer present in this document. Organizations that would have been subject to the Convention's obligations no longer have access to its provisions through this instrument.
View source →
NIS2 Directive (2022/2555) [EN]
EU · high · detected 2026-08-30
```json
{"summary": "The entire substantive text of the NIS2 Directive (EU 2022/2555), including its recitals, scope, cybersecurity requirements, and obligations for essential and important entities, has been removed and replaced with generic Official Journal navigation/indexing content. If taken at face value, this means the comprehensive EU cybersecurity framework—covering risk management, incident reporting, supervision, and enforcement—no longer exists in this document. Organizations previously subject to NIS2 would face the elimination of all mandated cybersecurity obligations, though this diff likely reflects a document structure or source artifact
View source →
Digital Operational Resilience Act (2022/2554) — AI in Financial Services
EU · high · detected 2026-08-30
The entire substantive text of Regulation (EU) 2022/2554 (DORA), including all recitals, provisions, and requirements on digital operational resilience for the financial sector, has been removed and replaced with a generic Official Journal navigation/index page listing recent OJ publication dates and series. This means the full regulatory instrument is no longer present at this location. For organizations subject to DORA, the disappearance of the regulation's text from this source would eliminate access to the specific obligations governing ICT risk management, incident reporting, third-party oversight, and resilience testing.
View source →
E-Commerce Directive (2000/31/EC) — Liability Framework for AI Services
EU · high · detected 2026-08-30
View source →
CJEU — Russmedia (C-492/23): Platform Controller for User-Generated Sensitive Data (2025)
EU · high · detected 2026-08-29
```json
{"summary": "The entire text of the CJEU Grand Chamber judgment in Russmedia (C-492/23)—which addressed whether online marketplace operators qualify as GDPR 'controllers' for user-generated personal data—has been removed from this EUR-Lex page and replaced with generic Official Journal navigation and listing content. This appears
View source →
Toys Safety Directive (2009/48/EC) — Safety of Connected Toys
EU · high · detected 2026-08-29
The substantive legal text of Directive 2009/48/EC on toy safety—including its recitals, safety requirements, references to harmonised standards, and framework for marketing toys in the EU—has been entirely removed. In its place, only generic Official Journal navigation/indexing references (dates and series labels) remain. This effectively strips the document of its regulatory content, meaning organizations can no longer rely on this source for the toy safety obligations previously established.
View source →
CJEU — La Quadrature du Net (C-511/18): Bulk Data Retention (2020)
EU · high · detected 2026-08-29
```json
{"summary": "The entire text of the CJEU's La Quadrature du Net judgment—which addressed the legality of bulk data retention by electronic communications providers—has been removed from this document and replaced with generic EUR-Lex Official Journal navigation and listing content. This
View source →
CJEU — Schrems II (C-311/18): Privacy Shield Invalidated (2020)
EU · high · detected 2026-08-29
The full text of the Schrems II judgment (C-311/18), which invalidated the EU-US Privacy Shield and established key requirements for transatlantic data transfers, has been entirely removed and replaced with generic EUR-Lex Official Journal navigation and listing content. This means the substantive legal ruling and its detailed reasoning are no longer present at this document location. Organizations that relied on this page for the judgment's guidance on data transfer mechanisms and supplementary safeguards would lose direct access to that content here.
View source →
CJEU — Google Spain v AEPD (C-131/12): Right to Be Forgotten (2014)
EU · high · detected 2026-08-29
```json
{"summary": "The full text of the
View source →
Regulatory document
high · detected 2026-08-29
The entire EUR-Lex page for Regulation (EU) 2024/1787—the EU Methane Emissions Regulation for the energy sector—has been removed, including all navigation, metadata, multilingual versions, and document content. In its place, only generic Official Journal (OJ) date and series listing entries remain. This means the full regulatory text and its associated requirements are no longer accessible at this source, though the regulation itself remains in force.
View source →
Regulatory document
high · detected 2026-08-29
The entire content and metadata of Regulation (EU) 2023/1804 (the Alternative Fuels Infrastructure Regulation, AFIR) has been removed and replaced with generic Official Journal listing/navigation content. This means the substantive regulatory text governing the deployment of alternative fuels infrastructure across the EU is no longer present in this document. Organizations that relied on this document for AFIR compliance requirements, obligations, and standards would lose access to the applicable legal framework.
View source →
Regulatory document
high · detected 2026-08-29
```json
{"summary": "The entire EUR-Lex page content for Regulation (EU) 2023/2405 (ReFuelEU Aviation), including the full regulation text, navigation elements, and multilingual references, has been removed and replaced with brief references to several Official Journal Series C entries dated August 25–29, 2026. This suggests the regulation's standalone presentation has been taken down or superseded, with the replacement pointing only to OJ Series C notices (which typically contain informational or preparatory notices rather than binding legislative acts). Organizations in the aviation and sustainable fuel sectors that rely on ReFuelEU Aviation's SAF blending mandates and reporting obligations would face significant uncertainty about the regulation's current
View source →
Regulatory document
high · detected 2026-08-29
View source →
Regulatory document
high · detected 2026-08-29
View source →
Market Surveillance Regulation (2019/1020) — Enforcement of AI Product Safety
EU · high · detected 2026-08-26
The provided text shows a significant removal of content related to the original Market Surveillance Regulation (EU) 2019/1020, including its legislative details and introductory recitals. The added text introduces a new section on how to verify the authenticity of the Official Journal, along with specific dates and series information for future publications. This suggests a shift in focus from the original regulation's scope to the procedural aspects of official publication.
View source →
Brazil — ANPD: Autoridade Nacional de Proteção de Dados (National Data Protection Authority portal)
BR · high · detected 2026-08-26
The ANPD has fined TikTok R$153.7 million for data protection failures concerning children and adolescents. Additionally, the ANPD is evaluating how digital platforms prevent criminal content and protect children and women online. This signifies increased enforcement and scrutiny regarding child data protection and online safety.
View source →
EU AI Act (2024/1689) — Phased Application Timeline
EU · high · detected 2026-08-26
The provided text indicates a significant update to the EUR-Lex entry for Regulation (EU) 2024/1689, the EU AI Act. The changes involve the addition of multiple 'Official Journal' (OJ) entries with specific dates in August 2026, suggesting a phased application or amendment timeline is being detailed. This matters to organizations as it clarifies when specific provisions of the AI Act will come into effect, requiring them to align their compliance strategies with these dates.
View source →
Regulation (EU) 2024/1689 — Artificial Intelligence Act
EU · high · detected 2026-08-26
The provided diff indicates a significant update to the official journal publication details for Regulation (EU) 2024/1689, the Artificial Intelligence Act. It appears to be a consolidation or republication of the text with new dates associated with its publication in the Official Journal (OJ) and its respective series (L and C). This matters because it signifies the final, official version of the AI Act is being published, and organizations need to be aware of the precise dates for compliance and implementation timelines.
View source →
AI Liability Directive — Proposal (COM/2022/496) [EN]
EU · high · detected 2026-08-26
The provided text indicates a significant change in the document's structure, moving from an explanatory memorandum detailing the rationale and context for an AI Liability Directive to a series of entries related to the Official Journal's publication dates and series. This suggests the transition from a proposal stage to the formal publication of the directive.
View source →
Product Liability Directive (2024/2853) [EN]
EU · high · detected 2026-08-26
This update indicates the repeal and replacement of Council Directive 85/374/EEC with a new Directive (EU) 2024/2853. The new directive aims to modernize product liability rules to address new technologies like AI, circular economy models, and global supply chains, while also clarifying concepts and ensuring a level playing field. It explicitly states that no-fault liability will apply to all movables, including software, and prohibits Member States from deviating from the directive's provisions.
View source →
EDPB — Greek DPA Fines Clearview AI €20M for Biometric Data Violations (2022)
GR · high · detected 2026-08-25
The Greek Data Protection Authority (DPA) has fined Clearview AI €20 million for violating biometric data regulations. This significant fine underscores the strict enforcement of GDPR provisions concerning the processing of sensitive biometric data and highlights the substantial financial penalties organizations face for non-compliance.
View source →
South Korea — Personal Information Protection Act (PIPA) — Personal Information Protection Commission (PIPC)
KR · medium · detected 2026-08-26
The document has been updated to reflect a public consultation period for the PIPC's Privacy Protection Framework Reform, specifically tailored for the AI era. This indicates a proactive regulatory approach to address emerging technologies and their impact on personal data protection, signaling potential future changes in compliance requirements for organizations operating in South Korea.
View source →
UK — Age Appropriate Design Code (Children's Code, ICO, 2020)
GB · medium · detected 2026-08-26
The document has been updated to reflect a later progress update date (August 2026) and explicitly includes guidance for online TV and radio services. This clarifies that these services may fall under the Children's Code if provided upon individual request, impacting providers of such content.
View source →
EU AI Act (2024/1689) [EN]
EU · medium · detected 2026-08-26
The document has been updated to reflect the final publication details of the EU AI Act in the Official Journal, including its publication date and series. This change signifies the formal enactment and upcoming enforcement of the regulation.
View source →
Obligations in focus
Active obligations attached to the documents in this issue — not necessarily extracted this week.
providers of general-purpose AI models — Bring general-purpose AI models placed on the market before 2 August 2025 into compliance with the Act.
Deadline: 2 August 2027
EU AI Act (2024/1689) — Phased Application Timeline
View source →
organisations that place AI on the EU market as, or within, regulated products — Ensure full high-risk conformity — risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, and conformity assessment — is in place.
Deadline: by 2 August 2027
EU AI Act (2024/1689) — Phased Application Timeline
View source →

Read this issue on the web: https://briefblip.com/weekly/2026-W35

BriefBlip is a Blue Note Logic Inc product. Brief anything, in a blip.

← All issues