BriefBlip Weekly · by Blue Note Logic
The EU AI Act Weekly
31 August – 6 September 2026 · 25 changes · 8 new documents · 2 obligations
Every item below links to the source document we read it from — a citation, not model memory.
What changed Documents we already monitor that moved this week. |
eIDAS 2 — Digital Identity (2024/1183) [EN] EU · high · detected 2026-09-06 This change introduces Regulation (EU) 2024/1183, which amends Regulation (EU) No 910/2014 to establish the European Digital Identity Framework. This new framework aims to provide Union citizens and residents with a voluntary, user-controlled digital identity for accessing services across the EU, enhancing digital integration and security. View source → |
Cybersecurity Act (2019/881) [EN] EU · high · detected 2026-09-06 This change replaces placeholder text about verifying the Official Journal with the actual text of Regulation (EU) 2019/881, also known as the Cybersecurity Act. This regulation establishes the European Union Agency for Cybersecurity (ENISA) and sets up a framework for ICT cybersecurity certification, aiming to improve the security and resilience of digital products, services, and networks across the EU. View source → |
Council of Europe — Framework Convention on AI, Human Rights, Democracy and Rule of Law (CETS 225, 2024) EU · high · detected 2026-09-06 This change introduces the full text of the Council of Europe's Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law, along with the European Commission's proposal for its conclusion. This signifies the formal EU process to adopt the convention, establishing a legal framework for AI that upholds fundamental rights and democratic principles. View source → |
EU4Health Programme Regulation (2021/522) — Digital Health and AI EU · high · detected 2026-09-06 This change introduces the full text of Regulation (EU) 2021/522, establishing the EU4Health Programme for 2021-2027. It outlines the Programme's objectives, legal basis, and the rationale behind its creation, emphasizing Union-level added value in health actions, cross-border threats, and internal market improvements. This matters to organizations as it defines the scope and funding priorities for health initiatives within the EU. View source → |
NIS2 Directive (2022/2555) [EN] EU · high · detected 2026-09-06 This change adds the full text of the NIS2 Directive (EU) 2022/2555, including its official publication details and recitals. It replaces previous lines that were related to verifying the authenticity of the Official Journal and specific publication dates. The addition of the directive's text signifies the formal enactment and publication of the new cybersecurity regulations. View source → |
Digital Operational Resilience Act (2022/2554) — AI in Financial Services EU · high · detected 2026-09-06 This change introduces the full text of Regulation (EU) 2022/2554, also known as the Digital Operational Resilience Act (DORA). It establishes a comprehensive framework for digital operational resilience in the financial sector, addressing ICT risks and enhancing the sector's ability to withstand, respond to, and recover from ICT disruptions. This is crucial for maintaining financial stability and protecting consumers in an increasingly digitalized financial landscape. View source → |
E-Commerce Directive (2000/31/EC) — Liability Framework for AI Services EU · high · detected 2026-09-06 This change introduces the full text of the E-Commerce Directive (2000/31/EC) into the document. It establishes a legal framework for information society services, including electronic commerce, within the EU's internal market. The directive aims to remove legal obstacles and ensure legal certainty for cross-border services, promoting economic growth and consumer protection. View source → |
Digital Markets Act (2022/1925) [EN] EU · high · detected 2026-09-06 This change introduces the official text of the Digital Markets Act (Regulation (EU) 2022/1925) into the document. It replaces placeholder information about the Official Journal with the full legislative text, including its purpose, legal basis, and introductory recitals explaining the rationale for regulating large digital platforms ('gatekeepers'). This matters because it signifies the formal publication and entry into force of the regulation, which will impose new obligations on designated gatekeepers. View source → |
CJEU — Russmedia (C-492/23): Platform Controller for User-Generated Sensitive Data (2025) EU · high · detected 2026-09-06 This update adds the full text of a CJEU judgment concerning the definition of 'controller' under GDPR for online marketplace operators who publish user-generated personal data. It clarifies the responsibility of such platforms for data processing activities, particularly concerning sensitive data, which is crucial for understanding their compliance obligations. View source → |
Toys Safety Directive (2009/48/EC) — Safety of Connected Toys EU · high · detected 2026-09-06 This change replaces placeholder text related to the Official Journal's publication dates with the actual introductory text of Directive 2009/48/EC on the safety of toys. It includes the directive's title, date, legal basis, and recitals, establishing the foundational legal text for toy safety in the EU. This matters to organizations as it signifies the formal adoption and publication of the directive, making its requirements legally binding. View source → |
CJEU — Planet49 (C-673/17): Cookie Consent Must Be Active (2019) EU · high · detected 2026-09-06 The document now includes the full text of the CJEU's judgment in the Planet49 case, which clarifies cookie consent requirements under EU law. It specifies that consent must be active and unambiguous, meaning pre-ticked boxes are insufficient. This impacts organizations using cookies for tracking or advertising, requiring them to obtain explicit user consent before placing cookies. View source → |
Regulatory document high · detected 2026-09-05 This update replaces previous references to specific dates and series of the Official Journal with the full text and metadata for Regulation (EU) 2024/1787. This regulation, concerning the reduction of methane emissions in the energy sector and amending a previous regulation, is now officially published and accessible. Organizations in the energy sector must now consult this specific regulation for compliance requirements regarding methane emissions. View source → |
Regulatory document high · detected 2026-09-05 The document has been updated to reflect Regulation (EU) 2023/1804 concerning the deployment of alternative fuels infrastructure, which repeals Directive 2014/94/EU. This change is significant for organizations involved in the energy and transportation sectors as it introduces new requirements and potentially replaces existing obligations related to the provision and use of alternative fuels. View source → |
Regulatory document high · detected 2026-09-05 The document has been updated to reflect the official publication of Regulation (EU) 2023/2405, also known as ReFuelEU Aviation, in the Official Journal. This regulation aims to ensure a level playing field for sustainable air transport. The changes indicate the official entry into force and availability of the consolidated version of this regulation. View source → |
Regulatory document high · detected 2026-09-05 The document has been updated to reflect the inclusion of Regulation (EU) 2023/1805 concerning the use of renewable and low-carbon fuels in maritime transport. This regulation amends Directive 2009/16/EC and is now officially published in the Official Journal (OJ L 234, 22.9.2023, pp. 48–100). Organizations in the maritime sector must now comply with the new requirements regarding fuel usage. View source → |
Regulatory document high · detected 2026-09-05 The document has been updated to reflect the consolidated text of Regulation (EU) 2019/631, which sets CO2 emission performance standards for new passenger cars and light commercial vehicles. This update includes a new effective date of January 1, 2024, and provides access to the current version of the regulation as of July 9, 2025. Organizations subject to these emission standards will need to ensure their compliance with the latest consolidated version. View source → |
EU AI Act (2024/1689) — Phased Application Timeline EU · high · detected 2026-09-03 The document has been updated to reflect the official publication of the EU AI Act (Regulation (EU) 2024/1689) in the Official Journal of the European Union. This change signifies the formal commencement of the regulation and its phased application timeline, which organizations must now adhere to. View source → |
Regulation (EU) 2024/1689 — Artificial Intelligence Act EU · high · detected 2026-09-03 The document has been updated to reflect the official publication of Regulation (EU) 2024/1689, also known as the Artificial Intelligence Act. This change signifies the formal enactment of the AI Act, establishing harmonized rules for artificial intelligence across the EU and amending several existing regulations and directives. Organizations must now prepare for compliance with these new AI regulations. View source → |
EU AI Act (2024/1689) [EN] EU · high · detected 2026-09-03 This change introduces the full text of the EU AI Act (Regulation (EU) 2024/1689) into the document. It replaces placeholder information about the Official Journal with the official publication details, including the date, title, and legal basis for the regulation. This signifies the formal enactment of the AI Act, establishing harmonized rules for AI systems across the Union. View source → |
Communication on Digital Transformation of Health and Care (COM/2018/233) EU · high · detected 2026-09-03 This change introduces the full text of a European Commission Communication regarding the digital transformation of health and care. It outlines the challenges facing European health systems, such as aging populations and workforce shortages, and highlights the potential of digital solutions to improve care delivery, promote health, and facilitate research. The communication emphasizes the importance of data as a key enabler for this transformation. View source → |
Clinical Trials Regulation (2014/536) — AI in Clinical Research EU · high · detected 2026-09-02 The document has been updated to include the full text of Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use. This regulation aims to harmonize and simplify the administrative provisions governing clinical trials across the EU, introducing a single submission portal for applications and clarifying definitions like 'clinical study'. It emphasizes protecting trial subjects and ensuring data reliability, while also aiming to make the EU a more attractive location for clinical research. View source → |
Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law (CETS 225) — EU signing package EU · high · detected 2026-09-02 The document has been updated to reflect a proposal for a Council Decision regarding the European Union's signing of the Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law. This change signifies a procedural step towards the EU formally adopting this convention, which will introduce new legal obligations and standards for AI development and deployment within the EU. View source → |
Cyber Resilience Act (2024/2847) [EN] EU · high · detected 2026-09-02 The diff replaces placeholder Official Journal metadata with the formally published text of Regulation (EU) 2024/2847, the Cyber Resilience Act, adopted on 23 October 2024 and published on 20 November 2024. This establishes binding, horizontal cybersecurity requirements for all products with digital elements placed on the EU market, including obligations on manufacturers to reduce vulnerabilities, provide security updates throughout the product lifecycle, and improve transparency for users. Organizations that manufacture, import, or distribute connected hardware or software products in the EU must now prepare to comply with these uniform cybersecurity obligations. View source → |
Market Surveillance Regulation (2019/1020) — Enforcement of AI Product Safety EU · high · detected 2026-09-02 The diff replaces a list of Official Journal reference entries with the full published text of Regulation (EU) 2019/1020, establishing the EU's market surveillance and product compliance framework. The regulation strengthens enforcement of Union harmonisation legislation for products placed on the EU market—whether online or offline, EU-manufactured or imported—covering compliance controls, cross-border cooperation among authorities, and customs coordination. Organizations placing products on the EU market now face a uniform, enforceable surveillance regime with clearer obligations and intensified compliance checks. View source → |
Open Data Directive (2019/1024) — Public Sector Data Reuse for AI EU · high · detected 2026-09-02 The diff replaces generic Official Journal index entries with the actual published text of Directive (EU) 2019/1024, the recast Open Data Directive. This directive modernizes the EU framework for re-use of public sector information, introducing requirements around real-time access to dynamic data, expanding the supply of re-usable public data (including from public undertakings and research organizations), limiting exclusive arrangements, and aligning with GDPR and related instruments — with explicit attention to stimulating AI innovation. Organizations subject to it face new or clarified obligations to make data available for re-use under standardized, low-cost terms. View source → |
New this week Newly ingested into the corpus. |
CoE — Joint Statement on AI, COVID-19 and Data Protection (Pierucci & Walter, 2020) EU · treaty This Joint Statement by the Council of Europe addresses data protection during the COVID-19 pandemic. It emphasizes that while extraordinary measures are justified, human rights, including privacy and data protection, cannot be suspended but only restricted by law to the extent strictly necessary. The statement… View source → |
CoE — CM/Rec(2024)5: AI in Criminal Justice Systems (Law Enforcement, Prisons, Probation) EU · treaty · published 2024-01-01 The Council of Europe's Committee of Ministers, in Recommendation CM/Rec(2024)5, provides guidance to member states on the ethical and organizational use of Artificial Intelligence (AI) and related digital technologies by prison and probation services. The document, adopted on October 9, 2024, aims to ensure that AI… View source → |
CoE/Turing — CAHAI Feasibility Study Primer: AI Legal Framework (2020) EU · treaty · published 2020-01-01 This primer, prepared by The Alan Turing Institute for the Council of Europe's Ad Hoc Committee on Artificial Intelligence (CAHAI), aims to explain the context and support the consultation phase of CAHAI's Feasibility Study on an AI legal framework. Its purpose is to facilitate informed public debate on the societal… View source → |
Australia — Online Safety Amendment (Social Media Minimum Age) Act 2024 (16+ social media restriction, in force 10 Dec 2025) AU · law · published 2025-12-01 The Online Safety Amendment (Social Media Minimum Age) Act 2024 amends the Online Safety Act 2021 to reduce harm to children by restricting social media access to users aged 16 and over. It introduces Part 4A, defining an "age-restricted user" as an Australian child under 16 (Section 5) and an "age-restricted social… View source → |
Brazil — Estatuto Digital da Crianca e do Adolescente / ECA Digital (Lei 15.211/2025, in force 17 Mar 2026) BR · law · published 2026-03-01 **Lei 15.211/2025 (ECA Digital)**, effective March 17, 2026, protects children and adolescents in digital environments. It applies to all IT products/services directed at or likely accessed by minors in Brazil (Art. 1). Art. 2 defines key terms like social networks, loot boxes, profiling, and parental supervision… View source → |
UK — Ofcom Protection of Children Code of Practice for Search Services (Online Safety Act 2023, Chapter 6 Part 3, in force 25 Jul 2025) GB · regulation · published 2025-07-01 This Ofcom document is the draft Protection of Children Code of Practice for search services, issued under section 41 of the Online Safety Act 2023 (OSA 2023). Its purpose is to guide providers of regulated search and combined services likely accessed by children on complying with statutory duties. It details… View source → |
UK — Ofcom Protection of Children Code of Practice for User-to-User Services (Online Safety Act 2023, Chapter 6 Part 3, in force 25 Jul 2025) GB · regulation · published 2025-07-01 This document presents Ofcom’s Draft Protection of Children Code of Practice for user-to-user services, prepared under section 41 of the Online Safety Act 2023. Its purpose is to guide regulated service providers in complying with child safety duties (sections 12(2)–(14)), content reporting duties (section 20), and… View source → |
EU — Commission Guidelines on Measures to Ensure a High Level of Privacy, Safety and Security for Minors Online (DSA Article 28(4), OJ C/2025/5519) EU · guidance Issued under Article 28(4) of Regulation (EU) 2022/2065 (DSA), these Guidelines aim to assist online platform providers and Digital Services Coordinators in ensuring minors' online privacy, safety, and security against risks like harmful content, cyberbullying, and AI-driven threats. Under Article 28(1), platforms… View source → |
Obligations in focus Active obligations attached to the documents in this issue — not necessarily extracted this week. |
providers of general-purpose AI models — Bring general-purpose AI models placed on the market before 2 August 2025 into compliance with the Act. Deadline: 2 August 2027 EU AI Act (2024/1689) — Phased Application Timeline View source → |
organisations that place AI on the EU market as, or within, regulated products — Ensure full high-risk conformity — risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, and conformity assessment — is in place. Deadline: by 2 August 2027 EU AI Act (2024/1689) — Phased Application Timeline View source → |
Read this issue on the web: https://briefblip.com/weekly/2026-W36
BriefBlip is a Blue Note Logic Inc product. Brief anything, in a blip.