BriefBlip Weekly · by Blue Note Logic
BriefBlip Weekly · by Blue Note Logic

The EU AI Act Weekly

14–20 September 2026 · 25 changes · 27 new documents · 8 obligations

Every item below links to the source document we read it from — a citation, not model memory.

What changed
Documents we already monitor that moved this week.
Cyber Resilience Act (2024/2847) [EN]
EU · high · detected 2026-09-17
The document has been updated to include a formal introduction of the Cyber Resilience Act, outlining its purpose to establish uniform cybersecurity requirements for products with digital elements across the EU. It emphasizes the need for improved cybersecurity measures to address vulnerabilities and enhance consumer safety, thereby creating a more consistent regulatory environment for manufacturers and users. This change is significant as it aims to reduce legal uncertainty and compliance burdens for organizations dealing with digital products.
View source →
Market Surveillance Regulation (2019/1020) — Enforcement of AI Product Safety
EU · high · detected 2026-09-17
The document has been updated to include a formal citation and introduction of the regulation, emphasizing the importance of market surveillance and compliance for product safety in the EU. It outlines the necessity for robust enforcement to protect public interests and ensure fair competition, while also clarifying the regulation's scope in relation to existing legislation. This change is significant for organizations as it reinforces the legal framework they must adhere to for product compliance and market entry.
View source →
Open Data Directive (2019/1024) — Public Sector Data Reuse for AI
EU · high · detected 2026-09-17
The document has been recast to clarify and update the legal framework regarding the reuse of public sector information, particularly in relation to digital technologies and artificial intelligence. It emphasizes the need for real-time access to dynamic data and addresses barriers to data reuse, which could enhance innovation and economic growth. This change is significant for organizations as it may affect their access to public data and the conditions under which they can use it.
View source →
Regulatory document
high · detected 2026-09-17
The document has been updated to reflect the new Regulation (EU) 2024/573 on fluorinated greenhouse gases, which amends Directive (EU) 2019/1937 and repeals Regulation (EU) No 517/2014. This change is significant as it indicates a shift in regulatory framework regarding greenhouse gases, which organizations must comply with to avoid penalties and ensure environmental standards are met.
View source →
EU Artificial Intelligence Act (Regulation 2024/1689) — Official Journal PDF
EU · medium · detected 2026-09-17
The document has been updated to reflect its official title and details, including the regulation number and the date it was laid down. The previous references to the Official Journal and various series have been removed, and the document now includes a direct link to the EUR-Lex website for access to European Union law. This change matters because it provides clearer and more direct access to the legal text for organizations needing to comply with the regulations.
View source →
Regulatory document
medium · detected 2026-09-17
The document has been updated to remove specific references to the Official Journal and its verification process, while adding a section that provides access to the EUR-Lex website and search tips for European Union law. This change emphasizes easier access to legal documents and guidance on how to search for them, which can help organizations stay compliant with EU regulations more efficiently.
View source →
EU — Digital Markets Act (DMA, Regulation 2022/1925)
EU · medium · detected 2026-09-17
The document has been updated to include the official publication details of the Digital Markets Act, including its regulation number, date, and context. This change formalizes the act's status and clarifies its legislative background, which is crucial for organizations to understand their compliance obligations and the legal framework governing digital market practices in the EU.
View source →
EU — Digital Services Act (DSA, Regulation 2022/2065)
EU · medium · detected 2026-09-17
The document has been updated to include the official publication details of the Digital Services Act (DSA), including its title, date, and context. This change clarifies the legal foundation and relevance of the regulation, which is crucial for organizations to understand their obligations under the law. The inclusion of specific references to the legislative process and the importance of harmonizing regulations across member states emphasizes the need for compliance and adaptation to a unified regulatory framework.
View source →
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
EU · medium · detected 2026-09-17
The changes primarily involve the removal of references to specific editions of the Official Journal and the addition of a comprehensive introduction to the General Data Protection Regulation (GDPR), detailing its legislative background and fundamental principles. This matters to organizations as it clarifies the legal context and foundational rights related to data protection, emphasizing the importance of compliance with these principles in their operations.
View source →
Health Technology Assessment Regulation (2021/2282) — AI Diagnostics Evaluation
EU · medium · detected 2026-09-17
The document has been updated to include specific references to the Official Journal of the European Union and details about the legislative process, including the context and importance of health technology assessments (HTAs). This change clarifies the legal framework and emphasizes the role of HTAs in promoting innovation and improving healthcare outcomes, which is crucial for organizations involved in health technology development and assessment. The inclusion of these details may affect compliance and operational strategies for stakeholders in the healthcare sector.
View source →
Platform-to-Business Regulation (2019/1150) — Algorithmic Ranking Transparency
EU · medium · detected 2026-09-17
The document has been updated to include a formal citation and introduction of the regulation, emphasizing the importance of fairness and transparency for business users of online intermediation services. It outlines the challenges posed by the power dynamics between service providers and business users, particularly for SMEs, and highlights the need for trust and transparency in the online platform economy. This change matters because it clarifies the regulatory framework and expectations for organizations operating in this space, ensuring they are aware of their rights and obligations.
View source →
Effort Sharing Amendment - Regulation (EU) 2023/857
EU · medium · detected 2026-09-17
The document has been updated to remove specific references to the Official Journal and its verification process, while adding a link to the EUR-Lex website for accessing European Union law. This change simplifies access to the regulation and may improve user navigation, which is important for organizations needing to comply with the regulation.
View source →
Regulatory document
medium · detected 2026-09-17
The document has removed references to specific editions of the Official Journal and their verification process, while adding navigation and access information related to the EUR-Lex website. This change enhances user accessibility to EU law documents but removes specific details that may have been relevant for verifying the authenticity of past publications. Organizations must adapt to the new access methods for compliance and reference purposes.
View source →
EDPB — Greek DPA Fines Clearview AI €20M for Biometric Data Violations (2022)
GR · medium · detected 2026-09-16
The document has been updated to include additional fines imposed by the French CNIL for various violations, including failure to respect individual rights and a health data breach. This matters to organizations as it highlights the increasing enforcement actions by regulatory authorities and the potential financial repercussions for non-compliance with data protection laws.
View source →
South Korea — Personal Information Protection Act (PIPA) — Personal Information Protection Commission (PIPC)
KR · medium · detected 2026-09-16
The document has added a section indicating a 'Database Processing Error' message, which suggests that there may be issues related to data handling or system functionality. This change could impact organizations by highlighting the importance of ensuring their data processing systems are robust and compliant with the Personal Information Protection Act (PIPA).
View source →
Brazil — ANPD: Autoridade Nacional de Proteção de Dados (National Data Protection Authority portal)
BR · medium · detected 2026-09-16
The updated document removes a reference to the ANPD evaluating digital platforms' actions to prevent criminal content and protect vulnerable groups, while adding information about public consultations for regulatory updates. This change indicates a shift towards engaging stakeholders in regulatory processes, which may affect how organizations prepare for compliance and adapt to new regulations.
View source →
AI Safety Institute - GOV.UK
medium · detected 2026-09-16
The document has shifted focus from 'Systemic AI safety fast grants' to 'Collaboration on the safety of AI: UK-US memorandum of understanding', indicating a move towards international cooperation on AI safety. This change is significant for organizations as it may affect funding opportunities and regulatory expectations regarding AI safety practices.
View source →
EDPB — AEPD Imposes €6M Fine on CaixaBank for Unlawful Data Processing (2021)
ES · medium · detected 2026-09-16
The document has been updated to include new fines imposed by the CNIL for various data breaches and the addition of an RSS feed. This reflects an expansion of enforcement actions and highlights the importance of compliance with data protection regulations, particularly regarding individual rights and health data. Organizations should be aware of these developments as they indicate increasing scrutiny and potential penalties for non-compliance.
View source →
EDPB — AEPD Fines CaixaBank €3M for Unlawful Profiling for Commercial Purposes (2021)
ES · medium · detected 2026-09-16
The document has been updated to include new fines imposed by the CNIL for various breaches, including a significant health data breach and failure to respect individual rights. This indicates an increased focus on compliance with data protection regulations, which is crucial for organizations to avoid similar penalties.
View source →
EDPB — Facial Recognition in School: Sweden's First GDPR Fine (2019)
SE · medium · detected 2026-09-16
The document has been updated to include new fines imposed by the CNIL on EXTIA and Hôpital Privé de la Loire for failing to respect individual rights and for a health data breach, respectively. This indicates an increased regulatory focus on compliance with data protection rights and the handling of sensitive health data, which is crucial for organizations to understand to avoid similar penalties.
View source →
EDPB — Dutch DPA Imposes €30.5M Fine on Clearview AI for Illegal Data Collection (2024)
NL · medium · detected 2026-09-16
The document has removed references to past EDPB news events and added new fines imposed by the CNIL on EXTIA and Hôpital Privé de la Loire for violations related to individual rights and health data breaches. This change highlights ongoing enforcement actions and the importance of compliance with data protection regulations, particularly in the health sector.
View source →
Policy papers and consultations - GOV.UK
UK · medium · detected 2026-09-16
The term 'Intertrade UK' has been added to the document, indicating a potential focus or emphasis on trade relations within the UK. This change may matter to organizations involved in trade, as it could signal new policies or initiatives related to inter-trade activities.
View source →
Research and statistics - GOV.UK
UK · medium · detected 2026-09-16
The term 'Intertrade UK' has been added to the document, indicating a potential focus on trade relationships and regulations involving the UK. This change may matter to organizations engaged in international trade, as it could imply new guidelines or frameworks for trading activities.
View source →
First International AI Safety Report to inform discussions at AI Action Summit - GOV.UK
UK · medium · detected 2026-09-16
The publication date for the First International AI Safety Report has been removed, indicating that the timeline for its release may be uncertain or subject to change. This could affect organizations planning for compliance or engagement with the report's findings and recommendations.
View source →
Guidance and regulation - GOV.UK
UK · medium · detected 2026-09-16
The term 'Intertrade UK' has been added to the document, which may refer to a specific initiative or organization related to trade within the UK. This change could impact organizations engaged in international trade by potentially introducing new guidelines or requirements associated with this entity.
View source →
New this week
Newly ingested into the corpus. Showing 15 of 27.
GDPRhub — VwGH - Ro 2021/04/0010
case law
The Austrian Supreme Administrative Court (VwGH) ruled in case Ro 2021/04/0010 on December 21, 2023, regarding the Public Employment Service (AMS) and its use of the Labor Market Opportunities Assistance System (AMAS). The court found that AMAS, which employs an algorithm to assess jobseekers' labor market prospects…
View source →
GDPRhub — VwGH - Ra 2023/04/0271
case law · published 2025-12-10
The Austrian Supreme Administrative Court (VwGH) ruled in case Ra 2023/04/0271 on November 13, 2025, confirming that a credit information agency's manual assignment of a credit score did not constitute automated decision-making under Article 22 of the GDPR. The court dismissed a data subject's complaint regarding…
View source →
GDPRhub — VwGH (Austria) - Ro 2020/04/0010
AT · case law · published 2025-10-07
The Austrian Supreme Administrative Court (VwGH) ruled on case Ro 2020/04/0010, determining that Dun & Bradstreet Austria GmbH violated Article 15(1)(h) of the GDPR by not providing adequate information regarding the logic and factors influencing its automated credit scoring process. The data subject, seeking…
View source →
GDPRhub — VG Wiesbaden - 6 K 788/20.WI
case law
The document summarizes the case VG Wiesbaden - 6 K 788/20.WI, where the court determined that credit scoring qualifies as automated decision-making under the GDPR, specifically referencing Article 15(1)(h) and Article 22 GDPR. The plaintiff, seeking information from a credit rating agency about how their credit score…
View source →
GDPRhub — VG Bremen - 2 K 763/23
case law
The VG Bremen court case (2 K 763/23) addressed a complaint from a Bremen resident regarding the automated determination of a waste disposal fee, which he argued violated Article 22 of the GDPR. The plaintiff contended that the fee notice issued in January 2022 was unlawful as it resulted from fully automated…
View source →
GDPRhub — Tietosuojavaltuutetun toimisto (Finland) - 6482/186/2020
FI · case law · published 2022-10-27
The document titled "GDPRhub — Tietosuojavaltuutetun toimisto (Finland) - 6482/186/2020" summarizes a case investigated by the Finnish Data Protection Authority (DPA) regarding a healthcare provider's use of an automated Health Benefit Analysis tool. The DPA assessed whether this tool constituted automated individual…
View source →
GDPRhub — TA - 413/2025
case law
The court case TA - 413/2025, decided on December 30, 2025, involved Microsoft Ireland Operations Limited and Microsoft Romania SRL, where a judge (the data subject) sought removal of defamatory content linked to him on Bing, per Articles 17, 18, 21, and 22 of the GDPR. The court ruled that the content harmed the…
View source →
GDPRhub — Rb. Oost-Brabant - ECLI:NL:RBZWB:2023:7274
case law · published 2023-10-30
The Court of East Brabant (ECLI:NL:RBZWB:2023:7274) ruled on October 18, 2023, regarding a data subject's claims under the GDPR against the Municipality of Oisterwijk. The data subject contested municipal taxes, asserting violations of Article 15 (right of access), Article 17 (right to erasure), and Article 22 (right…
View source →
GDPRhub — Rb. Gelderland - C/05/404505 / HA RK 22-99
case law · published 2022-11-08
The case Rb. Gelderland - C/05/404505 / HA RK 22-99, decided on November 1, 2022, by the District Court of Gelderland, involved Mollie B.V. as the data controller and a data subject who was the Ultimate Beneficial Owner (UBO) of two foundations. The data subject challenged Mollie's denial of multiple access requests…
View source →
GDPRhub — Rb. Gelderland - AWB-22/4722
case law · published 2023-09-28
The Gelderland District Court ruled on August 15, 2023, in case AWB-22/4722, involving the Dutch Tax Authority (Belastingdienst) and a data subject seeking access to personal data under Article 15 of the GDPR. The court determined that the Tax Authority failed to adequately respond to the data subject's access request…
View source →
GDPRhub — Rb. Den Haag - C/09/585239/ KG ZA 19/1221
case law
In the case Rb. Den Haag - C/09/585239/ KG ZA 19/1221, the Court of The Hague ruled on February 11, 2020, regarding the legality of the Dutch government's e-screener, a digital questionnaire assessing the psychological state of firearms license applicants. The Royal Dutch Hunters Society and the Royal Dutch Shooting…
View source →
GDPRhub — Rb. Den Haag - C/09/550982/HA ZA 18/388
case law · published 2020-02-05
The District Court of The Hague ruled on February 5, 2020, in case C/09/550982/HA ZA 18/388, that the digital tool SyRI, used by Dutch authorities to combat tax and social security fraud, violated the right to private life under Article 8 ECHR. The court assessed the legality of SyRI's interference with privacy…
View source →
GDPRhub — Rb. Amsterdam - C/13/696010 / HA ZA 21-81
case law
In the case Rb. Amsterdam - C/13/696010 / HA ZA 21-81, the District Court of Amsterdam ruled against Uber, ordering the reinstatement of six drivers dismissed due to automated processing under Article 22 of the GDPR. The court found Uber's automated decisions regarding alleged fraud unlawful, leading to a default…
View source →
GDPRhub — Rb. Amsterdam - C/13/692003/HA RK 20-302
case law · published 2021-03-11
In the case Rb. Amsterdam - C/13/692003/HA RK 20-302, decided on March 11, 2021, the Court of Amsterdam addressed a challenge from four Uber drivers regarding the automated termination of their accounts for alleged fraudulent acts. The drivers argued that the deactivation was a result of automated decision-making…
View source →
GDPRhub — Rb. Amsterdam - C/13/687315 / HA RK 20-207
case law · published 2021-03-11
The District Court of Amsterdam (Rb. Amsterdam) ruled on March 11, 2021, in case C/13/687315 / HA RK 20-207, involving Uber B.V. and ten drivers seeking access to their personal data under the GDPR. The court upheld the drivers' requests for data access under Article 15 GDPR but rejected many of their specific…
View source →
+12 more documents entered the corpus this week and are searchable there.
Obligations in focus
Active obligations attached to the documents in this issue — not necessarily extracted this week.
gatekeeper — Comply with the obligations laid down in Articles 5, 6 and 7.
Deadline: within 6 months after a core platform service has been listed in the designation decision
EU — Digital Markets Act (DMA, Regulation 2022/1925)
View source →
controller — Provide information on action taken on a request under Articles 15 to 22 to the data subject.
Deadline: within one month of receipt of the request
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
View source →
controller — Inform the data subject of any extension of the period for responding to a request under Articles 15 to 22.
Deadline: within one month of receipt of the request
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
View source →
controller — Inform the data subject of the reasons for not taking action on a request under Articles 15 to 22.
Deadline: at the latest within one month of receipt of the request
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
View source →
controller — Provide information under Articles 13 and 14 and any communication and actions taken under Articles 15 to 22 and 34 free of charge.
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
View source →
controller — Request additional information necessary to confirm the identity of the data subject if there are reasonable doubts concerning the identity of the natural person making the request.
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
View source →
controllers — Implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation.
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
View source →
controllers — Implement appropriate technical and organisational measures, such as pseudonymisation, to implement data-protection principles, such as data minimisation.
EU — General Data Protection Regulation (GDPR, Regulation 2016/679)
View source →

Read this issue on the web: https://briefblip.com/weekly/2026-W38

BriefBlip is a Blue Note Logic Inc product. Brief anything, in a blip.

← All issues