BriefBlip Weekly · by Blue Note Logic
The EU AI Act Weekly
21–27 September 2026 · 25 changes · 7 new documents
Every item below links to the source document we read it from — a citation, not model memory.
What changed Documents we already monitor that moved this week. |
EDPB — Greek DPA Fines Clearview AI €20M for Biometric Data Violations (2022) GR · high · detected 2026-09-23 The document has been updated to include new fines imposed by various data protection authorities, including significant fines against Google and Securitas Direct for violations related to personal data processing. Additionally, the EDPB has harmonized its fining methodology and adopted final guidelines, which may affect how organizations are penalized for data breaches. These changes are important as they reflect an evolving regulatory landscape that organizations must navigate to ensure compliance and avoid substantial fines. View source → |
Cyber Threats | ENISA EU · high · detected 2026-09-23 The document has been updated to reflect a new edition of the ENISA Threat Landscape, now focusing on 2026 instead of 2025. It emphasizes the evolution of the cyber threat landscape, particularly how dependencies can weaken digital resilience and expand the attack surface. This change is significant for organizations as it highlights the need for increased vigilance and updated strategies to address evolving cyber threats. View source → |
Brazil — ANPD: Autoridade Nacional de Proteção de Dados (National Data Protection Authority portal) BR · medium · detected 2026-09-23 The updated document reflects changes in the activities and announcements of the ANPD, including the scheduling of a public hearing for a new regulatory framework and the celebration of the ECA Digital's first anniversary. These changes indicate ongoing regulatory developments and a focus on protecting children and adolescents online, which may affect compliance requirements for organizations handling data related to these groups. View source → |
EU incident response and cyber crisis management | ENISA EU · medium · detected 2026-09-23 The addition of the term 'Single Reporting Platform (SRP)' indicates a new centralized system for reporting incidents, which may streamline the process for organizations. This change is significant as it could enhance the efficiency and effectiveness of incident reporting and management across the EU. View source → |
AI Safety Institute - GOV.UK medium · detected 2026-09-23 The document has shifted focus from the AI Safety Institute's approach to evaluations to introducing systemic AI safety fast grants and providing guidance, with a new date of May 22, 2024. This change indicates a move towards funding initiatives and offering support for AI safety, which could impact how organizations engage with AI safety measures. View source → |
EDPB — AEPD Imposes €6M Fine on CaixaBank for Unlawful Data Processing (2021) ES · medium · detected 2026-09-23 The document now includes a fine imposed on Securitas Direct by the Spanish DPA for obstructing data subject rights, replacing a previous fine on a telecommunications company. Additionally, it notes the EDPB's harmonization of fining methodology and the adoption of final guidelines related to the DSA and GDPR. These changes are significant as they clarify enforcement actions and guidelines that organizations must follow, impacting their compliance strategies. View source → |
EDPB — AEPD Fines CaixaBank €3M for Unlawful Profiling for Commercial Purposes (2021) ES · medium · detected 2026-09-23 The document now includes a fine imposed on Securitas Direct by the Spanish DPA for complicating the exercise of data subject rights, replacing a previous fine on a telecommunications company in Italy. Additionally, it mentions the EDPB's harmonization of fining methodology and the adoption of final guidelines related to the DSA-GDPR. These changes highlight the enforcement actions and regulatory updates that organizations must be aware of to ensure compliance with data protection laws. View source → |
EDPB — Facial Recognition in School: Sweden's First GDPR Fine (2019) SE · medium · detected 2026-09-23 The document now includes a new fine imposed by the Spanish DPA on Securitas Direct for hindering data subject rights, replacing a previous fine on an Italian telecommunications company. Additionally, it mentions the EDPB's harmonization of fining methodology and the adoption of final guidelines related to the DSA and GDPR. This change is significant as it highlights the evolving enforcement landscape and the importance of compliance with data subject rights across jurisdictions. View source → |
EDPB — Dutch DPA Imposes €30.5M Fine on Clearview AI for Illegal Data Collection (2024) NL · medium · detected 2026-09-23 The document now includes information about a fine imposed by the Spanish DPA on Securitas Direct for complicating the exercise of data subject rights, as well as updates on the EDPB's harmonization of fining methodology and final guidelines related to the DSA-GDPR. These additions highlight ongoing enforcement actions and regulatory developments that organizations must be aware of to ensure compliance with data protection laws. View source → |
Artificial Intelligence | Shaping Europe’s digital future EU · medium · detected 2026-09-23 The document has shifted from a focus on specific calls for proposals related to strengthening EU cybersecurity capacities and capabilities to including news articles that discuss the impact of artificial intelligence on education and the development of AI-related projects. This change indicates a broader emphasis on the implications of AI across various sectors, particularly education, which may affect organizations involved in these areas by highlighting new regulatory and operational considerations. View source → |
Policy papers and consultations - GOV.UK UK · medium · detected 2026-09-23 The addition of 'British Steel Limited (BSL)' indicates that this specific company is now referenced in the policy papers and consultations. This change may matter to organizations as it could imply new regulations or considerations that directly affect BSL and potentially its stakeholders. View source → |
Research and statistics - GOV.UK UK · medium · detected 2026-09-23 The addition of 'British Steel Limited (BSL)' specifies a particular entity within the document, which may indicate that the regulations or guidelines apply specifically to this organization. This change is important for organizations as it clarifies the scope of the regulations and who is affected by them. View source → |
Guidance and regulation - GOV.UK UK · medium · detected 2026-09-23 The reference to the AI Safety Institute has been replaced with information about British Steel Limited and a joint announcement by the governments of the UK and Canada. This change shifts the focus from AI safety to a specific corporate entity and international collaboration, which may affect organizations involved in steel production or trade. View source → |
EU international engagement on Artificial Intelligence EU · medium · detected 2026-09-23 The document has removed several events related to AI adoption and innovation in the public sector and replaced them with new articles and events focusing on the impact of AI on education and health data initiatives. This shift emphasizes the EU's current priorities in addressing AI's implications for education and health, which may affect organizations by altering funding, compliance, and strategic focus areas. Organizations may need to adapt to these new priorities to align with EU initiatives. View source → |
Artificial Intelligence in Health EU · medium · detected 2026-09-23 The date for a survey on the EU legal framework for health data has been removed and replaced with a high-level event for the 1+ Million Genomes initiative scheduled for December 2026. This change indicates a shift in focus from assessing existing regulations to promoting a specific genomic initiative, which may impact how organizations prioritize their compliance efforts. View source → |
Live data from OECD.AI - OECD.AI INTERNATIONAL · medium · detected 2026-09-23 The updated section on live data now includes additional categories such as 'AI search trends', 'AI compute', 'AI knowledge flows', 'AI model usage', 'AI models and datasets', and 'AI patents', while removing the note about the data being updated. This change enhances the comprehensiveness of the data presented, providing organizations with more insights into various aspects of AI development and usage. View source → |
AI Act Standardisation — Harmonised Standards and Conformity EU · medium · detected 2026-09-22 The document has removed references to past meetings and support for the Code of Practice on Transparency of AI-generated Content, while adding new articles about the impact of AI on education, recent meetings of the AI Board, and the establishment of a significant project in AI by multiple Member States. This shift emphasizes ongoing developments and enforcement of the AI Act, highlighting the importance of transparency and collaboration in AI initiatives, which organizations must now consider in their compliance strategies. View source → |
EU AI Pact - voluntary commitments EU · medium · detected 2026-09-22 The date for a commitment has been changed from 10 September 2026 to 17 September 2026, and specific entities 'Cogito Coach' and 'LOGIKS' have been added. This change may affect the timeline for compliance and the entities involved in the voluntary commitments under the EU AI Pact. View source → |
European AI Office - mandate and implementation role EU · medium · detected 2026-09-22 The document has updated event dates and topics, replacing a press release about a past event with future events related to genomic data and data unions. This change indicates a shift in focus towards current and upcoming initiatives, which may affect organizations involved in AI and data management in the EU. View source → |
NORA — Norwegian Artificial Intelligence Research Consortium NO · medium · detected 2026-09-22 The document has replaced a section about the Nordic AI Meet 2026 with details about a Public Roundtable event focused on trust in AI and its impact on news media. This change highlights a shift in focus from a broader symposium on AI applications to a specific discussion on the ethical implications of AI in journalism. This matters to organizations as it emphasizes the importance of addressing trust and ethics in AI, particularly in media contexts, which could affect their operations and responsibilities. View source → |
UK — AI Opportunities Action Plan (DSIT, 2025) GB · low · detected 2026-09-23 The change involves the removal of a period at the end of the sentence, which does not alter the meaning or requirements of the document. This is a minor typographical correction that does not affect the content or obligations for organizations. View source → |
Data Protection Act 2018 (UK) — Contents Page — legislation.gov.uk GB · low · detected 2026-09-23 There are no substantive changes in the content of the Data Protection Act 2018; the differences are related to formatting or presentation of the document. This means that organizations subject to this regulation are not affected by any changes in legal obligations or compliance requirements. View source → |
South Korea — Personal Information Protection Act (PIPA) — Personal Information Protection Commission (PIPC) KR · low · detected 2026-09-23 The changes primarily involve the addition of navigation and content elements to the website of the Personal Information Protection Commission (PIPC) in South Korea. This includes links to social media, language options, and various sections related to personal information protection. These updates enhance accessibility and user experience for organizations and individuals seeking information on compliance with the Personal Information Protection Act (PIPA). View source → |
UK — DSIT: AI Regulation — A Pro-Innovation Approach (White Paper + Consultation Response, 2023-2024) GB · low · detected 2026-09-23 The phrasing of the request for an accessible format has been standardized by removing redundant repetitions. This change clarifies the document's intent without altering its substantive meaning. View source → |
UK — Online Safety Act 2023 GB · low · detected 2026-09-23 There are no substantive changes in the content of the Online Safety Act 2023; the text appears to be a formatting or presentation update without altering any legal obligations or requirements. View source → |
New this week Newly ingested into the corpus. |
GDPRhub — VwGH - Ro 2021/04/0010-11 case law · published 2024-02-20 The Austrian Supreme Administrative Court (VwGH) ruled on December 21, 2023, in case Ro 2021/04/0010-11, concerning the use of an algorithm by the Public Employment Service Austria for assessing job seekers’ employment opportunities. The court determined that the algorithm constituted automated decision-making under… View source → |
GDPRhub — IMY (Sweden) - IMY-2025-11828 SE · case law · published 2025-11-18 The document summarizes the investigation conducted by the Swedish Data Protection Authority (IMY) regarding the Swedish Social Insurance Agency’s (SSIA) use of machine learning for risk-based selection in checks on individuals receiving temporary parental benefits. Initiated in June 2025, the inquiry specifically… View source → |
GDPRhub — ICO (UK) - EA-2023-0252-FP case law · published 2024-05-02 The document summarizes the case EA-2023-0252-FP, where the UK Information Commissioner's Office (ICO) penalized Join the Triboo Ltd (JTT) for sending approximately 107 million unsolicited marketing emails without valid consent, violating Regulation 22 of the Privacy and Electronic Communications Regulations 2003… View source → |
GDPRhub — HmbBfDI (Hamburg) - Fine against a financial company case law · published 2025-09-30 The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a €492,000 fine on a financial services company for violating Article 22 of the GDPR, which governs automated decision-making. The investigation revealed that the company rejected credit card applications based on automated… View source → |
GDPRhub — HDPA (Greece) - 51/2021 GR · case law · published 2021-11-19 The document is a case summary from the Hellenic Data Protection Authority (HDPA) regarding complaint number 51/2021, decided on November 19, 2021. The case involved a data subject who alleged that a Greek bank engaged in automated decision-making and profiling related to debt collection, potentially violating Article… View source → |
GDPRhub — HDPA (Greece) - 13/2024 GR · case law · published 2024-04-02 The Greek Data Protection Authority (HDPA) issued a ruling (13/2024) on October 17, 2023, resulting in a €175,000 fine for the Ministry of Migration and Asylum due to multiple violations of the General Data Protection Regulation (GDPR). The case stemmed from the ministry's use of the "Centaurus" and "Hyperion"… View source → |
GDPRhub — DSB (Austria) - DSB-D124.2437/25 AT · case law · published 2026-07-07 The Austrian Data Protection Authority (DSB) ruled in case DSB-D124.2437/25 regarding a complaint from a patient against N***-Therapie, a therapy association. The patient claimed a violation of their right of access under Article 15 of the General Data Protection Regulation (GDPR) due to incomplete information… View source → |
Read this issue on the web: https://briefblip.com/weekly/2026-W39
BriefBlip is a Blue Note Logic Inc product. Brief anything, in a blip.