To harmonize cybersecurity requirements across the EU, the Cyber Resilience Act (CRA) applies to hardware and software products made available in the EU whose intended or reasonably foreseeable use involves a direct or indirect connection to a device or network. This includes software applications, Internet-of-Things (IoT) products, routers, connected machinery and separately marketed digital components (e.g., smartphones, laptops, smart home products, smartwatches, connected toys, microprocessors, firewalls, connected machinery, accounting and finance software, games and apps, as well as open-source software supplied in the course of a commercial activity).

While most CRA obligations will apply from 11 December 2027, manufacturers must comply with reporting obligations under CRA Article 14 from 11 September 2026. This also applies to products with digital elements that have already been placed on the EU market. These reporting obligations concern

  • Actively exploited vulnerabilities, i.e., security weaknesses for which there is reliable evidence that a malicious actor has exploited them. For example, the confirmed exploitation of an authentication flaw to obtain unauthorized access.
  • Severe incidents affecting the security of a product, for example, an incident that comprises the confidentiality or integrity of sensitive data.

The reporting process under the CRA is staged as follows:

  • An early warning must be submitted without undue delay and, in any event, within 24 hours of the manufacturer becoming aware of the vulnerability or incident. The notification must be submitted through the CRA single reporting platform (SRP), operated by the EU Agency for Cybersecurity (ENISA), and is made available to the relevant computer security incident response team (CSIRT) designated as coordinator and, generally, simultaneously to ENISA. The competent CSIRT is determined in accordance with the CRA and selected by the manufacturer when submitting the notification. It is generally the CSIRT of the member state in which the manufacturer has its main establishment, i.e., where decisions concerning the cybersecurity of its products are predominantly taken.
    • The individual submitting the notification on behalf of the manufacturer must have an EU login account (EU LOGIN) and register as an “Assigned Representative” of the relevant manufacturer. Advance registration with the SRP is not required. Registration and association with the relevant manufacturer can be competed in connection with the first notification. Prior validation of the association by the CSIRT is not a prerequisite for submission. However, an EU login account should be set up in advance.
  • Within 72 hours, the manufacturer must submit a more detailed notification. Depending on the event, this must include available information on the affected product, the nature, severity and impact of the vulnerability or incident, as well as any corrective or mitigating measures taken or available.
  • A final report must subsequently be submitted: for an actively exploited vulnerability, generally no later than 14 days after a corrective or mitigating measure becomes available; for a severe incident, within one month after the 72 hour notification.

In addition, after becoming aware of an actively exploited vulnerability or severe incident, manufacturers must inform impacted users without undue delay and, where appropriate, all users. The information must include any measures users can take to mitigate or correct the risk where necessary.

Although the CRA’s general product compliance requirements do not yet apply to the relevant product, manufactures nevertheless become subject to these reporting obligations from 11 September 2026.

In-scope businesses should therefore assess

  • Which hardware and software products fall within the CRA’s scope
  • Which entity qualifies as the manufacturer and which CSIRT will be competent
  • Whether identified vulnerabilities are merely theoretical or are actively exploited, and whether incidents meet the CRA’s severity criteria based on their impact on sensitive or important data or functions or the execution of malicious code
  • Whether robust internal 24 and 72 hour identification, escalation and reporting processes are in place

For further practical guidance, the German Federal Office for Information Security (BSI) has published the Technical Guideline BSI TR 03183-1, “Cyber Resilience Requirements for Manufacturers and Products Part 1: General requirements” (BSI TR), which provides nonbinding, introductory guidance on the implementation of the CRA, and is aimed particularly at manufacturers that have not yet established mature IT security processes for product development and vulnerability handling.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

Last week, a European Data Protection Authority imposed a substantial fine for a company’s use of an algorithmic system that automatically restricted individuals’ access to income-generating opportunities via an online platform and the failure to provide adequate transparency.  Accounts were deactivated where the system detected suspected fraud or low customer ratings and no human assessment took place. According to the authority, this constitutes prohibited automatic decision making within the meaning of Art. 22 GDPR, which states that a “data subject shall have the right not to be subject to a decision based on automated processing, including profiling, which produces legal effects concerning him or her or similarly significant affects him or her”. 

The investigation followed complaints from 171 individuals. The fine was calculated by reference to the company’s worldwide annual turnover. The decision is not yet final and is subject to appeal.

The case is not merely a platform-economy issue.  Automated scores and system-generated flags increasingly influence everyday business decisions, including decisions affecting employees and customers. While many automated processes are routine and legally unproblematic, Art. 22 GDPR may apply where a decision is based solely on automated processing and produces legal or similar significant effects. Examples include loss of income, as in the decision at hand, denial of credit or insurance, rejection of a job application, or exclusion from an important service.  

Where automated-decision making is permitted under one of the limited exceptions in Art. 22 GDPR, businesses must implement appropriate safeguards. These include meaningful human intervention, transparent information about the decision-making process and an effective opportunity to contest the decision. A nominal review or a routine approval of a system generated recommendation is unlikely to be sufficient.

Relevant use cases may include, for example, automated recruitment screening, allocation or withdrawal of shifts, performance scoring, fraud detection, refusal of returns or payment options, as well as automated access restrictions. Business should identify where automated outputs trigger adverse consequences and assess whether the decision is genuinely reviewed by a person with sufficient information, authority and ability to depart from the system’s recommendation. 

While the decision concerns the GDPR and does not determine whether the system in question qualifies as an AI system under the AI Act, the decision may nevertheless provide useful context for the AI Act’s human oversight requirements. In the employment context, AI-supported recruitment, performance evaluation, task allocation or disciplinary decisions may qualify as high-risk under Annex III. This may be the case even where a human formally makes the final decision. Effective human oversight under the AI Act must therefore be substantive rather than merely procedural: the responsible person must be able to understand and critically assess the system’s output and, where appropriate, disregard, override or reverse it. 

Businesses should review their inventories of automated and AI-supported systems, conduct or update a data protection impact assessment where required, update their privacy information where necessary, establish effective procedures for dealing with objections to automated decisions and document both the decision-making process and any human review. Although the AI Act requirements for Annex III high risk systems will not apply until 2 December 2027, the necessary governance and documentation should be developed now.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

2026 started with 20 state consumer privacy laws (SCPLs), three of which went into force on January 1, 2026. During the first half of 2026, four new SCPLs were added, bringing the count to 24 – all since the California legislature passed the California Consumer Privacy Act (CCPA) in June 2018. Also, during the first half of 2026, state legislatures enacted significant amendments to their existing SCPLs. We cover the state privacy laws developments in this first of a three-part series on mid-year US data law updates – stay tuned for updates on teen online privacy and safety, as well as AI.

Continue Reading Adding to the Count: The latest in state consumer privacy laws

In case you missed it, below are recent posts from Privacy World covering the latest developments on data privacy, security and innovation. Please reach out to the authors if you are interested in additional information.

China Introduces Simplified Personal Information Protection Regime for Small-Scale Personal Information Handlers

Upcoming CLE Opportunities with the SPB Data Team

Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

How Deep is Your Fake? A 3-Minute-Guide on Labelling Obligations under the EU AI Act

Another Omnibus package – no.’VII’ – this time on all things AI

Upcoming Events in Asia

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

On July 22, 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers (the “Provisions”), which will take effect on September 1, 2026.

The Provisions are designed to reduce compliance burdens for smaller businesses, while maintaining baseline personal information protection requirements. They introduce a series of streamlined compliance measures for qualifying entities in China.

Continue Reading China Introduces Simplified Personal Information Protection Regime for Small-Scale Personal Information Handlers

On August 5, 2026, Julia Jacobson, Partner (New York), and Joel Schwarz, Managing Partner, The Schwarz Consulting Group LLC, will present “Privacy and Online Safety Laws for Minors: Navigating Evolving Compliance, Business, and Technology Challenges.”  This Strafford webinar will review the growing body of laws focused on the privacy and safety of minors online and offer some tips for developing and uplifting compliance practices.  To learn more: click here.   We have a few complimentary access codes.  Please contact julia.jacobson@squirepb.com or TheSchwarzGroup@outlook.com.

On August 20, 2026, Alan Friel, Partner (Atlanta/Los Angeles), and Julia Jacobson, Partner (New York), are joined by Faye Ricci, VP & Deputy General Counsel, Boeing Employee Credit Union (BECU), for “AI and Data Privacy: Adapting Policies, Ensuring Responsible Use of Data, Mitigating Risks.”  Also sponsored by Strafford, this session will cover privacy risks associated with deployment of artificial intelligence (AI) systems.  To learn more: click here.  To request a complimentary access code, please contact your Squire Patton Boggs relationship partner or the speakers.

Kyle Dull, Senior Associate (Miami/New York), will present “AI-Assisted Advertising and Retail” to the Association of Corporate Counsel (South Florida Chapter) on August 25, 2026, in Miami, Florida. This CLE will cover consumer protection regulations; profiling and ADMT regulations; and an action plan for in-house teams. Please reach out to christina.kim@squirepb.com for more details.

On August 28, 2026, Alan Friel, Partner (Atlanta/Los Angeles), and Kyle Dull, Senior Associate (Miami/New York), will present “Consumer Privacy Requests and Wiretapping Claims Across a Patchwork of State Laws: A Defensible Response Playbook,” a live webinar Co-Sponsored by the Federal Bar Association and myLawCLE. For a free pass, please reach out to Elizabeth Roby and for further details on the webinar, click here.

Also in August, Julia Jacobson, Partner (New York), is joined by Dominic Braithwaite, a member of the firm’s Public Policy Practice, to present “The New Reasonable Security: How AI Has Changed What’s ‘Reasonable’.”  This webinar, sponsored by Law Practice CLE, will explore how AI has changed the cyber threat landscape and the challenges of complying with ‘reasonable’ security requirements in the AI age.  Please contact us for details.

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

Email this postTweet this postLike this postShare this post on LinkedIn

The Guidelines 03/2026 on web scraping in the context of generative AI, adopted by the European Data Protection Board “EDPB” for public consultation on 7 July 2026, are notable not only for what they require but for what they acknowledge. The document is unusually candid about three limitations: an epistemic one (the controller may not always know what it has collected), a technical one (what a model has learned cannot, today, be easily unlearned), and an institutional one (some of the assessments woven into the GDPR analysis sit, at least in part, with other authorities and courts). These acknowledgements are welcome, and they distinguish the text from more declaratory guidance. The tension is that the requirements built on top of them are not always adjusted accordingly, and that gap, between what the EDPB admits and what it nonetheless requires, is where the most interesting questions of the consultation lie.

Briefly, the Guidelines cover scraping performed by private entities, whether carried out in-house, commissioned from a third party or effected through the acquisition of pre-scraped datasets. They work through the familiar sequence: allocation of controller and processor roles, the core principles of Article 5 GDPR (purpose limitation, transparency, minimization, accuracy), the choice of legal basis, with legitimate interest under Article 6(1)(f) GDPR treated as the realistic candidate and consent all but discarded, and the treatment of special categories of data incidentally swept up in the collection, for which the EDPB adapts the CJEU’s GC & Others framework. Little of this structure will surprise anyone who has followed the Board’s recent work on AI. What rewards attention is how each of these familiar steps is made to function once the three limitations above enter the analysis.

Continue Reading Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

The EU Artificial Intelligence (AI) Act requires companies to disclose in certain cases whether content has been created or modified by AI. This also applies to companies that make use of AI such as image-generation programs for product advertising.

Given that the new rules are enforceable from 2 August 2026, with fines up to EUR 15 million or 3% of global annual turnover, the importance of compliance with these rules is now in sharp focus.

The good news is that for deployers of AI systems, besides chatbot disclosure, labelling obligations only apply in two scenarios: (i) AI-generated or manipulated texts aiming at informing the public on matters of public interest, and (ii) deep fakes[1].

Looking at all of this in more detail, what does this mean to companies that create and/or publish advertising and promotional content?

Why AI-Generated or Manipulated Texts on Public Matters Might be a Concern

As one example of AI generated or manipulated texts which inform the public on matters of public interest, the EU Commission’s Draft Guidelines (the latest version being a 2024 draft for stakeholder consultation)[2] list AI-manipulated corporate reports published on a listed company’s website which contain investor information.

By contrast, the EU Commission’s Draft Guidelines assume that the labelling obligation will not apply to:

  • AI-manipulated texts that are part of a company’s advertisements other than text that promotes any claims relating to e.g. health, consumer safety or sustainability
  • AI-generated fictional novels or poems in any genre
  • news summaries by a chatbot that are only available to the user that prompted the chatbot.

A general exemption applies to AI generated or manipulated text that has undergone human review or editorial control and for which a legal or natural person holds editorial responsibility[3].

Deep Fakes


What seems more challenging for companies promoting or selling products on their websites, in catalogues, on billboards, on TV and social media or other means of advertising, is the obligation to disclose AI generated or manipulated image, audio or video content constituting a deep fake. The term “deep fake” is defined in Article 3(60) of the AI Act as

AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”.

Whilst there are good reasons for extending the definition of “deep fake” beyond persons, i.e. realistic natural human beings, in view of the dangers involved with simulated events without persons being involved, the inclusion of:

  • objects,
  • places,
  • entities, and
  • events

opens the door for the labelling obligations applying to a broad spectrum of content including product advertisements.

The key question in the individual case is whether such content is likely to deceive or mislead a person regarding its authenticity or truthfulness. This assessment is to be conducted based on a hypothetical average person expected to be exposed to such content, which is particularly important if advertising is directed at children or groups with lower digital and AI literacy[4].

The sheer variety of options to generate and manipulate content with AI leads to various borderline cases. For example, does color correction, re-scaling, background editing, removal of elements, simulated movement, lighting or seasonal adjustment in relation to product images amount to a deep fake? Most likely not if the lack of authenticity is obvious (e.g. in case of blurred backgrounds) or the manipulation has only a minor impact on the consumer’s perception.

However, images of persons who are made to resemble a celebrity might be caught. The same question may arise in relation to depictions of real persons, for example, an advertisement may use a genuine photograph of a person while AI is merely used to place that person in a kitchen setting where the original image is not taken in a kitchen, or AI is used to change the person’s posture or the shade of the hair.

Practical Considerations

AI-generated or AI-modified content must be clearly labelled in a manner that is easily noticeable to users and remains visible when the content is viewed or shared. Until there is case law available on how strict the labelling requirements are interpreted and how they are fulfilled, the EU AI Office’s Code of Practice on Transparency of AI-Generated Content[5] provides valuable, albeit non-binding practical guidance on the topic.

  • Standardized Icons. This includes freely available standardized EU icons that companies may want to use to comply with the labelling requirements.
  • Size of Icons. As far as the icon’s size is concerned, the only guideline so far is basically that it must be “clear and distinguishable[6].
  • “AI”, “AI Generated” or “AI Modified”. Whether the designation “AI” is sufficient or – as “encouraged” in the Code of Practice (i.e. not binding but recommended) – transparency requires distinguishing between “AI Generated” and “AI Modified”, is still an open question.
  • Implementation of a second layer. According to the Code of Practice, the integration of interactive second layers to enrich the static icons with provenance data and information on what has been modified is currently explored. 
  • Placing icons on images and videos. For images and videos, the disclosure should be displayed prominently within the visible content area and embedded in the metadata; where available, AI watermarks or visual labels should also be used.
  • Audio labelling. Audio content must include a clear audible disclosure.
  • Periodic disclosure. Video and audiovisual content must be labelled at the beginning and, for content exceeding a short period of time, continuously or at regular intervals, with both visual and audio disclosures where applicable.

In view of the legal consequences of violations and sometimes huge amount of content involved, it is no wonder that some prominent retailers have already decided to take the bull by the horns and label any AI created or modified images. All of this will be of interest to manufacturers, retailers and the creators of advertising material. Besides the risk of fines, the new labelling requirements will most likely be deemed provisions intended to regulate market behavior under the laws of unfair competition, opening the door for claims by competitors and watchdog associations, with the consequence that advertising may, by way of a preliminary injunction, be prohibited literally overnight. Companies are therefore well-advised to establish internal guidelines and procedures for AI transparency and closely monitor the developments in the sector to verify on a regular basis whether existing compliance measures require updates.


[1] Article 50(4) AI Act.

[2] The consultation period ended on 3 June 2026.

[3] Article 50(4), subparagraph 2 AI Act.

[4] Cf. Draft Guidelines, p. 28.

[5] https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content.

[6] Article 50(5) AI Act.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

Consistent with the recent strategic shift in policy around EU regulations, the EU’s seventh package of changes to simplify/lighten their burden has just been approved and, with it, we will see changes to the way the EU’s Artificial Intelligence Act will be applied (although some obligations under this legislation are already in force).

The EU’s Council of Ministers and Parliament have agreed to changes and, consistently with the overall themes of previous Omnibus packages, there is an emphasis on slowing things down, reducing burdens for smaller sized companies and seeking to avoid the application of a double regulatory burden where legal obligations under other EU rules are already in place. This is similar to what the EU has done under previous packages with ESG rules under the Corporate Sustainability Reporting Directive, Corporate Due Diligence Directive and the EU Deforestation Regulation (amongst other examples). The changes should be adopted imminently given that the deadlines they are seeking to delay otherwise start to apply in August.

Recall that the approach to (high risk) AI products incorporates the tried and tested conformity assessment and CE marking system that we see with so many consumer products on the EU market. AI products, for all their world-changing promise and potential, are in effect treated no differently in this respect from your average widget that requires to have a CE mark. Thus, where the Omnibus VII package slows down the application of the law and clarifies the various overlaps with specific sectoral laws that already ensure safety (such as the Machinery Regulation), companies developing their products for the AI world, using AI as a safety component for products, or those venturing into the manufacture of products incorporating AI for the first time can be reassured that they are treading a well-worn path, albeit with slightly different considerations (noting that what is ‘high-risk’ in terms of AI does not only depend on the product-regime, but also the particularities of the AI system itself and its intended use). Lawyers are there to interpret the laws (e.g. does your AI system fall within a high-risk category? Is it borderline? What are the arguments that will work that will keep you away from additional regulatory burdens? What are the minimum legal requirements for AI?) and explain the legal value of standards and guidance documents as opposed to specific implementing regulations while, just as importantly, if not more, those same lawyers know how and when to liaise with technical consultants, your in-house experts, technical bodies, etc., as appropriate, to compile the necessary technical documentation and establish the appropriate inhouse systems. In that regard, it will help if your legal team includes lawyers who know their way around CE marking/conformity assessment rules because they do it on a daily basis by reference to the Radio Equipment Directive, or Batteries Regulation or RoHS Directive, for example as much as they are experts in data privacy and digital assets law.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

We are delighted to invite you to our forthcoming events in Asia, where you will have the opportunity to connect with industry peers and hear from our team as they explore emerging trends, regulatory developments, and practical challenges at the intersection of data privacy, AI, and cybersecurity worldwide.

  • IAPP Asia Networking Reception: On July 21 2026, 5:30-8:00 p.m., we are happy to host our annual networking reception celebrating the International Association of Privacy Professionals conference in Singapore.  This will be hosted at our Singapore office at One Marina Boulevard.  As space is limited, if you are interested, please reach out with your name, company, industry and contact details to mogana.ramasamy@squirepb.com and sheela.subramaniam@squirepb.com.
  • IAPP Asia Forum 2026: On July 22 2026, our partner Tanvi Mehta Krensel will be moderating a panel titled “(Age) Verified by Law: Privacy, Anonymity and the New Era of Online Safety”, along with Hailun Ying (Head of PrivSec, Legal at Roblox), Claire Tan Chu Wen (Lead Senior Counsel at Lenovo) and Song Yeong Ng (Deputy Director, Policy and Technology at Singapore Personal Data Protection Commission). It will be hosted at the IAPP Asia Forum between 2:45-3:45 p.m. If you are interested, please register for the Forum here.
  • Data Privacy, Cybersecurity, AI and Child Safety: On July 24 2026, 2:00-3:00 p.m., we will be hosting in our Singapore office a client update of latest developments in data privacy, cybersecurity, AI and child safety, all of which are moving swiftly in the regulatory space. This will feature many of our Data Privacy, Cybersecurity and Digital Assets team members who are visiting Singapore for the IAPP Conference.  It will be hosted at our office at One Marina Boulavard. As space is limited, if you are interested, please reach out with your name, company, industry and contact details to mogana.ramasamy@squirepb.com and sheela.subramaniam@squirepb.com.
  • 23rd China International Compliance Summit 2026: On October 28 or 29 2026, (date being set), Scott Warren will be providing an update on the latest US to China data transfer regulations, impact and class action lawsuits surrounding the US Bulk Data Transfer Rule.  For more information regarding this in-person event in Shanghai, please contact helen.su@linworld-group.com.