G7 data protection authorities have reached multilateral consensus on child privacy and AI governance, issuing joint principles from Paris on June 25–26 under France's CNIL presidency. The declaration covers privacy-respecting age verification, connected device standards for minors, and rights-respecting AI systems — with participation from the EU, US, Canada, Japan, and G7 European states. While non-binding, G7 DPA joint declarations have historically served as precursors to coordinated domestic enforcement priorities and legislative activity. Multinational organizations should treat this output as an early signal of where supervisory attention across major economies is converging.
Watch level: MONITOR (child-facing platform operators, consumer device manufacturers, privacy counsel in G7-market companies)
Two US House bills introduced this week propose distinct but complementary federal AI oversight mechanisms, marking a notable cluster of legislative activity. HR 9477 would require AI model developers to file mandatory reports with the Secretary of Commerce, establishing a disclosure floor for federal visibility into model development. HR 9439, the Voluntary Consumer AI Disclosure Pilot Act, takes a softer approach, proposing a pilot transparency framework before any binding obligations attach. Both bills have been referred to the House Committee on Energy and Commerce, where the fate of the broader federal AI governance agenda will likely be shaped in the coming months.
Watch level: MONITOR (AI developers, foundation model operators, federal affairs counsel)
HR 9482, which would prohibit data brokers from selling or transferring specified categories of sensitive personal data, adds momentum to federal pressure on a largely self-regulated industry. The bill targets the same data broker ecosystem that state AGs and the FTC have pursued through enforcement, suggesting a potential legislative complement to existing regulatory action. Its referral to the House Energy and Commerce Committee places it alongside several other data-related measures competing for committee attention. Organizations in the data brokerage and adtech sectors should treat the accumulation of committee-stage bills as a leading indicator of eventual federal action.
Watch level: MONITOR (data brokers, adtech platforms, consumer data aggregators)
State-level child safety and post-breach enforcement continues to accelerate independent of federal action. The Arkansas AG's actions against Roblox and Discord — previously noted — have drawn additional attention as platforms assess whether Arkansas's legal theories signal coordinated multi-state strategy. The Texas AG's pursuit of Carnival Cruise Line over a data breach, also previously signaled, remains active, reinforcing Texas's posture as a high-volume post-breach enforcement jurisdiction. Consumer-facing platforms with minor users and large-scale data operations should treat both state AG offices as active enforcement risks requiring dedicated compliance monitoring.
Watch level: PREPARE (consumer platform operators with minor users, large-volume data handlers in TX and AR)
HR 9470, proposing strengthened HIPAA protections for pregnancy termination and loss data, signals continued congressional attention to reproductive health privacy in the post-Dobbs environment. The bill would restrict how such information can be processed or disclosed under existing federal health privacy law. Its prospects remain dependent on committee prioritization, but its introduction reflects sustained legislative pressure on health data handlers operating in states where such records could be sought in criminal or civil proceedings. HIPAA-covered entities and their business associates should monitor committee activity and review current data minimization practices for reproductive health data.
Watch level: MONITOR (HIPAA-covered entities, health IT vendors, reproductive health service providers)
The EDPB's updated One-Stop-Shop case digest on erasure and objection rights provides structured precedent on how lead and concerned supervisory authorities have resolved cross-border disputes in these areas. The update is confirmatory rather than novel, but it consolidates enforcement outcomes that compliance teams may not have tracked individually. Organizations managing high volumes of data subject requests across EU member states should review the digest to ensure their handling practices align with the emerging pattern of OSS decisions.
Watch level: AWARENESS (EU-market data controllers, DSR compliance teams)
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.