Two Senate bills introduced this week — the Stop Spying Bosses Act and the No Robot Bosses Act — represent the most ambitious federal attempt yet to constrain algorithmic management in the workplace. Together they would prohibit employers with eleven or more workers from using AI, biometric surveillance, and behavioral inference tools for consequential HR decisions, and would explicitly bar monitoring for union activity or off-duty conduct. Events [1] and [13] are closely related: SB4833, referred to the Senate Committee on Health, Education, Labor, and Pensions, addresses automated decision systems in employment on a narrower basis, while the paired Stop Spying Bosses and No Robot Bosses bills frame a broader prohibitory regime. Taken together, they signal that federal algorithmic employment accountability — long confined to state experiments in California, Colorado, and Michigan — is now a live Senate priority.
Watch Level: PREPARE (mid-to-large private employers, HR technology vendors, employment counsel)
The EU General Court's dismissal of Apple's challenge to its DMA gatekeeper designation removes a critical legal escape route for platform operators contesting Commission authority. The ruling in Joined Cases T-1079/23, T-1080/23, and T-214/24 confirms that the Commission's classification of the App Store and iOS as core platform services subject to DMA obligations will stand, at least through this stage of review. Platform operators currently contesting or anticipating gatekeeper designations should treat judicial reversal as an unlikely near-term outcome. Compliance planning around DMA obligations — interoperability, self-preferencing prohibitions, data access requirements — should proceed on the assumption that designations will be upheld.
Watch Level: PREPARE (platform operators with potential DMA gatekeeper exposure, EU regulatory counsel)
The European Commission's consultation on data sovereignty and international data flows, open through September 8, 2026, operationalizes the November 2025 Data Union Strategy and could produce binding policy measures affecting how EU organizations handle cross-border data transfers and third-country access. Simultaneously, Spain's AEPD has published a formal analysis warning that eIDAS 2.0's biometric authentication requirements for the EUDI Wallet risk excluding users across physical, economic, and demographic lines — a position that directly challenges current implementation discretion among member states. These two EU-level developments, though procedurally distinct, together signal that the Commission faces mounting regulatory and civil society pressure on both the external data dimension of its digital strategy and the internal inclusion architecture of its flagship identity infrastructure.
Watch Level: MONITOR (EU compliance teams, identity technology vendors, eIDAS implementers, data transfer counsel)
The G7 Data Protection and Privacy Authorities have issued dual statements on child privacy: one addressing privacy-preserving age assurance principles and one targeting data risks from connected home devices. The documents carry persuasive rather than binding authority, but their alignment across nine major regulatory jurisdictions — including the US, EU, UK, Canada, Japan, and South Korea — signals regulatory convergence that typically precedes domestic enforcement guidance or legislative action. Compliance teams in ed-tech, connected device manufacturing, and consumer platform sectors should treat these principles as leading indicators of enforcement expectation in G7 markets.
Watch Level: MONITOR (child-facing platform operators, connected device manufacturers, age assurance technology vendors)
The Illinois frontier AI safety law signed July 6 — previously noted here — has now been formally confirmed as enacted with a January 1, 2027 effective date, giving developers approximately six months to achieve compliance. A civil society coalition in the UK has separately written to the Science, Innovation and Technology Select Committee requesting a parliamentary investigation into the Information Commissioner's Office over alleged failures to enforce data protection law against the Home Office's eVisa scheme. The UK action escalates accountability pressure to the parliamentary level and, if a formal inquiry proceeds, could constrain the ICO's discretion in supervising major government digital identity programmes more broadly.
Watch Level: PREPARE (frontier AI model developers with Illinois exposure) | MONITOR (UK immigration technology vendors, digital identity programme operators, ICO-regulated entities)
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.