Child online safety legislation is entering its most consequential phase in the US legislative cycle, while EU supervisory authorities are simultaneously shaping the compliance architecture that will govern AI data practices and financial intelligence sharing for years ahead. Neither development is preliminary: each demands near-term attention from affected organizations.
The House-passed KIDS Online Safety Act package remains alive in today's briefing only because the Senate battle is now the operative story — and it is a harder one. The 267–117 House margin reflects political momentum, but civil liberties organizations including EFF have intensified opposition, framing the bill's age-verification requirements as a structural mandate to collect government IDs or biometric data at scale. That framing is gaining traction in Senate offices. Platforms, ed-tech vendors, and their counsel should be stress-testing compliance architectures now rather than waiting for Senate passage, given the bill's potential to reshape identity verification obligations across the consumer internet.
Watch level: PREPARE (online platforms, ed-tech vendors, social media counsel with US user bases)
The EDPB's guidance on anonymisation and web scraping for generative AI — covered in prior editions as forthcoming — is now published and operative. Organizations training or fine-tuning models on web-scraped data have authoritative GDPR-compatible thresholds to meet and, critically, no further ambiguity to invoke as a compliance defense. The accompanying blockchain guidelines finalize a separate but equally long-awaited interpretive gap. Legal and technical teams should begin gap assessments against both documents immediately, as supervisory authorities across the EU will treat these as the enforcement baseline going forward.
Watch level: PREPARE (AI developers, data engineering teams, DPOs at organizations using web-scraped training data)
The EDPB–AMLA joint guidelines initiative on financial information-sharing partnerships signals a structural realignment between two previously separate supervisory regimes. Financial institutions subject to both GDPR and EU AML obligations have long operated under interpretive tension between the two frameworks. The joint development process gives compliance teams a narrow window to engage — and a clear signal that the output will set binding expectations for data flows between private financial entities and public authorities.
Watch level: MONITOR (EU-regulated banks, payment institutions, AML compliance officers, financial sector DPOs)
Dock Labs' analysis of EUDI Wallet market boundaries is private-sector guidance rather than regulatory output, but its practical utility warrants attention ahead of the 2027 mandatory rollout. The three-pathway framework — relying party, issuer, wallet provider — clarifies which roles require qualified trust service provider status and which do not. UK-headquartered organizations with EU market exposure should note that several framework components, including wallet certification and cross-border revocation, remain under active development and carry interoperability obligations that are not yet fully specified.
Watch level: MONITOR (identity technology vendors, relying parties in EU-regulated sectors, UK organizations with EU digital identity exposure)
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.