European child online safety regulation crystallized on September 16 as the Commission moved toward formally proposing the EU KIDS Act, a framework that would set 15 as the minimum age for unrestricted social media access and introduce a tiered supervised-use model for younger children. The proposal extends the DSA and AI Act enforcement architecture—including supervisory fees on high-risk platforms—to social media, video-sharing services, online games, and AI chatbots. Its appearance reflects sustained pressure from France and other member states to preempt the patchwork of national laws already emerging across the bloc. The text remains in draft and must survive trilogue negotiations before acquiring legal force, but the architecture it signals will set the terms of debate across the sector for the coming legislative cycle.
California's legislature passed three AI employment regulation bills—anchored by SB 947, the 'No Robo Bosses Act'—and forwarded the package to Governor Newsom for action by September 30. A signature would make California the first US state to impose comprehensive restrictions on algorithmic management and automated employment decisions, establishing a de facto national standard for employers with California operations in the absence of any federal analog. The bills reflect an accelerating pattern of state-level AI governance filling the vacuum left by congressional inaction on workplace automation. Employers and HR technology vendors operating in California should treat the September 30 deadline as a compliance trigger requiring legal review of current AI-assisted hiring, performance, and termination systems.
Watch level: PREPARE (employers using AI-driven HR tools in California, HR technology vendors, employment counsel)
The Manhattan District Attorney's takedown of twelve AI-generated non-consensual pornography sites—affecting over 1,200 identified victims—marks a notable escalation in state-level prosecutorial enforcement against AI-facilitated image-based abuse. The action demonstrates that existing state law, applied aggressively, can reach AI content generation operations without waiting for a federal framework. For platforms operating user-generated AI image or video tools, the enforcement underscores exposure under state criminal and civil statutes that predate generative AI. The absence of a comprehensive federal NCII law reinforces the current patchwork trajectory, where prosecutorial capacity and political will at the state level determine enforcement intensity.
Watch level: PREPARE (platforms hosting user-generated AI image or video content, trust and safety counsel, policy teams tracking NCII legislation)
US financial regulators have narrowed a longstanding ambiguity in customer identity verification by formally mapping verifiable digital credentials to existing Customer Identification Program requirements. The September 8 joint guidance from FinCEN, the Federal Reserve, FDIC, NCUA, and OCC covers both government-issued and third-party credentials—as documentary and non-documentary methods, respectively—without endorsing specific providers or creating new supervisory obligations. Proof's simultaneous launch of a reusable VDC product designed around this framework reflects how regulatory clarity rapidly translates into commercial infrastructure deployment. Compliance teams at covered financial institutions should now assess whether their CIP procedures explicitly accommodate VDCs as permissible verification inputs.
Watch level: PREPARE (BSA/AML compliance officers, digital identity vendors serving financial institutions, bank counsel)
South Africa's State Information Technology Agency has issued a tender for police body-worn and dashboard cameras integrated with facial recognition and ALPR, with bids closing September 29. POPIA's broad law enforcement exemptions appear to place the system outside any formal legal oversight mechanism—a gap civil society identified when the statute was enacted and that remains unaddressed. The procurement's undefined budget and scope compound the governance concern, as there is no public baseline against which a future deployment can be evaluated. Regional privacy advocates and compliance observers tracking biometric surveillance governance in sub-Saharan Africa should treat this tender as a precedent-setting procurement.
Watch level: MONITOR (civil society organizations, comparative law researchers, compliance teams with South African operations)
NYDFS has released detailed guidance on cybersecurity risk assessments under its Part 500 framework, narrowing interpretive flexibility for covered entities and establishing a clearer compliance baseline ahead of the next certification cycle. Separately, NIST has finalized guidelines on protecting online identity and access tokens, providing a reference standard that regulators and auditors are likely to cite when evaluating identity management controls across sectors. Both publications reinforce a broader convergence between regulatory expectations and technical standards in cybersecurity governance. Financial services firms and other entities subject to Part 500 should conduct a gap analysis against the NYDFS guidance before their next certification submission.
Watch level: PREPARE (NYDFS-regulated entities, financial sector CISOs, cybersecurity compliance counsel)
Still developing: EU-US Biometric Border Framework forwarded to Council ahead of December VWP deadline: no material change since last reported; the framework awaits Council action. California SB 690 eliminating private CIPA pen register claims: no material change since last reported; bill awaits Governor's signature. Revolut fraudulent emergency data request disclosure: no material change since last reported; incident under regulatory review. EFF ALPR audit log findings: no material change since last reported; legislative and vendor responses pending.
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.