<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>CyberEyeQ Weekly Podcast</title>
<link>https://cybereyeq.github.io/podcast/</link>
<atom:link href="https://cybereyeq.github.io/podcast/feed.xml" rel="self" type="application/rss+xml"/>
<language>en-us</language>
<copyright>(c) 2026 CyberEyeQ</copyright>
<description>Two hosts break down enforcement actions, compliance deadlines, and policy developments across AI governance, privacy, cybersecurity, financial services, healthcare, and child safety regulation. Produced from CyberEyeQ's daily regulation tracking pipeline.</description>
<itunes:subtitle>10-minute weekly briefings on the regulatory stories that actually matter</itunes:subtitle>
<itunes:summary>Two hosts break down enforcement actions, compliance deadlines, and policy developments across AI governance, privacy, cybersecurity, financial services, healthcare, and child safety regulation. Produced from CyberEyeQ's daily regulation tracking pipeline.</itunes:summary>
<itunes:author>CyberEyeQ</itunes:author>
<itunes:owner>
  <itunes:name>CyberEyeQ</itunes:name>
  <itunes:email>info@cybereyeq.com</itunes:email>
</itunes:owner>
<itunes:image href="https://cybereyeq.github.io/podcast/cover.jpg"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:explicit>false</itunes:explicit>
<itunes:type>episodic</itunes:type>
<lastBuildDate>Thu, 21 May 2026 11:41:04 +0000</lastBuildDate>
<item>
<title>Episode 22: CIRCIA Still Missing + EU AI Transparency August 2 + CT Neural Data</title>
<itunes:title>Episode 22: CIRCIA Still Missing + EU AI Transparency August 2 + CT Neural Data</itunes:title>
<itunes:episode>22</itunes:episode>
<itunes:episodeType>full</itunes:episodeType>
<pubDate>Thu, 21 May 2026 12:00:00 +0000</pubDate>
<enclosure url="https://cybereyeq.github.io/podcast/episodes/podcast-2026-05-21.mp3" length="8739117" type="audio/mpeg"/>
<guid isPermaLink="false">cybereyeq-podcast-ep-022</guid>
<itunes:duration>00:09:06</itunes:duration>
<itunes:summary>CIRCIA's final rule is still unpublished past its May 2026 target, leaving 300,000 critical infrastructure entities in limbo with $500K/day penalties ahead. Plus: EU AI Act Article 50 transparency obligations still land August 2, Connecticut pioneers neural data protections, and two sector deadlines hit this week — NERC CIP-003-11 on May 26 and EUDAMED on May 28.</itunes:summary>
<description>CIRCIA's final rule is still unpublished past its May 2026 target, leaving 300,000 critical infrastructure entities in limbo with $500K/day penalties ahead. Plus: EU AI Act Article 50 transparency obligations still land August 2, Connecticut pioneers neural data protections, and two sector deadlines hit this week — NERC CIP-003-11 on May 26 and EUDAMED on May 28.</description>
<content:encoded><![CDATA[<!DOCTYPE html>
<html lang="en">
<head>
  <meta charset="UTF-8">
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  <title>Episode 22: CIRCIA Still Missing + EU AI Transparency Lands August 2 + CT Neural Data</title>
  <style>
    body { margin: 0; padding: 0; background: #f4f4f8; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, 'Helvetica Neue', Arial, sans-serif; color: #1a1a2e; }
    .container { max-width: 680px; margin: 0 auto; padding: 32px 20px; }
    .header { background: #1a1a2e; border-radius: 10px 10px 0 0; padding: 32px; }
    .header h1 { color: #22d3ee; font-size: 22px; margin: 0 0 8px; line-height: 1.3; }
    .header .meta { color: #94a3b8; font-size: 13px; margin: 0; }
    .body-card { background: #fff; border-radius: 0 0 10px 10px; padding: 28px 32px; margin-bottom: 24px; box-shadow: 0 2px 12px rgba(0,0,0,0.07); }
    h2 { font-size: 16px; color: #1a1a2e; border-bottom: 2px solid #e94560; padding-bottom: 6px; margin: 28px 0 14px; }
    h3 { font-size: 14px; color: #1a1a2e; margin: 18px 0 6px; }
    p { font-size: 14px; line-height: 1.7; color: #374151; margin: 0 0 12px; }
    .badge { display: inline-block; font-size: 11px; font-weight: 700; padding: 2px 8px; border-radius: 4px; text-transform: uppercase; letter-spacing: 0.05em; margin-right: 6px; }
    .critical { background: #fee2e2; color: #b91c1c; }
    .high { background: #fef9c3; color: #854d0e; }
    .medium { background: #dbeafe; color: #1d4ed8; }
    ul { padding-left: 20px; margin: 6px 0 12px; }
    li { font-size: 14px; color: #374151; line-height: 1.7; margin-bottom: 4px; }
    a { color: #22d3ee; text-decoration: none; }
    a:hover { text-decoration: underline; }
    .deadline-table { width: 100%; border-collapse: collapse; margin: 12px 0; }
    .deadline-table th { background: #1a1a2e; color: #e2e8f0; font-size: 12px; padding: 8px 12px; text-align: left; }
    .deadline-table td { font-size: 13px; padding: 8px 12px; border-bottom: 1px solid #e5e7eb; }
    .deadline-table tr:nth-child(even) td { background: #f9fafb; }
    .footer { text-align: center; font-size: 12px; color: #6b7280; padding: 16px 0; }
    .feed-cta { background: #1a1a2e; border-radius: 8px; padding: 18px 24px; text-align: center; margin: 20px 0; }
    .feed-cta a { color: #22d3ee; font-weight: 600; font-size: 14px; }
  </style>
</head>
<body>
<div class="container">
  <div class="header">
    <h1>Episode 22: CIRCIA Still Missing + EU AI Transparency Lands August 2 + CT Neural Data</h1>
    <p class="meta">CyberEyeQ Weekly Podcast &middot; May 21, 2026 &middot; ~8 min &middot; Hosts: Alex &amp; Sarah</p>
  </div>
  <div class="body-card">
    <div class="feed-cta">
      <a href="https://cybereyeq.github.io/podcast/feed.xml">Subscribe via RSS</a>
      &nbsp;&middot;&nbsp;
      <a href="https://podcasts.apple.com/podcast/cybereyeq">Apple Podcasts</a>
    </div>

    <h2>This Week in One Minute</h2>
    <p>CIRCIA's final rule remains unpublished past its own May 2026 target — 300,000 critical infrastructure entities in compliance limbo, with $500K/day penalties once the rule lands. The EU AI Act Omnibus is now clearer: Article 50 transparency obligations still hit <strong>August 2, 2026</strong> — that date was NOT moved. China confirmed a comprehensive omnibus AI law is in drafting. Connecticut's AI bill passed the legislature: first US law to classify <strong>neural data</strong> as sensitive personal information, effective July 1. EUDAMED's four mandatory modules go live May 28. NERC CIP-003-11 extends cybersecurity controls to low-impact electric grid sites on May 26.</p>

    <h2>Top 5 Stories</h2>

    <h3><span class="badge critical">Critical</span> 1. CIRCIA Final Rule Still Missing</h3>
    <p>CISA's cyber incident reporting rule missed its own May 2026 target. ~300,000 critical infrastructure entities remain in compliance limbo. DHS funding disruptions cancelled stakeholder town halls; further delay is "increasingly likely." Core requirements — 72-hour incident reporting, 24-hour ransomware payment reporting — are not expected to change. Once published: <strong>$500,000/day penalties apply immediately</strong>.</p>
    <p><strong>Action:</strong> Design compliance programs to the proposed rule now. Do not wait for the final.</p>
    <p><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs">CISA CIRCIA FAQ</a></p>

    <h3><span class="badge high">High</span> 2. EU AI Act: What August 2, 2026 Still Means</h3>
    <p>The Omnibus pushed Annex III deadlines to December 2027 and Annex I to August 2028. But <strong>Article 50(1) transparency obligations stay at August 2, 2026</strong>: deepfake labelling, AI-interaction disclosure, biometric/emotion-recognition notices. Commission's draft guidelines adopt the "average consumer" standard — consultation closes June 3.</p>
    <p><strong>Action:</strong> Map every EU-facing AI surface against Article 50(1) and file a consultation response before June 3.</p>
    <p><a href="https://digital-strategy.ec.europa.eu/en/consultations/consultation-draft-guidelines-transparency-obligations-under-ai-act">EU Article 50 Consultation</a></p>

    <h3><span class="badge high">High</span> 3. Connecticut Pioneers Neural Data Protection</h3>
    <p>Connecticut's AI bill (SB 5) awaits the governor's signature. <strong>Effective July 1:</strong> neural data (BCI, EEG) classified as sensitive requiring opt-in consent. Minor protections expanded to ages 13-17 with a blanket ban on targeted advertising and data sale. The bill also covers frontier AI supply chains, chatbot transparency, employment AI use, and content provenance.</p>
    <p><strong>Action:</strong> Reclassify neural-interface product data as sensitive. Rewire minor-protection flows for CT users before July 1.</p>

    <h3><span class="badge medium">Medium</span> 4. China's Two-Track AI Governance</h3>
    <p><strong>Track 1 (May 17):</strong> State Council confirms comprehensive national AI law in drafting — a single statute to replace CAC's patchwork. No timeline yet. <strong>Track 2 (July 15):</strong> CAC Anthropomorphic AI Interactive Services rules effective — mandatory AI identity disclosure, emotional dependency prohibitions, ban on simulating vulnerable groups for China-facing conversational AI.</p>
    <p><a href="https://www.cac.gov.cn">CAC China</a></p>

    <h3><span class="badge critical">Critical</span> 5. Two Sector Deadlines in 7 Days</h3>
    <p><strong>May 26 — NERC CIP-003-11:</strong> FERC Order No. 918 extends mandatory cybersecurity controls to low-impact Bulk Electric System (BES) Cyber Systems for the first time. Utilities must document physical security, transient cyber asset management, and supply chain risk.</p>
    <p><strong>May 28 — EUDAMED Mandatory Modules:</strong> Actor registration, UDI/Devices, Notified Bodies &amp; Certificates, and Vigilance modules become mandatory across EU MDR/IVDR. Non-compliant manufacturers risk supply-chain disruption.</p>

    <h2>Compliance Action Items</h2>
    <ul>
      <li><strong>Now:</strong> Design CIRCIA compliance to proposed rule — don't wait for the final.</li>
      <li><strong>May 26:</strong> Audit low-impact BES assets against CIP-003-11 requirements.</li>
      <li><strong>May 28:</strong> Verify EUDAMED SRN issuance; complete UDI submissions before deadline.</li>
      <li><strong>June 3:</strong> File EU Article 50 consultation response if you operate generative, biometric, or emotion-recognition AI in the EU.</li>
      <li><strong>July 1:</strong> Reclassify CT neural data as sensitive; rewire minor ad/data protections for ages 13-17.</li>
      <li><strong>July 15:</strong> Audit China-facing conversational AI for CAC Anthropomorphic AI compliance.</li>
      <li><strong>August 2:</strong> EU AI Act Article 50(1) transparency obligations live — deepfake labelling, AI-interaction disclosure, biometric notices.</li>
    </ul>

    <h2>Upcoming Deadlines (60 Days)</h2>
    <table class="deadline-table">
      <tr><th>Date</th><th>Regulation</th><th>Jurisdiction</th><th>Sector</th></tr>
      <tr><td>May 26</td><td>NERC CIP-003-11 effective</td><td>US</td><td>Energy</td></tr>
      <tr><td>May 28</td><td>EUDAMED four mandatory modules</td><td>EU</td><td>Healthcare / MedTech</td></tr>
      <tr><td>June 3</td><td>EU AI Act Article 50 consultation closes</td><td>EU</td><td>AI Governance</td></tr>
      <tr><td>July 1</td><td>Connecticut neural data + privacy + AI amendments</td><td>US / CT</td><td>Privacy / AI</td></tr>
      <tr><td>July 15</td><td>CAC Anthropomorphic AI rules effective</td><td>China</td><td>AI / Conversational AI</td></tr>
      <tr><td>August 2</td><td>EU AI Act Article 50(1) transparency obligations</td><td>EU</td><td>AI Governance</td></tr>
    </table>

    <h2>Resources</h2>
    <ul>
      <li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs">CISA CIRCIA FAQ</a></li>
      <li><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/">EU AI Act Omnibus Council Press Release</a></li>
      <li><a href="https://digital-strategy.ec.europa.eu/en/consultations/consultation-draft-guidelines-transparency-obligations-under-ai-act">EU Article 50 Consultation (closes June 3)</a></li>
      <li><a href="https://www.federalregister.gov/documents/2026/03/24/2026-05711/order-no-918-critical-infrastructure-protection-reliability-standard-cip-003-11-cyber">FERC Order No. 918 — NERC CIP-003-11</a></li>
      <li><a href="https://health.ec.europa.eu/latest-updates/eudamed-four-first-modules-will-be-mandatory-use-28-may-2026-2025-11-27_en">EU Commission EUDAMED Mandatory Modules</a></li>
      <li><a href="https://cybereyeq.github.io/podcast/feed.xml">CyberEyeQ Podcast RSS Feed</a></li>
    </ul>

    <div class="feed-cta">
      <p style="color:#94a3b8; font-size:13px; margin:0 0 6px;">Subscribe to stay current on regulatory compliance</p>
      <a href="https://cybereyeq.github.io/podcast/feed.xml">Add RSS feed to your podcast app</a>
    </div>
  </div>
  <div class="footer">CyberEyeQ &mdash; Actionable Regulatory Intelligence &middot; info@cybereyeq.com</div>
</div>
</body>
</html>
]]></content:encoded>
<itunes:image href="https://cybereyeq.github.io/podcast/cover.jpg"/>
<itunes:explicit>false</itunes:explicit>
</item>
<item>
<title>Episode 21: EU AI Three-Track Locks In + Record $12.75M CCPA Fine + China AI Agents</title>
<itunes:title>Episode 21: EU AI Three-Track Locks In + Record $12.75M CCPA Fine + China AI Agents</itunes:title>
<itunes:episode>21</itunes:episode>
<itunes:episodeType>full</itunes:episodeType>
<pubDate>Thu, 14 May 2026 12:00:00 +0000</pubDate>
<enclosure url="https://cybereyeq.github.io/podcast/episodes/podcast-2026-05-14.mp3" length="8256813" type="audio/mpeg"/>
<guid isPermaLink="false">cybereyeq-podcast-ep-021</guid>
<itunes:duration>00:08:36</itunes:duration>
<itunes:summary>EU AI Act Digital Omnibus reaches political agreement May 7 (Annex III to Dec 2 2027, GPAI still Aug 2 2026). California AG hits GM/OnStar with a record $12.75M CCPA penalty for selling driver telemetry. Plus: Connecticut SB 5 / SB 4 and Colorado SB 26-189 advance, China issues the first horizontal AI-agent regime, CMS freezes new hospice/HHA Medicare enrollments for six months, Luxembourg NIS2 goes live, and FedRAMP CR26 hits public preview.</itunes:summary>
<description>EU AI Act Digital Omnibus reaches political agreement May 7 (Annex III to Dec 2 2027, GPAI still Aug 2 2026). California AG hits GM/OnStar with a record $12.75M CCPA penalty for selling driver telemetry. Plus: Connecticut SB 5 / SB 4 and Colorado SB 26-189 advance, China issues the first horizontal AI-agent regime, CMS freezes new hospice/HHA Medicare enrollments for six months, Luxembourg NIS2 goes live, and FedRAMP CR26 hits public preview.</description>
<content:encoded><![CDATA[<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>CyberEyeQ Weekly Podcast &mdash; Episode 21 (May 14, 2026)</title>
<style>
  body { font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif; max-width: 760px; margin: 2em auto; padding: 0 1em; color: #1a1a1a; line-height: 1.55; }
  h1 { color: #003366; border-bottom: 2px solid #003366; padding-bottom: 0.3em; }
  h2 { color: #003366; margin-top: 1.6em; border-bottom: 1px solid #ccd; padding-bottom: 0.2em; }
  h3 { color: #224; margin-top: 1.2em; }
  .meta { color: #555; font-size: 0.9em; margin-bottom: 1.5em; }
  .badge { background: #003366; color: white; padding: 2px 8px; border-radius: 3px; font-size: 0.8em; font-weight: bold; }
  .deadline { background: #fff3cd; border-left: 4px solid #ffb300; padding: 0.6em 1em; margin: 0.6em 0; }
  .deadline strong { color: #8a6d00; }
  ul { padding-left: 1.4em; }
  li { margin-bottom: 0.45em; }
  a { color: #0055aa; }
  blockquote { background: #f4f6fb; border-left: 4px solid #003366; margin: 1em 0; padding: 0.6em 1em; font-style: italic; }
  .footer { margin-top: 2.5em; padding-top: 1em; border-top: 1px solid #ccd; color: #555; font-size: 0.9em; }
</style>
</head>
<body>

<h1>CyberEyeQ Weekly Podcast</h1>
<p class="meta"><span class="badge">Episode 21</span> &middot; May 14, 2026 &middot; Source: <a href="https://github.com/cybereyeq/results/blob/main/newsletter/output/weekly-2026-05-14.html">Weekly Briefing #20 (May 14, 2026)</a></p>

<blockquote>This week's briefing: Brussels reaches political agreement on the EU AI Act Digital Omnibus (Annex III slips to Dec 2 2027); California AG secures a record $12.75M CCPA penalty against GM/OnStar for selling driver telemetry; Connecticut and Colorado pass new AI laws; China issues the world's first horizontal regime for autonomous AI agents; CMS freezes new hospice and home-health enrollments nationwide for six months; Luxembourg's NIS2 goes live; FedRAMP CR26 enters public preview.</blockquote>

<h2>Top 5 Stories</h2>

<h3>1. EU AI Act Digital Omnibus &mdash; Political Agreement, Annex III to Dec 2 2027</h3>
<p>On May 7 the Council and Parliament reached political agreement on the EU AI Act Digital Omnibus. <strong>Annex III high-risk obligations slip to December 2, 2027</strong>; AI embedded in Annex I regulated products moves to <strong>August 2, 2028</strong>; <strong>GPAI enforcement still goes live August 2, 2026</strong>; and nudification apps are now banned EU-wide. Risk: governance teams treat the postponement as a pause and miss the GPAI date and the November 2 2026 watermarking obligation.</p>
<p>Source: <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">European Commission &mdash; AI Act regulatory framework</a></p>

<h3>2. California AG &mdash; Record $12.75M CCPA Penalty Against GM &amp; OnStar</h3>
<p>The California Attorney General secured a <strong>$12.75 million CCPA penalty</strong> against General Motors and OnStar for selling driver geolocation and telemetry data without proper notice or opt-out. The figure is roughly 4.6&times; the prior Disney/ABC CCPA record. Notable for connected-vehicle and IoT-data programs &mdash; the AG is now pricing sensitive-attribute sales materially above prior baselines.</p>
<p>Source: <a href="https://oag.ca.gov/privacy/ccpa">California Attorney General &mdash; CCPA enforcement</a></p>

<h3>3. Connecticut SB 5 / SB 4 and Colorado SB 26-189 &mdash; State AI &amp; Privacy Wave</h3>
<p>Connecticut passed <strong>SB 5 (AI)</strong> and <strong>SB 4 (privacy &amp; data brokers)</strong> on May 1; Colorado passed <strong>SB 26-189 on May 9</strong> to replace its stayed AI Act. Both Connecticut bills and the Colorado bill are awaiting governor signatures. Pattern continues: state-level AI/privacy frameworks are filling federal gaps and creating compounding multi-state compliance work.</p>
<p>Source: <a href="https://www.cga.ct.gov/">Connecticut General Assembly</a> &middot; <a href="https://leg.colorado.gov/">Colorado General Assembly</a></p>

<h3>4. China &mdash; World's First Horizontal AI-Agent Regime (CAC/NDRC/MIIT, May 8)</h3>
<p>On May 8 the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued <strong>Implementation Opinions on autonomous AI agents</strong> &mdash; the first horizontal regulatory regime for agent-based AI anywhere. Headline obligations: <strong>mandatory digital-ID registration for agents</strong>, a <strong>70% smart-terminal adoption target by 2027</strong>, and supply-chain accountability requirements for terminal manufacturers. Multinational AI deployments with a China nexus need to plan for an agent-registration pathway.</p>
<p>Source: <a href="http://www.cac.gov.cn/">Cyberspace Administration of China</a></p>

<h3>5. CMS Hospice / HHA Enrollment Moratorium &mdash; Six Months, Nationwide</h3>
<p>On May 13 the Centers for Medicare &amp; Medicaid Services imposed a <strong>nationwide six-month moratorium on new Medicare enrollments for hospice agencies and home health agencies</strong> under the Anti-Fraud Task Force. Most majority-ownership changes are also paused. Existing providers and current patients are unaffected. The moratorium may be extended in six-month increments. Healthcare M&amp;A counsel: pause hospice/HHA transactions or expect change-of-ownership delays.</p>
<p>Source: <a href="https://www.cms.gov/newsroom">CMS &mdash; Newsroom</a></p>

<h2>Compliance Action Items</h2>

<div class="deadline"><strong>May 19, 2026 (5 days) &mdash; FTC Take It Down Act &sect;3 takedown obligations effective.</strong> Covered platforms must operationalize a notice-and-takedown process for non-consensual intimate imagery and remove valid-request content (and known identical copies) within 48 hours. Trust &amp; Safety: confirm intake form is live, dedup/hash-matching pipeline is operational, and 48-hour SLA telemetry feeds the audit log.</div>

<div class="deadline"><strong>May 28, 2026 (14 days) &mdash; EUDAMED four-module mandatory use.</strong> Actor registration, UDI/Devices, Notified Bodies &amp; Certificates, and Vigilance modules become mandatory across the EU MDR/IVDR perimeter. MedTech RA: verify SRN issuance and complete UDI submissions before this date.</div>

<div class="deadline"><strong>June 11, 2026 &mdash; EU CRA Member-State conformity-assessment-body designation.</strong> Member States must designate CABs under the Cyber Resilience Act framework.</div>

<div class="deadline"><strong>June 19, 2026 &mdash; UK DUAA mandatory complaints-procedure deadline.</strong></div>

<div class="deadline"><strong>End of June 2026 &mdash; FedRAMP CR26 final.</strong> Public preview launched May 4; final by end of June; in force early July; baseline runs through December 31, 2028. Cloud providers seeking federal authorization: review the preview now.</div>

<div class="deadline"><strong>August 2, 2026 &mdash; EU AI Act GPAI obligations operative.</strong> Despite the Annex III/Annex I postponements, general-purpose AI enforcement is still on the original timeline.</div>

<div class="deadline"><strong>November 2, 2026 &mdash; EU AI Act watermarking obligation.</strong> Any organisation creating synthetic media. Don't let the Annex III/Annex I postponements push this date out of view.</div>

<div class="deadline"><strong>December 2, 2027 &mdash; EU AI Act Annex III high-risk obligations (revised).</strong></div>

<h2>Enforcement Watch</h2>
<ul>
  <li><strong>California AG &mdash; $12.75M CCPA penalty against GM/OnStar</strong> for selling driver geolocation/telemetry; ~4.6&times; the prior Disney/ABC record.</li>
  <li><strong>CMS &mdash; Six-month nationwide moratorium on new hospice/HHA Medicare enrollments</strong> effective May 13 under the Anti-Fraud Task Force.</li>
  <li><strong>Luxembourg &mdash; NIS2 transposition went live May 10</strong>; EU tally now ~23 of 27 Member States transposed.</li>
  <li><strong>CISA &mdash; CIRCIA final rule still pending</strong>; the May target window closed without publication.</li>
</ul>

<h2>Resources &amp; References</h2>
<ul>
  <li><a href="https://github.com/cybereyeq/results/blob/main/newsletter/output/weekly-2026-05-14.html">Full Weekly Briefing #20 (May 14, 2026) on GitHub</a></li>
  <li><a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">European Commission &mdash; AI Act regulatory framework</a></li>
  <li><a href="https://oag.ca.gov/privacy/ccpa">California Attorney General &mdash; CCPA</a></li>
  <li><a href="https://www.cga.ct.gov/">Connecticut General Assembly</a></li>
  <li><a href="https://leg.colorado.gov/">Colorado General Assembly</a></li>
  <li><a href="http://www.cac.gov.cn/">Cyberspace Administration of China</a></li>
  <li><a href="https://www.cms.gov/newsroom">CMS &mdash; Newsroom</a></li>
  <li><a href="https://www.fedramp.gov/">FedRAMP</a></li>
  <li><a href="https://www.ftc.gov/">Federal Trade Commission</a></li>
  <li><a href="https://cybereyeq.github.io/podcast/feed.xml">CyberEyeQ Podcast RSS feed</a></li>
</ul>

<div class="footer">
  <p>CyberEyeQ Weekly is an automated regtech-intelligence digest. The dialogue is generated from the weekly newsletter; treat the show notes and the underlying primary-source links as authoritative.</p>
  <p>RSS: <a href="https://cybereyeq.github.io/podcast/feed.xml">https://cybereyeq.github.io/podcast/feed.xml</a></p>
</div>

</body>
</html>
]]></content:encoded>
<itunes:image href="https://cybereyeq.github.io/podcast/cover.jpg"/>
<itunes:explicit>false</itunes:explicit>
</item>
<item>
<title>Episode 20: EU AI Three-Track Timeline + EUDAMED Deadline + China Crypto Marketing Ban</title>
<itunes:title>Episode 20: EU AI Three-Track Timeline + EUDAMED Deadline + China Crypto Marketing Ban</itunes:title>
<itunes:episode>20</itunes:episode>
<itunes:episodeType>full</itunes:episodeType>
<pubDate>Thu, 07 May 2026 12:00:00 +0000</pubDate>
<enclosure url="https://cybereyeq.github.io/podcast/episodes/podcast-2026-05-07.mp3" length="7401261" type="audio/mpeg"/>
<guid isPermaLink="false">cybereyeq-podcast-ep-020</guid>
<itunes:duration>00:07:43</itunes:duration>
<itunes:summary>Three-week look at the regtech week-of-April-30: EU Digital Omnibus on AI emerges as a three-track program (watermarking Nov 2 2026, Annex III Dec 2 2027, Annex I Aug 2 2028), HHS OCR's $1.165M four-settlement HIPAA ransomware bundle, today's Ofcom OSA platform deadline, China's eight-agency online crypto-marketing ban, and the EDPB's 25-DPA Article 12-14 transparency sweep. EUDAMED four-module mandatory use lands May 28.</itunes:summary>
<description>Three-week look at the regtech week-of-April-30: EU Digital Omnibus on AI emerges as a three-track program (watermarking Nov 2 2026, Annex III Dec 2 2027, Annex I Aug 2 2028), HHS OCR's $1.165M four-settlement HIPAA ransomware bundle, today's Ofcom OSA platform deadline, China's eight-agency online crypto-marketing ban, and the EDPB's 25-DPA Article 12-14 transparency sweep. EUDAMED four-module mandatory use lands May 28.</description>
<content:encoded><![CDATA[<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>CyberEyeQ Weekly Podcast — Episode 20 (May 7, 2026)</title>
<style>
  body { font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif; max-width: 760px; margin: 2em auto; padding: 0 1em; color: #1a1a1a; line-height: 1.55; }
  h1 { color: #003366; border-bottom: 2px solid #003366; padding-bottom: 0.3em; }
  h2 { color: #003366; margin-top: 1.6em; border-bottom: 1px solid #ccd; padding-bottom: 0.2em; }
  h3 { color: #224; margin-top: 1.2em; }
  .meta { color: #555; font-size: 0.9em; margin-bottom: 1.5em; }
  .badge { background: #003366; color: white; padding: 2px 8px; border-radius: 3px; font-size: 0.8em; font-weight: bold; }
  .deadline { background: #fff3cd; border-left: 4px solid #ffb300; padding: 0.6em 1em; margin: 0.6em 0; }
  .deadline strong { color: #8a6d00; }
  ul { padding-left: 1.4em; }
  li { margin-bottom: 0.45em; }
  a { color: #0055aa; }
  blockquote { background: #f4f6fb; border-left: 4px solid #003366; margin: 1em 0; padding: 0.6em 1em; font-style: italic; }
  .footer { margin-top: 2.5em; padding-top: 1em; border-top: 1px solid #ccd; color: #555; font-size: 0.9em; }
</style>
</head>
<body>

<h1>CyberEyeQ Weekly Podcast</h1>
<p class="meta"><span class="badge">Episode 20</span> &middot; May 7, 2026 &middot; Source: <a href="https://github.com/cybereyeq/results/blob/main/newsletter/output/weekly-2026-04-30.md">Weekly Briefing #19 (April 30, 2026)</a></p>

<blockquote>This week's briefing: the EU Digital Omnibus on AI moves into a three-track compliance program; HHS OCR bundles four HIPAA ransomware settlements; Ofcom's OSA platform-response deadline lands; eight Chinese regulators ban online crypto marketing; and the EDPB launches a 25-DPA transparency sweep.</blockquote>

<h2>Top 5 Stories</h2>

<h3>1. EU Digital Omnibus on AI &mdash; Three-Track Compliance Program Emerges</h3>
<p>The April 28 trilogue reached political agreement on the AI Act timeline split. Proposed deadlines: <strong>watermarking obligation Nov 2, 2026</strong>; <strong>Annex III high-risk systems Dec 2, 2027</strong>; <strong>Annex I embedded AI Aug 2, 2028</strong>. Risk: governance teams treat the postponement as a pause and miss the Nov 2026 watermarking date.</p>
<p>Source: <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">European Commission &mdash; AI Act</a></p>

<h3>2. HHS OCR HIPAA Ransomware Bundle &mdash; $1.165M Across Four Settlements</h3>
<p>OCR settled four investigations on April 23, 2026: Regional Women's Health Group/Axia (37,989 affected), Assured Imaging, Star Group L.P. Health Benefits Plan, and Consociate Health. 427K individuals affected total. 2-year corrective action plans on each. Risk Analysis Initiative now extends to <em>risk management</em>, not just analysis.</p>
<p>Source: <a href="https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html">HHS &mdash; OCR Settles Four Ransomware Investigations</a></p>

<h3>3. UK Ofcom Online Safety Act &mdash; Mandatory Platform Submissions</h3>
<p>April 30 was the mandatory deadline for Facebook, Instagram, Roblox, Snapchat, TikTok, and YouTube to provide written submissions on under-18 protection measures. Six post-OSA age-assurance fines totalling &pound;2.3M+ already logged. Non-response or weak response expected to drive the next enforcement wave through May.</p>
<p>Source: <a href="https://www.ofcom.org.uk/online-safety/protecting-children/">Ofcom &mdash; Protecting Children</a></p>

<h3>4. China &mdash; PBOC + Seven Agencies Ban Online Crypto Marketing</h3>
<p>The Financial Product Online Marketing Management Measures, issued April 24, 2026 by PBOC plus seven other regulators (effective <strong>September 30, 2026</strong>), explicitly prohibit online marketing for virtual-currency issuance and trading. Also bans misleading promotional language ("low barrier", "instant funding"), requires loan products to display annualised interest rates, and limits live-stream financial promoters to direct employees of licensed institutions. Liability sits squarely on the platform.</p>
<p>Source: <a href="http://www.pbc.gov.cn/">People's Bank of China</a></p>

<h3>5. EDPB Coordinated Enforcement Framework &mdash; Transparency Sweep</h3>
<p>The European Data Protection Board launched its 2026 Coordinated Enforcement Framework focused on GDPR Articles 12&ndash;14 transparency obligations. <strong>Twenty-five Data Protection Authorities</strong> are participating. The throughline for 2026: "say what you do, in writing, before you do it." Disclosure design is no longer a late-stage task.</p>
<p>Source: <a href="https://www.edpb.europa.eu/our-work-tools/our-documents/coordinated-enforcement-framework_en">EDPB &mdash; Coordinated Enforcement Framework</a></p>

<h2>Compliance Action Items</h2>

<div class="deadline"><strong>May 4, 2026 (past) &mdash; CISA KEV remediation.</strong> Eight-CVE batch (PaperCut, JetBrains TeamCity, three Cisco CVEs) for FCEB agencies under BOD 22-01. Private-sector benchmark. If you missed it: confirm patches in place and document remediation evidence.</div>

<div class="deadline"><strong>May 28, 2026 (21 days) &mdash; EUDAMED four-module mandatory use.</strong> Actor registration, UDI/Devices, Notified Bodies &amp; Certificates, Vigilance modules become mandatory across the EU MDR/IVDR perimeter. MedTech regulatory affairs &mdash; verify SRN issuance and complete UDI submissions before this date.</div>

<div class="deadline"><strong>June 1, 2026 &mdash; CMS CY2027 MA / Part D final rule effective.</strong></div>

<div class="deadline"><strong>June 11, 2026 &mdash; EU CRA Member-State conformity-assessment-body designation.</strong></div>

<div class="deadline"><strong>June 19, 2026 &mdash; UK DUAA mandatory complaints-procedure deadline.</strong></div>

<div class="deadline"><strong>June 30, 2026 &mdash; Colorado AI Act enforcement clock (absent further amendments).</strong></div>

<div class="deadline"><strong>September 30, 2026 &mdash; China Financial Product Online Marketing Measures effective.</strong> Multinational platforms with a China nexus: expect inspection campaigns. Audit affiliate-link and in-stream commerce flows for crypto and financial-product references.</div>

<div class="deadline"><strong>November 2, 2026 &mdash; EU AI Act watermarking obligation.</strong> Any organisation creating synthetic media. Don't let the Annex III/Annex I postponements push this date out of view.</div>

<h2>Enforcement Watch</h2>
<ul>
  <li><strong>OCR HIPAA Ransomware Bundle &mdash; $1,165,000 across 4 settlements (April 23, 2026).</strong> Largest single-day Risk Analysis Initiative bundle since October 2024.</li>
  <li><strong>CFTC + SDNY parallel insider-trading action (April 23).</strong> First-of-its-kind on a CFTC-regulated prediction market.</li>
  <li><strong>Ofcom post-OSA age-assurance fines &mdash; &pound;2.3M+ cumulative</strong> across six actions.</li>
  <li><strong>FTC OkCupid / Match Group privacy settlement.</strong> First Section 5 privacy settlement under Chair Ferguson.</li>
</ul>

<h2>Resources &amp; References</h2>
<ul>
  <li><a href="https://github.com/cybereyeq/results/blob/main/newsletter/output/weekly-2026-04-30.md">Full Weekly Briefing #19 (April 30, 2026) on GitHub</a></li>
  <li><a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">European Commission &mdash; AI Act regulatory framework</a></li>
  <li><a href="https://health.ec.europa.eu/latest-updates/eudamed-four-first-modules-will-be-mandatory-use-28-may-2026-2025-11-27_en">European Commission &mdash; EUDAMED four first modules mandatory 28 May 2026</a></li>
  <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA &mdash; Known Exploited Vulnerabilities Catalog</a></li>
  <li><a href="https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html">HHS &mdash; OCR ransomware-investigations press release</a></li>
  <li><a href="https://www.ofcom.org.uk/online-safety/protecting-children/">Ofcom &mdash; Online Safety: Protecting Children</a></li>
  <li><a href="https://www.edpb.europa.eu/our-work-tools/our-documents/coordinated-enforcement-framework_en">EDPB &mdash; Coordinated Enforcement Framework</a></li>
  <li><a href="https://cybereyeq.github.io/podcast/feed.xml">CyberEyeQ Podcast RSS feed</a></li>
</ul>

<div class="footer">
  <p>CyberEyeQ Weekly is an automated regtech-intelligence digest. The dialogue is generated from the weekly newsletter; treat the show notes and the underlying primary-source links as authoritative.</p>
  <p>RSS: <a href="https://cybereyeq.github.io/podcast/feed.xml">https://cybereyeq.github.io/podcast/feed.xml</a></p>
</div>

</body>
</html>
]]></content:encoded>
<itunes:image href="https://cybereyeq.github.io/podcast/cover.jpg"/>
<itunes:explicit>false</itunes:explicit>
</item>
<item>
<title>Episode 19: EU Digital Omnibus Lands + $1.165M HIPAA Ransomware Bundle</title>
<itunes:title>Episode 19: EU Digital Omnibus Lands + $1.165M HIPAA Ransomware Bundle</itunes:title>
<itunes:episode>19</itunes:episode>
<itunes:episodeType>full</itunes:episodeType>
<pubDate>Thu, 30 Apr 2026 12:00:00 +0000</pubDate>
<enclosure url="https://cybereyeq.github.io/podcast/episodes/podcast-2026-04-30.mp3" length="7661613" type="audio/mpeg"/>
<guid isPermaLink="false">cybereyeq-podcast-ep-019</guid>
<itunes:duration>00:07:59</itunes:duration>
<itunes:summary>EU AI Act Digital Omnibus hits political agreement at the April 28 trilogue with a three-track new timeline (Annex III Dec 2 2027, Annex I Aug 2 2028, watermarking Nov 2 2026). Plus: OCR's $1.165M four-settlement HIPAA ransomware bundle, today's Ofcom OSA platform deadline, China's eight-agency crypto-marketing ban, and the EDPB's 25-DPA transparency sweep.</itunes:summary>
<description>EU AI Act Digital Omnibus hits political agreement at the April 28 trilogue with a three-track new timeline (Annex III Dec 2 2027, Annex I Aug 2 2028, watermarking Nov 2 2026). Plus: OCR's $1.165M four-settlement HIPAA ransomware bundle, today's Ofcom OSA platform deadline, China's eight-agency crypto-marketing ban, and the EDPB's 25-DPA transparency sweep.</description>
<content:encoded><![CDATA[<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>CyberEyeQ Weekly — Episode 19 (April 30, 2026)</title>
<style>
  body { font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, sans-serif; max-width: 720px; margin: 0 auto; padding: 24px; line-height: 1.55; color: #1a1a1a; }
  h1 { font-size: 26px; margin-bottom: 4px; }
  h2 { font-size: 20px; margin-top: 32px; padding-bottom: 6px; border-bottom: 2px solid #e0e0e0; }
  h3 { font-size: 16px; margin-top: 22px; color: #2c3e50; }
  .meta { color: #666; font-size: 14px; margin-bottom: 24px; }
  .badge { display: inline-block; padding: 2px 8px; background: #f0f4f8; border-radius: 4px; font-size: 12px; margin-right: 6px; color: #2c3e50; }
  ul { padding-left: 22px; }
  li { margin-bottom: 6px; }
  a { color: #1a5490; text-decoration: none; }
  a:hover { text-decoration: underline; }
  .deadline { background: #fff7e6; border-left: 4px solid #d97706; padding: 10px 14px; margin: 12px 0; }
  .source { font-size: 13px; color: #666; margin-top: 4px; }
  .footer { margin-top: 40px; padding-top: 16px; border-top: 1px solid #e0e0e0; font-size: 13px; color: #666; }
</style>
</head>
<body>

<h1>Episode 19: EU Digital Omnibus Lands + $1.165M HIPAA Ransomware Bundle</h1>
<p class="meta">CyberEyeQ Weekly · April 30, 2026 · ~9 minutes</p>

<p>This week's five stories: the EU Digital Omnibus on AI hits political agreement at the April 28 trilogue with a three-track new timeline; OCR settles four ransomware investigations on a single day; Ofcom's hard platform-response deadline lands today; eight Chinese regulators outlaw online marketing of crypto and other illegal financial products; and the EDPB launches a 25-DPA coordinated enforcement sweep on GDPR transparency.</p>

<h2>Top 5 Stories</h2>

<h3>1. EU Digital Omnibus on AI — Political agreement at April 28 trilogue</h3>
<p>The trilogue converged on three structural changes: Annex III high-risk standalone systems postponed to <strong>December 2, 2027</strong>; Annex I AI embedded in regulated products to <strong>August 2, 2028</strong>; and a watermarking obligation for AI-generated content on <strong>November 2, 2026</strong>. Note: this is political agreement, not yet legal enactment — until Official Journal publication, August 2, 2026 remains operative.</p>
<div class="source">Sources:
  <a href="https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai">European Parliament Legislative Train</a> ·
  <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">European Commission — AI regulatory framework</a> ·
  <a href="https://www.aoshearman.com/en/insights/digital-omnibus-on-ai-what-is-really-on-the-table-as-trilogues-begin">A&amp;O Shearman — Digital Omnibus trilogue analysis</a>
</div>

<h3>2. HHS OCR HIPAA Ransomware Bundle — $1.165M, four settlements (April 23)</h3>
<p>OCR settled four ransomware investigations on April 23: Regional Women's Health Group / Axia (37,989 affected), Assured Imaging, Star Group L.P. Health Benefits Plan, and Consociate Health. Total payments $1,165,000; 427,000 individuals affected; two-year corrective action plans on each. Largest single-day Risk Analysis Initiative bundle since October 2024. Posture shifts from <em>risk analysis</em> to <em>risk management</em> evidence.</p>
<div class="source">Source:
  <a href="https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html">HHS — OCR settles four ransomware investigations</a>
</div>

<h3>3. Ofcom OSA platform-response deadline — Today (April 30)</h3>
<p>Mandatory written submissions due today from Facebook, Instagram, Roblox, Snapchat, TikTok, and YouTube on under-18 protection measures under the UK Online Safety Act 2023. Six post-OSA age-assurance fines totalling £2.3M+ already logged. Non-response expected to feed Ofcom's next enforcement wave through May.</p>
<div class="source">Source:
  <a href="https://www.ofcom.org.uk/online-safety/protecting-children/">Ofcom — Protecting Children</a>
</div>

<h3>4. China — Eight-agency Financial Product Online Marketing Measures (April 24)</h3>
<p>PBOC + MIIT + SAMR + NFRA + CSRC + NIPA + CAC + SAFE released the Financial Product Online Marketing Management Measures (金融产品网络营销管理办法), <strong>effective September 30, 2026</strong>. Bans misleading promotional language; requires loan products to display annualised rates; restricts live-stream/short-video promoters to direct employees of licensed institutions; <em>explicitly prohibits online marketing services for virtual currency issuance and trading</em>.</p>
<div class="source">Sources:
  <a href="https://www.bastillepost.com/global/article/5808096-china-adopts-measures-to-regulate-online-marketing-of-financial-products">Bastille Post — China adopts marketing measures</a> ·
  <a href="https://www.tradingview.com/news/cointelegraph:ad28bf74e094b:0-china-s-new-online-marketing-rules-tighten-ban-on-crypto-promotions/">Cointelegraph — Crypto promotion ban</a>
</div>

<h3>5. EDPB 2026 Coordinated Enforcement Framework — GDPR transparency</h3>
<p>EDPB launched its 2026 CEF on GDPR Articles 12–14 (privacy-notice transparency); 25 supervisory authorities participating. Companion development: Ireland's DPC opened an inquiry into X / Grok using public posts to train an LLM — Article 13/14 question.</p>
<div class="source">Source:
  <a href="https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en">EDPB — 2026 CEF on transparency</a>
</div>

<h2>Compliance Action Items with Deadlines</h2>
<div class="deadline">
  <strong>TODAY · April 30, 2026</strong> — UK platform legal/policy leads (Facebook, Instagram, Roblox, Snapchat, TikTok, YouTube): confirm Ofcom submission filed and audit log retained. <span class="badge">UK · OSA</span>
</div>
<div class="deadline">
  <strong>May 4, 2026 (4 days)</strong> — Federal civilian agencies and benchmarked private-sector teams: remediate the 8-CVE CISA KEV batch (PaperCut, JetBrains TeamCity, Cisco). <span class="badge">US · CISA</span>
</div>
<div class="deadline">
  <strong>May 28, 2026 (28 days)</strong> — MedTech regulatory affairs: complete EUDAMED actor / UDI / Notified Body / Vigilance module registration ahead of mandatory use. <span class="badge">EU · MDR/IVDR</span>
</div>
<div class="deadline">
  <strong>June 19, 2026 (50 days)</strong> — UK organisations: implement DUAA mandatory complaints procedure. <span class="badge">UK · DUAA</span>
</div>
<div class="deadline">
  <strong>September 30, 2026 (155 days)</strong> — Multinational platforms with China nexus: complete financial-promotion content review under PBOC + 7-agency Measures. <span class="badge">China · Financial</span>
</div>
<div class="deadline">
  <strong>November 2, 2026 (188 days)</strong> — AI-generated content producers: implement watermarking under EU AI Act Omnibus track. <span class="badge">EU · AI Act</span>
</div>

<h2>Resources</h2>
<ul>
  <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities Catalog</a></li>
  <li><a href="https://health.ec.europa.eu/latest-updates/eudamed-four-first-modules-will-be-mandatory-use-28-may-2026-2025-11-27_en">European Commission — EUDAMED mandatory use guidance</a></li>
  <li><a href="https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement">FTC — privacy &amp; security enforcement</a></li>
  <li><a href="https://cybereyeq.github.io/podcast/feed.xml">CyberEyeQ Weekly RSS Feed</a></li>
</ul>

<p class="footer">CyberEyeQ — Actionable Regulatory Intelligence. This podcast is for informational purposes only and does not constitute legal advice. Always consult qualified legal counsel for compliance decisions. Contact: <a href="mailto:info@cybereyeq.com">info@cybereyeq.com</a></p>

</body>
</html>
]]></content:encoded>
<itunes:image href="https://cybereyeq.github.io/podcast/cover.jpg"/>
<itunes:explicit>false</itunes:explicit>
</item>
<item>
<title>Episode 18: EU AI Act Countdown + Iranian OT Attacks on US Infrastructure</title>
<itunes:title>Episode 18: EU AI Act Countdown + Iranian OT Attacks on US Infrastructure</itunes:title>
<itunes:episode>18</itunes:episode>
<itunes:episodeType>full</itunes:episodeType>
<pubDate>Sun, 26 Apr 2026 12:00:00 +0000</pubDate>
<enclosure url="https://cybereyeq.github.io/podcast/episodes/podcast-2026-04-26.mp3" length="17265311" type="audio/mpeg"/>
<guid isPermaLink="false">cybereyeq-podcast-ep-018</guid>
<itunes:duration>00:11:59</itunes:duration>
<itunes:summary>EU AI Act Omnibus trilogue targets April 28 for a deal that would push high-risk compliance to December 2027 — but August 2 remains operative until enacted. Plus: Iranian APTs actively attacking US critical infrastructure PLCs, COPPA 2025 now in force, China supply chain data conflicts, and FDA-CMS RAPID device coverage pathway.</itunes:summary>
<description>EU AI Act Omnibus trilogue targets April 28 for a deal that would push high-risk compliance to December 2027 — but August 2 remains operative until enacted. Plus: Iranian APTs actively attacking US critical infrastructure PLCs, COPPA 2025 now in force, China supply chain data conflicts, and FDA-CMS RAPID device coverage pathway.</description>
<content:encoded><![CDATA[<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>CyberEyeQ Weekly — Episode 18: EU AI Act Countdown + Iranian OT Attacks (2026-04-26)</title>
<style>
  body { font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif; max-width: 720px; margin: 0 auto; padding: 24px 16px; color: #1a1a2e; background: #f8f9fc; }
  h1 { font-size: 1.4rem; color: #0d1b2a; margin-bottom: 4px; }
  .meta { color: #555; font-size: 0.85rem; margin-bottom: 28px; }
  h2 { font-size: 1rem; color: #0d1b2a; border-left: 4px solid #2563eb; padding-left: 10px; margin-top: 28px; }
  .story { background: #fff; border-radius: 8px; padding: 16px 20px; margin-bottom: 16px; box-shadow: 0 1px 3px rgba(0,0,0,0.08); }
  .story-title { font-weight: 700; font-size: 1rem; margin-bottom: 6px; }
  .badge { display: inline-block; font-size: 0.72rem; font-weight: 600; border-radius: 4px; padding: 2px 7px; margin-right: 6px; }
  .badge-red { background: #fee2e2; color: #b91c1c; }
  .badge-orange { background: #ffedd5; color: #c2410c; }
  .badge-blue { background: #dbeafe; color: #1d4ed8; }
  p { margin: 6px 0; font-size: 0.92rem; line-height: 1.6; }
  .actions { margin-top: 10px; padding-top: 10px; border-top: 1px solid #f0f0f0; }
  .actions p { font-weight: 600; font-size: 0.82rem; color: #374151; margin-bottom: 4px; }
  ul { margin: 4px 0; padding-left: 20px; }
  li { font-size: 0.88rem; margin-bottom: 3px; line-height: 1.5; }
  .source-link { font-size: 0.82rem; color: #2563eb; }
  .deadlines { background: #fef3c7; border-radius: 8px; padding: 14px 18px; margin-bottom: 20px; }
  .deadlines h2 { border-left-color: #d97706; color: #92400e; margin-top: 0; }
  .deadline-item { display: flex; justify-content: space-between; align-items: center; padding: 5px 0; border-bottom: 1px solid #fde68a; font-size: 0.88rem; }
  .deadline-item:last-child { border-bottom: none; }
  .deadline-date { font-weight: 700; color: #b45309; white-space: nowrap; margin-left: 12px; }
  .resources { background: #eff6ff; border-radius: 8px; padding: 14px 18px; margin-top: 20px; }
  .resources h2 { border-left-color: #3b82f6; margin-top: 0; }
  a { color: #2563eb; text-decoration: none; }
  a:hover { text-decoration: underline; }
  .ep-nav { font-size: 0.82rem; color: #888; margin-bottom: 20px; }
</style>
</head>
<body>

<p class="ep-nav"><a href="https://cybereyeq.github.io/podcast/">← All Episodes</a></p>

<h1>Episode 18: EU AI Act Countdown + Iranian OT Attacks</h1>
<p class="meta">Published: April 26, 2026 &nbsp;·&nbsp; CyberEyeQ Weekly &nbsp;·&nbsp; ~9 min</p>

<div class="deadlines">
  <h2>⏰ Upcoming Deadlines</h2>
  <div class="deadline-item"><span>EU AI Act Omnibus — Trilogue political agreement targeted</span><span class="deadline-date">Apr 28</span></div>
  <div class="deadline-item"><span>OCC GENIUS Act Stablecoin NPRM — Comment deadline</span><span class="deadline-date">May 1</span></div>
  <div class="deadline-item"><span>China CAC Draft Digital Virtual Human Measures — Comment closes</span><span class="deadline-date">May 6</span></div>
  <div class="deadline-item"><span>EUDAMED — Mandatory enforcement begins</span><span class="deadline-date">May 28</span></div>
  <div class="deadline-item"><span>NERC CIP-003-11 — Effective date</span><span class="deadline-date">May 26</span></div>
  <div class="deadline-item"><span>MiCA CASP transitional period ends</span><span class="deadline-date">Jul 1</span></div>
  <div class="deadline-item"><span>EU AI Act high-risk compliance (operative until Omnibus enacted)</span><span class="deadline-date">Aug 2</span></div>
</div>

<h2>This Week's Top 5</h2>

<div class="story">
  <div class="story-title"><span class="badge badge-red">URGENT</span>1. EU AI Act Digital Omnibus — April 28 Trilogue</div>
  <p>The EU Parliament and Council are targeting a political agreement on April 28 that would delay the high-risk AI compliance deadline from <strong>August 2, 2026</strong> to <strong>December 2, 2027</strong> for standalone Annex III systems (and August 2028 for AI in regulated products).</p>
  <p><strong>Critical caveat:</strong> No agreement has been reached yet. August 2, 2026 remains the operative enforcement date (97 days). Do not pause conformity assessments.</p>
  <p>The Omnibus also introduces a new prohibition on AI-generated non-consensual intimate imagery of real, identifiable persons, and softens mandatory AI literacy training to a voluntary industry initiative.</p>
  <div class="actions">
    <p>Action items:</p>
    <ul>
      <li>Monitor April 28 for political agreement announcement</li>
      <li>Continue treating August 2, 2026 as the compliance deadline until Official Journal publication</li>
      <li>Audit image/video generation products against the forthcoming non-consensual intimate imagery prohibition</li>
    </ul>
  </div>
  <p class="source-link">Sources: <a href="https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai" target="_blank">EU Parliament Legislative Train</a> · <a href="https://www.ropesgray.com/en/insights/viewpoints/102mquz/ai-omnibus-trilogue-underwaywhat-to-expect-as-negotiations-progress" target="_blank">Ropes &amp; Gray Analysis</a></p>
</div>

<div class="story">
  <div class="story-title"><span class="badge badge-red">CRITICAL THREAT</span>2. Iranian APT Actively Exploiting US Critical Infrastructure PLCs</div>
  <p>CISA, FBI, NSA, EPA, DOE, and US Cyber Command issued joint advisory <strong>AA26-097A</strong> (April 7, 2026). Iranian-affiliated threat actors have been exploiting internet-facing Rockwell Automation Allen-Bradley PLCs across energy, water, healthcare, and manufacturing since at least March 2026, causing operational disruptions.</p>
  <div class="actions">
    <p>Action items:</p>
    <ul>
      <li>Audit all internet-facing OT/SCADA devices; take offline from public internet immediately where possible</li>
      <li>Review CISA AA26-097A indicators of compromise against OT logs now</li>
      <li>Apply Rockwell Automation security hardening for Allen-Bradley PLCs</li>
      <li>Verify OT-specific incident detection rules are active</li>
    </ul>
  </div>
  <p class="source-link">Sources: <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a" target="_blank">CISA AA26-097A</a> · <a href="https://www.cybersecuritydive.com/news/iran-linked-hackers-targeting-water-energy-in-us-fbi-and-cisa-warn/816949/" target="_blank">Cybersecurity Dive</a></p>
</div>

<div class="story">
  <div class="story-title"><span class="badge badge-red">NOW IN FORCE</span>3. COPPA 2025 Amendments — Compliance Deadline Passed April 22</div>
  <p>The FTC's amended COPPA Rule is now enforceable. No grace period has been announced. Four new obligations are in force:</p>
  <ul>
    <li><strong>Biometric identifiers</strong> (fingerprints, face prints, voice prints) added to COPPA-protected information</li>
    <li><strong>Separate parental consent</strong> required for sharing children's data with third parties for targeted advertising</li>
    <li><strong>Written information security program</strong> and data retention policy with named responsible party required</li>
    <li><strong>New consent methods</strong> approved: text message and knowledge-based authentication</li>
  </ul>
  <div class="actions">
    <p>Action items:</p>
    <ul>
      <li>Verify written WISP and data retention policy are finalized and signed off</li>
      <li>Audit all third-party data sharing flows for children's data; confirm separate consent is live</li>
      <li>Document compliance progress — partial compliance with evidence is better than nothing</li>
    </ul>
  </div>
  <p class="source-link">Sources: <a href="https://www.hunton.com/privacy-and-cybersecurity-law-blog/coppa-rule-amendment-compliance-deadline-approaches" target="_blank">Hunton Andrews Kurth</a> · <a href="https://www.whitecase.com/insight-alert/unpacking-ftcs-coppa-amendments-what-you-need-know" target="_blank">White &amp; Case</a></p>
</div>

<div class="story">
  <div class="story-title"><span class="badge badge-orange">MNC RISK</span>4. China Decrees 834 &amp; 835 — Supply Chain Data Creates Cross-Jurisdictional Conflict</div>
  <p>State Council Decree 834 (effective April 7, 2026) creates China's first supply chain security framework. Article 13 restricts collection/transfer of supply chain data located in China. Article 15 authorizes and Article 16 mandates countermeasures against non-compliant multinationals.</p>
  <p><strong>The conflict:</strong> Compliance with the EU CSDDD or US Uyghur Forced Labor Prevention Act (UFLPA) — both of which require supply chain data collection — may simultaneously violate Decree 834 Article 13. No implementing guidelines or grace periods have been issued.</p>
  <p>Decree 835 (also effective April 7) establishes a Malicious Entity List blocking compliance with certain foreign legal orders.</p>
  <div class="actions">
    <p>Action items:</p>
    <ul>
      <li>Legal review of cross-border supply chain data flows against Decree 834 Article 13 scope</li>
      <li>Assess UFLPA/CSDDD compliance programs for China conflict exposure</li>
      <li>Brief China subsidiary leadership on Article 15/16 countermeasure risk</li>
    </ul>
  </div>
  <p class="source-link">Sources: <a href="https://www.morganlewis.com/pubs/2026/04/china-enacts-first-comprehensive-regulations-on-industrial-and-supply-chain-security" target="_blank">Morgan Lewis</a> · <a href="https://english.www.gov.cn/policies/latestreleases/202604/07/content_WS69d5038cc6d00ca5f9a0a460.html" target="_blank">State Council (English)</a></p>
</div>

<div class="story">
  <div class="story-title"><span class="badge badge-blue">OPPORTUNITY</span>5. FDA-CMS RAPID Pathway — Breakthrough Device Coverage in 2 Months</div>
  <p>FDA and CMS jointly announced the <strong>RAPID</strong> (Regulatory Alignment for Predictable and Immediate Device) coverage pathway on April 23, 2026. Eligible breakthrough devices can receive Medicare national coverage within approximately two months of FDA market authorization — down from one year or more under the current process.</p>
  <p><strong>Eligibility:</strong> FDA Breakthrough Device designation + unmet Medicare beneficiary need + IDE study enrolling Medicare patients.</p>
  <p>A proposed procedural notice will be published in the Federal Register with a 60-day comment period. A separate near-term deadline: EUDAMED mandatory enforcement begins May 28 (32 days) for EU medical device manufacturers.</p>
  <div class="actions">
    <p>Action items:</p>
    <ul>
      <li>Evaluate pipeline devices for RAPID eligibility criteria (breakthrough designation + IDE study with Medicare enrollees)</li>
      <li>Monitor Federal Register for procedural notice; submit comments in the 60-day window</li>
      <li>Confirm EUDAMED registration is complete ahead of May 28</li>
    </ul>
  </div>
  <p class="source-link">Sources: <a href="https://www.fda.gov/news-events/press-announcements/cms-and-fda-announce-rapid-coverage-pathway-accelerate-patient-access-life-changing-medical-devices" target="_blank">FDA Announcement</a> · <a href="https://www.cms.gov/newsroom/press-releases/cms-fda-announce-rapid-coverage-pathway-accelerate-patient-access-life-changing-medical-devices" target="_blank">CMS Press Release</a></p>
</div>

<div class="resources">
  <h2>📚 Resources</h2>
  <ul>
    <li><a href="https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai" target="_blank">EU Parliament Legislative Train — Digital Omnibus on AI</a></li>
    <li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a" target="_blank">CISA Joint Advisory AA26-097A (Iranian PLC Attacks)</a></li>
    <li><a href="https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa" target="_blank">FTC COPPA Rule — Full Text &amp; Amendments</a></li>
    <li><a href="https://english.www.gov.cn/policies/latestreleases/202604/07/content_WS69d5038cc6d00ca5f9a0a460.html" target="_blank">State Council Decree 834 — Industrial &amp; Supply Chain Security</a></li>
    <li><a href="https://www.fda.gov/news-events/press-announcements/cms-and-fda-announce-rapid-coverage-pathway-accelerate-patient-access-life-changing-medical-devices" target="_blank">FDA-CMS RAPID Coverage Pathway Announcement</a></li>
    <li><a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai" target="_blank">EU AI Act — European Digital Strategy</a></li>
    <li><a href="https://cybereyeq.github.io/podcast/" target="_blank">CyberEyeQ Podcast — All Episodes</a></li>
  </ul>
</div>

<p style="font-size:0.78rem;color:#999;margin-top:28px;text-align:center;">CyberEyeQ Weekly · Episode 18 · April 26, 2026 · Generated from CyberEyeQ daily regulation tracking pipeline</p>
</body>
</html>
]]></content:encoded>
<itunes:image href="https://cybereyeq.github.io/podcast/cover.jpg"/>
<itunes:explicit>false</itunes:explicit>
</item>
<item>
<title>Episode 17: COPPA Deadline in 4 Days + China AI Companion Law</title>
<itunes:title>Episode 17: COPPA Deadline in 4 Days + China AI Companion Law</itunes:title>
<itunes:episode>17</itunes:episode>
<itunes:episodeType>full</itunes:episodeType>
<pubDate>Sat, 18 Apr 2026 12:00:00 +0000</pubDate>
<enclosure url="https://cybereyeq.github.io/podcast/episodes/podcast-2026-04-18.mp3" length="14287351" type="audio/mpeg"/>
<guid isPermaLink="false">cybereyeq-podcast-ep-017</guid>
<itunes:duration>00:09:55</itunes:duration>
<itunes:summary>FTC's amended COPPA Rule takes effect April 22 (4 days). China's AI Companion Law passes second NPCSC reading. Plus updates on EU AI Act GPAI compliance and 3 enforcement actions worth tracking.</itunes:summary>
<description>FTC's amended COPPA Rule takes effect April 22 (4 days). China's AI Companion Law passes second NPCSC reading. Plus updates on EU AI Act GPAI compliance and 3 enforcement actions worth tracking.</description>
<content:encoded><![CDATA[<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CyberEyeQ Weekly Podcast — Episode 17 (April 18, 2026)</title>
<style>
body { font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Helvetica, Arial, sans-serif; max-width: 780px; margin: 2em auto; padding: 0 1em; line-height: 1.55; color: #222; }
h1 { border-bottom: 3px solid #0a5; padding-bottom: .25em; }
h2 { color: #0a5; margin-top: 1.6em; }
h3 { color: #444; }
ul { padding-left: 1.4em; }
li { margin-bottom: .4em; }
.meta { color: #555; font-size: .95em; }
.cta { background: #f5f9f6; border-left: 4px solid #0a5; padding: 1em 1.2em; margin-top: 2em; }
.story-num { font-weight: 700; color: #0a5; }
.transcript { border-top: 1px solid #ddd; padding-top: 1em; margin-top: 1.5em; }
.transcript p { margin: .5em 0; }
.speaker-alex { color: #184a8c; font-weight: 600; }
.speaker-sarah { color: #7a2a6f; font-weight: 600; }
.footer { font-size: .85em; color: #777; margin-top: 3em; border-top: 1px solid #eee; padding-top: 1em; }
</style>
</head>
<body>

<h1>CyberEyeQ Weekly Podcast — Episode 17</h1>
<p class="meta"><strong>Date:</strong> April 18, 2026 &middot; <strong>Duration:</strong> ~10 minutes &middot; <strong>Hosts:</strong> Alex Chen &amp; Dr. Sarah Kim</p>
<p>Your weekly briefing on the regulatory stories that actually matter for compliance teams. Sourced from CyberEyeQ Weekly Newsletter Issue #17.</p>

<h2>This Week's Top 5 Stories</h2>
<ul>
<li><span class="story-num">1.</span> <strong>COPPA Amended Rule — Full Compliance Deadline</strong> (April 22, 4 days out). Operators of child-directed services need written security programs, retention policies, and separate verifiable parental consent for non-integral disclosures. Biometric identifiers (voiceprints, faceprints, facial templates) are now protected personal information.</li>
<li><span class="story-num">2.</span> <strong>China Finalizes World's First AI Companion Law</strong>. Interim Measures for Anthropomorphic AI Interaction Services (CAC, NDRC, MIIT, MPS, SAMR), effective July 15, 2026. Blanket ban on virtual intimate relationships for minors; mandatory AI-nature disclosure and 2-hour continuous-use reminders; consent required before interaction data is used for model training. Fines RMB 10,000–200,000 with service-suspension powers.</li>
<li><span class="story-num">3.</span> <strong>FinCEN Proposes Largest AML Overhaul in Decades</strong>. Joint NPRM with OCC, FDIC, NCUA shifts US AML/CFT compliance from an "existence" standard to an "effectiveness" standard. Includes an innovation safe harbor for AI/ML in compliance — a first for US financial regulation. Comments due June 9, 2026.</li>
<li><span class="story-num">4.</span> <strong>EU Cyber Resilience Act — Conformity Body Notification Deadline</strong>. Member States must designate notifying authorities for conformity assessment bodies by <strong>June 11, 2026</strong> (54 days out). Manufacturer reporting obligations for actively exploited vulnerabilities take effect <strong>September 11, 2026</strong>. Covers all products with digital elements placed on the EU market.</li>
<li><span class="story-num">5.</span> <strong>EU Digital Omnibus Trilogue — Targeted April 28</strong>. Political trilogue aims to finalize deal on AI Act high-risk deadline extensions and new prohibited-practice rules. Outcome will shape 2026–2027 AI Act compliance roadmaps.</li>
</ul>

<h2>Action Items This Week</h2>
<ul>
<li>Verify COPPA program covers biometric data and confirm written security / retention policies are operational before <strong>April 22</strong>.</li>
<li>If you operate emotional-AI or companion products with users in China, begin compliance mapping against the <strong>July 15</strong> effective date.</li>
<li>US financial institutions: start drafting a FinCEN comment letter and assess your AML program against the effectiveness standard. Deadline <strong>June 9</strong>.</li>
<li>Watch Colorado AI Act enforcement begin <strong>June 30</strong> (75 days) and EUDAMED mandatory use begin <strong>May 28</strong> (40 days).</li>
</ul>

<div class="transcript">
<h2>Full Transcript</h2>

<p><span class="speaker-alex">Alex:</span> Welcome back to the CyberEyeQ Weekly Podcast. I'm Alex Chen, and this is your ten-minute briefing on the regulatory stories that actually matter for compliance teams. With me as always is Dr. Sarah Kim, our regulatory analyst. Sarah, we have an unusually deadline-heavy week. What should listeners focus on first?</p>

<p><span class="speaker-sarah">Sarah:</span> Alex, the single most urgent item on every compliance calendar right now is the FTC's amended COPPA Rule. Full compliance is due April 22, which is exactly four days from today. Operators of child-directed websites and services must have a written information security program, a written data retention policy, and separate verifiable parental consent for any non-integral data disclosure. On top of that, biometric identifiers — voiceprints, faceprints, facial templates — are now explicitly protected personal information under COPPA.</p>

<p><span class="speaker-alex">Alex:</span> So this is not a drill. What should compliance teams be doing right now?</p>

<p><span class="speaker-sarah">Sarah:</span> Three things. One: verify that your COPPA program covers biometric data, not just traditional identifiers. Two: review your parental consent flows for non-integral disclosures, which is the trickiest new category. Three: confirm your written security and retention policies are documented and actually operational — not sitting in a draft folder. And separately, remember the Senate just passed COPPA 2.0 unanimously, which extends protections to ages 13 through 16. That's on the horizon, but April 22 is the live wire.</p>

<p><span class="speaker-alex">Alex:</span> Let's pivot across the Pacific. On April 10, China finalized what our newsletter calls the world's first AI companion regulation. Walk us through it.</p>

<p><span class="speaker-sarah">Sarah:</span> This is a landmark. Four agencies — the CAC, NDRC, MIIT, MPS, and SAMR — jointly issued the Interim Measures for the Administration of Anthropomorphic AI Interaction Services. Effective July 15, so a 90-day compliance window starts now. The centerpiece is a blanket prohibition on virtual intimate relationships — virtual family members, virtual partners — for minors. All covered services must disclose that the user is interacting with AI, must issue continuous-use reminders every two hours, must obtain separate user consent before using interaction data for model training, and must undergo security assessments if they exceed one million registered users or 100,000 monthly active users.</p>

<p><span class="speaker-alex">Alex:</span> What's the penalty range, and why does this matter outside China?</p>

<p><span class="speaker-sarah">Sarah:</span> Fines run from 10,000 to 200,000 RMB, with service suspension powers available to regulators. But the real significance is global. This is the first regulatory framework anywhere to treat sustained emotional AI interaction as a distinct category requiring specialized oversight. The EU AI Act addresses exploitation of vulnerabilities for specific groups, but not emotional engagement as a category. The US has COPPA for children's data, but nothing specifically about the psychological dynamics of AI companionship. European and US regulators will study this template closely. If you operate companion chatbots or emotional-AI products accessible to Chinese users, compliance mapping needs to start this week.</p>

<p><span class="speaker-alex">Alex:</span> Let's talk about money. FinCEN proposed what the newsletter calls the largest AML overhaul in decades. What's actually changing?</p>

<p><span class="speaker-sarah">Sarah:</span> It's a philosophical shift. For decades, US anti-money laundering compliance has been measured against an existence standard — does your program exist, does it cover the required components. FinCEN's proposed rule, developed jointly with the OCC, FDIC, and NCUA, replaces that with an effectiveness standard — does your program actually work. That's a fundamentally different regulatory posture. The rule also includes an innovation safe harbor that explicitly encourages the use of AI and machine learning in AML compliance without triggering additional enforcement risk. That's a first for US financial regulation.</p>

<p><span class="speaker-alex">Alex:</span> And the comment deadline?</p>

<p><span class="speaker-sarah">Sarah:</span> June 9, so you have roughly 52 days. Banks, credit unions, and money services businesses should be drafting comment letters now. The practical question is whether your current AML program — your transaction monitoring, your customer due diligence, your suspicious activity reporting — can demonstrate effectiveness, not just coverage. Institutions with mature risk analytics are well-positioned. Institutions relying on legacy rules-based systems will need to invest.</p>

<p><span class="speaker-alex">Alex:</span> Over to Europe, but sticking with cybersecurity. The EU Cyber Resilience Act has a conformity body notification deadline coming up on June 11. Why does this matter?</p>

<p><span class="speaker-sarah">Sarah:</span> The CRA is the EU's comprehensive cybersecurity regulation for products with digital elements — everything from consumer IoT to enterprise software. Member States must designate notifying authorities responsible for conformity assessment bodies by June 11, so 54 days from now. That's the infrastructure step. The real operational hammer comes on September 11, when manufacturer reporting obligations for actively exploited vulnerabilities take effect.</p>

<p><span class="speaker-alex">Alex:</span> What should manufacturers be doing now?</p>

<p><span class="speaker-sarah">Sarah:</span> Two things. First, review the CRA conformity assessment requirements for your specific product category — some products will need third-party assessment, others can self-declare, and getting that classification wrong is expensive. Second, engage with the designated notifying authorities in your operating jurisdictions as they come online. If you ship products with digital elements into the EU, this is not optional. And start building your vulnerability disclosure and reporting workflow now, because the September 11 deadline for reporting actively exploited vulnerabilities is an absolute cliff.</p>

<p><span class="speaker-alex">Alex:</span> Last story. The EU Digital Omnibus — there's a political trilogue targeted for April 28, just ten days out. What's at stake?</p>

<p><span class="speaker-sarah">Sarah:</span> The trilogue aims to finalize a political deal on extensions to the AI Act's high-risk system deadlines and on new prohibited-practice rules. For companies that have been building AI Act compliance programs assuming the original deadlines, this could mean more runway — or it could mean new obligations, depending on how the final text lands. The key thing for compliance teams is: don't assume your current AI Act implementation plan is final. Track the April 28 outcome closely, because it will shape your 2026 and 2027 compliance roadmap.</p>

<p><span class="speaker-alex">Alex:</span> Sarah, before we close, three takeaways for compliance teams leaving this podcast.</p>

<p><span class="speaker-sarah">Sarah:</span> First: if you operate any child-directed service, COPPA April 22 is non-negotiable. Verify your written security program, data retention policy, and biometric data controls today. Second: if you operate emotional-AI or companion products, begin China compliance mapping now — the July 15 effective date gives you 90 days and the penalty exposure includes service suspension. Third: if you're a US financial institution, start drafting your FinCEN comment letter this week and begin assessing whether your AML program meets an effectiveness standard, not just an existence standard.</p>

<p><span class="speaker-alex">Alex:</span> And one more to watch. Colorado's AI Act enforcement begins June 30 — that's 75 days from now — for high-risk AI system deployers. If you haven't started your Colorado impact assessments, that deadline is the next one after China.</p>

<p><span class="speaker-sarah">Sarah:</span> Right. And EUDAMED mandatory use for medical device manufacturers begins May 28. That's 40 days out. A lot of calendars are converging this quarter.</p>

<p><span class="speaker-alex">Alex:</span> That's the briefing. Five stories, four urgent deadlines, one clear message: the regulatory velocity is not slowing down. Subscribe to the CyberEyeQ Weekly Newsletter for the full written briefing, the enforcement watch, and our deep dives. Thanks for listening. I'm Alex Chen, she's Dr. Sarah Kim, and we'll see you next week.</p>

<p><span class="speaker-sarah">Sarah:</span> Thanks Alex. Stay compliant out there.</p>

</div>

<div class="cta">
<strong>Subscribe to the CyberEyeQ Weekly Newsletter</strong><br>
Actionable regulatory intelligence across AI governance, financial services, healthcare, cybersecurity, privacy, age verification, cloud security, and China regulation — delivered weekly.<br>
Contact: info@cybereyeq.com
</div>

<p class="footer">Episode sourced from CyberEyeQ Weekly Newsletter Issue #17 (April 16, 2026). All fine amounts, dates, and regulatory details verified against the newsletter source. This podcast is for informational purposes only and does not constitute legal advice.</p>

</body>
</html>
]]></content:encoded>
<itunes:image href="https://cybereyeq.github.io/podcast/cover.jpg"/>
<itunes:explicit>false</itunes:explicit>
</item>
</channel>
</rss>