Low
Guidance
Published
Global · Sep 18, 2026
Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs
The EFF warns that cloud‑based trusted execution environments (TEEs) do not provide the same privacy guarantees as end‑to‑end encryption. When AI features offload message data to TEEs, the content leaves the device and is exposed to…
Low
Guidance
Announced
Global · Sep 18, 2026
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The EFF explains that while trusted execution environments (TEEs) can protect data on cloud servers, they do not provide the same mathematical guarantees as end‑to‑end encryption. Sending message content to a TEE for AI processing creates…
Moderate
Guidance
Published
France · Sep 17, 2026
CNIL outlines its status, organization and sanction powers
The CNIL, created by the 1978 Loi Informatique et Libertés, is an independent administrative authority composed of a college of 18 members. Its restricted board can impose fines up to €20 million or 4 % of global annual turnover under the…
CNIL · loi Informatique et Libertés
Moderate
Guidance
Announced
New York · Sep 17, 2026 · effective Jan 1, 2027
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York Attorney General Letitia James issued an alert encouraging employees with knowledge of unsafe or illegal AI development to submit confidential whistleblower complaints. The alert references the Responsible AI Safety and Education…
New York Attorney General's Office · New York SHIELD Act
Moderate
Guidance
Published
United States (federal) · Sep 16, 2026
EPIC report: Data brokers sell personal data to Disney, GM, insurers and banks
EPIC highlights that data brokers collect and sell personal information to major companies such as Disney, General Motors, insurers and banks. The article notes that brokers infer additional characteristics like finance, health…
Low
Guidance
Announced
United States (federal) · Sep 16, 2026
EPIC report finds companies hinder personal data access under state privacy laws
The Electronic Privacy Information Center reports that many large firms make it difficult for consumers to obtain their personal data, despite state privacy statutes. EPIC notes that small fines and warning letters often have limited…
Low
Guidance
Announced
United States (federal) · Sep 16, 2026
EFF appoints former White House official Alexander Macgillivray to Board of Directors
The Electronic Frontier Foundation announced that Alexander "amac" Macgillivray has joined its Board of Directors. Macgillivray previously served as Deputy Assistant to the President and Principal Deputy U.S. Chief Technology Officer and…
Blueprint for an AI Bill of Rights
Moderate
Guidance
Published
KE · Sep 16, 2026
Kenya publishes new guidance on cross‑border data transfers
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences…
Office of the Data Protection Commissioner (ODPC) · General Data Protection Regulation
Low
Guidance
Announced
United States (federal) · Sep 15, 2026
EPIC senior counsel warns of privacy risks in unproven health technologies
The Washington Post health brief quoted EPIC senior counsel Sara Geoghegan stating that emerging health technologies are unproven and may be riddled with privacy risks. She emphasized that companies must build and demonstrate trust, noting…
Low
Guidance
Published
United States (federal) · Sep 11, 2026
Amazon Ring's 'Throw Away the Key Encryption' adds limited privacy but falls short of true end‑to‑end encryption
Amazon introduced the Throw Away the Key Encryption (TAKE) feature for Ring cameras, where encryption keys are held temporarily in the cloud and deleted after 24 hours. The system still allows Ring to decrypt footage for cloud‑based…
Moderate
Guidance
Announced
European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act