Kritia Law Watch
EU AI and data rules, for firms that use the tools
A free daily briefing: the decisions authorities actually published, what is only a proposal, and what a firm that uses AI tools should do about it. Every item links its source. Today’s issue is below, in full.
Monday 2026-08-31
Two regulators published decisions worth your time, one of them this morning and at a scale that actually resembles a small firm. Plus the Commission's own answers on what Article 4 now asks of you.
01 — ENFORCEMENT
Decisions authorities and courts actually published.
Fine for failing to ensure the independence of the data protection officer (3 minute read)
UODO (Polish data protection authority)· EU
A court bailiff was fined 15,500 PLN — about EUR 3,600 — in two parts: 12,000 for appointing themselves as their own data protection officer for five years, and 3,500 for not notifying the authority. The regulator's reasoning is blunt: a person who runs the organisation cannot be its DPO, because they would be monitoring themselves. Published today, in Polish.
Uber fined nearly 825 million euros for automated driver blocking (4 minute read)
Autoriteit Persoonsgegevens (Netherlands)· EU
The Dutch authority fined Uber 824,990,000 euros for deactivating drivers' accounts by software alone between 2018 and 2022, on fraud suspicion or low ratings, with no human assessment and inadequate notice to drivers. The size belongs to the company, not to the rule. The deputy chair's line is the transferable part: a computer should not make decisions on its own that have major consequences for someone.
02 — RULES & GUIDANCE
New or changed official text, guidance and proposals.
Commission designates ChatGPT, Reddit and Roblox under the Digital Services Act (3 minute read)
European Commission· EU
Announced this morning, on the services' own declarations of at least 45 million average monthly users in the EU: ChatGPT as a very large online search engine, Reddit and Roblox as very large online platforms. They have four months, to 1 January 2027, to meet the extra obligations. Those duties land on the designated services, not on the businesses that use them.
AI literacy — questions and answers (8 minute read)
European Commission / AI Office· EU
The Commission's own answers on what Article 4 asks, last updated 27 July 2026 — which is to say, after the amendment that changed it. If someone has told you the AI Act obliges you to buy a course, this is the page to check them against.
Guidelines on transparency obligations for providers and deployers of certain AI systems (5 minute read)
European Commission· EU
Published 20 July 2026, and the closest thing yet to an official answer on which Article 50 duties fall on the firm that buys a tool rather than the one that builds it. Deployer duties covered include informing people exposed to deepfakes, to AI-generated content on matters of public interest published without human review, and to emotion-recognition systems.
03 — PRACTICAL
Worth doing, or worth the time to read.
Before you deploy an AI tool, check how it stands up under the GDPR (4 minute read)
UODO (Polish data protection authority)· EU
A regulator writing directly to organisations about to adopt an AI tool, on 6 August 2026 — what to establish before it goes live rather than after a complaint. Short, and unusually plain for a supervisory authority. In Polish.
Identifying and managing a DPO's conflicts of interest (6 minute read)
CNIL (France)· EU
Published 10 August, three weeks before the Polish fine above landed on exactly this failure. If one person in your firm both runs an operation and oversees its data protection, this sets out how French regulators read that. In French.
04 — THE WIDER VIEW
Written about the rules, not by the people who make them.
Deployer obligations under the AI Act: implications for employers from 2 August 2026 (7 minute read)
DLA Piper· EUAnalysis
A law firm's read of what an employer that uses AI — rather than builds it — actually took on when the duties became enforceable. Useful if you are running AI anywhere near hiring or performance. Their view, not the regulator's.
The EDPB's draft anonymisation guidelines: what they mean for your data strategy (9 minute read)
IAPP· EUAnalysisNot law yet
The European Data Protection Board has put anonymisation guidelines out in draft. Relevant to anyone who has been told that stripping names from a dataset puts it outside the GDPR. Draft means draft: nothing here binds you yet.
05 — QUICK LINKS
- A controller must report a breach that happened at its processor (3 minute read)
UODO — Your vendor had the incident; the 72-hour clock is still yours. Poland, 12 August. - Italian authority fines Lusha 2 million euros (5 minute read)
Garante — A contact-data business, monitored at scale. Italy, 27 July. - The enforcement framework of the AI Act (4 minute read)
European Commission — Who enforces what: the AI Office, the EDPS, and national authorities. Updated 24 August.
06 — COUNTDOWN
93days · 2026-12-02
Machine-readable marking for generative systems placed on the market before 2 Aug 2026.
What this isn’t
News about the law, not legal advice, and not an assessment of your business. Items marked Analysis are someone’s view of the rules, not the rules. Whether a duty applies to you depends on what you actually do — the scope checker is free.
Get this each publishing day
Free, about a minute to read, every claim linked to its source.
Double opt-in, one-click unsubscribe, never shared.
Past briefings
Not news
The guides are the evergreen half: plain-English explainers of the Act as amended, each carrying the date its legal snapshot was verified. Trading outside the EU? The website scan reads UK and US duties too.