Data Privacy, AI Regulatory, and Compliance Update: July 2026

Data Privacy, AI Regulatory, and Compliance Update: July 2026

July 2026 continued the rapid development of global privacy, AI, and online safety regulation.  In the United States, two significant Supreme Court decisions addressed the independence of the Federal Trade Commission and constitutional protections for location data.  At the same time, the EU finalized amendments to the AI Act, issued final transparency guidance, and released new guidance addressing generative AI training data, anonymization, and video games.  Regulators abroad also advanced new requirements and enforcement priorities concerning age assurance, AI transparency, and consumer protection.

For businesses, the common theme is that privacy and AI compliance continues to become more technical and operational.  Companies should review cross-border transfer safeguards, update AI Act compliance timelines, assess how training data is collected and validated, and prepare for more detailed regulatory expectations concerning age assurance, AI agents, and sector-specific data practices.

Key Takeaways:

  • The U.S. Supreme Court’s decision in Trump v. Slaughter eliminated statutory removal protection for FTC commissioners, prompting prominent EU privacy advocate Max Schrems and his digital privacy rights NGO, noyb, to call for a withdrawal of the EU-U.S.  Data Privacy Framework adequacy decision.
  • In Chatrie v. United States, the Supreme Court held that law enforcement conducts a Fourth Amendment search when it obtains a person’s historical location information from Google.
  • The EU AI Omnibus entered into force on July 27, 2026, extending key high-risk AI compliance deadlines.  The European Commission also issued final guidance for the AI Act’s Article 50 transparency obligations, which apply beginning August 2, 2026.
  • The European Data Protection Board issued draft guidance on anonymization and web scraping for generative AI, while the Spanish and Belgian data protection authorities published Europe’s first data protection guidance specifically for the video game sector.
  • Ofcom published its first report on the use of age assurance under the UK Online Safety Act and opened an investigation into whether TikTok is adequately protecting children from harmful content.
  • Japan enacted significant amendments to its national privacy law.

Read the complete client alert.

*  *  *

Kasowitz’s Data Strategy, Privacy, and Security team has deep knowledge in the data, privacy, and security sectors, and is familiar with the potentially existential risks faced by companies that rely on data as an engine of commerce and innovation.  Global data, AI, privacy, and security threats are “bet the company” issues that Kasowitz is well equipped to handle.  Our team consists of seasoned lawyers who have worked at or represented the largest and most innovative companies in the world, former regulators, and former government attorneys.  We leverage our extensive subject matter knowledge to support companies through global privacy and technology counseling, regulatory support in the AI, privacy and security space, litigation, and incident preparedness and response.

For more information, please contact:

Brandy Worden
Partner
bworden@kasowitz.com   

Frederick C. Bingham
Associate
fbingham@kasowitz.com  

Cyrus Borhani
Associate
cborhani@kasowitz.com