EU AI Act Transparency, ALPR Suits & California DROP (08/01/2026)

August 1, 2026
EU AI Act Transparency, ALPR Suits & California DROP (08/01/2026)
Key Intel / TL;DR
  • EU AI Act transparency obligations start applying August 2, and chatbots have to say what they are.
  • Automated license plate reader litigation is forming along the same lines that made BIPA expensive.
  • California's DROP deletion platform opened August 1 with hundreds of thousands already registered.
  • Madison Square Garden runs facial recognition on everyone at the door and flags people who campaign against it.
  • South Korea fined KT about $39 million over data protection failures tied to a customer breach.

The EU AI Act’s transparency rules start applying tomorrow, which means a chatbot in Europe has to tell a person what it is. California opened its deletion platform today, and hundreds of thousands of residents signed up before the doors opened. Meanwhile Madison Square Garden runs facial recognition on everyone walking through its doors, flags the activists who campaign against it, and switched the system off for a celebrity wedding it wanted kept quiet. Watch who gets privacy in that last one, and how.

Top 5 Critical Privacy Alerts

1. EU AI Act Transparency Obligations Apply August 2

The European Commission issued a press release on July 30 confirming that the AI Act’s transparency rules start applying Sunday, August 2, 2026. Chatbots and other interactive systems have to identify themselves to the people using them, and synthetic images, audio, and video that look authentic have to be labeled as generated. Disclosure is the version of AI regulation worth having. It tells a person what they are talking to and leaves them to decide what that is worth. Global Privacy Watch

Operator Note: If you run a support bot, a voice agent, or a hiring screener anywhere touching an EU user, the disclosure is a product change and a policy change. Find out today who owns the copy in that first message.

2. Plate Readers Are Setting Up as the Next BIPA

Jackson Lewis is flagging automated license plate recognition as the next wave of privacy litigation, following the pattern that made claims under Illinois biometric privacy law (BIPA), the California Invasion of Privacy Act (CIPA), and their genetic and telephone equivalents expensive: a statute with a private right of action and statutory damages. California suits are already moving after Bartholomew v. Parking Concepts, Inc. Plate readers sit at the seam between physical and digital security, which is exactly where most organizations have nobody accountable. The camera is a facilities purchase and the data retention is a legal problem, and those two people rarely talk. PogoWasRight

Operator Note: Pull the retention setting on every plate reader on your property, including the ones your parking vendor installed. Whoever holds the footage holds the liability.

3. California’s DROP Deletion Platform Opens

The Delete Request and Opt-out Platform launched August 1, and hundreds of thousands of California residents registered before it went live. One submission propagates a deletion request to registered data brokers, which is the first time the burden has sat with the broker instead of the person. Other states are watching to see whether the process holds up at volume. Dark Reading

Operator Note: If your company buys or enriches consumer data, your vendor list just became a compliance surface. Ask each broker in writing whether they are registered and how they are processing DROP requests.

4. Madison Square Garden Flags the People Who Object to Being Scanned

Madison Square Garden runs facial recognition on everyone entering the venue and builds dossiers, and among the groups it flags are activists who campaign against facial recognition. Evan Greer, one of those activists, was flagged. The same system was switched off for Taylor Swift’s wedding at the venue, and no photographs leaked. The technology works fine either way. The variable is who has enough standing to get it turned off. Schneier on Security

Operator Note: Every venue biometric program eventually gets asked who is on the list and who put them there. Have the answer written down before a reporter asks.

5. The SCREEN Act Puts Age Verification in Front of the Whole Internet

The Senate Commerce Committee is taking up S. 737, the SCREEN Act, which would require online services to verify users’ ages before granting access to sexually explicit content. EFF’s read is that the mechanism reaches far past adult sites: a platform hosting a single piece of covered content triggers the requirement, which pulls in Netflix, Reddit, and Discord, and the bill rejects simple attestation in favor of verification tied to a real identity. It also requires age checks on traffic from known VPN addresses. The identity document you upload to prove you are old enough becomes a database somebody breaches in three years. EFF

Additional Privacy Alerts

Privacy Laws & Regulations

  • South Carolina passes an aggressive age-appropriate design code: The new Act pairs prescriptive privacy-by-design controls with restrictions on targeted advertising, and adds audits, parental controls, and personal liability for employees. Sidley Data Matters
  • Amended AB 1709 still bans social media for California minors: EFF argues the amendments do not fix the core problem, and that an under-16 access ban carries First Amendment and privacy costs for every Californian, since enforcing it means age-checking everyone. EFF
  • The CHATBOT Act would impose one parenting model federally: EFF’s objection is to Congress fixing a single answer for when minors may use AI tools, across every family and every school. EFF
  • Singapore finalizes generative AI guidance: The Personal Data Protection Commission published its final Advisory Guidelines on the use of personal data in generative AI, a significant marker for the region’s AI governance. PogoWasRight
  • Minors’ privacy legislation keeps accelerating in 2026: Covington’s mid-year recap tracks the state and federal developments, and the trend lines behind them. PogoWasRight
  • EU rules will require labels on realistic AI content: Companies must make sure people know when images, audio, and text designed to look real were generated. The Guardian
  • CIPA wiretap suits keep climbing: A 1967 California penal code provision written for telephone wiretaps now drives a surge of demands and lawsuits over website tracking technology. PogoWasRight
  • Judge trims the LinkedIn Insight Tag case: A federal judge mostly dismissed claims that the tag, which ties activity on third-party advertiser sites back to LinkedIn profiles, collected sensitive medical data without permission. PogoWasRight

Regulatory Fines & Enforcement Actions

  • South Korea fines KT about $39 million: The Personal Information Protection Commission penalized the telecom giant KRW 53.979 billion over a breach running from October 2024 to September 2025 that exposed 16,647 subscribers and produced fraudulent mobile payments for at least 368 of them. Findings included femtocell certificates valid for 10 years and destroyed network logs. BleepingComputer

Cross-Border Data Transfers

  • The Tunick border case is narrower than the headline: A close read of the incident, where a phone wiped itself after federal agents compelled an unlock at the border, separates what the case actually turns on from what privacy circles have made of it. PogoWasRight

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Jeff Welch
Chief Executive Officer
Jeff Welch
Architect of the 'Cognitive Firewall.'

A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)