What's new this week
If you shipped an app with Lovable, Bolt, or v0 and it talks to users or touches personal data, four dates on the calendar deserve your attention. Two are already enforceable, two are coming in the next 180 days. None of this requires a legal team to understand — just a checklist.
Already in force: EU AI Act transparency duties (Art. 50)
Since August 2, 2026, the transparency obligations of the EU AI Act (Regulation (EU) 2024/1689) apply to providers and deployers of AI systems offered in the EU. In plain terms: if your app lets users interact with an AI system (a chatbot, an AI assistant, an image generator), you need to disclose that they're talking to AI, and content generated by the system needs to be labeled as such.
This isn't a future deadline — it's live now. The digital Omnibus adopted in June 2026 kept this date unchanged, so there's no extra runway here. If your app has any generative AI feature and you haven't added a disclosure or label yet, this is the one to close first.
Full details: EU AI Act
Coming up: the labeling grace period ends December 2, 2026
Here's the nuance that trips up a lot of builders: if your AI system was already on the market before August 2, 2026, you got a grace period for the machine-readable content marking specifically required under Art. 50.2. That grace period ends on December 2, 2026.
After that date, generative AI systems that were already live before the transparency duties kicked in also need machine-readable marking on generated content — not just a human-readable disclosure. If you launched your AI feature early and assumed you were covered indefinitely, mark this date: the exemption runs out.
Coming up: India's DPDP Act enforcement rules, November 1, 2026
India's Digital Personal Data Protection Act, 2023 applies to anyone processing digital personal data in India — including apps based outside India, if they offer goods or services to users there. The enforcement rules that operationalize the Act take effect on November 1, 2026, bringing verifiable consent mechanisms and concrete obligations for "data fiduciaries" (the DPDP Act's term for what other frameworks call a data controller).
If your app has users in India — even a modest slice of your traffic — this is worth checking now rather than in October. Verifiable consent flows and fiduciary obligations aren't things you bolt on overnight.
Full details: DPDP Act
Coming up: Chile's new data protection law, December 1, 2026
Chile is replacing its old data protection framework (Ley 19.628) with Ley 21.719, a new regime that also creates a dedicated supervisory agency. It takes effect on December 1, 2026. If you have users in Chile, this is a full regime change, not a patch — worth planning for rather than reacting to in Q4.
Full details: Ley 21.719 (Chile)
Why this matters even for small apps
None of these rules only apply to "big tech." The EU AI Act's transparency duties apply to any provider or deployer offering AI systems in the EU, regardless of size. The DPDP Act and Ley 21.719 apply based on where your users are, not where your company is incorporated or how many people are on your team. A solo builder with a Bolt-built app and a few hundred users in Santiago or Mumbai is squarely in scope.
The practical takeaway isn't to panic — it's to know which of these four apply to you based on your actual user base and AI features, and to have a plan for the ones with a real deadline (November and December 2026 for India and Chile; December 2026 for the labeling grace period; now, already, for Art. 50 transparency).
Check where your app stands
If you're not sure whether your app needs an AI disclosure, an updated privacy policy, or a cookie banner that matches these rules, don't guess. Run a free check at golexvibe.com/check — no signup required. It scans your app's current state against the rules that actually apply to it, so you know exactly what to fix and by when.