What just became enforceable
EU AI Act — transparency obligations (Article 50), in force since August 2, 2026.
If your app uses generative AI — chatbots, image generation, synthetic voice, auto-written content — you now need to:
- Tell users clearly when they're interacting with an AI system (unless it's obvious from context).
- Label AI-generated content (text, audio, image, video) as such.
This applies to any provider or deployer offering AI systems in the EU, regardless of where your company is based. The June 2026 "digital omnibus" review kept this date unchanged, so there's no extra runway here.
Details: EU AI Act on golexvibe.com · official text (EUR-Lex)
Practical read: if your product already shows a "This response was generated by AI" note or watermarks generated images, you're likely covered. If not, this is the moment to add it — not a future to-do.
What's coming in the next 180 days
EU AI Act — end of the labeling grace period, December 2, 2026
This one matters if you shipped a generative AI feature before August 2, 2026. The digital omnibus gave those systems a grace period, but it ends on this date. From then on, AI-generated content from systems already on the market also needs the machine-readable marking required by Article 50(2) — not just new deployments. If your product predates August 2026, add this to your December checklist now.
India's DPDP Act, 2023 — enforcement rules, November 1, 2026
The Digital Personal Data Protection Act itself already exists, but the implementing rules — the part that actually operationalizes it — take effect on this date. Two things builders should watch:
- Verifiable consent mechanisms for processing digital personal data.
- Concrete obligations for the "data fiduciary" (India's term for what GDPR calls a data controller).
This law applies not only to companies in India, but to any app processing personal data of people in India while offering goods or services there — so a web or mobile app with Indian users, even without an Indian entity, is in scope.
Details: DPDP Act on golexvibe.com · official text (India Code)
Chile's Ley 21.719 — new data protection regime, December 1, 2026
Chile is replacing its older data protection law (Ley 19.628) with Ley 21.719, which also creates a new supervisory agency. If you have users in Chile — or plan to — this is the framework that will govern how you collect, store, and process their personal data going forward.
Details: Ley 21.719 on golexvibe.com · official text (BCN Chile)
Why this matters if you shipped fast with Lovable, Bolt, or v0
Vibe-coded apps tend to launch with a generic privacy policy template — or none at all — and go global from day one because there's no deployment friction. That's exactly the profile these rules are aimed at: it doesn't matter that you're a two-person team or a side project. If your app has users in India, Chile, or the EU, or if it uses generative AI, these dates apply to you the same way they apply to a 500-person company.
The good news: none of this requires a legal team. It requires knowing which rules actually apply to your app, and updating a handful of documents and UI elements (consent flows, AI disclosure labels, a privacy policy that reflects reality) before the relevant date.
Check where your app stands
Not sure which of these apply to you, or whether your current privacy policy, terms, cookie banner, or AI Act classification are up to date? Run a free check — no signup — at golexvibe.com/check. It tells you what's missing and what's coming up next, so you're not guessing.