What actually matters this week
If you're shipping a product built with Lovable, Bolt, or v0, you don't need to track every regulatory filing on earth — just the handful that touch how your app collects data, talks to users, or uses AI. Here's what's moving right now, and what it means in plain terms.
Already live: EU AI Act transparency duties (Art. 50)
As of August 2, 2026, the EU AI Act's transparency obligations are in force. If your app uses generative AI or lets users interact with an AI system, you're expected to:
- Let people know when they're talking to AI, not a human.
- Label AI-generated content (text, image, audio, video) so it's identifiable as such.
This applies to providers and deployers offering AI systems in the EU — which, in practice, means most SaaS products with any EU user base. The recent "digital Omnibus" update (adopted June 2026) confirmed this date stands, so there's no extra buffer here. If you haven't reviewed how your product discloses AI use, this is the moment.
👉 Full details: EU AI Act
Coming up: the labeling grace period ends
Here's the one to circle: December 2, 2026. This is when the grace period under the digital Omnibus expires for AI systems that were already on the market before August 2, 2026. After this date, those systems also need the machine-readable marking required under Article 50.2 — meaning the labeling can't just be visible to humans, it needs to be detectable by machines too.
If your app launched before August 2026 and generates content with AI, this is a compliance step you don't want to leave until the last week. Machine-readable marking is a technical implementation detail, not just a UI toggle, so budgeting time for it now is the sane move.
India: DPDP Act enforcement rules land November 1, 2026
India's Digital Personal Data Protection Act, 2023 has been on the books for a while, but the enforcement rules that make it concrete take effect November 1, 2026. These rules define things like verifiable consent mechanisms and the obligations of "data fiduciaries" (India's term for what other frameworks call data controllers).
Why this matters even if you're not based in India: the DPDP Act applies to processing personal data of people in India, and to entities outside India offering goods or services to users in India. If your app has Indian users — even a modest slice of your user base — this is worth a look.
👉 Full details: DPDP Act
Chile: new data protection regime starts December 1, 2026
Chile is overhauling its privacy framework. Ley 21.719 replaces the older Ley 19.628 and takes effect December 1, 2026, bringing in a new supervisory authority for data protection in the country. If you have Chilean users or are expanding into Latin America, this is the law that will govern how you handle their personal data going forward — plan your privacy documentation accordingly rather than retrofitting it after the fact.
👉 Full details: Ley 21.719
The pattern here
Notice the common thread: transparency about AI, verifiable consent, and clearer accountability for whoever controls user data. Whether it's Brussels, Delhi, or Santiago, regulators are converging on the same basic asks — tell people what's happening with their data and their interactions with AI, and be able to prove it.
For a small team shipping fast with AI-assisted tools, this isn't about hiring a compliance department. It's about making sure your privacy policy, terms, cookie banner, and AI disclosures actually reflect what your app does — and keeping them updated as these deadlines roll through.
Check where your app stands
Not sure which of these apply to you, or whether your current policies already cover them? You can run a free check on your app at golexvibe.com/check — no signup required. It's a quick way to see what's missing before a deadline sneaks up on you.