The big one: EU AI Act transparency duties are now in force
If your app uses generative AI in any way — a chatbot, an AI writing assistant, image generation, anything that talks back or creates content — this is the item to read first.
Since August 2, 2026, the transparency obligations under Article 50 of the EU AI Act (Regulation (EU) 2024/1689) apply to providers and deployers offering AI systems in the EU. In plain terms:
- If a user is interacting with an AI system (not a human), you need to tell them.
- If your app generates content (text, image, audio, video), that content needs to be identifiable as AI-generated.
This isn't new legislation — it's a date that just passed, and the June 2026 "digital Omnibus" update kept it in place rather than pushing it back. So if you shipped an AI feature in the last few weeks without adding any disclosure, this is worth fixing now rather than later.
📄 Full context: /law/eu-ai-act
What's coming: the grace period for AI content marking ends
Related to the above, mark your calendar for December 2, 2026. This is when the grace period from the digital Omnibus runs out for the machine-readable marking requirement under Article 50.2.
The distinction matters: telling a user "this is AI" is one thing; embedding a machine-readable marker in the generated content itself is a separate, more technical requirement. If your AI system was already on the market before August 2, 2026, you get until this December date to add that machine-readable marking. New systems don't get the same buffer.
For small teams, this means: don't just add a text disclaimer and consider it done — check whether your generated outputs (images especially) need an embedded, machine-readable signal too.
India: DPDP Act enforcement rules land November 1, 2026
If your app has users in India, or you offer goods/services there even without being based in India, the Digital Personal Data Protection Act, 2023 becomes enforceable on November 1, 2026, alongside the rules that operationalize it.
Two things to know in practice:
- Consent needs to be verifiable, not just a checkbox buried in a footer.
- If you process personal data, you take on obligations as a "data fiduciary" — roughly the Indian equivalent of a data controller.
This applies based on where your users are, not where your company is incorporated — a common surprise for builders who assume EU/US rules are the whole picture.
📄 Full context: /law/dpdp
Chile: a new data protection law replaces the old one
December 1, 2026 marks the start of Ley 21.719, Chile's new personal data protection regime. It replaces the older Ley 19.628 and creates a dedicated supervisory agency.
If you have Chilean users, this is a full regime change, not a minor update — worth treating similarly to how EU builders had to adjust for GDPR. Details on scope and specific obligations will matter most in the months before the effective date, but the direction is clear: Chile is moving toward a more structured, agency-supervised model.
Why this matters even for a weekend project
None of these dates require a legal team to understand. But they share a pattern that matters for small apps built fast with tools like Lovable, Bolt, or v0:
- AI disclosure and labeling is now a live requirement in the EU, not a future one.
- Where your users are — India, Chile, the EU — determines which rules apply, regardless of where you're sitting.
- Grace periods expire. The December 2026 AI Act deadline is a good reminder that "we'll deal with it later" has a shelf life.
None of this means panic. It means checking, once, whether your app's privacy policy, terms, cookie banner, and AI disclosures actually reflect what your app does today.
Check your app in two minutes
LexVibe scans your app and tells you where you stand against rules like these — privacy policy, terms, cookie banner, and EU AI Act classification — and keeps it updated as the rules change.
👉 Run a free check, no signup needed: golexvibe.com/check