Key developments
UK plans under-16 social media restrictions
The UK government announced plans to restrict under-16s from major social media platforms, with initial regulations expected before year-end and implementation planned for spring 2027. Time's Callum Sutherland and IAPP's Lexie White reported the framework is expected to cover Instagram, YouTube, TikTok, Snapchat, Facebook and X, with exemptions including YouTube Kids, Google Classroom, WhatsApp and Signal. Ofcom would oversee age assurance, while explicit AI romantic-companion chatbots would face an 18-plus restriction.
Why it matters
The proposal would make age verification a central privacy and platform-compliance issue for UK children’s online services.
Sources & driving stories
Canada introduces sweeping private-sector privacy bill
Canada introduced Bill C-36, the Protecting Privacy and Consumer Data Act, to overhaul private-sector privacy enforcement. IAPP's Lexie White reported the bill would recognize privacy as a fundamental right, strengthen consent, expand deletion rights, treat children’s personal information as sensitive, require privacy impact assessments and address risks tied to AI deepfakes and automated decisions. It would also create the Digital Safety and Data Protection Commission of Canada with binding enforcement powers and penalties up to CAD 10 million or 3% of global revenue, or CAD 25 million or 5% for serious offences.
Why it matters
The bill would materially reshape Canadian privacy enforcement by moving private-sector complaints from the OPC to a new penalty-capable regulator.
Sources & driving stories
IAPP · Lexie White
IAPP coverageGoogle sues alleged AI-assisted smishing operation
Google filed a lawsuit against the alleged Outsider Enterprise cybercrime operation, which Claims Journal reported is suspected of sending 2.5 million fraudulent Android text messages over two weeks in May. Google alleged the group coordinated through Telegram, used fake websites posing as trusted brands and encouraged use of Gemini to generate malicious website code. The complaint cited 9,000 fake websites and more than 1 million fraudulent URLs, with Google saying it worked with AT&T, T-Mobile US and Verizon to block the texts.
Why it matters
The case gives a concrete example of generative AI being folded into large-scale credential and personal-data theft infrastructure.
Sources & driving stories
CLAIMS JOURNAL
Claims Journal coverageWorth noting
WORTH NOTING
EU approves AI Act changes
The European Parliament approved amendments delaying some AI Act obligations while banning AI systems that generate CSAM or nonconsensual intimate depictions of identifiable people.
WORTH NOTING
Novo Nordisk faces ransom claim
Insurance Business's Matthew Sellers reported FulcrumSec threatened to sell more than 1 TB of allegedly stolen Novo Nordisk data after a claimed $25 million ransom demand, including alleged clinical trial, employee, physician and drug information.
WORTH NOTING
Maine breach portal hit by hoaxes
TechRadar reported Maine’s Attorney General temporarily disabled public access to its breach notification portal after fake disclosures impersonating Discord and VRChat were submitted and published.
Still unclear
OPEN QUESTION
Can child age checks avoid data overcollection?
The UK proposal depends on robust age assurance, but age verification systems can create new identity, tracking and circumvention risks, including VPN-driven avoidance.
OPEN QUESTION
How verifiable is AI-enabled privacy abuse?
Google’s lawsuit, the EU nudifier ban and voice-cloning research all point to a growing enforcement problem: proving when AI systems generated, amplified or personalized harmful misuse of personal data.
