Digital Policy Alert, an independent tracking system for shifts in digital economy regulation, has compiled the month's major developments. The following summary draws on its monitoring of G20 nations and covers four key policy domains.
Core Policy Areas
- Content moderation: The European Commission imposed a €550 million penalty on AliExpress and opened preliminary investigations into Meta and TikTok for breaching Digital Services Act child protection rules. France enacted legislation barring minors under 15 from social networks, Brazil activated decrees on content moderation and gender-based online violence, and South Korea expanded categories of banned illegal content.
- AI regulation: The EU's Digital Omnibus on AI Regulation took effect. Twenty-nine nations, including Brazil, China, Indonesia, Russia, and South Africa, established the World Artificial Intelligence Cooperation Organization. Russia signed its Federal Law on Supporting the Development of AI Technologies, China issued interim rules for anthropomorphic AI services, and South Korea introduced five bills amending its AI Basic Act.
- Competition policy: The European Commission levied €460 million and €430 million in fines against Alphabet under the Digital Markets Act. China fined Trip.com ¥5.18 billion for dominance abuse. South Korea's competition authority launched an investigation into Google's Games Velocity Program.
- Data governance: The European Data Protection Board drafted guidelines on web scraping for generative AI training and anonymization standards. The UK's Upper Tribunal upheld a £12.7 million fine against TikTok. South Korea's Personal Information Protection Commission fined Apple ₩252 million and TikTok ₩10.3 billion for unlawful data practices.
Europe
The EU's ePrivacy Directive derogation allowing voluntary detection and removal of child sexual abuse material by electronic communications services extended through April 2028. A special panel on child online safety convened by the European Commission's President delivered recommendations including a minimum social media access age of 13 and privacy-preserving age assurance mechanisms.
The Commission's Digital Services Act enforcement intensified. Beyond the AliExpress fine, preliminary findings determined that Meta failed to adequately address addictive features on Instagram and Facebook, while TikTok's default settings for minors exposed their content too broadly. Potential penalties could reach 6% of global annual turnover if violations are confirmed. The Commission accepted X's action plan on advertising transparency and researcher access, pending implementation and audit.
The Court of Justice ruled that YouTube hosting gambling advertising falls under the e-Commerce Directive, but Google cannot claim hosting liability protection where it actively reviews and partners with creators. The Court also determined that streaming subscriptions qualify as digital services under consumer protection law.
Austria launched consultation on a draft requiring video platforms to block users under 14 lacking adequate child protections. Bulgaria introduced a bill prohibiting children under 16 from creating public social media profiles without parental consent exception. France's Parliament adopted legislation prohibiting minors under 15 from accessing social networks, with implementation beginning September 2026 following Constitutional Council review.
France's Competition Authority imposed interim measures requiring Meta to resume good-faith negotiations with press publishers over content remuneration and disclose payment information. The French audiovisual regulator Arcom analyzed advertising repository effectiveness and extended Amazon Prime Video's service agreement until December 2026, maintaining its €90 million investment commitment in European and French-language original content. Arcom also opened an investigation into pornographic sites over age verification non-compliance.
Germany's Commission on Licensing and Supervision stated that German media law applies to Google's AI Overviews and Perplexity's AI chatbot. The Munich Regional Court largely upheld claims by GEMA against Suno, finding the AI music generator unlawfully reproduced copyrighted works during training and that these acts fell outside Germany's text and data mining exception.
Italy's communications regulator consulted on guidelines requiring businesses to verify reviews come from genuine consumers and prohibit misleading practices. The regulator also ordered internet providers to block an Escort Advisor website for failing to implement age verification.
Turkey's new law expanded the Cyber Security Presidency's powers to regulate domain policies and order rapid implementation of content measures, with operators required to comply within 2 hours. The law also mandates conditional access media providers and internet platform operators contribute 2% of annual net sales to a Turkish film industry fund.
The United Kingdom's Television Selection Services Regulations designated 15 services from Amazon, Google, Roku, Samsung, Sky, LG, Apple, and Virgin Media as regulated, subject to public service broadcaster prominence rules. Ofcom issued regulations extending listed-events protections to on-demand and streaming platforms.
Under the Online Safety Act, Ofcom adopted a service register and opened consultations on draft codes. The Fraudulent Advertising Code for Category 1 services—including Facebook, Instagram, Pinterest, Quora, Reddit, Roblox, Snapchat, TikTok, WhatsApp, X, and YouTube—requires risk-based systems to detect and remove fraudulent ads, maintain searchable advertising libraries, and increase transparency. A parallel code for Category 2A services covers Google Search, Bing, ChatGPT Search, and Facebook Feed Deep Dive. Ofcom also consulted on an Additional Duties Code addressing user empowerment, complaints, and content of democratic importance.
Ofcom fined the provider of Fapello £630,000 for age assurance failures, opened an investigation into TikTok's child protection compliance, and issued a revised notice to Im.ge's provider over illegal content assessment duties. The regulator also issued a provisional decision that an online suicide discussion forum breached the Act by failing to conduct adequate risk assessments.
Asia and Australia
Australia's House of Representatives passed the Online Safety Amendment increasing penalties for platforms failing to enforce a 16-year minimum age requirement. The Interactive Gambling Amendment was introduced, covering content moderation governance, fair marketing, and age verification. The government announced laws reducing the threshold for minors' claims against platforms and empowering the Civil and Administrative Tribunal to issue demasking orders requiring disclosure of anonymous users accused of online vilification.
Australia's Federal Court fined JustAnswer AU$10 million for misleading conduct in online advice services. The eSafety Commissioner sued Telegram over alleged failure to remove pro-terror material and filed a report identifying safety gaps in how large platforms detect child sexual exploitation.
China's State Administration for Market Regulation and Ministry of Commerce opened consultation on E-commerce Law amendments increasing penalties for platform non-compliance and expanding supervisory powers. The Cyberspace Administration consulted on an Anti-Cyber Violence Law establishing platform obligations to detect and remove cyberbullying content. Following investigations into AI applications by Huawei, Alibaba, Zhipu, Xiyu, and DeepSeek, over 6 million pieces of illegal information were removed, more than 26,000 accounts faced action, and over 1,300 AI products and nine illegal datasets were taken down.
India faced a public interest litigation seeking restrictions on minors' access to Roblox and other gaming platforms. A parliamentary committee recommended establishing coordinated monitoring across agencies to address food listing mislabeling on e-commerce platforms. The Food Safety Authority opened an investigation into Swiggy Instamart over alleged violations, and the Central Consumer Protection Authority investigated SpiceJet over dark patterns including pre-ticked checkboxes.
Indonesia's Ministry of Communication and Digital Affairs announced verification of child protection requirements across 14 Apple digital services.
Japan's Ministry of Internal Affairs consulted on a report recommending mandatory age verification, risk assessments, and default protective measures for minors on digital platforms.
South Korea's Act on Promotion of Information and Communications Network Utilization took effect, expanding prohibited illegal content categories to include discriminatory and harmful false or manipulated information. Large-scale providers must establish policies to identify and address such content. The law introduces punitive damages up to five times actual damages for intentional or negligent distribution of harmful false information. Related amendments to e-commerce consumer protection entered force addressing review disclosure, user identification, and violation surcharges. Bills were introduced addressing music track distribution harmful to youth and repealing false information and hate speech provisions.
Americas
Brazil's Decree 12,975 updated content moderation rules requiring removal of illegal third-party content upon notification, though court orders are required for crimes against honor. It introduces systemic failure liability for terrorism, incitement to suicide or self-harm, discrimination, gender-based violence, sexual crimes against vulnerable persons, and human trafficking. Decree 12,976 establishes protections for women online, requiring removal of material linked to gender-based offenses and unlawful acts against women. Providers must restrict AI or similar technologies generating or altering intimate content and detect and block such activity.
Brazil's National Secretariat for Digital Rights published a report identifying 32 websites offering AI tools to generate synthetic nude images, referring findings to law enforcement and the National Data Protection Agency.
International
Twenty-nine countries signed an agreement establishing the World Artificial Intelligence Cooperation Organization. Asia-Pacific Economic Cooperation members issued a statement promoting AI development in the region. Fourteen countries adopted guidance on minimum software bill of materials elements. Australia, Canada, and India signed a Technology and Innovation Partnership.
AI Regulation
Europe
The EU's Digital Omnibus on AI Regulation entered into force, clarifying the AI Office's competences for supervising general-purpose AI systems and extending enforcement powers to systems embedded in very large online platforms and search engines. The Regulation expands access to AI regulatory sandboxes and extends SME exemptions to small mid-cap enterprises. It amends design, quality of service, and cybersecurity requirements for high-risk systems and modifies the legal basis for processing special categories of personal data for bias detection. From December 2026, the Omnibus prohibits AI systems designed to generate child sexual abuse material or non-consensual intimate content without adequate technical safeguards.
The European Commission published guidelines on Article 50 transparency obligations, clarifying disclosure requirements for AI systems interacting with users, generating synthetic content, or performing emotion recognition and biometric categorization. The Commission adopted an action plan on cybersecurity and AI. European standardization bodies adopted a quality management system standard for AI Act purposes.
France's Competition Authority published a report on AI agents competition, identifying barriers to expansion and risks from vertically integrated providers. The report recommends regulatory oversight, improved interoperability and data portability, technical standards development, and closer acquisition monitoring. France's data protection and AI councils published a note on agentic AI risks for personal data protection.
Russia's President signed the Federal Law on Supporting the Development of AI Technologies, establishing a framework for large foundation AI models, providing government support, defining sovereign and national model requirements, and introducing AI-generated content labeling and intellectual property obligations. Implementation begins September 2026.
The UK's Department for Business and Trade opened consultation on workplace monitoring technologies, including AI-enabled monitoring and automated decision-making, seeking views on transparency, worker engagement, and accountability measures.
Asia and Australia
Australia announced legislation on AI standards focused on environmental and energy requirements for large data centers, including grid connection obligations and net energy contribution requirements, and creation of an Office of Artificial Intelligence. The Cyber Security Centre published guidance on AI model harnesses for cybersecurity, finding well-designed harnesses around mid-tier models can achieve comparable defensive capabilities to frontier models.
China's interim measures for anthropomorphic AI interaction services took effect, prohibiting manipulation through emotional dependence, addiction, self-harm content, or replacing real interaction. Virtual relative or partner services to minors are banned. Providers must identify underage users, enable "minor mode," obtain parental consent for users under 14, and provide appeal mechanisms. The Cyberspace Administration issued filing information for 7 generative AI services from Apple, Huawei, OPPO, Vivo, Xiaomi, Samsung, and Nubia and published the eighteenth batch of deep synthesis algorithms. Consultations opened on cybersecurity and AI standards, AI browser security guidelines, and AI agent interaction security.
India's Delhi High Court dismissed ANI Media's copyright infringement lawsuit against OpenAI, ruling that using published content to train AI models constitutes protected research under Indian copyright law.
Indonesia's Ministry of Communication and Digital Affairs completed drafting a Presidential Regulation governing AI use and closed consultations on annual reporting formats for AI businesses and blockchain services.
South Korea introduced five bills amending the AI Basic Act, addressing non-discrimination, expanding high-impact AI definitions, intellectual property governance, generative AI disclosure, and personal information use exceptions for AI development. The Ministry of Science and ICT published an AI security redteaming guide and threat response manual.
Saudi Arabia adopted a National Framework for AI Risk Management requiring government and private entities to classify and manage AI risks across bias, privacy, security, and misinformation.
Competition Policy
Europe
The European Commission fined Alphabet €460 million for self-preferencing on Google Search and €430 million for restricting app developers' steering on Google Play, both breaching the Digital Markets Act. The Commission adopted a final decision requiring Google to share search data with competitors and opened a specification proceeding supporting Google's interoperability compliance. It opened an investigation into Temu over alleged distortive foreign subsidies, approved Paramount Skydance's acquisition of Warner Bros. Discovery, and accepted binding commitments from SAP closing an investigation into enterprise resource planning practices.
The General Court dismissed Apple's challenge to its gatekeeper designation, and the Court of Justice dismissed Google's appeal of a €4.125 billion fine over Android dominance abuse.
Italy's Competition Authority fined Lime Technology €1.4 million for barriers preventing Lime Transit Pass activation and Bird Rides €750,000 for unfair scooter-sharing practices. The Authority opened consultation on Perplexity AI contract terms.
The UK's Competition and Markets Authority consulted on conduct requirements following strategic market status designations for Apple and Google mobile platforms and closed a call for evidence on near-field communication access on Apple's platform. The CMA approved eBay's acquisition of Depop. Getty Images and Shutterstock terminated their proposed merger, formally notifying the CMA.
Asia and Australia
Australia's Competition and Consumer Commission opened consultation on its determination regarding the Google and Epic Games application store settlement capping Google Play fees at 10 to 20%.
China's State Administration for Market Regulation fined Trip.com ¥5.18 billion for dominance abuse in online hotel reservations.
India's Competition Commission dismissed a Zomato pricing complaint, fined HP India ₹128.09 crore over bid manipulation, and approved upGrad Education's Sorting Hat Technologies acquisition.
Indonesia's Business Competition Supervisory Commission announced a TikTok investigation over alleged dominance abuse and released a one-year impact assessment of its Shopee case, finding the ecosystem gained Rp1,477 trillion in benefits, though algorithmic dominance remained.
Japan's Fair Trade Commission opened consultation on amended merger review guidelines addressing platform markets, indirect network effects, and data foreclosure.
South Korea introduced a bill amending the Monopoly Regulation and Fair Trade Act mandating review and accountability for overturned dispositions, and another imposing commission caps and cost disclosure on delivery platforms. The Fair Trade Commission fined eight SolidWorks resellers ₩2.372 billion over price-fixing and customer allocation, approved Mirae Asset Consulting's Korbit acquisition, initiated proceedings against Analog Devices and NXP over semiconductor distribution restrictions, and opened an investigation into Google's Games Velocity Program.
Africa
South Africa's Competition Commission referred Audatex to the Competition Tribunal for prosecution over alleged price discrimination in vehicle repair estimation software.
Data Governance
Europe
The European Commission published guidance supporting Cyber Resilience Act implementation, clarifying scope, product coverage, substantial modifications, support periods, reporting, and risk assessment requirements. It opened consultation on a cybersecurity certification scheme for EU Managed Security Services and on international data sovereignty challenges. The Commission completed its first review of the 2021 adequacy decision for South Korea, confirming adequate protection for EU personal data transfers.
The European Data Protection Board opened consultations on draft guidelines addressing legal basis and safeguards for web scraping to train generative AI and on anonymization, introducing a three-part test of no record isolation, no linkage, and no inference. It adopted a second version of blockchain processing guidelines recommending permissioned blockchains and off-chain storage. At a Dublin meeting, the EDPB called on the Commission to propose a legal basis for cross-regulatory information sharing and set out measures to strengthen cross-border GDPR enforcement. The EDPB wrote to the Commission on the US Supreme Court's Trump v Slaughter judgment, asking assessment of implications for the EU-US Data Privacy Framework. The EDPB and Anti-Money Laundering Authority announced joint guidelines on Article 75 information-sharing partnerships, with public consultation expected in the first half of 2027.
Germany's Data Protection Conference launched consultation on the Stuttgart Impulses for Modernization of Data Protection, inviting feedback on 10 reform proposals addressing governance, coordination, and operational processes of data protection authorities.
Italy's Data Protection Authority opened an investigation into TIM over alleged unlawful telemarketing and data-subject rights violations, and continued investigating Lusha Systems over unauthorized contact data processing.
Turkey's Data Protection Authority issued a decision on accident victim personal data processing and guidance on third-party data use for advertising and marketing.
The UK's HM Treasury designated four cloud service providers as Critical Third Parties under financial services rules. The Department for Science, Innovation and Technology opened inquiries into international data transfers and data regulation in the age of AI. The Upper Tribunal dismissed TikTok's appeal against a £12.7 million fine for data protection breaches, including unlawful children's data processing. The Tribunal confirmed TikTok's processing does not fall within the Data Protection Act 2018's special purposes exemption.
Asia and Australia
Australia's Signals Directorate published guidance on agentic AI adoption in cyber defense, post-quantum cryptography vendor readiness, and facial recognition privacy requirements. The Cyber Security Centre closed consultation on its Essential Eight framework evolution, providing threat-informed mitigations.
China's technical standards on data transaction security, network virtualization, wireless access, network security testing, public key cryptography, data interface monitoring, and cybersecurity product interconnectivity entered force. Standards on connected camera security and intelligent agent guidelines also took effect. The Cyberspace Administration adopted simplified personal information protection measures for small processors handling fewer than 100,000 people. The National Information Security Standardization Technical Committee opened consultations on data provision and collaborative processing, anonymous entity identification, security classification for cybersecurity and AI, and the SM9 cryptographic algorithm, and on a network data security risk assessment guideline. The Ministry of Industry and Information Technology issued notices against 32 mobile app developers over data privacy breaches.
Indonesia advanced a Presidential Regulation establishing an independent Personal Data Protection Authority.
Japan's amended Act on Protection of Personal Information took effect, expanding the Personal Information Protection Commission's enforcement powers and introducing a mandatory administrative surcharge equal to financial benefits from unlawful handling affecting 1,000 or more individuals, with penalties rising for repeat violations. Criminal penalties for intentional data theft or unauthorized access increased. New categories of "contactable personal-related information" and "specific biometric personal information" require advance notice and grant individuals rights to request use suspension or cessation, exercised by legal representatives for those under 16.
South Korea's Personal Information Protection Commission opened consultations on measures implementing amendments to the Personal Information Protection Act, including investigation and disposition regulations, complaint-filing standards, disciplinary recommendation standards, public announcement guidelines, and administrative fine standards. Bills were introduced strengthening notification and security measures for unauthorized access, increasing penalties for illegal leaked information distribution, reducing fines for vulnerability reward programs, strengthening data preservation for security incident analysis, and introducing a personal information use exception for AI development. The PIPC fined Apple ₩252 million and TikTok ₩10.3 billion over unlawful data collection and transfers, fined Korea Telecom ₩539.8 billion over unauthorized femtocell data leakage, and referred LG Uplus to law enforcement over alleged breaches.
Americas
Argentina introduced a bill establishing a new Personal Data Protection Law covering cross-border transfers, data protection authority governance, and general regulation.
Brazil's National Data Protection Authority concluded monitoring of data protection officer appointment obligations and considered sanctions, and renewed a Technical Cooperation Agreement with the Competition Authority.
Canada's Securities Administrators published a review of registered firms' cybersecurity practices, and the Office of the Privacy Commissioner released guidance for reporting entities on codes of practice under anti-money laundering legislation.
Source: Tech Policy Press



