The Great Deadline Slide in Tech Privacy

The Great Deadline Slide in Tech Privacy

The deadlines for AI privacy rules keep moving out. The EU pushed its high risk AI obligations from August 2026 to December 2027 when the AI Omnibus entered into force on July 27. Colorado rewrote its AI law in May and moved the start date to January 1, 2027. HHS has delayed its overhaul of the HIPAA Security Rule, and the CFPB's open banking rule sits under a court order while the Bureau rewrites it. Meanwhile, the software those rules were written for is already working. Agents place orders, initiate payments and read customer data today. Protection in September 2026 comes from general laws that never paused, plus the few new rules that landed on schedule. A business that reads every delay as breathing room is misreading the calendar. Agents are already on the job Mastercard is rolling out an agentic payment option with the startup Alchemy, which makes virtual cards for AI agents. Cardholders can authorize agents ahead of time to buy within limits such as a price range. Visa, Mastercard and Ant International have also announced work on common standards to identify, verify and monitor the agents that initiate payments. Washington has started to notice. Senator Mark Warner released a discussion draft on June 29 that would require large platforms to admit authorized consumer agents on the same terms as human users. An IAPP analysis from September 16 argues that agentic AI strains the consent and purpose limitation principles behind GDPR and CCPA, since nobody can know an agent's next step when a person clicks agree. In Europe, the transparency duties in Article 50 of the AI Act have been enforceable since August 2, so chatbots serving EU customers already fall under them, and the content marking duty reaches systems already on the market on December 2. In the United States, the White House push to preempt state AI laws has produced an executive order, a Justice Department task force and a legislative framework, and no statute. Agents now reach businesses that look far removed from software. Retail runs on shelves, shoppers and parcels, yet the technical work behind a store is a task an agent can take on. Scandiweb's Agent for Magento carries out development work for store teams from plain language requests, on a copy of the store. The vendor says customer data is stripped from that copy, which shows that what an agent can see is a design decision made before the merchant ever logs in. Agents built for one narrow market raise their own privacy questions. A niche agent gets deep access to a single industry's systems, which places it close to catalogs, order histories, customer records and checkout flows. The vendor typically becomes a processor under GDPR and a service provider under the state privacy laws, so a small specialist company's data handling ends up inside every merchant's compliance file. The AI Act deferral changes little for these tools, since a store development agent does not appear among the high risk categories, and GDPR and the state privacy acts already govern any personal data the agent touches. Merchants adopting niche agents can ask vendors what data reaches the agent, where it is processed, how long logs are kept and who signs off on each change. Payments run ahead of the rules Payments show the gap clearly. The CFPB finalized its Section 1033 open banking rule in October 2024, with the first compliance date set for April 1, 2026. That date passed while a federal court had enjoined enforcement and the Bureau worked on a rewrite, and a replacement proposal reached OIRA for review in early August. One question in the rewrite bears directly on agents. The Bureau asked whether the "representative" who can request data on a consumer's behalf should be limited to fiduciaries or should include third party service providers. The answer shapes whether an AI agent can pull a customer's bank data on request. Europe's answer is PSD3 and the Payment Services Regulation. The final compromise texts landed on April 23, and Official Journal publication, once expected for early summer, has been drifting toward autumn. The regulation applies roughly 18 to 21 months after publication. It adds reimbursement duties for payment providers when a customer is tricked into authorizing a payment and the provider missed expected fraud detection standards. Credit assessment sits in the AI Act's high risk group, while fraud detection is carved out of it. California's automated decision rules also reach lending decisions. Payment providers serving European merchants hold a key position in all of this. They sit between the merchant, the bank and any agent that initiates a purchase. "Questions about who authorized a payment and who carries the liability will reach payment providers long before they reach a regulator," says Victor Cretu, Head of Payments at Solid Stake. Merchants can ask their payment partners now how they plan to verify agents and handle the new liability rules. Health data waits on HHS The HIPAA Security Rule overhaul would make encryption and multifactor authentication mandatory for systems that hold patient data. HHS has pushed final action to July 2027 and reclassified the rule as a long term action, and more than 100 hospital and provider groups have asked HHS to withdraw it. A separate Privacy Rule update went to the Office of Management and Budget on April 4 and, as of July, was still awaiting approval. HIPAA has no AI specific rule, and its existing requirements already cover any AI tool that touches patient data, including access controls and breach notification. Patients are moving faster than the regulators. A June AARP survey found that 41 percent of adults 50 and older who use AI have already asked it a health question, and 58 percent of respondents uneasy about sharing health information with AI cited privacy and security concerns. Retail and adtech get homework Connecticut's amendments took effect July 1 and cut the threshold from 100,000 consumers to 35,000, which pulls smaller online shops into scope. Privacy notices there must now say whether the company uses personal data to train LLMs, and selling sensitive data without consent is barred. California's DROP platform adds pressure on the data behind ad targeting. Since August 1, registered data brokers have to pull deletion requests from DROP at least every 45 days, delete the matching data including inferences, and report the outcome. Fines run $200 per request for each day a broker fails to delete. Retailers that sell audience data or run lead generation could qualify as brokers, and other businesses may receive deletion requests passed along by broker partners. Hiring meets the algorithm California's automated decision rules take effect January 1, 2027 for businesses already using such tools. Any business that uses software to replace human decision making in a significant decision, such as hiring or promotion, must give notice before deployment, honor opt outs unless an exception applies and explain on request how the tool produced its output. Job applicants and employees count as consumers under the CCPA, so employment tools fall inside. Colorado's replacement law drops the duty of care, the impact assessments and the risk management programs of the original and centers on disclosures about automated decision tools. The EU also places employment systems in its high risk group. Location data loses its free pass On June 29 the Supreme Court ruled in Chatrie v. United States that police conduct a Fourth Amendment search when they obtain a person's location history from Google, even for a short stretch and even when a company stores the data. The Court sent the question of whether the specific geofence warrant was valid back to the Fourth Circuit. The ruling is the Court's first digital surveillance decision since Carpenter in 2018. The commercial side is tightening in parallel. Connecticut bans the sale of precise geolocation data starting October 1, joining Maryland and Oregon. Virginia's ban took effect July 1. Build for the rules in force The dates still ahead all land on top of laws that already apply. Businesses running agents can act on that now. Inventory which agents touch personal data, keep a person in the approval path for anything that changes a system or moves money, strip customer data from test environments and keep logs that show what each agent did. The rules will catch up with the agents, and the businesses that already keep those records will be ready when they do.

Original Source

Read the full article at Hackernoon →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.