Regulatory Cadence·~14 min read·3,015 words

What changed in May 2026: a practitioner's monthly bulletinPremium

Practitioner reference for CISOs, DPOs, GRC leads, internal audit, and compliance counsel · Issue 01 · 2026-05-25 · The monthly digest of what moved in security, privacy, and AI governance regulation, with the practitioner-relevant interpretation


How this bulletin works

This is the first issue of the monthly “What changed” cadence. Each issue covers what actually moved in the previous four to six weeks across security, privacy, and AI governance regulation in India, the EU, the US, and other jurisdictions that materially affect organisations operating cross-border.

The format for each item is consistent: what changed, who is affected, what auditors will start testing for, what to do this quarter, and the effective date where applicable. The items are ranked by how much they will change practitioner work in the next twelve months, not by how much press they received.

I am writing the first one in the format I would have wanted when I was running a programme — short enough to read in one sitting, long enough to give you the operational read, not a press-release recap. If the cadence is useful, it continues monthly. If items are missing that you think should have been here, the format is open to suggestions for the next issue.


The five things that mattered most

  1. EU AI Act Omnibus political agreement (7 May 2026) — major deferral of high-risk AI obligations, new prohibition on non-consensual intimate imagery, SME simplifications extended to mid-caps. Pending formal adoption.
  2. DPBI first-wave operational inspections — the Indian privacy regulator is now actively engaging Data Fiduciaries, including pre-designation inquiries on Significant Data Fiduciary candidates.
  3. NIST AI RMF GenAI Profile finalisation — additional subcategories for generative AI risk management, with implications for both standalone use and integration with the EU AI Act.
  4. ISO/IEC 27701:2025 Edition 2 — substantial restructuring of the privacy information management system standard, affecting certification pipelines.
  5. CERT-In Direction refinements — clarifications to the 6-hour incident reporting requirements and log retention specifications, with material implications for the 2026 audit cycle.

The rest of this bulletin walks through each in operational detail.


1. EU AI Act Omnibus political agreement of 7 May 2026

What changed. After two earlier failed political agreements in March and April, the European Council and Parliament reached political agreement on the AI Act Omnibus package on 7 May 2026. The package amends the original Regulation (EU) 2024/1689 substantially, with the main practitioner-relevant changes being:

  • High-risk AI obligations for Annex III (use-based) systems deferred from 2 August 2026 to 2 December 2027 — a 16-month extension.
  • High-risk AI obligations for Annex I (product-embedded) systems deferred from 2 August 2027 to 2 August 2028 — a 12-month extension.
  • AI-generated content marking under Article 50(2) deferred from August 2026 to 2 December 2026 — a three-month extension.
  • National regulatory sandboxes deferred from August 2026 to August 2027.
  • New prohibition under Article 5 from 2 December 2026: AI systems generating or manipulating non-consensual intimate imagery and child sexual abuse material (“nudifier” applications).
  • SME simplifications under Article 17 extended to mid-caps (up to 750 employees / EUR 150M revenue): simplified documentation, lower fines, sandbox access, standardised templates.
  • Strict necessity test for using GDPR special category data for bias detection reinstated (earlier drafts had allowed more flexibility).
  • “Safety component” definition narrowed to exclude AI components that merely assist or optimise without health/safety risk.

Who is affected. Anyone with AI systems on the EU market, particularly providers of high-risk AI under Annex III (which includes credit decisioning, recruitment, education, biometric identification, employment-related AI, critical infrastructure, law enforcement). Mid-cap providers benefit most from the SME extension — between 250 and 750 employees, the new category opens access to simplified documentation that was previously SME-only.

What auditors will test for. Until the Omnibus formally adopts (expected July 2026), both timelines remain live. Practitioners need to maintain compliance readiness against the original August 2026 high-risk obligations as a conservative case, while planning the longer runway against the new December 2027 deadline. Auditors and supervisory authorities are likely to probe whether organisations have pre-built the QMS, technical documentation, and conformity assessment readiness even though formal enforcement is deferred. The deferred deadlines do not exempt the underlying programmes.

What to do this quarter. Maintain the August 2026 readiness work in parallel until the Omnibus is published in the Official Journal. If the published text drifts from the political agreement, recalibrate. For Annex III providers with QMS work in progress, do not pause — the work product remains useful and the additional runway is operational benefit, not strategic permission to defer. For mid-cap providers, confirm eligibility for the extended simplifications and update the QMS scope statement to claim them where applicable.

Effective date. Formal adoption expected July 2026; if formal adoption fails before 2 August 2026, original timelines snap back.


2. DPBI operational inspections begin

What changed. The Data Protection Board of India has been operationally active since the DPDP Rules notification of 13 November 2025. Through Q1 2026 and into Q2, the DPBI has begun what practitioners are reading as a first-wave operational pattern:

  • Information requests to large data-processing entities (e-commerce, social media, fintech) covering their pre-DPDPA processing posture and current readiness.
  • Pre-designation inquiries on Significant Data Fiduciary candidates — these are not formal SDF designations yet, but are widely understood as the precursor.
  • Engagement with sectoral regulators (RBI, SEBI, IRDAI, TRAI) on the conflict-of-laws rule under Section 38.
  • Public guidance issuance through DPBI advisories on specific Rule clarifications, particularly around Rule 6 security safeguards.

Who is affected. Any entity that is likely to be designated as an SDF under DPDPA Section 10, plus larger Data Fiduciaries in regulated sectors. The first wave is expected to focus on the highest-volume e-commerce, social media, payment, fintech, and large internet platform operators. Other entities should expect a quieter ramp through 2026 and 2027.

What auditors will test for. The pre-designation phase is the operationally significant window. Practitioners should expect DPBI inquiries to focus on: data inventory completeness, notice and consent UX quality, breach response capability, processor contract quality (Rule 6(f)), and emerging SDF structural readiness (Section 10 + Rules 11-13).

What to do this quarter. Treat SDF readiness as imminent for any entity that meets the likely-designation criteria. The structural elements — India-resident DPO reporting to the Board, independent Data Auditor, periodic DPIA programme — take six to nine months to put in place. Waiting for a designation letter is too late. Inspectors are not yet imposing penalties, but the inspection record from 2026 will inform the enforcement posture from 2027.

Effective date. Ongoing.


3. NIST AI RMF GenAI Profile additional subcategories

What changed. NIST has finalised additional subcategories within the AI Risk Management Framework’s GenAI Profile (AI 600-1), introduced in 2024. The May 2026 update expands subcategory granularity around: generative model evaluation, prompt injection and jailbreak resistance, output verification for generated text and image content, training data provenance for foundation models, and downstream-deployment risk allocation.

Who is affected. US-headquartered AI developers and deployers using NIST AI RMF as their primary framework. Also relevant to organisations operating under the EU AI Act that use NIST AI RMF as a supplementary control reference. Organisations developing or deploying generative AI features should treat this as an operational update to their existing AI risk register.

What auditors will test for. The GenAI Profile is voluntary at the federal level but is increasingly being incorporated into procurement requirements, particularly for US federal agencies and large enterprises with AI vendor due diligence programmes. Auditors mapping against NIST AI RMF should expect to test for additional documentation around generative-specific risks: prompt injection testing, output provenance tracking, foundation model selection rationale.

What to do this quarter. If you are using NIST AI RMF as your primary framework, integrate the new subcategories into your AI risk register and update your Govern/Map/Measure/Manage documentation. If you are operating under the EU AI Act, use the NIST subcategories as a supplementary control reference where Article 15 (accuracy/robustness/cybersecurity) and Article 9 (risk management) require operational depth that the AI Act text alone does not specify.

Effective date. Effective immediately for adopters; voluntary at the federal level.


4. ISO/IEC 27701:2025 Edition 2 re-curation

What changed. ISO/IEC 27701, the Privacy Information Management System standard that extends ISO/IEC 27001, has been substantially restructured in its Edition 2 (published late 2025, with practitioner uptake building through Q1 and Q2 2026). The structural changes include:

  • Restructuring of the management system clauses to align with the latest Annex SL Harmonized Structure.
  • Refinement of the controls in Annex A and Annex B for controllers and processors respectively, with the total control count adjusted to 55.
  • Better integration with ISO/IEC 27001:2022, allowing for a more streamlined joint certification path.
  • Updated guidance on aligning the PIMS with GDPR, with implicit alignment also possible to DPDPA, CCPA, and other modern privacy regimes.

Who is affected. Any organisation certified to ISO/IEC 27701:2019 (the previous edition) or pursuing certification. The transition timeline from Edition 1 to Edition 2 is being managed by certification bodies; expect a 12-24 month migration window for existing certifications.

What auditors will test for. Existing certifications will continue to be audited against the version in effect at the original certification date until the next major recertification. New certifications from mid-2026 onwards will increasingly be done against Edition 2. The control set re-curation means that previously-implemented controls may need to be re-mapped — the work is largely paperwork, not new operational requirements.

What to do this quarter. If you are pursuing a new certification, do it against Edition 2. If you are recertifying, discuss the migration timeline with your certification body — most will allow a one-cycle continuation under Edition 1 followed by migration. If you are using ISO 27701 as a DPDPA or GDPR baseline (rather than for certification), the Edition 2 controls are the better mapping reference.

Effective date. Edition 2 published late 2025; transition windows vary by certification body.


5. CERT-In Direction refinements

What changed. CERT-In has issued clarifications to the 70B Direction (the 28 April 2022 cyber incident reporting direction) addressing several operational ambiguities raised by industry over the preceding three years. The May 2026 clarifications include:

  • Refinement of the “6-hour reporting” trigger — clarification that the clock starts at the point of objectively-verifiable internal awareness, not at the point of formal incident declaration.
  • Updated KYC retention specifications for VPN providers, data centres, and intermediaries.
  • Reporting format updates for specific incident categories.
  • Coordination guidance with sectoral regulators (RBI CIMS, SEBI, IRDAI) for incidents that trigger multiple notification regimes.

Who is affected. Any organisation in India subject to CERT-In Direction 70B — which covers almost all corporate IT operations, plus specifically named categories including data centres, VPN providers, cloud service providers, intermediaries, and crypto exchanges.

What auditors will test for. The 6-hour clock has been operationally tightening over the last 24 months. Auditors and CERT-In’s own inspections increasingly expect organisations to have a pre-staged notification procedure that does not depend on full incident scope being known. Organisations that have been measuring the 6-hour clock from public disclosure or from formal incident declaration are at increasing risk.

What to do this quarter. Update your incident response runbook to reflect the awareness-trigger interpretation. Pre-stage the CERT-In notification template with the minimum-required fields, and document the named approver for issuing the notification. Test in tabletop. If you operate under multiple Indian regulators (RBI + CERT-In, SEBI + CERT-In, etc.), update the notification matrix to reflect the parallel reporting obligations.

Effective date. Clarifications operative immediately.


Also worth knowing about

A handful of items that did not make the top five but are worth filing for the quarter ahead.

SEC cyber incident disclosure enforcement (US). The SEC has continued enforcement of the cyber incident disclosure rules adopted in 2023. May 2026 saw additional actions against listed companies that materially delayed Form 8-K filings or omitted required disclosures. Indian-listed companies with US listings (ADR/GDR) should treat these as relevant precedents; the four-business-day disclosure clock is being interpreted strictly.

California CPRA agency enforcement (US-State). The California Privacy Protection Agency has continued targeted enforcement, with May actions focused on automated decision-making transparency and dark-pattern consent UX. Companies serving California consumers — including many India-headquartered SaaS — should review their consent flows against the CPPA’s growing body of decided cases.

UK ICO AI strategy. The UK ICO published its 2026 AI strategy in early May, reaffirming a principles-based approach distinct from the EU AI Act. UK-only operations may benefit from the lighter-touch regime, but cross-border operations still need to plan for the stricter EU obligations.

IRDAI Cyber Security Guidelines 2026 update. IRDAI has notified updates to the 2026 cyber security guidelines for insurance entities, with refinements to incident reporting and third-party risk management. Insurance regulator entities should re-check the alignment with both the original 2026 guidelines and the May 2026 amendments.

RBI ITGRCA enforcement. Through Q1 and Q2 2026, RBI has continued material enforcement against banks and NBFCs on ITGRCA-related gaps, with monetary penalties in the ₹50 lakh to ₹5 crore range for representative cases. The pattern of findings continues to be: third-party risk depth for critical vendors, application security manual penetration testing, CIMS submission discipline, and cloud assurance gaps.

SEBI CSCRF Tier 1 entity readiness. As CSCRF Tier 1 obligations bind through 2026, SEBI is conducting an early-stage assessment of programme readiness across the top-tier regulated entities. Findings are not yet public, but practitioner reporting suggests material gaps in BCP/DR sophistication and incident response coordination.

PCI SSC Bulletin updates. PCI SSC issued additional clarifying bulletins in May 2026 on PCI DSS v4.0.1 implementation, particularly around the v4.0.1-only requirements that bind from 31 March 2025. Entities with QSA-led assessments coming up should verify current bulletin guidance is reflected in their assessment scoping.


The pattern reading

Five themes are converging across the regulatory developments of May 2026:

  1. Defer-but-don’t-loosen. The EU AI Act Omnibus is the cleanest example — the deadlines move, the obligations remain. Regulators globally are recognising that AI governance and privacy obligations are technically demanding to implement, but they are not relaxing the underlying expectations. The deferrals are operational accommodation, not strategic retreat.

  2. Mid-cap recognition. The Omnibus’s extension of SME simplifications to mid-caps reflects a broader recognition that the regulatory burden was poorly calibrated for the 250-750 employee segment. Expect similar adjustments in other regimes over 2026-2027 — DPDPA’s eventual SDF threshold setting may follow a similar logic.

  3. Awareness-trigger enforcement. Multiple regimes (CERT-In, DPDPA, GDPR Article 33) are converging on the principle that the breach notification clock starts at internal awareness, not at investigation completeness or public disclosure. Practitioners need to instrument their incident response procedures to mark the awareness moment objectively.

  4. Manual depth over automated breadth. RBI’s continued enforcement on manual penetration testing (vs scan-only VAPT) and on cloud-configuration review (vs accepting cloud-provider attestations) is a pattern that is showing up in other regulators’ inspection practices too. The era of accepting automated outputs as compliance evidence is closing.

  5. Cross-regulator coordination. The DPBI’s emerging engagement with sectoral regulators, the EU AI Act’s interfaces with GDPR, and CERT-In’s coordination guidance with RBI all reflect a regulatory environment that is increasingly aware of overlap. Practitioners need to think in regulatory matrices, not single regimes.


What to put on the agenda for next quarter

If I were running a security or privacy programme right now and using this bulletin to update my Q3 2026 plan, here is what I would do.

Refresh the AI scope statement. The EU AI Act Omnibus deferrals affect the timeline; they do not affect the underlying scope. Document any AI systems against the new deadline calendar but maintain the programme. If you are a mid-cap, claim the extended simplifications explicitly.

Sharpen the awareness clock. Update the IR runbook to mark the moment of objectively-verifiable internal awareness for any incident. Test in a tabletop. The CERT-In refinement is operationally significant; the same logic applies to DPDPA and GDPR.

SDF readiness if not already started. The DPBI’s pre-designation engagement is the leading indicator. The DPO, independent Data Auditor, and DPIA programme need lead time.

Reassess ISO 27701 strategy. If you are using ISO 27701 as your privacy baseline or pursuing certification, the Edition 2 transition is an opportunity to clean up the control mapping. Recurse against your DPDPA and GDPR scope.

Update the regulator engagement log. Add the May 2026 items to the log. The board update in your next quarterly slot should reference the material developments and the response.


What this bulletin does not cover

Three areas worth flagging:

  1. Sector-specific developments at granular depth. RBI, SEBI, IRDAI, and TRAI each have ongoing regulatory activity that I have summarised at the top level but not gone into in operational depth. Sector-specific monthly bulletins are a possible separate format.

  2. Non-EU AI governance developments. Singapore AI Verify, UK AI principles, Canada AIDA, OECD activity — the international AI governance landscape is broader than what fit in this issue. Future issues will cover more international regulators as material developments warrant.

  3. Active litigation and enforcement detail. The bulletin covers regulatory developments; the active litigation under each regime (GDPR enforcement cases, US class actions, India privacy litigation as it emerges) is a separate space. Worth a periodic litigation digest if there is demand.


This is a practitioner reference, not legal advice. It reflects publicly available information as of 25 May 2026. Compliance teams should validate specific obligations against the issuing authority’s published text and counsel review.

ControlForge maintains the cross-framework synthesis underlying this bulletin: 38 frameworks, 1,932 controls, 215 mapping clusters, 106 synthesis entries, and a regulator-developments log tracking changes across India, the EU, the US, and other jurisdictions. The monthly cadence continues. Next issue: 25 June 2026.