What changed: early June 2026 — practitioner's monthly bulletin, issue 02Premium
Monthly bulletin for CISOs, DPOs, GRC analysts, internal auditors, and consultants tracking what's moving across the regulatory landscape · Issue 02 · 2026-05-25 · Written from the practitioner's perspective: what auditors will start asking about, what evidence to gather, what to surface to the board, and what to ignore as noise
TL;DR — items moving into early June 2026
Six items worth attention for compliance, security, and privacy practitioners in the early-June window. Three are continuations of May 2026 developments where the next move is now visible; three are net-new since the May bulletin.
- EU AI Act Omnibus formal adoption track. The 7 May 2026 political agreement is moving toward formal adoption; the European Parliament procedural vote is expected in early-to-mid June with formal Council adoption to follow. Compliance teams should keep both calendars live (Omnibus and original AI Act timelines) until Official Journal publication confirms the deferral.
- DPBI six-month operational pattern. With the Data Protection Board of India operational since 13 November 2025, the early-complaint pattern is now visible enough to draw a line. Three sectors are over-represented in early complaints; one is conspicuously absent.
- RBI ITGRCA enforcement actions ticking up. The third intensification theme — CIMS submission discipline — is producing a measurable rise in supervisory action letters. Banks and NBFCs with late or incomplete CIMS submissions in the past 6 months should expect questions in the next inspection cycle.
- CERT-In Direction 70B reauthorisation expected. The original 28 April 2022 direction has a five-year functional review window; CERT-In is signalling a refresh for mid-2026 with possible expansion of scope.
- NIST AI RMF GenAI Profile addendum. A pair of new subcategories addressing agentic AI behaviour and tool-use risk is in public review. Compliance teams running AI risk management programmes should consume the draft.
- First DPF-related challenge developments. The EU-US Data Privacy Framework continues to face challenges; a procedural ruling expected in early June will indicate the trajectory of the broader Schrems III-style litigation.
The rest of this bulletin walks through each item with the practitioner-relevant detail.
1. EU AI Act Omnibus — formal adoption track and what to do this month
The Omnibus political agreement of 7 May 2026 (covered in issue 01) is now on the formal adoption track. The expected timeline:
- Early-to-mid June 2026: European Parliament procedural vote on the Omnibus text.
- Late June to early July 2026: Council adoption.
- July 2026: Publication in the Official Journal; the deferral becomes operative.
What this means for compliance teams in early June: continue planning to both calendars. If formal adoption proceeds on schedule, the deferred timelines hold (HRAIS Annex III to December 2027, HRAIS Annex I to August 2028, AI-generated content marking to December 2026). If adoption stalls or is significantly amended in the procedural votes, the original AI Act calendar snaps back — with HRAIS obligations live from 2 August 2026.
The conservative read: prepare against the original calendar (Aug 2026) and treat the deferral as a deferred deadline rather than a relaxed one. The deferral does not change what compliance looks like; it changes only when penalty exposure starts.
What is actually shifting in early June is downstream guidance from the AI Office and from CEN-CENELEC. Watch for:
- AI Office Q&A updates clarifying value-chain re-classification (Article 25) interpretation, particularly for substantial fine-tuning of foundation models.
- First drafts of harmonised standards from CEN-CENELEC JTC 21. None expected to formally publish in early June, but draft texts circulating to interested parties.
- Member State competent authority designations finalising — the Member States are required to designate national competent authorities; about half have done so explicitly as of late May.
If your organisation operates AI systems in the EU, the operational priority for early June is the Article 25 screening for any model modifications that may have triggered provider reclassification. This is the most-missed obligation; the deferral does not affect it because it applies whenever a substantial modification occurs.
2. DPBI — six-month operational pattern
The Data Protection Board of India has been operational for approximately 6.5 months as of 25 May 2026 (operational since 13 November 2025). The early-complaint pattern is now visible enough to be useful.
Without revealing complainant-specific information, the publicly-available indication from DPBI’s quarterly status reports plus discussions with privacy counsel handling early matters suggests three sectors over-represented in early complaints:
- Edtech. Children’s-data issues, particularly around verifiable parental consent, behavioural tracking of student users, and retention of academic-performance data after course completion. The Section 9 + Rule 10 children’s-data regime is the most-tested provision in the early complaint pattern.
- Online lending. Complaint volume around consent quality (specifically: granular consent for credit-bureau reporting, third-party data sharing for fraud assessment), withdrawal mechanisms, and grievance redressal. The Section 6 + Rule 5 consent regime is being tested alongside Section 13 grievance redressal.
- Quick-commerce and food-delivery platforms. Complaints around purpose-limitation overreach (advertising and analytics processing beyond the order-fulfilment purpose), retention of order history, and the difficulty of effective consent withdrawal where the service is built on continuous personalisation.
Conspicuously absent from the early pattern: financial services beyond online lending. Banks and regulated NBFCs appear to be treating their existing sectoral compliance (RBI ITGRCA, RBI cyber-security directions, IT Outsourcing 2023) as functional pre-DPDPA preparation and are not generating early complaints at the rate the consumer-facing sectors are. This may shift after May 2027 full enforcement, but for now the financial sector is the relative bright spot in the complaint pattern.
What this means for practitioners:
- Edtech, online lending, and quick-commerce/foodtech entities should prioritise the three control areas surfacing in complaints: children’s-data verification, granular consent with parity withdrawal, and purpose-limitation discipline. The DPBI is signalling which controls it will inspect first.
- Financial services entities should continue their sectoral compliance trajectory; the existing RBI/SEBI/IRDAI compliance load is producing useful DPDPA-adjacent evidence.
- All sectors should review the Section 13 grievance redressal mechanism — internal grievance handling is a prerequisite for the Data Principal to escalate to DPBI, so an effective internal mechanism is also a complaint-volume reducer.
The DPBI has not yet imposed penalties (penalties become operative 13 May 2027); current complaint processing is informal mediation plus advisory action. The inflection point is May 2027.
3. RBI ITGRCA — CIMS submission discipline producing supervisory action
The third intensification theme from RBI inspections through 2025-26 has been Centralised Information Management System (CIMS) submission discipline: initial reports within 6 hours, detailed reports within 21 days. Late or incomplete submissions have been a recurring finding through Q1-Q2 2026.
In early June, the pattern is moving from “finding in inspection report” to “supervisory action letter from RBI.” Several banks and NBFCs are reported to have received specific letters from RBI cybersecurity supervision regarding CIMS submission patterns over the past six months. The typical letter pattern is a request for explanation of specific late or missing submissions, with a 30-day response window, followed by either resolution or referral for supervisory action.
What this means for affected entities:
- Late or missing CIMS submissions in the period roughly October 2025 through March 2026 are the current focus. Banks and NBFCs should run an internal CIMS submission audit covering this window and identify any gaps.
- The 6-hour clock is being interpreted strictly. RBI is treating the awareness timestamp as objective and verifiable; “we did not realise we needed to file” is not an accepted explanation.
- Coordination with CERT-In Direction 70B (also 6-hour) is required. Filing one and missing the other is a finding for both regulators simultaneously.
For boards of banks and NBFCs, this is the moment to ensure that the cyber crisis management plan has a clearly-named CIMS submission owner with backup designate, pre-staged submission templates, and a documented escalation path. Tabletop the workflow once a quarter; verify that the 6-hour clock can be met in practice.
For non-bank payment system operators governed by the Cyber Resilience and Digital Payment Security Controls Master Directions (July 2024), the same submission discipline applies and the same supervisory pattern is emerging.
4. CERT-In Direction 70B — reauthorisation expected mid-2026
The original CERT-In Direction 70B (28 April 2022) has been in force for approximately four years. The direction has a functional five-year review window, and CERT-In has been signalling a refresh through industry consultation since Q4 2025.
Expected changes in the refresh, based on industry consultation themes:
- Possible expansion of the 6-hour reporting obligation to additional incident categories beyond the current cyber-incident list. AI-related incidents (model poisoning, prompt injection at scale, generative-content abuse) are reported as a consultation theme.
- Tighter specification of KYC verification for VPN, VPS, and cloud service providers — the 2022 direction’s KYC scope has been contested in implementation, and the refresh is expected to clarify the obligation.
- Possible extension of the 180-day log retention requirement, particularly for VPN providers, with proposals in consultation suggesting 365 days.
- Sectoral interaction clarification — how CERT-In direction interacts with RBI, SEBI, IRDAI sectoral reporting timelines.
The refresh is expected to be notified mid-2026, with a transition window before enforcement. Practitioners should follow the public consultation timeline and prepare for the announced changes; the architecture for 6-hour reporting is mature in most regulated entities and small parameter shifts will not require fundamental rework, but the KYC and log retention changes may require operational changes for VPN, VPS, and cloud providers.
5. NIST AI RMF GenAI Profile — agentic AI and tool-use addendum
NIST released the GenAI Profile companion to the AI RMF 1.0 in July 2024, addressing generative AI specifically. In early 2026, NIST has been developing additional subcategories addressing agentic AI behaviour and tool-use risk — AI systems that act autonomously across multiple steps, invoke external tools, and operate with reduced direct human oversight.
The draft addendum, in public review, addresses:
- Risk management for AI systems with tool-use capabilities (web access, code execution, file system access, API calling).
- Trust boundary definition for agentic systems and how to evaluate which actions warrant approval gates.
- Auditing and logging requirements for multi-step agentic interactions.
- Cross-system risk assessment when agentic AI systems interact with other agentic AI systems (multi-agent setups).
- Specific transparency requirements for end users interacting with agentic systems.
This is a useful addendum for organisations deploying agentic AI products. The voluntary nature of NIST AI RMF means there is no compliance deadline, but procurement requirements and customer questionnaires are starting to reference the GenAI Profile, and the agentic addendum will be cited similarly within 6-12 months of finalisation.
The relevant audience: organisations building or deploying autonomous AI agents, particularly in customer-facing or transaction-completing contexts. The draft is worth consuming early; it shapes the questions auditors and customers will ask in 2027.
6. EU-US Data Privacy Framework — first procedural challenge developments
The EU-US Data Privacy Framework (in force since July 2023) has been subject to ongoing legal challenge. A procedural ruling in one of the pending challenges is expected in early June 2026. The procedural ruling will not resolve the substantive question (whether the DPF survives Schrems-style scrutiny) but will indicate the trajectory.
For practitioners relying on the DPF for EU-US data transfers, the operational guidance is unchanged: continue using the DPF where applicable, document the DPF-certification status of US recipients, and maintain optionality in case the DPF is struck down. Optionality means:
- SCCs in place as a backup transfer mechanism for any DPF-dependent flow.
- Transfer impact assessments documented for each cross-border flow regardless of DPF.
- Architectural optionality to relocate data processing to the EEA if the DPF is invalidated.
The history is consistent: Safe Harbor was struck down in Schrems I (2015), Privacy Shield was struck down in Schrems II (2020), the DPF is the third iteration. Each iteration has been challenged. The legally-prudent assumption is that the DPF will also be challenged on its merits within 3-5 years, and EU customers will increasingly request EU-data-stays-in-EU architecture.
Also moving — briefly
A faster read on developments not warranting full sections:
ISO/IEC 42001 certification market. Edition 1 (December 2023) certifications continue to grow; the first cohort of certified bodies is publishing case-study material that is useful for practitioners preparing for their own certification. Watch for industry-association content on what the first surveillance audits look like.
Indian DPDP Rules 2025 implementation FAQs. MeitY has been issuing informal clarifications through the DPBI portal on operational questions (notice translation requirements, consent withdrawal mechanisms, breach notification format). The clarifications are not formally legally binding but are the operational guidance most likely to be followed by the DPBI itself.
SEBI CSCRF Inspection Readiness Framework. SEBI circulated a draft framework for CSCRF inspection readiness in late May; final framework expected in Q3 2026. Capital markets entities should consume the draft and align internal audit programmes.
US state privacy enforcement. California, Connecticut, and Texas continued to be the most active state regulators through May. Texas DPSA enforcement has accelerated; California CPPA continues to focus on cookie compliance and dark-pattern enforcement.
DORA second-year enforcement. The European Supervisory Authorities completed initial designation of critical ICT service providers; the named providers (mostly major cloud and SaaS firms) now have a defined supervisory relationship with the ESAs. Financial entities in the EU should be tracking which of their critical providers are now designated.
NIS 2 Member State transposition. Continued fragmentation across Member States; the European Commission has signalled potential infringement proceedings against Member States with significant transposition gaps. Practitioners should watch their primary EU jurisdiction’s transposition status.
What to put on the agenda for next quarter
Based on the patterns above, three items deserve board or executive-team attention in the next 90 days:
One. EU AI Act readiness against the original 2 August 2026 calendar, treating the Omnibus deferral as an operational benefit rather than a compliance relaxation. The conservative-then-realistic position is to be ready for August and be glad if the deferral holds.
Two. DPBI complaint exposure assessment for sectors over-represented in the early-complaint pattern. If your sector is showing complaint volume above industry average, the controls that survive DPBI scrutiny need attention now rather than after the first penalty.
Three. CIMS submission discipline audit for Indian banking, NBFC, and payment-system entities. The window where supervisory letters are landing creates a deadline for internal review and remediation.
What this bulletin does not cover
Three categories of development deliberately not covered:
-
Vendor-specific announcements. Individual security or compliance vendor product launches, certifications obtained, partnership news. These are not regulator-driven and rarely change practitioner posture.
-
Industry conference takeaways. Conference reports from RSA, Black Hat, DEF CON, IAPP, OWASP events — useful but not bulletin-format material.
-
National security and intelligence developments. State-actor activity, sanctions developments, export-control changes — these matter operationally but are tracked separately by national authorities and trade-compliance teams.
This bulletin is a practitioner reference, not legal or regulatory advice. It reflects publicly available information as of 25 May 2026. Compliance teams should validate specific obligations against current regulator notifications, ongoing legal proceedings, and counsel review.
ControlForge tracks regulatory developments across DPDPA, GDPR, UK GDPR, US state privacy laws, EU AI Act, ISO 42001, NIST AI RMF, RBI cyber-security framework, SEBI CSCRF, IRDAI, CERT-In, and major sectoral regulators. The monthly bulletin format aggregates the developments that matter for audit-defensible compliance posture.