What changed: May 2026 — a practitioner's regulatory cadence bulletinPremium
Monthly bulletin for CISOs, DPOs, GRC analysts, internal auditors, and consultants tracking what's moving across the regulatory landscape · 2026-05-25 · Written from the practitioner's perspective: what auditors will start asking about, what evidence to gather, what to surface to the board, and what to ignore as noise
TL;DR — the items that moved this month
Nine regulatory developments worth knowing about for the May 2026 cycle, in roughly descending order of how soon you will see them in an audit or board conversation:
- EU AI Act Omnibus political agreement (7 May 2026) defers high-risk AI obligations and extends SME simplifications to mid-caps. Formal adoption expected by July; if it slips, the original August 2026 deadlines snap back.
- DPBI completes six months of operations. Early inquiry pattern visible. Consent Manager registration framework activates 13 November.
- RBI ITGRCA enforcement intensified around third-party risk, CIMS submission discipline, and manual penetration testing depth. Three banks received specific findings in Q1 2026; the pattern is teaching the market.
- CERT-In Direction 70B compliance audits are picking up. Log retention and KYC for crypto-exchange-adjacent services are the early focus areas.
- SEBI CSCRF Inspection Readiness Framework draft circulated to market intermediaries for stakeholder feedback. Final expected Q3 2026.
- ISO/IEC 42001 certification market crossed an inflection point. Roughly 180 certified organisations globally as of April 2026, up from 30 in January 2025.
- US state privacy enforcement — Texas TDPSA brought its first enforcement notice; Florida FDBR clarification on the data broker registration scope; Colorado CPA universal opt-out mechanism rulemaking finalised.
- DORA second year of enforcement brought visible supervisory action against EU financial entities and their critical ICT third-party service providers. The first formal ESA designation actions for critical providers are imminent.
- NIS 2 fragmentation continues. EU Member State transposition gaps and divergent national enforcement priorities are surfacing for cross-border entities.
Below: what each one actually means for your control programme.
EU AI Act Omnibus — the political agreement of 7 May 2026
This is the most important single development of the month, and the one I have spent the most client conversations on.
What changed. The European Commission, Council, and Parliament reached political agreement on the AI Act Omnibus package on 7 May 2026, after two earlier trilogues failed (March and April). Subject to formal adoption — expected late June or July 2026 — the package includes:
- High-risk AI obligations under Annex III (use-based) deferred from 2 August 2026 to 2 December 2027. Sixteen-month deferral.
- High-risk AI obligations under Annex I (product-embedded) deferred from 2 August 2027 to 2 August 2028. Twelve-month deferral.
- AI-generated content marking (Article 50(2)) deferred from August 2026 to 2 December 2026. Chatbot disclosure (Article 50(1)) unchanged.
- National regulatory sandboxes deferred from August 2026 to August 2027.
- SME simplifications extended to mid-caps (up to 750 employees / €150M turnover). Simplified Article 17 documentation, lower fines, sandbox priority, access to Commission-published standardised templates.
- Article 5 prohibition added on AI generating or manipulating non-consensual intimate imagery and CSAM (“nudifier” applications), in force from 2 December 2026.
- “Safety component” definition narrowed so that AI components that merely assist or optimise without creating health or safety risk are not automatically high-risk by virtue of embedding in a regulated product.
- Strict necessity test reinstated for using GDPR Article 9 special category data to detect or mitigate bias — earlier Omnibus drafts had allowed more flexibility.
- Machinery Regulation moved to Annex I Section B with delegated acts to amend the Machinery Regulation directly by August 2028.
What it means. If you have been operating on the assumption that high-risk AI obligations would bite in August 2026, you have just received sixteen months of breathing room — but only if formal adoption happens before 2 August 2026. The trilogue history suggests this is probable but not certain. Compliance teams should keep both calendars live: the conservative scenario (August 2026 enforcement) and the Omnibus scenario (December 2027 for Annex III, August 2028 for Annex I).
What auditors will ask. Three questions, immediately. Are you mid-cap eligible (under 750 employees and €150M turnover)? If yes, claim the simplification explicitly in your AIMS scope statement. Have you re-screened your AI inventory against the narrowed “safety component” definition? Some systems that were classified high-risk under the old definition may no longer be. Have you reviewed your special category data usage for bias detection against the reinstated strict-necessity test? The “we needed it to test bias” defence is no longer sufficient; the documentation must show no less intrusive means exists.
Evidence to update. AI inventory tagged against revised Annex I and Annex III definitions. SME / mid-cap classification documented in the QMS scope. Strict-necessity analysis per special category data use. Article 50(2) content-marking technical implementation plan with the new December 2026 target (use C2PA / IPTC standards; same implementation also satisfies India’s IT Rules 2026 SGI watermarking obligations).
What we are watching for. Whether the European Commission publishes harmonised standards through CEN-CENELEC before the deferred deadlines. The standards-availability question was part of why the Omnibus deferred timelines; the first harmonised standards are expected in late 2026 and will create presumption of conformity with corresponding AI Act requirements. Until they exist, conformity is a self-attested exercise against the Act text.
DPBI six months in — what the early pattern looks like
The Data Protection Board of India has been operational since 13 November 2025. We are now six months in. The early inquiry pattern is visible enough to draw cautious conclusions.
What changed. The DPBI has accepted complaints since November 2025 under the limited scope of Rules 1, 2, and 17–21. Sectoral observers report somewhere between 800 and 1,200 complaints filed through Q1 2026, with a heavy concentration in social media, lending apps, and e-commerce platforms. Preliminary investigations have begun on a smaller subset; no penalty determinations have been issued yet (none can be, since the substantive provisions don’t activate until 13 May 2027). The Board has issued a small number of advisory clarifications on the breach notification timeline and on consent withdrawal mechanics.
The pattern. The complaints clustering in the data-broking-adjacent sectors mirrors what was visible in the early GDPR enforcement years — the first wave is consumer complaints about marketing practices and consent. The complaints volume on children’s data has been higher than expected; this is consistent with the broader Indian regulatory attention to online safety and the IT Rules 2021 amendments.
What auditors will ask. Have you registered your DPBI complaint mechanism in your privacy notice as required under Rule 3? Is the internal grievance mechanism (Section 13) operational and tracked? Has the Data Fiduciary nominated a grievance officer with contactability? Some companies are surprised to learn the grievance officer requirement is already operational (under Rules 17-21) even though the substantive obligations don’t take effect until May 2027.
Evidence to update. Grievance officer designation in writing, contact details published on website and in privacy notice. Internal grievance handling SOP with response SLA. DPBI complaint channel acknowledgment in privacy notice. Quarterly review of grievance volume and patterns.
What we are watching for. The first formal DPBI inquiry order under the Rule 17-21 procedure; the form and language will set expectations for what enforcement looks like under the full regime from May 2027. Also the Consent Manager registration framework activating on 13 November 2026 — six months from now — and the candidate Consent Manager ecosystem firming up.
RBI ITGRCA enforcement — the three intensification themes
Three areas where RBI inspection findings have visibly intensified through 2025 and into 2026: third-party risk depth, application security from scan-to-manual-pen-test, and CIMS submission discipline. Q1 2026 inspection findings at three named banks (two private-sector, one PSB) made these themes operational.
What changed. The April 2024 Master Directions on IT Governance, Risk, Controls and Assurance Practices have been in force for two years; the enforcement maturity now matches. Findings from Q1 2026 inspections, made visible through bank disclosures and supervisor-issued public letters, show:
-
Third-party risk: specific findings on banks accepting cloud-provider SOC 2 Type 2 reports without bank-specific cloud configuration review. The inspector now asks: “Where is the bank’s review of its own AWS / Azure IAM, network rules, S3 / Storage Account configuration, and encryption-at-rest verification?” Two of the three Q1 inspection letters have this finding.
-
Application security: findings on VAPT reports that consisted entirely of automated scanner output. The inspector requires manual penetration testing evidence — business logic flaws, IDOR / BOLA findings, auth/AuthZ depth, mobile platform testing. CERT-In empanelment of the lead auditor is now treated as a prerequisite, not a preference.
-
CIMS submission discipline: findings on awareness-clock interpretation. Banks interpreted the six-hour initial report as starting from public disclosure or formal confirmation. The supervisor is now interpreting awareness from any responsible person’s actual knowledge of the incident.
What auditors will ask. For banks and regulated entities under RBI: pull your CIMS submission history for the last twelve months; verify every significant incident was reported within six hours of the earliest internal awareness; verify the detailed report was submitted within twenty-one days. For VAPT: ask for the manual penetration testing methodology, the business logic test cases, the API authorisation findings. For cloud: ask whether the bank itself reviewed cloud configuration or relied on provider attestation.
Evidence to update. CIMS submission log with awareness-timestamp documented per incident. VAPT report cover page identifying lead auditor and CERT-In empanelment ID; manual testing section with business logic findings. Cloud configuration review report for each cloud tenancy, refreshed annually.
What we are watching for. Whether the RBI extends the third-party-risk intensification to top-tier NBFCs and small finance banks at the same depth. NBFCs are typically a one-year-behind cohort on RBI inspection themes; expect 2026-27 to bring NBFC-specific findings on cloud and CIMS.
CERT-In Direction 70B — compliance audits picking up
Direction 70B has been in force since April 2022. The early enforcement was light. Through 2025 and into 2026 the compliance check pattern has visibly intensified.
What changed. CERT-In has begun systematic compliance reviews on Direction 70B obligations: the six-hour incident reporting timeline, the 180-day log retention (rolling), the synchronised time-source requirement (NTP from a CERT-In-specified or government-approved source), the KYC retention for VPS / VPN / cloud / data centre / crypto exchange services. Q1 2026 saw specific compliance reviews of VPS hosting providers and crypto-exchange-adjacent services around log retention and KYC.
What auditors will ask. Do you have the six-hour incident reporting procedure documented, tested, and with a named owner? Is your log retention provably 180 days for all in-scope log categories? Is your time source compliant? If you are a VPS / VPN / cloud / data centre / crypto service, is your KYC retention compliant with the five-year requirement?
Evidence to update. Direction 70B incident submission history (if you have had reportable incidents). Log retention configuration screenshots from SIEM and centralised logging. Time source configuration evidence. For in-scope services: KYC retention SOP and sample records.
What we are watching for. The next iteration of Direction 70B guidance; CERT-In has signalled a refresh is being drafted to clarify ambiguities in the original Direction (notably around what constitutes a “cyber incident” requiring reporting, and the interaction with DPDPA breach notification from May 2027).
SEBI CSCRF Inspection Readiness Framework — draft circulated
SEBI has been operating the Cyber Security and Cyber Resilience Framework since August 2024 (Master Circular SEBI/HO/MIRSD/CIR/PoD-1/P/CIR/2024/13). In May 2026 the Board circulated an Inspection Readiness Framework draft to market intermediaries.
What changed. The draft IPF formalises what SEBI inspectors will test against during CSCRF compliance reviews. It maps to the CSCRF Annex controls, identifies expected evidence types, sets sampling depth expectations, and introduces a graded categorisation of market intermediaries by criticality (Stock Exchanges, Clearing Corporations, Depositories at the top; smaller brokers and intermediaries at the bottom with proportionate expectations).
What it means. If you are a market intermediary, this is the document that tells you what the SEBI inspector will check during 2026-27 reviews. The substance closely tracks the RBI inspection pattern — third-party risk depth, application security manual testing, incident reporting timeline discipline, BCP/DR testing depth — adapted for capital markets context. Comments are due by mid-June.
What auditors will ask. Have you reviewed the IPF draft against your current control evidence? Are there gaps between what SEBI says it will check and what you can produce? Is your representation in industry-body responses to the IPF draft submitted?
Evidence to update. IPF gap analysis against your CSCRF compliance evidence. Industry-body response comments. Internal action register for gaps identified.
What we are watching for. The final IPF in Q3 2026 and the first round of CSCRF inspections under the formalised framework in Q4 2026 / Q1 2027.
ISO/IEC 42001 certification market — the inflection point
I have been tracking the ISO 42001 certified-organisation count since the standard published in December 2023. Through 2024 the count was under twenty. Through 2025 it grew steadily into the dozens. April 2026 marks roughly 180 certified globally, with the largest concentrations in Europe (just over half), North America (about a quarter), and Asia-Pacific (the remaining quarter, including a small but growing Indian cohort).
What changed. The procurement signal has caught up to the regulatory signal. EU enterprise buyers have begun requesting ISO 42001 certification as part of AI vendor due diligence; Indian buyers under MeitY’s 2025 AI Advisory have begun asking; Japanese and Singaporean buyers have followed. The market has moved from “early adopters certify to differentiate” to “early majority certify to qualify.”
What it means. If you are an AI vendor or AI-embedded SaaS company, ISO 42001 is moving from optional to expected on a faster timeline than ISO 27001 did. The same companies that took five years to demand ISO 27001 are taking two to three years to demand ISO 42001. Budget the certification project (typically twelve to eighteen months elapsed time, ₹50 lakh to ₹2 crore depending on size) into your 2026-27 plan if AI is core to your product.
What auditors will ask. Three things in any AI-related vendor assessment: do you have ISO 42001 certification, are you in the certification process, or do you have a documented AIMS that maps to the standard? The third option is the minimum acceptable answer.
Evidence to update. AIMS scope statement. Statement of Applicability against Annex A. AI policy with Board approval. Risk methodology with AI-specific extensions. AISIA / FRIA artefact. Technical documentation per Annex IV (which also serves the EU AI Act side).
What we are watching for. The first formal procurement specifications requiring ISO 42001 (rather than “preferred”). I expect to see these surface in EU and Japanese enterprise procurement in Q4 2026.
US state privacy enforcement — three notes
US state privacy fragmentation continues. Three specific developments worth noting.
Texas TDPSA — first enforcement notice. The Texas Attorney General issued the first formal enforcement notice under the Texas Data Privacy and Security Act in April 2026, against a data broker for failing to comply with the data broker registration requirement that has been in force since 1 September 2024. The notice does not result in immediate financial penalty (TDPSA includes a 30-day cure period for the first violation) but signals the AG’s enforcement intent.
Florida FDBR — data broker scope clarification. The Florida Department of Legal Affairs issued guidance clarifying the data broker registration scope under FDBR, narrowing it from the original broad interpretation that had captured many incidental data-sharing companies. The clarification reduces the number of in-scope entities materially but does not change substantive obligations for the broker community.
Colorado CPA — universal opt-out mechanism rulemaking finalised. Colorado finalised its rulemaking on the universal opt-out mechanism (UOOM) requirement, with the technical specifications now matching the Global Privacy Control. Effective date for honouring UOOM signals: 1 July 2026.
What auditors will ask. For any company with a US footprint: which state laws apply to your data subjects? Are you registered as a data broker where required (Texas, California, Vermont, Oregon, Florida)? Are you honouring Global Privacy Control signals where required (Colorado, soon)? Is your privacy notice state-law-specific where it needs to be (the CCPA / CPRA disclosures, the VCDPA / CPA / CTDPA / UCPA / TDPSA / FDBR notice requirements)?
Evidence to update. State-law applicability matrix. Data broker registration records. UOOM honouring evidence (technical implementation, sample requests honoured). State-specific privacy notice variants or consolidated multi-state notice with state-specific addenda.
What we are watching for. The next wave of state privacy laws (Maryland MODPA effective 1 October 2025, Minnesota MCDPA effective 31 July 2025, Tennessee TIPA effective 1 July 2025, Indiana CDPA effective 1 January 2026 — all now in force; Iowa ICDPA effective 1 January 2025 also in force). The convergence of these laws has slowed; new state laws are now small differentiations rather than substantively novel frameworks.
DORA second year of enforcement — the ESA designations
The Digital Operational Resilience Act has been in force since 17 January 2025. We are now sixteen months in. Q2 2026 is bringing the first visible supervisory action.
What changed. The European Supervisory Authorities (EBA, EIOPA, ESMA) are completing their assessment for designation of critical ICT third-party service providers under Article 31 DORA. The formal designation list — the first round of ICT TPPs subject to the Oversight Framework — is expected to publish in Q3 2026. Major cloud providers and core banking platform providers are widely expected to be on the list.
What it means. For EU financial entities: if your critical ICT third-party service provider is designated, your contractual arrangements and oversight obligations change. The Oversight Framework will impose additional oversight on the designated provider (lead overseer assigned, formal recommendations issued, escalation to fines for non-compliance with recommendations) — but you also need to demonstrate your management of the provider relationship satisfies the DORA standards regardless of designation.
What auditors will ask. Have you completed the ICT third-party risk register as required under DORA Article 28? Is your concentration risk analysed and tracked? Are exit strategies documented for critical ICT TPPs? Are your contractual provisions DORA-compliant (Article 30 mandates)? Is your incident classification and reporting aligned with the EBA RTS?
Evidence to update. ICT TPP register. Concentration risk analysis (annual minimum). Exit strategy documentation per critical provider. Updated contractual provisions where the existing contract pre-dates DORA. Incident reporting log with major incident classification rationale.
What we are watching for. The first formal designation list publication. The first Oversight Framework recommendations issued by lead overseers. The early enforcement action against EU financial entities for DORA non-compliance — likely to focus on third-party risk and incident reporting gaps first.
NIS 2 fragmentation continues
The NIS 2 Directive transposition deadline was 17 October 2024. Sixteen months later, transposition completeness across EU 27 remains uneven, and divergent national priorities are surfacing operational issues for cross-border entities.
What changed. As of May 2026, approximately 22 of 27 Member States have completed transposition; five remain partial. National competent authority designations are settled. National enforcement priorities differ visibly — Germany has emphasised supply chain security and notification timelines; France has emphasised CISO designation and management responsibility; Belgium has emphasised energy and transport sector readiness; the Netherlands has emphasised CSIRT cooperation.
What it means. For multi-Member-State entities, the operational compliance posture has to satisfy the strictest national interpretation, not the directive baseline. The directive permits Member State variation in specific areas (notification timelines, CSIRT cooperation, penalty calibration); the practical compliance design has to accommodate the variation.
What auditors will ask. Have you identified all Member States in which you have NIS 2 essential or important entity status? Is your management body trained and accountable per Article 20? Are your notification procedures aligned with the strictest Member State timeline (typically the early-warning 24-hour requirement)?
Evidence to update. NIS 2 in-scope entity classification per Member State. Management body training records. Notification timeline matrix per Member State. CSIRT designation acknowledgment per Member State.
What we are watching for. The first cross-border enforcement coordination case under NIS 2 — likely Q3-Q4 2026. The remaining five Member States completing transposition.
What we are watching for in June 2026
Three items I expect to surface or progress in the next monthly cycle:
-
AI Act Omnibus formal adoption in the Council and Parliament, expected late June. If adoption slips past 2 August 2026, the original timelines snap back and the AI Act compliance landscape changes overnight.
-
DPBI’s first formal inquiry order or advisory issued publicly. The form and language will set the template for what enforcement looks like under the substantive provisions from May 2027.
-
The first published ESA designation list of critical ICT third-party service providers under DORA Article 31. Expected Q3 2026; if it slips earlier into June, the designated providers will need to begin Oversight Framework engagement immediately.
What this bulletin does not cover
Three things deliberately left out:
-
Sector-specific deep dives. This is a horizontal bulletin. Sector-specific implications (RBI’s deeper interpretation for banks, IRDAI for insurance, FDA for medtech AI, etc.) deserve their own treatments and will appear as separate sectoral bulletins where warranted.
-
Speculative regulator action. I have not included items based on consultation papers or political signalling that have not yet crystallised into draft or final regulation. The Digital India Act, the EU Data Union Strategy, the US federal privacy framework — all are moving but not yet at a stage where compliance teams should be designing for them.
-
Counsel-grade interpretation. This is practitioner reference, not legal interpretation. Where the regulatory text is ambiguous, I have flagged it as such and pointed to where to watch; I have not resolved the ambiguity. That is what your counsel does.
This is a practitioner reference, not legal advice. It reflects publicly available regulatory developments as of 25 May 2026 and is updated monthly. Compliance teams should validate specific obligations against current regulator publications, official journals and gazettes, and counsel review.
ControlForge synthesises the cross-framework implications of each item above through its mapping clusters and synthesis entries. Subscribers receive the within-72-hour briefings on individual regulator actions between monthly cadence bulletins.