US lawmakers pile new AI and surveillance bills onto an already crowded stack — here's what EU operators need to extract from the noise.
elcome to issue fourteen. This week the US legislative machine kept churning, with three separate bills targeting how AI and social platforms interact with minors, while deepfake-fuelled digital violence against sex workers landed a sharp spotlight on the gap between harm and remedy. None of these bills are EU law, but every one of them shapes the products your US-based vendors build, test, and then sell into Europe. We dig into the CHATBOT Act and what it signals for AI tools already in your stack, and we pull out the deepfake story that deserves far more attention than it is getting.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We added a vendor-change-of-law clause template to the Flux compliance toolkit this week, covering scenarios where a supplier's home-jurisdiction legislation forces unilateral product changes.
- Updated The Flux high-risk AI system checklist has been updated to include a section on third-party chatbot components following the CHATBOT Act discussion.
- ICYMI If you missed issue thirteen, the US border surveillance tower expansion to 2,300 sites is still the clearest vendor-risk signal we have seen this year for EU operators using US infrastructure.
US CHATBOT Act Would Force Age-Gates and Disclosure Rules onto AI Tools Already Deployed Across European Businesses

A blunt instrument looking for a target. The recently introduced CHATBOT Act would require AI chatbots to disclose their non-human nature and impose access restrictions for minors, applying a single legislative template to every conversational AI regardless of context or risk level. The EFF argues the bill answers genuinely hard questions about AI and young people with a one-size-fits-all mandate that ignores the diversity of educational and family contexts.
Why this lands on your desk even if you are based in Berlin or Barcelona. Most mid-market and enterprise AI tools sold into Europe are built, trained, and primarily regulated in the US. If the CHATBOT Act passes, vendors will rebuild product defaults around US compliance requirements, and those defaults will arrive in your procurement pipeline. EU operators who have spent time mapping their own AI Act obligations could find vendor behaviour suddenly drifting in a direction neither party planned for.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓No new EU AI Act implementing measures published this week; the 2 December 2027 high-risk deadline remains 482 days out.
- ✓Deepfake harm debate intensified via AlgorithmWatch reporting, putting pressure on EU enforcement bodies to clarify remedies under existing rules.
- ✓Surveillance pricing practices highlighted in San Francisco mirror data-monetisation models that would face Article 5 scrutiny under the AI Act if deployed in the EU.
- ~US CHATBOT Act introduced, proposing mandatory disclosure and minor-access rules for all conversational AI tools regardless of risk level.
- ~


- 1EFF Deeplinksmonitoring
The Electronic Frontier Foundation's primary publication covering digital rights, surveillance, and emerging tech legislation in the US.
Why we like it. It gives EU compliance teams an early-warning feed on US legislative moves that will eventually reshape vendor product defaults.
- 2AlgorithmWatchresearch
A Berlin-based non-profit that investigates algorithmic decision-making and its social consequences across Europe and beyond.
Why we like it. Their deepfake harm reporting this week is the kind of primary source that regulators cite when writing enforcement guidance.
- 3EU AI Act full text (EUR-Lex)primary source

The real compliance risk this week is not a new EU rule. It is three US bills you probably have not read.
By John Ferguson
I keep hearing from operators that they are struggling to keep up with the AI Act. I get it. The regulation is long, the implementing acts are still coming, and the deadlines feel abstract. But this week reminded me that the compliance surface is bigger than Brussels.
Three US bills moved through committee or landed on Senate agendas, each one touching AI tools that European businesses use every day. None of them apply to us directly. All of them will reshape the products in our stacks.
The deepfake reporting from AlgorithmWatch sat in my head all week for a different reason. It is a clean illustration of what happens when the harm outpaces the remedy. The EU AI Act is supposed to prevent some of that gap. But only if operators actually use the leverage the regulation gives them, including in vendor negotiations.
My practical suggestion for this weekend: pull up your three most critical AI vendors and check whether their terms of service include a clause obliging them to notify you of material product changes. If they do not, that is a gap worth closing before the next US bill becomes law.
John Ferguson · Founder, Agentic Fluxus

Short answer.Yes, and sooner than you think. If a vendor changes how their system discloses its AI nature or restricts access to certain users, those changes affect your own transparency and human-oversight obligations under the AI Act. Review your vendor contracts for a change-notification clause, and treat any unilateral product update as a trigger for a short re-assessment of your conformity documentation.
When a key AI vendor changes their product to comply with US law, what do you do?

Multiple LGBTQ+ venues in San Francisco's Castro neighbourhood have been using PatronScan, an ID-checking and face-scanning system, to photograph patrons on entry. The system creates a searchable database of attendees, raising acute risks for a community that has historically faced state targeting.
EFF's latest EFFector found that the majority of fitness wearable companies are doing far less than technically possible to protect sensitive health data from third-party access. The gap between what the hardware can protect and what companies actually protect is, in their words, large.

