A New Chapter: Compliance & Risks is now Adherent. Read more.

8 min read
Blog

What’s Trending in Compliance? July 2026

Authors
A smiling woman with curly red hair and blue eyes, wearing a denim shirt, looks to the right in a brightly lit, blurred setting.

This blog was originally posted on 27th July, 2026. Further regulatory developments may have occurred after publication. To keep up-to-date with the latest compliance news, sign up to our newsletter.


Adherent is the agentic AI product compliance platform that allows teams to anticipate and respond to ever-growing, ever-changing regulatory requirements. Adherent is trusted to manage compliance for billions of products across appliances, electronics, medical equipment, toys, cars, apparel, and more.

We help ensure global companies have the tools and information to build safe, sustainable products in a world full of change.

Below we break down some of the top compliance trends in July 2026 that are generating the most interest globally this month.

1. Saudi Arabia: AI Cybersecurity, Draft Guidelines, July 2026

On 5 July 2026, the National Cybersecurity Authority (NCA) launched a public consultation on the Draft AI Cybersecurity Guidelines (AICG – 1: 2026). The draft aims to support national cybersecurity objectives by addressing AI-specific cybersecurity risks across the AI system lifecycle, including design, development, deployment, operation, production, and retirement.

The Guidelines apply, on a recommended basis, to entities in Saudi Arabia that use or plan to use AI systems. The scope includes emerging AI technologies such as generative AI and agentic AI. Importantly, the draft states that the Guidelines are not mandatory, but are intended to help entities implement minimum cybersecurity best practices and reduce cybersecurity risks arising from the use of AI technologies.

The draft is structured around 4 main domains, 15 subdomains, and 42 guidelines. The main domains are cybersecurity governance, cybersecurity defense, cybersecurity resilience, and third-party cybersecurity.

the draft sets out practical cybersecurity measures for AI systems, including AI cybersecurity risk management, security-by-design requirements, secure handling of data retrieved from external tools and APIs, review and testing of AI-generated code, approval processes for high-impact AI systems, human oversight of AI agents, personnel vetting, confidentiality obligations, and AI-specific cybersecurity awareness and training.

The draft Guidelines are open for comments until 5 August 2026.

2. EU: Identification and Assessment of Prominent and Recurrent Systemic Risks Reported by VLOPs and VLOSEs, Report, July 2026

The EU Digital Services Act requires the European Board for Digital Services (‘the Board’) in cooperation with the Commission to publish comprehensive reports once a year, identifying and assessing the most prominent and recurrent systemic risks reported by providers of very large online platforms and of very large online search engines or identified through other information sources.

This report is the second year’s edition of the Article 35(2) report. The first edition was adopted by the Board and published on 18 November 2025.

Similarly to the first edition of the report, risks related to the dissemination of illegal, unsafe or restricted products were identified by nearly all providers and civil society organisations (“CSOs”), but in particular with regard to online marketplaces. Examples of illegal products identified by providers and CSOs included, for example, unsafe, dangerous and/or non-compliant products (e.g. lacking CE markings, or products including toys made with hazardous or prohibited materials or substances), medical products and devices which may only be marketed via regulated channels, hazardous chemicals and pesticides, unsafe electrical goods, and IP-infringing products such as counterfeits.

Systemic risks related to the fundamental right to consumer protection are also highlighted. For example, providers and CSOs have noted systemic risks resulting from fake engagement, including fake or manipulated reviews, which may affect consumers’ choices by limiting their ability to distinguish authentic from inauthentic feedback. In the same context, risks related to merchant impersonation as well as the misrepresentation of business or product information have also been highlighted by online marketplaces.

The report outlines various practices that providers can use to mitigate these systemic risks. For example: 

  • Pre-screening and pre-listing interception tools to stop prohibited or unsafe products before they go live
  • Automated and manual detection of mis-categorised, illegal, harmful, counterfeit, or non-compliant products, including keyword matching and fraud-detection tools
  • EU-based third-party monitoring and sampling of live listings to catch repeated uploads and prevent bad actors from re-listing goods
  • Daily spot checks on physical products, plus controls for document compliance, expiry, and correct product categorisation
  • Stronger account or seller sanctions, such as suspensions, terminations, store bans, and preventing repeat offenders from reopening new stores

3. EU: Per- and Polyfluoroalkyl Substances: Tackling ‘Forever’ Chemical Pollution, Briefing Document, July 2026

This Briefing Document was published on 14 July 2026. 

It mentions that the EU legislation has increasingly covered Per- and polyfluoroalkyl chemicals (‘PFAS’), with decisive Parliament input. However, regulatory steps taken so far are fragmented and cannot effectively address PFAS risks. 

Due to the sheer number of PFAS, regulating them individually is impractical and inadequate. The EU chemicals strategy for sustainability committed to regulate PFAS as a group. 

The European Chemicals Agency is assessing a wide-ranging restriction proposal (targeted ban) under the EU Regulation on the registration, evaluation, authorisation and restriction of chemicals (REACH) that covers nearly 10 000 compounds. 

PFAS contain carbon-fluorine bonds, one of the strongest chemical bonds in organic chemistry, making them resistant to degradation. The favourable physicochemical properties that make PFAS valuable for countless applications and products pose huge environmental challenges, as PFAS are persistent. 

There is a need to protect citizens’ health and preserve essential natural resources, and on the other hand there are technical and economic challenges for businesses; Europe’s need to catch up on innovation; and PFAS risks for investors and insurers. 

The European Chemicals Agency is expected to transmit its final opinion to the European Commission by the end of 2026. Parliament will scrutinise the Commission’s draft restriction.

4. Ireland: Consumer Product Safety Recall Guidelines, July 2026

In July 2026 The Competition Consumer Protection Commission in Ireland updated the guidelines for consumer product recalls.

This guidance explains how a business should conduct a product recall by ensuring affected consumers are reached as directly and widely as possible. The business should first try to contact consumers individually, using customer registers, loyalty schemes, email, phone, or post. Where individual contact is not possible, it should make a public announcement through suitable media, its website, retail premises, distributors, social media, and newsletters. The CCPC should be informed where and how the recall notice has been published, and it may require further communication if the business’s efforts are not sufficient.

To ensure that as many consumers as possible become aware of the recall the business should consider communicating to consumers who have purchased the affected products. The announcement of a recall should be strongly worded, inform consumers to stop using the product and clearly identified as an urgent communication. 

When alerting consumers to a dangerous product and of the product’s recall, the business should primarily attempt to contact consumers on an individual basis. If the business maintains a loyalty customer system or other customer register for communication or marketing purposes, the company can use these electronic contact channels for individual communication on the recall. This information can also be communicated by post.

If the business is unable to individually contact all consumers who have purchased the product, the company can consider carrying out effective public communication on the matter.

A good and clear recall notice:

  • Draws attention, stands out clearly from advertisements and is large enough
  • Has the word “RECALL” in the heading. If a different measure is involved, this can be described in the heading, such as “IMPORTANT SAFETY NOTICE”
  • Includes a picture and identifying information of the product, such as the trade name or brand, model, batch or serial number, rating plate, or similar
  • States clearly what kind of a risk the product may pose and why; for example: too long cords in the head and neck area of small children’s hoodies may pose a risk of choking
  • Includes clear instructions for consumers on how to act; for example: stop using the product immediately/take the product away from the reach of children and return it to the place of purchase
  • Includes a phone number or online contact information

A business must use the recall notice template when posting a recall notice to consumers.

5. Canada: Sustainable Finance Taxonomy, Consultation Paper, July 2026

On 7 July 2026, the Canadian Sustainable Finance Taxonomy Consultation Paper was published for comment. Public feedback will help inform the final version of the Canadian Sustainable Finance Taxonomy: Methodology Report, which will serve as the “North Star” for the development of sustainable investment guidelines for major sectors of Canada’s economy

A taxonomy works as a voluntary guidebook for sustainable investment. It establishes credible, science-backed definitions for economic activities that align with climate goals.

The first phase of Canada’s taxonomy will focus on activities that reduce carbon emissions in alignment with the country’s legislated target of net zero emissions by 2050. The independent Canadian Taxonomy and Transition Planning Council, working in collaboration with the Canadian Climate Institute and Business Future Pathways, has been mandated by the Federal government to develop taxonomy guidelines for six sectors by the end of 2027. 

Based on historical emissions, potential to decarbonize and to enable decarbonization across other sectors, and investment promise, the Council has prioritized: 

  • Electricity 
  • Buildings 
  • Transportation 
  • Mining 
  • Manufacturing 
  • Agriculture/forestry. 

The deadline for comments is 13 August 2026.

See Adherent in Action

Discover how agentic AI is reshaping product compliance for global enterprises.

Authors

Ani Nozadze

Senior Regulatory Compliance Specialist, Team Lead

Global regulatory compliance professional with expertise in privacy/personal data protection and emerging digital regulations.

Sign up to our

Monthly Market Insights

Our Connect Newsletter delivers the latest regulatory developments, trends and expert insights straight to your inbox.