Investment & Regulation

The Seqlense Regulatory Brief - Crypto & TradFi - Edition #25 (English)

The Seqlense Regulatory Brief - Crypto & TradFi - Edition #25 (English) Edition #25 examines how personal data law is beginning to capture the behaviours of AI itself. On 17 September 2026, the European Commission presented the KIDS Act, a proposed regulation protecting minors online that covers social networks, video platforms, games, app stores and AI companions, combining privacy-preserving age verification with a specific regime for AI chatbots. In parallel, the Spanish AEPD received the first notification in Spain of a data breach attributed to a largely autonomous AI agent, testing the GDPR's security standards (Articles 32 to 34). In both cases, AI is no longer merely a system to be regulated: it is becoming an actor whose behaviours, simulated relationships or autonomous attacks, fall directly within data protection law.

2026-09-21 AIGDPRdata
Free note PDF preview
  Download
Like this analysis? Subscribe to unlock every premium note and weekly newsletters.
Sign in & subscribe

About the author

Cécile Henry

Cécile Henry

Regulatory and compliance expert at Seqlense. Cécile authors every Seqlense Note — bringing hands-on experience and a pragmatic approach to regulatory analysis, with a focus on real operational impact rather than abstract theory. Her work covers French, Luxembourg and Belgian regulators, EU frameworks (MiCA, DORA, AML), and the operational reality of compliance in financial services and crypto.

View LinkedIn profile →

Speak with Sales

Schedule a demo, access technical documentation, or receive a customized compliance assessment.

Reach our team Request a demo