
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Sat, 16 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/nist-ai-rmf/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-privacy-ai-regulations-2026-gdpr-eu-ai-act-dsa-dma-pipa-appi-nist-ai-rmf-iso-42001-deep-dive.en</guid>
    <title>Privacy &amp; AI Regulation 2026 — GDPR / EU AI Act (Full Enforcement Aug 2026) / DSA / DMA / PIPA / APPI / NIST AI RMF / ISO 42001 Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-privacy-ai-regulations-2026-gdpr-eu-ai-act-dsa-dma-pipa-appi-nist-ai-rmf-iso-42001-deep-dive.en</link>
    <description>In May 2026, privacy and AI regulation has split into five camps. The EU has stacked the EU AI Act (effective Aug 2024, prohibitions Feb 2025, full enforcement Aug 2026), DSA, DMA, Data Act, and Cyber Resilience Act on top of GDPR (2018). The US still has no federal omnibus law, while 8 states actively enforce comprehensive privacy laws and IL BIPA forms a separate biometric front. Koreas PIPA was amended in 2024 to formalize pseudonymized data, MyData, and medical MyData; Japans APPI continues to refine foreign transfer and anonymized processing rules. Layered on top: China PIPL, Brazil LGPD, OECD AI Principles, NIST AI RMF, ISO 42001, and the multilateral AISI agreements. This article maps all of it in one place and turns &quot;what should we do?&quot; into a phased compliance plan.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>privacy</category><category>ai-regulation</category><category>gdpr</category><category>eu-ai-act</category><category>dsa</category><category>dma</category><category>data-act</category><category>cyber-resilience-act</category><category>ccpa</category><category>cpra</category><category>vcdpa</category><category>cpa</category><category>ctdpa</category><category>tdpsa</category><category>oapa</category><category>pipa-korea</category><category>appi-japan</category><category>pipl-china</category><category>lgpd-brazil</category><category>nist-ai-rmf</category><category>iso-42001</category><category>oecd-ai</category><category>aisi</category><category>2026</category><category>deep-dive</category><category>english</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-privacy-ai-regulations-2026-gdpr-eu-ai-act-dsa-dma-pipa-appi-nist-ai-rmf-iso-42001-deep-dive.ja</guid>
    <title>プライバシー &amp; AI 規制 2026 — GDPR / EU AI Act(2026.8 全面施行)/ DSA / DMA / PIPA / APPI / NIST AI RMF / ISO 42001 ディープダイブ</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-privacy-ai-regulations-2026-gdpr-eu-ai-act-dsa-dma-pipa-appi-nist-ai-rmf-iso-42001-deep-dive.ja</link>
    <description>2026年5月、プライバシー・AI 規制は5陣営に分かれた。EU は GDPR(2018)の上に EU AI Act(2024.8 発効、2025.2 禁止、2026.8 全面施行)、DSA・DMA・Data Act・Cyber Resilience Act を積み上げた。米国は連邦の包括法がないまま、8つの州が包括プライバシー法を運用し、IL BIPA が生体情報の別戦線を形成する。韓国 PIPA は 2024 改正で仮名情報・MyData・医療マイデータを整備し、日本 APPI は外国移転・匿名加工情報の運用を磨いている。その上に中国 PIPL、ブラジル LGPD、OECD AI 原則、NIST AI RMF、ISO 42001、AISI 多国間協定が乗る。この記事ではその全体図を一度に整理し、「自社で何をすべきか」を段階で示す。</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>privacy</category><category>ai-regulation</category><category>gdpr</category><category>eu-ai-act</category><category>dsa</category><category>dma</category><category>data-act</category><category>cyber-resilience-act</category><category>ccpa</category><category>cpra</category><category>vcdpa</category><category>cpa</category><category>ctdpa</category><category>tdpsa</category><category>oapa</category><category>pipa-korea</category><category>appi-japan</category><category>pipl-china</category><category>lgpd-brazil</category><category>nist-ai-rmf</category><category>iso-42001</category><category>oecd-ai</category><category>aisi</category><category>2026</category><category>deep-dive</category><category>日本語</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-16-privacy-ai-regulations-2026-gdpr-eu-ai-act-dsa-dma-pipa-appi-nist-ai-rmf-iso-42001-deep-dive</guid>
    <title>프라이버시 &amp; AI 규제 2026 — GDPR / EU AI Act (2026.8 전면 시행) / DSA / DMA / PIPA / APPI / NIST AI RMF / ISO 42001 심층 가이드</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-16-privacy-ai-regulations-2026-gdpr-eu-ai-act-dsa-dma-pipa-appi-nist-ai-rmf-iso-42001-deep-dive</link>
    <description>2026년 5월, 프라이버시·AI 규제는 다섯 진영으로 갈라졌다. EU는 GDPR(2018) 위에 EU AI Act(2024.8 발효, 2025.2 금지, 2026.8 전면 시행)와 DSA·DMA·Data Act·Cyber Resilience Act를 차곡차곡 쌓았다. 미국은 연방법이 없는 채로 8개 주가 활성 프라이버시법을 시행 중이고, IL BIPA는 별도의 생체정보 전선을 형성한다. 한국 PIPA는 2024 개정으로 가명정보·MyData·의료데이터를 정비했고, 일본 APPI는 외국 이전·익명가공정보의 운영을 가다듬는다. 그 위에 중국 PIPL, 브라질 LGPD, OECD AI 원칙, NIST AI RMF, ISO 42001, AISI 다자 협정이 얹힌다. 이 글은 그 모든 지도를 한 번에 정리하고, &quot;우리 회사는 무엇을 해야 하나&quot;를 단계로 풀어준다.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>privacy</category><category>ai-regulation</category><category>gdpr</category><category>eu-ai-act</category><category>dsa</category><category>dma</category><category>data-act</category><category>cyber-resilience-act</category><category>ccpa</category><category>cpra</category><category>vcdpa</category><category>cpa</category><category>ctdpa</category><category>tdpsa</category><category>oapa</category><category>pipa-korea</category><category>appi-japan</category><category>pipl-china</category><category>lgpd-brazil</category><category>nist-ai-rmf</category><category>iso-42001</category><category>oecd-ai</category><category>aisi</category><category>2026</category><category>deep-dive</category>
  </item>

    </channel>
  </rss>
