Blog
Company updates, regulatory intelligence insights, and product news from Cleo Labs.

Regulation (EU) 2024/1781 — the Ecodesign for Sustainable Products Regulation (ESPR) — entered into force on 18 July 2024, replacing Directive 2009/125/EC. It extends ecodesign obligations to almost all physical goods sold in the EU, introduces the Digital Product Passport (DPP) and bans destruction of unsold consumer goods. This guide explains what ESPR requires, which products are in scope, how it interacts with REACH, the Battery Regulation and GPSR, and what to prepare before the delegated acts are published.

Seven days after open-sourcing the Cleo skills_library and its MCP server, here is the honest retrospective: the decision, what shipped in a week, what worked (dev.to traction, npm wedge), what flopped (awesome-llm-apps rejection, bad Show HN timing), and the roadmap for the next 60 skills.
On 3 June 2026, France’s consumer authority (DGCCRF) fined Shein over €22M — €5.77M and €16.73M across two entities — for hiding garment origin, undeclared microplastics, a denied 14-day withdrawal right and non-compliant order confirmations. Not a DSA case and not a safety ban: a transparency case that pushes France’s total fines on Shein past €210M and resets the traceability baseline for every textile brand.

Step-by-step guide: plug the @cleo-labs/skills-mcp package into Cursor, get 45 product compliance skills in any project, and run your first real compliance query in under a minute. No API key required for the base catalog.

Five product compliance scenarios — retinol cosmetics, Bluetooth CE marking, Japan supplement export, toy EN 71-3 migration limits, EU Battery Regulation deadlines — answered in 49 seconds total with the Cleo skills_library on Claude Code. With timings, citations and the cost they would have been the traditional way.

MARIA, the engine behind Cleo, moved to Claude Opus 4.8. We ran a head-to-head eval against Opus 4.7 on 5 real product cases, grading every cited regulation against the official source. 4.8: 5/5 correct verdicts vs 4/5, and a 2.7% citation-error rate vs 9.4%.

Cleo opens up Legal Atlas — a machine-readable legal database aggregating legislation, case law and doctrine from 1,494 official sources across 177 jurisdictions, exposed through a single REST API. Built for legal-tech, law firms and AI agents.

Cleo Labs just released a library of 40 production-grade compliance skills for Claude Code and AI agents. Install in 30 seconds. Powered by the Cleo Legal API. Open-source under MIT.
On 28 May 2026, the European Commission imposed a €200M fine on Temu under the Digital Services Act for failing to identify, analyse and assess the systemic risks of illegal products on its platform. The first DSA fine targeting illegal products on a marketplace — and what it means for European brands selling cosmetics, toys, electronics and jewellery.
Most PLM compliance modules are empty shells. The gap between having a PLM and being compliant is about the regulatory data you inject. Here's why data quality is the real bottleneck — and how to fix it.
The data behind Cleo grew more this month than in our entire first year. 50,101 regulations indexed (×2), 27,500+ authorities (+45%), +11 new countries including China, 134 organizations tracking 2,839 real products, +6 API filters, and Cleo as a connector inside ChatGPT.
Four product launches this month: +18 new countries (now 106 total, 234M+ legal documents), in-app AI chat with slash commands and @entity mentions, Cleo Insight as a connector inside Claude / Cursor / ChatGPT, and a public API v1 with seven endpoints.

Round led by Larry Berger, with Kima Ventures, Financière Saint-James, and several tech ecosystem figures — plus additional funding from Deel. Cleo Labs will accelerate technology development, structure European expansion, and prepare for entry into the U.S. market.

CE marking is the European passport for products. Roughly 25 harmonisation directives and regulations cover machinery, electrical equipment, radio devices, toys, medical devices, PPE, construction products and more — and from December 2027, software and connected devices join the list under the Cyber Resilience Act. Here is what 2026 actually requires across both worlds.

In 2024, cosmetics accounted for 36% of all alerts on EU Safety Gate — the leading category, ahead of toys, clothing and electronics. Three recent recalls (MCI/MI in leave-on creams, heavy metals in makeup, French PFAS law n°2025-188) show why compliance in cosmetics is not an event but a regulatory flow that has to be tracked across living annexes.

A product can look identical across markets — its legal status will not. Four real magnetic toy recalls from the UK and Canada show how a single technical threshold (flux index, small parts cylinder, warnings) separates a sellable product from one yanked off the shelves.

Every physical product sold globally faces 100+ regulations across R&D, manufacturing, labelling, and customs. Here's how Cleo Labs is automating global product compliance with AI — and why Deel just picked us as their winner at Station F.

A new research paper interviews EU-based data practitioners and exposes 5 systemic gaps between GDPR requirements and ML pipeline reality.

Kinder Surprise, Red Bull, melatonin gummies — these everyday products are perfectly legal in one country and completely banned in another. Here's why, and what it means for brands selling internationally.

A landmark paper introduces TRISM, the first framework to separate trust, risk, and security in multi-agent AI systems. 66 citations in 3 months — here's why compliance teams should pay attention.

A cosmetic product sold globally must comply with completely different regulatory frameworks in each market. The EU bans over 1,600 ingredients; the US bans 11. Japan requires quasi-drug classification for anti-aging claims. China mandates animal testing for imported ordinary cosmetics. This guide maps the key differences across five major markets.

Starting in 2027, the EU will require Digital Product Passports for textiles, electronics, batteries and more — every product will need a QR code linking to a structured dataset on its composition, origin, repairability and end-of-life. Here's how retail brands should prepare under ESPR (Regulation 2024/1781).

From CAS number screening to full formulation compliance across 106 countries — chemicals, packaging, labeling, and regulatory forecasting for South Africa, Mexico, EU, Brazil, China, India, and beyond.

Launching a product across 106 countries? Map every regulation — ingredients, labeling, safety, packaging — with AI-powered compliance intelligence.

Most compliance AI assumes regulatory text is authentic. A new research paper introduces DEF, the first framework that detects falsified legal documents.

Peer-reviewed 2026 studies confirm multi-agent AI can evaluate compliance across GDPR, AI Act, NIS2, and DORA — faster and more accurately.

The EU General Product Safety Regulation (GPSR, Regulation 2023/988) replaced the General Product Safety Directive on December 13, 2024. It applies to every non-food consumer product sold in the EU — from cosmetics to electronics to toys. Here is what brands need to do, with risk assessment, documentation and online-marketplace obligations.

Product compliance is the fastest-growing challenge for EU tech companies. This guide covers every framework from CE marking to AI Act.

From CNIL enforcement to Sapin II and the Duty of Vigilance law, here's everything tech companies need to know about regulatory compliance in France.

Beyond the directive itself, CSRD compliance is a massive data aggregation challenge. Here are the concrete problems large companies face.

Most companies confuse product compliance with corporate compliance. The distinction matters, especially in the EU, where product-specific regulations are multiplying faster than ever.

A data-driven breakdown of how GDPR enforcement varies across EU member states. Compare fines, enforcement patterns, and DPA priorities in 2026.

NIS2 dramatically expands cybersecurity obligations across the EU. This guide covers who's in scope, what's required, the penalties for non-compliance, and how to prepare.

The UK regulatory landscape has diverged from the EU since Brexit. From UK GDPR to FCA Consumer Duty, here's what European companies need to track.

GRC platforms were built for 5 regulations. Fintechs face 50+. Here's why compliance IT teams are switching to AI-powered regulatory intelligence.

Operating in both Brazil and the EU? Here's a practical comparison of LGPD and GDPR covering legal bases, DPO requirements, data transfers, and penalties.

Launching a fintech in the EU means navigating PSD2, MiCA, DORA, AML6, GDPR, and the AI Act. This checklist covers every regulatory step.

With high-risk AI system requirements taking effect in August 2026, compliance teams have months, not years, to prepare. A practical guide to AI Act obligations, timelines, and how to build readiness.
DORA is fully applicable, but many financial entities are still catching up. A practical tracker of every key deadline, requirement, and action item for ICT risk management compliance in 2026.

Regulatory complexity is outpacing compliance teams. Agentic AI — systems that reason, plan, and act autonomously — is the only viable response.

From GDPR's €5B+ in cumulative fines to AI Act penalties of 7% of global revenue, the cost of non-compliance in the EU has never been higher. Here are the numbers that matter.

AI tools for compliance are proliferating. But which ones actually deliver? A research-backed guide to evaluating AI compliance platforms, from regulatory monitoring to due diligence.

From keyword alerts to contextual intelligence: how AI-powered monitoring systems are replacing manual regulatory watch and giving compliance teams a decisive edge.

The RegTech market is projected to reach $42B by 2026. This landscape guide maps the key players, emerging categories, and the shift from reactive GRC to proactive regulatory intelligence.

A deep dive into the multi-agent AI architecture behind Cleo's regulatory risk scoring, from the 5-stage pipeline to the 30+ specialized agents that achieve 98.5% accuracy.

NIS2 and DORA are rewriting the rules for cybersecurity compliance in the EU. For tech companies, this means new obligations for incident reporting, risk management, and supply chain security.

From the EU AI Act enforcement wave to cross-border data transfer upheaval, here are the five regulatory trends shaping compliance strategy this year.

Regulators demand that AI-driven compliance decisions be auditable and explainable. Black-box models create risk even when they perform well. Here's how to build AI that regulators trust.

Manual third-party screening is slow, expensive, and error-prone. AI-powered due diligence collapses weeks of work into hours, with better coverage and full auditability.

Eight years after GDPR, enforcement has matured. Here's what compliance teams need to know about the regulation's new reality in 2026.