Cosmetics Regulatory Risk: Ingredients & Lawsuits in 2026
In 2026, cosmetics regulatory risk is coming from several fronts at once, and the source is not always obvious. Regulators are reviewing specific ingredients while courts weigh lawsuits brought by thousands of consumers. A generation of content creators is also doing its own research, sometimes with more rigor than the brand’s own communications.
The usual suspect
Formaldehyde remains the clearest example of how scientific evidence and regulation can move at different speeds. In the US, the FDA has delayed its proposed rule on formaldehyde in hair straightening products six times since 2023, with November 2026 now the target. In the EU, formaldehyde as a direct ingredient has long been banned under Annex II of Regulation (EC) 1223/2009. Formaldehyde-releasing preservatives remain permitted under Annex V, but the labelling threshold has fallen from 500 ppm to 10 ppm.
A 2022 NIH study (Chang et al., JNCI) followed 33,947 women in the Sister Study for close to eleven years. It found an association between frequent use and a nearly 2.5 times higher risk of uterine cancer compared with never using hair straighteners.
When an ingredient controversy reaches the courts
That study is now a central piece of evidence in one of the largest class-action litigations in the US cosmetics sector. More than 12,000 lawsuits over hair straightening products are consolidated in multidistrict litigation (MDL 2873) before the federal court for the Northern District of Illinois. L’Oréal is among the named manufacturers, while plaintiffs allege increased risks of uterine, ovarian, or endometrial cancer from using these products. The case remains in its science-evidence phase: a “Science Day” was held in January 2026, but no settlement or final ruling has followed. Those are allegations in an ongoing case, not established liability.
When the problem isn’t the ingredient, it’s the channel
Not every alert about a banned ingredient points to the manufacturer. This summer, Hong Kong detected the banned dye Sudan Red in a Medicube cream, while Singapore suspended sales pending its own tests. Weeks later, the dye appeared only in batches sold by a parallel-import reseller. It was absent from the brand’s official channel, and Medicube’s official Singapore entity was cleared.
One creator raised another issue in her breakdown: according to her, the brand’s lab could not detect dye concentrations below 10 ppm. Hong Kong detected 1.5 ppm, so “not detected” might reflect the test’s sensitivity rather than the dye’s absence. That reading is a social media interpretation, not a finding confirmed by the health authority, but it shows why a lab’s detection threshold matters.
Korea also suspended advertising on two Medicube products that month over phrases such as “regeneration” and “pore improvement,” which sounded too medical for a cosmetic.
The new front: who’s talking about the ingredient
Scrutiny used to center on the brand, but it now extends to the people talking about ingredients online. Since October 2025, China has required creators discussing “professional” topics to hold verified credentials with platforms within a two-month window. The requirement includes medical-adjacent language, so it overlaps with terms already sensitive for cosmetics. This is a rule for creators, yet the same vocabulary can also get a cosmetic product into regulatory trouble.
A creator who cites a study, its figures, and its source is informing an audience. Someone who says “never buy this brand” without substantiation is doing something else, and regulators are starting to notice the difference.
The practical takeaway on cosmetics regulatory risk
An ingredient controversy, a lawsuit, a market alert, and a viral video involve different risks, but each requires a brand to verify the source. A study needs to be read before a brand reacts to a headline; a batch needs to be traced before responsibility is assumed. The credentials behind a claim also matter before a brand shares it or lets it circulate without context.
Cosmetics regulatory risk now comes from several places at once, so the question is whether a brand knows where an alert began.
Frequently asked questions
Is it illegal to use formaldehyde in a cosmetic product?
It depends on its form: the EU bans formaldehyde as a direct ingredient under Annex II of Regulation (EC) 1223/2009. Formaldehyde-releasing preservatives remain permitted under Annex V, but they now carry a 10 ppm labelling threshold.
Does the lawsuit against L’Oréal mean its products are dangerous?
A lawsuit alone does not establish that: the claims remain allegations in MDL 2873, with no settlement or final ruling to date. The case is still in its science-evidence phase.
What actually happened with the banned dye found in a Medicube product?
The dye appeared only in batches sold by a parallel-import reseller, while the brand’s official channel was unaffected. Medicube’s official Singapore entity was cleared after the health authority’s investigation.
Can an influencer say an ingredient is dangerous without legal consequences?
They can if they cite a source, a study, and a specific figure, but legal risk appears when an unsubstantiated claim targets a specific brand or product without a technical basis.
What should a brand do if it’s named in an alert like this?
A brand should check whether the product came through its official channel or an unauthorized reseller. Only then should it consider a public response, because reacting too early often creates more noise than clarity.