This week the EU AI Act moved from planning to implementation, with the Commission issuing Article 50 transparency guidance and Regulation (EU) 2026/1744 amending the Act to bring new prohibitions and transparency duties into force from 2 December 2026. In the US, the FTC continued to signal active enforcement against deceptive AI claims, while FDA guidance reinforced lifecycle expectations for AI-enabled medical devices. In Europe and the UK, supervisory guidance remains live: the ICO says its AI guidance is still active and under review, and Switzerland’s FDPIC confirmed the Federal Data Protection Act applies directly to AI-supported processing. Singapore also updated its Model AI Governance Framework for agentic AI, pushing organizations to revisit accountability, transparency, and human oversight.
EU AI Act
EU publishes Article 50 transparency guidance
The European Commission published guidance on Article 50 transparency obligations ahead of the 2 August 2026 applicability date. The guidance is aimed at providers and deployers of certain AI systems and explains how the Commission expects labeling and disclosure duties to be operationalized.
Why it matters: Teams need to turn provenance, labeling, and user-disclosure requirements into working controls now, not after enforcement begins. If your AI outputs can be generated or manipulated content, Article 50 workflows need to be ready in production and in downstream contracts.
Read source →Regulation (EU) 2026/1744 resets AI Act controls
The European Parliament and Council adopted Regulation (EU) 2026/1744, which amends the AI Act and makes new prohibitions on realistic intimate and deepfake-style synthetic content operative from 2 December 2026. It also updates Article 50 transparency obligations and introduces further changes to governance, literacy, bias-detection, documentation, and monitoring requirements.
Why it matters: Organizations using generative or synthetic-content tooling need to revisit prohibited-use lists, labeling workflows, and post-market monitoring now because the operative date is fixed. This also affects how compliance teams map sectoral rules and SME-oriented obligations against AI Act requirements.
Read source →US Federal & State Regulation
FTC keeps pressure on deceptive AI claims
The FTC’s AI enforcement hub and recent actions show continued scrutiny of misleading performance, capability, and compliance claims. The agency is signaling that AI marketing statements remain a Section 5 risk, especially where claims are not substantiated.
Why it matters: Marketing, sales, and investor materials now need evidence before publication, not after a challenge. Compliance teams should expect document-retention and compulsory-process demands if product claims overstate accuracy, automation, or regulatory readiness.
Read source →California AI privacy activity stays active
California’s privacy and AI legislative tracker shows continuing state-level momentum on transparency, governance, and AI-specific consumer rights. The tracker indicates that AI-related consumer protections may continue to layer onto CCPA/CPRA obligations.
Why it matters: Deployers with California exposure should keep notice, access, and opt-out workflows aligned with evolving AI use cases. The practical risk is regulatory drift, where new state requirements land faster than enterprise control frameworks are updated.
Read source →GDPR / Data Protection Enforcement
ICO keeps AI guidance live and under review
The ICO said its AI guidance is not statutory, but it is actively used in audit and enforcement and remains under review because of newer UK data legislation. The guidance continues to shape how organizations should assess AI use under UK GDPR.
Why it matters: UK teams should treat the guidance as supervisory reality, not optional reading, when setting lawful basis, fairness, transparency, security, and rights-handling controls. DPIAs and AI impact assessments need evidence that maps directly to the ICO’s expectations.
Read source →FDPIC says Swiss data law applies to AI now
Switzerland’s FDPIC reiterated that the Federal Data Protection Act applies directly to AI-supported processing. The regulator said organizations should not wait for a separate AI statute before addressing transparency, automated-decision, and human-review issues.
Why it matters: Swiss deployments need documented purposes, data sources, and explanations of functionality now, especially where automated decisions could require human review or contestability. The message is that AI does not sit outside existing data-protection law, so gaps are already enforceable risk.
Read source →ISO Standards
Agentic AI controls need a refresh in Singapore
IMDA updated Singapore’s Model AI Governance Framework for agentic AI, replacing older assumptions from the 2024 GenAI framework. The update is guidance, but it is now the current Singapore baseline for autonomous and multi-agent systems.
Why it matters: Organizations using agentic AI should revisit human-accountability models, bounding-use-case rules, and controls for third-party agents and automation bias. User-facing transparency and training materials also need updating if systems can act autonomously.
Read source →US Federal & State Regulation
FDA expands lifecycle expectations for AI devices
FDA’s AI/ML medical device guidance set and device list continue to expand, reinforcing expectations for premarket evidence, transparency, and change control. The guidance emphasizes predetermined change control, performance evaluation, and good machine-learning-practice artifacts across the product lifecycle.
Why it matters: Health-tech teams need to align submissions, labeling, and post-market change management with FDA expectations before new or modified systems are marketed. Compliance evidence should be organized around lifecycle controls, not just the initial model approval packet.
Read source →On Our Radar
2 August AI Act date: Article 50 transparency obligations are approaching fast, and the Commission has already published implementation guidance. Teams should expect labeling and disclosure controls to be tested against the new standard almost immediately.
December 2026 prohibitions: Regulation (EU) 2026/1744 pushes new AI Act prohibitions into force on 2 December 2026. Organizations handling synthetic media should review prohibited-use policies and escalation paths now.
Supervisory AI guidance drift: The ICO and FDPIC both show that existing data-protection law is being applied directly to AI use cases. Expect more enforcement-grade guidance before any new AI-specific statutes fully settle.
FTC claim substantiation risk: The FTC’s AI hub suggests deceptive claims will remain a live enforcement theme. Product, legal, and marketing teams should keep substantiation files ready for any externally facing AI claims.