AI Compliance Weekly — 2026-08-02

weekly roundup12 regulations5 frameworks

This week’s biggest shift is in the EU AI Act: the AI Office says GPAI and transparency obligations start applying from 2 August 2026, alongside a transparency code for AI-generated content. In the EU financial sector, the EBA, EIOPA and ESMA warned that frontier AI is now a live ICT-risk issue under DORA and related security expectations. In the US, the SEC and FTC kept pressure on AI marketing and disclosure, with new enforcement and oversight signals around false AI claims, while Switzerland’s FDPIC reiterated that existing data-protection law already applies directly to AI-supported processing.

EU AI Act

critical

EU AI Office starts GPAI enforcement on 2 August

The European Commission’s AI Office issued GPAI compliance guidance and confirmed that full enforcement of GPAI and transparency obligations begins on 2026-08-02. The guidance is non-binding, but it is explicitly tied to operational readiness for providers and deployers under the EU AI Act.

Why it matters: Providers now need evidence-ready workflows for model documentation, safety/security, copyright, and transparency controls. If you touch GPAI or generate/manipulate content, this is now a live compliance date, not just a policy signal.

Read source →
high

AI-generated content code aligns with Article 50 duties

The AI Office promoted a Code of Practice on transparency of AI-generated content, designed to support compliance with Article 50. It applies from 2026-08-02 and focuses on labeling and provenance for synthetic or manipulated content.

Why it matters: Teams that publish or distribute AI-generated content need operational controls for labeling, disclosure, and retention of provenance records. Voluntary adoption may also become a practical benchmark for whether a company can demonstrate good-faith compliance.

Read source →
medium

CJEU reference may narrow AI system classification

A CJEU preliminary reference asks whether software using AI elements can qualify as a high-risk AI system under the EU AI Act. The reference does not itself change the law, but it could shape how hybrid software is classified and overseen.

Why it matters: Compliance teams should re-check high-risk assessments for products that combine AI and conventional software, because classification could affect oversight, traceability, and documentation duties. This is especially relevant where internal memos assume non-AI components keep a system outside the Act.

Read source →

DORA

high

ESAs warn frontier AI is an ICT-risk issue

The EBA, EIOPA and ESMA issued a joint statement on 2026-07-31 calling for a cross-sector, risk-based and consistent supervisory approach to frontier AI models. They said the ICT risks created by these models are now a live concern in EU financial supervision.

Why it matters: Financial entities should inventory frontier AI use and map it into ICT, operational, and third-party risk controls already used for DORA and NIS2. Supervisory scrutiny is likely to focus on model lifecycle governance, escalation, and evidence that AI testing is integrated into security oversight.

Read source →

GDPR / Data Protection Enforcement

high

Swiss FDPIC says AI processing is already covered

The FDPIC reiterated that Switzerland’s data-protection law applies directly to AI-supported processing. It said transparency, purpose limitation, and data-subject rights must be built into AI operations now, without waiting for future AI legislation.

Why it matters: Swiss teams cannot treat AI governance as a separate future regime; current FADP obligations already apply to data collection, training, and deployment. That means lawful purpose, notices, objections, access, correction, and review workflows need to be in place for AI use cases today.

Read source →

US Federal & State Regulation

high

SEC charges advisers over false AI claims

The SEC charged two investment advisers for making false and misleading statements about their use of artificial intelligence. The action confirms that AI-washing in financial marketing and disclosures is a live enforcement issue.

Why it matters: Firms should align website copy, Form ADV disclosures, pitch materials, and client-facing claims with actual model use. Any statement about AI capabilities now needs substantiation, and evidence of functionality, testing, and governance should be preserved for exams or investigations.

Read source →
medium

SEC task force signals tighter AI oversight

The SEC created an AI Task Force to coordinate innovation and efficiency across the agency. While internal, the move suggests more structured agency oversight of AI-related supervisory and enforcement activity.

Why it matters: Compliance teams should expect more consistent SEC attention to AI-related disclosures, exam questions, and internal governance. Regulated firms should review how AI is used in advisory, trading, and recordkeeping workflows before expectations harden.

Read source →
medium

FTC opens inquiry into AI companion chatbots

The FTC launched 6(b) orders into AI companion chatbots, focusing on advertising, safety, and data-handling practices. The inquiry is not an enforcement action, but it signals close federal review of how these systems are designed and marketed.

Why it matters: Developers of consumer chatbots should be ready to explain claims about companionship, memory, emotional support, moderation, and escalation. Data collection, retention, and sharing practices, especially for minors or vulnerable users, may face direct FTC scrutiny.

Read source →
high

FTC penalizes deceptive accessibility AI claims

The FTC took action against misleading claims that an AI product could make websites WCAG-compliant. The case reinforces that product claims tied to compliance outcomes must be substantiated before they are marketed.

Why it matters: If you sell AI tools that promise legal, accessibility, or compliance results, marketing language now needs legal review and proof. Avoid absolute claims unless you can show testing, clear limitations, and any required human review dependencies.

Read source →
high

FTC finalizes DoNotPay order on AI lawyer claims

The FTC finalized an order against DoNotPay that prohibits deceptive 'AI lawyer' claims and adds monetary relief and consumer-notice obligations. The action makes unsupported legal-automation marketing an immediate enforcement risk.

Why it matters: Any consumer-facing claim that an AI tool can deliver legal or compliance outcomes needs pre-publication substantiation and legal review. Companies with similar claims should also track order-specific obligations if they are parties to related proceedings or settlements.

Read source →

Other jurisdictions / frameworks

low

Congressional AI bills remain horizon signals

Multiple AI-adjacent bills and resolutions in the 119th Congress were introduced or advanced, but they do not yet create binding federal AI obligations. The activity is best read as legislative tracking rather than immediate compliance change.

Why it matters: Policy teams should monitor whether any of these measures start carrying disclosure, governance, or procurement requirements. Until then, they should not be treated as operational compliance duties.

Read source →
high

FDA seeks comments on AI medical device evaluation

The FDA opened public comment on how to measure and evaluate AI-enabled medical device performance in the real world. The consultation focuses on post-market monitoring and drift management for AI/ML-enabled devices.

Why it matters: Medical device teams should review whether current surveillance, evidence collection, and drift-detection controls will satisfy likely FDA expectations after the consultation closes. Regulatory, quality, and security functions need to coordinate now if AI-enabled devices are in scope.

Read source →

On Our Radar

GPAI enforcement begins: The EU AI Office says GPAI and transparency obligations apply from 2 August 2026. Providers and deployers should watch for how quickly enforcement and code adoption shape practical expectations.

Frontier AI under DORA scrutiny: EU financial regulators are signalling that frontier AI is now part of ICT-risk supervision. Expect closer attention to governance, third-party dependencies, and model lifecycle controls.

AI marketing claims under fire: SEC and FTC actions show regulators are focusing on false or overstated AI claims. Product, sales, and legal teams should keep tightening substantiation before publication.

AI data rights stay immediate: The FDPIC’s Swiss guidance is a reminder that existing data-protection rules already cover AI processing. Similar arguments are likely to keep showing up in other jurisdictions as AI-specific laws mature.

Frameworks Covered

EU AI ActDORAGDPR / Data Protection EnforcementUS Federal & State RegulationOther jurisdictions / frameworks

Weekly digest

Leave your email to get each issue in your inbox. Free, no account required.

We use your email only for the digest. Privacy policy