This week the EU AI Act moved from policy to implementation, with the European Commission and AI Office issuing operational guidance on transparency, GPAI obligations, and governance. In the US, the FTC sharpened enforcement risk around deceptive AI claims, while the FDA reinforced lifecycle expectations for AI-enabled medical devices. Canada’s Bill C-27 advanced in Parliament, and Switzerland’s FDPIC confirmed that the FADP applies directly to AI-supported processing with active supervisory attention. California also introduced multiple AI bills that could affect employment, health care, and agentic AI use cases.
EU AI Act
EU AI Office issues active AI Act implementation guidance
The European Commission and AI Office issued operational guidance covering transparency, GPAI obligations, and governance under the EU AI Act. The update signals that implementation is now a live compliance program, not just a future policy project, with Article 50 and GPAI code expectations in focus.
Why it matters: Providers need to map systems against transparency, GPAI, and high-risk obligations now, and build evidence packs that can support supervisory review. Teams considering the General-Purpose AI Code of Practice should assess whether signing it helps demonstrate compliance.
Read source →US Federal & State Regulation
FTC targets deceptive AI claims and accuracy gaps
The FTC is actively enforcing against deceptive AI claims and has proposed an AI accuracy policy statement. The agency’s current posture makes it clear that marketing, output accuracy, and performance representations are all potential Section 5 risk areas.
Why it matters: Compliance teams should substantiate every claim about automation, detection, accuracy, and performance with competent evidence. Customer-facing language, testing records, QA controls, and monitoring for hallucination or material limitations should be reviewed now.
Read source →FDA draft guidance raises bar for AI medical devices
FDA issued draft guidance for AI-enabled medical devices and continued emphasizing lifecycle documentation, predetermined change control plans, and real-world performance monitoring. The guidance reinforces that AI/ML device submissions need clear documentation of future model updates and ongoing postmarket oversight.
Why it matters: Device teams should update design, validation, submission, and quality-system documentation now, especially where model changes are expected. Postmarket monitoring and performance surveillance need to be built into the control environment, not treated as an afterthought.
Read source →California bills target employment and agentic AI
California introduced multiple AI bills affecting employment, health care, labor impacts, and agentic AI, with hearings and suspense-file movement already underway in early August 2026. The bills referenced include AB2575, AB1979, AB2545, SB947, and SB1106.
Why it matters: Employers and AI vendors operating in California should immediately assess whether their automated decision systems, agentic AI, or health-care tools fall within the bills’ scope. Internal position papers, operational impact assessments, and disclosure planning may be needed before the legislative cycle advances further.
Read source →State court decisions may shape AI liability
Recent state and federal court decisions may affect AI-related liability and employment disputes, but the source material treats them as developing precedent rather than settled regulatory rules. The cases could influence treatment of AI evidence, automated decision systems, and algorithmic discrimination in litigation.
Why it matters: Legal teams should preserve records for AI-assisted decisions and monitor how courts handle AI evidence and discrimination claims. Litigation counsel should be consulted before changing controls based on these cases, since the precedent is still developing.
Read source →White House keeps voluntary AI commitments as benchmark
The White House’s voluntary AI commitments remain a soft-law benchmark for frontier AI governance. The document continues to emphasize safety testing, provenance, cybersecurity, and information-sharing controls for advanced AI systems.
Why it matters: Organizations making public AI governance statements should check that their internal practices still match those commitments. Teams should retain red-team results, provenance and watermarking controls, and cybersecurity measures that can support those claims.
Read source →GDPR / Data Protection Enforcement
Swiss FDPIC applies FADP directly to AI
The FDPIC says the Swiss FADP applies directly to AI-supported processing and that it is actively pursuing investigations. The guidance highlights transparency, proportionality, purpose limitation, and readiness for human review of automated individual decisions.
Why it matters: Organizations processing personal data through AI in Switzerland need to document purpose, functionality, data sources, lawful basis, and objection pathways. DPIAs, decision logs, and vendor and data-flow records should be retained because they may be requested in an inquiry.
Read source →Canada’s Bill C-27 advances toward AI regime
Bill C-27’s AI and Data Act component has advanced in Parliament, signaling a future federal AI governance regime in Canada. The source describes commissioner oversight and serious-penalty exposure, but the statute is not yet enacted.
Why it matters: Organizations operating in or into Canada should map products and services that may fall within the proposed high-impact scope. Governance, audit, incident-response, and vendor inventories should be prepared so privacy programs can be extended into AI-specific obligations if the bill progresses.
Read source →ISO Standards
AI governance benchmarks remain tied to ISO 42001
Multiple updates this week referenced ISO/IEC 42001 as a governance benchmark for AI risk management, documentation, and control design. It appears in the context of EU AI Act implementation, FTC scrutiny, California bills, and data protection enforcement.
Why it matters: Teams using ISO/IEC 42001 can use it as a control framework to organize evidence, accountability, and monitoring across legal regimes. It is especially useful where regulators are asking for documented testing, governance, and lifecycle controls rather than one-off policy statements.
Read source →NIS2 / Cybersecurity
AI governance now tied to cybersecurity controls
This week’s AI updates repeatedly linked AI governance to cybersecurity controls, especially in the White House voluntary commitments, FDA lifecycle expectations, and FTC enforcement posture. The common thread is that secure model access, testing, and monitoring are becoming core compliance expectations.
Why it matters: Security teams should ensure AI systems have access controls, testing records, and monitoring that can withstand regulatory scrutiny. If AI outputs or model access are part of customer claims or safety cases, weak cybersecurity controls can become a compliance issue as well as an operational one.
Read source →On Our Radar
EU AI Act rollout: The AI Office is now issuing implementation materials, so more operational guidance on transparency and GPAI obligations is likely to follow. Expect compliance teams to keep refining evidence packs and governance mapping rather than waiting for a single final rule.
FTC AI advertising risk: The FTC’s current enforcement posture suggests AI marketing claims will stay under scrutiny. Companies should expect continued focus on substantiation, accuracy, and avoiding implied capabilities their products do not actually have.
California legislative movement: The California bills referenced here already have near-term committee and suspense-file milestones. That makes the next few weeks important for tracking whether employment, health, and agentic AI proposals gain traction.
Canada and Switzerland readiness: Canada’s Bill C-27 and the FDPIC’s AI guidance both point to stronger AI-specific accountability outside the EU. Multinationals should keep privacy and AI governance programs flexible enough to support multiple jurisdictions.