AI Compliance Weekly — 2026-08-16

weekly roundup7 regulations3 frameworks

This week’s biggest signals came from the US and EU. In the US, FDA finalized guidance on clinical decision support software, while the FTC escalated both AI marketing enforcement with Workado and a formal inquiry into AI companion chatbots. In Europe, the AI Office and financial supervisors signaled tougher governance expectations for frontier AI in financial services, tying AI Act implementation more tightly to DORA-style risk controls. Separately, NIST confirmed the AI RMF 1.0 is being revised under the White House AI Action Plan, and California’s AI bill activity shows state-level compliance tracking is still very active.

US Federal & State Regulation

high

FDA final guidance narrows CDS software scope

FDA’s January 2026 final guidance clarifies when clinical decision support software is outside device regulation and when FDA oversight still applies. AI health tools should be re-triaged now against the final criteria, especially where the product may still fall within device oversight.

Why it matters: Health AI teams need to confirm intended use, clinician transparency, and whether users can independently review the basis for recommendations. Products that no longer qualify as outside device regulation may need premarket review or other FDA controls.

Read source →
high

FTC order punishes misleading AI accuracy claims

The FTC entered a final order against Workado after finding false claims about AI content-detection accuracy. The order requires substantiation and multi-year compliance reporting, making AI marketing claims an active enforcement target.

Why it matters: Companies need competent and reliable evidence before making performance claims in product pages, sales decks, or customer materials. Unsupported absolute claims now carry real enforcement and reporting risk, not just reputational exposure.

Read source →
medium

FTC opens inquiry into AI companion chatbots

The FTC launched a formal inquiry into AI companion chatbots, signaling closer scrutiny of data practices, age protections, and safety controls. The inquiry does not impose a new rule, but it creates immediate information-preservation and governance pressure.

Why it matters: Teams should document collection, retention, and use of chatbot data, plus age-gating and escalation procedures for harmful outputs. Vendors and internal records may be requested, so preserving relevant materials now reduces downstream risk.

Read source →
medium

California SB947 targets employment AI systems

California SB947 would regulate employment automated decision systems used in hiring, promotion, and screening. The bill is still moving through the legislature and has not been enacted.

Why it matters: Employers and HR vendors should inventory employment AI now and assess likely notice, human review, and bias-risk controls. Procurement and legal teams should also map vendor responsibilities so they are ready if the bill advances.

Read source →
medium

California AI bills advance on key use cases

Multiple California AI bills moved forward on August 12-13, 2026, including measures on automated decision systems, agentic AI, transparency, and health-care AI. These are not enacted laws yet, but they indicate active state-level momentum.

Why it matters: Companies operating in California should treat legislative monitoring as an immediate compliance task, especially for HR, health, and critical-infrastructure AI use cases. Teams may need rapid gap analyses if any bill becomes law.

Read source →

EU AI Act

high

EU supervisors tighten frontier AI governance expectations

The EU AI Office and financial supervisors are calling for enhanced governance and more consistent supervision of frontier AI models in financial services. The message is that AI Act implementation in regulated finance now needs to align with supervisory expectations, not just internal policy.

Why it matters: Financial firms should map frontier AI and other high-impact use cases to existing governance and ICT-risk controls right away. Model documentation, escalation paths, and transparency measures may need to be updated for board and supervisory review.

Read source →

NIST AI RMF

medium

NIST begins revising AI RMF 1.0

NIST said the AI RMF 1.0 is being revised under the July 23, 2025 White House AI Action Plan. The update is in progress, so organizations should expect revised implementation guidance and profiles rather than a static framework.

Why it matters: Teams using the AI RMF as a governance backbone should plan for periodic reassessment of their controls and mappings. Crosswalks with cybersecurity and critical infrastructure profiles may change, affecting how programs are documented and defended.

Read source →

On Our Radar

California bill watching: California’s AI legislative stack is moving quickly, especially around employment systems, transparency, and health-care AI. Companies with California exposure should expect repeated scope changes before any final enactment.

FTC AI marketing scrutiny: Workado shows the FTC is willing to act on AI performance claims, not just privacy or safety issues. Marketing, legal, and product teams should tighten evidence files for any claim involving accuracy, detection, or safety.

Financial-sector AI governance: EU financial supervisors are signaling that frontier AI will be assessed through both AI Act and ICT-risk lenses. Expect closer alignment with DORA-style governance, reporting, and control expectations.

NIST revision cycle: The AI RMF revision is underway, which means existing AI governance programs may need a refresh once companion profiles are published. Organizations using NIST as their reference point should avoid treating current mappings as final.

Frameworks Covered

US Federal & State RegulationEU AI ActNIST AI RMF

Weekly digest

Leave your email to get each issue in your inbox. Free, no account required.

We use your email only for the digest. Privacy policy