AI Compliance Weekly — 2026-08-23

weekly roundup9 regulations5 frameworks

This week, the clearest enforcement signal came from the US FTC, which is sharpening scrutiny of deceptive AI claims through the DoNotPay order, the MindSift matter, and its AI enforcement hub. In the EU, EBA, EIOPA and ESMA called for stronger governance of frontier AI-related ICT risks, reinforcing expectations under DORA and NIS2 for financial firms. In the US health-tech space, FDA’s draft guidance for AI-enabled medical devices pushes lifecycle documentation, bias controls, and post-market monitoring to the forefront. California also kept AI legislation moving, with bills on healthcare AI, automated decision systems, and transparency advancing in the legislature.

US Federal & State Regulation

high

FTC tightens rules on deceptive AI lawyer claims

The FTC finalized its DoNotPay order in February 2025, prohibiting deceptive claims that AI can serve as a lawyer and requiring monetary relief and notice. The order is a concrete enforcement benchmark for AI products making professional-services claims.

Why it matters: Legal-assistance, compliance, and advisory AI products should immediately review marketing language, disclaimers, and evidence files. Any claim that suggests replacement of a licensed professional now carries obvious Section 5 risk.

Read source →
high

FTC MindSift case targets AI consent claims

The FTC matter against MindSift alleges deceptive claims around AI-powered active listening and opt-in behavior. The case highlights scrutiny of whether product capabilities and data-collection disclosures match actual system behavior.

Why it matters: Vendors using AI for ad targeting, listening, or audience profiling should verify that consent language, sales claims, and privacy notices reflect real data flows. Mismatches can now become enforcement issues quickly, even when framed as product innovation.

Read source →
high

FTC AI hub spotlights active Section 5 risk

The FTC’s AI hub consolidates recent enforcement and policy actions, making clear that unsupported AI performance, bias, and compliance claims remain a live priority. It also reinforces the need for disclosures about material limits, human involvement, and validation constraints.

Why it matters: Teams should treat AI product pages, sales decks, and customer promises as enforcement-sensitive content. Keep testing, benchmarking, and approval records ready, because the FTC is signaling it will ask for substantiation.

Read source →
medium

California AI bills advance on healthcare and transparency

California state bills AB2575, SB947, SB503, AB1979, and SB1159 advanced in late August 2026. The package points to continued legislative movement on healthcare AI, automated decision systems, and AI transparency and governance.

Why it matters: California teams should map affected product lines, employment tools, and disclosure obligations now so they can react if any bill advances further. Even without enacted law yet, the bills signal likely state-specific compliance work on AI governance and review processes.

Read source →
low

Congressional AI measures remain mostly non-operative

The source material references several congressional AI-adjacent measures, but it does not identify a current enacted federal AI statute with immediate compliance effect. The update is mainly a reminder to verify scope and legislative stage before treating congressional text as an operative obligation.

Why it matters: Compliance teams should avoid adding historical or unrelated bills to obligation registers without confirming that they are current and AI-relevant. Congress pages are useful status sources, but not proof of binding AI duties.

Read source →

DORA (Digital Operational Resilience)

high

EU supervisors push frontier AI ICT governance

On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to strengthen governance and supervision of frontier AI-related ICT risks. The message is supervisory guidance, not new legislation, but it clearly raises the bar for resilience controls and oversight.

Why it matters: Financial firms should map frontier AI dependencies into ICT risk, incident response, and vendor oversight processes now. Boards should expect evidence of accountability, monitoring, and escalation paths aligned with DORA-style resilience expectations.

Read source →

FDA / Medical Devices

high

FDA draft guidance raises AI device lifecycle bar

FDA’s January 2025 draft guidance for developers of AI-enabled medical devices puts lifecycle documentation, transparency, maintenance, and bias controls at the center of review. It also points to ongoing expectations around post-market monitoring and predetermined change control.

Why it matters: Medical device teams should align design, training, validation, and maintenance records to the draft expectations before submissions and QMS updates get locked in. The guidance suggests FDA will expect evidence of bias management, drift monitoring, and transparent user-facing materials.

Read source →

ISO Standards

medium

NIST draft SP 1353 opens comment window

NIST issued the initial public draft of SP 1353 on 2026-08-19 and set comments due by 2026-10-15. The draft addresses AI-enabled CSF analysis and reporting, making it relevant for teams using AI in control mapping, monitoring, or security reporting workflows.

Why it matters: Security teams using AI to support CSF 2.0 analysis should review whether the draft changes their operating assumptions or documentation model. If the guidance affects implementation, submit comments before the deadline and watch for the final version.

Read source →

Other jurisdictions / frameworks

medium

NIST draft informs AI-enabled security workflows

The SP 1353 draft is not binding yet, but it is an early signal of how NIST may shape AI use in cybersecurity reporting and analysis. The public comment deadline is 2026-10-15, so this remains a live consultation rather than final guidance.

Why it matters: Organizations that depend on AI for security control mapping or reporting should treat the draft as an opportunity to influence future implementation guidance. It is also a useful checkpoint for internal governance over AI-assisted security operations.

Read source →

On Our Radar

FTC AI claims scrutiny: The FTC’s recent actions suggest sustained attention on marketing language, capability claims, and consent representations for AI products. Vendors should expect Section 5 theories to remain a central enforcement tool.

California bill movement: AB2575, SB947, SB503, AB1979, and SB1159 are still moving, so California-specific AI obligations could emerge quickly. Product, legal, and policy teams should watch amendments and next readings closely.

EU frontier AI supervision: EBA, EIOPA and ESMA have signaled that frontier AI-related ICT risk will be a supervision priority. Financial firms should expect more pressure on board reporting, vendor controls, and resilience testing under existing frameworks.

NIST comment deadline: Comments on draft SP 1353 are due 2026-10-15. Teams using AI in cyber reporting should decide now whether to submit feedback or adjust internal workflows ahead of final publication.

Frameworks Covered

US Federal & State RegulationDORA (Digital Operational Resilience)FDA / Medical DevicesISO StandardsOther jurisdictions / frameworks

Weekly digest

Leave your email to get each issue in your inbox. Free, no account required.

We use your email only for the digest. Privacy policy