This week’s biggest signals came from the EU AI Act, EU financial-services supervisors, and the FTC. In Europe, the Commission is still shaping the EU AI Act rulebook through consultations on GPAI, transparency, high-risk classification, and sandboxes, while ESMA, EBA, and EIOPA pushed financial firms to tighten governance over frontier AI ICT risks under DORA-style expectations. In the US, the FTC stayed aggressive on deceptive AI claims and finalized more enforcement against misleading AI marketing, reinforcing that substantiation and disclosure are now core compliance issues. For regulated sectors, FDA, FINMA, NIST, and ISO all show that AI governance is moving from strategy to operational control and evidence.
EU AI Act
Commission consults on GPAI and transparency rules
The European Commission has open consultations on AI Act implementation issues covering general-purpose AI, transparency obligations, high-risk classification, sandboxes, and the scientific panel. The materials show the operational rulebook is still being finalized, so providers and deployers should expect interpretive detail to continue evolving.
Why it matters: Teams may need to adjust disclosure workflows, machine-readable content marking, and model classification decisions as the final guidance lands. If you sell or deploy into the EU, now is the time to compare current controls against the draft implementation direction.
Read source →DORA
EU supervisors press frontier AI governance in finance
On 2026-07-31, EBA, EIOPA and ESMA called for stronger governance and more consistent supervision to mitigate ICT risks from frontier AI models in financial services. The message is that firms should not wait for new hard law before tightening oversight of AI-linked operational resilience.
Why it matters: Financial institutions should map frontier AI use cases into ICT risk, incident escalation, and third-party oversight under DORA-style controls. Supervisors will likely expect evidence of monitoring, accountability, and resilience testing now, not after a formal rule change.
Read source →GDPR / Data Protection Enforcement
FTC keeps scrutiny high on deceptive AI claims
The FTC’s AI hub and related matters, including Rytr, Workado, and DoNotPay, show a continuing enforcement posture against deceptive AI claims and conduct. The agency is signaling that marketing, product, and investor-facing statements about AI remain under active review.
Why it matters: Companies need substantiation for claims about accuracy, automation, and service replacement, plus internal evidence to back those claims if challenged. This is especially relevant where AI messaging intersects with privacy disclosures, consent language, or customer promises.
Read source →FTC finalizes Cox Media Group AI orders
On 2026-08-27, the FTC finalized orders and $930,000 in settlements against Cox Media Group and two other firms over allegedly deceptive AI-powered “active listening” marketing claims and customer consent issues. The case reinforces that the FTC is moving beyond warnings into finalized enforcement.
Why it matters: Marketing and sales teams should verify that any AI targeting, analytics, or consent claims match actual product behavior and recorded disclosures. Vendors and partners that describe AI-driven services can create enforcement exposure if their scripts overstate capabilities or obscure consent mechanics.
Read source →ISO Standards
ISO AI standards pipeline expands around 42001
ISO’s AI standards pages indicate continued development around AI management systems, audit and certification, privacy protection, and generative-AI risk guidance. The activity suggests ISO/IEC 42001 is becoming part of a broader assurance stack rather than a standalone management-system topic.
Why it matters: Organizations pursuing ISO-based assurance should make sure AIMS documentation can be reused across privacy, security, and AI governance programs. If certification is on the roadmap, draft alignment work now can reduce rework later when adjacent standards mature.
Read source →US Federal & State Regulation
California AI health-care bills keep moving
Several California AI bills were active in late August 2026, including health-care AI and transparency measures moving through amendments and enrollment. The source materials indicate the bills are still in process and not yet final law.
Why it matters: California-facing teams should monitor final text for disclosure, human-review, or workflow obligations that could affect consumer or clinical AI products. Product, legal, and compliance functions should compare draft requirements with existing privacy and health workflows before the bills advance further.
Read source →FDA advances AI medical device feedback cycle
FDA’s AI-enabled medical device materials show a continuing draft-guidance and feedback process, with public feedback on generative AI-enabled medical devices due by 2026-10-19. The agency is still shaping how it expects lifecycle management, submissions, and validation evidence to look for these devices.
Why it matters: Device teams should prepare model performance, change-control, and postmarket monitoring materials now so they are ready for submissions and any feedback response. Generative AI features may also trigger additional safety, transparency, or human-factors review in the regulatory package.
Read source →FTC enforcement stays active on AI claims
The FTC’s broader AI enforcement posture remains active across deceptive claims and AI investments, with matters such as Rytr, Workado, and DoNotPay cited as examples. The agency is continuing to police what firms say about AI products and business practices.
Why it matters: AI product teams should keep a substantiation file for performance claims and ensure investor, customer, and partner messaging does not overpromise automation or accuracy. That evidence can be critical if the FTC asks how claims were tested and approved.
Read source →Other jurisdictions / frameworks
FINMA sets AI governance expectations for Swiss banks
FINMA’s Guidance 08/2024 says Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks inside their existing supervisory framework. The guidance is operationally immediate for supervised firms and covers model, data, cyber, third-party, legal, and reputational risk.
Why it matters: Swiss firms should test whether current model-risk and governance controls are enough for AI use cases, especially where vendors provide the system or data pipeline. FINMA expects AI oversight to be embedded in existing governance, monitoring, and escalation processes, not treated as an isolated project.
Read source →NIST signals AI RMF revision work
NIST says the AI RMF is being revised and that a new trustworthy-AI profile for critical infrastructure launched on 2026-04-07. The current materials point to active framework development rather than a finalized replacement.
Why it matters: Organizations mapping controls to the AI RMF should watch for terminology and control changes that could affect internal governance, inventories, and assurance evidence. Critical-infrastructure users should also check whether the new profile changes expected risk-management depth.
Read source →On Our Radar
AI Act guidance to land: The EU AI Act consultations show the rulebook is still being shaped. Watch for follow-on guidance, codes, and implementing acts that could harden transparency and GPAI obligations.
FDA feedback deadline: Public feedback on generative AI-enabled medical devices is due by 2026-10-19. Device teams should be preparing submission and validation materials now rather than waiting for the deadline.
FTC claim substantiation: FTC cases suggest deceptive AI marketing is a durable enforcement theme. Expect more scrutiny of accuracy claims, consent language, and vendor-driven AI messaging.
ISO and NIST alignment: ISO 42001 and the NIST AI RMF are both evolving. Compliance teams should keep governance, privacy, and security controls aligned so evidence can be reused across frameworks.