This week, the biggest moves were in the EU AI Act, where the European Commission advanced implementation work on GPAI, high-risk classification, transparency, and sandboxes, and in Singapore, where IMDA updated its agentic AI governance framework while PDPC personal-data guidance remains the baseline. In the UK, the FCA said it will not create AI-specific rules, and the ICO confirmed its AI and data protection guidance still applies while under review after the Data (Use and Access) Act 2025. In the US, NIST is revising the AI RMF, the FTC continues to shape expectations through AI enforcement, and FDA guidance remains important for AI-enabled medical devices. Switzerland also stood out, with the FDPIC confirming existing data protection law already covers AI processing and pointing to a federal AI bill target by end-2026.
EU AI Act
Commission advances AI Act guidance on GPAI
The European Commission and European AI Office advanced implementation workstreams for the EU AI Act covering general-purpose AI, high-risk classification, transparency, and regulatory sandboxes. The update is consultation and guidance-track material, so providers and deployers should use it to align implementation plans before final guidance lands.
Why it matters: Teams need to map models and systems now against likely GPAI, high-risk, and Article 50 transparency obligations. Waiting for national practice to settle risks rework in disclosures, labelling, governance documentation, and sandbox participation decisions.
Read source →NIS2 / Cybersecurity
Singapore refines agentic AI governance framework
IMDA updated Singapore’s model AI governance framework for agentic AI, while PDPC personal-data guidance remains the main reference for AI recommendation and decision systems. The guidance focuses on autonomy, third-party agent dependencies, human oversight, transparency, accountability, and escalation of model failures.
Why it matters: Organizations using agentic or multi-agent systems should review where human review actually occurs and whether vendor or agent dependencies are documented. Product and operations teams also need to align user disclosures and data-use controls with PDPC guidance now, not after a failure event.
Read source →NIST revises AI RMF, adds critical-infrastructure profile
NIST said the AI Risk Management Framework is being revised and that a new trustworthy-use profile for critical infrastructure is under development. AI RMF 1.0 remains voluntary, with a formal review no later than 2028.
Why it matters: Security and governance teams using the AI RMF as an internal control baseline should expect changes to risk taxonomy and board reporting. Critical-infrastructure use cases should be checked against the emerging profile now so control gaps are not discovered during later updates.
Read source →DORA
FCA will not add AI-specific financial rules
The FCA said it is not planning AI-specific regulation and will rely on existing regimes such as Consumer Duty and SM&CR. The update is a policy position, not a new rule, and the regulator points firms toward current governance, resilience, and conduct frameworks.
Why it matters: Financial firms should embed AI oversight into existing operational resilience, model risk, and conduct controls instead of waiting for a separate AI rulebook. That means reviewing third-party tools and customer-facing use cases under current controls now.
Read source →GDPR / Data Protection Enforcement
ICO keeps AI guidance active during review
The ICO said its AI and data protection guidance remains the current baseline for audit and enforcement activity, even though it is under review following the Data (Use and Access) Act 2025. The guidance still supports risk assessments, accountability, and enforcement preparation.
Why it matters: UK organizations should continue using the existing ICO guidance for personal-data processing in AI systems while tracking any revisions. If you are preparing for enforcement, the published toolkits and fining frameworks should already be reflected in your evidence pack and governance records.
Read source →Swiss FDPIC confirms FADP applies to AI
The FDPIC said Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026. The guidance emphasizes transparency, legal basis, and human review for automated decisions using personal data.
Why it matters: Companies operating in Switzerland should tighten disclosures around data sources, purpose, and functionality, and build objection and human-review workflows for automated decisions. This is a current compliance issue under existing FADP rules, not just a future legislative watch item.
Read source →ISO Standards
ISO/IEC 42006:2025 sets certifier requirements
ISO/IEC 42006:2025 adds requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001. ISO records its publication in July 2025, making it relevant to certification bodies and to organizations choosing an AI management system certifier.
Why it matters: If your company is seeking ISO/IEC 42001 certification, the certifier’s own qualifications and process requirements now matter more clearly. Procurement and assurance teams should use the standard to assess the credibility and scope of certification providers.
Read source →AICPA reaffirms SOC 2 controls for AI services
AICPA’s SOC resources confirmed that the current Trust Services Criteria remain the baseline and do not introduce AI-specific rules. AI-enabled services still need to satisfy existing expectations for security, availability, processing integrity, confidentiality, and privacy in audits.
Why it matters: Service teams cannot treat AI as an exemption from SOC 2 evidence requirements. System descriptions, vendor dependencies, human oversight points, and incident handling all need to reflect AI components in the audit file.
Read source →US Federal & State Regulation
FTC cases sharpen AI claims substantiation risk
FTC records cover separate proceedings involving AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order. The materials do not create a single new deadline, but they show the FTC’s continued focus on deceptive AI performance claims and evidence backing those claims.
Why it matters: Companies marketing AI tools should tighten substantiation, testing, and documentation before making performance claims. Enforcement posture depends on the facts of each matter, so teams should review their own claims and evidence rather than rely on generic AI branding language.
Read source →FDA PCCP guidance remains the device baseline
FDA’s August 2025 guidance on planned modifications for AI-enabled medical devices remains the reference point for devices reviewed through 510(k), De Novo, and PMA pathways. The guidance says a PCCP may be appropriate for planned changes, but it is not mandatory for every AI-enabled device.
Why it matters: Medical-device teams need to confirm the applicable submission pathway and decide whether a PCCP is needed for planned model changes. If used, the PCCP must describe the modifications, validation and implementation methods, and impact assessment.
Read source →California AI bills keep moving late session
California bills AB2575, SB503, AB1979, and SB947 advanced late in session, with proposals touching healthcare services and automated decision systems. The items are still in the legislative pipeline and are not yet final obligations.
Why it matters: Employers and healthcare providers should continue mapping AI use cases to the proposed requirements so they can move quickly if any bill is enacted. At this stage, the main risk is assuming the status quo is permanent when disclosure or governance duties may change.
Read source →SEC AI task force is internal only
The SEC announced an internal AI task force in August 2025 to coordinate responsible AI adoption across the agency. The announcement does not impose a new external compliance requirement on regulated firms.
Why it matters: This is useful context on the SEC’s internal direction, but it should not be confused with a new AI filing, reporting, or governance rule. Firms should still monitor enforcement actions separately for any AI-related expectations.
Read source →Other jurisdictions / frameworks
Swiss roadmap points to AI bill by 2026
Alongside its data protection guidance, the FDPIC said the federal government is targeting an AI bill by the end of 2026 and tracking ratification steps for the Council of Europe AI Convention. The current position is a policy roadmap, not an enacted deadline.
Why it matters: Swiss businesses should treat the roadmap as a signal to harden transparency and objection processes now, because legislative follow-on is expected. Governance teams should watch for legal alignment work once the bill enters the legislative process.
Read source →On Our Radar
EU AI Act implementation: Consultations on GPAI, transparency, and sandboxes are moving now, so compliance teams should expect the next wave of practical obligations to come through guidance rather than a single clean deadline.
AI governance inside existing regimes: The FCA and ICO both signaled that AI will be managed through existing conduct and data-protection frameworks, which means firms need to retrofit AI into current control libraries rather than wait for bespoke AI rules.
Voluntary baselines are hardening: NIST AI RMF revision, ISO/IEC 42006:2025, and AICPA SOC materials all point to more structured assurance expectations for AI systems, especially where certification, audit evidence, and critical infrastructure are involved.
Healthcare and employment bills: California’s AI bills are still live, so employers and healthcare organizations should keep a close watch for final enactment and prepare to update disclosures and automated-decision governance quickly.