This week, AI governance moved from advisory to operational in several jurisdictions. The European Commission’s AI Office is now positioned as the central enforcement and coordination hub for the EU AI Act, while Australia’s Search Code adds AI-specific restrictions on synthetic child abuse material. In healthcare, HHS and FDA continued to clarify HIPAA responsibilities and the regulatory treatment of AI-enabled medical devices in the US. Meanwhile, regulators in the UK, Switzerland, Singapore and across the EU kept tightening expectations on AI risk management, transparency and third-party resilience.
EU AI Act
EU AI Office takes centre stage on GPAI enforcement
The European Commission says the AI Office is established to support, enforce and coordinate implementation of the AI Act, especially for general-purpose AI. The office can evaluate GPAI models, request information and measures from providers, and apply sanctions.
Why it matters: Teams developing or deploying GPAI in the EU should expect a more centralized enforcement point and more direct information requests. Governance, model documentation and incident response processes should be ready for supervisory scrutiny.
Read source →NIS2 / Cybersecurity
Australia Search Code adds AI safeguards for search engines
eSafety will register the Search Code with extra protections aimed at reducing the risk that search services return child abuse material or use integrated AI to generate synthetic versions of it. The code is set to come into effect six months after registration, and eSafety will oversee complaints and investigations.
Why it matters: Search and platform operators using integrated AI will need controls that prevent generation of prohibited synthetic content, not just ranking or moderation of existing content. Compliance teams should align product, trust and safety, and escalation workflows before the code takes effect.
Read source →ESAs flag AI-linked cyber and dependency risk
The ESAs say external dependencies, cyber threats linked to capable AI models, and private credit are key vulnerabilities for the EU financial system. They urge supervisors and market participants to strengthen preparedness and monitor exposures to non-EEA entities and non-EU/EEA service providers.
Why it matters: Financial firms should treat vendor dependency and AI-related cyber exposure as board-level resilience issues, not just IT concerns. Expect closer scrutiny of critical suppliers, concentration risk and cross-border service dependencies.
Read source →GDPR / Data Protection Enforcement
Dutch DPA issues AI model guidance under GDPR
The Dutch DPA published initial guidance on the lawful development and deployment of generative AI models under the GDPR. It is framed as an initial interpretation for organisations that develop or deploy such models, rather than a new deadline or binding rule.
Why it matters: AI developers and deployers in the EU now have a clearer supervisory signal on how GDPR applies to generative AI lifecycle decisions. That raises the bar for privacy-by-design, data sourcing and documentation around lawful processing.
Read source →Spain’s AEPD tightens transparency for automated decisions
The AEPD says meaningful transparency under the GDPR requires explaining how algorithms influence automated decisions, not just stating that AI was used. It points to GDPR Articles 12 to 14 and Article 22, including the need for meaningful information about the logic applied and the expected consequences for individuals.
Why it matters: Companies using automated decision-making need explanations that are contextual and understandable, especially where decisions are high impact. Generic AI notices are unlikely to satisfy transparency obligations if they do not explain the decision logic and consequences.
Read source →ISO Standards
FINMA sets AI supervision expectations for institutions
FINMA says supervised institutions must manage AI-related risks in business processes, monitor AI-specific risks through appropriate governance, and keep human involvement where outputs cannot be fully understood or explained. It says these expectations are described in the 2023 Risk Monitor and notes ongoing on-site inspections and supervisory exchanges since Q4 2023.
Why it matters: Banks and other supervised firms should treat AI governance as part of standard risk management and audit readiness, especially for opaque models in operational workflows. Human override, model explainability and documented controls are now clearly part of supervisory expectations.
Read source →ICO AI toolkit stays under review after law changes
The ICO says its AI and data protection risk toolkit is practical support for reducing risks to individuals’ rights and freedoms caused by AI systems. The guidance is under review following changes made by the Data (Use and Access) Act and may change.
Why it matters: UK organisations should treat the toolkit as useful operational guidance, but not assume it is static. Privacy and AI governance teams need to watch for revisions that could affect their risk assessments and controls.
Read source →ICO fines guidance clarifies penalty calculations
The ICO published fining guidance explaining when the Commissioner may issue a penalty notice and how fine amounts are determined under UK data protection law. It applies to infringements of the UK GDPR, Parts 3 and 4 of the DPA 2018, and certain notice failures under Part 6.
Why it matters: This gives compliance teams a clearer view of how the ICO will think about penalties when enforcement is on the table. Organisations should review escalation, remediation and evidence preservation processes with potential fining exposure in mind.
Read source →Singapore PDPC keeps AI governance guidance in play
The PDPC published Singapore’s Approach to AI Governance as a guidance resource and also announced a proposed guide to synthetic data generation. The synthetic data item is presented as an announcement rather than a binding rule, and the public consultation on AI recommendation and decision systems remains advisory.
Why it matters: Singapore continues to signal expectations around practical AI governance without hard enforcement deadlines in these materials. Organisations using synthetic data or recommendation systems should track these publications as indicators of future supervisory direction.
Read source →US Federal & State Regulation
HHS reiterates HIPAA covered entity and associate duties
HHS explains that HIPAA applies to covered entities and business associates, and that covered entities must use written business associate arrangements when delegating work involving protected health information. It also notes that business associates are directly liable for certain HIPAA provisions, while entities outside those definitions are not subject to the HIPAA Rules.
Why it matters: Healthcare organisations and vendors should verify their role classification and contract chain before handling PHI. Missing or weak business associate arrangements remain a direct compliance gap, not just a procurement issue.
Read source →HHS refreshes minimum necessary PHI guidance
HHS says the HIPAA Privacy Rule generally requires covered entities to limit uses, disclosures and requests for PHI to the minimum necessary to accomplish the intended purpose. The guidance recommends policies, standard protocols for routine requests and case-by-case review for non-routine disclosures.
Why it matters: This affects day-to-day data handling, not just policy language, because teams need routine request workflows that actually minimize PHI shared. Compliance teams should check whether internal procedures and role-based access still reflect the minimum necessary standard.
Read source →FDA restates risk-based approach for AI medical devices
FDA says AI-enabled medical devices are regulated under the FD&C Act through a risk-based approach and highlights lifecycle management, PCCPs and software modification pathways. The agency also points to its AI-enabled medical device resources and the AI-Enabled Medical Device List.
Why it matters: Medical device manufacturers should align design controls, change management and submission strategy with FDA’s risk-based model for software and AI updates. If a product uses a Predetermined Change Control Plan, the submission and post-market governance process needs to be documented early.
Read source →FDA updates list of authorized AI medical devices
The FDA’s AI-Enabled Medical Device List identifies AI-enabled devices authorized for marketing in the United States and is updated periodically. FDA notes the list is not comprehensive and is based mainly on AI-related terms in public summaries and classifications.
Why it matters: This is a useful market intelligence source for regulated manufacturers and buyers, but not a complete register of AI devices. Companies should not assume a device is absent from the list just because it is not shown there yet.
Read source →FDA cites IMDRF principles for GMLP
FDA says IMDRF released 10 guiding principles in January 2025 that can inform Good Machine Learning Practice for AI and machine-learning medical devices. The principles are intended to help advance safe, effective and high-quality devices and to push standards bodies and regulators toward further collaboration.
Why it matters: Manufacturers should expect GMLP expectations to continue converging with international standards and lifecycle controls. Even without a new binding rule, these principles are useful for design, validation and post-market planning.
Read source →Other jurisdictions / frameworks
OECD launches daily AI Law Radar tracker
The OECD’s AI Law Radar tracks AI laws, regulations and obligations across 79 jurisdictions for compliance, legal, privacy and AI governance teams. Users can browse by jurisdiction or topic, export deadlines to a calendar file and download the register as CSV, with each entry linked to a primary source.
Why it matters: This is not a rule change, but it is a useful operating tool for teams managing multi-jurisdiction AI compliance. It can help legal and compliance functions centralize obligations and keep track of source-linked updates across markets.
Read source →HHS OCR newsroom shows active HIPAA enforcement
HHS OCR’s newsroom page lists recent press releases and bulletins on HIPAA, civil rights and related enforcement activity, including multiple 2026 settlements and investigations. The page is an index rather than a new rulemaking or enforcement notice.
Why it matters: Even without a new obligation, the newsroom signals where OCR is focusing enforcement attention. Privacy and security teams should use it to spot recurring enforcement themes and test whether current controls would withstand scrutiny.
Read source →On Our Radar
EU AI Act enforcement build-out: The AI Office now has a clear support and enforcement role for general-purpose AI. Watch for more supervisory activity, information requests and model-level scrutiny from Brussels.
Synthetic data scrutiny: Singapore is still publishing guidance and consultation material around AI recommendation systems and synthetic data. That suggests continued interest in how these techniques affect privacy, fairness and accountability.
HIPAA enforcement themes: OCR’s newsroom shows ongoing settlements and investigations. Healthcare privacy teams should keep watching for patterns that could influence audits, investigations and settlement expectations.
AI transparency for automated decisions: The AEPD’s guidance reinforces that generic AI disclosures are not enough under GDPR. Expect more pressure on firms to explain logic, consequences and context in automated decision-making notices.