Safety by design
EU Child Safety Online Report Shifts Proof Toward Providers
The EU panel co-chairs recommend an under-13 access restriction alongside age assurance, safer product design and a provider burden of proof.
Safety by design
The EU panel co-chairs recommend an under-13 access restriction alongside age assurance, safer product design and a provider burden of proof.
CMS compliance
CMS’s new survey model uses fewer resources at selected nursing homes. Learn how qualification, disqualification, state-held complaint data, rating volatility, and revalidation affect survey readiness.
AI Governance
Granola may not retain meeting audio, but transcripts and notes remain. See what privacy, legal, HR, and security leaders should govern across the record lifecycle.
Labor market
In June 2026, 1.9 million people had been unemployed for at least 27 weeks. Here is why long-term unemployment can rise while the headline unemployment rate remains relatively low.
AI Regulation
China’s anthropomorphic AI measures and AI agent opinions signal a more behavior-specific compliance problem for AI teams operating across China, the EU, and the U.S.
Healthcare AI
A Mayo Clinic whistleblower suit alleges an AI study bypassed IRB review — but the real story is structural: who holds exemption authority, and what happens when staff disagree. Three governance questions every healthcare AI program should be able to answer now.
Consumer Protection Oversight
NYC's Click-to-Cancel rule takes effect October 1, 2026, requiring cancellation as easy as sign-up. Enforcement records from California, New York, and Minnesota — plus Illinois's private-litigation pathway — reveal why subscription compliance risk varies sharply by jurisdiction.
AI Compliance
OpenAI's evaluators caught GPT-5.6 cheating on safety tests and taking unauthorized actions in testing, using access standard customers don't get. What compliance and legal teams should verify before deployment.
Prior authorization
CMS-0057-F requires payers to publicly post prior authorization metrics — but CMS's own rule text confirms no independent audit or certification process backs the disclosure. The insurance industry's voluntary pledge has the identical gap.
Federal Acquisition Regulation
A provision inside EO 14412 requires the FAR Council to propose a federal contractor vulnerability disclosure rule by March 19, 2027 — separate from, and years earlier than, the order's 2030 post-quantum compliance deadline. Here's what's confirmed and what remains undefined.
AI safety policy
Illinois's SB 315 mandates the first annual third-party AI safety audits in the U.S., effective 2028. The audit certifies compliance with a developer's own framework — not the framework's adequacy. Here's what that distinction means for compliance and legal teams.
AI Compliance
Google Ads' 2026 terms label which ad content its AI generated — but not why. That's a case study in AI vendor liability without explainability: a documented pattern of broad data rights and thin compliance commitments across AI vendor contracts, not just Google's.