Skip to content
Regulayer™Human Control for AI
Book a live demo

Research library · Law and regulation

AI law, June to September 2026: what changed

A dated digest of AI law and regulation events from 9 June to 28 September 2026, grouped by jurisdiction. Each item is stated as it stood when it happened, with a dated "Since then" line where it has moved, checked on 2 October 2026.

Compiled from public sources, 2 October 2026. Information, not legal advice.

Period covered: 9 June to 28 September 2026. Every item was checked against a primary or reputable source on 2 October 2026. Bills that had not been signed at the time are marked pending. Nothing here is legal advice.

US federal

  • FTC proposed policy statement on AI accuracy, 1 July 2026. The FTC sought comment, until 31 July 2026, on a proposed statement that altering AI outputs for undisclosed ideological ends can be deceptive under Section 5 of the FTC Act. It says state laws requiring such alterations may be impliedly preempted, and names Colorado's AI Act. (FTC)
  • State attorneys general subpoena OpenAI, June 2026. New York's Attorney General served OpenAI with a subpoena on behalf of a multistate coalition, reported as 42 states. It seeks records on advertising, engagement, consumer and health data, minors and seniors, and model sycophancy. (TechCrunch, 13 June 2026, The Next Web)
  • FDA discussion paper on generative AI-enabled medical devices, 18 August 2026. FDA published "Considerations for the Regulation of Generative AI-Enabled Medical Devices", a discussion paper and request for feedback (docket FDA-2026-N-7874, comments due 19 October 2026). It is not guidance. It proposes a two-axis risk framework, competency-based premarket evaluation and postmarket monitoring. (FDA press announcement, FDA discussion paper page)
  • FTC final orders over "Active Listening", 27 August 2026. The FTC finalized orders against Cox Media Group (880,000 dollars), MindSift (25,000 dollars) and 1010 Digital Works (25,000 dollars), 930,000 dollars in all, over an advertising service marketed as using AI to target ads from consumers' device conversations. Each firm is barred for 20 years from misrepresenting its advertising services, voice data collection and consent, and geographic targeting. (FTC)

US states

California

  • AI Transparency Act detection tools tested, 12 August 2026. Indicator and WITNESS published tests of the detection tools of 13 providers covered by the Act, which became operative on 2 August 2026. Indicator reported that seven providers "do not appear to have a dedicated public detection tool available yet". (Indicator, Transparency Coalition)
  • Appropriations suspense votes, 13 August 2026. Of 29 active AI bills, 24 moved forward and five were held in committee: AB 412 (documentation of copyrighted training material), AB 2545, SB 1015, SB 1146 and SB 1181. (Transparency Coalition)
  • SB 1000 cleared the legislature, 27 August 2026. It amends the California AI Transparency Act: it removes the 1,000,000 monthly user threshold for covered providers, deletes the optional manifest disclosure, requires the latent disclosure to say whether the system created or altered the content, and renames the "AI detection tool" a "disclosure verification tool". It is an urgency statute. Pending signature at the time. (CalMatters Digital Democracy)
  • Since then (checked 2 October 2026): chaptered on 30 September 2026 as Chapter 861, Statutes of 2026. (CalMatters Digital Democracy)
  • AB 2713 cleared the legislature by the 31 August 2026 close. It changes the large online platform statement from whether provenance data or digital signatures "are available" to whether they are "embedded into, attached to, or otherwise associated with the content". It also provides that platforms need not act on provenance data that does not comply with "widely adopted specifications issued by an established standards-setting body". Pending signature at the time. (Transparency Coalition, 4 September 2026, CalMatters Digital Democracy)
  • Since then (checked 2 October 2026): chaptered on 30 September 2026 as Chapter 856, Statutes of 2026. (CalMatters Digital Democracy)
  • Session closed, 31 August 2026. The legislature adjourned near midnight; the Governor had until 30 September to act on about 30 AI-related bills. (Transparency Coalition, 4 September 2026)
  • SB 813 and AB 1405 signed, 9 September 2026. SB 813 sets up a framework for independent verification organizations; AB 1405 creates an AI Auditor Registry. Under the enacted texts, the Government Operations Agency must set up the verification organization process by 1 January 2028, and the registry by 1 January 2029, when unregistered persons may no longer offer, sell or conduct a covered AI audit. SB 813 does not require developers or deployers to engage a verification organization. (Governor of California, Kelley Drye)
  • SB 1119 signed, 10 September 2026. It amends the companion chatbot law. Operators must carry out risk assessments for minor users and, from 1 January 2029, undergo independent child safety audits every two years, with a revenue-based exemption for smaller operators until 2032. The lead auditor certifies the results under penalty of perjury. Chapter 190, Statutes of 2026. (CalMatters Digital Democracy, Kelley Drye)
  • SB 1050 signed, 16 September 2026. Advertisements featuring a synthetic performer need a disclosure substantially similar to "this performance features a synthetic digital performer". It covers video and audio advertisements and bars continued use of an advertisement found in violation. (Governor of California, Kelley Drye)
  • Executive order on frontier AI oversight, 18 September 2026. The Governor directed the Government Operations Agency, with the Office of Emergency Services, to recommend by 16 November 2026: independent verification organizations embedded onsite at frontier AI labs, independent verification of safety frameworks, transparency reports and risk assessments, a "kill switch" for frontier models, and expanding critical safety incidents to include loss-of-control incidents. These are recommendations, not requirements. (Governor of California, CalMatters)
  • 27 September 2026 actions. AB 2025, requiring disclosure of digitally altered images in rental housing, was signed. Many AI bills, including SB 1000, AB 2713, SB 947, SB 574 and SB 1159, were still unsigned with the 30 September deadline three days away. (Governor of California, 27 September 2026)
  • Since then (checked 2 October 2026): on 30 September the Governor signed SB 1000, AB 2713, SB 947 (employer use of automated decision systems, effective 1 July 2027), SB 951, SB 503, SB 1111, SB 1159 (AI systems are not a "person" under the Public Records Act and open meeting laws, Chapter 863), AB 1979 and AB 1883, among others (Transparency Coalition, Stauss PLLC). SB 574, on attorneys' and arbitrators' use of generative AI, was chaptered as Chapter 858 (CalMatters Digital Democracy). AB 2575 (AI in health care services) and SB 903 (AI in psychotherapy services) were vetoed (Governor of California, 30 September 2026).

Colorado

  • ADMT Act and Chatbot Safety Act rulemaking. The Attorney General's pre-rulemaking comment form closed on 13 July 2026. On 11 August 2026 the Department of Law filed proposed Automated Decision-Making Technology and Chatbot Safety rules to implement SB 26-189 and HB 26-1263, both effective 1 January 2027. Comments received by 4 September were to be considered for a revised draft; the comment period runs to 26 October 2026, the date of the formal hearing. The ADMT Act requires rules before 1 January 2027. (Colorado Attorney General)
  • Since then (checked 2 October 2026): the Attorney General's page says the revised draft will be circulated at least five days before the hearing, and no revised draft is posted there. (Colorado Attorney General)

Other states

  • New York, 9 June 2026. General Business Law section 396-b (S.8420-A / A.8887-B) took effect: advertisers must conspicuously disclose a synthetic performer in an advertisement when they have actual knowledge of it, with penalties of 1,000 dollars for a first violation and 5,000 dollars for each later one. Audio-only advertisements are excluded. (Cooley)
  • Washington, 10 June 2026. SSB 5886 took effect. It amends the state's personality rights law to cover forged digital likenesses, including AI deepfakes. (NBC Right Now, Mondaq)
  • Connecticut, 1 July 2026. Amendments to the Connecticut Data Privacy Act (SB 1295, Public Act 25-113) took effect, lowering the applicability threshold and extending the profiling opt-out from "solely automated" to "any automated" decisions with legal or similarly significant effects, with a new right to contest profiling decisions. (Covington, Inside Privacy, Ice Miller)
  • Illinois, 6 July 2026. SB 315, the Artificial Intelligence Safety Measures Act, was signed. It applies to developers of the largest frontier models and requires public safety disclosures, reporting of significant safety incidents, whistleblower protections and independent third-party safety audits. Effective 1 January 2027. (Governor of Illinois)
  • Hawaii, 14 July 2026. HB 2137 (Act 247) creates a civil action of up to 25,000 dollars per piece of content for unauthorized realistic AI digital imitations. SB 3001 (Act 248), the Artificial Intelligence Disclosure and Safety Act, requires AI companion operators to disclose that users are interacting with AI, to have protocols for users expressing suicidal ideation, and to add protections for minors. (Big Island Now, Hunton)
  • New Jersey, 20 July 2026. The Governor signed the Forbidding the Algorithmic Inflation of Rent (FAIR) Act, A3497, which regulates algorithmic rent-setting. New Jersey is the fourth state to regulate rent-setting algorithms. (Governor of New Jersey, ROI-NJ)
  • State totals, 21 July 2026. The Transparency Coalition's mid-year report counted 84 new AI laws enacted in 27 states in the first half of 2026. (Transparency Coalition)
  • Massachusetts, 29 July 2026. H 4616, a health insurance prior authorization bill that includes the use of AI in prior authorizations, was recommended ought to pass and referred to House Ways and Means. Pending. (Massachusetts Legislature, Transparency Coalition)
  • Texas. The Attorney General's Consumer AI Rights page under the Texas Responsible AI Governance Act carries a "File An AI Complaint" link. It lists civil penalties of 10,000 to 12,000 dollars per curable violation, 80,000 to 200,000 dollars per uncurable violation, and 2,000 to 40,000 dollars per day for a continued violation, and states that the Act provides no private right of action (page checked 2 October 2026). (Texas Attorney General)
  • New York, 3 September 2026. Sponsors urged Governor Hochul to sign a bill requiring businesses to report AI's workforce effects (displacement, reduced hours, new jobs) to the Department of Labor. Pending. (Spectrum News)

EU

  • Digital Omnibus on AI becomes law. Parliament approved the agreed text on 16 June 2026 and the Council adopted it on 29 June. It was signed on 8 July, published in the Official Journal as Regulation (EU) 2026/1744 on 24 July and entered into force on 27 July 2026. High-risk obligations move to 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in regulated products. The grace period for marking AI-generated content by systems already on the market ends on 2 December 2026. National sandboxes move to 2 August 2027. It adds a new Article 5 prohibition covering AI systems that generate non-consensual intimate imagery and child sexual abuse material. (Law & Technology, Sofia Globe, 16 June 2026, Shumaker, EUR-Lex)
  • Code of Practice on Transparency of AI-Generated Content. The final code was published on 10 June 2026. On 8 July the Commission found that it adequately covers Article 50(2), (4) and (5); the AI Board adopted its adequacy assessment on 9 July. Google said on 24 July that it would sign. On 31 July the Commission reported about 190 signatories, among them Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia as providers, with two task forces to start in September 2026. (Commission, code page, Commission opinion, Google, Commission, 31 July 2026)
  • Article 50 guidelines, 20 July 2026. The Commission adopted guidelines on the transparency obligations of providers and deployers of AI systems under Article 50. (Commission)
  • Article 50 applies, 2 August 2026. The transparency obligations apply from 2 August 2026. The Commission's FAQ says a limited grace period, to 2 December 2026, applies only to systems placed on the market before 2 August 2026 and only to the marking and detection obligation. (Commission FAQ)
  • AI Office enforcement powers over general-purpose AI, 2 August 2026. From this date the AI Office can use its investigative and enforcement powers over general-purpose AI providers, including fines up to the higher of 15 million euros or 3 percent of worldwide annual turnover. Its FAQ calls "technical compliance dialogues" its preferred initial tool. No formal action had been reported as of 3 August. (Wilson Sonsini, 3 August 2026, AI Act Service Desk FAQ)
  • Italy, 4 August 2026. The Council of Ministers gave final approval to two legislative decrees adapting Italian law to the AI Act under Law 132/2025. One covers AI in policing, allowing real-time biometric identification only exceptionally with prior judicial authorization and banning untargeted web-scraped biometric databases. The other designates AgID as notifying authority and ACN as market surveillance authority. (Department for European Affairs, DIMT)

Rest of world

  • Singapore, 1 July 2026. The Personal Data Protection Commission's consultation on proposed Advisory Guidelines on Use of Personal Data in Generative AI closed. (Hogan Lovells)
  • Since then (checked 2 October 2026): the final guidelines were published on 20 July 2026. (Stephenson Harwood, Eversheds Sutherland)

Courts and federal evidence rules

  • Proposed Federal Rule of Evidence 707 (machine-generated evidence). At its June 2026 meeting the Judicial Conference's Standing Committee decided "not to recommend action on Rule 707 at this time" and returned it for revision, alongside the separate deepfake question. (National Law Review)
  • Since then (checked 2 October 2026): the Advisory Committee's agenda book for its 15 October 2026 meeting says the Committee voted to withdraw the rule as published for comment and to submit a modified proposal for further study, with a panel of experts at that meeting. Draft Rule 901(c), on evidence challenged as a deepfake, will be taken up at the same session. A Federal Judicial Center survey reported there found that of 931 responding federal judges, 15 had encountered a deepfake challenge. (Advisory Committee on Evidence Rules, agenda book)
  • Estate of Lokken v. UnitedHealth Group (D. Minn., No. 23-cv-3514). On 18 September 2026 the court granted a joint motion to amend the schedule. Plaintiffs' class certification expert declarations are due 14 October 2026; the class certification motion is due 16 February 2027; class certification briefing runs to 21 June 2027; dispositive motions are due 27 September 2027; trial ready is on or about 7 February 2028. No class has been certified. (Order, 18 September 2026)
  • xAI v. Weiser (D. Colo.). The United States intervened on 24 April 2026 in xAI's challenge to Colorado's AI law. Through the period, enforcement was stayed until 14 days after a ruling on xAI's preliminary injunction motion, which is due 28 days after the state finalizes its rules. (Norton Rose Fulbright, Jenner & Block)

Related rules outside AI law

  • EU Cyber Resilience Act. The Commission published non-binding implementation guidance with 67 practical examples on 27 July 2026. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents; ENISA launched the initial operating capability of the Single Reporting Platform that day. (Commission, ENISA)
  • US HIPAA Security Rule. The 2026 Unified Agenda moved the proposed Security Rule amendments (RIN 0945-AA22) to Long-Term Actions, with July 2027 as the planned final action date, a planning target rather than a deadline. (Clark Hill, McDermott)