Covering South African Reserve Bank, Durable Medical Equipment, Inflation Target, Cybersecurity Framework, Generative AI. Explore key regulatory updates on the South African Reserve Bank, Durable Medical Equipment fraud, Inflation Target policies, the NIST Cybersecurity Framework 2.0, and FDA's approach to Generative AI in medical devices.
Weekly news, analysis, and insights from AI regulation updates the world over
Welcome to This Week in AI Regulations.
In the United States, the Food and Drug Administration, or FDA, has issued a discussion paper seeking public feedback to inform a regulatory framework for generative AI-enabled medical devices. The FDA invites comments on risk assessment frameworks, proposed premarket competency assessments including non-clinical benchmarking and clinical confirmation, and risk-proportionate postmarket monitoring strategies.
Also in the United States, the National Institute of Standards and Technology released Special Publication 1353, a draft offering structured AI prompts and use cases to support the implementation and analysis of the Cybersecurity Framework 2.0. Public comments are open until October 15, 2026. The publication encourages the use of AI-assisted tools to enhance cybersecurity risk governance and compliance. Stakeholders are urged to consider specific precautions regarding AI use and submit feedback by the deadline.
The Commodity Futures Trading Commission, or CFTC, announced that its Innovation Advisory Committee will hold its inaugural meeting on August 20, 2026, in Washington, D.C. The committee will provide insights on innovation-related regulatory matters including crypto assets, artificial intelligence, and prediction markets. The meeting is open to the public both virtually and in person, with comments accepted until August 27, 2026. A livestream and transcript will be made available.
Turning to the European Union and the Netherlands, the Autoriteit Persoonsgegevens, the Dutch Data Protection Authority, has introduced a new requirement for organizations deploying high-risk AI systems. Starting December 2027, both public and private organizations must conduct a Fundamental Rights Impact Assessment, or FRIA, before deploying such AI systems. The FRIA must assess impacts on fundamental rights including equality, dignity, privacy, and access to essential services. Organizations are also required to describe risk mitigation measures and report their findings to the supervisory authority. To assist with compliance, the AP has launched a pilot program to provide practical experience with the FRIA process.