AI Regulation Tightens, but Medical Model Rules Remain Unclear
New rules in the EU and Connecticut are expanding requirements for AI transparency, safety, oversight and accountability across newsrooms and consumer services. The FDA petition shows the unresolved tension: as obligations grow, developers and downstream users still lack clear standards for validating and assigning responsibility for foundation models used in medical diagnosis.
Monday, Aug 24, 2026
Tracking: AI Legislation · AI law · AI regulation
1. EU AI Act Transparency Rules Reach Newsrooms
Transparency obligations under the EU AI Act came into force in August 2026, putting new pressure on media companies to label AI-generated material and show who remains accountable for publication.
The law does not ban newsroom AI use: it covers tools used for research, translation, summarisation, creation and distribution, while requiring oversight and transparency around their use.
The wider Act uses risk tiers: unacceptable applications are prohibited, high-risk systems face detailed controls, and lower-risk tools such as chatbots and deepfakes carry lighter disclosure duties.
Its rules also reach providers outside the EU when high-risk outputs are used in Europe, and require general-purpose AI providers to document models, comply with copyright rules and summarise training content.
South African newsrooms are an early stress test: a CINIA study found fragmented policies, informal training and uncertainty about permitted use, with journalists reporting mistranslations of political and cultural terms.
Key facts:
- EU AI Act transparency obligations came into force in August 2026.
- CINIA found few South African newsrooms had clear AI policies.
- The Act prohibits social scoring and manipulative AI causing significant harm.
- Systemic-risk GPAI providers must conduct evaluations, incident reporting, and cybersecurity protections.
- The European Commission published draft GPAI guidelines on 18 July 2025.
Why it matters: For publishers, AI transparency is becoming an editorial-control requirement rather than a voluntary trust measure.
The Act distinguishes obligations for providers and professional deployers, while the South African experience shows the practical gap between formal rules and newsroom practice: staff may be using tools inconsistently, without clear disclosure, human review or accountability.
Newsrooms that establish written policies, training and fact-checking processes will be better placed to manage that gap; those relying on informal experimentation face greater exposure to errors and complaints.
The EU framework also extends beyond European companies when relevant systems or outputs are used in Europe, giving its requirements international reach.
The next issue to watch is whether South Africa’s press bodies turn existing nonbinding guidance into a formal AI press code, and how regulators address language and cultural failures that imported models can produce.
2. Connecticut Enacts Broad AI and Online-Safety Law
Connecticut enacted the Artificial Intelligence Responsibility and Transparency Act, known as the CART Act, after passing SB5.
The omnibus law combines rules for frontier AI developers, chatbots, synthetic-content labels, employment decisions, subscriptions, youth online safety, and workforce training. It takes effect October 1, 2026, with most business obligations beginning in 2027.
From January 1, 2027, covered AI companions must disclose their artificial nature when needed and respond to detected suicide, self-harm, or imminent-violence expressions with mental-health resources.
Operators aware that users are under 18 face additional duties, while the Attorney General—not private plaintiffs—enforces the law. Connecticut also created a working group and economic initiatives tied to the state’s 2026 “Anno Machinae” program.
Unlike Connecticut’s privacy law, SB5 applies to all entities doing business in the state, without CTDPA thresholds.
Key facts:
- SB5 was retitled the Connecticut Artificial Intelligence Responsibility and Transparency Act.
- The law takes effect October 1, 2026; most business obligations begin in 2027.
- AI-companion rules begin January 1, 2027.
- The Attorney General enforces SB5; it creates no private right of action.
- SB5 applies to all entities doing business in Connecticut, unlike CTDPA thresholds.
Why it matters: Connecticut is choosing breadth over the narrower state approach described in the article, placing frontier-model risks, chatbot safety, employment decisions, synthetic media, and online youth protections in one statute.
Its reach extends beyond traditional AI companies because SB5 covers all entities doing business in Connecticut, while enforcement is concentrated with the Attorney General.
AI-companion providers will need disclosure and crisis-response processes, and products used by minors may require age gating or significant redesign.
Businesses should watch the staggered compliance dates, the Attorney General’s enforcement approach, and the working group’s proposals as Connecticut develops its broader AI policy framework.
3. Radiology Partners asks FDA to clarify rules for imaging AI models
Radiology Partners and its technology services division are petitioning the FDA to clarify how commercially distributed vision-language models used for medical-image diagnosis should be regulated.
Mosaic Clinical Technologies submitted the citizen petition on August 12, asking whether a model marketed for later fine-tuning with institution-specific data is itself a medical device requiring premarket clearance or approval.
The petition also seeks consistent FDA expectations for validation, performance monitoring, transparency and quality management.
Its authors argue that foundation models lack an established standard for performance and quality, potentially leaving radiologists and other downstream users responsible for judging safety and suitability while developers disclaim reliability or legal compliance.
The request frames clearer rules as a way to protect patients and support responsible innovation.
Key facts:
- Mosaic Clinical Technologies submitted the FDA citizen petition on August 12.
- The petition asks whether fine-tunable imaging models require premarket clearance or approval.
- No established standard currently validates these models’ performance and quality.
- The petition requests clarity on validation, monitoring, transparency and quality management.
Why it matters: The dispute centers on who carries regulatory responsibility when a general-purpose imaging model is adapted for clinical use.
Radiology Partners says unclear requirements can leave radiologists and healthcare organizations judging whether models are safe and suitable, even when developers provide limited warranties or disclaim responsibility for reliability and legal compliance.
FDA clarification could give developers, hospitals and clinicians a more consistent compliance framework.
The petition warns that absent oversight and standardization, models may rely on biased or unrepresentative data, lack transparency or cybersecurity controls, and create risks of patient harm; the agency’s response will determine whether existing medical-device rules are applied more consistently to these systems.